Drop contrib + non-free from default COMPONENTS, support --contrib + -non-free cmdlin...
[grml-debootstrap.git] / grml-debootstrap
index 0c0df3f..ca4172b 100755 (executable)
@@ -6,9 +6,45 @@
 # License:       This file is licensed under the GPL v2+
 ################################################################################
 
+# error_handler {{{
+[ -n "$REPORT_TRAP_ERR" ] || REPORT_TRAP_ERR='no'
+[ -n "$FAIL_TRAP_ERR" ] || FAIL_TRAP_ERR='no'
+
+error_handler() {
+   last_exit_code="$?"
+   last_bash_command="$BASH_COMMAND"
+   if [ "$REPORT_TRAP_ERR" = "yes" ]; then
+      echo "Unexpected non-zero exit code $last_exit_code in $BASH_SOURCE at line $BASH_LINENO detected!
+last bash command: $last_bash_command"
+   fi
+   if [ ! "$FAIL_TRAP_ERR" = "yes" ]; then
+      return
+   fi
+   ## Check if "bailout" function is available.
+   ## This is not the case in chroot-script.
+   if command -v bailout >/dev/null 2>&1; then
+      bailout 1
+   else
+      echo 'FAIL_TRAP_ERR is set to "yes", exit 1.'
+      exit 1
+   fi
+}
+
+if [ "$REPORT_TRAP_ERR" = "yes" ] || [ "$FAIL_TRAP_ERR" = "yes" ]; then
+   set -E
+   set -o pipefail
+   trap "error_handler" ERR
+   export -f "error_handler"
+fi
+# }}}
+
 # variables {{{
-PN="$(basename $0)"
-VERSION="$(dpkg-query --show --showformat='${Version}' "$PN")"
+PN="$(basename "$0")"
+if [[ -d "$(dirname "$(which "$0")")"/.git ]]; then
+  VERSION="$(git describe | sed 's|^v||')"
+else
+  VERSION="$(dpkg-query --show --showformat='${Version}' "$PN")"
+fi
 VERSION="${VERSION:-unknown}"
 MNTPOINT="/mnt/debootstrap.$$"
 
@@ -18,20 +54,24 @@ MNTPOINT="/mnt/debootstrap.$$"
 [ -n "$DEBCONF" ] || DEBCONF='yes'
 [ -n "$DEBIAN_FRONTEND" ] || DEBIAN_FRONTEND='noninteractive'
 [ -n "$DEBOOTSTRAP" ] || DEBOOTSTRAP='debootstrap'
+[ -n "$DEFAULT_LANGUAGE" ] || DEFAULT_LANGUAGE='en_US:en'
 [ -n "$DEFAULT_LOCALES" ] || DEFAULT_LOCALES='en_US.UTF-8'
+[ -n "$DISK_IDENTIFIER" ] || DISK_IDENTIFIER='26ada0c0-1165-4098-884d-aafd2220c2c6'
 [ -n "$EXTRAPACKAGES" ] || EXTRAPACKAGES='yes'
 [ -n "$FALLBACK_MIRROR" ] || FALLBACK_MIRROR='http://http.debian.net/debian'
+[ -n "$FIXED_DISK_IDENTIFIERS" ] || FIXED_DISK_IDENTIFIERS="no"
 [ -n "$FORCE" ] || FORCE=''
 [ -n "$HOSTNAME" ] || HOSTNAME='grml'
 [ -n "$INITRD" ] || INITRD='yes'
 [ -n "$INSTALL_NOTES" ] || INSTALL_NOTES='/etc/debootstrap/install_notes'
 [ -n "$LOCALES" ] || LOCALES='yes'
 [ -n "$MIRROR" ] || MIRROR="$FALLBACK_MIRROR"
-[ -n "$MKFS" ] || MKFS='mkfs.ext3'
+[ -n "$MKFS" ] || MKFS='mkfs.ext4'
+[ -n "$MKFS_OPTS" ] || MKFS_OPTS=''
 [ -n "$PACKAGES" ] || PACKAGES='yes'
 [ -n "$PRE_SCRIPTS" ] || PRE_SCRIPTS='yes'
 [ -n "$RECONFIGURE" ] || RECONFIGURE='console-data'
-[ -n "$RELEASE" ] || RELEASE='wheezy'
+[ -n "$RELEASE" ] || RELEASE='jessie'
 [ -n "$RM_APTCACHE" ] || RM_APTCACHE='yes'
 [ -n "$SCRIPTS" ] || SCRIPTS='yes'
 [ -n "$SECURE" ] || SECURE='yes'
@@ -60,7 +100,7 @@ Bootstrap options:
   -m, --mirror <URL>     Mirror which should be used for apt-get/aptitude.
   -i, --iso <mnt>        Mountpoint where a Debian ISO is mounted to, for use
                          instead of fetching packages from a mirror.
-  -r, --release <name>   Release of new Debian system (default: wheezy).
+  -r, --release <name>   Release of new Debian system (default: jessie).
   -t, --target <target>  Target partition (/dev/...) or directory where the
                          system should be installed to.
   -p, --mntpoint <mnt>   Mountpoint used for mounting the target system,
@@ -76,9 +116,11 @@ Bootstrap options:
 
 Options for Virtual Machine deployment:
 
-      --vmfile           Set up a Virtual Machine (raw format) instead of installing
+      --vm               Set up a Virtual Machine, instead of plainly installing
                          to a partition or directory, to be combined with --target,
-                         like: --vmfile --target /mnt/sda1/qemu.img
+                         like: --vm --target /dev/mapper/your-vm-disk
+      --vmfile           Like --vm, but install into a file (raw format).
+                         Example: --vmfile --target /mnt/sda1/qemu.img
       --vmsize <size>    Use specified size for size of VM file (default: 2G).
                          Syntax as supported by qemu-img, like: --vmsize 3G
 
@@ -92,10 +134,18 @@ Configuration options:
                              instead of using /etc/debootstrap/packages.
       --nopackages         Skip installation of packages defined in
                              /etc/debootstrap/packages
+      --nokernel           Skip installation of default kernel images.
+      --nointerfaces       Do not copy /etc/network/interfaces from host system
+                           to target system.
+                           (This option is automatically enabled when using --vmfile.)
+      --defaultinterfaces  Install a default /etc/network/interfaces file (enabling
+                           DHCP for eth0) instead of taking over config from host system.
       --debconf <file>     Pre-seed packages using specified pre-seed db file.
       --grmlrepos          Enable Grml's Debian repository (deb.grml.org).
       --backportrepos      Enable Debian's backports repository (backports.debian.org).
       --keep_src_list      Do not overwrite user provided apt sources.list.
+      --contrib            Enable 'contrib' in COMPONENTS (defaults to 'main' only).
+      --non-free           Enable non-free in COMPONENTS (defaults to 'main' only).
       --hostname <name>    Hostname of Debian system.
       --nopassword         Do not prompt for the root password.
       --password <pwd>     Use specified password as password for user root.
@@ -107,6 +157,7 @@ Configuration options:
 Other options:
 
   -v, --verbose            Increase verbosity.
+      --debug              Execute in very verbose way.
   -h, --help               Print this usage information and exit.
   -V, --version            Show summary of options and exit.
 
