]> git.proxmox.com Git - qemu-server.git/blob - PVE/QemuServer/Cloudinit.pm
fix #3792: cloudinit: use of uninitialized value
[qemu-server.git] / PVE / QemuServer / Cloudinit.pm
1 package PVE::QemuServer::Cloudinit;
2
3 use strict;
4 use warnings;
5
6 use File::Path;
7 use Digest::SHA;
8 use URI::Escape;
9 use MIME::Base64 qw(encode_base64);
10
11 use PVE::Tools qw(run_command file_set_contents);
12 use PVE::Storage;
13 use PVE::QemuServer;
14
15 use constant CLOUDINIT_DISK_SIZE => 4 * 1024 * 1024; # 4MiB in bytes
16
17 sub commit_cloudinit_disk {
18 my ($conf, $vmid, $drive, $volname, $storeid, $files, $label) = @_;
19
20 my $path = "/run/pve/cloudinit/$vmid/";
21 mkpath $path;
22 foreach my $filepath (keys %$files) {
23 if ($filepath !~ m@^(.*)\/[^/]+$@) {
24 die "internal error: bad file name in cloud-init image: $filepath\n";
25 }
26 my $dirname = $1;
27 mkpath "$path/$dirname";
28
29 my $contents = $files->{$filepath};
30 file_set_contents("$path/$filepath", $contents);
31 }
32
33 my $storecfg = PVE::Storage::config();
34 my $iso_path = PVE::Storage::path($storecfg, $drive->{file});
35 my $scfg = PVE::Storage::storage_config($storecfg, $storeid);
36 my $format = PVE::QemuServer::qemu_img_format($scfg, $volname);
37
38 my $size = eval { PVE::Storage::volume_size_info($storecfg, $drive->{file}) };
39 if (!defined($size) || $size <= 0) {
40 $volname =~ m/(vm-$vmid-cloudinit(.\Q$format\E)?)/;
41 my $name = $1;
42 $size = 4 * 1024;
43 PVE::Storage::vdisk_alloc($storecfg, $storeid, $vmid, $format, $name, $size);
44 $size *= 1024; # vdisk alloc takes KB, qemu-img dd's osize takes byte
45 }
46 my $plugin = PVE::Storage::Plugin->lookup($scfg->{type});
47 $plugin->activate_volume($storeid, $scfg, $volname);
48
49 print "generating cloud-init ISO\n";
50 eval {
51 run_command([
52 ['genisoimage', '-quiet', '-iso-level', '3', '-R', '-V', $label, $path],
53 ['qemu-img', 'dd', '-n', '-f', 'raw', '-O', $format, 'isize=0', "osize=$size", "of=$iso_path"]
54 ]);
55 };
56 my $err = $@;
57 rmtree($path);
58 die $err if $err;
59 }
60
61 sub get_cloudinit_format {
62 my ($conf) = @_;
63 if (defined(my $format = $conf->{citype})) {
64 return $format;
65 }
66
67 # No format specified, default based on ostype because windows'
68 # cloudbased-init only supports configdrivev2, whereas on linux we need
69 # to use mac addresses because regular cloudinit doesn't map 'ethX' to
70 # the new predicatble network device naming scheme.
