Compare commits
	
		
			28 Commits
		
	
	
		
			v0.38
			...
			5d4c54f5fa
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| 5d4c54f5fa | |||
| c79ac4ac30 | |||
| 76c720354c | |||
| f3f348164a | |||
| dcec35459c | |||
| e4d699e228 | |||
| 48a0357a3f | |||
| 5b2f3a2f0a | |||
| 2df22b10b1 | |||
| c19e40b139 | |||
| 259c3ee1e0 | |||
| 8cabae7134 | |||
| 9fcc7a6572 | |||
| 5586b164c6 | |||
| 4cc1c476aa | |||
| ce79783540 | |||
| 18d35b9224 | |||
| f41c93368d | |||
| 452b0e4b4e | |||
| dbe9622a01 | |||
| 6ead474a78 | |||
| 4edd0b7414 | |||
| b54ebfd915 | |||
| 69665fdcef | |||
| 7e1c213ff4 | |||
| 26ceb1630a | |||
| 87e9ae894a | |||
| ed5f8f0b1c | 
							
								
								
									
										36
									
								
								README.md
									
									
									
									
									
								
							
							
						
						
									
										36
									
								
								README.md
									
									
									
									
									
								
							| @ -16,25 +16,19 @@ Config.Jail_zfs_mountpoint = none | ||||
|  | ||||
| Create jails | ||||
| ------------ | ||||
| For now, we can't pass config at creation time. We have to define config after creation:   | ||||
| You need to specify release, and optional configuration:   | ||||
| <pre><code> | ||||
| gocage create jail1 -r 13.2-RELEASE | ||||
| gocage set Config.Ip4_addr="vnet0|192.168.1.91/24" Config.Vnet=1 jail1 | ||||
| gocage create jail1 -r 13.2-RELEASE -p "Config.Ip4_addr='vnet0|192.168.1.91/24',Config.Ip6=none,Config.Boot=1" | ||||
| </code></pre> | ||||
|  | ||||
| Create basejail (jail based on a template, system will be nullfs read-only mounted from the template): | ||||
| Create basejail. A basejail is a jail based on a release: system will be nullfs read-only mounted from the release directory. Main advantage is that release updates will immediately apply to jails based on this release. Another advantage is that jail system is mounted read-only, a plus from a security perspective:   | ||||
| <pre><code> | ||||
| # First create basetpl from 13.2-RELEASE, set it as a template | ||||
| gocage create -r 13.2-RELEASE basetpl | ||||
| gocage set Config.Jailtype="template" basetpl | ||||
| # Then create basejail1 based on basetpl | ||||
| gocage create -b basetpl basejail1 | ||||
| gocage create -b -r 14.0-RELEASE basejail1 | ||||
| </code></pre> | ||||
|  | ||||
|  | ||||
| List jails | ||||
| ---------- | ||||
| Nothing fancy, just use   | ||||
| `gocage list` | ||||
|  | ||||
| ### Specify fields to display | ||||
| @ -143,20 +137,36 @@ Stop jails | ||||
| ---------- | ||||
| `gocage stop test` | ||||
|  | ||||
|  | ||||
| Update jails   | ||||
| ---------- | ||||
| To update jail patch version, use gocage update :   | ||||
| `gocage update test` | ||||
|  | ||||
| Update basejails/releases   | ||||
| ---------- | ||||
| To update basejails, you need to update the release they are base on. Specify release with -r, and the datastore storing concerned release with -d :   | ||||
| `gocage update -d fastgocage -r 14.1-RELEASE` | ||||
|  | ||||
| Upgrade jails   | ||||
| ---------- | ||||
| To upgrade jail to newer release, use gocage upgrade :   | ||||
| `gocage upgrade -r 13.2-RELEASE test` | ||||
|    | ||||
| A pre-upgrade snapshot wil be made so we can rollback if needed.   | ||||
| A pre-upgrade snapshot wil be made so you can rollback if needed.   | ||||
|  | ||||
| Upgrading basejail/release | ||||
| ---------- | ||||
| Upgrading basejails currently needs to be done manually, for each jail.   | ||||
| The idea is to stop the jail, change the content of its fstab file to point to the new release, then start jail.   | ||||
| If one change the fstab while the jail is running, its system directories won't be unmounted at stop time and this will provoke stop errors.   | ||||
| To minimize downtime, the change could be scripted:   | ||||
| `gocage stop jail1 | ||||
| sed -i .bak 's/14.0-RELEASE/14.1-RELEASE/' /iocage/jails/jail1/fstab | ||||
| # Avoid race-condition by waiting for the update in fstab | ||||
| until grep -q 14.1-RELEASE /iocage/jails/jail1/fstab; do sleep 0.2; done | ||||
| gocage start jail1` | ||||
|  | ||||
| You can now update ports. | ||||
|  | ||||
| Delete jails   | ||||
| ---------- | ||||
| @ -237,7 +247,7 @@ Fetch | ||||
| Files can be fetched from custom repository, or from local directory with "from" option.   | ||||
| For example if you destroyed releases/12.3-RELEASE and still have the downloaded files in /iocage/download/12.3-RELEASE:   | ||||
| <pre><code> | ||||
| gocage fetch -r 12.3 -o iocage --from file:/iocage/download | ||||
| gocage fetch -r 12.3 -d iocage -f file:/iocage/download | ||||
| </pre></code> | ||||
|  | ||||
|  | ||||
|  | ||||
							
								
								
									
										11
									
								
								TODO.md
									
									
									
									
									
								
							
							
						
						
									
										11
									
								
								TODO.md
									
									
									
									
									