@@ -124,11 +175,9 @@ fi
 
 # early helper functions {{{
 GOOD='\e[32;01m'
-WARN='\e[33;01m'
 BAD='\e[31;01m'
+WARN='\e[33;01m'
 NORMAL='\e[0m'
-HILITE='\e[36;01m'
-BRACKET='\e[34;01m'
 
 einfo() {
   einfon "$1\n"
@@ -142,6 +191,11 @@ einfon() {
   return 0
 }
 
+ewarn() {
+  printf " ${WARN}*${NORMAL} $*\n"
+  return 0
+}
+
 eerror() {
   [ "${RC_ENDCOL}" != "yes" ] && [ "${LAST_E_CMD}" = "ebegin" ] && echo
   printf " ${BAD}*${NORMAL} $*\n" >&2
@@ -152,10 +206,10 @@ eerror() {
 eend() {
   local retval="${1:-0}"
   shift
-  if [ $retval -gt 0 ]; then
+  if [ "$retval" -gt 0 ]; then
     printf " ${BAD}-> Failed (rc=${retval})${NORMAL}\n"
   fi
-  return $retval
+  return "$retval"
 }
 
 check4root(){
@@ -166,8 +220,8 @@ check4root(){
 
 check4progs(){
   local RC=''
-  for arg in $* ; do
-    which $arg >/dev/null 2>&1 || RC="$arg"
+  for arg in "$@" ; do
+    which "$arg" >/dev/null 2>&1 || RC="$arg"
   done
   if [ -n "$RC" ] ; then
      echo "$RC not installed"
@@ -195,14 +249,17 @@ cleanup() {
   if [ -n "$MNTPOINT" ] ; then
     if grep -q "$MNTPOINT" /proc/mounts ; then
       # make sure nothing is left inside chroot so we can unmount it
-      [ -x "$MNTPOINT"/etc/init.d/ssh   ] && "$MNTPOINT"/etc/init.d/ssh stop
-      [ -x "$MNTPOINT"/etc/init.d/mdadm ] && "$MNTPOINT"/etc/init.d/mdadm stop
+      for service in ssh mdadm ; do
+        if [ -x "${MNTPOINT}/etc/init.d/${service}" ] ; then
+          chroot "$MNTPOINT" "/etc/init.d/${service}" stop
+        fi
+      done
 
       [ -x "$MNTPOINT"/bin/umount ] && chroot "$MNTPOINT" umount -a >/dev/null 2>&1
 
       # ugly, but make sure we really don't leave anything (/proc /proc and
       # /dev /dev are intended, trying to work around timing issues, see #657023)
-      for ARG in /sys /proc /proc /dev /dev ; do
+      for ARG in /sys /proc /proc /dev/pts /dev/pts /dev /dev ; do
         [ -x "$MNTPOINT"/bin/umount ] && chroot "$MNTPOINT" umount $ARG >/dev/null 2>&1
         umount "$MNTPOINT"/$ARG >/dev/null 2>&1
       done
@@ -221,7 +278,7 @@ cleanup() {
 
       if [ -n "$STAGES" ] ; then
         echo -n "Removing stages directory ${STAGES}: "
-        rm -rf "$STAGES" && echo done
+        rm -rf "$STAGES" && echo 'done'
       fi
 
       # remove directory only if we used the default with process id inside the name
@@ -256,7 +313,7 @@ stage() {
   if [ -n "$2" ] ; then
      echo "$2" > "${STAGES}/${1}"
      return 0
-  elif grep -q done "${STAGES}/${1}" 2>/dev/null ; then
+  elif grep -q 'done' "${STAGES}/${1}" 2>/dev/null ; then
      ewarn "Notice: stage $1 has been executed already, skipping execution therefore." ; eend 0
      ewarn "  To reexecute it clean up the according directory inside $STAGES" ; eend 0
      return 1
@@ -276,8 +333,9 @@ fi
 
 # cmdline handling {{{
 # source external command line parameter-processing script
-if [ -r ./cmdlineopts.clp ] ; then
-   . ./cmdlineopts.clp
+self_dir="$(dirname "$(which "$0")")"
+if [ -r "${self_dir}"/cmdlineopts.clp ] ; then
+   . "${self_dir}"/cmdlineopts.clp
 elif [ -r /usr/share/grml-debootstrap/functions/cmdlineopts.clp ] ; then
    . /usr/share/grml-debootstrap/functions/cmdlineopts.clp
 else
@@ -307,7 +365,8 @@ fi
 [ "$_opt_iso" ]                 && ISO=$_opt_iso
 [ "$_opt_release" ]             && RELEASE=$_opt_release
 [ "$_opt_target" ]              && TARGET=$_opt_target
-[ "$_opt_vmfile" ]              && VIRTUAL=1
+[ "$_opt_vm" ]                  && VIRTUAL=1
+[ "$_opt_vmfile" ]              && VMFILE=1 && VIRTUAL=1
 [ "$_opt_vmsize" ]              && VMSIZE=$_opt_vmsize
 [ "$_opt_mntpoint" ]            && MNTPOINT=$_opt_mntpoint
 [ "$_opt_debopt" ]              && DEBOOTSTRAP_OPT=$_opt_debopt
@@ -326,12 +385,25 @@ fi
 [ "$_opt_hostname" ]            && HOSTNAME=$_opt_hostname
 [ "$_opt_password" ]            && ROOTPASSWORD=$_opt_password
 [ "$_opt_nopassword" ]          && NOPASSWORD='yes'
+[ "$_opt_defaultinterfaces" ]   && USE_DEFAULT_INTERFACES="true"
+[ "$_opt_nointerfaces" ]        && NOINTERFACES="true"
+[ "$_opt_nokernel" ]            && NOKERNEL="true"
 [ "$_opt_bootappend" ]          && BOOT_APPEND=$_opt_bootappend
 [ "$_opt_grub" ]                && GRUB=$_opt_grub
 [ "$_opt_arch" ]                && ARCH=$_opt_arch
 [ "$_opt_insecure" ]            && echo "Warning: --insecure is deprecated, continuing anyway."
 [ "$_opt_force" ]               && FORCE=$_opt_force
 [ "$_opt_verbose" ]             && VERBOSE="-v"
+[ "$_opt_debug" ]               && DEBUG="true"
+
+# make sure main is always included
+[ -z "$COMPONENTS" ]            && COMPONENTS="main"
+[ "$_opt_contrib" ]             && COMPONENTS="$COMPONENTS contrib"
+[ "$_opt_non_free" ]            && COMPONENTS="$COMPONENTS non-free"
+
+if [ "$DEBUG" = "true" ] ; then
+  set -x
+fi
 
 [ "$_opt_help" ] && {
   usage ; eend 0
@@ -400,7 +472,7 @@ prompt_for_target()
   AVAILABLE_PARTITIONS=$(LANG=C fdisk -l 2>/dev/null | \
                sed 's/*//' | \
                grep -v 'Extended$' | \
-               gawk -v num=0 -v ORS=' ' '/^\/dev\// {print $1}'; ls /dev/md* 2>/dev/null || true);
+               gawk -v num=0 -v ORS=' ' '/^\/dev\// {print $1}'; ls /dev/md[0-9]* 2>/dev/null || true);
 
   if [ -z "$AVAILABLE_PARTITIONS" ] ; then
      dialog --title "$PN" --trim \
@@ -410,8 +482,11 @@ prompt_for_target()
      bailout 1
   fi
 
-  PARTITION_LIST=$(for i in $(echo $AVAILABLE_PARTITIONS) ; do
-                       echo "$i $(blkid -s TYPE -o value $i 2>/dev/null || echo [no_filesystem_yet])"
+  PARTITION_LIST=$(for i in $AVAILABLE_PARTITIONS ; do
+                     fs="$(blkid -s TYPE -o value "$i" 2>/dev/null)"
+                     [ -n "$fs" ] || fs='[no_filesystem_yet]'
+                     echo "$i" "$fs"
+                     unset fs
                    done)
 
   TARGET=$(dialog --title "$PN" --single-quoted --stdout \
@@ -433,16 +508,16 @@ prompt_for_bootmanager()
      found=
      for device in /dev/disk/by-id/*
      do
-        [ $(readlink -f $device) = ${TARGET} ] || continue
+        [ "$(readlink -f "$device")" = "${TARGET}" ] || continue
         found=1
         break
      done
-     [ -n "$found" ] && MBRDISK=$(echo ${device}|sed -e 's/-part[0-9][0-9]*$//')
+     [ -n "$found" ] && MBRDISK=$(echo "${device}" |sed -e 's/-part[0-9][0-9]*$//')
      if [ -e "$MBRDISK" ]; then
-        MBRDISK=$(readlink -f $MBRDISK)
+        MBRDISK=$(readlink -f "$MBRDISK")
      else
         # fall back to old behaviour
-        MBRDISK=$(echo ${TARGET} | sed -e 's/[0-9][0-9]*$//')
+        MBRDISK=$(echo "${TARGET}" | sed -e 's/[0-9][0-9]*$//')
      fi
 