71 if (defined(my $ostype = $conf->{ostype})) {
72 return 'configdrive2'
73 if PVE::QemuServer::windows_version($ostype);
74 }
75
76 return 'nocloud';
77 }
78
79 sub get_hostname_fqdn {
80 my ($conf, $vmid) = @_;
81 my $hostname = $conf->{name} // "VM$vmid";
82 my $fqdn;
83 if ($hostname =~ /\./) {
84 $fqdn = $hostname;
85 $hostname =~ s/\..*$//;
86 } elsif (my $search = $conf->{searchdomain}) {
87 $fqdn = "$hostname.$search";
88 }
89 return ($hostname, $fqdn);
90 }
91
92 sub get_dns_conf {
93 my ($conf) = @_;
94
95 # Same logic as in pve-container, but without the testcase special case
96 my $host_resolv_conf = PVE::INotify::read_file('resolvconf');
97
98 my $searchdomains = [
99 split(/\s+/, $conf->{searchdomain} // $host_resolv_conf->{search})
100 ];
101
102 my $nameserver = $conf->{nameserver};
103 if (!defined($nameserver)) {
104 $nameserver = [grep { $_ } $host_resolv_conf->@{qw(dns1 dns2 dns3)}];
105 } else {
106 $nameserver = [split(/\s+/, $nameserver)];
107 }
108
109 return ($searchdomains, $nameserver);
110 }
111
112 sub cloudinit_userdata {
113 my ($conf, $vmid) = @_;
114
115 my ($hostname, $fqdn) = get_hostname_fqdn($conf, $vmid);
116
117 my $content = "#cloud-config\n";
118
119 $content .= "hostname: $hostname\n";
120 $content .= "manage_etc_hosts: true\n";
121 $content .= "fqdn: $fqdn\n" if defined($fqdn);
122
123 my $username = $conf->{ciuser};
124 my $password = $conf->{cipassword};
125
126 $content .= "user: $username\n" if defined($username);
127 $content .= "disable_root: False\n" if defined($username) && $username eq 'root';
128 $content .= "password: $password\n" if defined($password);
129
130 if (defined(my $keys = $conf->{sshkeys})) {
131 $keys = URI::Escape::uri_unescape($keys);
132 $keys = [map { my $key = $_; chomp $key; $key } split(/\n/, $keys)];
133 $keys = [grep { /\S/ } @$keys];
134 $content .= "ssh_authorized_keys:\n";
135 foreach my $k (@$keys) {
136 $content .= " - $k\n";
137 }
138 }
139 $content .= "chpasswd:\n";
140 $content .= " expire: False\n";
141
142 if (!defined($username) || $username ne 'root') {
143 $content .= "users:\n";
144 $content .= " - default\n";
145 }
146
147 $content .= "package_upgrade: true\n";
148
149 return $content;
150 }
151
152 sub split_ip4 {
153 my ($ip) = @_;
154 my ($addr, $mask) = split('/', $ip);
155 die "not a CIDR: $ip\n" if !defined $mask;
156 return ($addr, $PVE::Network::ipv4_reverse_mask->[$mask]);
157 }
158
159 sub configdrive2_network {
160 my ($conf) = @_;
161
162 my $content = "auto lo\n";
163 $content .= "iface lo inet loopback\n\n";
164
165 my ($searchdomains, $nameservers) = get_dns_conf($conf);
166 if ($nameservers && @$nameservers) {
167 $nameservers = join(' ', @$nameservers);
168 $content .= " dns_nameservers $nameservers\n";
169 }
170 if ($searchdomains && @$searchdomains) {
171 $searchdomains = join(' ', @$searchdomains);
172 $content .= " dns_search $searchdomains\n";
173 }
174
175 my @ifaces = grep { /^net(\d+)$/ } keys %$conf;
176 foreach my $iface (sort @ifaces) {
177 (my $id = $iface) =~ s/^net//;
178 next if !$conf->{"ipconfig$id"};
179 my $net = PVE::QemuServer::parse_ipconfig($conf->{"ipconfig$id"});
180 $id = "eth$id";
181
182 $content .="auto $id\n";
183 if ($net->{ip}) {
184 if ($net->{ip} eq 'dhcp') {