								
							| @ -1,8 +1,19 @@ | ||||
| Replicating jails between two servers (use zrepl) | ||||
| Manage remote jails : | ||||
|   - Make gocage a service | ||||
|   - All commands should become API endpoint | ||||
|   - How to handle authentication ? | ||||
|  | ||||
| DEBUG:  | ||||
| - cmd/list.go:275: | ||||
|     // FIXME ??? Shouldn't be ioc-$Name ? | ||||
|     j.InternalName = rj.Name | ||||
| - WriteConfigToDisk don't write neither "release" in cmd stop neither "last_started" in cmd start | ||||
|   26/08/2023 : Last_started is updated | ||||
|  | ||||
| BUGS: | ||||
| - unable to set values containing equal sign : | ||||
|   # gocage set Config.Exec_poststart="jail -m allow.mount.linprocfs=1 name=ioc-poudriere-noo" poudriere-noo | ||||
|   Error parsing args: Config.Exec_poststart=jail -m allow.mount.linprocfs=1 name=ioc-poudriere-noo | ||||
| - Fix fstab when migrating jail   | ||||
|  | ||||
|  | ||||
| @ -16,6 +16,11 @@ func CreateJail(args []string) { | ||||
| 	var err error | ||||
| 	var jtype []string | ||||
|  | ||||
| 	if gCreateArgs.BaseJail && gCreateArgs.Release == "" { | ||||
| 		fmt.Println("Release should be set when creating basejail") | ||||
| 		os.Exit(1) | ||||
| 	} | ||||
|  | ||||
| 	if len(gCreateArgs.JailType) > 0 { | ||||
| 		jtype = []string{gCreateArgs.JailType} | ||||
| 	} | ||||
| @ -39,7 +44,7 @@ func CreateJail(args []string) { | ||||
|  | ||||
| 		var ds *Datastore | ||||
| 		if len(gCreateArgs.Datastore) > 0 { | ||||
| 			fmt.Printf("DEBUG: Use %s datastore\n", gCreateArgs.Datastore) | ||||
| 			log.Debugf("Use %s datastore\n", gCreateArgs.Datastore) | ||||
| 			ds, err = getDatastoreFromArray(gCreateArgs.Datastore, gDatastores) | ||||
| 			if err != nil { | ||||
| 				fmt.Printf("ERROR Getting datastore: %s\n", gCreateArgs.Datastore, err.Error()) | ||||
| @ -50,21 +55,20 @@ func CreateJail(args []string) { | ||||
| 		} | ||||
|  | ||||
| 		// Get base template if specified | ||||
| 		if len(gCreateArgs.BaseTemplate) > 0 { | ||||
| 		if gCreateArgs.BaseJail { | ||||
| 			/************************************************************************** | ||||
| 			*  Create based jail from a template | ||||
| 			*/ | ||||
| 			log.Debugf("Jail will be created from a base template\n") | ||||
| 			bj, err := getJailFromArray(gCreateArgs.BaseTemplate, []string{"template"}, gJails) | ||||
| 			if err != nil { | ||||
| 				if strings.EqualFold(err.Error(), "Jail not found") { | ||||
| 					fmt.Printf("Template not found\n") | ||||
| 					return | ||||
| 				} else { | ||||
| 					fmt.Printf("ERROR: %s\n", err.Error()) | ||||
| 			log.Debugf("Jail will be created read-only from release %s\n", gCreateArgs.Release) | ||||
|  | ||||
| 			// First check if we got release on the same datastore | ||||
| 			releasePath := fmt.Sprintf("%s/releases/%s/root", ds.Mountpoint, gCreateArgs.Release) | ||||
| 			_, err := os.Stat(releasePath) | ||||
| 			if os.IsNotExist(err) { | ||||
| 				fmt.Printf("ERROR: Release locally not available. Run \"gocage fetch\"\n") | ||||
| 				return | ||||
| 			} | ||||
| 			} | ||||
|  | ||||
| 			// Create jail datasets | ||||
| 			dstDset := fmt.Sprintf("%s/jails/%s", ds.ZFSDataset, jname) | ||||
| 			fmt.Printf("    > Initialize dataset %s\n", dstDset) | ||||
| @ -87,7 +91,7 @@ func CreateJail(args []string) { | ||||
| 			dstRootDir := fmt.Sprintf("%s/jails/%s/root", ds.Mountpoint, jname) | ||||
| 			for _, d := range append(gBaseDirs, gEmptyDirs...) { | ||||
| 				dstPath := dstRootDir | ||||
| 				srcPath := bj.RootPath | ||||
| 				srcPath := releasePath | ||||
| 				for _, cd := range strings.Split(d, "/") { | ||||
| 					srcPath = fmt.Sprintf("%s/%s", srcPath, cd) | ||||
| 					dstPath = fmt.Sprintf("%s/%s", dstPath, cd) | ||||
| @ -110,9 +114,9 @@ func CreateJail(args []string) { | ||||
| 			// Copy these from basejail | ||||
| 			fmt.Printf("    > Create base writable directories\n") | ||||
| 			for _, d := range gCopyDirs { | ||||
| 				err := cp.Copy(fmt.Sprintf("%s/%s", bj.RootPath, d), fmt.Sprintf("%s/%s", dstRootDir, d)) | ||||
| 				err := cp.Copy(fmt.Sprintf("%s/%s", releasePath, d), fmt.Sprintf("%s/%s", dstRootDir, d)) | ||||
| 				if err != nil { | ||||
| 					fmt.Printf("ERROR copying %s to %s: %s\n", fmt.Sprintf("%s/%s", bj.RootPath, d), | ||||
| 					fmt.Printf("ERROR copying %s to %s: %s\n", fmt.Sprintf("%s/%s", releasePath, d), | ||||
| 						   fmt.Sprintf("%s/%s", dstRootDir, d), err.Error()) | ||||
| 					return | ||||
| 				} | ||||
| @ -150,7 +154,7 @@ func CreateJail(args []string) { | ||||
| 			// 2. Add a json item to config ("basejail_template" p.e.), but iocage would delete it once jail is started from iocage | ||||
| 			// 3. Add a gocage specific config ("config.gocage.json" p.e.) | ||||
| 			j.Config.Jailtype = "basejail" | ||||
| 			j.Config.Origin = bj.Name | ||||
| 			j.Config.Origin = gCreateArgs.Release | ||||
| 			j.Config.Host_hostname = jname | ||||
| 			j.Config.Host_hostuuid = jname | ||||
|  | ||||
| @ -166,7 +170,7 @@ func CreateJail(args []string) { | ||||
| 			defer fstabHandle.Close() | ||||
|  | ||||
| 			for _, d := range gBaseDirs { | ||||
| 				fmt.Fprintf(fstabHandle, "%s\t%s\tnullfs\tro\t0\t0\n", fmt.Sprintf("%s/%s", bj.RootPath, d), fmt.Sprintf("%s/%s", dstRootDir, d)) | ||||
| 				fmt.Fprintf(fstabHandle, "%s\t%s\tnullfs\tro\t0\t0\n", fmt.Sprintf("%s/%s", releasePath, d), fmt.Sprintf("%s/%s", dstRootDir, d)) | ||||
| 			} | ||||
|  | ||||
| 			fmt.Printf("  > Jail created!\n") | ||||
| @ -268,7 +272,6 @@ func CreateJail(args []string) { | ||||
| 			j.Config.Host_hostname = jname | ||||
| 			j.Config.Host_hostuuid = jname | ||||
| 			j.Config.Jailtype = "jail" | ||||
| 						 | ||||
| 			j.WriteConfigToDisk(false) | ||||
|  | ||||
| 			/////////////////////////////////////////////////////////////////////// | ||||
| @ -281,5 +284,17 @@ func CreateJail(args []string) { | ||||
| 			defer fstabHandle.Close() | ||||
| 			fmt.Printf("  > Jail created!\n") | ||||
| 		} | ||||
|  | ||||
| 		var cmdline []string | ||||
| 		for _, props := range strings.Split(gCreateArgs.Properties, ",") { | ||||
| 			cmdline = append(cmdline, props) | ||||
| 		} | ||||
|  | ||||
| 		// Reload jail list so SetJailProperties will see it | ||||
| 		ListJails(nil, false) | ||||
|  | ||||
| 		cmdline = append(cmdline, jname) | ||||
| 		log.Debugf("cmdline: \"%v\"", cmdline) | ||||
| 		SetJailProperties(cmdline) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| @ -1,85 +0,0 @@ | ||||
| package cmd | ||||
|  | ||||
| const ( | ||||
| 	fbsdUpdateConfig = ` | ||||
| 	# $FreeBSD$ | ||||
| 	 | ||||
| 	# Trusted keyprint.  Changing this is a Bad Idea unless you've received | ||||
| 	# a PGP-signed email from <security-officer@FreeBSD.org> telling you to | ||||
| 	# change it and explaining why. | ||||
| 	KeyPrint 800651ef4b4c71c27e60786d7b487188970f4b4169cc055784e21eb71d410cc5 | ||||
| 	 | ||||
| 	# Server or server pool from which to fetch updates.  You can change | ||||
| 	# this to point at a specific server if you want, but in most cases | ||||
| 	# using a "nearby" server won't provide a measurable improvement in | ||||
| 	# performance. | ||||
| 	ServerName update.FreeBSD.org | ||||
| 	 | ||||
| 	# Components of the base system which should be kept updated. | ||||
| 	Components world | ||||
| 	 | ||||
| 	# Example for updating the userland and the kernel source code only: | ||||
| 	# Components src/base src/sys world | ||||
| 	 | ||||
| 	# Paths which start with anything matching an entry in an IgnorePaths | ||||
| 	# statement will be ignored. | ||||
| 	IgnorePaths | ||||
| 	 | ||||
| 	# Paths which start with anything matching an entry in an IDSIgnorePaths | ||||
| 	# statement will be ignored by "freebsd-update IDS". | ||||
| 	IDSIgnorePaths /usr/share/man/cat | ||||
| 	IDSIgnorePaths /usr/share/man/whatis | ||||
| 	IDSIgnorePaths /var/db/locate.database | ||||
| 	IDSIgnorePaths /var/log | ||||
| 	 | ||||
| 	# Paths which start with anything matching an entry in an UpdateIfUnmodified | ||||
| 	# statement will only be updated if the contents of the file have not been | ||||
| 	# modified by the user (unless changes are merged; see below). | ||||
| 	UpdateIfUnmodified /etc/ /var/ /root/ /.cshrc /.profile | ||||
| 	 | ||||
| 	# When upgrading to a new FreeBSD release, files which match MergeChanges | ||||
| 	# will have any local changes merged into the version from the new release. | ||||
| 	MergeChanges /etc/ | ||||
| 	 | ||||
| 	### Default configuration options: | ||||
| 	 | ||||
| 	# Directory in which to store downloaded updates and temporary | ||||
| 	# files used by FreeBSD Update. | ||||
| 	WorkDir /iocage/freebsd-update | ||||
| 	 | ||||
| 	# Destination to send output of "freebsd-update cron" if an error | ||||
| 	# occurs or updates have been downloaded. | ||||
| 	# MailTo root | ||||
| 	 | ||||
| 	# Is FreeBSD Update allowed to create new files? | ||||
| 	# AllowAdd yes | ||||
| 	 | ||||
| 	# Is FreeBSD Update allowed to delete files? | ||||
| 	# AllowDelete yes | ||||
| 	 | ||||
| 	# If the user has modified file ownership, permissions, or flags, should | ||||
| 	# FreeBSD Update retain this modified metadata when installing a new version | ||||
| 	# of that file? | ||||
| 	# KeepModifiedMetadata yes | ||||
| 	 | ||||
| 	# When upgrading between releases, should the list of Components be | ||||
| 	# read strictly (StrictComponents yes) or merely as a list of components | ||||
| 	# which *might* be installed of which FreeBSD Update should figure out | ||||
| 	# which actually are installed and upgrade those (StrictComponents no)? | ||||
| 	StrictComponents yes | ||||
| 	 | ||||
| 	# When installing a new kernel perform a backup of the old one first | ||||
| 	# so it is possible to boot the old kernel in case of problems. | ||||
| 	BackupKernel no | ||||
| 	 | ||||
| 	# If BackupKernel is enabled, the backup kernel is saved to this | ||||
| 	# directory. | ||||
| 	# BackupKernelDir /boot/kernel.old | ||||
| 	 | ||||
| 	# When backing up a kernel also back up debug symbol files? | ||||
| 	BackupKernelSymbolFiles no | ||||
| 	 | ||||
| 	# Create a new boot environment when installing patches | ||||
| 	CreateBootEnv no | ||||
| 	` | ||||
| )  | ||||
							
