X-Git-Url: https://iankelling.org/git/?p=automated-distro-installer;a=blobdiff_plain;f=pxe-server;h=6137386a1188d9ab9c50e4bee783e7ee57dfc053;hp=1f75adb61ebb3a443ae7a2e4e7029adc3a728991;hb=HEAD;hpb=23bf2f3666becf9d3c219af1eaea08b4cf843492 diff --git a/pxe-server b/pxe-server index 1f75adb..1e99b03 100755 --- a/pxe-server +++ b/pxe-server @@ -15,144 +15,272 @@ # along with this program; if not, write to the Free Software # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA. -# Setup dhcp server to point to tftp server, -# and depending on the type, setup the tftp server. -# usage: $0 TYPE -# default distro is the base debian/fedora type. others are fai & arch. -# for no pxe server, use a no-op like : or true. +[[ $EUID == 0 ]] || exec sudo -E "${BASH_SOURCE[0]}" "$@" -set -eE -o pipefail -trap 'echo "$0:$LINENO:error: \"$BASH_COMMAND\" returned $?" >&2' ERR +readonly this_file="$(readlink -f -- "${BASH_SOURCE[0]}")" +script_dir="${this_file%/*}" +# shellcheck source=./bash-trace +source "${script_dir}/bash-trace" +cd $script_dir +PATH="$PATH:$PWD" usage() { - cat < tftpboot + + +Notes on debugging pxe dhcp tftp: + +For debugging dhcp, add to /etc/dnsmasq.conf: log-dhcp + +Newer openwrt runs dnsmasq with a whitelist of readable files and dirs: + +ps ww : +/sbin/ujail -t 5 -n dnsmasq -u -l -r /bin/ubus -r /etc/TZ -r /etc/dnsmasq.conf -r /etc/ethers -r /etc/group -r /etc/hosts -r /etc/passwd -w /tmp/dhcp.leases -r /tmp/dnsmasq.d -r /tmp/hosts -r /tmp/resolv.conf.d -r /usr/bin/jshn -r /usr/lib/dnsmasq/dhcp-script.sh -r /usr/share/dnsmasq/dhcpbogushostname.conf -r /usr/share/dnsmasq/rfc6761.conf -r /usr/share/dnsmasq/trust-anchors.conf -r /usr/share/libubox/jshn.sh -r /var/etc/dnsmasq.conf.cfg01411c -w /var/run/dnsmasq/ -- /usr/sbin/dnsmasq -C /var/etc/dnsmasq.conf.cfg01411c -k -x /var/run/dnsmasq/dnsmasq.cfg01411c.pid + +logging tftp requests: +/etc/default/tftpd-hpa: +add -vv: +TFTP_OPTIONS="--secure -vv" +jr -u tftpd-hpa -f + +Note: Uses GNU getopt options parsing style EOF - exit $1 + exit $1 } +pre="${0##*/}:" +m() { printf "$pre %s\n" "$*"; "$@"; } +e() { printf "$pre %s\n" "$*"; } +err() { echo "[$(date +'%Y-%m-%d %H:%M:%S%z')]: $pre: $*" >&2; } + +PATH="/a/exe:$PATH" + ##### begin command line parsing ######## -persist=false -args=() +dhcp=true redep=true -acks=3 -while [[ $1 ]]; do - case $1 in - --) shift; break ;; - -h|--help) usage ;; - -r) redep=false; shift ;; - -p) persist=true; shift ;; - -a) acks=2; shift ;; - *) args+=("$1"); shift ;; - esac -done -args+=("$@") +acks=2 +wait=false +fsf_office=false + +case $HOSTNAME in + x3|kw) fsf_office=true ;; +esac +chboot_args=() +temp=$(getopt -l no-r,help adkrSwh "$@") || usage 1 +eval set -- "$temp" +while true; do + case $1 in + -a) wait=true; set=false; shift ;; + -d) dhcp=false; shift ;; + -k) chboot_args+=(-k); shift ;; + --no-r) chboot_args+=(--no-r); shift ;; + -r) redep=false; shift ;; + -S) chboot_args+=(-S); shift ;; + -w) wait=true; set=true; shift ;; + -h|--help) usage ;; + --) shift; break ;; + *) echo "$0: Internal error!" ; exit 1 ;; + esac +done -read type host <<<"${args[@]}" +read -r host type <<<"$@" -if [[ ! $type ]]; then - echo "$0: error: exptected 1 argument of type" +case $# in + [01]);; + 2) + case $type in + arch|parabola) cmd=archlike ;; + fai) cmd=fai ;; + *) + echo "$0: error expected type of arch|parabola|fai" + echo + usage 1 + ;; + esac + ;; + *) + echo "$0: error: expected 0-2 arguments" + echo usage 1 -fi + ;; +esac -if [[ $host ]]; then - host_tag="tag:$host," + +if $wait && ! $dhcp; then + echo "$0: error -w conflicts with -d, choose one or other" >&2 + exit 1 fi -case $type in - :|true) persist=true ;; - arch) acks=2 ;; -esac +if $fsf_office && [[ ! $host ]]; then + echo "$0: at fsf_office, provide HOST arg" >&2 + exit 1 + fi -##### end command line parsing ######## +if [[ $host && $host != default ]]; then + host_tag="tag:$host," +fi -sv() { - echo "$@" - "$@" -} +##### end command line parsing ######## -arch() { - cat </dev/null || sudo apt-get -y install dnsutils +faiserverip=$(host faiserver | sed -rn 's/^\S+ has address //p;T;q' ||:) +if [[ ! $faiserverip || $faiserverip =~ [[:space:]] ]]; then + echo "$0: error: failed to get \$faiserverip, got: $faiserverip" + exit 1 +fi -if [[ $type == fai ]]; then + +if $set; then + set-pxe + if [[ $type == fai ]]; then if $redep; then - fai-redep + m fai-redep fi - faiserver-enable + m myfai-chboot ${chboot_args[@]} $host + else + # This will fail if faiserver is not setup, so ignore any + # failure and don't bother us about it. + m myfai-chboot &>/dev/null ||: + fi fi -if ! $persist; then - # fai's debian jessie 8.5ish does 2 dhcp requests when booting, - # roughly 4 seconds apart. Earlier - # versions did just 1. Now testing on a vm, it does 1. - # bleh. - echo "waiting for $acks dhcp acks then disabling pxe" - ack-wait $acks - set-pxe : - if [[ $type == fai ]]; then - # fai server can contain sensitive info, so turn it off - # when it's not in use. - echo "waiting for 1 dhcp ack then disabling fai server" - ack-wait 1 - faiserver-disable - fi +if $wait; then + # fai's debian jessie 8.5ish does 2 dhcp requests when booting, + # roughly 4 seconds apart. Earlier + # versions did just 1. Now testing on a vm, it does 1. + # bleh. + echo "waiting for $acks dhcp acks then disabling pxe" + ack-wait $acks + type= + unset cmd + set-pxe + + # previously tried waiting for one more ack then disabling faiserver, + # since it can contain sensitive info, so turn it off when not in use, + # but disabling that for now as it's inconvenient to clean this + # up and run it in the background etc. + + # if [[ $type == fai ]]; then + # echo "waiting for 1 dhcp ack then disabling fai server" + # ack-wait 1 + # faiserver-disable + # fi fi