      MBRPART="MBR of $MBRDISK"
@@ -491,13 +566,15 @@ prompt_for_bootmanager()
 # ask for Debian release {{{
 prompt_for_release()
 {
-  [ -n "$RELEASE" ] && DEFAULT_RELEASE="$RELEASE" || DEFAULT_RELEASE='wheezy'
+  [ -n "$RELEASE" ] && DEFAULT_RELEASE="$RELEASE" || DEFAULT_RELEASE='jessie'
   RELEASE="$(dialog --stdout --title "${PN}" --default-item $DEFAULT_RELEASE --menu \
             "Please enter the Debian release you would like to use for installation:" \
-            0 50 4 \
+            0 50 5 \
             lenny    Debian/5.0 \
             squeeze  Debian/6.0 \
             wheezy   Debian/7.0 \
+            jessie   Debian/8.0 \
+            stretch  Debian/9.0 \
             sid      Debian/unstable)"
   [ $? -eq 0 ] || bailout
 }
@@ -508,7 +585,7 @@ prompt_for_hostname()
 {
   HOSTNAME="$(dialog --stdout --title "${PN}" --inputbox \
             "Please enter the hostname you would like to use for installation:" \
-            0 0 $HOSTNAME)"
+            0 0 "$HOSTNAME")"
   [ $? -eq 0 ] || bailout
 }
 # }}}
@@ -527,14 +604,15 @@ prompt_for_password()
     ROOTPW1=$(dialog --insecure --stdout --title "${PN}" --passwordbox \
     "Please enter the password for the root account:" 10 60)
     [ $? -eq 0 ] || bailout
+
     ROOTPW2=$(dialog --insecure --stdout --title "${PN}" --passwordbox \
     "Please enter the password for the root account again for \
     confirmation:" 10 60)
     [ $? -eq 0 ] || bailout
 
     if [ "$ROOTPW1" != "$ROOTPW2" ]; then
-      $(dialog --stdout --title "${PN}" --ok-label \
-      "Retry" --msgbox "Passwords do not match!" 10 60)
+      dialog --stdout --title "${PN}" --ok-label \
+        "Retry" --msgbox "Passwords do not match!" 10 60
     fi
   done
   ROOTPASSWORD="$ROOTPW1"
@@ -577,14 +655,8 @@ TMPFILE=$(mktemp)
 # Currently we support only raid1:
 RAIDLEVEL='raid1'
 
-#RAIDLEVEL=$(dialog --stdout --title "$PN" --default-item raid1 \
-#                   --menu "Which RAID level do you want to use?" 0 0 0 \
-#                     raid1 "Software RAID level 1" \
-#                     raid5 "Software RAID level 5")
-#[ $? -eq 0 ] || bailout 20
-
 MD_LIST=$(for i in $(seq 0 9) ; do
-            awk '{print $4}' /proc/partitions | grep -q md$i || \
+            awk '{print $4}' /proc/partitions | grep -q "md$i" || \
             echo "/dev/md$i /dev/md$i"
           done)
 
@@ -599,26 +671,25 @@ AVAILABLE_PARTITIONS=$(LANG=C fdisk -l 2>/dev/null | \
              sed 's/*//' | \
              grep -v 'Extended$' | \
              gawk -v num=0 -v ORS=' ' '/^\/dev\// {print $1}')
-[ -n "$AVAILABLE_PARTITIONS" ] || echo "FIXME: no partitions available?"
-PARTITION_LIST=$(for i in $(echo $AVAILABLE_PARTITIONS) ; do
-                     echo "$i $(blkid -s TYPE -o value $i 2>/dev/null || echo [no_filesystem_yet]) off"
+[ -n "$AVAILABLE_PARTITIONS" ] || echo "Fatal error: no partitions available?"
+PARTITION_LIST=$(for i in $AVAILABLE_PARTITIONS ; do
+                     echo "$i $(blkid -s TYPE -o value "$i" 2>/dev/null || echo '[no_filesystem_yet]') off"
                  done)
 
 dialog --title "$PN" --separate-output \
        --checklist "Please select the partitions you would like to use for your $RAIDLEVEL on ${TARGET}:" 0 0 0 \
-       $PARTITION_LIST 2>$TMPFILE
+       $PARTITION_LIST 2>"$TMPFILE"
 [ $? -eq 0 ] || bailout
-RETVAL=$?
-SELECTED_PARTITIONS="$(cat $TMPFILE)"
+SELECTED_PARTITIONS="$(cat "$TMPFILE")"
 
 NUM_PARTITIONS=0
-for i in $(cat $TMPFILE) ; do
-   NUM_PARTITIONS=$((${NUM_PARTITIONS}+1))
+for i in $(cat "$TMPFILE") ; do
+   NUM_PARTITIONS=$(( NUM_PARTITIONS + 1 ))
 done
 
 # force metadata version 0.90 for lenny so old grub can boot from this array.
 METADATA_VERSION=""
-if [ $RELEASE = "lenny" ]; then
+if [ "$RELEASE" = "lenny" ]; then
    METADATA_VERSION="-e0"
 fi
 
@@ -634,7 +705,7 @@ else
    dialog --title "$PN" --msgbox \
    "There was an error setting up $TARGET:
 
-$(cat $ERRORFILE)
+$(cat "$ERRORFILE")
 
 Exiting." 0 0
    rm -f "$TMPFILE" "$ERRORFILE"
@@ -724,7 +795,9 @@ else # if not running automatic installation display configuration and prompt fo
    [ -n "$ARCH" ]     && echo "   Using arch:      $ARCH"
    if [ -n "$VIRTUAL" ] ; then
       echo "   Deploying as Virtual Machine."
-      [ -n "$VMSIZE" ] && echo "   Using Virtual Disk file with size of ${VMSIZE}."
+      if [ -n "$VMSIZE" -a -n "$VMFILE" ]; then
+         echo "   Using Virtual Disk file with size of ${VMSIZE}."
+      fi
    fi
 
    if [ ! -t 0 -a -z "$ROOTPASSWORD" -a -z "$NOPASSWORD" ] ; then
@@ -792,6 +865,24 @@ else
 fi
 # }}}
 
+# It is not possible to build amd64 on i686. {{{
+CURRENT_ARCH="$(uname -m)"
+if [ "$CURRENT_ARCH" != "x86_64" ] ; then
+   if [ "$ARCH" = "amd64" ] ; then
+      eerror "It is not possible to build amd64 on $CURRENT_ARCH." ; eend 1
+      bailout 1
+   fi
+fi
+# }}}
+
+# Support for generic release codenames is unavailable. {{{
+if [ "$RELEASE" = "stable" ] || [ "$RELEASE" = "testing" ] ; then
+   eerror "Generic release codenames (stable, testing) are unsupported. \
+Please use specific codenames such as lenny, squeeze, wheezy, jessie or stretch." ; eend 1
+   bailout 1
+fi
+# }}}
+
 checkconfiguration
 
 # finally make sure at least $TARGET is set [the partition for the new system] {{{
@@ -811,7 +902,7 @@ if [ -z "$STAGES" ] ; then
 fi
 
 if [ -r "$STAGES"/grml-debootstrap ] ; then
-   if grep -q done $STAGES/grml-debootstrap ; then
+   if grep -q 'done' "${STAGES}/grml-debootstrap" ; then
       eerror "Error: grml-debootstrap has been executed already, won't continue therefore."
       eerror "If you want to re-execute grml-debootstrap just manually remove ${STAGES}" ; eend 1
    fi
@@ -829,11 +920,10 @@ set_target_directory(){
     MKFS=''
     TUNE2FS=''
     FSCK=''
-    GRUB=''
     # make sure we normalise the path to an absolute directory name so something like:
     #  mkdir -p foo/a bar/a; (cd foo; grml-debootstrap -t a)&; (cd bar; grml-debootstrap -t a)&; wait
     # works
-    TARGET="$(readlink -f $TARGET)"
+    TARGET="$(readlink -f "$TARGET")"
 }
 
 if [ -b "$TARGET" ] || [ -n "$VIRTUAL" ] ; then
@@ -867,33 +957,57 @@ fi
 mkfs() {
   if [ -n "$DIRECTORY" ] ; then
      einfo "Running grml-debootstrap on a directory, skipping mkfs stage."
-  else
-    if grep -q "$TARGET" /proc/mounts ; then
-      eerror "$TARGET already mounted, exiting to avoid possible damage. (Manually unmount $TARGET)" ; eend 1
-      bailout 1
-    fi
+     return 0
+  fi
 
-    if [ -n "$MKFS" ] ; then
-       einfo "Running $MKFS on $TARGET"
-       $MKFS $TARGET ; RC=$?
+  if grep -q "$TARGET" /proc/mounts ; then
+    eerror "$TARGET already mounted, exiting to avoid possible damage. (Manually unmount $TARGET)" ; eend 1
+    bailout 1
+  fi
 