								
								
									
										153
									
								
								cmd/init.go
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										153
									
								
								cmd/init.go
									
									
									
									
									
										Normal file
									
								
							| @ -0,0 +1,153 @@ | ||||
| package cmd | ||||
|  | ||||
| import ( | ||||
| 	"os" | ||||
| 	"fmt" | ||||
| 	"strings" | ||||
|  | ||||
| 	"github.com/spf13/viper" | ||||
| 	log "github.com/sirupsen/logrus" | ||||
| ) | ||||
|  | ||||
| /******************************************************************************** | ||||
|  * Initialize datastore(s) /iocage, /iocage/jails | ||||
|  * Put defaults.json, | ||||
|  * Update it with hostid, interfaces, and maybe other necessary fields | ||||
|  * Initialize bridge | ||||
|  *******************************************************************************/ | ||||
| func InitGoCage(args []string) { | ||||
| 	// Create datastores | ||||
| 	for _, dstore := range viper.GetStringSlice("datastore") { | ||||
| 		log.Debugf("Ranging over %v\n", dstore) | ||||
| 		dset, err := zfsGetDatasetByMountpoint(dstore) | ||||
| 		if err != nil && strings.HasSuffix(err.Error(), "No such file or directory\"") { | ||||
| 			if len(gZPool) == 0 { | ||||
| 				log.Errorf("Datastore mountpoint \"%s\" does not exist. Specify a pool if you want to create it.", dstore) | ||||
| 				return | ||||
| 			} | ||||
| 			// Create dataset /iocage | ||||
| 			rootDSName := fmt.Sprintf("%s%s", gZPool, dstore) | ||||
| 			log.Debugf("Creating dataset %s mounted on %s\n", rootDSName, dstore) | ||||
| 			if err = zfsCreateDataset(rootDSName, dstore, ""); err != nil { | ||||
| 				log.Errorf("Error creating dataset %s: %v\n", rootDSName, err) | ||||
| 				return | ||||
| 			} | ||||
| 			// Create /iocage/jail, releases, templates | ||||
| 			for _, l := range []string{"jails","releases","templates"} { | ||||
| 				cds := fmt.Sprintf("%s/%s", rootDSName, l) | ||||
| 				cmp := fmt.Sprintf("%s/%s", dstore, l) | ||||
| 				log.Debugf("Creating dataset %s mounted on %s\n", cds, cmp) | ||||
| 				if err = zfsCreateDataset(cds, cmp, ""); err != nil { | ||||
| 					log.Errorf("Error creating dataset %s: %v\n", cds, err) | ||||
| 					return | ||||
| 				} | ||||
| 			} | ||||
| 			 | ||||
| 			// Create /iocage/defaults.json | ||||
| 			exists, err := doFileExist(fmt.Sprintf("%s/defaults.json", dstore)) | ||||
| 			if err != nil { | ||||
| 				log.Errorf("Error checking defaults.json: %v\n", err) | ||||
| 				return | ||||
| 			} | ||||
| 			if !exists { | ||||
| 				if err = createDefaultsJson(dstore, gBridge); err != nil { | ||||
| 					log.Errorf("%v\n", err) | ||||
| 				} | ||||
| 			} | ||||
| 		} else if err != nil { | ||||
| 			log.Errorf("Error checking datastore existence: %v\n", err) | ||||
| 			return | ||||
| 		} else { | ||||
| 			log.Debugf("Datastore dataset exist: %s\n", dset) | ||||
| 		} | ||||
| 	} | ||||
| 	// Check and create bridge | ||||
| 	// FIXME: What if bridge name is invalid, as we already wrote it in defaults.json in dstore loop? | ||||
| 	if len(gBridge) > 0 && len(gInterface) > 0 { | ||||
| 		if err := initBridge(); err != nil { | ||||
| 			log.Errorf("%v\n", err) | ||||
| 		} | ||||
| 	} | ||||
| } | ||||
|  | ||||
| func createDefaultsJson(rootDirectory string, bridge string) error { | ||||
| 	hostid, err := os.ReadFile("/etc/hostid") | ||||
| 	if err != nil { | ||||
| 		log.Fatalf("Unable to read /etc/hostid: %v\n", err) | ||||
| 	} | ||||
| 	json := strings.Replace(gDefaultsJson, "TO-BE-REPLACED-WITH-HOSTID", strings.Trim(string(hostid), "\n"), 1) | ||||
| 	json = strings.Replace(json, "TO-BE-REPLACED-WITH-BRIDGE", bridge, 1) | ||||
| 	if err := os.WriteFile(fmt.Sprintf("%s/defaults.json", rootDirectory), []byte(json), 0640); err != nil { | ||||
| 		log.Fatal(err) | ||||
| 	} | ||||
| 	 | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func createInterface(iface string) error { | ||||
| 	log.Debugf("creating interface \"%s\"\n", iface) | ||||
| 	cmd := fmt.Sprintf("/sbin/ifconfig %s create", iface) | ||||
| 	_, err := executeCommand(cmd) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func bringUpInterface(iface string) error { | ||||
| 	log.Debugf("bringing up interface \"%s\"\n", iface) | ||||
| 	cmd := fmt.Sprintf("/sbin/ifconfig %s up", iface) | ||||
| 	_, err := executeCommand(cmd) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func addMemberToBridge(bridge string, iface string) error { | ||||
| 	log.Debugf("adding member interface \"%s\" to bridge \"%s\"\n", iface, bridge) | ||||
| 	cmd := fmt.Sprintf("/sbin/ifconfig %s addm %s", bridge, iface) | ||||
| 	_, err := executeCommand(cmd) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| func initBridge() error { | ||||
| 	hostInt, err := gJailHost.GetInterfaces() | ||||
| 	if err != nil { | ||||
| 		return fmt.Errorf("Error listing interfaces: %v\n", err) | ||||
| 	} | ||||
| 	if !isStringInArray(hostInt, gInterface) { | ||||
| 		return fmt.Errorf("Interface not found: %s\n", gInterface) | ||||
| 	} | ||||
| 	if !isStringInArray(hostInt, gBridge) { | ||||
| 		if err := createInterface(gBridge); err != nil { | ||||
| 			return fmt.Errorf("Error creating bridge: %v\n", err) | ||||
| 		} | ||||
| 		if err := bringUpInterface(gBridge); err != nil { | ||||
| 			return fmt.Errorf("Error bringing up bridge: %v\n", err) | ||||
| 		} | ||||
| 		log.Infof("bridge was created, but it won't persist reboot. Configure rc.conf to persist. See https://docs.freebsd.org/en/books/handbook/advanced-networking/#network-bridging\n") | ||||
| 		log.Infof("It is strongly suggested you move interface %s IP to bridge %s\n", gInterface, gBridge) | ||||
| 	} | ||||
| 	// FIXME: Need to check if not already member | ||||
| 	members, err := getBridgeMembers(gBridge) | ||||
| 	if err != nil { | ||||
| 		return fmt.Errorf("Error getting bridge members: %v\n", err) | ||||
| 	} | ||||
| 	 | ||||
| 	// Return if interface already member of the bridge | ||||
| 	for _, m := range members { | ||||
| 		log.Debugf("Bridge member: %s\n", m) | ||||
| 		if strings.EqualFold(m, gInterface) { | ||||
| 			return nil | ||||
| 		} | ||||
| 	} | ||||
| 	if err := addMemberToBridge(gBridge, gInterface); err != nil { | ||||
| 		return fmt.Errorf("Error adding interface to bridge: %v\n", err) | ||||
| 	} | ||||
|  | ||||
| 	return nil | ||||
| } | ||||
| @ -1,8 +1,9 @@ | ||||
| package cmd | ||||
|  | ||||
| import ( | ||||
| 	"errors" | ||||
| 	"os" | ||||
| 	"fmt" | ||||
| 	"errors" | ||||
| 	"reflect" | ||||
| 	"strconv" | ||||
| 	"strings" | ||||
| @ -20,7 +21,7 @@ func GetJailProperties(args []string) { | ||||
| 				jail, err = getJailFromArray(a, []string{""}, gJails) | ||||
| 				if err != nil { | ||||
| 					fmt.Printf("Error: %s\n", err.Error()) | ||||
| 					return | ||||
| 					os.Exit(1) | ||||
| 				} | ||||
| 			} else { | ||||
| 				props = append(props, a) | ||||
| @ -105,20 +106,20 @@ func SetJailProperties(args []string) { | ||||
| 		return | ||||
| 	} | ||||
|  | ||||
| 	// Get jail by index to modify it | ||||
| 	for i, _ := range gJails { | ||||
| 		if gJails[i].Name == jail.Name { | ||||
| 	cj, err := getJailFromArray(jail.Name, []string{""}, gJails) | ||||
| 	if err != nil { | ||||
| 		fmt.Printf("Error getting jail %s: %v\n", jail.Name, err) | ||||
| 		return | ||||
| 	} | ||||
|  | ||||
| 	for _, p := range props { | ||||
| 				err := setStructFieldValue(&gJails[i], p.name, p.value) | ||||
| 		err := setStructFieldValue(cj, p.name, p.value) | ||||
| 		if err != nil { | ||||
| 			fmt.Printf("Error: %s\n", err.Error()) | ||||
| 			return | ||||
| 		} else { | ||||
| 					fmt.Printf("%s: %s set to %s\n", gJails[i].Name, p.name, p.value) | ||||
| 					gJails[i].ConfigUpdated = true | ||||
| 				} | ||||
| 			} | ||||
| 			writeConfigToDisk(&gJails[i], false) | ||||
| 			fmt.Printf("%s: %s set to %s\n", cj.Name, p.name, p.value) | ||||
| 		} | ||||
| 	} | ||||
| 	cj.WriteConfigToDisk(false) | ||||
| } | ||||
|  | ||||
							
