Updated wwinit for clarity #1156

Also:

- Renamed /warewulf/wwinit to /warewulf/prescripts

Signed-off-by: Jonathon Anderson <janderson@ciq.com>
This commit is contained in:
Jonathon Anderson
2025-02-12 11:45:55 -07:00
parent fb9f269fc5
commit 4fa8601b75
12 changed files with 159 additions and 68 deletions

View File

@@ -1,14 +1,13 @@
#!/bin/sh
#
# This is one of those types of files that you shouldn't edit unless you really
# know what you are doing and even then you should make a backup.
#
# Edit at your own risk! DANGER DANGER.
echo "Warewulf pre-init (/init)"
echo
echo "Mounting kernel file systems..."
mountpoint -q /proc || (mkdir -p /proc && mount -t proc proc /proc && echo "Mounted /proc")
mountpoint -q /dev || (mkdir -p /dev && mount -t devtmpfs devtmpfs /dev && echo "Mounted /dev")
mountpoint -q /sys || (mkdir -p /sys && mount -t sysfs sysfs /sys && echo "Mounted /sys")
echo
echo "Loading /warewulf/config..."
if [ -f "/warewulf/config" ]; then
. /warewulf/config
else
@@ -17,24 +16,24 @@ else
sleep 60
echo b > /proc/sysrq-trigger || /sbin/reboot -f
fi
echo
echo "Warewulf v4 is now booting: ${WWHOSTNAME}"
echo
echo "Configuring root file system..."
chmod 755 /warewulf/wwinit
WWPRESCRIPTS=/warewulf/wwprescripts
chmod +rx "${WWPRESCRIPTS}"
if [ -z "${WWROOT}" -o "${WWROOT}" = "initramfs" ]; then
echo "Retaining initramfs and invoking /warewulf/wwinit..."
exec /warewulf/wwinit
WWROOT="${WWROOT:-initramfs}"
if [ "${WWROOT}" = "initramfs" ]; then
echo "WWROOT=${WWROOT}: using initial rootfs and invoking ${WWPRESCRIPTS}..."
exec "${WWPRESCRIPTS}"
elif [ "${WWROOT}" = "ramfs" -o "${WWROOT}" = "tmpfs" ]; then
echo "Setting up new ${WWROOT} rootfs..."
echo "WWROOT=${WWROOT}: setting up new ${WWROOT} rootfs (/newroot)..."
mkdir /newroot
mount wwroot /newroot -t ${WWROOT} -o mpol=interleave # mpol ignored for ramfs
tar -cf - --exclude ./proc --exclude ./sys --exclude ./dev --exclude --exclude ./newroot . | tar -xf - -C /newroot
mkdir /newroot/proc /newroot/dev /newroot/sys 2>/dev/null
echo "Switching to new rootfs and invoking /warewulf/wwinit..."
exec /sbin/switch_root /newroot /warewulf/wwinit
echo "Switching to new rootfs (/newroot) and invoking ${WWPRESCRIPTS}..."
exec /sbin/switch_root /newroot "${WWPRESCRIPTS}"
else
echo "ERROR: Unrecognized rootfs type requested: ${WWROOT}"
echo "Rebooting in 1 minute..."
@@ -43,7 +42,7 @@ else
fi
echo
echo "ERROR: There was a problem with the initial provisioning process."
echo "ERROR: wwinit encountered a problem."
echo "Rebooting in 1 minute..."
sleep 60
echo b > /proc/sysrq-trigger || /sbin/reboot -f

View File

@@ -1,6 +1,6 @@
#!/bin/sh
. /warewulf/config
echo "Bringing up lo:127.0.0.1"
echo "Warewulf prescript: localhost"
echo
echo "Bringing up lo..."
/sbin/ip link set dev lo up

View File

@@ -4,17 +4,22 @@
export PATH=/usr/bin:/bin:/usr/sbin:/sbin
echo "Warewulf prescript: IPMI"
echo
if [ "$WWIPMI_WRITE" != "true" ]; then
echo "IPMI write not configured: skipping"
exit
fi
echo "Loading IPMI kernel modules..."
modprobe ipmi_si ipmi_ssif ipmi_devintf ipmi_msghandler || (
echo "unable to load IPMI kernel modules: skipping IPMI configuration"
echo "Unable to load IPMI kernel modules: skipping IPMI configuration"
exit
)
if [ ! -e /dev/ipmi0 ]; then
echo "/dev/ipmi0 does not exist; creating..."
sleep 1
ipmi_dev=$(grep ipmidev /proc/devices | awk '{ print $1 }')
mknod -m 0666 /dev/ipmi0 c "$ipmi_dev" 0
@@ -83,7 +88,7 @@ if [ -n "$WWIPMI_PASSWORD" ]; then
fi
fi
# Serial Over LAN
echo "Configuring Serial over LAN..."
ipmitool channel setaccess 1 2 link=on ipmi=on callin=on privilege=4
ipmitool sol set force-encryption true 1
ipmitool sol set force-authentication true 1

