-
Notifications
You must be signed in to change notification settings - Fork 6
/
make-template.ml
executable file
·1690 lines (1479 loc) · 55.3 KB
/
make-template.ml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
#!/usr/bin/env ocaml
(* libguestfs
* Copyright (C) 2016-2023 Red Hat Inc.
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 2 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program; if not, write to the Free Software
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
*)
(* This script is used to create the virt-builder templates hosted
* http://libguestfs.org/download/builder/
*
* Prior to November 2016, the templates were generated using
* shell scripts located in libguestfs.git/builder/website.
*)
#load "str.cma";;
#load "unix.cma";;
#directory "+guestfs";; (* use globally installed guestfs *)
#load "mlguestfs.cma";;
open Printf
let windows_installers = "/mnt/media/installers/Windows"
let prog = "make-template"
(* Ensure that a file is deleted on exit. *)
let unlink_on_exit =
let files = ref [] in
at_exit (
fun () -> List.iter (fun f -> try Unix.unlink f with _ -> ()) !files
);
fun file -> files := file :: !files
let () =
(* Check we are being run from the correct directory. *)
if not (Sys.file_exists "debian.preseed") then (
eprintf "%s: run this script from the builder/templates subdirectory\n"
prog;
exit 1
);
(* Check that the ./run script was used. *)
(try ignore (Sys.getenv "VIRT_BUILDER_DIRS")
with Not_found ->
eprintf "%s: you must use `../../run ./make-template.ml ...' \
to run this script\n"
prog;
exit 1
);
(* Check we're not being run as root. *)
if Unix.geteuid () = 0 then (
eprintf "%s: don't run this script as root\n" prog;
exit 1
);
(* ... and that LIBVIRT_DEFAULT_URI=qemu:///system is NOT set,
* which is the same as above.
*)
let s = try Sys.getenv "LIBVIRT_DEFAULT_URI" with Not_found -> "" in
if s = "qemu:///system" then (
eprintf "%s: don't set LIBVIRT_DEFAULT_URI=qemu:///system\n" prog;
exit 1
)
;;
type os =
| Alma of int * int (* major, minor *)
| CentOS of int * int (* major, minor *)
| CentOSStream of int (* major *)
| RHEL of int * int
| Debian of int * string (* version, dist name like "wheezy" *)
| Ubuntu of string * string
| Fedora of int (* version number *)
| FreeBSD of int * int (* major, minor *)
| Windows of int * int * windows_variant (* major, minor, variant *)
and windows_variant = Client | Server
type arch = X86_64 | Aarch64 | Armv7 | I686 | PPC64 | PPC64le | S390X
type boot_media =
| Location of string (* virt-install --location (preferred) *)
| CDRom of string (* downloaded CD-ROM *)
let quote = Filename.quote
let (//) = Filename.concat
let rec main () =
assert (Sys.word_size = 64);
Random.self_init ();
(* Parse the command line. *)
let os, arch = parse_cmdline () in
(* Choose a disk size for this OS. *)
let virtual_size_gb = get_virtual_size_gb os arch in
(* For OSes which require a kickstart, this generates one.
* For OSes which require a preseed file, this returns one (we
* don't generate preseed files at the moment).
* For Windows this returns an unattend file in an ISO.
* For OSes which cannot be automated (FreeBSD), this returns None.
*)
let ks = make_kickstart os arch in
(* Find the boot media. Normally ‘virt-install --location’ but
* for FreeBSD it downloads the boot ISO.
*)
let boot_media = make_boot_media os arch in
(* Choose a random temporary name for the libvirt domain. *)
let tmpname = sprintf "tmp-%s" (random8 ()) in
(* Choose a random temporary disk name. *)
let tmpout = sprintf "%s.img" tmpname in
unlink_on_exit tmpout;
(* Create the final output name (actually not quite final because
* we will xz-compress it).