-       # make sure /dev/disk/by-uuid/... is up2date, otherwise grub
-       # will fail to detect the uuid in the chroot
-       if echo "$TARGET" | grep -q "/dev/md" ; then
-         blockdev --rereadpt "${TARGET}"
-       elif ! [ -n "$VIRTUAL" ] ; then
-         blockdev --rereadpt "${TARGET%%[0-9]*}"
-       fi
-       # give the system 2 seconds, otherwise we might run into
-       # race conditions :-/
-       sleep 2
+  # mkfs.ext* might prompt with "/dev/sdX# contains a ext* file system
+  # created on ... Proceed anyway? (y,n)" which we want to skip in force mode
+  if [ -n "$MKFS" ] && [ -n "$FORCE" ] ; then
+    case "$MKFS" in
+      mkfs.ext*)
+        einfo "Enabling force option (-F) for mkfs.ext* tool as requested via --force switch."
+        MKFS_OPTS="$MKFS_OPTS -F"
+        eend 0
+        ;;
+    esac
+  fi
 
-       eval $(blkid -o udev $TARGET 2>/dev/null)
-       [ -n "$ID_FS_UUID" ] && TARGET_UUID="$ID_FS_UUID" || TARGET_UUID=""
+  if [ -n "$MKFS" ] ; then
+    einfo "Running $MKFS $MKFS_OPTS on $TARGET"
+    "$MKFS" $MKFS_OPTS "$TARGET" ; RC=$?
 
-       eend $RC
+    if [ "$FIXED_DISK_IDENTIFIERS" = "yes" ] ; then
+      if ! echo "$MKFS" | grep -q "mkfs.ext" ; then
+        eerror "Not changing disk uuid for $TARGET because $MKFS doesn't seem to match for ext{2,3,4} file system"
+        eend 1
+        bailout 1
+      else
+        einfo "Changing disk uuid for $TARGET to fixed (non-random) value $DISK_IDENTIFIER using tune2fs"
+        tune2fs "$TARGET" -U "$DISK_IDENTIFIER"
+        eend $?
+      fi
+    fi
+
+    # make sure /dev/disk/by-uuid/... is up2date, otherwise grub
+    # will fail to detect the uuid in the chroot
+    if echo "$TARGET" | grep -q "/dev/md" ; then
+      blockdev --rereadpt "${TARGET}"
+    elif ! [ -n "$VIRTUAL" ] ; then
+      blockdev --rereadpt "${TARGET%%[0-9]*}"
     fi
+    # give the system 2 seconds, otherwise we might run into
+    # race conditions :-/
+    sleep 2
+
+    eval "$(blkid -o udev "$TARGET" 2>/dev/null)"
+    [ -n "$ID_FS_UUID" ] && TARGET_UUID="$ID_FS_UUID" || TARGET_UUID=""
 
+    eend $RC
   fi
 }
 # }}}
@@ -902,7 +1016,7 @@ mkfs() {
 tunefs() {
   if [ -n "$TUNE2FS" ] && echo "$MKFS" | grep -q "mkfs.ext" ; then
      einfo "Disabling automatic filesystem check on $TARGET via tune2fs"
-     $TUNE2FS $TARGET
+     $TUNE2FS "$TARGET"
      eend $?
   fi
 }
@@ -913,7 +1027,7 @@ mount_target() {
   if [ -n "$DIRECTORY" ] ; then
      einfo "Running grml-debootstrap on a directory, nothing to mount."
   else
-     if grep -q $TARGET /proc/mounts ; then
+     if grep -q "$TARGET" /proc/mounts ; then
         ewarn "$TARGET already mounted, continuing anyway." ; eend 0
      else
        if ! [ -d "${MNTPOINT}" ] ; then
@@ -921,7 +1035,7 @@ mount_target() {
        fi
        einfo "Mounting $TARGET to $MNTPOINT"
        mkdir -p "$MNTPOINT"
-       mount -o rw,suid,dev $TARGET $MNTPOINT
+       mount -o rw,suid,dev "$TARGET" "$MNTPOINT"
        eend $?
      fi
   fi
@@ -937,25 +1051,40 @@ mount_target() {
 # prepare VM image for usage with debootstrap {{{
 prepare_vm() {
   if [ -z "$VIRTUAL" ] ; then
-     return 0 # be quite by intention
+     return 0 # be quiet by intention
   fi
 
-  if [ -b "$TARGET" ] ; then
+  if [ -b "$TARGET" -a -n "$VMFILE" ] ; then
      eerror "Error: specified virtual disk target ($TARGET) is an existing block device."
      eend 1
      bailout 1
   fi
+  if [ ! -b "$TARGET" -a -z "$VMFILE" ] ; then
+     eerror "Error: specified virtual disk target ($TARGET) does not exist yet."
+     eend 1
+     bailout 1
+  fi
 
   ORIG_TARGET="$TARGET" # store for later reuse
 
-  qemu-img create -f raw "${TARGET}" "${VMSIZE}"
+  if [ -n "$VMFILE" ]; then
+    qemu-img create -f raw "${TARGET}" "${VMSIZE}"
+  fi
   echo 4 66 | /usr/share/grml-debootstrap/bootgrub.mksh -A | dd of="$TARGET" conv=notrunc
   dd if=/dev/zero bs=1 conv=notrunc count=64 seek=446 of="$TARGET"
-  parted -s "${TARGET}" 'mkpart primary ext3 2M -1'
+  if [ "$FIXED_DISK_IDENTIFIERS" = "yes" ] ; then
+    einfo "Adjusting disk signature to a fixed (non-random) value"
+    MBRTMPFILE=$(mktemp)
+    dd if="${TARGET}" of="${MBRTMPFILE}" bs=512 count=1
+    echo -en "\x41\x41\x41\x41" | dd of="${MBRTMPFILE}" conv=notrunc seek=440 bs=1
+    dd if="${MBRTMPFILE}" of="${TARGET}" conv=notrunc
+    eend $?
+  fi
+  parted -s "${TARGET}" 'mkpart primary ext4 2M -1'
 
   # if dm-mod isn't available then kpartx will fail with
   # "Is device-mapper driver missing from kernel? [...]"
-  if ! kpartx -av $TARGET >/dev/null 2>&1 || ! grep -q device-mapper /proc/misc >/dev/null 2>&1 ; then
+  if ! kpartx -av "$TARGET" >/dev/null 2>&1 || ! grep -q 'device-mapper' /proc/misc >/dev/null 2>&1 ; then
     einfo "Device-mapper not ready yet, trying to load dm-mod module."
     modprobe dm-mod ; eend $?
   fi
@@ -972,16 +1101,15 @@ prepare_vm() {
     fi
   fi
 
-  DEVINFO=$(kpartx -av $TARGET) # 'add map loop1p1 (253:0): 0 6289408 linear /dev/loop1 2048'
+  DEVINFO=$(kpartx -asv "$TARGET") # 'add map loop1p1 (253:0): 0 6289408 linear /dev/loop1 2048'
   if [ -z "${DEVINFO}" ] ; then
     eerror "Error setting up loopback device." ; eend 1
     bailout 1
   fi
 
   # hopefully this always works as expected
-  LOOP=$(echo ${DEVINFO} | sed 's/.* linear //; s/ [[:digit:]]*//') # '/dev/loop1'
-  BLOCKDEV=$(echo "${DEVINFO}" | sed -e 's/.* (\(.*:.*\)).*/\1/')   # '253:0'
-  LOOP_PART="$(echo ${DEVINFO##add map } | sed 's/ .*//')" # '/dev/loop1p1'
+  LOOP=$(echo "${DEVINFO}" | sed 's/.* linear //; s/ [[:digit:]]*//') # 'loop1'
+  LOOP_PART="$(echo "${DEVINFO##add map }" | sed 's/ .*//')" # 'loop1p1'
   export TARGET="/dev/mapper/$LOOP_PART" # '/dev/mapper/loop1p1'
 
   blockdev --rereadpt "${LOOP}"
@@ -1004,21 +1132,33 @@ finalize_vm() {
     bailout 1
   fi
 