View File

@@ -2,23 +2,19 @@
. /warewulf/config
# This will eventually be optional
if true; then
if [ -f "/etc/pam.d/system-auth" ]; then
echo "FIXING: system-auth"
sed -i -e '/^account.*pam_unix\.so\s*$/s/\s*$/\ broken_shadow/' /etc/pam.d/system-auth
echo "Warewulf prescript: VNFS fixes"
echo
add_broken_shadow() {
if [ -f "${1}" ]; then
echo "Adding broken_shadow to ${1}..."
sed -i -e '/^account.*pam_unix\.so\s*$/s/\s*$/\ broken_shadow/' "${1}"
fi
}
if [ -f "/etc/pam.d/password-auth" ]; then
echo "FIXING: password-auth"
sed -i -e '/^account.*pam_unix\.so\s*$/s/\s*$/\ broken_shadow/' /etc/pam.d/password-auth
fi
if [ -f "/etc/pam.d/common-account" ]; then
echo "FIXING: common-account"
sed -i -e '/^account.*pam_unix\.so\s*$/s/\s*$/\ broken_shadow/' /etc/pam.d/common-account
fi
fi
add_broken_shadow /etc/pam.d/system-auth
add_broken_shadow /etc/pam.d/password-auth
add_broken_shadow /etc/pam.d/common-account
echo "Adjusting root directory permissions..."
chmod 755 /

View File

@@ -2,32 +2,42 @@
. /warewulf/config
echo "Warewulf prescript: SELinux"
if test -f "/etc/sysconfig/selinux"; then
. /etc/sysconfig/selinux
else
echo "Skipping SELinux configuration: Host config not found: /etc/sysconfig/selinux"
echo "File not found: /etc/sysconfig/selinux"
echo "Skipping SELinux configuration."
exit
fi
if test "$SELINUX" == "disabled"; then
echo "Skipping SELinux setup per /etc/sysconfig/selinux"
if [ "$SELINUX" = "disabled" ]; then
echo "/etc/sysconfig/selinux:SELINUX=${SELINUX}: skipping SELinux configuration."
exit
fi
if grep -q "selinux=0" /proc/cmdline; then
echo "Skipping SELinux setup per kernel command line"
echo "/proc/cmdline:selinux=0: skipping SELinux configuration."
exit
fi
if [ $(findmnt / --noheadings --output SOURCE) == 'rootfs' ]; then
echo "Skipping SELinux configuration: rootfs does not support SELinux contexts"
if [ $(findmnt / --noheadings --output SOURCE) = 'rootfs' ]; then
echo "/ is a 'rootfs' file system, which does not support SELinux contexts."
echo "Skipping SELinux configuration."
echo
echo "WARNING: SELinux prep is being skipped, but SELinux is enabled on host! This may"
echo "WARNING: cause the system to not work properly. Try setting 'Root=tmpfs'"
sleep 5
echo "WARNING: SELinux configuration is being skipped, but SELinux is"
echo "WARNING: enabled in the image! The node will probably not boot"
echo "WARNING: properly."
echo "WARNING:"
echo "WARNING: Try setting 'Root=tmpfs'"
echo
echo "Continuing in 60s..."
sleep 60
exit
fi
echo "Setting up SELinux"
echo "Loading SELinux policy..."
/sbin/load_policy -i
echo "Restoring filesystem labels..."
/sbin/restorecon -e /sys -r /

View File

@@ -1,17 +0,0 @@
#!/bin/sh
echo "Hello from WWINIT"
. /warewulf/config
myPATH=/warewulf/init.d
ls -1 $myPATH/ | while read -r NAME; do
echo "Launching: $NAME"
sh "$myPATH/$NAME"
done
echo "Calling $WWINIT..."
echo
sleep 2
exec $WWINIT

View File

@@ -0,0 +1,14 @@
#!/usr/bin/sh
. /warewulf/config
echo "Warewulf prescript runner (/warewulf/wwprescripts)"
scriptdir=/warewulf/init.d
echo "Looking for prescripts in /warewulf/init.d/..."
ls -1 "${scriptdir}/" | while read -r name; do
echo "Running prescript: ${name}..."
sh "${scriptdir}/${name}"
done
echo
echo "Running ${WWINIT}..."
exec $WWINIT