185 $content .= "iface $id inet dhcp\n";
186 } else {
187 my ($addr, $mask) = split_ip4($net->{ip});
188 $content .= "iface $id inet static\n";
189 $content .= " address $addr\n";
190 $content .= " netmask $mask\n";
191 $content .= " gateway $net->{gw}\n" if $net->{gw};
192 }
193 }
194 if ($net->{ip6}) {
195 if ($net->{ip6} =~ /^(auto|dhcp)$/) {
196 $content .= "iface $id inet6 $1\n";
197 } else {
198 my ($addr, $mask) = split('/', $net->{ip6});
199 $content .= "iface $id inet6 static\n";
200 $content .= " address $addr\n";
201 $content .= " netmask $mask\n";
202 $content .= " gateway $net->{gw6}\n" if $net->{gw6};
203 }
204 }
205 }
206
207 return $content;
208 }
209
210 sub configdrive2_gen_metadata {
211 my ($user, $network) = @_;
212
213 my $uuid_str = Digest::SHA::sha1_hex($user.$network);
214 return configdrive2_metadata($uuid_str);
215 }
216
217 sub configdrive2_metadata {
218 my ($uuid) = @_;
219 return <<"EOF";
220 {
221 "uuid": "$uuid",
222 "network_config": { "content_path": "/content/0000" }
223 }
224 EOF
225 }
226
227 sub generate_configdrive2 {
228 my ($conf, $vmid, $drive, $volname, $storeid) = @_;
229
230 my ($user_data, $network_data, $meta_data, $vendor_data) = get_custom_cloudinit_files($conf);
231 $user_data = cloudinit_userdata($conf, $vmid) if !defined($user_data);
232 $network_data = configdrive2_network($conf) if !defined($network_data);
233 $vendor_data = '' if !defined($vendor_data);
234
235 if (!defined($meta_data)) {
236 $meta_data = configdrive2_gen_metadata($user_data, $network_data);
237 }
238
239 # we always allocate a 4MiB disk for cloudinit and with the overhead of the ISO
240 # make sure we always stay below it by keeping the sum of all files below 3 MiB
241 my $sum = length($user_data) + length($network_data) + length($meta_data) + length($vendor_data);
242 die "Cloud-Init sum of snippets too big (> 3 MiB)\n" if $sum > (3 * 1024 * 1024);
243
244 my $files = {
245 '/openstack/latest/user_data' => $user_data,
246 '/openstack/content/0000' => $network_data,
247 '/openstack/latest/meta_data.json' => $meta_data,
248 '/openstack/latest/vendor_data.json' => $vendor_data
249 };
250 commit_cloudinit_disk($conf, $vmid, $drive, $volname, $storeid, $files, 'config-2');
251 }
252
253 sub generate_opennebula {
254 my ($conf, $vmid, $drive, $volname, $storeid) = @_;
255
256 my $content = "";
257
258 my $username = $conf->{ciuser} || "root";
259 $content .= "USERNAME=$username\n" if defined($username);
260
261 if (defined(my $password = $conf->{cipassword})) {
262 $content .= "CRYPTED_PASSWORD_BASE64=". encode_base64($password) ."\n";
263 }
264
265 if (defined($conf->{sshkeys})) {
266 my $keys = [ split(/\s*\n\s*/, URI::Escape::uri_unescape($conf->{sshkeys})) ];
267 $content .= "SSH_PUBLIC_KEY=\"". join("\n", $keys->@*) ."\"\n";
268 }
269
270 my ($hostname, $fqdn) = get_hostname_fqdn($conf, $vmid);
271 $content .= "SET_HOSTNAME=$hostname\n";
272
273 my ($searchdomains, $nameservers) = get_dns_conf($conf);
274 $content .= 'DNS="' . join(' ', @$nameservers) ."\"\n" if $nameservers && @$nameservers;
275 $content .= 'SEARCH_DOMAIN="'. join(' ', @$searchdomains) ."\"\n" if $searchdomains && @$searchdomains;
276
277 my $networkenabled = undef;
