X-Git-Url: http://git.grml.org/?a=blobdiff_plain;f=scripts%2Flive-helpers;h=db6d25c9e0bc885701347247ef84b852521902f0;hb=8b3ccc55856039a150b0d06c4dce24c50020a8fd;hp=795de55392597686e70a99fb8ee4778923fe4d5b;hpb=7a8eabff4eab223553420e5ee3857d15b84559a1;p=live-boot-grml.git diff --git a/scripts/live-helpers b/scripts/live-helpers index 795de55..db6d25c 100644 --- a/scripts/live-helpers +++ b/scripts/live-helpers @@ -519,8 +519,9 @@ where_is_mounted () } trim_path () { - # remove all unnecessary /:s in the path, including last - echo ${1} | sed 's|//|/|g' | sed 's|/$||' + # remove all unnecessary /:s in the path, including last one (except + # if path is just "/") + echo ${1} | sed 's|//\+|/|g' | sed 's|^\(.*[^/]\)/$|\1|' } what_is_mounted_on () @@ -764,6 +765,22 @@ mount_persistent_media () return 0 } +close_persistent_media () { + local device=${1} + local backing="$(where_is_mounted ${device})" + + if [ -d "${backing}" ] + then + umount "${backing}" >/dev/null 2>&1 + rmdir "${backing}" >/dev/null 2>&1 + fi + + if is_active_luks_mapping ${device} + then + /sbin/cryptsetup luksClose ${device} + fi +} + open_luks_device () { dev="${1}" @@ -832,15 +849,23 @@ probe_for_gpt_name () local snapshots="${2}" local dev="${3}" - if ! is_gpt_device ${dev} || \ - ( echo ${PERSISTENT_ENCRYPTION} | grep -qve "\" && \ - /sbin/cryptsetup isLuks ${dev} > /dev/null 2>&1 ) + local gpt_dev="${dev}" + if is_active_luks_mapping ${dev} + then + # if $dev is an opened luks device, we need to check + # GPT stuff on the backing device + gpt_dev=$(get_luks_backing_device "${dev}") + fi + + if ! is_gpt_device ${gpt_dev} then return fi + + local gpt_name=$(get_gpt_name ${gpt_dev}) for label in ${overlays} ${snapshots} do - if [ "$(get_gpt_name ${dev})" = "${label}" ] + if [ "${gpt_name}" = "${label}" ] then echo "${label}=${dev}" fi @@ -936,18 +961,16 @@ find_persistent_media () do local result="" - local real_dev="" local luks_device="" # Check if it's a luks device; we'll have to open the device # in order to probe any filesystem it contains, like we do - # below. do_custom_mounts() also depends on that any luks + # below. activate_custom_mounts() also depends on that any luks # device already has been opened. if echo ${PERSISTENT_ENCRYPTION} | grep -qe "\" && \ - /sbin/cryptsetup isLuks ${dev} >/dev/null 2>&1 + is_luks_partition ${dev} then if luks_device=$(open_luks_device "${dev}") then - real_dev="${dev}" dev="${luks_device}" else # skip $dev since we failed/chose not to open it @@ -962,15 +985,7 @@ find_persistent_media () # Probe for matching GPT partition names or filesystem labels if echo ${PERSISTENT_STORAGE} | grep -qe "\" then - local gpt_dev="${dev}" - if [ -n "${luks_device}" ] - then - # When we probe GPT partitions we need to look - # at the real device, not the virtual, opened - # luks device - gpt_dev="${real_dev}" - fi - result=$(probe_for_gpt_name "${overlays}" "${snapshots}" ${gpt_dev}) + result=$(probe_for_gpt_name "${overlays}" "${snapshots}" ${dev}) if [ -n "${result}" ] then ret="${ret} ${result}" @@ -998,7 +1013,7 @@ find_persistent_media () # Close luks device if it isn't used if [ -z "${result}" ] && [ -n "${luks_device}" ] && \ - /sbin/cryptsetup status "${luks_device}" 1> /dev/null 2>&1 + is_active_luks_mapping "${luks_device}" then /sbin/cryptsetup luksClose "${luks_device}" fi @@ -1028,17 +1043,22 @@ get_mac () echo ${mac} } -is_luks() +is_luks_partition () { - devname="${1}" - if [ -x /sbin/cryptsetup ] - then - /sbin/cryptsetup isLuks "${devname}" 2>/dev/null || ret=${?