}
trim_path () {
- # remove all unnecessary /:s in the path, including last
- echo ${1} | sed 's|//|/|g' | sed 's|/$||'
+ # remove all unnecessary /:s in the path, including last one (except
+ # if path is just "/")
+ echo ${1} | sed 's|//\+|/|g' | sed 's|^\(.*[^/]\)/$|\1|'
}
what_is_mounted_on ()
grep -m1 "^[^ ]\+ ${dir} " /proc/mounts | cut -d' ' -f1
}
+chown_ref ()
+{
+ local reference="${1}"
+ shift
+ local targets=${@}
+ local owner=$(stat -c %u:%g "${reference}")
+ chown -h ${owner} ${targets}
+}
+
+chmod_ref ()
+{
+ local reference="${1}"
+ shift
+ local targets=${@}
+ local rights=$(stat -c %a "${reference}")
+ chmod ${rights} ${targets}
+}
+
lastline ()
{
while read lines
return 0
}
+close_persistent_media () {
+ local device=${1}
+ local backing="$(where_is_mounted ${device})"
+
+ if [ -d "${backing}" ]
+ then
+ umount "${backing}" >/dev/null 2>&1
+ rmdir "${backing}" >/dev/null 2>&1
+ fi
+
+ if is_active_luks_mapping ${device}
+ then
+ /sbin/cryptsetup luksClose ${device}
+ fi
+}
+
open_luks_device ()
{
dev="${1}"
local snapshots="${2}"
local dev="${3}"
- if ! is_gpt_device ${dev} || \
- ( echo ${PERSISTENT_ENCRYPTION} | grep -qve "\<luks\>" && \
- /sbin/cryptsetup isLuks ${dev} > /dev/null 2>&1 )
+ local gpt_dev="${dev}"
+ if is_active_luks_mapping ${dev}
+ then
+ # if $dev is an opened luks device, we need to check
+ # GPT stuff on the backing device
+ gpt_dev=$(get_luks_backing_device "${dev}")
+ fi
+
+ if ! is_gpt_device ${gpt_dev}
then
return
fi
+
+ local gpt_name=$(get_gpt_name ${gpt_dev})
for label in ${overlays} ${snapshots}
do
- if [ "$(get_gpt_name ${dev})" = "${label}" ]
+ if [ "${gpt_name}" = "${label}" ]
then
echo "${label}=${dev}"
fi
do
local result=""
- local real_dev=""
local luks_device=""
# Check if it's a luks device; we'll have to open the device
# in order to probe any filesystem it contains, like we do
- # below. do_custom_mounts() also depends on that any luks
+ # below. activate_custom_mounts() also depends on that any luks
# device already has been opened.
if echo ${PERSISTENT_ENCRYPTION} | grep -qe "\<luks\>" && \
- /sbin/cryptsetup isLuks ${dev} >/dev/null 2>&1
+ is_luks_partition ${dev}
then
if luks_device=$(open_luks_device "${dev}")
then
- real_dev="${dev}"
dev="${luks_device}"
else
# skip $dev since we failed/chose not to open it
# Probe for matching GPT partition names or filesystem labels
if echo ${PERSISTENT_STORAGE} | grep -qe "\<filesystem\>"
then
- local gpt_dev="${dev}"
- if [ -n "${luks_device}" ]
- then
- # When we probe GPT partitions we need to look
- # at the real device, not the virtual, opened
- # luks device
- gpt_dev="${real_dev}"
- fi
- result=$(probe_for_gpt_name "${overlays}" "${snapshots}" ${gpt_dev})
+ result=$(probe_for_gpt_name "${overlays}" "${snapshots}" ${dev})
if [ -n "${result}" ]
then
ret="${ret} ${result}"
# Close luks device if it isn't used
if [ -z "${result}" ] && [ -n "${luks_device}" ] && \
- /sbin/cryptsetup status "${luks_device}" 1> /dev/null 2>&1
+ is_active_luks_mapping "${luks_device}"
then
/sbin/cryptsetup luksClose "${luks_device}"
fi
echo ${mac}
}
-is_luks()
+is_luks_partition ()
{
- devname="${1}"
- if [ -x /sbin/cryptsetup ]
- then
- /sbin/cryptsetup isLuks "${devname}" 2>/dev/null || ret=${?}
- return ${ret}
- else
- return 1
- fi
+ device="${1}"
+ /sbin/cryptsetup isLuks "${device}" 1>/dev/null 2>&1
+}
+is_active_luks_mapping ()
+{
+ device="${1}"
+ /sbin/cryptsetup status "${device}" 1>/dev/null 2>&1
+}
+
