Implement and make use of robust list functions.
[live-boot-grml.git] / scripts / live-helpers
index 442f749..2fcf441 100644 (file)
@@ -15,14 +15,13 @@ else
        udevinfo='udevinfo'
 fi
 
-root_overlay_label="full-ov"
 old_root_overlay_label="live-rw"
 old_home_overlay_label="home-rw"
 custom_overlay_label="custom-ov"
 root_snapshot_label="live-sn"
 old_root_snapshot_label="live-sn"
 home_snapshot_label="home-sn"
-persistence_list="live.persist"
+persistence_list="live-persistence.conf"
 
 Arguments ()
 {
@@ -89,9 +88,14 @@ Arguments ()
                                export FETCH
                                ;;
 
-                       forcepersistentfsck)
-                               FORCEPERSISTENTFSCK="Yes"
-                               export FORCEPERSISTENTFSCK
+                       findiso=*)
+                               FINDISO="${ARGUMENT#findiso=}"
+                               export FINDISO
+                               ;;
+
+                       forcepersistencefsck)
+                               FORCEPERSISTENCEFSCK="Yes"
+                               export FORCEPERSISTENCEFSCK
                                ;;
 
                        ftpfs=*)
@@ -188,8 +192,8 @@ Arguments ()
                                export NFSOPTS
                                ;;
 
-                       nfscow=*)
-                               NFS_COW="${ARGUMENT#nfscow=}"
+                       nfsoverlay=*)
+                               NFS_COW="${ARGUMENT#nfsoverlay=}"
                                export NFS_COW
                                ;;
 
@@ -222,52 +226,51 @@ Arguments ()
                                export SWAPON
                                ;;
 
-                       persistent)
-                               PERSISTENT="Yes"
-                               export PERSISTENT
+                       persistence)
+                               PERSISTENCE="Yes"
+                               export PERSISTENCE
                                ;;
 
-                       persistent-encryption=*)
-                               PERSISTENT_ENCRYPTION="${ARGUMENT#*=}"
-                               export PERSISTENT_ENCRYPTION
+                       persistence-encryption=*)
+                               PERSISTENCE_ENCRYPTION="${ARGUMENT#*=}"
+                               export PERSISTENCE_ENCRYPTION
                                ;;
 
-                       persistent-media=*)
-                               PERSISTENT_MEDIA="${ARGUMENT#*=}"
-                               export PERSISTENT_MEDIA
+                       persistence-media=*)
+                               PERSISTENCE_MEDIA="${ARGUMENT#*=}"
+                               export PERSISTENCE_MEDIA
                                ;;
-                       persistent-method=*)
-                               PERSISTENT_METHOD="${ARGUMENT#*=}"
-                               export PERSISTENT_METHOD
+                       persistence-method=*)
+                               PERSISTENCE_METHOD="${ARGUMENT#*=}"
+                               export PERSISTENCE_METHOD
                                ;;
 
-                       persistent-path=*)
-                               PERSISTENT_PATH="${ARGUMENT#persistent-path=}"
-                               export PERSISTENT_PATH
+                       persistence-path=*)
+                               PERSISTENCE_PATH="${ARGUMENT#persistence-path=}"
+                               export PERSISTENCE_PATH
                                ;;
-                       persistent-read-only)
-                               PERSISTENT_READONLY="Yes"
-                               export PERSISTENT_READONLY
+                       persistence-read-only)
+                               PERSISTENCE_READONLY="Yes"
+                               export PERSISTENCE_READONLY
                                ;;
 
-                       persistent-storage=*)
-                               PERSISTENT_STORAGE="${ARGUMENT#persistent-storage=}"
-                               export PERSISTENT_STORAGE
+                       persistence-storage=*)
+                               PERSISTENCE_STORAGE="${ARGUMENT#persistence-storage=}"
+                               export PERSISTENCE_STORAGE
                                ;;
 