} - return ${ret} - else - return 1 - fi + device="${1}" + /sbin/cryptsetup isLuks "${device}" 1>/dev/null 2>&1 +} +is_active_luks_mapping () +{ + device="${1}" + /sbin/cryptsetup status "${device}" 1>/dev/null 2>&1 +} + +get_luks_backing_device () { + device=${1} + cryptsetup status ${device} 2> /dev/null | \ + awk '{if ($1 == "device:") print $2}' } removable_dev () @@ -1225,8 +1245,9 @@ get_custom_mounts () # Side-effect: leaves $devices with live.persist mounted in ${rootmnt}/live/persistent # Side-effect: prints info to file $custom_mounts - local devices="${1}" - local custom_mounts="${2}" # print result to this file + local custom_mounts=${1} + shift + local devices=${@} local bindings="/tmp/bindings.list" local links="/tmp/links.list" @@ -1240,7 +1261,6 @@ get_custom_mounts () fi local device_name="$(basename ${device})" - local device_used="" local backing=$(mount_persistent_media ${device}) if [ -z "${backing}" ] then @@ -1250,12 +1270,6 @@ get_custom_mounts () local include_list="${backing}/${persistence_list}" if [ ! -r "${include_list}" ] then - umount "${backing}" >/dev/null 2>&1 - rmdir "${backing}" >/dev/null 2>&1 - if /sbin/cryptsetup status ${device_name} >/dev/null 2>&1 - then - /sbin/cryptsetup luksClose "${device_name}" - fi continue fi @@ -1264,39 +1278,32 @@ get_custom_mounts () cp ${include_list} ${rootmnt}/live/persistent/${persistence_list}.${device_name} fi - while read source dest options # < ${include_list} + while read dir options # < ${include_list} do - if echo ${source} | grep -qe "^[[:space:]]*\(#.*\)\?$" + if echo ${dir} | grep -qe "^[[:space:]]*\(#.*\)\?$" then # skipping empty or commented lines continue fi - if echo ${dest} | grep -qe "^[^/]" - then - options="${dest}" - dest="${source}" - elif [ -z "${dest}" ] - then - dest="${source}" - fi - - if trim_path ${source} | grep -qe "^\(.*/\)\?\.\.\?\(/.*\)\?$" - then - log_warning_msg "Skipping unsafe custom mount with source ${source}: the source is a relative or absolute path w.r.t. the persistent media root and cannot use \".\" or \"..\"" - continue - fi - - if trim_path ${dest} | grep -q -e "^/$" -e "^/live\(/.*\)\?$" -e "^/\(.*/\)\?\.\.\?\(/.*\)\?$" + if trim_path ${dir} | grep -q -e "^[^/]" -e "^/$" -e "^/live\(/.*\)\?$" -e "^/\(.*/\)\?\.\.\?\(/.*\)\?$" then - log_warning_msg "Skipping unsafe custom mount with desination ${dest}: the destination must be an absolute path using neither \".\" nor \"..\", and cannot be /live (or any sub-directory therein) or / (for the latter, use ${root_overlay_label}-type persistence instead)" + log_warning_msg "Skipping unsafe custom mount ${dir}: must be an absolute path containing neither the \".\" nor \"..\" special dirs, and cannot be \"/live\" (or any sub-directory therein) or \"/\" (for the latter, use ${root_overlay_label}-type persistence)" continue fi + local opt_source="" + local opt_linkfiles="" for opt in $(echo ${options} | tr ',' ' '); do case "${opt}" in - linkfiles|union) + source=*) + opt_source=${opt#source=} + ;; + linkfiles) + opt_linkfiles="yes" + ;; + union) ;; *) log_warning_msg "Skipping custom mount with unkown option: ${opt}" @@ -1305,48 +1312,68 @@ get_custom_mounts () esac done - # ensure that no multiple-/ occur in paths + local source="${dir}" + if [ -n "${opt_source}" ] + then + if echo ${opt_source} | grep -q -e "^/" -e "^\(.*/\)\?\.\.\?\(/.*\)\?$" && [ "${source}" != "." ] + then + log_warning_msg "Skipping unsafe custom mount with option source=${opt_source}: must be either \".\" (the media root) or a relative path w.r.t. the media root that contains neither comas, nor the special \".\" and \"..\" path components" + continue + else + source="${opt_source}" + fi + fi + local full_source="$(trim_path ${backing}/${source})" - local full_dest="$(trim_path ${rootmnt}/${dest})" - device_used="yes" - if echo ${options} | grep -qe "\"; + local full_dest="$(trim_path ${rootmnt}/${dir})" + if [ -n "${opt_linkfiles}" ] then - echo "${full_source} ${full_dest} ${options}" >> ${links} + echo "${device} ${full_source} ${full_dest} ${options}" >> ${links} else - echo "${full_source} ${full_dest} ${options}" >> ${bindings} + echo "${device} ${full_source} ${full_dest} ${options}" >> ${bindings} fi done < ${include_list} - - if [ -z "${device_used}" ] - then - # this device was not used for / earlier, or - # custom mount point now, so