-  einfo "Installing Grub as bootloader."
   mount -t proc none "${MNTPOINT}"/proc
   mount -t sysfs none "${MNTPOINT}"/sys
   mount --bind /dev "${MNTPOINT}"/dev
+  mount --bind /dev/pts "${MNTPOINT}"/dev/pts
 
+# Has chroot-script installed GRUB to MBR using grub-install (successfully), already?
+# chroot-script skips installation for unset ${GRUB}
+if [[ -z "${GRUB}" ]] || ! dd if="${GRUB}" bs=512 count=1 2>/dev/null | cat -v | fgrep -q GRUB; then
+  einfo "Installing Grub as bootloader."
   mkdir -p "${MNTPOINT}/boot/grub"
   if ! [ -d "${MNTPOINT}"/usr/lib/grub/i386-pc/ ] ; then
      eerror "Error: grub not installed inside Virtual Machine. Can not install bootloader." ; eend 1
      bailout 1
   fi
 
-  cp "${MNTPOINT}"/usr/lib/grub/i386-pc/* "${MNTPOINT}/boot/grub/"
+  case "$RELEASE" in
+    lenny|squeeze|wheezy)
+      cp "${MNTPOINT}"/usr/lib/grub/i386-pc/* "${MNTPOINT}/boot/grub/"
+      ;;
+    *)
+      cp -a "${MNTPOINT}"/usr/lib/grub/i386-pc "${MNTPOINT}/boot/grub/"
+      ;;
+  esac
   chroot "${MNTPOINT}" grub-mkimage -O i386-pc -p "(hd0,msdos1)/boot/grub" -o /tmp/core.img biosdisk part_msdos ext2
   dd if="${MNTPOINT}/tmp/core.img" of="${ORIG_TARGET}" conv=notrunc seek=4
   rm -f "${MNTPOINT}/tmp/core.img"
+fi
 
   einfo "Updating grub configuration file."
   if [ -n "$BOOT_APPEND" ] ; then
@@ -1026,15 +1166,17 @@ finalize_vm() {
   fi
   chroot "${MNTPOINT}" update-grub
 
+  case "$RELEASE" in
+    lenny|squeeze|wheezy)
+      einfo "Adjusting grub.cfg for successful boot sequence."
+      sed -i "s;root=[^ ]\+;root=UUID=$TARGET_UUID;" "${MNTPOINT}"/boot/grub/grub.cfg
+      ;;
+  esac
+
   umount "${MNTPOINT}"/proc
   umount "${MNTPOINT}"/sys
-  umount "${MNTPOINT}"/dev
-
-  einfo "Adjusting grub.cfg for successful boot sequence."
-  # ugly but needed to boot grub acordingly
-  sed -i "s;set root=.*;set root='(hd0,msdos1)';" "${MNTPOINT}"/boot/grub/grub.cfg
-  sed -i "s;root=[^ ]\+;root=/dev/sda1;" "${MNTPOINT}"/boot/grub/grub.cfg
-
+  umount "${MNTPOINT}"/dev/pts
+  try_umount 3 "${MNTPOINT}"/dev
   umount "${MNTPOINT}"
   kpartx -d "${ORIG_TARGET}" >/dev/null
 }
@@ -1057,12 +1199,12 @@ debootstrap_system() {
   if [ -n "$ISO" ] ; then
     einfo "Running $DEBOOTSTRAP $DEBOOTSTRAP_OPT for release ${RELEASE}${ARCHINFO} using ${ISO}"
     einfo "Executing: $DEBOOTSTRAP $ARCHCMD $KEYRING $DEBOOTSTRAP_OPT $RELEASE $MNTPOINT $ISO"
-    $DEBOOTSTRAP $ARCHCMD $KEYRING $DEBOOTSTRAP_OPT $RELEASE $MNTPOINT $ISO
+    "$DEBOOTSTRAP" $ARCHCMD $KEYRING $DEBOOTSTRAP_OPT "$RELEASE" "$MNTPOINT" "$ISO"
     RC=$?
   else
     einfo "Running $DEBOOTSTRAP $DEBOOTSTRAP_OPT for release ${RELEASE}${ARCHINFO} using ${MIRROR}"
     einfo "Executing: $DEBOOTSTRAP $ARCHCMD $KEYRING $DEBOOTSTRAP_OPT $RELEASE $MNTPOINT $MIRROR"
-    $DEBOOTSTRAP $ARCHCMD $KEYRING $DEBOOTSTRAP_OPT $RELEASE $MNTPOINT $MIRROR
+    "$DEBOOTSTRAP" $ARCHCMD $KEYRING $DEBOOTSTRAP_OPT "$RELEASE" "$MNTPOINT" "$MIRROR"
     RC=$?
   fi
 
@@ -1070,7 +1212,7 @@ debootstrap_system() {
     if [ -r "$MNTPOINT/debootstrap/debootstrap.log" ] && \
       [ -s "$MNTPOINT/debootstrap/debootstrap.log" ] ; then
       einfo "Presenting last ten lines of debootstrap.log:"
-      tail -10 $MNTPOINT/debootstrap/debootstrap.log
+      tail -10 "${MNTPOINT}"/debootstrap/debootstrap.log
       einfo "End of debootstrap.log"
     fi
   fi
@@ -1085,112 +1227,145 @@ preparechroot() {
 
