1 package PVE
::LXC
::Create
;
9 use PVE
::RPCEnvironment
;
10 use PVE
::Storage
::PBSPlugin
;
12 use PVE
::DataCenterConfig
;
15 use PVE
::VZDump
::ConvertOVZ
;
19 sub detect_architecture
{
22 # see https://en.wikipedia.org/wiki/Executable_and_Linkable_Format
24 my $supported_elf_machine = {
32 my $elf_fn = '/bin/sh'; # '/bin/sh' is POSIX mandatory
33 my $detect_arch = sub {
34 # chroot avoids a problem where we check the binary of the host system
35 # if $elf_fn is an absolut symlink (e.g. $rootdir/bin/sh -> /bin/bash)
36 chroot($rootdir) or die "chroot '$rootdir' failed: $!\n";
37 chdir('/') or die "failed to change to root directory\n";
39 open(my $fh, "<", $elf_fn) or die "open '$elf_fn' failed: $!\n";
42 my $length = read($fh, my $data, 20) or die "read failed: $!\n";
44 # 4 bytes ELF magic number and 1 byte ELF class, padding, machine
45 my ($magic, $class, undef, $machine) = unpack("A4CA12n", $data);
47 die "'$elf_fn' does not resolve to an ELF!\n"
48 if (!defined($class) || !defined($magic) || $magic ne "\177ELF");
50 my $arch = $supported_elf_machine->{$machine};
51 die "'$elf_fn' has unknown ELF machine '$machine'!\n"
54 if ($arch eq 'riscv') {
57 } elsif ($class eq 2) {
60 die "'$elf_fn' has invalid class '$class'!\n";
67 my $arch = eval { PVE
::Tools
::run_fork_with_timeout
(10, $detect_arch); };
70 if (!defined($arch) && !defined($err)) {
72 die "Architecture detection failed: timeout\n";
76 print "Architecture detection failed: $err\nFalling back to $arch.\n" .
77 "Use `pct set VMID --arch ARCH` to change.\n";
79 print "Detected container architecture: $arch\n";
86 my ($storage_cfg, $archive, $rootdir, $conf, $no_unpack_error, $bwlimit) = @_;
88 my ($storeid, $volname) = PVE
::Storage
::parse_volume_id
($archive, 1);
89 if (defined($storeid)) {
90 my $scfg = PVE
::Storage
::storage_check_enabled
($storage_cfg, $storeid);
91 if ($scfg->{type
} eq 'pbs') {
92 return restore_proxmox_backup_archive
($storage_cfg, $archive, $rootdir, $conf, $no_unpack_error, $bwlimit);
96 $archive = PVE
::Storage
::abs_filesystem_path
($storage_cfg, $archive) if $archive ne '-';
97 restore_tar_archive
($archive, $rootdir, $conf, $no_unpack_error, $bwlimit);
100 sub restore_proxmox_backup_archive
{
101 my ($storage_cfg, $archive, $rootdir, $conf, $no_unpack_error, $bwlimit) = @_;
103 my ($storeid, $volname) = PVE
::Storage
::parse_volume_id
($archive);
104 my $scfg = PVE
::Storage
::storage_config
($storage_cfg, $storeid);
106 my ($vtype, $name, undef, undef, undef, undef, $format) =
107 PVE
::Storage
::parse_volname
($storage_cfg, $archive);
109 die "got unexpected vtype '$vtype'\n" if $vtype ne 'backup';
111 die "got unexpected backup format '$format'\n" if $format ne 'pbs-ct';
113 my ($id_map, $rootuid, $rootgid) = PVE
::LXC
::parse_id_maps
($conf);
114 my $userns_cmd = PVE
::LXC
::userns_command
($id_map);
117 my $param = [$name, "root.pxar", $rootdir, '--allow-existing-dirs'];
119 PVE
::Storage
::PBSPlugin
::run_raw_client_cmd
(
120 $scfg, $storeid, $cmd, $param, userns_cmd
=> $userns_cmd);
122 # if arch is set, we do not try to autodetect it
123 return if defined($conf->{arch
});
125 $conf->{arch
} = detect_architecture
($rootdir);
128 sub restore_tar_archive
{