+get_luks_backing_device () {
+ device=${1}
+ cryptsetup status ${device} 2> /dev/null | \
+ awk '{if ($1 == "device:") print $2}'
}
removable_dev ()
then
mkdir -p "${dest}"
prev="$(dirname "${dest}")"
- chown --reference "${prev}" "${dest}"
- chmod --reference "${prev}" "${dest}"
+ chown_ref "${prev}" "${dest}"
+ chmod_ref "${prev}" "${dest}"
fi
link_files "${src}" "${dest}" "${src_mask}"
else
+ local final_src=${src}
if [ -n "${src_mask}" ]
then
- src="$(echo ${src} | sed "s|^${src_mask}||")"
+ final_src="$(echo ${final_src} | sed "s|^${src_mask}||")"
fi
rm -rf "${dest}" 2> /dev/null
- ln -s "${src}" "${dest}"
+ ln -s "${final_src}" "${dest}"
+ chown_ref "${src}" "${dest}"
fi
done
}
# Side-effect: leaves $devices with live.persist mounted in ${rootmnt}/live/persistent
# Side-effect: prints info to file $custom_mounts
- local devices="${1}"
- local custom_mounts="${2}" # print result to this file
+ local custom_mounts=${1}
+ shift
+ local devices=${@}
local bindings="/tmp/bindings.list"
local links="/tmp/links.list"
fi
local device_name="$(basename ${device})"
- local device_used=""
local backing=$(mount_persistent_media ${device})
if [ -z "${backing}" ]
then
local include_list="${backing}/${persistence_list}"
if [ ! -r "${include_list}" ]
then
- umount "${backing}" >/dev/null 2>&1
- rmdir "${backing}" >/dev/null 2>&1
- if /sbin/cryptsetup status ${device_name} >/dev/null 2>&1
- then
- /sbin/cryptsetup luksClose "${device_name}"
- fi
continue
fi
cp ${include_list} ${rootmnt}/live/persistent/${persistence_list}.${device_name}
fi
- while read source dest options # < ${include_list}
+ while read dir options # < ${include_list}
do
- if echo ${source} | grep -qe "^[[:space:]]*\(#.*\)\?$"
+ if echo ${dir} | grep -qe "^[[:space:]]*\(#.*\)\?$"
then
# skipping empty or commented lines
continue
fi
- if echo ${dest} | grep -qe "^[^/]"
- then
- options="${dest}"
- dest="${source}"
- elif [ -z "${dest}" ]
- then
- dest="${source}"
- fi
-
- if trim_path ${source} | grep -qe "^\(.*/\)\?\.\.\?\(/.*\)\?$"
- then
- log_warning_msg "Skipping unsafe custom mount with source ${source}: the source is a relative or absolute path w.r.t. the persistent media root and cannot use \".\" or \"..\""
- continue
- fi
-
- if trim_path ${dest} | grep -q -e "^/$" -e "^/live\(/.*\)\?$" -e "^/\(.*/\)\?\.\.\?\(/.*\)\?$"
+ if trim_path ${dir} | grep -q -e "^[^/]" -e "^/$" -e "^/live\(/.*\)\?$" -e "^/\(.*/\)\?\.\.\?\(/.*\)\?$"
then
- log_warning_msg "Skipping unsafe custom mount with desination ${dest}: the destination must be an absolute path using neither \".\" nor \"..\", and cannot be /live (or any sub-directory therein) or / (for the latter, use ${root_overlay_label}-type persistence instead)"
+ log_warning_msg "Skipping unsafe custom mount ${dir}: must be an absolute path containing neither the \".\" nor \"..\" special dirs, and cannot be \"/live\" (or any sub-directory therein) or \"/\" (for the latter, use ${root_overlay_label}-type persistence)"
continue
fi
+ local opt_source=""
+ local opt_linkfiles=""
for opt in $(echo ${options} | tr ',' ' ');
do
case "${opt}" in
- linkfiles|union)
+ source=*)
+ opt_source=${opt#source=}
+ ;;
+ linkfiles)
+ opt_linkfiles="yes"
+ ;;
+ union|bind)
;;
*)
log_warning_msg "Skipping custom mount with unkown option: ${opt}"
esac
done
- # ensure that no multiple-/ occur in paths
- local full_source="$(echo ${backing}/${source}/ | sed -e 's|/\+|/|g')"
- local full_dest="$(echo ${rootmnt}/${dest}/ | sed -e 's|/\+|/|g')"
