]>
git.proxmox.com Git - aab.git/blob - PVE/AAB.pm
c5e5bea669f8e0f993bfea4b151324bb455e1248
14 my @BASE_PACKAGES = qw(base openssh);
15 my @BASE_EXCLUDES = qw(e2fsprogs
25 my $PKGDIR = "/var/cache/pacman/pkg";
27 my ($aablibdir, $fake_init);
29 sub setup_defaults
($) {
32 $fake_init = "$aablibdir/scripts/init.bash";
35 setup_defaults
('/usr/lib/aab');
38 my ($data, $file, $perm) = @_;
40 die "no filename" if !$file;
43 my $fh = IO
::File-
>new ($file, O_WRONLY
| O_CREAT
, $perm) ||
44 die "unable to open file '$file'";
52 copy
($a, $b) or die "failed to copy $a => $b: $!";
57 rename($a, $b) or die "failed to rename $a => $b: $!";
62 symlink($a, $b) or die "failed to symlink $a => $b: $!";
73 my $fd = $self->{logfd
};
82 my $fh = IO
::File-
>new ("<$filename") || return $res;
85 while (defined (my $line = <$fh>)) {
86 next if $line =~ m/^\#/;
87 next if $line =~ m/^\s*$/;
97 if ($rec =~ s/^Description:\s*([^\n]*)(\n\s+.*)*$//si) {
98 $res->{headline
} = $1;
99 chomp $res->{headline
};
102 $res->{description
} = $long;
103 chomp $res->{description
};
104 } elsif ($rec =~ s/^([^:]+):\s*(.*\S)\s*\n//) {
105 my ($key, $value) = (lc ($1), $2);
106 if ($key eq 'source' || $key eq 'mirror') {
107 push @{$res->{$key}}, $value;
109 die "duplicate key '$key'\n" if defined ($res->{$key});
110 $res->{$key} = $value;
113 die "unable to parse config file: $rec";
117 die "unable to parse config file" if $rec;
123 my ($class, $config) = @_;
125 $config = read_config
('aab.conf') if !$config;
126 my $version = $config->{version
};
127 die "no 'version' specified\n" if !$version;
128 die "no 'section' specified\n" if !$config->{section
};
129 die "no 'description' specified\n" if !$config->{headline
};
130 die "no 'maintainer' specified\n" if !$config->{maintainer
};
132 my $name = $config->{name
} || die "no 'name' specified\n";
133 $name =~ m/^[a-z][0-9a-z\-\*\.]+$/ ||
134 die "illegal characters in name '$name'\n";
137 if ($name =~ m/^archlinux/) {
138 $targetname = "${name}_${version}_$config->{architecture}";
140 $targetname = "archlinux-${name}_${version}_$config->{architecture}";
143 my $self = { logfile
=> 'logfile',
145 targetname
=> $targetname,
146 incl
=> [@BASE_PACKAGES],
147 excl
=> [@BASE_EXCLUDES],
150 $self->{logfd
} = IO
::File-
>new($self->{logfile
}, O_WRONLY
| O_APPEND
| O_CREAT
)
151 or die "unable to open log file";
155 $self->__allocate_ve();
160 sub __sample_config
{
163 my $arch = $self->{config
}->{architecture
};
167 lxc.include = /usr/share/lxc/config/archlinux.common.conf
168 lxc.utsname = localhost
169 lxc.rootfs = $self->{rootfs}
170 lxc.mount.entry = $self->{pkgcache} $self->{pkgdir} none bind 0 0
178 if (my $fd = IO
::File-
>new(".veid")) {
185 $self->{working_dir
} = getcwd
;
186 $self->{veconffile
} = "$self->{working_dir}/config";
187 $self->{rootfs
} = "$self->{working_dir}/rootfs";
188 $self->{pkgdir
} = "$self->{working_dir}/rootfs/$PKGDIR";
189 $self->{pkgcache
} = "$self->{working_dir}/pkgcache";
190 $self->{'pacman.conf'} = "$self->{working_dir}/pacman.conf";
193 $self->{veid
} = $cid;
199 UUID
::generate
($uuid);
200 UUID
::unparse