129 my ($archive, $rootdir, $conf, $no_unpack_error, $bwlimit) = @_;
131 my ($id_map, $rootuid, $rootgid) = PVE
::LXC
::parse_id_maps
($conf);
132 my $userns_cmd = PVE
::LXC
::userns_command
($id_map);
135 my $tar_input = '<&STDIN';
137 if ($archive ne '-') {
138 # GNU tar refuses to autodetect this... *sigh*
139 my %compression_map = (
146 if ($archive =~ /\.tar(\.[^.]+)?$/) {
148 die "unrecognized compression format: $1\n" if !defined($compression_map{$1});
149 @compression_opt = $compression_map{$1};
152 die "file does not look like a template archive: $archive\n";
154 sysopen($archive_fh, $archive, O_RDONLY
)
155 or die "failed to open '$archive': $!\n";
156 my $flags = $archive_fh->fcntl(Fcntl
::F_GETFD
(), 0);
157 $archive_fh->fcntl(Fcntl
::F_SETFD
(), $flags & ~(Fcntl
::FD_CLOEXEC
()));
158 $tar_input = '<&'.fileno($archive_fh);
161 my $cmd = [@$userns_cmd, 'tar', 'xpf', '-', @compression_opt, '--totals',
162 @PVE::Storage
::Plugin
::COMMON_TAR_FLAGS
,
165 # skip-old-files doesn't have anything to do with time (old/new), but is
166 # simply -k (annoyingly also called --keep-old-files) without the 'treat
167 # existing files as errors' part... iow. it's bsdtar's interpretation of -k
169 push @$cmd, '--skip-old-files';
170 push @$cmd, '--anchored';
171 push @$cmd, '--exclude' , './dev/*';
173 if (defined($bwlimit)) {
174 $cmd = [ ['cstream', '-t', $bwlimit*1024], $cmd ];
177 if ($archive eq '-') {
178 print "extracting archive from STDIN\n";
180 print "extracting archive '$archive'\n";
182 eval { PVE
::Tools
::run_command
($cmd, input
=> $tar_input); };
184 close($archive_fh) if defined $archive_fh;
185 die $err if $err && !$no_unpack_error;
187 # if arch is set, we do not try to autodetect it
188 return if defined($conf->{arch
});
190 $conf->{arch
} = detect_architecture
($rootdir);
194 my ($storage_cfg, $volid, $vmid) = @_;
196 my ($storeid, $volname) = PVE
::Storage
::parse_volume_id
($volid, 1);
197 if (defined($storeid)) {
198 my $scfg = PVE
::Storage
::storage_check_enabled
($storage_cfg, $storeid);
199 if ($scfg->{type
} eq 'pbs') {
200 return recover_config_from_proxmox_backup
($storage_cfg, $volid, $vmid);
204 my $archive = PVE
::Storage
::abs_filesystem_path
($storage_cfg, $volid);
205 recover_config_from_tar
($archive, $vmid);
208 sub recover_config_from_proxmox_backup
{
209 my ($storage_cfg, $volid, $vmid) = @_;
213 my ($storeid, $volname) = PVE
::Storage
::parse_volume_id
($volid);
214 my $scfg = PVE
::Storage
::storage_config
($storage_cfg, $storeid);
216 my ($vtype, $name, undef, undef, undef, undef, $format) =
217 PVE
::Storage
::parse_volname
($storage_cfg, $volid);
219 die "got unexpected vtype '$vtype'\n" if $vtype ne 'backup';
221 die "got unexpected backup format '$format'\n" if $format ne 'pbs-ct';
224 my $param = [$name, "pct.conf", "-"];
227 my $outfunc = sub { my $line = shift; $raw .= "$line\n"; };
228 PVE
::Storage
::PBSPlugin
::run_raw_client_cmd
(
229 $scfg, $storeid, $cmd, $param, outfunc
=> $outfunc);
231 my $conf = PVE
::LXC
::Config
::parse_pct_config
("/lxc/${vmid}.conf" , $raw);
233 delete $conf->{snapshots
};
236 PVE
::LXC
::Config-
>foreach_volume($conf, sub {
237 my ($ms, $mountpoint) = @_;
238 $mp_param->{$ms} = $conf->{$ms};
241 return wantarray ?