-                       persistent-subtext=*)
-                               root_overlay_label="${root_overlay_label}-${ARGUMENT#persistent-subtext=}"
-                               old_root_overlay_label="${old_root_overlay_label}-${ARGUMENT#persistent-subtext=}"
-                               old_home_overlay_label="${old_home_overlay_label}-${ARGUMENT#persistent-subtext=}"
-                               custom_overlay_label="${custom_overlay_label}-${ARGUMENT#persistent-subtext=}"
-                               root_snapshot_label="${root_snapshot_label}-${ARGUMENT#persistent-subtext=}"
-                               old_root_snapshot_label="${root_snapshot_label}-${ARGUMENT#persistent-subtext=}"
-                               home_snapshot_label="${home_snapshot_label}-${ARGUMENT#persistent-subtext=}"
+                       persistence-subtext=*)
+                               old_root_overlay_label="${old_root_overlay_label}-${ARGUMENT#persistence-subtext=}"
+                               old_home_overlay_label="${old_home_overlay_label}-${ARGUMENT#persistence-subtext=}"
+                               custom_overlay_label="${custom_overlay_label}-${ARGUMENT#persistence-subtext=}"
+                               root_snapshot_label="${root_snapshot_label}-${ARGUMENT#persistence-subtext=}"
+                               old_root_snapshot_label="${root_snapshot_label}-${ARGUMENT#persistence-subtext=}"
+                               home_snapshot_label="${home_snapshot_label}-${ARGUMENT#persistence-subtext=}"
                                ;;
 
-                       nopersistent)
-                               NOPERSISTENT="Yes"
-                               export NOPERSISTENT
+                       nopersistence)
+                               NOPERSISTENCE="Yes"
+                               export NOPERSISTENCE
                                ;;
 
                        noprompt)
@@ -381,40 +384,61 @@ Arguments ()
                export UNIONTYPE
        fi
 
-       if [ -z "${PERSISTENT_ENCRYPTION}" ]
+       if [ -z "${PERSISTENCE_ENCRYPTION}" ]
        then
-               PERSISTENT_ENCRYPTION="none"
-               export PERSISTENT_ENCRYPTION
-       elif echo ${PERSISTENT_ENCRYPTION} | grep -qe "\<luks\>"
+               PERSISTENCE_ENCRYPTION="none"
+               export PERSISTENCE_ENCRYPTION
+       elif is_in_comma_sep_list luks ${PERSISTENCE_ENCRYPTION}
        then
                if ! modprobe dm-crypt
                then
                        log_warning_msg "Unable to load module dm-crypt"
-                       PERSISTENT_ENCRYPTION=$(echo ${PERSISTENT_ENCRYPTION} | sed -e 's/\<luks,\|,\?luks$//g')
-                       export PERSISTENT_ENCRYPTION
+                       PERSISTENCE_ENCRYPTION=$(echo ${PERSISTENCE_ENCRYPTION} | sed -e 's/\<luks,\|,\?luks$//g')
+                       export PERSISTENCE_ENCRYPTION
                fi
 
                if [ ! -x /lib/cryptsetup/askpass ] || [ ! -x /sbin/cryptsetup ]
                then
                        log_warning_msg "cryptsetup in unavailable"
-                       PERSISTENT_ENCRYPTION=$(echo ${PERSISTENT_ENCRYPTION} | sed -e 's/\<luks,\|,\?luks$//g')
-                       export PERSISTENT_ENCRYPTION
+                       PERSISTENCE_ENCRYPTION=$(echo ${PERSISTENCE_ENCRYPTION} | sed -e 's/\<luks,\|,\?luks$//g')
+                       export PERSISTENCE_ENCRYPTION
                fi
        fi
 
-       if [ -z "${PERSISTENT_METHOD}" ]
+       if [ -z "${PERSISTENCE_METHOD}" ]
        then
-               PERSISTENT_METHOD="snapshot,overlay"
-               export PERSISTENT_METHOD
+               PERSISTENCE_METHOD="snapshot,overlay"
+               export PERSISTENCE_METHOD
        fi
 
-       if [ -z "${PERSISTENT_STORAGE}" ]
+       if [ -z "${PERSISTENCE_STORAGE}" ]
        then
-               PERSISTENT_STORAGE="filesystem,file"
-               export PERSISTENT_STORAGE
+               PERSISTENCE_STORAGE="filesystem,file"
+               export PERSISTENCE_STORAGE
        fi
 }
 
+is_in_list_separator_helper () {
+       local sep=${1}
+       shift
+       local element=${1}
+       shift
+       local list=${*}
+       echo ${list} | grep -qe "^\(.*${sep}\)\?${element}\(${sep}.*\)\?$"
+}
+
+is_in_space_sep_list () {
+       local element=${1}
+       shift
+       is_in_list_separator_helper "[[:space:]]" "${element}" "${*}"
+}
+
+is_in_comma_sep_list () {
+       local element=${1}
+       shift
+       is_in_list_separator_helper "," "${element}" "${*}"
+}
+
 sys2dev ()
 {
        sysdev=${1#/sys}
@@ -446,9 +470,9 @@ storage_devices()
        do
                fulldevname=$(sys2dev "${sysblock}")
 