it's useless - umount "${backing}" - rmdir "${backing}" - fi done # We sort the list according to destination so we're sure that # we won't hide a previous mount. We also ignore duplicate # destinations in a more or less arbitrary way. - [ -e "${bindings}" ] && sort -k2 -sbu ${bindings} >> ${custom_mounts} && rm ${bindings} + [ -e "${bindings}" ] && sort -k3 -sbu ${bindings} >> ${custom_mounts} && rm ${bindings} # After all mounts are considered we add symlinks so they # won't be hidden by some mount. - [ -e "${links}" ] && sort -k2 -sbu ${links} >> ${custom_mounts} && rm ${links} + [ -e "${links}" ] && cat ${links} >> ${custom_mounts} && rm ${links} + + # We need to make sure that no two custom mounts have the same sources + # or are nested; if that is the case, too much weird stuff can happen. + local prev_source="impossible source" # first iteration must not match + local prev_dest="" + # This sort will ensure that a source /a comes right before a source + # /a/b so we only need to look at the previous source + sort -k2 -b ${custom_mounts} | + while read device source dest options + do + if echo ${source} | grep -qe "^${prev_source}\(/.*\)\?$" + then + panic "Two persistent mounts have the same or nested sources: ${source} on ${dest}, and ${prev_source} on ${prev_dest}" + fi + prev_source=${source} + prev_dest=${dest} + done } -do_custom_mounts () +activate_custom_mounts () { local custom_mounts="${1}" # the ouput from get_custom_mounts() + local used_devices="" - while read source dest options # < ${custom_mounts} + while read device source dest options # < ${custom_mounts} do local opt_linkfiles="" local opt_union="" for opt in $(echo ${options} | tr ',' ' '); do - case "${opt}" in + case "${opt}" in linkfiles) opt_linkfiles="yes" ;; @@ -1356,9 +1383,14 @@ do_custom_mounts () esac done + if [ -n "${opt_linkfiles}" ] && [ -n "${opt_union}" ] + then + log_warning_msg "Skipping custom mount ${dest} with options ${options}: \"linkfiles\" and \"union\" are mutually exclusive options" + fi + if [ -n "$(what_is_mounted_on "${dest}")" ] then - log_warning_msg "Skipping custom mount ${source} on ${dest}: $(what_is_mounted_on "${dest}") is already mounted there" + log_warning_msg "Skipping custom mount ${dest}: $(what_is_mounted_on "${dest}") is already mounted there" continue fi @@ -1397,13 +1429,16 @@ do_custom_mounts () # dealing with /etc or other system dir. if [ ! -d "${source}" ] then - if [ -n "${PERSISTENT_READONLY}" ] || [ -n "${opt_linkfiles}" ] + if [ -n "${PERSISTENT_READONLY}" ] then continue - elif [ -n "${opt_union}" ] + elif [ -n "${opt_union}" ] || [ -n "${opt_linkfiles}" ] then - # union's don't need to be bootstrapped + # unions and don't need to be bootstrapped + # linkfiles dirs can't be bootstrapped in a sensible way mkdir "${source}" + chown --reference "${dest}" "${source}" + chmod --reference "${dest}" "${source}" else # ensure that $dest is not copied *into* $source mkdir -p "$(dirname ${source})" @@ -1411,6 +1446,8 @@ do_custom_mounts () fi fi + # XXX: If CONFIG_AUFS_ROBR is added to the Debian kernel we can + # ignore the loop below and set rofs_dest_backing=$dest rofs_dest_backing="" for d in ${rootmnt}/live/rofs/* do @@ -1454,6 +1491,8 @@ do_custom_mounts () cow_dir="/live/cow/${dest}" fi mkdir -p ${cow_dir} + chown --reference "${source}" "${cow_dir}" + chmod --reference "${source}" "${cow_dir}" do_union ${dest} ${cow_dir} ${source} ${rofs_dest_backing} fi @@ -1464,7 +1503,14 @@ do_custom_mounts () PERSISTENCE_IS_ON="1" export PERSISTENCE_IS_ON + + if echo ${used_devices} | grep -qve "^\(.* \)\?${device}\( .*\)\?$" + then + used_devices="${used_devices} ${device}" + fi done < ${custom_mounts} + + echo ${used_devices} } fix_home_rw_compatibility () @@ -1486,6 +1532,6 @@ fix_home_rw_compatibility () if [ ! -r "${include_list}" ] then echo "# home-rw backwards compatibility: -/ /home" > "${include_list}" +/home source=." > "${include_list}" fi }