($conf, $mp_param) : $conf;
244 sub recover_config_from_tar
{
245 my ($archive, $vmid) = @_;
247 my ($raw, $conf_file) = PVE
::Storage
::extract_vzdump_config_tar
($archive, qr!(\./etc/vzdump/(pct|vps)\.conf)$!);
252 if ($conf_file =~ m/pct\.conf/) {
254 $conf = PVE
::LXC
::Config
::parse_pct_config
("/lxc/${vmid}.conf" , $raw);
256 delete $conf->{snapshots
};
258 PVE
::LXC
::Config-
>foreach_volume($conf, sub {
259 my ($ms, $mountpoint) = @_;
260 $mp_param->{$ms} = $conf->{$ms};
263 } elsif ($conf_file =~ m/vps\.conf/) {
265 ($conf, $mp_param) = PVE
::VZDump
::ConvertOVZ
::convert_ovz
($raw);
269 die "internal error";
272 return wantarray ?
($conf, $mp_param) : $conf;
275 sub restore_configuration
{
276 my ($vmid, $storage_cfg, $archive, $rootdir, $conf, $restricted, $unique, $skip_fw) = @_;
278 my ($storeid, $volname) = PVE
::Storage
::parse_volume_id
($archive, 1);
279 if (defined($storeid)) {
280 my $scfg = PVE
::Storage
::storage_config
($storage_cfg, $storeid);
281 if ($scfg->{type
} eq 'pbs') {
282 return restore_configuration_from_proxmox_backup
($vmid, $storage_cfg, $archive, $rootdir, $conf, $restricted, $unique, $skip_fw);
285 restore_configuration_from_etc_vzdump
($vmid, $rootdir, $conf, $restricted, $unique, $skip_fw);
288 sub restore_configuration_from_proxmox_backup
{
289 my ($vmid, $storage_cfg, $archive, $rootdir, $conf, $restricted, $unique, $skip_fw) = @_;
291 my ($storeid, $volname) = PVE
::Storage
::parse_volume_id
($archive);
292 my $scfg = PVE
::Storage
::storage_config
($storage_cfg, $storeid);
294 my ($vtype, $name, undef, undef, undef, undef, $format) =
295 PVE
::Storage
::parse_volname
($storage_cfg, $archive);
297 my $oldconf = recover_config_from_proxmox_backup
($storage_cfg, $archive, $vmid);
299 sanitize_and_merge_config
($conf, $oldconf, $restricted, $unique);
303 my $list = PVE
::Storage
::PBSPlugin
::run_client_cmd
($scfg, $storeid, "files", [$name]);
304 my $has_fw_conf = grep { $_->{filename
} eq 'fw.conf.blob' } @$list;
307 my $pve_firewall_dir = '/etc/pve/firewall';
308 my $pct_fwcfg_target = "${pve_firewall_dir}/${vmid}.fw";
310 warn "ignoring firewall config from backup archive's 'fw.conf', lacking API permission to modify firewall.\n";
311 warn "old firewall configuration in '$pct_fwcfg_target' left in place!\n"
312 if -e
$pct_fwcfg_target;
314 mkdir $pve_firewall_dir; # make sure the directory exists
315 unlink $pct_fwcfg_target;
318 my $param = [$name, "fw.conf", $pct_fwcfg_target];
319 PVE
::Storage
::PBSPlugin
::run_raw_client_cmd
($scfg, $storeid, $cmd, $param);
324 sub sanitize_and_merge_config
{
325 my ($conf, $oldconf, $restricted, $unique) = @_;
327 my $rpcenv = PVE
::RPCEnvironment
::get
();
328 my $authuser = $rpcenv->get_user();
330 foreach my $key (keys %$oldconf) {
331 next if $key eq 'digest' || $key eq 'rootfs' || $key eq 'snapshots' || $key eq 'unprivileged' || $key eq 'parent';
332 next if $key =~ /^mp\d+$/; # don't recover mountpoints
333 next if $key =~ /^unused\d+$/; # don't recover unused disks
334 # we know if it was a template in the restore API call and check if the target
335 # storage supports creating a template there
336 next if $key =~ /^template$/;
338 if ($restricted && $key eq 'features' && !$conf->{unprivileged