-               if echo "${black_listed_devices}" | grep -qe "\<${fulldevname}\>" || \
+               if is_in_space_sep_list ${fulldevname} ${black_listed_devices} || \
                        [ -n "${white_listed_devices}" ] && \
-                       echo "${white_listed_devices}" | grep -qve "\<${fulldevname}\>"
+                       ! is_in_space_sep_list ${fulldevname} ${white_listed_devices}
                then
                        # skip this device entirely
                        continue
@@ -458,7 +482,7 @@ storage_devices()
                do
                        devname=$(sys2dev "${dev}")
 
-                       if echo "${black_listed_devices}" | grep -qe "\<${devname}\>"
+                       if is_in_space_sep_list ${devname} ${black_listed_devices}
                        then
                                # skip this subdevice
                                continue
@@ -519,8 +543,9 @@ where_is_mounted ()
 }
 
 trim_path () {
-    # remove all unnecessary /:s in the path, including last
-    echo ${1} | sed 's|//|/|g' | sed 's|/$||'
+    # remove all unnecessary /:s in the path, including last one (except
+    # if path is just "/")
+    echo ${1} | sed 's|//\+|/|g' | sed 's|^\(.*[^/]\)/$|\1|'
 }
 
 what_is_mounted_on ()
@@ -529,6 +554,24 @@ what_is_mounted_on ()
        grep -m1 "^[^ ]\+ ${dir} " /proc/mounts | cut -d' ' -f1
 }
 
+chown_ref ()
+{
+       local reference="${1}"
+       shift
+       local targets=${@}
+       local owner=$(stat -c %u:%g "${reference}")
+       chown -h ${owner} ${targets}
+}
+
+chmod_ref ()
+{
+       local reference="${1}"
+       shift
+       local targets=${@}
+       local rights=$(stat -c %a "${reference}")
+       chmod ${rights} ${targets}
+}
+
 lastline ()
 {
        while read lines
@@ -714,23 +757,16 @@ try_mount ()
                        fstype=$(get_fstype "${dev}")
                fi
                mount -t "${fstype}" -o "${opts}" "${dev}" "${mountp}" || \
-               ( echo "SKIPPING: Cannot mount ${dev} on ${mountp}, fstype=${fstype}, options=${opts}" > live-boot.log && return 0 )
+               ( echo "SKIPPING: Cannot mount ${dev} on ${mountp}, fstype=${fstype}, options=${opts}" > boot.log && return 0 )
        fi
 }
 
-mount_persistent_media ()
+mount_persistence_media ()
 {
        local device=${1}
-       local backing=""
+       local probe=${2}
 
-       # We can't mount into ${rootmnt}/live before ${rootmnt} has been
-       # mounted since that would cover our mountpoint.
-       if [ -n "${rootmnt}" ] && [ -z "$(what_is_mounted_on ${rootmnt})" ]
-       then
-               backing="/$(basename ${device})-backing"
-       else
-               backing="${rootmnt}/live/persistent/$(basename ${device})"
-       fi
+       local backing="/live/persistence/$(basename ${device})"
 
        mkdir -p "${backing}"
        local old_backing="$(where_is_mounted ${device})"
@@ -738,7 +774,7 @@ mount_persistent_media ()
        then
                local fstype="$(get_fstype ${device})"
                local mount_opts="rw,noatime"
-               if [ -n "${PERSISTENT_READONLY}" ]
+               if [ -n "${PERSISTENCE_READONLY}" ]
                then
                        mount_opts="ro,noatime"
                fi
@@ -747,7 +783,8 @@ mount_persistent_media ()
                        echo ${backing}
                        return 0
                else
-                       log_warning_msg "Failed to mount persistent media ${device}"
+                       [ -z "${probe}" ] && log_warning_msg "Failed to mount persistence media ${device}"
+                       rmdir "${backing}"
                        return 1
                fi
        elif [ "${backing}" != "${old_backing}" ]
@@ -757,14 +794,15 @@ mount_persistent_media ()
                        echo ${backing}
                        return 0
                else
-                       log_warning_msg "Failed to move persistent media ${device}"
+                       [ -z "${probe}" ] && log_warning_msg "Failed to move persistence media ${device}"
+                       rmdir "${backing}"
                        return 1
                fi
        fi
        return 0
 }
 