*)
let output = filename_of_os os arch "" in
(* Some architectures need EFI boot. *)
let tmpefivars =
if needs_uefi os arch then (
let code, vars =
match arch with
| X86_64 ->
"/usr/share/edk2/ovmf/OVMF_CODE.fd",
"/usr/share/edk2/ovmf/OVMF_VARS.fd"
| Aarch64 ->
"/usr/share/edk2/aarch64/QEMU_EFI-pflash.raw",
"/usr/share/edk2/aarch64/vars-template-pflash.raw"
| Armv7 ->
"/usr/share/edk2/arm/QEMU_EFI-pflash.raw",
"/usr/share/edk2/arm/vars-template-pflash.raw"
| _ -> assert false in
let vars_out = Sys.getcwd () // sprintf "%s.vars" tmpname in
unlink_on_exit vars_out;
let cmd = sprintf "cp %s %s" (quote vars) (quote vars_out) in
if Sys.command cmd <> 0 then exit 1;
Some (code, vars_out)
)
else None in
(* Now construct the virt-install command. *)
let vi = make_virt_install_command os arch ks tmpname tmpout tmpefivars
boot_media virtual_size_gb in
(* Print the virt-install command just before we run it, because
* this is expected to be long-running.
*)
print_virt_install_command stdout vi;
(* Save the virt-install command to a file, for documentation. *)
let chan = open_out (filename_of_os os arch ".virt-install-cmd") in
fprintf chan "# This is the virt-install command which was used to create\n";
fprintf chan "# the virt-builder template '%s'\n" (string_of_os os arch);
fprintf chan "# NB: This file is generated for documentation \
purposes ONLY!\n";
fprintf chan "# This script was never run, and is not intended to be run.\n";
fprintf chan "\n";
print_virt_install_command chan vi;
close_out chan;
(* Print the virt-install notes for OSes which cannot be automated
* fully. (These are different from the ‘notes=’ section in the
* index fragment).
*)
print_install_notes os;
printf "\n\n%!";
(* Run the virt-install command. *)
let pid = Unix.fork () in
if pid = 0 then Unix.execvp "virt-install" vi;
let _, pstat = Unix.waitpid [] pid in
check_process_status_for_errors pstat;
(* If there were NVRAM variables, move them to the final name and
* compress them. Doing this operation later means the cleanup of
* the guest will remove them as well (because of --nvram).
*)
let nvram =
match tmpefivars with
| Some (_, vars) ->
let f = sprintf "%s-nvram" output in
let cmd = sprintf "mv %s %s" (quote vars) (quote f) in
if Sys.command cmd <> 0 then exit 1;
let cmd = sprintf "xz -f --best %s" (quote f) in
if Sys.command cmd <> 0 then exit 1;
Some (f ^ ".xz")
| None -> None in
ignore (Sys.command "sync");
(* Run virt-filesystems, simply to display the filesystems in the image. *)
let cmd = sprintf "virt-filesystems -a %s --all --long -h" (quote tmpout) in
if Sys.command cmd <> 0 then exit 1;
(* Some guests are special flowers that need post-installation
* filesystem changes.
*)
let postinstall = make_postinstall os arch in
(* Get the root filesystem. If the root filesystem is LVM then
* get the partition containing it.
*)
let g = open_guest ~mount:(postinstall <> None) tmpout in
let roots = g#inspect_get_roots () in
let expandfs, lvexpandfs =
let rootfs = g#canonical_device_name roots.(0) in
if String.length rootfs >= 7 && String.sub rootfs 0 7 = "/dev/sd" then
rootfs, None (* non-LVM case *)
else (
(* The LVM case, find the containing partition to expand. *)
let pvs = Array.to_list (g#pvs ()) in
match pvs with
| [pv] ->
let pv = g#canonical_device_name pv in
assert (String.length pv >= 7 && String.sub pv 0 7 = "/dev/sd");
pv, Some rootfs
| [] | _::_::_ -> assert false
) in
(match postinstall with
| None -> ()
| Some f -> f g
);
g#shutdown ();
g#close ();
(match os with
| Ubuntu (ver, _) when ver >= "14.04" ->
(* In Ubuntu >= 14.04 you can't complete the install without creating
* a user account. We create one called 'builder', but we also
* disable it. XXX Combine with virt-sysprep step.