   # provide variables to chroot system
   CHROOT_VARIABLES="/var/cache/grml-debootstrap/variables_${SHORT_TARGET}"
-  touch $CHROOT_VARIABLES
-  chmod 600 $CHROOT_VARIABLES # make sure nobody except root can read it
-  echo "# Configuration of ${PN}"                              > $CHROOT_VARIABLES
-  [ -n "$ARCH" ]                && echo "ARCH=\"$ARCH\""                               >> $CHROOT_VARIABLES
-  [ -n "$BACKPORTREPOS" ]       && echo "BACKPORTREPOS=\"$BACKPORTREPOS\""             >> $CHROOT_VARIABLES
-  [ -n "$CHROOT_SCRIPTS" ]      && echo "CHROOT_SCRIPTS=\"$CHROOT_SCRIPTS\""           >> $CHROOT_VARIABLES
-  [ -n "$CONFFILES" ]           && echo "CONFFILES=\"$CONFFILES\""                     >> $CHROOT_VARIABLES
-  [ -n "$DEBCONF" ]             && echo "DEBCONF=\"$DEBCONF\""                         >> $CHROOT_VARIABLES
-  [ -n "$DEBIAN_FRONTEND" ]     && echo "DEBIAN_FRONTEND=\"$DEBIAN_FRONTEND\""         >> $CHROOT_VARIABLES
-  [ -n "$DEBOOTSTRAP" ]         && echo "DEBOOTSTRAP=\"$DEBOOTSTRAP\""                 >> $CHROOT_VARIABLES
-  [ -n "$DEFAULT_LOCALES" ]     && echo "DEFAULT_LOCALES=\"$DEFAULT_LOCALES\""         >> $CHROOT_VARIABLES
-  [ -n "$EXTRAPACKAGES" ]       && echo "EXTRAPACKAGES=\"$EXTRAPACKAGES\""             >> $CHROOT_VARIABLES
-  [ -n "$FALLBACK_MIRROR" ]     && echo "FALLBACK_MIRROR=\"$FALLBACK_MIRROR\""         >> $CHROOT_VARIABLES
-  [ -n "$FORCE" ]               && echo "FORCE=\"$FORCE\""                             >> $CHROOT_VARIABLES
-  [ -n "$GRMLREPOS" ]           && echo "GRMLREPOS=\"$GRMLREPOS\""                     >> $CHROOT_VARIABLES
-  [ -n "$GRUB" ]                && echo "GRUB=\"$GRUB\""                               >> $CHROOT_VARIABLES
-  [ -n "$HOSTNAME" ]            && echo "HOSTNAME=\"$HOSTNAME\""                       >> $CHROOT_VARIABLES
-  [ -n "$INITRD" ]              && echo "INITRD=\"$INITRD\""                           >> $CHROOT_VARIABLES
-  [ -n "$INSTALL_NOTES" ]       && echo "INSTALL_NOTES=\"$INSTALL_NOTES\""             >> $CHROOT_VARIABLES
-  [ -n "$ISODIR" ]              && echo "ISODIR=\"$ISO\""                              >> $CHROOT_VARIABLES
-  [ -n "$ISO" ]                 && echo "ISO=\"$ISO\""                                 >> $CHROOT_VARIABLES
-  [ -n "$KEEP_SRC_LIST" ]       && echo "KEEP_SRC_LIST=\"$KEEP_SRC_LIST\""             >> $CHROOT_VARIABLES
-  [ -n "$LOCALES" ]             && echo "LOCALES=\"$LOCALES\""                         >> $CHROOT_VARIABLES
-  [ -n "$MIRROR" ]              && echo "MIRROR=\"$MIRROR\""                           >> $CHROOT_VARIABLES
-  [ -n "$MKFS" ]                && echo "MKFS=\"$MKFS\""                               >> $CHROOT_VARIABLES
-  [ -n "$NOPASSWORD" ]          && echo "NOPASSWORD=\"true\""                          >> $CHROOT_VARIABLES
-  [ -n "$PACKAGES" ]            && echo "PACKAGES=\"$PACKAGES\""                       >> $CHROOT_VARIABLES
-  [ -n "$PRE_SCRIPTS" ]         && echo "PRE_SCRIPTS=\"$PRE_SCRIPTS\""                 >> $CHROOT_VARIABLES
-  [ -n "$RECONFIGURE" ]         && echo "RECONFIGURE=\"$RECONFIGURE\""                 >> $CHROOT_VARIABLES
-  [ -n "$RELEASE" ]             && echo "RELEASE=\"$RELEASE\""                         >> $CHROOT_VARIABLES
-  [ -n "$RM_APTCACHE" ]         && echo "RM_APTCACHE=\"$RM_APTCACHE\""                 >> $CHROOT_VARIABLES
-  [ -n "$ROOTPASSWORD" ]        && echo "ROOTPASSWORD=\"$ROOTPASSWORD\""               >> $CHROOT_VARIABLES
-  [ -n "$SCRIPTS" ]             && echo "SCRIPTS=\"$SCRIPTS\""                         >> $CHROOT_VARIABLES
-  [ -n "$SECURE" ]              && echo "SECURE=\"$SECURE\""                           >> $CHROOT_VARIABLES
-  [ -n "$SELECTED_PARTITIONS" ] && echo "SELECTED_PARTITIONS=\"$SELECTED_PARTITIONS\"" >> $CHROOT_VARIABLES
-  [ -n "$TARGET" ]              && echo "TARGET=\"$TARGET\""                           >> $CHROOT_VARIABLES
-  [ -n "$UPGRADE_SYSTEM" ]      && echo "UPGRADE_SYSTEM=\"$UPGRADE_SYSTEM\""           >> $CHROOT_VARIABLES
-  [ -n "$TARGET_UUID" ]         && echo "TARGET_UUID=\"$TARGET_UUID\""                 >> $CHROOT_VARIABLES
-  [ -n "$TIMEZONE" ]            && echo "TIMEZONE=\"$TIMEZONE\""                       >> $CHROOT_VARIABLES
-  [ -n "$TUNE2FS" ]             && echo "TUNE2FS=\"$TUNE2FS\""                         >> $CHROOT_VARIABLES
-  [ -n "$VMSIZE" ]              && echo "VMSIZE=\"$VMSIZE\""                           >> $CHROOT_VARIABLES
-
-  cp $VERBOSE $CONFFILES/chroot-script $MNTPOINT/bin/chroot-script
-  chmod 755 $MNTPOINT/bin/chroot-script
+  touch "$CHROOT_VARIABLES"
+  chmod 600 "$CHROOT_VARIABLES" # make sure nobody except root can read it
+  echo "# Configuration of ${PN}"                                                                                   > "$CHROOT_VARIABLES"
+  # Resorting to sed(1) for escaping since "VAR='${VAR//\'/\'\\\'\'}'" does not work with all versions of Bash,
+  #   e.g. not with 4.2.37(1)-release (a.k.a 4.2+dfsg-0.1+deb7u3) of Debian wheezy
+  [ -n "$ARCH" ]                && echo "ARCH='$(sed "s,','\\\\'',g" <<<"${ARCH}")'"                               >> "$CHROOT_VARIABLES"
+  [ -n "$BACKPORTREPOS" ]       && echo "BACKPORTREPOS='$(sed "s,','\\\\'',g" <<<"${BACKPORTREPOS}")'"             >> "$CHROOT_VARIABLES"
+  [ -n "$CHROOT_SCRIPTS" ]      && echo "CHROOT_SCRIPTS='$(sed "s,','\\\\'',g" <<<"${CHROOT_SCRIPTS}")'"           >> "$CHROOT_VARIABLES"
+  [ -n "$COMPONENTS" ]          && echo "COMPONENTS='$(sed "s,','\\\\'',g" <<<"${COMPONENTS}")'"                   >> "$CHROOT_VARIABLES"
+  [ -n "$CONFFILES" ]           && echo "CONFFILES='$(sed "s,','\\\\'',g" <<<"${CONFFILES}")'"                     >> "$CHROOT_VARIABLES"
+  [ -n "$DEBCONF" ]             && echo "DEBCONF='$(sed "s,','\\\\'',g" <<<"${DEBCONF}")'"                         >> "$CHROOT_VARIABLES"
+  [ -n "$DEBIAN_FRONTEND" ]     && echo "DEBIAN_FRONTEND='$(sed "s,','\\\\'',g" <<<"${DEBIAN_FRONTEND}")'"         >> "$CHROOT_VARIABLES"
+  [ -n "$DEBOOTSTRAP" ]         && echo "DEBOOTSTRAP='$(sed "s,','\\\\'',g" <<<"${DEBOOTSTRAP}")'"                 >> "$CHROOT_VARIABLES"
+  [ -n "$DEFAULT_LOCALES" ]     && echo "DEFAULT_LOCALES='$(sed "s,','\\\\'',g" <<<"${DEFAULT_LOCALES}")'"         >> "$CHROOT_VARIABLES"
+  [ -n "$DEFAULT_LANGUAGE" ]    && echo "DEFAULT_LANGUAGE='$(sed "s,','\\\\'',g" <<<"${DEFAULT_LANGUAGE}")'"       >> "$CHROOT_VARIABLES"
+  [ -n "$EXTRAPACKAGES" ]       && echo "EXTRAPACKAGES='$(sed "s,','\\\\'',g" <<<"${EXTRAPACKAGES}")'"             >> "$CHROOT_VARIABLES"
+  [ -n "$FALLBACK_MIRROR" ]     && echo "FALLBACK_MIRROR='$(sed "s,','\\\\'',g" <<<"${FALLBACK_MIRROR}")'"         >> "$CHROOT_VARIABLES"
+  [ -n "$FORCE" ]               && echo "FORCE='$(sed "s,','\\\\'',g" <<<"${FORCE}")'"                             >> "$CHROOT_VARIABLES"
+  [ -n "$GRMLREPOS" ]           && echo "GRMLREPOS='$(sed "s,','\\\\'',g" <<<"${GRMLREPOS}")'"                     >> "$CHROOT_VARIABLES"
+  [ -n "$GRUB" ]                && echo "GRUB='$(sed "s,','\\\\'',g" <<<"${GRUB}")'"                               >> "$CHROOT_VARIABLES"
+  [ -n "$HOSTNAME" ]            && echo "HOSTNAME='$(sed "s,','\\\\'',g" <<<"${HOSTNAME}")'"                       >> "$CHROOT_VARIABLES"
+  [ -n "$INITRD" ]              && echo "INITRD='$(sed "s,','\\\\'',g" <<<"${INITRD}")'"                           >> "$CHROOT_VARIABLES"
+  [ -n "$INSTALL_NOTES" ]       && echo "INSTALL_NOTES='$(sed "s,','\\\\'',g" <<<"${INSTALL_NOTES}")'"             >> "$CHROOT_VARIABLES"
+  [ -n "$ISODIR" ]              && echo "ISODIR='$(sed "s,','\\\\'',g" <<<"${ISO}")'"                              >> "$CHROOT_VARIABLES"
+  [ -n "$ISO" ]                 && echo "ISO='$(sed "s,','\\\\'',g" <<<"${ISO}")'"                                 >> "$CHROOT_VARIABLES"
+  [ -n "$KEEP_SRC_LIST" ]       && echo "KEEP_SRC_LIST='$(sed "s,','\\\\'',g" <<<"${KEEP_SRC_LIST}")'"             >> "$CHROOT_VARIABLES"
+  [ -n "$LOCALES" ]             && echo "LOCALES='$(sed "s,','\\\\'',g" <<<"${LOCALES}")'"                         >> "$CHROOT_VARIABLES"
+  [ -n "$MIRROR" ]              && echo "MIRROR='$(sed "s,','\\\\'',g" <<<"${MIRROR}")'"                           >> "$CHROOT_VARIABLES"
+  [ -n "$MKFS" ]                && echo "MKFS='$(sed "s,','\\\\'',g" <<<"${MKFS}")'"                               >> "$CHROOT_VARIABLES"
+  [ -n "$NOPASSWORD" ]          && echo "NOPASSWORD=\"true\""                                                      >> "$CHROOT_VARIABLES"
+  [ -n "$NOKERNEL" ]            && echo "NOKERNEL=\"true\""                                                        >> "$CHROOT_VARIABLES"
+  [ -n "$PACKAGES" ]            && echo "PACKAGES='$(sed "s,','\\\\'',g" <<<"${PACKAGES}")'"                       >> "$CHROOT_VARIABLES"
+  [ -n "$PRE_SCRIPTS" ]         && echo "PRE_SCRIPTS='$(sed "s,','\\\\'',g" <<<"${PRE_SCRIPTS}")'"                 >> "$CHROOT_VARIABLES"
+  [ -n "$RECONFIGURE" ]         && echo "RECONFIGURE='$(sed "s,','\\\\'',g" <<<"${RECONFIGURE}")'"                 >> "$CHROOT_VARIABLES"
+  [ -n "$RELEASE" ]             && echo "RELEASE='$(sed "s,','\\\\'',g" <<<"${RELEASE}")'"                         >> "$CHROOT_VARIABLES"
+  [ -n "$RM_APTCACHE" ]         && echo "RM_APTCACHE='$(sed "s,','\\\\'',g" <<<"${RM_APTCACHE}")'"                 >> "$CHROOT_VARIABLES"
+  [ -n "$ROOTPASSWORD" ]        && echo "ROOTPASSWORD='$(sed "s,','\\\\'',g" <<<"${ROOTPASSWORD}")'"               >> "$CHROOT_VARIABLES"
+  [ -n "$SCRIPTS" ]             && echo "SCRIPTS='$(sed "s,','\\\\'',g" <<<"${SCRIPTS}")'"                         >> "$CHROOT_VARIABLES"
+  [ -n "$SECURE" ]              && echo "SECURE='$(sed "s,','\\\\'',g" <<<"${SECURE}")'"                           >> "$CHROOT_VARIABLES"
+  [ -n "$SELECTED_PARTITIONS" ] && echo "SELECTED_PARTITIONS='$(sed "s,','\\\\'',g" <<<"${SELECTED_PARTITIONS}")'" >> "$CHROOT_VARIABLES"
+  [ -n "$TARGET" ]              && echo "TARGET='$(sed "s,','\\\\'',g" <<<"${TARGET}")'"                           >> "$CHROOT_VARIABLES"
+  [ -n "$UPGRADE_SYSTEM" ]      && echo "UPGRADE_SYSTEM='$(sed "s,','\\\\'',g" <<<"${UPGRADE_SYSTEM}")'"           >> "$CHROOT_VARIABLES"
+  [ -n "$TARGET_UUID" ]         && echo "TARGET_UUID='$(sed "s,','\\\\'',g" <<<"${TARGET_UUID}")'"                 >> "$CHROOT_VARIABLES"
+  [ -n "$TIMEZONE" ]            && echo "TIMEZONE='$(sed "s,','\\\\'',g" <<<"${TIMEZONE}")'"                       >> "$CHROOT_VARIABLES"
+  [ -n "$TUNE2FS" ]             && echo "TUNE2FS='$(sed "s,','\\\\'',g" <<<"${TUNE2FS}")'"                         >> "$CHROOT_VARIABLES"
+  [ -n "$VMSIZE" ]              && echo "VMSIZE='$(sed "s,','\\\\'',g" <<<"${VMSIZE}")'"                           >> "$CHROOT_VARIABLES"
+
+  cp $VERBOSE "${CONFFILES}"/chroot-script "${MNTPOINT}"/bin/chroot-script
+  chmod 755 "${MNTPOINT}"/bin/chroot-script
   [ -d "$MNTPOINT"/etc/debootstrap/ ] || mkdir "$MNTPOINT"/etc/debootstrap/
 