-close_persistent_media () {
+close_persistence_media () {
        local device=${1}
        local backing="$(where_is_mounted ${device})"
 
@@ -785,7 +823,7 @@ open_luks_device ()
        dev="${1}"
        name="$(basename ${dev})"
        opts="--key-file=-"
-       if [ -n "${PERSISTENT_READONLY}" ]
+       if [ -n "${PERSISTENCE_READONLY}" ]
        then
                opts="${opts} --readonly"
        fi
@@ -893,7 +931,7 @@ probe_for_file_name ()
        local dev="${3}"
 
        local ret=""
-       local backing="$(mount_persistent_media ${dev})"
+       local backing="$(mount_persistence_media ${dev} probe)"
        if [ -z "${backing}" ]
        then
            return
@@ -901,7 +939,7 @@ probe_for_file_name ()
 
        for label in ${overlays}
        do
-               path=${backing}/${PERSISTENT_PATH}${label}
+               path=${backing}/${PERSISTENCE_PATH}${label}
                if [ -f "${path}" ]
                then
                        local loopdev=$(setup_loop "${path}" "loop" "/sys/block/loop*")
@@ -912,7 +950,7 @@ probe_for_file_name ()
        do
                for ext in squashfs cpio.gz ext2 ext3 ext4 jffs2
                do
-                       path="${PERSISTENT_PATH}${label}.${ext}"
+                       path="${PERSISTENCE_PATH}${label}.${ext}"
                        if [ -f "${backing}/${path}" ]
                        then
                                ret="${ret} ${label}=${dev}:${backing}:${path}"
@@ -928,7 +966,7 @@ probe_for_file_name ()
        fi
 }
 
-find_persistent_media ()
+find_persistence_media ()
 {
        # Scans devices for overlays and snapshots, and returns a whitespace
        # separated list of how to use them. Only overlays with a partition
@@ -936,7 +974,7 @@ find_persistent_media ()
        # snapshots with labels in ${snapshots}.
        #
        # When scanning a LUKS device, the user will be asked to enter the
-       # passphrase; on failure to enter it, or if no persistent partitions
+       # passphrase; on failure to enter it, or if no persistence partitions
        # or files were found, the LUKS device is closed.
        #
        # For a snapshot file the return value is ${label}=${snapdata}", where
@@ -956,7 +994,9 @@ find_persistent_media ()
        local white_listed_devices="${3}"
        local ret=""
 
-       for dev in $(storage_devices "" "${white_listed_devices}")
+       local black_listed_devices="$(what_is_mounted_on /live/image)"
+
+       for dev in $(storage_devices "${black_listed_devices}" "${white_listed_devices}")
        do
                local result=""
 
@@ -965,7 +1005,7 @@ find_persistent_media ()
                # in order to probe any filesystem it contains, like we do
                # below. activate_custom_mounts() also depends on that any luks
                # device already has been opened.
-               if echo ${PERSISTENT_ENCRYPTION} | grep -qe "\<luks\>" && \
+               if is_in_comma_sep_list luks ${PERSISTENCE_ENCRYPTION} && \
                   is_luks_partition ${dev}
                then
                        if luks_device=$(open_luks_device "${dev}")
@@ -975,14 +1015,14 @@ find_persistent_media ()
                                # skip $dev since we failed/chose not to open it
                                continue
                        fi
-               elif echo ${PERSISTENT_ENCRYPTION} | grep -qve "\<none\>"
+               elif ! is_in_comma_sep_list none ${PERSISTENCE_ENCRYPTION}
                then
                        # skip $dev since we don't allow unencrypted storage
                        continue
                fi
 
                # Probe for matching GPT partition names or filesystem labels
-               if echo ${PERSISTENT_STORAGE} | grep -qe "\<filesystem\>"
+               if is_in_comma_sep_list filesystem ${PERSISTENCE_STORAGE}
                then
                        result=$(probe_for_gpt_name "${overlays}" "${snapshots}" ${dev})
                        if [ -n "${result}" ]
@@ -1000,7 +1040,7 @@ find_persistent_media ()
                fi
 
                # Probe for files with matching name on mounted partition
-               if echo ${PERSISTENT_STORAGE} | grep -qe "\<file\>"
+               if is_in_comma_sep_list file ${PERSISTENCE_STORAGE}
                then
                        result=$(probe_for_file_name "${overlays}" "${snapshots}" ${dev})
                        if [ -n "${result}" ]
@@ -1139,8 +1179,8 @@ link_files ()
        # live-boot normally does (into $rootmnt)).
 
