1 use std
::path
::PathBuf
;
3 use std
::os
::unix
::io
::RawFd
;
6 use std
::collections
::HashMap
;
7 use std
::hash
::BuildHasher
;
9 use anyhow
::{bail, format_err, Error}
;
10 use serde_json
::Value
;
11 use tokio
::signal
::unix
::{signal, SignalKind}
;
12 use nix
::unistd
::{fork, ForkResult, pipe}
;
14 use futures
::future
::FutureExt
;
15 use futures
::stream
::{StreamExt, TryStreamExt}
;
17 use proxmox
::{sortable, identity}
;
18 use proxmox
::api
::{ApiHandler, ApiMethod, RpcEnvironment, schema::*, cli::*}
;
21 use proxmox_backup
::tools
;
22 use proxmox_backup
::backup
::{
28 BufferedDynamicReader
,
32 use proxmox_backup
::client
::*;
36 extract_repository_from_value
,
37 complete_pxar_archive_name
,
38 complete_img_archive_name
,
39 complete_group_or_snapshot
,
43 api_datastore_latest_snapshot
,
44 BufferedDynamicReadAt
,
48 const API_METHOD_MOUNT
: ApiMethod
= ApiMethod
::new(
49 &ApiHandler
::Sync(&mount
),
51 "Mount pxar archive.",
53 ("snapshot", false, &StringSchema
::new("Group/Snapshot path.").schema()),
54 ("archive-name", false, &StringSchema
::new("Backup archive name.").schema()),
55 ("target", false, &StringSchema
::new("Target directory path.").schema()),
56 ("repository", true, &REPO_URL_SCHEMA
),
57 ("keyfile", true, &StringSchema
::new("Path to encryption key.").schema()),
58 ("verbose", true, &BooleanSchema
::new("Verbose output and stay in foreground.").default(false).schema()),
64 const API_METHOD_MAP
: ApiMethod
= ApiMethod
::new(
65 &ApiHandler
::Sync(&mount
),
67 "Map a drive image from a VM backup to a local loopback device. Use 'unmap' to undo.
68 WARNING: Only do this with *trusted* backups!",
70 ("snapshot", false, &StringSchema
::new("Group/Snapshot path.").schema()),
71 ("archive-name", false, &StringSchema
::new("Backup archive name.").schema()),
72 ("repository", true, &REPO_URL_SCHEMA
),
73 ("keyfile", true, &StringSchema
::new("Path to encryption key.").schema()),
74 ("verbose", true, &BooleanSchema
::new("Verbose output and stay in foreground.").default(false).schema()),
80 const API_METHOD_UNMAP
: ApiMethod
= ApiMethod
::new(
81 &ApiHandler
::Sync(&unmap
),
83 "Unmap a loop device mapped with 'map' and release all resources.",
85 ("name", true, &StringSchema
::new(
86 concat
!("Archive name, path to loopdev (/dev/loopX) or loop device number. ",
87 "Omit to list all current mappings and force cleaning up leftover instances.")
93 pub fn mount_cmd_def() -> CliCommand
{
95 CliCommand
::new(&API_METHOD_MOUNT
)
96 .arg_param(&["snapshot", "archive-name", "target"])
97 .completion_cb("repository", complete_repository
)
98 .completion_cb("snapshot", complete_group_or_snapshot
)
99 .completion_cb("archive-name", complete_pxar_archive_name
)
100 .completion_cb("target", tools
::complete_file_name
)
103 pub fn map_cmd_def() -> CliCommand
{
105 CliCommand
::new(&API_METHOD_MAP
)
106 .arg_param(&["snapshot", "archive-name"])
107 .completion_cb("repository", complete_repository
)
108 .completion_cb("snapshot", complete_group_or_snapshot
)
109 .completion_cb("archive-name", complete_img_archive_name
)
112 pub fn unmap_cmd_def() -> CliCommand
{
114 CliCommand
::new(&API_METHOD_UNMAP
)
115 .arg_param(&["name"])
116 .completion_cb("name", complete_mapping_names
)
119 fn complete_mapping_names
<S
: BuildHasher
>(_arg
: &str, _param
: &HashMap
<String
, String
, S
>)
122 match tools
::fuse_loop
::find_all_mappings() {
123 Ok(mappings
) => mappings
124 .filter_map(|(name
, _
)| {
125 tools
::systemd
::unescape_unit(&name
).ok()
134 _rpcenv
: &mut dyn RpcEnvironment
,
135 ) -> Result
<Value
, Error
> {
137 let verbose
= param
["verbose"].as_bool().unwrap_or(false);
139 // This will stay in foreground with debug output enabled as None is
140 // passed for the RawFd.
