1 package PVE
::LXC
::Setup
::Base
;
20 my ($class, $conf, $rootdir, $os_release) = @_;
22 return bless { conf
=> $conf, rootdir
=> $rootdir, os_release
=> $os_release }, $class;
26 my ($self, $conf) = @_;
28 my $nameserver = $conf->{nameserver
};
29 my $searchdomains = $conf->{searchdomain
};
31 if ($conf->{'testmode'}) {
32 return ('proxmox.com', '8.8.8.8 8.8.8.9');
35 my $host_resolv_conf = $self->{host_resolv_conf
};
37 if (!defined($nameserver)) {
39 foreach my $k ("dns1", "dns2", "dns3") {
40 if (my $ns = $host_resolv_conf->{$k}) {
44 $nameserver = join(' ', @list);
47 if (!defined($searchdomains)) {
48 $searchdomains = $host_resolv_conf->{search
};
51 return ($searchdomains, $nameserver);
54 sub update_etc_hosts
{
55 my ($self, $hostip, $oldname, $newname, $searchdomains) = @_;
57 my $hosts_fn = '/etc/hosts';
58 return if $self->ct_is_file_ignored($hosts_fn);
60 my $namepart = ($newname =~ s/\..*$//r);
63 if ($newname =~ /\./) {
64 $all_names .= "$newname $namepart";
66 foreach my $domain (PVE
::Tools
::split_list
($searchdomains)) {
67 $all_names .= ' ' if $all_names;
68 $all_names .= "$newname.$domain";
70 $all_names .= ' ' if $all_names;
71 $all_names .= $newname;
77 my $lo4 = "127.0.0.1 localhost.localnet localhost\n";
78 my $lo6 = "::1 localhost.localnet localhost\n";
79 if ($self->ct_file_exists($hosts_fn)) {
80 my $data = $self->ct_file_get_contents($hosts_fn);
81 # don't take localhost entries within our hosts sections into account
82 $data = remove_pve_sections
($data);
84 # check for existing localhost entries
85 $section .= $lo4 if $data !~ /^\h*127\.0\.0\.1\h+/m;
86 $section .= $lo6 if $data !~ /^\h*::1\h+/m;
88 $section .= $lo4 . $lo6;
91 if (defined($hostip)) {
92 $section .= "$hostip $all_names\n";
93 } elsif ($namepart ne 'localhost') {
94 $section .= "127.0.1.1 $all_names\n";
96 $section .= "127.0.1.1 $namepart\n";
99 $self->ct_modify_file($hosts_fn, $section);
103 my ($self, $conf) = @_;
105 # do nothing by default
109 my ($self, $conf) = @_;
111 my ($searchdomains, $nameserver) = $self->lookup_dns_conf($conf);
115 $data .= "search " . join(' ', PVE
::Tools
::split_list
($searchdomains)) . "\n"
118 foreach my $ns ( PVE
::Tools
::split_list
($nameserver)) {
119 $data .= "nameserver $ns\n";
122 $self->ct_modify_file("/etc/resolv.conf", $data, replace
=> 1);
126 my ($self, $conf) = @_;
128 my $hostname = $conf->{hostname
} || 'localhost';
130 my $namepart = ($hostname =~ s/\..*$//r);
132 my $hostname_fn = "/etc/hostname";
134 my $oldname = $self->ct_file_read_firstline($hostname_fn) || 'localhost';
136 my ($ipv4, $ipv6) = PVE
::LXC
::get_primary_ips
($conf);
137 my $hostip = $ipv4 || $ipv6;
139 my ($searchdomains) = $self->lookup_dns_conf($conf);
141 $self->update_etc_hosts($hostip, $oldname, $hostname, $searchdomains);
143 $self->ct_file_set_contents($hostname_fn, "$namepart\n");
147 my ($self, $conf) = @_;
149 die "please implement this inside subclass"
153 my ($self, $conf) = @_;
155 die "please implement this inside subclass"
158 # A few distros as well as unprivileged containers cannot deal with the
159 # /dev/lxc/ tty subdirectory.