        # remove multiple /:s and ensure ending on /
-       local src_dir="$(echo "${1}"/ | sed -e 's|/\+|/|g')"
-       local dest_dir="$(echo "${2}"/ | sed -e 's|/\+|/|g')"
+       local src_dir="$(trim_path ${1})/"
+       local dest_dir="$(trim_path ${2})/"
        local src_mask="${3}"
 
        # This check can only trigger on the inital, non-recursive call since
@@ -1162,18 +1202,19 @@ link_files ()
                        if [ ! -d "${dest}" ]
                        then
                                mkdir -p "${dest}"
-                               prev="$(dirname "${dest}")"
-                               chown --reference "${prev}" "${dest}"
-                               chmod --reference "${prev}" "${dest}"
+                               chown_ref "${src}" "${dest}"
+                               chmod_ref "${src}" "${dest}"
                        fi
                        link_files "${src}" "${dest}" "${src_mask}"
                else
+                       local final_src=${src}
                        if [ -n "${src_mask}" ]
                        then
-                               src="$(echo ${src} | sed "s|^${src_mask}||")"
+                               final_src="$(echo ${final_src} | sed "s|^${src_mask}||")"
                        fi
                        rm -rf "${dest}" 2> /dev/null
-                       ln -s "${src}" "${dest}"
+                       ln -s "${final_src}" "${dest}"
+                       chown_ref "${src}" "${dest}"
                fi
        done
 }
@@ -1241,7 +1282,7 @@ do_union ()
 
 get_custom_mounts ()
 {
-       # Side-effect: leaves $devices with live.persist mounted in ${rootmnt}/live/persistent
+       # Side-effect: leaves $devices with live-persistence.conf mounted in /live/persistence
        # Side-effect: prints info to file $custom_mounts
 
        local custom_mounts=${1}
@@ -1260,7 +1301,7 @@ get_custom_mounts ()
                fi
 
                local device_name="$(basename ${device})"
-               local backing=$(mount_persistent_media ${device})
+               local backing=$(mount_persistence_media ${device})
                if [ -z "${backing}" ]
                then
                        continue
@@ -1274,38 +1315,35 @@ get_custom_mounts ()
 
                if [ -n "${DEBUG}" ] && [ -e "${include_list}" ]
                then
-                       cp ${include_list} ${rootmnt}/live/persistent/${persistence_list}.${device_name}
+                       cp ${include_list} /live/persistence/${persistence_list}.${device_name}
                fi
 
-               while read source dest options # < ${include_list}
+               while read dir options # < ${include_list}
                do
-                       if echo ${source} | grep -qe "^[[:space:]]*\(#.*\)\?$"
+                       if echo ${dir} | grep -qe "^[[:space:]]*\(#.*\)\?$"
                        then
                                # skipping empty or commented lines
                                continue
                        fi
 
-                       if [ -z "${dest}" ]
+                       if trim_path ${dir} | grep -q -e "^[^/]" -e "^/live\(/.*\)\?$" -e "^/\(.*/\)\?\.\.\?\(/.*\)\?$"
                        then
-                               dest="${source}"
-                       fi
-
-                       if trim_path ${source} | grep -q -e "^[^/]" -e "^\(.*/\)\?\.\.\?\(/.*\)\?$"
-                       then
-                               log_warning_msg "Skipping unsafe custom mount with source ${source}: the source must be an absolute path w.r.t. the persistent media root and cannot contain \".\" or \"..\""
-                               continue
-                       fi
-
-                       if trim_path ${dest} | grep -q -e "^[^/]" -e "^/$" -e "^/live\(/.*\)\?$" -e "^/\(.*/\)\?\.\.\?\(/.*\)\?$"
-                       then
-                               log_warning_msg "Skipping unsafe custom mount with desination ${dest}: the destination must be an absolute path containing neither \".\" nor \"..\", and cannot be /live (or any sub-directory therein) or / (for the latter, use ${root_overlay_label}-type persistence instead)"
+                               log_warning_msg "Skipping unsafe custom mount ${dir}: must be an absolute path containing neither the \".\" nor \"..\" special dirs, and cannot be \"/live\" or any sub-directory therein."
                                continue
                        fi
 