141 return proxmox_backup
::tools
::runtime
::main(mount_do(param
, None
));
144 // Process should be deamonized.
145 // Make sure to fork before the async runtime is instantiated to avoid troubles.
147 match unsafe { fork() }
{
148 Ok(ForkResult
::Parent { .. }
) => {
149 nix
::unistd
::close(pipe
.1).unwrap();
150 // Blocks the parent process until we are ready to go in the child
151 let _res
= nix
::unistd
::read(pipe
.0, &mut [0]).unwrap();
154 Ok(ForkResult
::Child
) => {
155 nix
::unistd
::close(pipe
.0).unwrap();
156 nix
::unistd
::setsid().unwrap();
157 proxmox_backup
::tools
::runtime
::main(mount_do(param
, Some(pipe
.1)))
159 Err(_
) => bail
!("failed to daemonize process"),
163 async
fn mount_do(param
: Value
, pipe
: Option
<RawFd
>) -> Result
<Value
, Error
> {
164 let repo
= extract_repository_from_value(¶m
)?
;
165 let archive_name
= tools
::required_string_param(¶m
, "archive-name")?
;
166 let client
= connect(&repo
)?
;
168 let target
= param
["target"].as_str();
170 record_repository(&repo
);
172 let path
= tools
::required_string_param(¶m
, "snapshot")?
;
173 let (backup_type
, backup_id
, backup_time
) = if path
.matches('
/'
).count() == 1 {
174 let group
: BackupGroup
= path
.parse()?
;
175 api_datastore_latest_snapshot(&client
, repo
.store(), group
).await?
177 let snapshot
: BackupDir
= path
.parse()?
;
178 (snapshot
.group().backup_type().to_owned(), snapshot
.group().backup_id().to_owned(), snapshot
.backup_time())
181 let keyfile
= param
["keyfile"].as_str().map(PathBuf
::from
);
182 let crypt_config
= match keyfile
{
185 println
!("Encryption key file: '{:?}'", path
);
186 let (key
, _
, fingerprint
) = load_and_decrypt_key(&path
, &crate::key
::get_encryption_key_password
)?
;
187 println
!("Encryption key fingerprint: '{}'", fingerprint
);
188 Some(Arc
::new(CryptConfig
::new(key
)?
))
192 let server_archive_name
= if archive_name
.ends_with(".pxar") {
193 if let None
= target
{
194 bail
!("use the 'mount' command to mount pxar archives");
196 format
!("{}.didx", archive_name
)
197 } else if archive_name
.ends_with(".img") {
198 if let Some(_
) = target
{
199 bail
!("use the 'map' command to map drive images");
201 format
!("{}.fidx", archive_name
)
203 bail
!("Can only mount/map pxar archives and drive images.");
206 let client
= BackupReader
::start(
208 crypt_config
.clone(),
216 let (manifest
, _
) = client
.download_manifest().await?
;
217 manifest
.check_fingerprint(crypt_config
.as_ref().map(Arc
::as_ref
))?
;
219 let file_info
= manifest
.lookup_file_info(&server_archive_name
)?
;
221 let daemonize
= || -> Result
<(), Error
> {
222 if let Some(pipe
) = pipe
{
223 nix
::unistd
::chdir(Path
::new("/")).unwrap();
224 // Finish creation of daemon by redirecting filedescriptors.
225 let nullfd
= nix
::fcntl
::open(
227 nix
::fcntl
::OFlag
::O_RDWR
,
228 nix
::sys
::stat
::Mode
::empty(),
230 nix
::unistd
::dup2(nullfd
, 0).unwrap();
231 nix
::unistd
::dup2(nullfd
, 1).unwrap();
232 nix
::unistd
::dup2(nullfd
, 2).unwrap();
234 nix
::unistd
::close(nullfd
).unwrap();
236 // Signal the parent process that we are done with the setup and it can
238 nix
::unistd
::write(pipe
, &[0u8])?
;
239 nix
::unistd
::close(pipe
).unwrap();
245 let options
= OsStr
::new("ro,default_permissions");
247 // handle SIGINT and SIGTERM
248 let mut interrupt_int
= signal(SignalKind
::interrupt())?
;
249 let mut interrupt_term
= signal(SignalKind
::terminate())?