($uuid, $uuid_str);
201 $self->{veid
} = $uuid_str;
203 my $fd = IO
::File-
>new (">.veid") ||
204 die "unable to write '.veid'\n";
205 print $fd "$self->{veid}\n";
207 $self->logmsg("allocated VE $self->{veid}\n");
213 my $config = $self->{config
};
215 $self->{logfd
} = IO
::File-
>new($self->{logfile
}, O_WRONLY
| O_TRUNC
| O_CREAT
)
216 or die "unable to open log file";
218 my $cdata = $self->__sample_config();
220 my $fh = IO
::File-
>new($self->{veconffile
}, O_WRONLY
|O_CREAT
|O_EXCL
) ||
221 die "unable to write lxc config file '$self->{veconffile}' - $!";
225 if (!$config->{source
} && !$config->{mirror
}) {
226 die "no sources/mirrors specified";
229 $config->{source
} //= [];
230 $config->{mirror
} //= [];
232 my $servers = "Server = "
233 . join("\nServer = ", @{$config->{source
}}, @{$config->{mirror
}})
236 $fh = IO
::File-
>new($self->{'pacman.conf'}, O_WRONLY
|O_CREAT
|O_EXCL
) ||
237 die "unable to write pacman config file $self->{'pacman.conf'} - $!";
240 HoldPkg = pacman glibc
241 Architecture = $config->{architecture}
253 if ($config->{architecture
} eq 'x86_64') {
254 print $fh "[multilib]\n$servers\n";
257 mkdir $self->{rootfs
} || die "unable to create rootfs - $!";
259 $self->logmsg("configured VE $self->{veid}\n");
265 my $veid = $self->{veid
};
267 my $res = { running
=> 0 };
269 $res->{exist
} = 1 if -d
"$self->{rootfs}/usr";
271 my $filename = "/proc/net/unix";
273 # similar test is used by lcxcontainers.c: list_active_containers
274 my $fh = IO
::File-
>new ($filename, "r");
277 while (defined(my $line = <$fh>)) {
278 if ($line =~ m/^[a-f0-9]+:\s\S+\s\S+\s\S+\s\S+\s\S+\s\d+\s(\S+)$/) {
280 if ($path =~ m!^@/\S+/$veid/command$!) {
293 my $veid = $self->{veid
}; # fixme
295 my $vestat = $self->ve_status();
296 if ($vestat->{running
}) {
297 $self->stop_container();
300 rmtree
$self->{rootfs
};
301 unlink $self->{veconffile
};
308 my $veid = $self->{veid
};
309 my $conffile = $self->{veconffile
};
311 $self->logmsg ("initialize VE $veid\n");
313 my $vestat = $self->ve_status();
314 if ($vestat->{running
}) {
315 $self->run_command ("lxc-stop -n $veid --rcfile $conffile --kill");
318 rmtree
$self->{rootfs
};
319 mkpath
$self->{rootfs
};
323 my ($self, $cmd, $input) = @_;
325 my $veid = $self->{veid
};
326 my $conffile = $self->{veconffile
};
328 if (ref ($cmd) eq 'ARRAY') {
329 unshift @$cmd, 'lxc-attach', '-n', $veid, '--rcfile', $conffile,'--clear-env', '--';
330 $self->run_command ($cmd, $input);
332 $self->run_command ("lxc-attach -n $veid --rcfile $conffile --clear-env -- $cmd", $input);
337 my ($self, @cmd) = @_;
339 my $veid = $self->{veid
};
340 my $conffile = $self->{veconffile
};
343 my $pid = open2
($reader, "<&STDIN", 'lxc-attach', '-n', $veid, '--rcfile', $conffile, '--', @cmd)
344 or die "unable to exec command";
346 while (defined (my $line = <$reader>)) {
347 $self->logmsg ($line);
353 die "ve_exec failed - status $rc\n" if $rc != 0;
357 my ($self, $cmd, $input, $getoutput) = @_;
359 my $reader = IO
::File-
>new();
360 my $writer = IO
::File-
>new();
361 my $error = IO
::File-
>new();
365 my $cmdstr = ref ($cmd) eq 'ARRAY' ?