161 my ($self, $conf) = @_;
162 return $conf->{unprivileged
} ?
'' : 'lxc/';
165 sub fixup_old_getty
{
168 my $sd_dir_rel = $self->ct_is_executable("/lib/systemd/systemd") ?
169 "/lib/systemd/system" : "/usr/lib/systemd/system";
171 my $sd_getty_service_rel = "$sd_dir_rel/getty\@.service";
172 return if !$self->ct_file_exists($sd_getty_service_rel);
174 my $raw = $self->ct_file_get_contents($sd_getty_service_rel);
176 my $sd_container_getty_service_rel = "$sd_dir_rel/container-getty\@.service";
177 # systemd on CenoOS 7.1 is too old (version 205), so there is no
178 # container-getty service
179 if (!$self->ct_file_exists($sd_container_getty_service_rel)) {
180 if ($raw =~ s!^ConditionPathExists=/dev/tty0$!ConditionPathExists=/dev/tty!m) {
181 $self->ct_file_set_contents($sd_getty_service_rel, $raw);
184 # undo above change (in case someone updated systemd)
185 if ($raw =~ s!^ConditionPathExists=/dev/tty$!ConditionPathExists=/dev/tty0!m) {
186 $self->ct_file_set_contents($sd_getty_service_rel, $raw);
191 sub setup_container_getty_service
{
192 my ($self, $conf) = @_;
194 my $sd_dir = $self->ct_is_executable("/lib/systemd/systemd") ?
195 "/lib/systemd/system" : "/usr/lib/systemd/system";
197 # prefer container-getty.service shipped by newer systemd versions
198 # fallback to getty.service and just return if that doesn't exists either..
199 my $template_base = "container-getty\@";
200 my $template_path = "${sd_dir}/${template_base}.service";
201 my $instance_base = $template_base;
203 if (!$self->ct_file_exists($template_path)) {
204 $template_base = "getty\@";
205 $template_path = "${template_base}.service";
206 $instance_base = "{$template_base}tty";
207 return if !$self->ct_file_exists($template_path);
210 my $raw = $self->ct_file_get_contents($template_path);
211 my $ttyname = $self->devttydir($conf) . 'tty%I';
212 if ($raw =~ s
@pts/%I|lxc
/tty
%I@$ttyname@g) {
213 $self->ct_file_set_contents($template_path, $raw);
216 my $getty_target_fn = "/etc/systemd/system/getty.target.wants/";
217 my $ttycount = PVE
::LXC
::Config-
>get_tty_count($conf);
219 for (my $i = 1; $i < 7; $i++) {
220 # ensure that not two gettys are using the same tty!
221 $self->ct_unlink("$getty_target_fn/getty\@tty$i.service");
222 $self->ct_unlink("$getty_target_fn/container-getty\@$i.service");
224 # re-enable only those requested
225 if ($i <= $ttycount) {
226 my $tty_service = "${instance_base}${i}.service";
228 $self->ct_symlink($template_path, "$getty_target_fn/$tty_service");
232 # ensure getty.target is not masked
233 $self->ct_unlink("/etc/systemd/system/getty.target");
236 sub setup_systemd_networkd
{
237 my ($self, $conf) = @_;
239 foreach my $k (keys %$conf) {
240 next if $k !~ m/^net(\d+)$/;
241 my $d = PVE
::LXC
::Config-
>parse_lxc_network($conf->{$k});
244 my $filename = "/etc/systemd/network/$d->{name}.network";
251 Description = Interface $d->{name} autoconfigured by PVE
255 my ($has_ipv4, $has_ipv6);
258 my @DHCPMODES = ('none', 'v4', 'v6', 'both');
259 my ($NONE, $DHCP4, $DHCP6, $BOTH) = (0, 1, 2, 3);
261 my $accept_ra = 'false';
263 if (defined(my $ip = $d->{ip
})) {
266 } elsif ($ip ne 'manual') {
268 $data .= "Address = $ip\n";
271 if (defined(my $gw = $d->{gw
})) {
272 $data .= "Gateway = $gw\n";