+                       local opt_source=""
+                       local opt_link=""
                        for opt in $(echo ${options} | tr ',' ' ');
                        do
                                case "${opt}" in
-                                       linkfiles|union)
+                                       source=*)
+                                               opt_source=${opt#source=}
+                                               ;;
+                                       link)
+                                               opt_link="yes"
+                                               ;;
+                                       union|bind)
                                                ;;
                                        *)
                                                log_warning_msg "Skipping custom mount with unkown option: ${opt}"
@@ -1314,10 +1352,21 @@ get_custom_mounts ()
                                esac
                        done
 
-                       # ensure that no multiple-/ occur in paths
+                       local source="${dir}"
+                       if [ -n "${opt_source}" ]
+                       then
+                               if echo ${opt_source} | grep -q -e "^/" -e "^\(.*/\)\?\.\.\?\(/.*\)\?$" && [ "${source}" != "." ]
+                               then
+                                       log_warning_msg "Skipping unsafe custom mount with option source=${opt_source}: must be either \".\" (the media root) or a relative path w.r.t. the media root that contains neither comas, nor the special \".\" and \"..\" path components"
+                                       continue
+                               else
+                                       source="${opt_source}"
+                               fi
+                       fi
+
                        local full_source="$(trim_path ${backing}/${source})"
-                       local full_dest="$(trim_path ${rootmnt}/${dest})"
-                       if echo ${options} | grep -qe "\<linkfiles\>";
+                       local full_dest="$(trim_path ${rootmnt}/${dir})"
+                       if [ -n "${opt_link}" ]
                        then
                                echo "${device} ${full_source} ${full_dest} ${options}" >> ${links}
                        else
@@ -1333,7 +1382,24 @@ get_custom_mounts ()
 
        # After all mounts are considered we add symlinks so they
        # won't be hidden by some mount.
-       [ -e "${links}" ] && sort -k3 -sbu ${links} >> ${custom_mounts} && rm ${links}
+       [ -e "${links}" ] && cat ${links} >> ${custom_mounts} && rm ${links}
+
+       # We need to make sure that no two custom mounts have the same sources
+       # or are nested; if that is the case, too much weird stuff can happen.
+       local prev_source="impossible source" # first iteration must not match
+       local prev_dest=""
+       # This sort will ensure that a source /a comes right before a source
+       # /a/b so we only need to look at the previous source
+       sort -k2 -b ${custom_mounts} |
+       while read device source dest options
+       do
+               if echo ${source} | grep -qe "^${prev_source}\(/.*\)\?$"
+               then
+                       panic "Two persistence mounts have the same or nested sources: ${source} on ${dest}, and ${prev_source} on ${prev_dest}"
+               fi
+               prev_source=${source}
+               prev_dest=${dest}
+       done
 }
 
 activate_custom_mounts ()
@@ -1343,128 +1409,161 @@ activate_custom_mounts ()
 
        while read device source dest options # < ${custom_mounts}
        do
-               local opt_linkfiles=""
+               local opt_bind="yes"
+               local opt_link=""
                local opt_union=""
                for opt in $(echo ${options} | tr ',' ' ');
                do
-                        case "${opt}" in
-                               linkfiles)
-                                       opt_linkfiles="yes"
+                       case "${opt}" in
+                               bind)
+                                       opt_bind="yes"
+                                       unset opt_link opt_union
+                                       ;;
+                               link)
+                                       opt_link="yes"
+                                       unset opt_bind opt_union
                                        ;;
                                union)
                                        opt_union="yes"
+                                       unset opt_bind opt_link
                                        ;;
                        esac
                done
 
                if [ -n "$(what_is_mounted_on "${dest}")" ]
                then
-                       log_warning_msg "Skipping custom mount ${source} on ${dest}: $(what_is_mounted_on "${dest}") is already mounted there"
-                       continue
+                       if [ "${dest}" = "${rootmnt}" ]
+                       then
+                               umount "${dest}"
+                       else
+                               log_warning_msg "Skipping custom mount ${dest}: $(what_is_mounted_on "${dest}") is already mounted there"
+                               continue
+                       fi
                fi
 