;
250 let mut interrupt
= futures
::future
::select(interrupt_int
.next(), interrupt_term
.next());
252 if server_archive_name
.ends_with(".didx") {
253 let index
= client
.download_dynamic_index(&manifest
, &server_archive_name
).await?
;
254 let most_used
= index
.find_most_used_chunks(8);
255 let chunk_reader
= RemoteChunkReader
::new(client
.clone(), crypt_config
, file_info
.chunk_crypt_mode(), most_used
);
256 let reader
= BufferedDynamicReader
::new(index
, chunk_reader
);
257 let archive_size
= reader
.archive_size();
258 let reader
: proxmox_backup
::pxar
::fuse
::Reader
=
259 Arc
::new(BufferedDynamicReadAt
::new(reader
));
260 let decoder
= proxmox_backup
::pxar
::fuse
::Accessor
::new(reader
, archive_size
).await?
;
262 let session
= proxmox_backup
::pxar
::fuse
::Session
::mount(
266 Path
::new(target
.unwrap()),
268 .map_err(|err
| format_err
!("pxar mount failed: {}", err
))?
;
273 res
= session
.fuse() => res?
,
275 // exit on interrupted
278 } else if server_archive_name
.ends_with(".fidx") {
279 let index
= client
.download_fixed_index(&manifest
, &server_archive_name
).await?
;
280 let size
= index
.index_bytes();
281 let chunk_reader
= RemoteChunkReader
::new(client
.clone(), crypt_config
, file_info
.chunk_crypt_mode(), HashMap
::new());
282 let reader
= AsyncIndexReader
::new(index
, chunk_reader
);
284 let name
= &format
!("{}:{}/{}", repo
.to_string(), path
, archive_name
);
285 let name_escaped
= tools
::systemd
::escape_unit(name
, false);
287 let mut session
= tools
::fuse_loop
::FuseLoopSession
::map_loop(size
, reader
, &name_escaped
, options
).await?
;
288 let loopdev
= session
.loopdev_path
.clone();
290 let (st_send
, st_recv
) = futures
::channel
::mpsc
::channel(1);
291 let (mut abort_send
, abort_recv
) = futures
::channel
::mpsc
::channel(1);
292 let mut st_recv
= st_recv
.fuse();
293 let mut session_fut
= session
.main(st_send
, abort_recv
).boxed().fuse();
295 // poll until loop file is mapped (or errors)
297 res
= session_fut
=> {
298 bail
!("FUSE session unexpectedly ended before loop file mapping");
300 res
= st_recv
.try_next() => {
301 if let Err(err
) = res
{
302 // init went wrong, abort now
303 abort_send
.try_send(()).map_err(|err
|
304 format_err
!("error while sending abort signal - {}", err
))?
;
305 // ignore and keep original error cause
306 let _
= session_fut
.await
;
312 // daemonize only now to be able to print mapped loopdev or startup errors
313 println
!("Image '{}' mapped on {}", name
, loopdev
);
316 // continue polling until complete or interrupted (which also happens on unmap)
318 res
= session_fut
=> res?
,
320 // exit on interrupted
321 abort_send
.try_send(()).map_err(|err
|
322 format_err
!("error while sending abort signal - {}", err
))?
;
327 println
!("Image unmapped");
329 bail
!("unknown archive file extension (expected .pxar or .img)");
338 _rpcenv
: &mut dyn RpcEnvironment
,
339 ) -> Result
<Value
, Error
> {
341 let mut name
= match param
["name"].as_str() {
342 Some(name
) => name
.to_owned(),
344 tools
::fuse_loop
::cleanup_unused_run_files(None
);
346 for (backing
, loopdev
) in tools
::fuse_loop
::find_all_mappings()?
{
347 let name
= tools
::systemd
::unescape_unit(&backing
)?
;
348 println
!("{}:\t{}", loopdev
.unwrap_or("(unmapped)".to_owned()), name
);
352 println
!("Nothing mapped.");
354 return Ok(Value
::Null
);
358 // allow loop device number alone
359 if let Ok(num
) = name
.parse
::<u8>() {
360 name
= format
!("/dev/loop{}", num
);
363 if name
.starts_with("/dev/loop") {
364 tools
::fuse_loop
::unmap_loopdev(name
)?
;
366 let name
= tools
::systemd
::escape_unit(&name
, false);
367 tools
::fuse_loop
::unmap_name(name
)?
;