								
								
									
										65
									
								
								cmd/root.go
									
									
									
									
									
								
							
							
						
						
									
										65
									
								
								cmd/root.go
									
									
									
									
									
								
							| @ -14,7 +14,7 @@ import ( | ||||
| ) | ||||
|  | ||||
| const ( | ||||
| 	gVersion = "0.38" | ||||
| 	gVersion = "0.42c" | ||||
| 	 | ||||
| 	// TODO : Get from $jail_zpool/defaults.json | ||||
| 	MIN_DYN_DEVFS_RULESET = 1000 | ||||
| @ -22,9 +22,10 @@ const ( | ||||
|  | ||||
| type createArgs struct { | ||||
| 	Release      string | ||||
| 	BaseTemplate string | ||||
| 	BaseJail     bool | ||||
| 	Datastore    string | ||||
| 	JailType     string | ||||
| 	Properties   string | ||||
| } | ||||
|  | ||||
| var ( | ||||
| @ -56,6 +57,9 @@ var ( | ||||
|  | ||||
| 	gTimeZone     string | ||||
| 	gSnapshotName string | ||||
| 	gZPool        string | ||||
| 	gBridge       string | ||||
| 	gInterface    string | ||||
|  | ||||
| 	gMigrateDestDatastore string | ||||
| 	gYesToAll             bool | ||||
| @ -64,6 +68,8 @@ var ( | ||||
| 	gFetchIntoDS     string | ||||
| 	gFetchFrom       string | ||||
| 	gUpgradeRelease  string | ||||
| 	gUpdateRelease   string | ||||
| 	gUpdateReleaseDS string | ||||
|  | ||||
| 	// For a based jail, these are directories binded to basejail | ||||
| 	gBaseDirs = []string{"bin", "boot", "lib", "libexec", "rescue", "sbin", "usr/bin", "usr/include", | ||||
| @ -97,19 +103,13 @@ It support iocage jails and can coexist with iocage.`, | ||||
| 		}, | ||||
| 	} | ||||
|  | ||||
| 	/* TODO | ||||
| 	Initialize datastore(s) /iocage, /iocage/jails | ||||
| 	Put defaults.json, update it with hostid,interfaces, and maybe other necessary fields | ||||
| 	Initialize bridge | ||||
| 	initCmd = &cobra.Command{ | ||||
| 		Use:   "init", | ||||
| 		Short: "Initialize GoCage", | ||||
| 		//Long:  `Let this show you how much fail I had to get this *cough* perfect`, | ||||
| 		Run: func(cmd *cobra.Command, args []string) { | ||||
| 			fv, _ := getFreeBSDVersion() | ||||
| 			fmt.Printf("GoCage v.%s on FreeBSD %d.%d-%s\n", gVersion, fv.major, fv.minor, fv.flavor) | ||||
| 			InitGoCage(args) | ||||
| 		}, | ||||
| 	}*/ | ||||
| 	} | ||||
|  | ||||
| 	listCmd = &cobra.Command{ | ||||
| 		Use:   "list", | ||||
| @ -379,6 +379,11 @@ func init() { | ||||
| 	rootCmd.PersistentFlags().BoolVar(&gDebug, "debug", false, "Debug mode") | ||||
|  | ||||
| 	// Command dependant switches | ||||
| 	initCmd.Flags().StringVarP(&gZPool, "pool", "p", "", "ZFS pool to create datastore on") | ||||
| 	initCmd.Flags().StringVarP(&gBridge, "bridge", "b", "", "bridge to create for jails networking") | ||||
| 	initCmd.Flags().StringVarP(&gInterface, "interface", "i", "", "interface to add as bridge member. This should be your main interface") | ||||
| 	initCmd.MarkFlagRequired("bridge") | ||||
| 	initCmd.MarkFlagsRequiredTogether("bridge", "interface") | ||||
|  | ||||
| 	// We reuse these flags in "gocage snapshot list myjail" and 'gocage datastore list" commands | ||||
| 	listCmd.Flags().StringVarP(&gDisplayJColumns, "outcol", "o", "JID,Name,Config.Release,Config.Ip4_addr,Running", "Show these columns in output") | ||||
| @ -411,19 +416,25 @@ func init() { | ||||
| 	migrateCmd.MarkFlagRequired("datastore") | ||||
|  | ||||
| 	fetchCmd.Flags().StringVarP(&gFetchRelease, "release", "r", "", "Release to fetch (e.g.: \"13.1-RELEASE\"") | ||||
| 	fetchCmd.Flags().StringVarP(&gFetchIntoDS, "datastore", "o", "", "Datastore release will be saved to") | ||||
| 	fetchCmd.Flags().StringVarP(&gFetchFrom, "from", "d", "", "Repository to download from. Should contain XY.Z-RELEASE. File protocol supported") | ||||
| 	fetchCmd.Flags().StringVarP(&gFetchIntoDS, "datastore", "d", "", "Datastore release will be saved to") | ||||
| 	fetchCmd.Flags().StringVarP(&gFetchFrom, "from", "f", "", "Repository to download from. Should contain XY.Z-RELEASE. File protocol supported") | ||||
| 	fetchCmd.MarkFlagRequired("release") | ||||
| 	fetchCmd.MarkFlagRequired("datastore") | ||||
|  | ||||
| 	upgradeCmd.Flags().StringVarP(&gUpgradeRelease, "release", "r", "", "Release to upgrade to (e.g.: \"13.1-RELEASE\"") | ||||
| 	upgradeCmd.MarkFlagRequired("release") | ||||
|  | ||||
| 	updateCmd.Flags().StringVarP(&gUpdateRelease, "release", "r", "", "Release to update (e.g.: \"13.1-RELEASE\"") | ||||
| 	updateCmd.Flags().StringVarP(&gUpdateReleaseDS, "datastore", "d", "", "Datastore release is stored on") | ||||
| 	updateCmd.MarkFlagsRequiredTogether("release", "datastore") | ||||
|  | ||||
| 	createCmd.Flags().StringVarP(&gCreateArgs.Release, "release", "r", "", "Release for the jail (e.g.: \"13.1-RELEASE\"") | ||||
| 	createCmd.Flags().StringVarP(&gCreateArgs.BaseTemplate, "basetpl", "b", "", "Base template. This will create a jail based on basetpl, so every up(date|grade) made to basetpl will immediately propagate to new jail\n") | ||||
| 	createCmd.Flags().BoolVarP(&gCreateArgs.BaseJail, "basejail", "b", false, "Basejail. This will create a jail mounted read only from a release, so every up(date|grade) made to this release will immediately propagate to new jail.\n") | ||||
| 	createCmd.Flags().StringVarP(&gCreateArgs.Datastore, "datastore", "d", "", "Datastore to create the jail on. Defaults to first declared in config.") | ||||
| 	createCmd.Flags().StringVarP(&gCreateArgs.Properties, "configuration", "p", "", "Configuration properties with format k1=v1,k2=v2 (Ex: \"Config.Ip4_addr=vnet0|192.168.1.2,Config.Ip6=none\")") | ||||
|  | ||||
| 	// Now declare commands | ||||
| 	rootCmd.AddCommand(initCmd) | ||||
| 	rootCmd.AddCommand(versionCmd) | ||||
| 	rootCmd.AddCommand(listCmd) | ||||
| 	listCmd.AddCommand(listPropsCmd) | ||||
| @ -441,7 +452,6 @@ func init() { | ||||
| 	rootCmd.AddCommand(updateCmd) | ||||
| 	rootCmd.AddCommand(upgradeCmd) | ||||
| 	rootCmd.AddCommand(createCmd) | ||||
| 	 | ||||
| 	rootCmd.AddCommand(testCmd) | ||||
| 	 | ||||
| 	snapshotCmd.AddCommand(snapshotListCmd) | ||||
| @ -472,17 +482,6 @@ func initConfig() { | ||||
| 		os.Exit(1) | ||||
| 	} | ||||
|  | ||||
| 	// Load default configs from datastores | ||||
| 	err := ListDatastores(viper.GetStringSlice("datastore"), false) | ||||
| 	if err != nil { | ||||
| 		fmt.Printf("ERROR: error checking datastores: %v\n", err) | ||||
| 		os.Exit(1) | ||||
| 	} | ||||
|  | ||||
| 	//	fmt.Println("Using config file:", viper.ConfigFileUsed()) | ||||
| 	//	fmt.Printf("datastore in config : %s\n", viper.GetStringSlice("datastore")) | ||||
| 	//	fmt.Printf("datastore.0 in config : %s\n", viper.GetStringSlice("datastore.0")) | ||||
|  | ||||
| 	// Command line flags have priority on config file | ||||
| 	if rootCmd.Flags().Lookup("sudo") != nil && false == rootCmd.Flags().Lookup("sudo").Changed { | ||||
| 		gUseSudo = viper.GetBool("sudo") | ||||
| @ -516,11 +515,25 @@ func initConfig() { | ||||
| 		os.Exit(1) | ||||
| 	} | ||||
|  | ||||
| 	 | ||||
| 	if gDebug { | ||||
| 		log.SetLevel(log.DebugLevel) | ||||
| 		log.Debugf("Debug mode enabled\n") | ||||
| 	} | ||||
|  | ||||
| 	// no need to check prerequesites if we are initializing gocage | ||||
| 	for _, rc := range rootCmd.Commands() { | ||||
| 		//fmt.Printf("DEBUG: rootCmd subcommand: %v. Was it called? %s\n", rc.Use, rootCmd.Commands()[i].CalledAs()) | ||||
| 		if len(rc.CalledAs()) > 0 && strings.EqualFold("init", rc.CalledAs()) { | ||||
| 			return | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	// Load default configs from datastores | ||||
| 	err := ListDatastores(viper.GetStringSlice("datastore"), false) | ||||
| 	if err != nil { | ||||
| 		fmt.Printf("ERROR: error checking datastores: %v\n", err) | ||||
| 		os.Exit(1) | ||||
| 	} | ||||
| } | ||||
|  | ||||
|  | ||||
|  | ||||
							