join (' ', @$cmd) : $cmd;
369 if (ref ($cmd) eq 'ARRAY') {
370 $pid = open3
($writer, $reader, $error, @$cmd) || die $!;
372 $pid = open3
($writer, $reader, $error, $cmdstr) || die $!;
379 if ($orig_pid != $$) {
380 $self->logmsg ("ERROR: command '$cmdstr' failed - fork failed\n");
387 print $writer $input if defined $input;
390 my $select = new IO
::Select
;
391 $select->add ($reader);
392 $select->add ($error);
395 my $logfd = $self->{logfd
};
397 while ($select->count) {
398 my @handles = $select->can_read ();
400 foreach my $h (@handles) {
402 my $count = sysread ($h, $buf, 4096);
403 if (!defined ($count)) {
405 die "command '$cmdstr' failed: $!";
407 $select->remove ($h) if !$count;
411 $res .= $buf if $getoutput;
418 die "command '$cmdstr' failed with exit code $ec\n" if $ec;
423 sub start_container
{
425 my $veid = $self->{veid
};
426 $self->run_command(['lxc-start', '-n', $veid, '-f', $self->{veconffile
}, '/usr/bin/aab_fake_init']);
431 my $veid = $self->{veid
};
432 my $conffile = $self->{veconffile
};
433 $self->run_command ("lxc-stop -n $veid --rcfile $conffile --kill");
438 my $root = $self->{rootfs
};
439 return ('/usr/bin/pacman',
441 '--config', $self->{'pacman.conf'},
442 '--cachedir', $self->{pkgcache
},
447 my ($self, $packages) = @_;
448 my $root = $self->{rootfs
};
450 my @pacman = $self->pacman_command();
451 $self->run_command([@pacman, '-Sw', '--', @$packages]);
455 my ($self, $include, $exclude) = @_;
456 my $root = $self->{rootfs
};
458 my @pacman = $self->pacman_command();
460 print "Fetching package database...\n";
461 mkpath
$self->{pkgcache
};
462 mkpath
$self->{pkgdir
};
463 mkpath
"$root/var/lib/pacman";
464 $self->run_command([@pacman, '-Sy']);
466 print "Figuring out what to install...\n";
467 my $incl = { map { $_ => 1 } @{$self->{incl
}} };
468 my $excl = { map { $_ => 1 } @{$self->{excl
}} };
470 foreach my $addinc (@$include) {
471 $incl->{$addinc} = 1;
472 delete $excl->{$addinc};
474 foreach my $addexc (@$exclude) {
475 $excl->{$addexc} = 1;
476 delete $incl->{$addexc};
481 foreach my $inc (keys %$lst) {
483 eval { $group = $self->run_command([@pacman, '-Sqg', $inc], undef, 1); };
487 $lst->{$_} = 1 foreach split(/\s+/, $group);
495 my $packages = [ grep { !$excl->{$_} } keys %$incl ];
497 print "Setting up basic environment...\n";
499 mkpath
"$root/usr/bin";
501 my $data = "# UNCONFIGURED FSTAB FOR BASE SYSTEM\n";
502 write_file
($data, "$root/etc/fstab", 0644);
504 write_file
("", "$root/etc/resolv.conf", 0644);
505 write_file
("localhost\n", "$root/etc/hostname", 0644);
506 $self->run_command(['install', '-m0755', $fake_init, "$root/usr/bin/aab_fake_init"]);
508 unlink "$root/etc/localtime";
509 symln
'/usr/share/zoneinfo/UTC', "$root/etc/localtime";
511 print "Caching packages...\n";
512 $self->cache_packages($packages);
513 #$self->copy_packages();
515 print "Installing package manager and essentials...\n";
516 # inetutils for 'hostname' for our init
517 $self->run_command([@pacman, '-S', 'pacman', 'inetutils', 'archlinux-keyring']);
519 print "Setting up pacman for installation from cache...\n";
520 my $file = "$root/etc/pacman.d/mirrorlist";
521 my $backup = "${file}.aab_orig";
523 rename_file
($file, $backup);
524 write_file
("Server = file://$PKGDIR\n", $file);
527 print "Populating keyring...\n";
528 $self->populate_keyring();
530 print "Starting container...\n";
531 $self->start_container();
533 print "Installing packages...\n";
534 $self->ve_command(['pacman', '-S', '--needed', '--noconfirm', '--', @$packages]);
537 sub populate_keyring
