1 use std
::collections
::HashMap
;
3 use std
::hash
::BuildHasher
;
4 use std
::os
::unix
::io
::AsRawFd
;
5 use std
::path
::{Path, PathBuf}
;
8 use anyhow
::{bail, format_err, Error}
;
9 use futures
::future
::FutureExt
;
11 use futures
::stream
::{StreamExt, TryStreamExt}
;
12 use nix
::unistd
::{fork, ForkResult}
;
13 use serde_json
::Value
;
14 use tokio
::signal
::unix
::{signal, SignalKind}
;
16 use proxmox
::{sortable, identity}
;
17 use proxmox
::api
::{ApiHandler, ApiMethod, RpcEnvironment, schema::*, cli::*}
;
18 use proxmox
::tools
::fd
::Fd
;
20 use pbs_tools
::crypt_config
::CryptConfig
;
21 use pbs_config
::key_config
::load_and_decrypt_key
;
22 use pbs_datastore
::{BackupDir, BackupGroup, }
;
23 use pbs_datastore
::index
::IndexFile
;
24 use pbs_datastore
::dynamic_index
::BufferedDynamicReader
;
25 use pbs_datastore
::cached_chunk_reader
::CachedChunkReader
;
26 use pbs_client
::tools
::key_source
::get_encryption_key_password
;
27 use pbs_client
::{BackupReader, RemoteChunkReader}
;
28 use pbs_tools
::json
::required_string_param
;
32 extract_repository_from_value
,
33 complete_pxar_archive_name
,
34 complete_img_archive_name
,
35 complete_group_or_snapshot
,
39 api_datastore_latest_snapshot
,
40 BufferedDynamicReadAt
,
44 const API_METHOD_MOUNT
: ApiMethod
= ApiMethod
::new(
45 &ApiHandler
::Sync(&mount
),
47 "Mount pxar archive.",
49 ("snapshot", false, &StringSchema
::new("Group/Snapshot path.").schema()),
50 ("archive-name", false, &StringSchema
::new("Backup archive name.").schema()),
51 ("target", false, &StringSchema
::new("Target directory path.").schema()),
52 ("repository", true, &REPO_URL_SCHEMA
),
53 ("keyfile", true, &StringSchema
::new("Path to encryption key.").schema()),
54 ("verbose", true, &BooleanSchema
::new("Verbose output and stay in foreground.").default(false).schema()),
60 const API_METHOD_MAP
: ApiMethod
= ApiMethod
::new(
61 &ApiHandler
::Sync(&mount
),
63 "Map a drive image from a VM backup to a local loopback device. Use 'unmap' to undo.
64 WARNING: Only do this with *trusted* backups!",
66 ("snapshot", false, &StringSchema
::new("Group/Snapshot path.").schema()),
67 ("archive-name", false, &StringSchema
::new("Backup archive name.").schema()),
68 ("repository", true, &REPO_URL_SCHEMA
),
69 ("keyfile", true, &StringSchema
::new("Path to encryption key.").schema()),
70 ("verbose", true, &BooleanSchema
::new("Verbose output and stay in foreground.").default(false).schema()),
76 const API_METHOD_UNMAP
: ApiMethod
= ApiMethod
::new(
77 &ApiHandler
::Sync(&unmap
),
79 "Unmap a loop device mapped with 'map' and release all resources.",
81 ("name", true, &StringSchema
::new(
82 concat
!("Archive name, path to loopdev (/dev/loopX) or loop device number. ",
83 "Omit to list all current mappings and force cleaning up leftover instances.")
89 pub fn mount_cmd_def() -> CliCommand
{
91 CliCommand
::new(&API_METHOD_MOUNT
)
92 .arg_param(&["snapshot", "archive-name", "target"])
93 .completion_cb("repository", complete_repository
)
94 .completion_cb("snapshot", complete_group_or_snapshot
)
95 .completion_cb("archive-name", complete_pxar_archive_name
)
96 .completion_cb("target", pbs_tools
::fs
::complete_file_name
)
99 pub fn map_cmd_def() -> CliCommand
{
101 CliCommand
::new(&API_METHOD_MAP
)
102 .arg_param(&["snapshot", "archive-name"])
103 .completion_cb("repository", complete_repository
)
104 .completion_cb("snapshot", complete_group_or_snapshot
)
105 .completion_cb("archive-name", complete_img_archive_name
)
108 pub fn unmap_cmd_def() -> CliCommand
{
110 CliCommand
::new(&API_METHOD_UNMAP
)
111 .arg_param(&["name"])
112 .completion_cb("name", complete_mapping_names
)
115 fn complete_mapping_names
<S
: BuildHasher
>(_arg
: &str, _param
: &HashMap
<String
, String
, S
>)
118 match pbs_fuse_loop
::find_all_mappings() {
119 Ok(mappings
) => mappings
120 .filter_map(|(name
, _
)| {
121 proxmox_systemd
::unescape_unit(&name
).ok()
130 _rpcenv
: &mut dyn RpcEnvironment
,
131 ) -> Result
<Value
, Error
> {
133 let verbose
= param
["verbose"].as_bool().unwrap_or(false);
135 // This will stay in foreground with debug output enabled as None is
136 // passed for the RawFd.