   # make sure we have our files for later use via chroot-script
-  cp $VERBOSE $CONFFILES/config    $MNTPOINT/etc/debootstrap/
+  cp $VERBOSE "${CONFFILES}/config"           "${MNTPOINT}"/etc/debootstrap/
   # make sure we adjust the configuration variables accordingly:
-  sed -i "s#RELEASE=.*#RELEASE=\"$RELEASE\"#" $MNTPOINT/etc/debootstrap/config
-  sed -i "s#TARGET=.*#TARGET=\"$TARGET\"#"    $MNTPOINT/etc/debootstrap/config
-  sed -i "s#GRUB=.*#GRUB=\"$GRUB\"#"          $MNTPOINT/etc/debootstrap/config
+  sed -i "s#RELEASE=.*#RELEASE=\"$RELEASE\"#" "${MNTPOINT}"/etc/debootstrap/config
+  sed -i "s#TARGET=.*#TARGET=\"$TARGET\"#"    "${MNTPOINT}"/etc/debootstrap/config
+  sed -i "s#GRUB=.*#GRUB=\"$GRUB\"#"          "${MNTPOINT}"/etc/debootstrap/config
 
   # install notes:
   if [ -n "$INSTALL_NOTES" ] ; then
-     [ -r "$INSTALL_NOTES" ] && cp "$INSTALL_NOTES" $MNTPOINT/etc/debootstrap/
+     [ -r "$INSTALL_NOTES" ] && cp "$INSTALL_NOTES" "${MNTPOINT}"/etc/debootstrap/
   fi
 
   # package selection:
-  cp $VERBOSE ${_opt_packages:-$CONFFILES/packages} \
-    $MNTPOINT/etc/debootstrap/packages
+  cp $VERBOSE "${_opt_packages:-$CONFFILES/packages}" \
+    "${MNTPOINT}"/etc/debootstrap/packages
 
   # debconf preseeding:
   _opt_debconf=${_opt_debconf:-$CONFFILES/debconf-selections}
-  [ -f $_opt_debconf -a "$DEBCONF" = 'yes' ] && \
-    cp $VERBOSE $_opt_debconf $MNTPOINT/etc/debootstrap/debconf-selections
+  [ -f "${_opt_debconf}" ] && [ "$DEBCONF" = 'yes' ] && \
+    cp $VERBOSE "${_opt_debconf}" "${MNTPOINT}"/etc/debootstrap/debconf-selections
 
   # copy scripts that should be executed inside the chroot:
   _opt_chroot_scripts=${_opt_chroot_scripts:-$CONFFILES/chroot-scripts/}
-  [ -d $_opt_chroot_scripts -a "$CHROOT_SCRIPTS" = 'yes' ] && {
-    mkdir -p $MNTPOINT/etc/debootstrap/chroot-scripts
-    cp -a $VERBOSE $_opt_chroot_scripts/* $MNTPOINT/etc/debootstrap/chroot-scripts/
+  [ -d "$_opt_chroot_scripts" ] && [ "$CHROOT_SCRIPTS" = 'yes' ] && {
+    mkdir -p "${MNTPOINT}"/etc/debootstrap/chroot-scripts
+    cp -a $VERBOSE "${_opt_chroot_scripts}"/* "${MNTPOINT}"/etc/debootstrap/chroot-scripts/
   }
 
   # notice: do NOT use $CHROOT_VARIABLES inside chroot but statically file instead!
-  cp $VERBOSE $CHROOT_VARIABLES  $MNTPOINT/etc/debootstrap/variables
+  cp $VERBOSE "${CHROOT_VARIABLES}" "${MNTPOINT}"/etc/debootstrap/variables
 
-  cp $VERBOSE -a -L $CONFFILES/extrapackages/ $MNTPOINT/etc/debootstrap/
+  cp $VERBOSE -a -L "${CONFFILES}"/extrapackages/ "${MNTPOINT}"/etc/debootstrap/
 