								
								
									
										37
									
								
								cmd/start.go
									
									
									
									
									
								
							
							
						
						
									
										37
									
								
								cmd/start.go
									
									
									
									
									
								
							| @ -340,7 +340,7 @@ func configureDhcpOrAcceptRtadv(jail *Jail, ipproto int, enable bool) error { | ||||
|  | ||||
| 		if ipproto == IPv6 { | ||||
| 			key = fmt.Sprintf("%s_ipv6", key) | ||||
| 			value = "inet6 auto_linklocal accept_rtadv autoconf" | ||||
| 			value = "\"inet6 auto_linklocal accept_rtadv autoconf\"" | ||||
| 		} | ||||
|  | ||||
| 		if enable == true { | ||||
| @ -363,7 +363,7 @@ func checkRtsold(jail *Jail) error { | ||||
| 	if strings.Contains(jail.Config.Ip6_addr, "accept_rtadv") == false { | ||||
| 		return fmt.Errorf("Must set at least one ip6_addr to accept_rtadv!\n") | ||||
| 	} | ||||
| 	err := enableRcKeyValue(jail.ConfigPath, "rtsold_enable", "yes") | ||||
| 	err := enableRcKeyValue(fmt.Sprintf("%s/etc/rc.conf", jail.RootPath), "rtsold_enable", "yes") | ||||
| 	if err != nil { | ||||
| 		return fmt.Errorf("ERROR setting rtsold_enable=YES with sysrc for jail %s: %s\n", jail.Name, err) | ||||
| 	} | ||||
| @ -810,7 +810,9 @@ func generateMAC(jail *Jail, nic string) ([]byte, []byte, error) { | ||||
| 	} | ||||
| 	 | ||||
| 	hsmac := append(prefix, suffix...) | ||||
| 	jsmac := append(hsmac[:5], hsmac[5]+1) | ||||
| 	jsmac := make([]byte, 6) | ||||
| 	copy(jsmac, hsmac) | ||||
| 	jsmac[5] = jsmac[5] + 1 | ||||
| 	 | ||||
| 	// Save MACs to config | ||||
| 	pname := fmt.Sprintf("Config.%s_mac", strings.Title(nic)) | ||||
| @ -840,7 +842,7 @@ func setupVnetInterfaceHostSide(jail *Jail) ([]string, error) { | ||||
| 		bridge := v[1] | ||||
| 		 | ||||
| 		// Get host side MAC | ||||
| 		pname := fmt.Sprintf("Config.%s_mac", nic) | ||||
| 		pname := fmt.Sprintf("Config.%s_mac", strings.Title(nic)) | ||||
| 		var val *reflect.Value | ||||
| 		val, pname, err = getStructFieldValue(jail, pname) | ||||
| 		if err != nil { | ||||
| @ -853,13 +855,22 @@ func setupVnetInterfaceHostSide(jail *Jail) ([]string, error) { | ||||
| 				return []string{}, err | ||||
| 			} | ||||
| 		} else { | ||||
| 			hsmac = val.Bytes() | ||||
| 			if strings.EqualFold(val.String(), "none") { | ||||
| 				hsmac, _, err = generateMAC(jail, nic) | ||||
| 				if err != nil { | ||||
| 					return []string{}, err | ||||
| 				} | ||||
| 			} | ||||
| 			hsmac, err = hex.DecodeString(strings.Split(val.String(), " ")[0]) | ||||
| 			if err != nil { | ||||
| 				return []string{}, fmt.Errorf("Error converting %s to hex\n", strings.Split(val.String(), " ")[0]) | ||||
| 			} | ||||
| 		} | ||||
| 		 | ||||
| 		// Get bridge MTU | ||||
| 		mtu, err := gJailHost.GetBridgeMTU(bridge) | ||||
| 		if err != nil { | ||||
| 			return []string{}, fmt.Errorf("Error getting bridge mtu: %v\n", err) | ||||
| 			return []string{}, fmt.Errorf("Error getting bridge \"%s\" mtu: %v\n", bridge, err) | ||||
| 		} | ||||
| 		 | ||||
| 		// Create epair interface | ||||
| @ -909,8 +920,10 @@ func setupVnetInterfaceJailSide(jail *Jail, hostepairs []string) error { | ||||
| 	 | ||||
| 	for _, i := range strings.Split(jail.Config.Ip4_addr, ",") { | ||||
| 		v := strings.Split(i, "|") | ||||
| 		if len(v) > 1 { | ||||
| 			ip4s[v[0]] = v[1] | ||||
| 		} | ||||
| 	} | ||||
| 	for _, i := range strings.Split(jail.Config.Ip6_addr, ",") { | ||||
| 		v := strings.Split(i, "|") | ||||
| 		if len(v) > 1 { | ||||
| @ -934,7 +947,7 @@ func setupVnetInterfaceJailSide(jail *Jail, hostepairs []string) error { | ||||
| 		jsepair := fmt.Sprintf("%sb", strings.TrimSuffix(hostepairs[i], "a")) | ||||
|  | ||||
| 		// Get jail side MAC | ||||
| 		pname := fmt.Sprintf("Config.%s_mac", nic) | ||||
| 		pname := fmt.Sprintf("Config.%s_mac", strings.Title(nic)) | ||||
| 		var val *reflect.Value | ||||
| 		val, pname, err = getStructFieldValue(jail, pname) | ||||
| 		if err != nil { | ||||
| @ -947,7 +960,11 @@ func setupVnetInterfaceJailSide(jail *Jail, hostepairs []string) error { | ||||
| 				return err | ||||
| 			} | ||||
| 		} else { | ||||
| 			jsmac = val.Bytes() | ||||
| 			jsmac, err = hex.DecodeString(strings.Split(val.String(), " ")[1]) | ||||
|                         if err != nil { | ||||
|                                 return fmt.Errorf("Error converting %s to hex\n", strings.Split(val.String(), " ")[1]) | ||||
|                         } | ||||
|  | ||||
| 		} | ||||
|  | ||||
| 		cmd := fmt.Sprintf("/sbin/ifconfig %s vnet %s", jsepair, jail.InternalName) | ||||
| @ -959,7 +976,7 @@ func setupVnetInterfaceJailSide(jail *Jail, hostepairs []string) error { | ||||
| 		// Get bridge MTU | ||||
| 		mtu, err := gJailHost.GetBridgeMTU(bridge) | ||||
| 		if err != nil { | ||||
| 			return fmt.Errorf("Error getting bridge %s mtu: %v\n", bridge, err) | ||||
| 			return fmt.Errorf("Error getting bridge \"%s\" mtu: %v\n", bridge, err) | ||||
| 		} | ||||
|  | ||||
| 		cmd = fmt.Sprintf("/usr/sbin/jexec %d ifconfig %s mtu %d", jail.JID, jsepair, mtu) | ||||
| @ -1431,7 +1448,7 @@ func StartJail(args []string) { | ||||
| 		fmt.Printf("  > Setup VNet network: OK\n") | ||||
| 		 | ||||
| 		// Set default route, unless main network is dhcp | ||||
| 		if ! cj.isFirstNetDhcp() { | ||||
| 		if ! cj.isFirstNetDhcp() && !strings.EqualFold(cj.Config.Ip4_addr, "none") { | ||||
| 			fmt.Printf("  > Setup default ipv4 gateway:\n") | ||||
| 			cmd := fmt.Sprintf("/usr/sbin/setfib %s /usr/sbin/jexec %d route add default %s", cj.Config.Exec_fib, cj.JID, cj.Config.Defaultrouter) | ||||
| 			out, err := executeCommand(cmd) | ||||
|  | ||||
							