*)
let cmd =
sprintf "virt-customize -a %s --password builder:disabled"
(quote tmpout) in
if Sys.command cmd <> 0 then exit 1
| _ -> ()
);
if can_sysprep_os os then (
(* Sysprep. Relabel SELinux-using guests. *)
printf "Sysprepping ...\n%!";
let cmd = sprintf "virt-sysprep --quiet -a %s" (quote tmpout) in
if Sys.command cmd <> 0 then exit 1
);
(* Sparsify and copy to output name. *)
printf "Sparsifying ...\n%!";
let cmd =
sprintf "virt-sparsify --inplace --quiet %s" (quote tmpout) in
if Sys.command cmd <> 0 then exit 1;
(* Move file to final name before compressing. *)
let cmd =
sprintf "mv %s %s" (quote tmpout) (quote output) in
if Sys.command cmd <> 0 then exit 1;
(* Compress the output. *)
printf "Compressing ...\n%!";
let cmd =
sprintf "xz -f --best --block-size=16777216 %s" (quote output) in
if Sys.command cmd <> 0 then exit 1;
let output = output ^ ".xz" in
(* Set public readable permissions on the final file. *)
let cmd = sprintf "chmod 0644 %s" (quote output) in
if Sys.command cmd <> 0 then exit 1;
printf "Template completed: %s\n%!" output;
(* Construct the index fragment, but don't create this for the private
* RHEL images.
*)
(match os with
| RHEL _ -> ()
| _ ->
let index_fragment = filename_of_os os arch ".index-fragment" in
(* If there is an existing file, read the revision and increment it. *)
let revision = read_revision index_fragment in
let revision =
match revision with
(* no existing file *)
| `No_file -> None
(* file exists, but no revision line, so revision=1 *)
| `No_revision -> Some 2
(* existing file with revision line *)
| `Revision i -> Some (i+1) in
make_index_fragment os arch index_fragment output nvram revision
expandfs lvexpandfs virtual_size_gb;
(* Validate the fragment we have just created. *)
let cmd = sprintf "virt-index-validate %s" (quote index_fragment) in
if Sys.command cmd <> 0 then exit 1;
printf "Index fragment created: %s\n" index_fragment
);
printf "Finished successfully.\n%!"
and parse_cmdline () =
let anon = ref [] in
let usage = "\
../../run ./make-template.ml [--options] os version [arch]
Usage:
../../run ./make-template.ml [--options] os version [arch]
Examples:
../../run ./make-template.ml fedora 25
../../run ./make-template.ml rhel 7.3 ppc64le
The arch defaults to x86_64. Note that i686 is treated as a
separate arch.
Options:
" in
let spec = Arg.align [
] in
Arg.parse spec (fun s -> anon := s :: !anon) usage;
let os, ver, arch =
match List.rev !anon with
| [os; ver] -> os, ver, "x86_64"
| [os; ver; arch] -> os, ver, arch
| _ ->
eprintf "%s [--options] os version [arch]\n" prog;
exit 1 in
let os = os_of_string os ver
and arch = arch_of_string arch in
os, arch
and os_of_string os ver =
match os, ver with
| "alma", ver -> let maj, min = parse_major_minor ver in Alma (maj, min)
| "centos", ver -> let maj, min = parse_major_minor ver in CentOS (maj, min)
| "centosstream", ver -> CentOSStream(int_of_string ver)
| "rhel", ver -> let maj, min = parse_major_minor ver in RHEL (maj, min)
| "debian", "6" -> Debian (6, "squeeze")
| "debian", "7" -> Debian (7, "wheezy")
| "debian", "8" -> Debian (8, "jessie")
| "debian", "9" -> Debian (9, "stretch")
| "debian", "10" -> Debian (10, "buster")
| "debian", "11" -> Debian (11, "bullseye")
| "debian", "12" -> Debian (12, "bookworm")
| "ubuntu", "10.04" -> Ubuntu (ver, "lucid")
| "ubuntu", "12.04" -> Ubuntu (ver, "precise")
| "ubuntu", "14.04" -> Ubuntu (ver, "trusty")
| "ubuntu", "16.04" -> Ubuntu (ver, "xenial")
| "ubuntu", "18.04" -> Ubuntu (ver, "bionic")