273 if ($has_ipv4 && !PVE
::Network
::is_ip_in_cidr
($gw, $d->{ip
}, 4)) {
274 $routes .= "\n[Route]\nDestination = $gw/32\nScope = link\n";
278 if (defined(my $ip = $d->{ip6
})) {
281 } elsif ($ip eq 'auto') {
283 } elsif ($ip ne 'manual') {
285 $data .= "Address = $ip\n";
288 if (defined(my $gw = $d->{gw6
})) {
289 $accept_ra = 'false';
290 $data .= "Gateway = $gw\n";
291 if ($has_ipv6 && !PVE
::Network
::is_ip_in_cidr
($gw, $d->{ip6
}, 6) &&
292 !PVE
::Network
::is_ip_in_cidr
($gw, 'fe80::/10', 6)) {
293 $routes .= "\n[Route]\nDestination = $gw/128\nScope = link\n";
297 $data .= "DHCP = $DHCPMODES[$dhcp]\n";
298 $data .= "IPv6AcceptRA = $accept_ra\n";
299 $data .= $routes if $routes;
301 $self->ct_file_set_contents($filename, $data);
305 sub setup_securetty
{
306 my ($self, $conf, @add) = @_;
308 my $filename = "/etc/securetty";
309 # root login is already allowed on every device if no securetty present
310 return if !$self->ct_file_exists($filename);
313 @add = qw(console tty1 tty2 tty3 tty4);
314 if (my $dir = $self->devttydir($conf)) {
315 @add = map { "${dir}$_" } @add;
319 my $data = $self->ct_file_get_contents($filename);
320 chomp $data; $data .= "\n";
321 foreach my $dev (@add) {
322 if ($data !~ m!^\Q$dev\E\s*$!m) {
326 $self->ct_file_set_contents($filename, $data);
329 my $replacepw = sub {
330 my ($self, $file, $user, $epw, $shadow) = @_;
332 my $tmpfile = "$file.$$";
335 my $src = $self->ct_open_file_read($file) ||
336 die "unable to open file '$file' - $!";
338 my $st = $self->ct_stat($src) ||
339 die "unable to stat file - $!";
341 my $dst = $self->ct_open_file_write($tmpfile) ||
342 die "unable to open file '$tmpfile' - $!";
344 # copy owner and permissions
345 chmod $st->mode, $dst;
346 chown $st->uid, $st->gid, $dst;
348 my $last_change = int(time()/(60*60*24));
350 while (defined (my $line = <$src>)) {
352 $line =~ s/^${user}:[^:]*:[^:]*:/${user}:${epw}:${last_change}:/;
354 $line =~ s/^${user}:[^:]*:/${user}:${epw}:/;
359 $src->close() || die "close '$file' failed - $!\n";
360 $dst->close() || die "close '$tmpfile' failed - $!\n";
363 $self->ct_unlink($tmpfile);
365 $self->ct_rename($tmpfile, $file);
366 $self->ct_unlink($tmpfile); # in case rename fails
370 sub set_user_password
{
371 my ($self, $conf, $user, $opt_password) = @_;
373 my $pwfile = "/etc/passwd";
375 return if !$self->ct_file_exists($pwfile);
377 my $shadow = "/etc/shadow";
379 if (defined($opt_password)) {
380 if ($opt_password !~ m/^\$(?:1|2[axy]?|5|6)\$[a-zA-Z0-9.\/]{1,16}\
$[a-zA-Z0-9
.\
/]+$/) {
381 my $time = substr (Digest
::SHA
::sha1_base64
(time), 0, 8);
382 $opt_password = crypt(encode
("utf8", $opt_password), "\$6\$$time\$");
388 if ($self->ct_file_exists($shadow)) {
389 &$replacepw ($self, $shadow, $user, $opt_password, 1);
390 &$replacepw ($self, $pwfile, $user, 'x');
392 &$replacepw ($self, $pwfile, $user, $opt_password);
396 my $parse_home_dir = sub {
397 my ($self, $passwdfile, $user) = @_;
399 my $fh = $self->ct_open_file_read($passwdfile);
400 while (defined (my $line = <$fh>)) {
402 if $line =~ m/^${user}:([^:]*:){4}([^:]*):/;
406 sub set_user_authorized_ssh_keys
{
407 my ($self, $conf, $user, $ssh_keys) = @_;
409 my $passwd = "/etc/passwd";
410 my $home = $user eq "root" ?