								
								
									
										15
									
								
								cmd/stop.go
									
									
									
									
									
								
							
							
						
						
									
										15
									
								
								cmd/stop.go
									
									
									
									
									
								
							| @ -83,6 +83,7 @@ func umountAndUnjailZFS(jail *Jail) error { | ||||
| } | ||||
|  | ||||
| func destroyVNetInterfaces(jail *Jail) error { | ||||
| 	if !strings.EqualFold(jail.Config.Ip4_addr, "none") { | ||||
| 		for _, i := range strings.Split(jail.Config.Ip4_addr, ",") { | ||||
| 			iname := fmt.Sprintf("%s.%d", strings.Split(i, "|")[0], jail.JID) | ||||
| 			fmt.Printf("%s: ", iname) | ||||
| @ -94,6 +95,20 @@ func destroyVNetInterfaces(jail *Jail) error { | ||||
| 				fmt.Printf("OK\n") | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
| 	if !strings.EqualFold(jail.Config.Ip6_addr, "none") { | ||||
| 		for _, i := range strings.Split(jail.Config.Ip6_addr, ",") { | ||||
| 			iname := fmt.Sprintf("%s.%d", strings.Split(i, "|")[0], jail.JID) | ||||
| 			fmt.Printf("%s: ", iname) | ||||
| 			_, err := executeCommand(fmt.Sprintf("ifconfig %s destroy", iname)) | ||||
| 			//_, err := executeScript(fmt.Sprintf("ifconfig %s destroy >/dev/null 2>&1", iname)) | ||||
| 			if err != nil { | ||||
| 				return err | ||||
| 			} else { | ||||
| 				fmt.Printf("OK\n") | ||||
| 			} | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| @ -5,33 +5,37 @@ import ( | ||||
| 	"fmt" | ||||
| 	//"log" | ||||
| 	"time" | ||||
| 	"strings" | ||||
| 	"github.com/spf13/viper" | ||||
| ) | ||||
|  | ||||
|  | ||||
| // Internal usage only | ||||
| func updateJail(jail *Jail) error { | ||||
| func updateJail(jail *Jail, doUpdateVersion bool) error { | ||||
| 	// Create default config as temporary file | ||||
| 	cfgFile, err := os.CreateTemp("", "gocage-jail-update-") | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
|  | ||||
| 	cfgFile.Write([]byte(fbsdUpdateConfig)) | ||||
|  | ||||
| 	defer cfgFile.Close() | ||||
| 	defer os.Remove(cfgFile.Name()) | ||||
|  | ||||
| 	// Folder containing update/upgrade temporary files. Common so we save bandwith when upgrading multiple jails | ||||
| 	// TODO: Variabilize /iocage/freebsd-update | ||||
| 	_, err = os.Stat("/iocage/freebsd-update") | ||||
| 	// Folder containing update/upgrade temporary files. Mutualized so we save bandwith when upgrading multiple jails | ||||
| 	uwd := viper.GetString("updateWorkDir") | ||||
| 	if len(uwd) == 0 { | ||||
| 		return fmt.Errorf("updateWorkDir not set in configuration") | ||||
| 	} | ||||
| 	_, err = os.Stat(uwd) | ||||
| 	if os.IsNotExist(err) { | ||||
| 		if err := os.Mkdir("/iocage/freebsd-update", 0755); err != nil { | ||||
| 		if err := os.Mkdir(uwd, 0755); err != nil { | ||||
| 			return err | ||||
| 		} | ||||
| 	} | ||||
| 	cfgFile.Write([]byte(strings.Replace(fbsdUpdateConfig, "TO-BE-REPLACED-WITH-UPDATEWORKDIR", uwd, 1))) | ||||
| 	defer cfgFile.Close() | ||||
| 	defer os.Remove(cfgFile.Name()) | ||||
|  | ||||
| 	cmd := fmt.Sprintf("/usr/sbin/freebsd-update --not-running-from-cron -f %s -b %s --currently-running %s fetch", | ||||
| 					   cfgFile.Name(), jail.RootPath, jail.Config.Release) | ||||
|  | ||||
| 	err = executeCommandWithOutputToStdout(cmd) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| @ -44,8 +48,10 @@ func updateJail(jail *Jail) error { | ||||
| 		return err | ||||
| 	} | ||||
|  | ||||
| 	// Get and write new release into config.json | ||||
| 	// Get and write new release into config.json. Don't do that for fake jail (aka release updating) | ||||
| 	if doUpdateVersion { | ||||
| 		updateVersion(jail) | ||||
| 	} | ||||
|  | ||||
| 	return nil | ||||
| } | ||||
| @ -55,6 +61,28 @@ func UpdateJail(args []string) { | ||||
| 	var cj *Jail | ||||
| 	var err error | ||||
|  | ||||
| 	// User is updateing a release, fake a jail | ||||
| 	if  len(gUpdateRelease) > 0 { | ||||
| 		// get datastore mountpoing from datastore name | ||||
| 		ds, err := getDatastoreFromArray(gUpdateReleaseDS, gDatastores) | ||||
| 		if err != nil { | ||||
| 			fmt.Printf("Error gettting datastore %s: %v\n", gUpdateReleaseDS, err) | ||||
| 			return | ||||
| 		} | ||||
| 		rp := fmt.Sprintf("%s/releases/%s/root", ds.Mountpoint, gUpdateRelease) | ||||
| 		fakeJail := Jail{RootPath: rp} | ||||
| 		v, err := getVersion(&fakeJail) | ||||
| 		if err != nil { | ||||
| 			fmt.Printf("Error getting version of release %s: %v\n", gUpdateRelease, err) | ||||
| 			return | ||||
| 		} | ||||
| 		fakeJail.Config.Release = v | ||||
| 		if err = updateJail(&fakeJail, false); err != nil { | ||||
| 			fmt.Printf("Error updating release %s: %v\n", gUpdateRelease, err) | ||||
| 		} | ||||
| 		return | ||||
| 	} | ||||
|  | ||||
| 	for _, a := range args { | ||||
| 		// Check if jail exist and is distinctly named | ||||
| 		cj, err = getJailFromArray(a, []string{""}, gJails) | ||||
| @ -63,6 +91,12 @@ func UpdateJail(args []string) { | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		// We cant update basejail as system is readonly | ||||
| 		if strings.EqualFold(cj.Config.Jailtype, "basejail") { | ||||
| 			fmt.Printf("%s is a basejail using %s system files. Please update %s!\n", cj.Name, cj.Config.Origin, cj.Config.Origin) | ||||
| 			continue | ||||
| 		} | ||||
|  | ||||
| 		fmt.Printf("  > Snapshot jail %s\n", cj.Name) | ||||
| 		// Set snapshot name | ||||
| 		dt := time.Now() | ||||
| @ -76,7 +110,7 @@ func UpdateJail(args []string) { | ||||
| 		fmt.Printf("  > Snapshot jail %s: OK\n", cj.Name) | ||||
| 		 | ||||
| 		fmt.Printf("  > Update jail %s\n", cj.Name) | ||||
| 		err = updateJail(cj) | ||||
| 		err = updateJail(cj, true) | ||||
| 		if err != nil { | ||||
| 			fmt.Printf("ERROR: %s\n", err.Error()) | ||||
| 		} else { | ||||
|  | ||||
							
								
								
									
										173
									
								
								cmd/utils.go
									
									
									