| "ubuntu", "20.04" -> Ubuntu (ver, "focal")
| "ubuntu", "22.04" -> Ubuntu (ver, "jammy")
| "fedora", ver -> Fedora (int_of_string ver)
| "freebsd", ver -> let maj, min = parse_major_minor ver in FreeBSD (maj, min)
| "windows", ver -> parse_windows_version ver
| _ ->
eprintf "%s: unknown or unsupported OS (%s, %s)\n" prog os ver; exit 1
and parse_major_minor ver =
let rex = Str.regexp "^\\([0-9]+\\)\\.\\([0-9]+\\)$" in
if Str.string_match rex ver 0 then (
int_of_string (Str.matched_group 1 ver),
int_of_string (Str.matched_group 2 ver)
)
else (
eprintf "%s: cannot parse major.minor (%s)\n" prog ver;
exit 1
)
(* https://en.wikipedia.org/wiki/List_of_Microsoft_Windows_versions *)
and parse_windows_version = function
| "7" -> Windows (6, 1, Client)
| "2k8r2" -> Windows (6, 1, Server)
| "2k12" -> Windows (6, 2, Server)
| "2k12r2" -> Windows (6, 3, Server)
| "2k16" -> Windows (10, 0, Server)
| _ ->
eprintf "%s: cannot parse Windows version, see ‘parse_windows_version’\n"
prog;
exit 1
and arch_of_string = function
| "x86_64" -> X86_64
| "aarch64" -> Aarch64
| "armv7l" -> Armv7
| "i686" -> I686
| "ppc64" -> PPC64
| "ppc64le" -> PPC64le
| "s390x" -> S390X
| s ->
eprintf "%s: unknown or unsupported arch (%s)\n" prog s; exit 1
and string_of_arch = function
| X86_64 -> "x86_64"
| Aarch64 -> "aarch64"
| Armv7 -> "armv7l"
| I686 -> "i686"
| PPC64 -> "ppc64"
| PPC64le -> "ppc64le"
| S390X -> "s390x"
and debian_arch_of_arch = function
| X86_64 -> "amd64"
| Aarch64 -> "arm64"
| Armv7 -> "armhf"
| I686 -> "i386"
| PPC64 -> "ppc64"
| PPC64le -> "ppc64el"
| S390X -> "s390x"
and filename_of_os os arch ext =
match os with
| Fedora ver ->
if arch = X86_64 then sprintf "fedora-%d%s" ver ext
else sprintf "fedora-%d-%s%s" ver (string_of_arch arch) ext
| Alma (major, minor) ->
if arch = X86_64 then sprintf "alma-%d.%d%s" major minor ext
else sprintf "alma-%d.%d-%s%s" major minor (string_of_arch arch) ext
| CentOS (major, minor) ->
if arch = X86_64 then sprintf "centos-%d.%d%s" major minor ext
else sprintf "centos-%d.%d-%s%s" major minor (string_of_arch arch) ext
| CentOSStream ver ->
if arch = X86_64 then sprintf "centosstream-%d%s" ver ext
else sprintf "centosstream-%d-%s%s" ver (string_of_arch arch) ext
| RHEL (major, minor) ->
if arch = X86_64 then sprintf "rhel-%d.%d%s" major minor ext
else sprintf "rhel-%d.%d-%s%s" major minor (string_of_arch arch) ext
| Debian (ver, _) ->
if arch = X86_64 then sprintf "debian-%d%s" ver ext
else sprintf "debian-%d-%s%s" ver (string_of_arch arch) ext
| Ubuntu (ver, _) ->
if arch = X86_64 then sprintf "ubuntu-%s%s" ver ext
else sprintf "ubuntu-%s-%s%s" ver (string_of_arch arch) ext
| FreeBSD (major, minor) ->
if arch = X86_64 then sprintf "freebsd-%d.%d%s" major minor ext
else sprintf "freebsd-%d.%d-%s%s" major minor (string_of_arch arch) ext
| Windows (major, minor, Client) ->
if arch = X86_64 then sprintf "windows-%d.%d-client%s" major minor ext
else sprintf "windows-%d.%d-client-%s%s"
major minor (string_of_arch arch) ext
| Windows (major, minor, Server) ->
if arch = X86_64 then sprintf "windows-%d.%d-server%s" major minor ext
else sprintf "windows-%d.%d-server-%s%s"
major minor (string_of_arch arch) ext
and string_of_os os arch = filename_of_os os arch ""
(* This is what virt-builder called "os-version". *)
and string_of_os_noarch = function
| Fedora ver -> sprintf "fedora-%d" ver
| Alma (major, minor) -> sprintf "alma-%d.%d" major minor
| CentOS (major, minor) -> sprintf "centos-%d.%d" major minor
| CentOSStream ver -> sprintf "centosstream-%d" ver