-               # FIXME: we don't handle already existing
-               # non-directory files in the paths of both $source and
-               # $dest.
-
                if [ ! -d "${dest}" ]
                then
-                       # if ${dest} is in /home/$user, try fixing
-                       # proper ownership
-                       # FIXME: this should really be handled by
-                       # live-config since we don't know for sure
-                       # which uid a certain user has until then
-                       if trim_path ${dest} | grep -qe "^${rootmnt}/*home/[^/]\+"
-                       then
-                               path="/"
-                               for dir in $(echo ${dest} | sed -e 's|/\+| |g')
-                               do
-                                       path=${path}/${dir}
-                                       if [ ! -e ${path} ]
+                       # create the destination and delete existing files in
+                       # its path that are in the way
+                       path="/"
+                       for dir in $(echo ${dest} | sed -e 's|/\+| |g')
+                       do
+                               path=$(trim_path ${path}/${dir})
+                               if [ -f ${path} ]
+                               then
+                                       rm -f ${path}
+                               fi
+                               if [ ! -e ${path} ]
+                               then
+                                       mkdir -p ${path}
+                                       if echo ${path} | grep -qe "^${rootmnt}/*home/[^/]\+"
                                        then
-                                               mkdir -p ${path}
-                                               # assume that the intended user is the first, which is usually the case
+                                               # if ${dest} is in /home try fixing proper ownership by assuming that the intended user is the first, which is usually the case
+                                               # FIXME: this should really be handled by live-config since we don't know for sure which uid a certain user has until then
                                                chown 1000:1000 ${path}
                                        fi
-                               done
-                       else
-                               mkdir -p ${dest}
-                       fi
+                               fi
+                       done
                fi
 
-               # if ${source} doesn't exist on our persistent media
+               # if ${source} doesn't exist on our persistence media
                # we bootstrap it with $dest from the live filesystem.
                # this both makes sense and is critical if we're
                # dealing with /etc or other system dir.
                if [ ! -d "${source}" ]
                then
-                       if [ -n "${PERSISTENT_READONLY}" ] || [ -n "${opt_linkfiles}" ]
+                       if [ -n "${PERSISTENCE_READONLY}" ]
                        then
                                continue
-                       elif [ -n "${opt_union}" ]
+                       elif [ -n "${opt_union}" ] || [ -n "${opt_link}" ]
+                       then
+                               # unions and don't need to be bootstrapped
+                               # link dirs can't be bootstrapped in a sensible way
+                               mkdir -p "${source}"
+                               chown_ref "${dest}" "${source}"
+                               chmod_ref "${dest}" "${source}"
+                       elif [ -n "${opt_bind}" ]
                        then
-                               # union's don't need to be bootstrapped
-                               mkdir "${source}"
-                       else
                                # ensure that $dest is not copied *into* $source
                                mkdir -p "$(dirname ${source})"
                                cp -a "${dest}" "${source}"
                        fi
                fi
 
-               rofs_dest_backing=""
-               for d in ${rootmnt}/live/rofs/*
-               do
-                       if [ -n "${rootmnt}" ]
-                       then
-                               rofs_dest_backing="${d}/$(echo ${dest} | sed -e "s|${rootmnt}||")"
-                       else
-                               rofs_dest_backing="${d}/${dest}"
-                       fi
-                       if [ -d "${rofs_dest_backing}" ]
-                       then
-                               break
-                       else
-                               rofs_dest_backing=""
-                       fi
-               done
+               # XXX: If CONFIG_AUFS_ROBR is added to the Debian kernel we can
+               # ignore the loop below and set rofs_dest_backing=$dest
+               local rofs_dest_backing=""
+               if [ -n "${opt_link}"]
+               then
+                       for d in /live/rofs/*
+                       do
+                               if [ -n "${rootmnt}" ]
+                               then
+                                       rofs_dest_backing="${d}/$(echo ${dest} | sed -e "s|${rootmnt}||")"
+                               else
+                                       rofs_dest_backing="${d}/${dest}"
+                               fi
+                               if [ -d "${rofs_dest_backing}" ]
+                               then
+                                       break
+                               else
+                                       rofs_dest_backing=""
+                               fi
+                       done
+               fi
 
