X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=vbuild-init-vserver.sh;h=301b8389549fdc4771cb52064ebd062536fda756;hb=bcb75ae3986f5ce19740727a0531d4df357d9b00;hp=d1b44b5711f86e143f7f30c5cc903a982ebfdac3;hpb=db863f7535a57e249204f47688a1046a0641c585;p=build.git diff --git a/vbuild-init-vserver.sh b/vbuild-init-vserver.sh index d1b44b57..301b8389 100755 --- a/vbuild-init-vserver.sh +++ b/vbuild-init-vserver.sh @@ -1,15 +1,22 @@ #!/bin/bash # -*-shell-*- +#shopt -s huponexit + COMMAND=$(basename $0) DIRNAME=$(dirname $0) # pkgs parsing utilities -PATH=$(dirname $0):$PATH . build.common +PATH=$(dirname $0):$PATH export PATH +. build.common -DEFAULT_FCDISTRO=f7 +DEFAULT_FCDISTRO=f14 DEFAULT_PLDISTRO=planetlab -DEFAULT_PERSONALITY=linux32 +DEFAULT_PERSONALITY=linux64 +DEFAULT_IFNAME=eth0 + +COMMAND_VBUILD="vbuild-init-vserver.sh" +COMMAND_MYPLC="vtest-init-vserver.sh" function failure () { echo "$COMMAND : Bailing out" @@ -26,36 +33,40 @@ function configure_yum_in_vserver () { vserver=$1; shift fcdistro=$1; shift + pldistro=$1; shift - cd /etc/vservers/.distributions/${fcdistro} - if [ -f yum/yum.conf ] ; then - echo "Initializing yum.conf in $vserver from $(pwd)/yum" + templates=/etc/vservers/.distributions/${fcdistro} + if [ -f ${templates}/yum/yum.conf ] ; then + echo "Initializing yum.conf in $vserver from ${templates}/yum" sed -e "s!@YUMETCDIR@!/etc!g; s!@YUMCACHEDIR@!/var/cache/yum!g; s!@YUMLOGDIR@!/var/log!g; s!@YUMLOCKDIR@!/var/lock!g; - " yum/yum.conf > /vservers/$vserver/etc/yum.conf + " ${templates}/yum/yum.conf > /vservers/$vserver/etc/yum.conf # post process the various @...@ variables from this yum.conf file. else echo "Using $fcdistro default for yum.conf" fi - if [ -d yum.repos.d ] ; then - echo "Initializing yum.repos.d in $vserver from $(pwd)/yum.repos.d" + if [ -d ${templates}/yum.repos.d ] ; then + echo "Initializing yum.repos.d in $vserver from ${templates}/yum.repos.d" rm -rf /vservers/$vserver/etc/yum.repos.d - tar cf - yum.repos.d | tar -C /vservers/$vserver/etc -xvf - + tar -C ${templates} -cf - yum.repos.d | tar -C /vservers/$vserver/etc -xvf - else echo "Cannot initialize yum.repos.d in $vserver" fi - if [ -n "$MYPLC_MODE" ] ; then + # for using vtest-init-vserver.sh as a general-purpose vserver creation wrapper + # just mention 'none' as the repo url + if [ -n "$MYPLC_MODE" -a "$REPO_URL" != "none" ] ; then if [ ! -d /vservers/$vserver/etc/yum.repos.d ] ; then echo "WARNING : cannot create myplc repo" else # exclude kernel from fedora repos - for i in /vservers/$vserver/etc/yum.repos.d/* ; do - [ -f $i ] && echo "exclude=kernel* ulogd iptables" >> $i + yumexclude=$(pl_plcyumexclude $fcdistro $pldistro $DIRNAME) + for repo in /vservers/$vserver/etc/yum.repos.d/* ; do + [ -f $repo ] && yumconf_exclude $repo "exclude=$yumexclude" done # the build repo is not signed at this stage cat > /vservers/$vserver/etc/yum.repos.d/myplc.repo < *before* populating it +function almost_empty () { + dir="$1"; shift ; + # non existing is fine + [ ! -d $dir ] && return 0; + # need to have at most one file + count=$(cd $dir; ls | wc -l); [ $count -le 1 ]; +} + function setup_vserver () { set -x @@ -78,66 +135,174 @@ function