"/root/" : "/home/$user/";
412 $home = &$parse_home_dir($self, $passwd, $user)
413 if $self->ct_file_exists($passwd);
415 die "home directory '$home' of $user does not exist!"
416 if ! ($self->ct_is_directory($home) || $self->ct_is_symlink($home));
418 $self->ct_mkdir("$home/.ssh", 0700)
419 if ! $self->ct_is_directory("$home/.ssh");
421 $self->ct_modify_file("$home/.ssh/authorized_keys", $ssh_keys, perms
=> 0700);
424 my $randomize_crontab = sub {
425 my ($self, $conf) = @_;
428 # Note: dir_glob_foreach() untaints filenames!
429 PVE
::Tools
::dir_glob_foreach
("/etc/cron.d", qr/[A-Z\-\_a-z0-9]+/, sub {
431 push @files, "/etc/cron.d/$name";
434 my $crontab_fn = "/etc/crontab";
435 unshift @files, $crontab_fn if $self->ct_file_exists($crontab_fn);
437 foreach my $filename (@files) {
438 my $data = $self->ct_file_get_contents($filename);
440 foreach my $line (split(/\n/, $data)) {
441 # we only randomize minutes for root crontab entries
442 if ($line =~ m/^\d+(\s+\S+\s+\S+\s+\S+\s+\S+\s+root\s+\S.*)$/) {
444 my $min = int(rand()*59);
445 $new .= "$min$rest\n";
450 $self->ct_file_set_contents($filename, $new);
455 my ($self, $conf) = @_;
457 $self->setup_init($conf);
458 $self->setup_network($conf);
459 $self->set_hostname($conf);
460 $self->set_dns($conf);
465 sub post_create_hook
{
466 my ($self, $conf, $root_password, $ssh_keys) = @_;
468 $self->template_fixup($conf);
470 &$randomize_crontab($self, $conf);
472 $self->set_user_password($conf, 'root', $root_password);
473 $self->set_user_authorized_ssh_keys($conf, 'root', $ssh_keys) if $ssh_keys;
474 $self->setup_init($conf);
475 $self->setup_network($conf);
476 $self->set_hostname($conf);
477 $self->set_dns($conf);
482 # File access wrappers for container setup code.
483 # For user-namespace support these might need to take uid and gid maps into account.
485 sub ct_is_file_ignored
{
486 my ($self, $file) = @_;
487 my ($name, $path) = fileparse
($file);
488 return -f
"$path/.pve-ignore.$name";
491 sub ct_reset_ownership
{
492 my ($self, @files) = @_;
493 my $conf = $self->{conf
};
494 return if !$self->{id_map
};
496 @files = grep { !$self->ct_is_file_ignored($_) } @files;
499 my $uid = $self->{rootuid
};
500 my $gid = $self->{rootgid
};
501 chown($uid, $gid, @files);
505 my ($self, $file, $mask) = @_;
506 # mkdir goes by parameter count - an `undef' mode acts like a mode of 0000
507 if (defined($mask)) {
508 return CORE
::mkdir($file, $mask) && $self->ct_reset_ownership($file);
510 return CORE
::mkdir($file) && $self->ct_reset_ownership($file);
515 my ($self, @files) = @_;
516 foreach my $file (@files) {
517 next if $self->ct_is_file_ignored($file);
523 my ($self, $old, $new) = @_;
524 return if $self->ct_is_file_ignored($new);
525 CORE
::rename($old, $new);
528 sub ct_open_file_read
{
531 return IO
::File-
>new($file, O_RDONLY
, @_);
534 sub ct_open_file_write
{
537 $file = '/dev/null' if $self->ct_is_file_ignored($file);
538 my $fh = IO
::File-
>new($file, O_WRONLY
| O_CREAT
, @_);
539 $self->ct_reset_ownership($fh);