137 return pbs_runtime
::main(mount_do(param
, None
));
140 // Process should be daemonized.
141 // Make sure to fork before the async runtime is instantiated to avoid troubles.
142 let (pr
, pw
) = pbs_tools
::io
::pipe()?
;
143 match unsafe { fork() }
{
144 Ok(ForkResult
::Parent { .. }
) => {
146 // Blocks the parent process until we are ready to go in the child
147 let _res
= nix
::unistd
::read(pr
.as_raw_fd(), &mut [0]).unwrap();
150 Ok(ForkResult
::Child
) => {
152 nix
::unistd
::setsid().unwrap();
153 pbs_runtime
::main(mount_do(param
, Some(pw
)))
155 Err(_
) => bail
!("failed to daemonize process"),
159 async
fn mount_do(param
: Value
, pipe
: Option
<Fd
>) -> Result
<Value
, Error
> {
160 let repo
= extract_repository_from_value(¶m
)?
;
161 let archive_name
= required_string_param(¶m
, "archive-name")?
;
162 let client
= connect(&repo
)?
;
164 let target
= param
["target"].as_str();
166 record_repository(&repo
);
168 let path
= required_string_param(¶m
, "snapshot")?
;
169 let (backup_type
, backup_id
, backup_time
) = if path
.matches('
/'
).count() == 1 {
170 let group
: BackupGroup
= path
.parse()?
;
171 api_datastore_latest_snapshot(&client
, repo
.store(), group
).await?
173 let snapshot
: BackupDir
= path
.parse()?
;
174 (snapshot
.group().backup_type().to_owned(), snapshot
.group().backup_id().to_owned(), snapshot
.backup_time())
177 let keyfile
= param
["keyfile"].as_str().map(PathBuf
::from
);
178 let crypt_config
= match keyfile
{
181 println
!("Encryption key file: '{:?}'", path
);
182 let (key
, _
, fingerprint
) = load_and_decrypt_key(&path
, &get_encryption_key_password
)?
;
183 println
!("Encryption key fingerprint: '{}'", fingerprint
);
184 Some(Arc
::new(CryptConfig
::new(key
)?
))
188 let server_archive_name
= if archive_name
.ends_with(".pxar") {
189 if target
.is_none() {
190 bail
!("use the 'mount' command to mount pxar archives");
192 format
!("{}.didx", archive_name
)
193 } else if archive_name
.ends_with(".img") {
194 if target
.is_some() {
195 bail
!("use the 'map' command to map drive images");
197 format
!("{}.fidx", archive_name
)
199 bail
!("Can only mount/map pxar archives and drive images.");
202 let client
= BackupReader
::start(
204 crypt_config
.clone(),
212 let (manifest
, _
) = client
.download_manifest().await?
;
213 manifest
.check_fingerprint(crypt_config
.as_ref().map(Arc
::as_ref
))?
;
215 let file_info
= manifest
.lookup_file_info(&server_archive_name
)?
;
217 let daemonize
= || -> Result
<(), Error
> {
218 if let Some(pipe
) = pipe
{
219 nix
::unistd
::chdir(Path
::new("/")).unwrap();
220 // Finish creation of daemon by redirecting filedescriptors.
221 let nullfd
= nix
::fcntl
::open(
223 nix
::fcntl
::OFlag
::O_RDWR
,
224 nix
::sys
::stat
::Mode
::empty(),
226 nix
::unistd
::dup2(nullfd
, 0).unwrap();
227 nix
::unistd
::dup2(nullfd
, 1).unwrap();
228 nix
::unistd
::dup2(nullfd
, 2).unwrap();
230 nix
::unistd
::close(nullfd
).unwrap();
232 // Signal the parent process that we are done with the setup and it can
234 nix
::unistd
::write(pipe
.as_raw_fd(), &[0u8])?
;
241 let options
= OsStr
::new("ro,default_permissions");
243 // handle SIGINT and SIGTERM
244 let mut interrupt_int
= signal(SignalKind
::interrupt())?