| RHEL (major, minor) -> sprintf "rhel-%d.%d" major minor
| Debian (ver, _) -> sprintf "debian-%d" ver
| Ubuntu (ver, _) -> sprintf "ubuntu-%s" ver
| FreeBSD (major, minor) -> sprintf "freebsd-%d.%d" major minor
| Windows (major, minor, Client) -> sprintf "windows-%d.%d-client" major minor
| Windows (major, minor, Server) -> sprintf "windows-%d.%d-server" major minor
(* Does virt-sysprep know how to sysprep this OS? *)
and can_sysprep_os = function
| RHEL _ | Alma _ | CentOS _ | CentOSStream _ | Fedora _
| Debian _ | Ubuntu _ -> true
| FreeBSD _ | Windows _ -> false
and needs_uefi os arch =
match os, arch with
| Fedora _, Armv7
| Fedora _, Aarch64
| RHEL _, Aarch64 -> true
| RHEL _, _ | Alma _, _ | CentOS _, _ | CentOSStream _, _ | Fedora _, _
| Debian _, _ | Ubuntu _, _
| FreeBSD _, _ | Windows _, _ -> false
and get_virtual_size_gb os arch =
match os with
| RHEL _ | Alma _ | CentOS _ | CentOSStream _ | Fedora _
| Debian _ | Ubuntu _
| FreeBSD _ -> 6
| Windows (10, _, _) -> 40 (* Windows 10 *)
| Windows (6, _, _) -> 10 (* Windows from 2008 - 2012 *)
| Windows (5, _, _) -> 6 (* Windows <= 2003 *)
| Windows _ -> assert false
and make_kickstart os arch =
match os with
(* Kickstart. *)
| Fedora _ | Alma _ | CentOS _ | CentOSStream _ | RHEL _ ->
let ks_filename = filename_of_os os arch ".ks" in
Some (make_kickstart_common ks_filename os arch)
(* Preseed. *)
| Debian _ -> Some (copy_preseed_to_temporary "debian.preseed")
| Ubuntu _ -> Some (copy_preseed_to_temporary "ubuntu.preseed")
(* Not automated. *)
| FreeBSD _ -> None
(* Windows unattend.xml wrapped in an ISO. *)
| Windows _ -> Some (make_unattend_iso os arch)
and make_kickstart_common ks_filename os arch =
let buf = Buffer.create 4096 in
let bpf fs = bprintf buf fs in
bpf "\
# Kickstart file for %s
# Generated by libguestfs.git/builder/templates/make-template.ml
" (string_of_os os arch);
(* Fedora 34+ removes the "install" keyword. *)
(match os with
| Fedora n when n >= 34 -> ()
| RHEL (n, _)
| Alma (n, _) | CentOS (n, _) | CentOSStream n when n >= 9 -> ()
| _ -> bpf "install\n";
);
bpf "\
text
reboot
lang en_US.UTF-8
keyboard us
network --bootproto dhcp
rootpw builder
firewall --enabled --ssh
timezone --utc America/New_York
";
(match os with
| RHEL (ver, _) when ver <= 4 ->
bpf "\
langsupport en_US
mouse generic
";
| _ -> ()
);
(match os with
| RHEL (3, _) -> ()
| _ ->
bpf "selinux --enforcing\n"
);
(match os with
| RHEL (5, _) -> bpf "key --skip\n"
| _ -> ()
);
bpf "\n";
bpf "bootloader --location=mbr --append=\"%s\"\n"
(kernel_cmdline_of_os os arch);
bpf "\n";
(* Required as a workaround for CentOS 8.0, see:
* https://lists.centos.org/pipermail/centos-devel/2019-September/017813.html
* https://lists.centos.org/pipermail/centos-devel/2019-October/017882.html
*)
(match os with
| CentOS (8, _) ->
bpf "url --url=\"https://vault.centos.org/8.5.2111/BaseOS/x86_64/os/\"\n"
| _ -> ()
);
bpf "\n";
(match os with
| CentOS ((3|4|5|6) as major, _) | RHEL ((3|4|5|6) as major, _) ->
let bootfs = if major <= 5 then "ext2" else "ext4" in
let rootfs = if major <= 4 then "ext3" else "ext4" in
bpf "\
zerombr
clearpart --all --initlabel
part /boot --fstype=%s --size=512 --asprimary
part swap --size=1024 --asprimary
part / --fstype=%s --size=1024 --grow --asprimary
" bootfs rootfs;
| Alma _ | CentOS _ | CentOSStream _ | RHEL _ | Fedora _ ->
bpf "\
zerombr
clearpart --all --initlabel --disklabel=gpt
autopart --type=plain
";
| _ -> assert false (* cannot happen, see caller *)
);
bpf "\n";
(match os with
| RHEL (3, _) -> ()