545 if ($self->{id_map
}) {
547 if (ref($opts) eq 'HASH') {
548 $opts->{owner
} = $self->{rootuid
} if !defined($self->{owner
});
549 $opts->{group
} = $self->{rootgid
} if !defined($self->{group
});
551 File
::Path
::make_path
(@_, $opts);
553 File
::Path
::make_path
(@_);
558 my ($self, $old, $new) = @_;
559 return if $self->ct_is_file_ignored($new);
560 return CORE
::symlink($old, $new);
564 my ($self, $name) = @_;
565 return CORE
::readlink($name);
569 my ($self, $file) = @_;
573 sub ct_is_directory
{
574 my ($self, $file) = @_;
579 my ($self, $file) = @_;
583 sub ct_is_executable
{
584 my ($self, $file) = @_;
589 my ($self, $file) = @_;
590 return File
::stat::stat($file);
593 sub ct_file_read_firstline
{
594 my ($self, $file) = @_;
595 return PVE
::Tools
::file_read_firstline
($file);
598 sub ct_file_get_contents
{
599 my ($self, $file) = @_;
600 return PVE
::Tools
::file_get_contents
($file);
603 sub ct_file_set_contents
{
604 my ($self, $file, $data, $perms) = @_;
605 return if $self->ct_is_file_ignored($file);
606 PVE
::Tools
::file_set_contents
($file, $data, $perms);
607 $self->ct_reset_ownership($file);
610 # Modify a marked portion of a file.
611 # Optionally if the file becomes empty it will be deleted.
613 my ($self, $file, $data, %options) = @_;
614 return if $self->ct_is_file_ignored($file);
616 my $head = "# --- BEGIN PVE ---\n";
617 my $tail = "# --- END PVE ---\n";
618 my $perms = $options{perms
};
619 $data .= "\n" if $data && $data !~ /\n$/;
621 if (!$self->ct_file_exists($file)) {
622 $self->ct_file_set_contents($file, $head.$data.$tail, $perms) if $data;
626 my $old = $self->ct_file_get_contents($file);
627 my @lines = split(/\n/, $old);
630 foreach my $i (0..(@lines-1)) {
631 my $line = $lines[$i];
632 $beg = $i if !defined($beg) &&
633 $line =~ /^#\s*---\s*BEGIN\s*PVE\s*/;
634 $end = $i if !defined($end) && defined($beg) &&
635 $line =~ /^#\s*---\s*END\s*PVE\s*/i;
636 last if defined($beg) && defined($end);
639 if (defined($beg) && defined($end)) {
643 splice @lines, $beg, $end-$beg+1, $head.$data.$tail;
645 if ($beg == 0 && $end == (@lines-1)) {
646 $self->ct_unlink($file) if $options{delete};
649 splice @lines, $beg, $end-$beg+1, $head.$data.$tail;
651 $self->ct_file_set_contents($file, join("\n", @lines) . "\n");
654 my $content = join("\n", @lines);
656 if (!$content && !$data && $options{delete}) {
657 $self->ct_unlink($file);
661 $data = $head.$data.$tail;
662 if ($options{replace
}) {
663 $self->ct_file_set_contents($file, $data, $perms);
664 } elsif ($options{prepend
}) {
665 $self->ct_file_set_contents($file, $data . $content, $perms);
667 $self->ct_file_set_contents($file, $content . $data, $perms);
672 sub remove_pve_sections
{
675 my $head = "# --- BEGIN PVE ---";
676 my $tail = "# --- END PVE ---";
678 # Remove the sections enclosed with the above headers and footers.
679 # from a line (^) starting with '\h*$head'
680 # to a line (the other ^) starting with '\h*$tail' up to including that
682 return $data =~ s/^\h*\Q$head\E.*^\h*\Q$tail\E.*?$//rgms;