-               if [ -z "${PERSISTENT_READONLY}" ]
+               if [ -n "${opt_link}" ] && [ -z "${PERSISTENCE_READONLY}" ]
                then
-                       if [ -n "${opt_linkfiles}" ]
-                       then
-                               links_source="${source}"
-                               links_dest="${dest}"
-                       elif [ -n "${opt_union}" ]
+                       link_files ${source} ${dest} ${rootmnt}
+               elif [ -n "${opt_link}" ] && [ -n "${PERSISTENCE_READONLY}" ]
+               then
+                       mkdir -p /live/persistence
+                       local links_source=$(mktemp -d /live/persistence/links-source-XXXXXX)
+                       chown_ref ${source} ${links_source}
+                       chmod_ref ${source} ${links_source}
+                       # We put the cow dir in the below strange place to
+                       # make it absolutely certain that the link source
+                       # has its own directory and isn't nested with some
+                       # other custom mount (if so that mount's files would
+                       # be linked, causing breakage.
+                       local cow_dir="/live/overlay/live/persistence/$(basename ${links_source})"
+                       mkdir -p ${cow_dir}
+                       chown_ref "${source}" "${cow_dir}"
+                       chmod_ref "${source}" "${cow_dir}"
+                       do_union ${links_source} ${cow_dir} ${source} ${rofs_dest_backing}
+                       link_files ${links_source} ${dest} ${rootmnt}
+               elif [ -n "${opt_union}" ] && [ -z "${PERSISTENCE_READONLY}" ]
+               then
+                       do_union ${dest} ${source} ${rofs_dest_backing}
+               elif [ -n "${opt_bind}" ] && [ -z "${PERSISTENCE_READONLY}" ]
+               then
+                       mount --bind "${source}" "${dest}"
+               elif [ -n "${opt_bind}" -o -n "${opt_union}" ] && [ -n "${PERSISTENCE_READONLY}" ]
+               then
+                       # bind-mount and union mount are handled the same
+                       # in read-only mode, but note that rofs_dest_backing
+                       # is non-empty (and necessary) only for unions
+                       if [ -n "${rootmnt}" ]
                        then
-                               do_union ${dest} ${source} ${rofs_dest_backing}
+                               local cow_dir="$(echo ${dest} | sed -e "s|^${rootmnt}|/live/overlay/|")"
                        else
-                               mount --bind "${source}" "${dest}"
+                               # This is happens if persistence is activated
+                               # post boot
+                               local cow_dir="/live/overlay/${dest}"
                        fi
-               else
-                       if [ -n "${opt_linkfiles}" ]
-                       then
-                               links_dest="${dest}"
-                               dest="$(mktemp -d ${persistent_backing}/links_source-XXXXXX)"
-                               links_source="${dest}"
-                       fi
-                       if [ -n "${rootmnt}" ]
+                       if [ -e "${cow_dir}" ] && [ -z "${opt_link}" ]
                        then
-                               cow_dir="$(echo ${dest} | sed -e "s|${rootmnt}|/cow/|")"
-                       else
-                               cow_dir="/live/cow/${dest}"
+                               # If an earlier custom mount has files here
+                               # it will "block" the current mount's files
+                               # which is undesirable
+                               rm -rf "${cow_dir}"
                        fi
                        mkdir -p ${cow_dir}
-                       chown --reference "${source}" "${cow_dir}"
-                       chmod --reference "${source}" "${cow_dir}"
+                       chown_ref "${source}" "${cow_dir}"
+                       chmod_ref "${source}" "${cow_dir}"
                        do_union ${dest} ${cow_dir} ${source} ${rofs_dest_backing}
                fi
 
-               if [ -n "${opt_linkfiles}" ]
-               then
-                       link_files "${links_source}" "${links_dest}" "${rootmnt}"
-               fi
-
                PERSISTENCE_IS_ON="1"
                export PERSISTENCE_IS_ON
 
@@ -1477,16 +1576,18 @@ activate_custom_mounts ()
        echo ${used_devices}
 }
 
-fix_home_rw_compatibility ()
+fix_backwards_compatibility ()
 {
        local device=${1}
+       local dir=${2}
+       local opt=${3}
 
-       if [ -n "${PERSISTENT_READONLY}" ]
+       if [ -n "${PERSISTENCE_READONLY}" ]
        then
                return
        fi
 
-       local backing="$(mount_persistent_media ${device})"
+       local backing="$(mount_persistence_media ${device})"
        if [ -z "${backing}" ]
        then
                return
@@ -1495,7 +1596,14 @@ fix_home_rw_compatibility ()
        local include_list="${backing}/${persistence_list}"
        if [ ! -r "${include_list}" ]
        then
-               echo "# home-rw backwards compatibility:
-/ /home" > "${include_list}"
+               echo "# persistence backwards compatibility:
+${dir} ${opt},source=." > "${include_list}"
        fi
 }
+
+is_mountpoint ()
+{
+       directory="$1"
+
+       [ $(stat -fc%d:%D "${directory}") != $(stat -fc%d:%D "${directory}/..") ]
+}