} && $oldconf->{unprivileged
}) {
339 warn "changing from unprivileged to privileged, skipping features\n";
343 if ($key eq 'lxc' && $restricted) {
344 my $lxc_list = $oldconf->{'lxc'};
346 my $msg = "skipping custom lxc options, restore manually as root:\n";
347 $msg .= "--------------------------------\n";
348 foreach my $lxc_opt (@$lxc_list) {
349 $msg .= "$lxc_opt->[0]: $lxc_opt->[1]\n"
351 $msg .= "--------------------------------";
358 if ($key =~ /^net\d+$/ && !defined($conf->{$key})) {
359 PVE
::LXC
::check_bridge_access
($rpcenv, $authuser, $oldconf->{$key});
362 if ($unique && $key =~ /^net\d+$/) {
363 my $net = PVE
::LXC
::Config-
>parse_lxc_network($oldconf->{$key});
364 my $dc = PVE
::Cluster
::cfs_read_file
('datacenter.cfg');
365 $net->{hwaddr
} = PVE
::Tools
::random_ether_addr
($dc->{mac_prefix
});
366 $conf->{$key} = PVE
::LXC
::Config-
>print_lxc_network($net);
369 $conf->{$key} = $oldconf->{$key} if !defined($conf->{$key});
373 sub restore_configuration_from_etc_vzdump
{
374 my ($vmid, $rootdir, $conf, $restricted, $unique, $skip_fw) = @_;
376 # restore: try to extract configuration from archive
378 my $pct_cfg_fn = "$rootdir/etc/vzdump/pct.conf";
379 my $pct_fwcfg_fn = "$rootdir/etc/vzdump/pct.fw";
380 my $ovz_cfg_fn = "$rootdir/etc/vzdump/vps.conf";
381 if (-f
$pct_cfg_fn) {
382 my $raw = PVE
::Tools
::file_get_contents
($pct_cfg_fn);
383 my $oldconf = PVE
::LXC
::Config
::parse_pct_config
("/lxc/$vmid.conf", $raw);
385 sanitize_and_merge_config
($conf, $oldconf, $restricted, $unique);
389 # note: this file is possibly from the container itself in backups
390 # created prior to pve-container 2.0-40 (PVE 5.x) / 3.0-5 (PVE 6.x)
391 # only copy non-empty, non-symlink files, and only if the user is
392 # allowed to modify the firewall config anyways
393 if (-f
$pct_fwcfg_fn && ! -l
$pct_fwcfg_fn && -s
$pct_fwcfg_fn) {
394 my $pve_firewall_dir = '/etc/pve/firewall';
395 my $pct_fwcfg_target = "${pve_firewall_dir}/${vmid}.fw";
397 warn "ignoring firewall config from backup archive's '$pct_fwcfg_fn', lacking API permission to modify firewall.\n";
398 warn "old firewall configuration in '$pct_fwcfg_target' left in place!\n"
399 if -e
$pct_fwcfg_target;
401 mkdir $pve_firewall_dir; # make sure the directory exists
402 PVE
::Tools
::file_copy
($pct_fwcfg_fn, $pct_fwcfg_target);
404 unlink $pct_fwcfg_fn;
407 } elsif (-f
$ovz_cfg_fn) {
408 print "###########################################################\n";
409 print "Converting OpenVZ configuration to LXC.\n";
410 print "Please check the configuration and reconfigure the network.\n";
411 print "###########################################################\n";
413 my $lxc_setup = PVE
::LXC
::Setup-
>new($conf, $rootdir); # detect OS
414 $conf->{ostype
} = $lxc_setup->{conf
}->{ostype
};
415 my $raw = PVE
::Tools
::file_get_contents
($ovz_cfg_fn);
416 my $oldconf = PVE
::VZDump
::ConvertOVZ
::convert_ovz
($raw);
417 foreach my $key (keys %$oldconf) {
418 $conf->{$key} = $oldconf->{$key} if !defined($conf->{$key});
423 print "###########################################################\n";
424 print "Backup archive does not contain any configuration\n";
425 print "###########################################################\n";