278 my @ifaces = grep { /^net(\d+)$/ } keys %$conf;
279 foreach my $iface (sort @ifaces) {
280 (my $id = $iface) =~ s/^net//;
281 my $net = PVE::QemuServer::parse_net($conf->{$iface});
282 next if !$conf->{"ipconfig$id"};
283 my $ipconfig = PVE::QemuServer::parse_ipconfig($conf->{"ipconfig$id"});
284 my $ethid = "ETH$id";
285
286 my $mac = lc $net->{hwaddr};
287
288 if ($ipconfig->{ip}) {
289 $networkenabled = 1;
290
291 if ($ipconfig->{ip} eq 'dhcp') {
292 $content .= "${ethid}_DHCP=YES\n";
293 } else {
294 my ($addr, $mask) = split_ip4($ipconfig->{ip});
295 $content .= "${ethid}_IP=$addr\n";
296 $content .= "${ethid}_MASK=$mask\n";
297 $content .= "${ethid}_MAC=$mac\n";
298 $content .= "${ethid}_GATEWAY=$ipconfig->{gw}\n" if $ipconfig->{gw};
299 }
300 $content .= "${ethid}_MTU=$net->{mtu}\n" if $net->{mtu};
301 }
302
303 if ($ipconfig->{ip6}) {
304 $networkenabled = 1;
305 if ($ipconfig->{ip6} eq 'dhcp') {
306 $content .= "${ethid}_DHCP6=YES\n";
307 } elsif ($ipconfig->{ip6} eq 'auto') {
308 $content .= "${ethid}_AUTO6=YES\n";
309 } else {
310 my ($addr, $mask) = split('/', $ipconfig->{ip6});
311 $content .= "${ethid}_IP6=$addr\n";
312 $content .= "${ethid}_MASK6=$mask\n";
313 $content .= "${ethid}_MAC6=$mac\n";
314 $content .= "${ethid}_GATEWAY6=$ipconfig->{gw6}\n" if $ipconfig->{gw6};
315 }
316 $content .= "${ethid}_MTU=$net->{mtu}\n" if $net->{mtu};
317 }
318 }
319
320 $content .= "NETWORK=YES\n" if $networkenabled;
321
322 my $files = { '/context.sh' => $content };
323 commit_cloudinit_disk($conf, $vmid, $drive, $volname, $storeid, $files, 'CONTEXT');
324 }
325
326 sub nocloud_network_v2 {
327 my ($conf) = @_;
328
329 my $content = '';
330
331 my $head = "version: 2\n"
332 . "ethernets:\n";
333
334 my $dns_done;
335
336 my @ifaces = grep { /^net(\d+)$/ } keys %$conf;
337 foreach my $iface (sort @ifaces) {
338 (my $id = $iface) =~ s/^net//;
339 next if !$conf->{"ipconfig$id"};
340
341 # indentation - network interfaces are inside an 'ethernets' hash
342 my $i = ' ';
343
344 my $net = PVE::QemuServer::parse_net($conf->{$iface});
345 my $ipconfig = PVE::QemuServer::parse_ipconfig($conf->{"ipconfig$id"});
346
347 my $mac = $net->{macaddr}
348 or die "network interface '$iface' has no mac address\n";
349
350 $content .= "${i}$iface:\n";
351 $i .= ' ';
352 $content .= "${i}match:\n"
353 . "${i} macaddress: \"$mac\"\n"
354 . "${i}set-name: eth$id\n";
355 my @addresses;
356 if (defined(my $ip = $ipconfig->{ip})) {
357 if ($ip eq 'dhcp') {
358 $content .= "${i}dhcp4: true\n";
359 } else {
360 push @addresses, $ip;
361 }
362 }
363 if (defined(my $ip = $ipconfig->{ip6})) {
364 if ($ip eq 'dhcp') {
365 $content .= "${i}dhcp6: true\n";
366 } else {
367 push @addresses, $ip;
368 }
369 }
370 if (@addresses) {
371 $content .= "${i}addresses:\n";
372 $content .= "${i}- '$_'\n" foreach @addresses;
373 }
374 if (defined(my $gw = $ipconfig->{gw})) {
375 $content .= "${i}gateway4: '$gw'\n";
376 }
377 if (defined(my $gw = $ipconfig->{gw6})) {
378 $content .= "${i}gateway6: '$gw'\n";
379 }
380
381 next if $dns_done;
382 $dns_done = 1;
383
384 my ($searchdomains, $nameservers) = get_dns_conf($conf);
385 if ($searchdomains || $nameservers) {
386 $content .= "${i}nameservers:\n";
387 if (defined($nameservers) && @$nameservers) {