setup_vserver () { vserver=$1; shift fcdistro=$1; shift + pldistro=$1; shift personality=$1; shift - if [ -d /vservers/$vserver ] ; then + # check that this is a new one - see above + almost_empty /vservers/$vserver || { echo "$COMMAND : vserver $vserver seems to exist - bailing out" exit 1 - fi + } + + pkg_method=$(package_method $fcdistro) + case $pkg_method in + yum) + build_options="-m yum -- -d $fcdistro" + ;; + debootstrap) + arch=$(canonical_arch $personality $fcdistro) + debmirror=$(debian_mirror $fcdistro) + build_options="-m debootstrap -- -d $fcdistro -m $debmirror -- --arch $arch" + ;; + *) + build_options="undefined-package_method" ;; + esac # create it # try to work around the vserver issue: # vc_ctx_migrate: No such process # rpm-fake.so: failed to initialize communication with resolver - for i in 1 2 3 4 5 ; do - $personality vserver $VERBOSE $vserver build $VSERVER_OPTIONS -m yum -- -d $fcdistro && break || true - echo "Waiting for one minute" - sleep 60 + for i in $(seq 20) ; do + $personality vserver $VERBOSE $vserver build $VSERVER_OPTIONS $build_options && break || true + echo "* ${i}-th attempt to 'vserver build' failed - waiting for 3 seconds" + sleep 3 done - # check success - [ -d /vservers/$vserver ] + # check success - not enough to check for the directory, let's assume /etc/ in image + [ -d /vservers/$vserver/etc ] if [ ! -z "$personality" ] ; then - registered_personality=$(grep $personality /etc/vservers/$vserver/personality | wc -l) + if [ -f "/etc/vservers/$vserver/personality" ] ; then + registered_personality=$(grep $personality /etc/vservers/$vserver/personality | wc -l) + else + registered_personality=0 + fi if [ $registered_personality -eq 0 -a "$personality" != "linux64" ] ; then echo $personality >> /etc/vservers/$vserver/personality fi fi + BCAPFILE=/etc/vservers/$vserver/bcapabilities + touch $BCAPFILE if [ -n "$VBUILD_MODE" ] ; then ### capabilities required for a build vserver # set up appropriate vserver capabilities to mount, mknod and IPC_LOCK - BCAPFILE=/etc/vservers/$vserver/bcapabilities - touch $BCAPFILE - cap=$(grep ^CAP_SYS_ADMIN /etc/vservers/$vserver/bcapabilities | wc -l) - [ $cap -eq 0 ] && echo 'CAP_SYS_ADMIN' >> /etc/vservers/$vserver/bcapabilities - cap=$(grep ^CAP_MKNOD /etc/vservers/$vserver/bcapabilities | wc -l) - [ $cap -eq 0 ] && echo 'CAP_MKNOD' >> /etc/vservers/$vserver/bcapabilities - cap=$(grep ^CAP_IPC_LOCK /etc/vservers/$vserver/bcapabilities | wc -l) - [ $cap -eq 0 ] && echo 'CAP_IPC_LOCK' >> /etc/vservers/$vserver/bcapabilities + grep -q ^CAP_SYS_ADMIN $BCAPFILE || echo CAP_SYS_ADMIN >> $BCAPFILE + grep -q ^CAP_MKNOD $BCAPFILE || echo CAP_MKNOD >> $BCAPFILE + grep -q ^CAP_IPC_LOCK $BCAPFILE || echo CAP_IPC_LOCK >> $BCAPFILE + # useful for f16 guests that use set_cap_file + grep -q ^CAP_SETFCAP $BCAPFILE || echo CAP_SETFCAP >> $BCAPFILE else ### capabilities required for a myplc vserver # for /etc/plc.d/gpg - need to init /dev/random - cap=$(grep ^CAP_MKNOD /etc/vservers/$vserver/bcapabilities | wc -l) - [ $cap -eq 0 ] && echo 'CAP_MKNOD' >> /etc/vservers/$vserver/bcapabilities + grep -q ^CAP_MKNOD $BCAPFILE || echo CAP_MKNOD >> $BCAPFILE + grep -q ^CAP_NET_BIND_SERVICE $BCAPFILE || echo CAP_NET_BIND_SERVICE >> $BCAPFILE + # useful for f16 guests that use set_cap_file + grep -q ^CAP_SETFCAP $BCAPFILE || echo CAP_SETFCAP >> $BCAPFILE fi - $personality vyum $vserver -- -y install yum - $personality vserver $VERBOSE $vserver pkgmgmt internalize + # Set persistent for the network context + # Thierry: Daniel's kernels come with single_ip turned off by default, let's make this explicit + echo "persistent,lback_allow,~single_ip" > /etc/vservers/$vserver/nflags + + # Set cflags + echo -e "persistent\n~info_init" > /etc/vservers/$vserver/cflags + + # Enable cgroup + mkdir /etc/vservers/$vserver/cgroup + + # Set the init style of your vserver to plain for f16 and higher + # not working with f16 anyways, systemd requires 2.6.36 to work + case $fcdistro in + f1[5-9]) echo plain > /etc/vservers/$vserver/apps/init/style ;; + esac + + if [ "$pkg_method" = "yum" ] ; then + $personality vyum $vserver -- -y install yum + # ditto + for i in $(seq 20) ; do + $personality vserver $VERBOSE $vserver pkgmgmt internalize && break || true + echo "* ${i}-th attempt to 'vserver pkgmgmt internalize' failed - waiting for 3 seconds" + sleep 3 + done + fi + + # turns out that with wheezy at least, at this point we're getting + # /vservers//var/run -> /run + # /vservers//var/lock -> /run/lock + # trying to fix this with relative links does not appear to work fine + # when trying to vserver start we're then getting + # + exec /usr/sbin/vspace --mount --fs --new -- /usr/sbin/vserver ----nonamespace debuild09 start + # fakerunlevel: open("/var/run/utmp"): No such file or directory + # so instead we bluntly create empty dirs and hope for the best +# if [ "$pkg_method" = "debootstrap" ] ; then + [ -h /vservers/$vserver/var/run ] && [ ! -d /vservers/$vserver/var/run ] && \ +# { rm -f /vservers/$vserver/var/run ; ln -s ../run /vservers/$vserver/var/run ; } + { rm -f /vservers/$vserver/var/run ; mkdir /vservers/$vserver/var/run ; } + [ -h /vservers/$vserver/var/lock ] && [ ! -d /vservers/$vserver/var/lock ] && \ +# { rm -f /vservers/$vserver/var/lock ; ln -s ../run/lock /vservers/$vserver/var/lock ; } + { rm -f /vservers/$vserver/var/lock ; mkdir /vservers/$vserver/var/lock ; } +# fi # start the vserver so we can do the following operations - $personality vserver $VERBOSE $vserver start - $personality vserver $VERBOSE $vserver exec sh -c "rm -f /var/lib/rpm/__db*" - $personality vserver $VERBOSE $vserver exec rpm --rebuilddb + # redirect out/err to protect against the vserver's init sequence getting stalled + # mostly used for f10 vservers created remotely through ssh + # with ubuntu/raring, somehow this fails, so ignore retcod, + # as subsequent vserver exec will fail anyway + $personality vserver $VERBOSE $vserver start >& /dev/null || : + + if [ "$pkg_method" == "yum" ] ; then + $personality vserver $VERBOSE $vserver exec sh -c "rm -f /var/lib/rpm/__db*" + + # run the host rpmdb_dump and restore with the guest rpmdb_load + function translate_rpm_hashes () { + set -x + set -e + local personality="$1"; shift + local vserver="$1"; shift + # need to have utilities installed + type -p file + type -p awk + type -p cut + guest_dir=/var/lib/rpm + host_dir=/vservers/$vserver/$guest_dir + files=$(cd $host_dir ; file * | grep Hash | cut -d: -f 1) + for file in $files; do + (cd $host_dir && mv $file ${file}-foreign) + /usr/lib/rpm/rpmdb_dump $host_dir/${file}-foreign | $personality vserver $VERBOSE $vserver exec /usr/lib/rpm/rpmdb_load $guest_dir/$file + done + $personality vserver $VERBOSE $vserver exec rpm --rebuilddb + return 0 + } + + # try the simple way, if that fails try to cross fix the rpm hashes + $personality vserver $VERBOSE $vserver exec rpm --rebuilddb || translate_rpm_hashes $personality $vserver + + elif [ "$pkg_method" == "debootstrap" ] ; then + # just check the vm is running + $personality vserver $VERBOSE $vserver exec arch + fi + + # check if the vserver kernel is using VSERVER_DEVICE (vdevmap) support + need_vdevmap=$(grep "CONFIG_VSERVER_DEVICE=y" /boot/config-$(uname -r) | wc -l) + if [ $need_vdevmap -eq 1 ] ; then + ctx=$(cat /etc/vservers/$vserver/context) + vdevmap --set --xid $ctx --open --create --target /dev/null + vdevmap --set --xid $ctx --open --create --target /dev/root + fi + # minimal config in the vserver for yum to work - configure_yum_in_vserver $vserver $fcdistro + [ "$pkg_method" = "yum" ] && configure_yum_in_vserver $vserver $fcdistro $pldistro # set up resolv.conf cp /etc/resolv.conf /vservers/$vserver/etc/resolv.conf + cp /etc/resolv.conf /vservers/$vserver/etc/resolv.conf.preserve + # and /etc/hosts for at least localhost + [ -f /vservers/$vserver/etc/hosts ] || echo "127.0.0.1 localhost localhost.localdomain" > /vservers/$vserver/etc/hosts + } -function devel_tools () { +function devel_or_vtest_tools () { set -x set -e @@ -148,20 +313,70 @@ function devel_tools () { pldistro=$1; shift personality=$1; shift - # check for .pkgs file based on pldistro - if [ -n "$VBUILD_MODE" ] ; then - pkgsname=devel.pkgs - else - pkgsname=vtest.pkgs - fi - pkgsfile=$(pl_locateDistroFile $DIRNAME $pldistro $pkgsname) + pkg_method=$(package_method $fcdistro) + + pkgsfile=$(pl_locateDistroFile $DIRNAME $pldistro $PREINSTALLED) - # install individual packages, then groups - packages=$(pl_getPackages ${fcdistro} $pkgsfile) - groups=$(pl_getGroups ${fcdistro} $pkgsfile) + ### install individual packages, then groups + # get target arch - use uname -i here (we want either x86_64 or i386) + vserver_arch=$($personality vserver $vserver exec uname -i) + # on debian systems we get arch through the 'arch' command + [ "$vserver_arch" = "unknown" ] && vserver_arch=$($personality vserver $vserver exec arch) + + packages=$(pl_getPackages -a $vserver_arch $fcdistro $pldistro $pkgsfile) + groups=$(pl_getGroups -a $vserver_arch $fcdistro $pldistro $pkgsfile) + + case "$pkg_method" in + yum) + [ -n "$packages" ] && $personality vserver $vserver exec yum -y install $packages + for group_plus in $groups; do + group=$(echo $group_plus | sed -e "s,+++, ,g") + $personality vserver $vserver exec yum -y groupinstall "$group" + done + # store current rpm list in /init-vserver.rpms in case we need to check the contents + $personality vserver $vserver exec rpm -aq > /vservers/$vserver/init-vserver.rpms + ;; + debootstrap) + # for ubuntu + if grep -iq ubuntu /vservers/$vserver/etc/lsb-release 