- device_used="yes"
- if echo ${options} | grep -qe "\<linkfiles\>";
+ local source="${dir}"
+ if [ -n "${opt_source}" ]
+ then
+ if echo ${opt_source} | grep -q -e "^/" -e "^\(.*/\)\?\.\.\?\(/.*\)\?$" && [ "${source}" != "." ]
+ then
+ log_warning_msg "Skipping unsafe custom mount with option source=${opt_source}: must be either \".\" (the media root) or a relative path w.r.t. the media root that contains neither comas, nor the special \".\" and \"..\" path components"
+ continue
+ else
+ source="${opt_source}"
+ fi
+ fi
+
+ local full_source="$(trim_path ${backing}/${source})"
+ local full_dest="$(trim_path ${rootmnt}/${dir})"
+ if [ -n "${opt_linkfiles}" ]
then
- echo "${full_source} ${full_dest} ${options}" >> ${links}
+ echo "${device} ${full_source} ${full_dest} ${options}" >> ${links}
else
- echo "${full_source} ${full_dest} ${options}" >> ${bindings}
+ echo "${device} ${full_source} ${full_dest} ${options}" >> ${bindings}
fi
done < ${include_list}
-
- if [ -z "${device_used}" ]
- then
- # this device was not used for / earlier, or
- # custom mount point now, so it's useless
- umount "${backing}"
- rmdir "${backing}"
- fi
done
# We sort the list according to destination so we're sure that
# we won't hide a previous mount. We also ignore duplicate
# destinations in a more or less arbitrary way.
- [ -e "${bindings}" ] && sort -k2 -sbu ${bindings} >> ${custom_mounts} && rm ${bindings}
+ [ -e "${bindings}" ] && sort -k3 -sbu ${bindings} >> ${custom_mounts} && rm ${bindings}
# After all mounts are considered we add symlinks so they
# won't be hidden by some mount.
- [ -e "${links}" ] && sort -k2 -sbu ${links} >> ${custom_mounts} && rm ${links}
+ [ -e "${links}" ] && cat ${links} >> ${custom_mounts} && rm ${links}
+
+ # We need to make sure that no two custom mounts have the same sources
+ # or are nested; if that is the case, too much weird stuff can happen.
+ local prev_source="impossible source" # first iteration must not match
+ local prev_dest=""
+ # This sort will ensure that a source /a comes right before a source
+ # /a/b so we only need to look at the previous source
+ sort -k2 -b ${custom_mounts} |
+ while read device source dest options
+ do
+ if echo ${source} | grep -qe "^${prev_source}\(/.*\)\?$"
+ then
+ panic "Two persistent mounts have the same or nested sources: ${source} on ${dest}, and ${prev_source} on ${prev_dest}"
+ fi
+ prev_source=${source}
+ prev_dest=${dest}
+ done
}
-do_custom_mounts ()
+activate_custom_mounts ()
{
local custom_mounts="${1}" # the ouput from get_custom_mounts()
+ local used_devices=""
- while read source dest options # < ${custom_mounts}
+ while read device source dest options # < ${custom_mounts}
do
+ local opt_bind="yes"
local opt_linkfiles=""
local opt_union=""
for opt in $(echo ${options} | tr ',' ' ');
do
- case "${opt}" in
+ case "${opt}" in
+ bind)
+ opt_bind="yes"
+ unset opt_linkfiles opt_union
+ ;;
linkfiles)
opt_linkfiles="yes"
+ unset opt_bind opt_union
;;
union)
opt_union="yes"
+ unset opt_bind opt_linkfiles
;;
esac
done
if [ -n "$(what_is_mounted_on "${dest}")" ]
then
- log_warning_msg "Skipping custom mount ${source} on ${dest}: $(what_is_mounted_on "${dest}") is already mounted there"
+ log_warning_msg "Skipping custom mount ${dest}: $(what_is_mounted_on "${dest}") is already mounted there"
continue
fi
- # FIXME: we don't handle already existing
- # non-directory files in the paths of both $source and
- # $dest.