388 $content .= "${i} addresses:\n";
389 $content .= "${i} - '$_'\n" foreach @$nameservers;
390 }
391 if (defined($searchdomains) && @$searchdomains) {
392 $content .= "${i} search:\n";
393 $content .= "${i} - '$_'\n" foreach @$searchdomains;
394 }
395 }
396 }
397
398 return $head.$content;
399 }
400
401 sub nocloud_network {
402 my ($conf) = @_;
403
404 my $content = "version: 1\n"
405 . "config:\n";
406
407 my @ifaces = grep { /^net(\d+)$/ } keys %$conf;
408 foreach my $iface (sort @ifaces) {
409 (my $id = $iface) =~ s/^net//;
410 next if !$conf->{"ipconfig$id"};
411
412 # indentation - network interfaces are inside an 'ethernets' hash
413 my $i = ' ';
414
415 my $net = PVE::QemuServer::parse_net($conf->{$iface});
416 my $ipconfig = PVE::QemuServer::parse_ipconfig($conf->{"ipconfig$id"});
417
418 my $mac = lc($net->{macaddr})
419 or die "network interface '$iface' has no mac address\n";
420
421 $content .= "${i}- type: physical\n"
422 . "${i} name: eth$id\n"
423 . "${i} mac_address: '$mac'\n"
424 . "${i} subnets:\n";
425 $i .= ' ';
426 if (defined(my $ip = $ipconfig->{ip})) {
427 if ($ip eq 'dhcp') {
428 $content .= "${i}- type: dhcp4\n";
429 } else {
430 my ($addr, $mask) = split_ip4($ip);
431 $content .= "${i}- type: static\n"
432 . "${i} address: '$addr'\n"
433 . "${i} netmask: '$mask'\n";
434 if (defined(my $gw = $ipconfig->{gw})) {
435 $content .= "${i} gateway: '$gw'\n";
436 }
437 }
438 }
439 if (defined(my $ip = $ipconfig->{ip6})) {
440 if ($ip eq 'dhcp') {
441 $content .= "${i}- type: dhcp6\n";
442 } elsif ($ip eq 'auto') {
443 # SLAAC is only supported by cloud-init since 19.4
444 $content .= "${i}- type: ipv6_slaac\n";
445 } else {
446 $content .= "${i}- type: static6\n"
447 . "${i} address: '$ip'\n";
448 if (defined(my $gw = $ipconfig->{gw6})) {
449 $content .= "${i} gateway: '$gw'\n";
450 }
451 }
452 }
453 }
454
455 my $i = ' ';
456 my ($searchdomains, $nameservers) = get_dns_conf($conf);
457 if ($searchdomains || $nameservers) {
458 $content .= "${i}- type: nameserver\n";
459 if (defined($nameservers) && @$nameservers) {
460 $content .= "${i} address:\n";
461 $content .= "${i} - '$_'\n" foreach @$nameservers;
462 }
463 if (defined($searchdomains) && @$searchdomains) {
464 $content .= "${i} search:\n";
465 $content .= "${i} - '$_'\n" foreach @$searchdomains;
466 }
467 }
468
469 return $content;
470 }
471
472 sub nocloud_metadata {
473 my ($uuid) = @_;
474 return "instance-id: $uuid\n";
475 }
476
477 sub nocloud_gen_metadata {
478 my ($user, $network) = @_;
479
480 my $uuid_str = Digest::SHA::sha1_hex($user.$network);
481 return nocloud_metadata($uuid_str);
482 }
483
484 sub generate_nocloud {
485 my ($conf, $vmid, $drive, $volname, $storeid) = @_;
486
487 my ($user_data, $network_data, $meta_data, $vendor_data) = get_custom_cloudinit_files($conf);
488 $user_data = cloudinit_userdata($conf, $vmid) if !defined($user_data);
489 $network_data = nocloud_network($conf) if !defined($network_data);
490 $vendor_data = '' if !defined($vendor_data);
491
492 if (!defined($meta_data)) {
493 $meta_data = nocloud_gen_metadata($user_data, $network_data);
494 }
495
496 # we always allocate a 4MiB disk for cloudinit and with the overhead of the ISO