2> /dev/null; then + # on ubuntu, at this point we end up with a single feed in /etc/apt/sources.list + # we need at least to add the 'universe' feed for python-rpm + ( cd /vservers/$vserver/etc/apt ; head -1 sources.list | sed -e s,main,universe, > sources.list.d/universe.list ) + # also adding a link to updates sounds about right + ( cd /vservers/$vserver/etc/apt ; head -1 sources.list | sed -e 's, main,-updates main,' > sources.list.d/updates.list ) + fi + $personality vserver $vserver exec apt-get update + # ignore result because that one failed on precise +sc $personality vserver $vserver exec apt-get -y upgrade ||: + # handle this one firt off to be sure; mostly cosmetic but avoid a huge amount of warnings + $personality vserver $vserver exec apt-get install -y locales + $personality vserver $vserver exec locale-gen en_US.UTF-8 + # install required packages + # all in a single batch + [ -n "$packages" ] && $personality vserver $vserver exec apt-get install -y --ignore-missing $packages || : + # of course, on ubuntu apt-get --ignore-missing .. does not ignore missing packages ! + # check it up a bit + for package in $packages ; do + if $personality vserver $vserver exec dpkg -l $package >& /dev/null ; then + echo "==========(debian) package $package OK (1)" + else + # try to install it individually - so this is for ubuntu + $personality vserver $vserver exec apt-get install -y $package || : + # still not there ? + if $personality vserver $vserver exec dpkg -l $package >& /dev/null ; then + echo "==========(debian) package $package OK (2)" + else + echo "==========(debian) package $package MISSING - ignored" + fi + fi + done + ### xxx todo install groups with apt.. + ;; + *) + echo "unknown pkg_method $pkg_method" + ;; + esac - [ -n "$packages" ] && $personality vserver $vserver exec yum -y install $packages - [ -n "$groups" ] && $personality vserver $vserver exec yum -y groupinstall $groups return 0 } @@ -171,6 +386,9 @@ function post_install () { else post_install_myplc "$@" fi + # setup localtime from the host + vserver=$1; shift + cp /etc/localtime /vservers/$vserver/etc/localtime } function post_install_vbuild () { @@ -191,7 +409,7 @@ function post_install_vbuild () { done # create symlink for /dev/fd - ln -fs /proc/self/fd /dev/fd + [ ! -e "/dev/fd" ] && ln -s /proc/self/fd /dev/fd # modify /etc/rpm/macros to not use /sbin/new-kernel-pkg sed -i 's,/sbin/new-kernel-pkg:,,' /etc/rpm/macros @@ -244,6 +462,18 @@ function post_install_myplc () { # be careful to backslash $ in this, otherwise it's the root context that's going to do the evaluation cat << EOF | $personality vserver $VERBOSE $vserver exec bash -x + # create /etc/sysconfig/network if missing + [ -f /etc/sysconfig/network ] || echo NETWORKING=yes > /etc/sysconfig/network + + # create symlink for /dev/fd + [ ! -e "/dev/fd" ] && ln -s /proc/self/fd /dev/fd + + # turn off regular crond, as plc invokes plc_crond + chkconfig crond off + + # take care of loginuid in /etc/pam.d + sed -i "s,#*\(.*loginuid.