{
539 my $root = $self->{rootfs
};
541 # devices needed for gnupg to function:
543 '/dev/null' => ['c', '1', '3'],
544 '/dev/random' => ['c', '1', '9'], # fake /dev/random (really urandom)
545 '/dev/urandom' => ['c', '1', '9'],
546 '/dev/tty' => ['c', '5', '0'],
549 my $cleanup_dev = sub {
550 # remove temporary device files
551 unlink "${root}$_" foreach keys %$devs;
553 local $SIG{INT
} = $SIG{TERM
} = $cleanup_dev;
555 # at least /dev/null exists as regular file after installing the filesystem package,
556 # and we want to replace /dev/random, so delete devices first
559 foreach my $dev (keys %$devs) {
560 my ($type, $major, $minor) = @{$devs->{$dev}};
561 system('mknod', "${root}${dev}", $type, $major, $minor);
564 # generate weak master key and populate the keyring
565 system('unshare', '--fork', '--pid', 'chroot', "$root", 'pacman-key', '--init') == 0
566 or die "failed to initialize keyring: $?";
567 system('unshare', '--fork', '--pid', 'chroot', "$root", 'pacman-key', '--populate') == 0
568 or die "failed to populate keyring: $?";
571 # reset to original state
572 system('touch', "$root/dev/null");
576 my ($self, $pkglist) = @_;
578 $self->cache_packages($pkglist);
579 $self->ve_command(['pacman', '-S', '--needed', '--noconfirm', '--', @$pkglist]);
583 my ($self, $filename, $size) = @_;
585 my $config = $self->{config
};
589 $data .= "Name: $config->{name}\n";
590 $data .= "Version: $config->{version}\n";
591 $data .= "Type: lxc\n";
592 $data .= "OS: archlinux\n";
593 $data .= "Section: $config->{section}\n";
594 $data .= "Maintainer: $config->{maintainer}\n";
595 $data .= "Architecture: $config->{architecture}\n";
596 $data .= "Infopage: https://www.archlinux.org\n";
597 $data .= "Installed-Size: $size\n";
600 $data .= "Infopage: $config->{infopage}\n" if $config->{infopage
};
601 $data .= "ManageUrl: $config->{manageurl}\n" if $config->{manageurl
};
602 $data .= "Certified: $config->{certified}\n" if $config->{certified
};
605 $data .= "Description: $config->{headline}\n";
606 $data .= "$config->{description}\n" if $config->{description
};
608 write_file
($data, $filename, 0644);
613 my $rootdir = $self->{rootfs
};
615 print "Stopping container...\n";
616 $self->stop_container();
618 print "Rolling back mirrorlist changes...\n";
619 my $file = "$rootdir/etc/pacman.d/mirrorlist";
621 rename_file
($file.'.aab_orig', $file);
623 print "Removing weak temporary pacman keyring...\n";
624 rmtree
("$rootdir/etc/pacman.d/gnupg");
626 my $sizestr = $self->run_command("du -sm $rootdir", undef, 1);
628 if ($sizestr =~ m/^(\d+)\s+\Q$rootdir\E$/) {
631 die "unable to detect size\n";
633 $self->logmsg ("$size MB\n");
635 $self->write_config ("$rootdir/etc/appliance.info", $size);
637 $self->logmsg ("creating final appliance archive\n");
639 my $target = "$self->{targetname}.tar";
643 $self->run_command ("tar cpf $target --numeric-owner -C '$rootdir' ./etc/appliance.info");
644 $self->run_command ("tar rpf $target --numeric-owner -C '$rootdir' --exclude ./etc/appliance.info .");
645 $self->run_command ("gzip $target");
650 my $veid = $self->{veid
};
651 my $conffile = $self->{veconffile
};
653 my $vestat = $self->ve_status();
654 if (!$vestat->{exist
}) {
655 $self->logmsg ("Please create the appliance first (bootstrap)");
659 if (!$vestat->{running
}) {
660 $self->start_container();
663 system ("lxc-attach -n $veid --rcfile $conffile --clear-env");
667 my ($self, $all) = @_;
669 unlink $self->{logfile
};
670 unlink $self->{'pacman.conf'};
673 rmtree
$self->{pkgcache
} if $all;