497 # make sure we always stay below it by keeping the sum of all files below 3 MiB
498 my $sum = length($user_data) + length($network_data) + length($meta_data) + length($vendor_data);
499 die "Cloud-Init sum of snippets too big (> 3 MiB)\n" if $sum > (3 * 1024 * 1024);
500
501 my $files = {
502 '/user-data' => $user_data,
503 '/network-config' => $network_data,
504 '/meta-data' => $meta_data,
505 '/vendor-data' => $vendor_data
506 };
507 commit_cloudinit_disk($conf, $vmid, $drive, $volname, $storeid, $files, 'cidata');
508 }
509
510 sub get_custom_cloudinit_files {
511 my ($conf) = @_;
512
513 my $cicustom = $conf->{cicustom};
514 my $files = $cicustom ? PVE::JSONSchema::parse_property_string('pve-qm-cicustom', $cicustom) : {};
515
516 my $network_volid = $files->{network};
517 my $user_volid = $files->{user};
518 my $meta_volid = $files->{meta};
519 my $vendor_volid = $files->{vendor};
520
521 my $storage_conf = PVE::Storage::config();
522
523 my $network_data;
524 if ($network_volid) {
525 $network_data = read_cloudinit_snippets_file($storage_conf, $network_volid);
526 }
527
528 my $user_data;
529 if ($user_volid) {
530 $user_data = read_cloudinit_snippets_file($storage_conf, $user_volid);
531 }
532
533 my $meta_data;
534 if ($meta_volid) {
535 $meta_data = read_cloudinit_snippets_file($storage_conf, $meta_volid);
536 }
537
538 my $vendor_data;
539 if ($vendor_volid) {
540 $vendor_data = read_cloudinit_snippets_file($storage_conf, $vendor_volid);
541 }
542
543 return ($user_data, $network_data, $meta_data, $vendor_data);
544 }
545
546 sub read_cloudinit_snippets_file {
547 my ($storage_conf, $volid) = @_;
548
549 my ($full_path, undef, $type) = PVE::Storage::path($storage_conf, $volid);
550 die "$volid is not in the snippets directory\n" if $type ne 'snippets';
551 return PVE::Tools::file_get_contents($full_path, 1 * 1024 * 1024);
552 }
553
554 my $cloudinit_methods = {
555 configdrive2 => \&generate_configdrive2,
556 nocloud => \&generate_nocloud,
557 opennebula => \&generate_opennebula,
558 };
559
560 sub generate_cloudinitconfig {
561 my ($conf, $vmid) = @_;
562
563 my $format = get_cloudinit_format($conf);
564
565 PVE::QemuConfig->foreach_volume($conf, sub {
566 my ($ds, $drive) = @_;
567
568 my ($storeid, $volname) = PVE::Storage::parse_volume_id($drive->{file}, 1);
569
570 return if !$volname || $volname !~ m/vm-$vmid-cloudinit/;
571
572 my $generator = $cloudinit_methods->{$format}
573 or die "missing cloudinit methods for format '$format'\n";
574
575 $generator->($conf, $vmid, $drive, $volname, $storeid);
576 });
577 }
578
579 sub dump_cloudinit_config {
580 my ($conf, $vmid, $type) = @_;
581
582 my $format = get_cloudinit_format($conf);
583
584 if ($type eq 'user') {
585 return cloudinit_userdata($conf, $vmid);
586 } elsif ($type eq 'network') {
587 if ($format eq 'nocloud') {
588 return nocloud_network($conf);
589 } else {
590 return configdrive2_network($conf);
591 }
592 } else { # metadata config
593 my $user = cloudinit_userdata($conf, $vmid);
594 if ($format eq 'nocloud') {
595 my $network = nocloud_network($conf);
596 return nocloud_gen_metadata($user, $network);
597 } else {
598 my $network = configdrive2_network($conf);
599 return configdrive2_gen_metadata($user, $network);
600 }
601 }
602 }
603
604 1;