*\),#\1," /etc/pam.d/* + # customize root's prompt cat << PROFILE > /root/.profile export PS1="[$vserver] \\w # " @@ -252,8 +482,34 @@ PROFILE EOF } -COMMAND_VBUILD="vbuild-init-vserver.sh" -COMMAND_MYPLC="vtest-init-vserver.sh" +# parses ifconfig's output to find out ip address and mask +# will then be passed to vserver as e.g. --interface 138.96.250.126/255.255.0.0 +# default is to use lo, that's enough for local mirrors +# use -i eth0 in case your fedora mirror is on a separate box on the network +function vserverIfconfig () { + ifname=$1; shift + local result="" + line=$(ifconfig $ifname 2> /dev/null | grep 'inet addr') + if [ -n "$line" ] ; then + set $line + for word in "$@" ; do + addr=$(echo $word | sed -e s,[aA][dD][dD][rR]:,,) + mask=$(echo $word | sed -e s,[mM][aA][sS][kK]:,,) + if [ "$word" != "$addr" ] ; then + result="${addr}" + elif [ "$word" != "$mask" ] ; then + result="${result}/${mask}" + fi + done + fi + if [ -z "$result" ] ; then + echo "vserverIfconfig failed to locate $ifname" + exit 1 + else + echo $result + fi +} + function usage () { set +x echo "Usage: $COMMAND_VBUILD [options] vserver-name [ -- vserver-options ]" @@ -266,10 +522,14 @@ function usage () { echo " -f fcdistro - for creating the root filesystem - defaults to $DEFAULT_FCDISTRO" echo " -d pldistro - defaults to $DEFAULT_PLDISTRO" echo " -p personality - defaults to $DEFAULT_PERSONALITY" + echo " -i ifname: determines ip and netmask attached to ifname, and passes it to the vserver" + echo " -r : set apps/init/mark to default so the vserver restart upon reboot" echo " -v : verbose - passes -v to calls to vserver" echo "vserver-options" echo " all args after the optional -- are passed to vserver build " echo " typical usage is e.g. --interface eth0:200.150.100.10/24" + echo "With $COMMAND_MYPLC you can give 'none' as the URL, in which case" + echo " myplc.repo does not get created" exit 1 } @@ -289,11 +549,24 @@ function main () { esac VERBOSE= - while getopts "f:d:p:v" opt ; do + RESISTANT="" + IFNAME="" + VSERVER_OPTIONS="" + + # the set of preinstalled packages - depends on vbuild or vtest + if [ -n "$VBUILD_MODE" ] ; then + PREINSTALLED=devel.pkgs + else + PREINSTALLED=vtest.pkgs + fi + while getopts "f:d:p:P:i:rv" opt ; do case $opt in f) fcdistro=$OPTARG;; d) pldistro=$OPTARG;; p) personality=$OPTARG;; + P) PREINSTALLED=$OPTARG;; + i) IFNAME=$OPTARG;; + r) RESISTANT="true";; v) VERBOSE="-v" ;; *) usage ;; esac @@ -319,14 +592,27 @@ function main () { fi fi + # with new util-vserver, it is mandatory to provide an IP even for building + if [ -n "$VBUILD_MODE" ] ; then + [ -z "$IFNAME" ] && IFNAME=$DEFAULT_IFNAME + fi + if [ -n "$IFNAME" ] ; then + localip=$(vserverIfconfig $IFNAME) + VSERVER_OPTIONS="$VSERVER_OPTIONS --interface $localip" + fi + [ -z "$fcdistro" ] && fcdistro=$DEFAULT_FCDISTRO [ -z "$pldistro" ] && pldistro=$DEFAULT_PLDISTRO [ -z "$personality" ] && personality=$DEFAULT_PERSONALITY - setup_vserver $vserver $fcdistro $personality - devel_tools $vserver $fcdistro $pldistro $personality + setup_vserver $vserver $fcdistro $pldistro $personality + devel_or_vtest_tools $vserver $fcdistro $pldistro $personality post_install $vserver $personality + # Start Vserver automatically on boot + [ -n "$RESISTANt" ] && echo "default" > /etc/vservers/$vserver/apps/init/mark + + echo $COMMAND Done } main "$@"