									
									
								
							
							
						
						
									
										173
									
								
								cmd/utils.go
									
									
									
									
									
								
							| @ -25,7 +25,88 @@ const ( | ||||
| 	// Maximum thread qty for start/stop | ||||
| 	gMaxThreads    = 4 | ||||
|  | ||||
| 	gDefaultsJson = ` { | ||||
| 	fbsdUpdateConfig = `# $FreeBSD$ | ||||
|  | ||||
| # Trusted keyprint.  Changing this is a Bad Idea unless you've received | ||||
| # a PGP-signed email from <security-officer@FreeBSD.org> telling you to | ||||
| # change it and explaining why. | ||||
| KeyPrint 800651ef4b4c71c27e60786d7b487188970f4b4169cc055784e21eb71d410cc5 | ||||
|  | ||||
| # Server or server pool from which to fetch updates.  You can change | ||||
| # this to point at a specific server if you want, but in most cases | ||||
| # using a "nearby" server won't provide a measurable improvement in | ||||
| # performance. | ||||
| ServerName update.FreeBSD.org | ||||
|  | ||||
| # Components of the base system which should be kept updated. | ||||
| Components world | ||||
|  | ||||
| # Example for updating the userland and the kernel source code only: | ||||
| # Components src/base src/sys world | ||||
|  | ||||
| # Paths which start with anything matching an entry in an IgnorePaths | ||||
| # statement will be ignored. | ||||
| IgnorePaths | ||||
|  | ||||
| # Paths which start with anything matching an entry in an IDSIgnorePaths | ||||
| # statement will be ignored by "freebsd-update IDS". | ||||
| IDSIgnorePaths /usr/share/man/cat | ||||
| IDSIgnorePaths /usr/share/man/whatis | ||||
| IDSIgnorePaths /var/db/locate.database | ||||
| IDSIgnorePaths /var/log | ||||
|  | ||||
| # Paths which start with anything matching an entry in an UpdateIfUnmodified | ||||
| # statement will only be updated if the contents of the file have not been | ||||
| # modified by the user (unless changes are merged; see below). | ||||
| UpdateIfUnmodified /etc/ /var/ /root/ /.cshrc /.profile | ||||
|  | ||||
| # When upgrading to a new FreeBSD release, files which match MergeChanges | ||||
| # will have any local changes merged into the version from the new release. | ||||
| MergeChanges /etc/ | ||||
|  | ||||
| ### Default configuration options: | ||||
|  | ||||
| # Directory in which to store downloaded updates and temporary | ||||
| # files used by FreeBSD Update. | ||||
| WorkDir TO-BE-REPLACED-WITH-UPDATEWORKDIR | ||||
|  | ||||
| # Destination to send output of "freebsd-update cron" if an error | ||||
| # occurs or updates have been downloaded. | ||||
| # MailTo root | ||||
|  | ||||
| # Is FreeBSD Update allowed to create new files? | ||||
| # AllowAdd yes | ||||
|  | ||||
| # Is FreeBSD Update allowed to delete files? | ||||
| # AllowDelete yes | ||||
|  | ||||
| # If the user has modified file ownership, permissions, or flags, should | ||||
| # FreeBSD Update retain this modified metadata when installing a new version | ||||
| # of that file? | ||||
| # KeepModifiedMetadata yes | ||||
|  | ||||
| # When upgrading between releases, should the list of Components be | ||||
| # read strictly (StrictComponents yes) or merely as a list of components | ||||
| # which *might* be installed of which FreeBSD Update should figure out | ||||
| # which actually are installed and upgrade those (StrictComponents no)? | ||||
| StrictComponents yes | ||||
|  | ||||
| # When installing a new kernel perform a backup of the old one first | ||||
| # so it is possible to boot the old kernel in case of problems. | ||||
| BackupKernel no | ||||
|  | ||||
| # If BackupKernel is enabled, the backup kernel is saved to this | ||||
| # directory. | ||||
| # BackupKernelDir /boot/kernel.old | ||||
|  | ||||
| # When backing up a kernel also back up debug symbol files? | ||||
| BackupKernelSymbolFiles no | ||||
|  | ||||
| # Create a new boot environment when installing patches | ||||
| CreateBootEnv no | ||||
| ` | ||||
|  | ||||
| 	gDefaultsJson = `{ | ||||
|     "CONFIG_VERSION": "27", | ||||
|     "allow_chflags": 0, | ||||
|     "allow_mlock": 0, | ||||
| @ -79,9 +160,9 @@ const ( | ||||
|     "exec_timeout": "60", | ||||
|     "host_domainname": "none", | ||||
|     "host_time": 1, | ||||
|        "hostid": "36353536-3135-5a43-4a34-313130315a56", | ||||
|     "hostid": "TO-BE-REPLACED-WITH-HOSTID", | ||||
|     "hostid_strict_check": 0, | ||||
|        "interfaces": "vnet0:bridge0", | ||||
|     "interfaces": "vnet0:TO-BE-REPLACED-WITH-BRIDGE", | ||||
|     "ip4": "new", | ||||
|     "ip4_addr": "none", | ||||
|     "ip4_saddrsel": 1, | ||||
| @ -147,7 +228,7 @@ const ( | ||||
|     "type": "jail", | ||||
|     "used": "readonly", | ||||
|     "vmemoryuse": "off", | ||||
|        "vnet": 0, | ||||
|     "vnet": 1, | ||||
|     "vnet0_mac": "none", | ||||
|     "vnet1_mac": "none", | ||||
|     "vnet2_mac": "none", | ||||
| @ -157,7 +238,7 @@ const ( | ||||
|     "wallclock": "off", | ||||
|     "writebps": "off", | ||||
|     "writeiops": "off" | ||||
|        } | ||||
| } | ||||
| ` | ||||
| ) | ||||
|  | ||||
| @ -362,7 +443,7 @@ func executeCommand(cmdline string) (string, error) { | ||||
| 		out, err = exec.Command(cmd[0]).CombinedOutput() | ||||
| 	} | ||||
|  | ||||
| 	return string(out), err | ||||
| 	return strings.TrimSuffix(string(out), "\n"), err | ||||
| } | ||||
|  | ||||
| /* From iocage:  | ||||
| @ -670,6 +751,30 @@ func executeScript(script string) (string, error) { | ||||
| 	return string(out), err | ||||
| } | ||||
|  | ||||
| /***************************************************************************** | ||||
|  * | ||||
|  * Network related operations | ||||
|  * | ||||
|  *****************************************************************************/ | ||||
| func getBridgeMembers(bridge string) ([]string, error) { | ||||
| 	var members []string | ||||
| 	cmd := fmt.Sprintf("/sbin/ifconfig %s", bridge) | ||||
| 	out, err := executeCommand(cmd) | ||||
| 	if err != nil { | ||||
| 		return members, errors.New(fmt.Sprintf("%v; command returned \"%s\"", err, out)) | ||||
| 	} | ||||
|  | ||||
| 	for _, line := range strings.Split(out, "\n") { | ||||
| 		if strings.HasPrefix(strings.TrimLeft(line, " \t"), "member:") { | ||||
| 			m := strings.Split(strings.TrimLeft(strings.Split(line, ":")[1], " "), " ")[0] | ||||
| 			log.Debugf("%s is member of %s\n", m, bridge) | ||||
| 			members = append(members, m) | ||||
| 		} | ||||
| 	} | ||||
| 	return members, nil | ||||
| } | ||||
|  | ||||
|  | ||||
| /***************************************************************************** | ||||
| * | ||||
| * ZFS datasets/pools operations | ||||
| @ -814,7 +919,9 @@ func zfsCreateDataset(dataset, mountpoint, compression string) error { | ||||
| } | ||||
| // Return dataset name for a given mountpoint | ||||
| func zfsGetDatasetByMountpoint(mountpoint string) (string, error) { | ||||
| 	cmd := fmt.Sprintf("zfs list -p -r -H -o name %s", mountpoint) | ||||
| 	// We dont want no recursivity | ||||
| 	//cmd := fmt.Sprintf("zfs list -p -r -H -o name %s", mountpoint) | ||||
| 	cmd := fmt.Sprintf("zfs list -p -H -o name %s", mountpoint) | ||||
| 	out, err := executeCommand(cmd) | ||||
| 	if err != nil { | ||||
| 		return "", errors.New(fmt.Sprintf("%v; command returned \"%s\"", err, out)) | ||||
| @ -868,6 +975,17 @@ func getPermissions(path string) (os.FileInfo, error) { | ||||
| 	return os.Stat(path) | ||||
| } | ||||
|  | ||||
| func doFileExist(filePath string) (bool, error) { | ||||
| 	if _, err := os.Stat(filePath); err != nil { | ||||
| 		if errors.Is(err, os.ErrNotExist) { | ||||
| 			return false, nil | ||||
| 		} else { | ||||
| 			return false, err | ||||
| 		} | ||||
| 	} | ||||
| 	return true, nil | ||||
| } | ||||
|  | ||||
| /***************************************************************************** | ||||
|  * | ||||
|  * rc.conf management | ||||
| @ -902,6 +1020,44 @@ func disableRcKey(rcconfpath string, key string) error { | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| // returns no error if rc key does not exist | ||||
| func getCurrentRcKeyValue(rcconfpath string, key string) (string, error) { | ||||
| 	cmd := "/usr/sbin/sysrc -a" | ||||
| 	kvs, err := executeCommand(cmd) | ||||
| 	if err != nil { | ||||
| 		return "", err | ||||
| 	} | ||||
| 	for _, kv := range strings.Split(string(kvs), "\n") { | ||||
| 		fmt.Printf("%s\n", kv) | ||||
| 		if strings.HasPrefix(kv, fmt.Sprintf("%s:", key)) { | ||||
| 			return strings.TrimPrefix(strings.Join(strings.Split(kv, ":")[1:], ":"), " "), nil | ||||
| 		} | ||||
| 	} | ||||
|  | ||||
| 	return "", nil | ||||
| } | ||||
|  | ||||
| // Add a value to current existing key value | ||||
| func addRcKeyValue(rcconfpath string, key string, value string) error { | ||||
| 	var nv string | ||||
| 	cv, err := getCurrentRcKeyValue(rcconfpath, key) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
| 	if len(cv) > 0 { | ||||
| 		log.Debugf("Current value of %s: %s\n", key, cv) | ||||
| 		nv = fmt.Sprintf("\"%s %s\"", cv, value) | ||||
| 	} else { | ||||
| 		nv = fmt.Sprintf("\"%s\"", value) | ||||
| 	} | ||||
| 	cmd := fmt.Sprintf("/usr/sbin/sysrc -f %s %s=%s", rcconfpath, key, nv) | ||||
| 	_, err = executeCommand(cmd) | ||||
| 	if err != nil { | ||||
| 		return err | ||||
| 	} | ||||
| 	return nil | ||||
| } | ||||
|  | ||||
| /***************************************************************************** | ||||
| * Parse an fstab file, returning an array of Mount | ||||
| *****************************************************************************/ | ||||
| @ -917,7 +1073,8 @@ func getFstab(path string) ([]Mount, error) { | ||||
| 	scan := bufio.NewScanner(f) | ||||
| 	for scan.Scan() { | ||||
| 		res := strings.Fields(scan.Text()) | ||||
| 		if len(res) != 6 { | ||||
| 		// iocage create lines like that : "/iocage/releases/13.2-RELEASE/root/bin   /iocage/jails/smtp-router-02/root/bin   nullfs  ro      0       0 # Added by iocage on 2023-10-10 17:20:51" | ||||
| 		if (len(res) > 6 && !strings.EqualFold(res[6], "#")) || len(res) < 6 { | ||||
| 			return mounts, fmt.Errorf("Incorrect format for fstab line %s", scan.Text()) | ||||
| 		} | ||||
| 		freq, err := strconv.Atoi(res[4]) | ||||
|  | ||||
							