   # make sure we can access network [relevant for cdebootstrap]
-  [ -f "$MNTPOINT/etc/resolv.conf" ] || cp $VERBOSE /etc/resolv.conf $MNTPOINT/etc/resolv.conf
+  [ -f "${MNTPOINT}"/etc/resolv.conf ] || cp $VERBOSE /etc/resolv.conf "${MNTPOINT}"/etc/resolv.conf
 
   # provide system's /etc/hosts to the target:
   if ! [ -f "$MNTPOINT/etc/hosts" ] ; then
-     cp $VERBOSE /etc/hosts $MNTPOINT/etc/hosts
+     cp $VERBOSE /etc/hosts "${MNTPOINT}"/etc/hosts
   fi
 
   # setup default locales
-  [ -n "$LOCALES" ] && cp $VERBOSE $CONFFILES/locale.gen  $MNTPOINT/etc/locale.gen
+  [ -n "$LOCALES" ] && cp $VERBOSE "${CONFFILES}"/locale.gen "${MNTPOINT}"/etc/locale.gen
 
   # MAKEDEV is just a forking bomb crap, let's do it on our own instead :)
-  ( cd $MNTPOINT/dev && tar zxf /etc/debootstrap/devices.tar.gz )
+  ( cd "${MNTPOINT}"/dev && tar zxf /etc/debootstrap/devices.tar.gz )
 
   # copy any existing files to chroot
-  [ -d $CONFFILES/bin   ] && cp $VERBOSE -a -L $CONFFILES/bin/*   $MNTPOINT/bin/
-  [ -d $CONFFILES/boot  ] && cp $VERBOSE -a -L $CONFFILES/boot/*  $MNTPOINT/boot/
-  [ -d $CONFFILES/etc   ] && cp $VERBOSE -a -L $CONFFILES/etc/*   $MNTPOINT/etc/
-  [ -d $CONFFILES/sbin  ] && cp $VERBOSE -a -L $CONFFILES/sbin/*  $MNTPOINT/sbin/
-  [ -d $CONFFILES/share ] && cp $VERBOSE -a -L $CONFFILES/share/* $MNTPOINT/share/
-  [ -d $CONFFILES/usr   ] && cp $VERBOSE -a -L $CONFFILES/usr/*   $MNTPOINT/usr/
-  [ -d $CONFFILES/var   ] && cp $VERBOSE -a -L $CONFFILES/var/*   $MNTPOINT/var/
-
-  # copy local network setup to chroot
-  if [ -r /etc/network/interfaces -a ! -r "${MNTPOINT}"/etc/network/interfaces ] ; then
-     [ -d $MNTPOINT/etc/network ] || mkdir $MNTPOINT/etc/network
-     cp $VERBOSE /etc/network/interfaces $MNTPOINT/etc/network/interfaces
+  [ -d "${CONFFILES}"/bin   ] && cp $VERBOSE -a -L "${CONFFILES}"/bin/*   "${MNTPOINT}"/bin/
+  [ -d "${CONFFILES}"/boot  ] && cp $VERBOSE -a -L "${CONFFILES}"/boot/*  "${MNTPOINT}"/boot/
+  [ -d "${CONFFILES}"/etc   ] && cp $VERBOSE -a -L "${CONFFILES}"/etc/*   "${MNTPOINT}"/etc/
+  [ -d "${CONFFILES}"/sbin  ] && cp $VERBOSE -a -L "${CONFFILES}"/sbin/*  "${MNTPOINT}"/sbin/
+  [ -d "${CONFFILES}"/share ] && cp $VERBOSE -a -L "${CONFFILES}"/share/* "${MNTPOINT}"/share/
+  [ -d "${CONFFILES}"/usr   ] && cp $VERBOSE -a -L "${CONFFILES}"/usr/*   "${MNTPOINT}"/usr/
+  [ -d "${CONFFILES}"/var   ] && cp $VERBOSE -a -L "${CONFFILES}"/var/*   "${MNTPOINT}"/var/
+
+  # network setup
+  DEFAULT_INTERFACES="# /etc/network/interfaces - generated by grml-debootstrap
+
+# Include files from /etc/network/interfaces.d when using
+# ifupdown v0.7.44 or newer:
+#source-directory /etc/network/interfaces.d
+
+auto lo
+iface lo inet loopback
+
+allow-hotplug eth0
+iface eth0 inet dhcp
+"
+
+  if [ -n "$NOINTERFACES" ] ; then
+    einfo "Not installing /etc/network/interfaces as requested via --nointerfaces option" ; eend 0
+  elif [ -n "$USE_DEFAULT_INTERFACES" ] ; then
+    einfo "Installing default /etc/network/interfaces as requested via --defaultinterfaces options."
+    echo "$DEFAULT_INTERFACES" > "${MNTPOINT}/etc/network/interfaces"
+    eend $?
+  elif [ -n "$VIRTUAL" ] ; then
+    einfo "Setting up Virtual Machine, installing default /etc/network/interfaces"
+    echo "$DEFAULT_INTERFACES" > "${MNTPOINT}/etc/network/interfaces"
+    eend $?
+  elif [ -r /etc/network/interfaces ] ; then
+    einfo "Copying /etc/network/interfaces from host to target system"
+    cp $VERBOSE /etc/network/interfaces "${MNTPOINT}/etc/network/interfaces"
+    eend $?
+  else
+    ewarn "Couldn't read /etc/network/interfaces, installing default /etc/network/interfaces"
+    echo "$DEFAULT_INTERFACES" > "${MNTPOINT}/etc/network/interfaces"
+    eend $?
   fi
 
   # install config file providing some example entries
@@ -1234,6 +1409,26 @@ execute_scripts() {
 }
 # }}}
 
+try_umount() {
+  local tries=$1
+  local mountpoint="$2"
+
+  for (( try=1; try<=tries; try++ )); do
+    if [[ ${try} -eq ${tries} ]]; then
+      # Last time, show errors this time
+      umount "${mountpoint}" && return 0
+    else
+      # Not last time, hide errors until fatal
+      if umount "${mountpoint}" 2>/dev/null ; then
+        return 0
+      else
+        sleep 1
+      fi
+    fi
+  done
+  return 1  # Tried enough
+}
+
 # execute chroot-script {{{
 chrootscript() {
   if ! [ -r "$MNTPOINT/bin/chroot-script" ] ; then
@@ -1246,8 +1441,14 @@ chrootscript() {
   else
     einfo "Executing chroot-script now"
     mount --bind /dev "$MNTPOINT"/dev
-    chroot "$MNTPOINT" /bin/chroot-script ; RC=$?
-    umount "$MNTPOINT"/dev
+    mount --bind /dev/pts "$MNTPOINT"/dev/pts
+    if [ "$DEBUG" = "true" ] ; then
+      chroot "$MNTPOINT" /bin/bash -x /bin/chroot-script ; RC=$?
+    else
+      chroot "$MNTPOINT" /bin/chroot-script ; RC=$?
+    fi
+    try_umount 3 "$MNTPOINT"/dev/pts
+    try_umount 3 "$MNTPOINT"/dev
     eend $RC
   fi
 
@@ -1283,7 +1484,7 @@ umount_chroot() {
   if grep -q "$MNTPOINT" /proc/mounts ; then
      if [ -n "$PARTITION" ] ; then
         einfo "Unmount $MNTPOINT"
-        umount $MNTPOINT
+        umount "$MNTPOINT"
         eend $?
      fi
   fi
@@ -1300,7 +1501,7 @@ fscktool() {
  if [ "$FSCK" = 'yes' ] ; then
    [ -n "$FSCKTOOL" ] || FSCKTOOL="fsck.${MKFS#mkfs.}"
    einfo "Checking filesystem on $TARGET using $FSCKTOOL"
-   $FSCKTOOL $TARGET
+   "$FSCKTOOL" "$TARGET"
    eend $?
  fi
 }
@@ -1311,7 +1512,11 @@ for i in prepare_vm mkfs tunefs mount_target debootstrap_system \
          preparechroot execute_pre_scripts chrootscript execute_scripts \
          umount_chroot finalize_vm fscktool ; do
     if stage "${i}" ; then
-       $i && ( stage "${i}" done && rm -f "${STAGES}/${i}" ) || bailout 2 "$i"
+      if "$i" ; then
+        stage "${i}" 'done' && rm -f "${STAGES}/${i}"
+      else
+        bailout 2 "$i"
+      fi
     fi
 done