;
245 let mut interrupt_term
= signal(SignalKind
::terminate())?
;
247 let mut interrupt
= futures
::future
::select(interrupt_int
.recv().boxed(), interrupt_term
.recv().boxed());
249 if server_archive_name
.ends_with(".didx") {
250 let index
= client
.download_dynamic_index(&manifest
, &server_archive_name
).await?
;
251 let most_used
= index
.find_most_used_chunks(8);
252 let chunk_reader
= RemoteChunkReader
::new(client
.clone(), crypt_config
, file_info
.chunk_crypt_mode(), most_used
);
253 let reader
= BufferedDynamicReader
::new(index
, chunk_reader
);
254 let archive_size
= reader
.archive_size();
255 let reader
: pbs_client
::pxar
::fuse
::Reader
=
256 Arc
::new(BufferedDynamicReadAt
::new(reader
));
257 let decoder
= pbs_client
::pxar
::fuse
::Accessor
::new(reader
, archive_size
).await?
;
259 let session
= pbs_client
::pxar
::fuse
::Session
::mount(
263 Path
::new(target
.unwrap()),
265 .map_err(|err
| format_err
!("pxar mount failed: {}", err
))?
;
270 res
= session
.fuse() => res?
,
272 // exit on interrupted
275 } else if server_archive_name
.ends_with(".fidx") {
276 let index
= client
.download_fixed_index(&manifest
, &server_archive_name
).await?
;
277 let size
= index
.index_bytes();
278 let chunk_reader
= RemoteChunkReader
::new(client
.clone(), crypt_config
, file_info
.chunk_crypt_mode(), HashMap
::new());
279 let reader
= CachedChunkReader
::new(chunk_reader
, index
, 8).seekable();
281 let name
= &format
!("{}:{}/{}", repo
.to_string(), path
, archive_name
);
282 let name_escaped
= proxmox_systemd
::escape_unit(name
, false);
284 let mut session
= pbs_fuse_loop
::FuseLoopSession
::map_loop(size
, reader
, &name_escaped
, options
).await?
;
285 let loopdev
= session
.loopdev_path
.clone();
287 let (st_send
, st_recv
) = futures
::channel
::mpsc
::channel(1);
288 let (mut abort_send
, abort_recv
) = futures
::channel
::mpsc
::channel(1);
289 let mut st_recv
= st_recv
.fuse();
290 let mut session_fut
= session
.main(st_send
, abort_recv
).boxed().fuse();
292 // poll until loop file is mapped (or errors)
294 _res
= session_fut
=> {
295 bail
!("FUSE session unexpectedly ended before loop file mapping");
297 res
= st_recv
.try_next() => {
298 if let Err(err
) = res
{
299 // init went wrong, abort now
300 abort_send
.try_send(()).map_err(|err
|
301 format_err
!("error while sending abort signal - {}", err
))?
;
302 // ignore and keep original error cause
303 let _
= session_fut
.await
;
309 // daemonize only now to be able to print mapped loopdev or startup errors
310 println
!("Image '{}' mapped on {}", name
, loopdev
);
313 // continue polling until complete or interrupted (which also happens on unmap)
315 res
= session_fut
=> res?
,
317 // exit on interrupted
318 abort_send
.try_send(()).map_err(|err
|
319 format_err
!("error while sending abort signal - {}", err
))?
;
324 println
!("Image unmapped");
326 bail
!("unknown archive file extension (expected .pxar or .img)");
335 _rpcenv
: &mut dyn RpcEnvironment
,
336 ) -> Result
<Value
, Error
> {
338 let mut name
= match param
["name"].as_str() {
339 Some(name
) => name
.to_owned(),
341 pbs_fuse_loop
::cleanup_unused_run_files(None
);
343 for (backing
, loopdev
) in pbs_fuse_loop
::find_all_mappings()?
{
344 let name
= proxmox_systemd
::unescape_unit(&backing
)?
;
345 println
!("{}:\t{}", loopdev
.unwrap_or_else(|| "(unmapped)".to_string()), name
);
349 println
!("Nothing mapped.");
351 return Ok(Value
::Null
);
355 // allow loop device number alone
356 if let Ok(num
) = name
.parse
::<u8>() {
357 name
= format
!("/dev/loop{}", num
);
360 if name
.starts_with("/dev/loop") {
361 pbs_fuse_loop
::unmap_loopdev(name
)?
;
363 let name
= proxmox_systemd
::escape_unit(&name
, false);
364 pbs_fuse_loop
::unmap_name(name
)?
;