								
								
									
										58
									
								
								go.mod
									
									
									
									
									
								
							
							
						
						
									
										58
									
								
								go.mod
									
									
									
									
									
								
							| @ -8,25 +8,51 @@ require ( | ||||
| 	github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 | ||||
| 	github.com/otiai10/copy v1.12.0 | ||||
| 	github.com/sirupsen/logrus v1.8.1 | ||||
| 	github.com/spf13/cobra v1.2.1 | ||||
| 	github.com/spf13/viper v1.9.0 | ||||
| 	golang.org/x/net v0.0.0-20210503060351-7fd8e65b6420 | ||||
| 	github.com/spf13/cobra v1.8.1 | ||||
| 	github.com/spf13/viper v1.19.0 | ||||
| 	golang.org/x/net v0.25.0 | ||||
| ) | ||||
|  | ||||
| require ( | ||||
| 	github.com/fsnotify/fsnotify v1.5.1 // indirect | ||||
| 	github.com/bytedance/sonic v1.11.6 // indirect | ||||
| 	github.com/bytedance/sonic/loader v0.1.1 // indirect | ||||
| 	github.com/cloudwego/base64x v0.1.4 // indirect | ||||
| 	github.com/cloudwego/iasm v0.2.0 // indirect | ||||
| 	github.com/fsnotify/fsnotify v1.7.0 // indirect | ||||
| 	github.com/gabriel-vasile/mimetype v1.4.3 // indirect | ||||
| 	github.com/gin-contrib/sse v0.1.0 // indirect | ||||
| 	github.com/go-playground/locales v0.14.1 // indirect | ||||
| 	github.com/go-playground/universal-translator v0.18.1 // indirect | ||||
| 	github.com/go-playground/validator/v10 v10.20.0 // indirect | ||||
| 	github.com/goccy/go-json v0.10.2 // indirect | ||||
| 	github.com/hashicorp/hcl v1.0.0 // indirect | ||||
| 	github.com/inconshreveable/mousetrap v1.0.0 // indirect | ||||
| 	github.com/magiconair/properties v1.8.5 // indirect | ||||
| 	github.com/mitchellh/mapstructure v1.4.2 // indirect | ||||
| 	github.com/pelletier/go-toml v1.9.4 // indirect | ||||
| 	github.com/spf13/afero v1.6.0 // indirect | ||||
| 	github.com/spf13/cast v1.4.1 // indirect | ||||
| 	github.com/spf13/jwalterweatherman v1.1.0 // indirect | ||||
| 	github.com/inconshreveable/mousetrap v1.1.0 // indirect | ||||
| 	github.com/json-iterator/go v1.1.12 // indirect | ||||
| 	github.com/klauspost/cpuid/v2 v2.2.7 // indirect | ||||
| 	github.com/leodido/go-urn v1.4.0 // indirect | ||||
| 	github.com/magiconair/properties v1.8.7 // indirect | ||||
| 	github.com/mattn/go-isatty v0.0.20 // indirect | ||||
| 	github.com/mitchellh/mapstructure v1.5.0 // indirect | ||||
| 	github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect | ||||
| 	github.com/modern-go/reflect2 v1.0.2 // indirect | ||||
| 	github.com/pelletier/go-toml/v2 v2.2.2 // indirect | ||||
| 	github.com/sagikazarmark/locafero v0.4.0 // indirect | ||||
| 	github.com/sagikazarmark/slog-shim v0.1.0 // indirect | ||||
| 	github.com/sourcegraph/conc v0.3.0 // indirect | ||||
| 	github.com/spf13/afero v1.11.0 // indirect | ||||
| 	github.com/spf13/cast v1.6.0 // indirect | ||||
| 	github.com/spf13/pflag v1.0.5 // indirect | ||||
| 	github.com/subosito/gotenv v1.2.0 // indirect | ||||
| 	golang.org/x/sys v0.0.0-20220715151400-c0bba94af5f8 // indirect | ||||
| 	golang.org/x/text v0.3.6 // indirect | ||||
| 	gopkg.in/ini.v1 v1.63.2 // indirect | ||||
| 	gopkg.in/yaml.v2 v2.4.0 // indirect | ||||
| 	github.com/subosito/gotenv v1.6.0 // indirect | ||||
| 	github.com/twitchyliquid64/golang-asm v0.15.1 // indirect | ||||
| 	github.com/ugorji/go/codec v1.2.12 // indirect | ||||
| 	go.uber.org/atomic v1.9.0 // indirect | ||||
| 	go.uber.org/multierr v1.9.0 // indirect | ||||
| 	golang.org/x/arch v0.8.0 // indirect | ||||
| 	golang.org/x/crypto v0.23.0 // indirect | ||||
| 	golang.org/x/exp v0.0.0-20230905200255-921286631fa9 // indirect | ||||
| 	golang.org/x/sys v0.20.0 // indirect | ||||
| 	golang.org/x/text v0.15.0 // indirect | ||||
| 	google.golang.org/protobuf v1.34.1 // indirect | ||||
| 	gopkg.in/ini.v1 v1.67.0 // indirect | ||||
| 	gopkg.in/yaml.v3 v3.0.1 // indirect | ||||
| ) | ||||
|  | ||||
| @ -5,6 +5,9 @@ datastore: | ||||
| # Prefix all commands with sudo | ||||
| sudo: false | ||||
|  | ||||
| # Directory used to store update temporary files. Mutualized so we save bandwith | ||||
| updateWorkDir: /iocage/freebsd-updates | ||||
|  | ||||
| # Columns to display when "gocage list". Column names are struct fields, see cmd/struct.go | ||||
| outcol: 'JID,Name,Config.Release,Config.Ip4_addr,Running' | ||||
|  | ||||
|  | ||||
		Reference in New Issue
	
	Block a user