-
if [ ! -d "${dest}" ]
then
- # if ${dest} is in /home/$user, try fixing
- # proper ownership
- # FIXME: this should really be handled by
- # live-config since we don't know for sure
- # which uid a certain user has until then
- if echo ${dest} | grep -qe "^${rootmnt}/*home/\+[^/]\+"
- then
- path="/"
- for dir in $(echo ${dest} | sed -e 's|/\+| |g')
- do
- path=${path}/${dir}
- if [ ! -e ${path} ]
+ # create the destination and delete existing files in
+ # its path that are in the way
+ path="/"
+ for dir in $(echo ${dest} | sed -e 's|/\+| |g')
+ do
+ path=$(trim_path ${path}/${dir})
+ if [ -f ${path} ]
+ then
+ rm -f ${path}
+ fi
+ if [ ! -e ${path} ]
+ then
+ mkdir -p ${path}
+ if echo ${path} | grep -qe "^${rootmnt}/*home/[^/]\+"
then
- mkdir -p ${path}
- # assume that the intended user is the first, which is usually the case
+ # if ${dest} is in /home try fixing proper ownership by assuming that the intended user is the first, which is usually the case
+ # FIXME: this should really be handled by live-config since we don't know for sure which uid a certain user has until then
chown 1000:1000 ${path}
fi
- done
- else
- mkdir -p ${dest}
- fi
+ fi
+ done
fi
# if ${source} doesn't exist on our persistent media
# dealing with /etc or other system dir.
if [ ! -d "${source}" ]
then
- if [ -n "${PERSISTENT_READONLY}" ] || [ -n "${opt_linkfiles}" ]
+ if [ -n "${PERSISTENT_READONLY}" ]
then
continue
- elif [ -n "${opt_union}" ]
+ elif [ -n "${opt_union}" ] || [ -n "${opt_linkfiles}" ]
+ then
+ # unions and don't need to be bootstrapped
+ # linkfiles dirs can't be bootstrapped in a sensible way
+ mkdir -p "${source}"
+ chown_ref "${dest}" "${source}"
+ chmod_ref "${dest}" "${source}"
+ elif [ -n "${opt_bind}" ]
then
- # union's don't need to be bootstrapped
- mkdir "${source}"
- else
# ensure that $dest is not copied *into* $source
mkdir -p "$(dirname ${source})"
cp -a "${dest}" "${source}"
fi
fi
+ # XXX: If CONFIG_AUFS_ROBR is added to the Debian kernel we can
+ # ignore the loop below and set rofs_dest_backing=$dest
rofs_dest_backing=""
for d in ${rootmnt}/live/rofs/*
do
else
cow_dir="/live/cow/${dest}"
fi
+ if [ -e "${cow_dir}" ]
+ then
+ # If an earlier custom mount has files here
+ # it will "block" the current mount's files
+ # which is undesirable
+ rm -rf "${cow_dir}"
+ fi
mkdir -p ${cow_dir}
+ chown_ref "${source}" "${cow_dir}"
+ chmod_ref "${source}" "${cow_dir}"
do_union ${dest} ${cow_dir} ${source} ${rofs_dest_backing}
fi
PERSISTENCE_IS_ON="1"
export PERSISTENCE_IS_ON
+
+ if echo ${used_devices} | grep -qve "^\(.* \)\?${device}\( .*\)\?$"
+ then
+ used_devices="${used_devices} ${device}"
+ fi
done < ${custom_mounts}
+
+ echo ${used_devices}
}
fix_home_rw_compatibility ()
if [ ! -r "${include_list}" ]
then
echo "# home-rw backwards compatibility:
-/ /home" > "${include_list}"
+/home source=." > "${include_list}"
fi
}