| _ ->
bpf "\
# Halt the system once configuration has finished.
poweroff
";
);
bpf "\n";
bpf "\
%%packages
@core
";
(match os with
| RHEL ((3|4|5), _) -> ()
| _ ->
bpf "%%end\n"
);
bpf "\n";
(* Generate the %post script section. The previous scripts did
* many different things here. The current script tries to update
* the packages and enable Xen drivers only.
*)
let regenerate_dracut () =
bpf "\
# To make dracut config changes permanent, we need to rerun dracut.
# Rerun dracut for the installed kernel (not the running kernel).
# See commit 0fa52e4e45d80874bc5ea5f112f74be1d3f3472f and
# https://www.redhat.com/archives/libguestfs/2014-June/thread.html#00045
KERNEL_VERSION=\"$(rpm -q kernel --qf '%%{version}-%%{release}.%%{arch}\\n' |
sort -V | tail -1)\"
dracut -f /boot/initramfs-$KERNEL_VERSION.img $KERNEL_VERSION
"
in
(match os with
| Fedora _ ->
bpf "%%post\n";
bpf "\
# Ensure the installation is up-to-date.
dnf -y --best upgrade
# This required otherwise the kernel will not be bootable, see
# https://bugzilla.redhat.com/show_bug.cgi?id=1911177
# https://bugzilla.redhat.com/show_bug.cgi?id=1945835#c24
grub2-mkconfig -o %s
" (quote
(if needs_uefi os arch then "/etc/grub2-efi.cfg"
else "/etc/grub2.cfg"));
let needs_regenerate_dracut = ref false in
if arch = X86_64 then (
bpf "\
# Enable Xen domU support.
pushd /etc/dracut.conf.d
echo 'add_drivers+=\" xen:vbd xen:vif \"' > virt-builder-xen-drivers.conf
popd
";
needs_regenerate_dracut := true
);
if arch = PPC64 || arch = PPC64le then (
bpf "\
# Enable virtio-scsi support.
pushd /etc/dracut.conf.d
echo 'add_drivers+=\" virtio-blk virtio-scsi \"' > virt-builder-virtio-scsi.conf
popd
";
needs_regenerate_dracut := true
);
if !needs_regenerate_dracut then regenerate_dracut ();
bpf "%%end\n\n"
| RHEL (7,_) ->
bpf "%%post\n";
let needs_regenerate_dracut = ref false in
if arch = PPC64 || arch = PPC64le then (
bpf "\
# Enable virtio-scsi support.
pushd /etc/dracut.conf.d
echo 'add_drivers+=\" virtio-blk virtio-scsi \"' > virt-builder-virtio-scsi.conf
popd
";
needs_regenerate_dracut := true
);
if !needs_regenerate_dracut then regenerate_dracut ();
bpf "%%end\n\n"
| _ -> ()
);
bpf "# EOF\n";
(* Write out the kickstart file. *)
let chan = open_out (ks_filename ^ ".new") in
Buffer.output_buffer chan buf;
close_out chan;
let cmd =
sprintf "mv %s %s" (quote (ks_filename ^ ".new")) (quote ks_filename) in
if Sys.command cmd <> 0 then exit 1;
(* Return the kickstart filename. *)
ks_filename
and copy_preseed_to_temporary source =
(* d-i only works if the file is literally called "/preseed.cfg" *)
let d = Filename.get_temp_dir_name () // random8 () ^ ".tmp" in
let f = d // "preseed.cfg" in
Unix.mkdir d 0o700;
let cmd = sprintf "cp %s %s" (quote source) (quote f) in
if Sys.command cmd <> 0 then exit 1;
f
(* For Windows:
* https://serverfault.com/questions/644437/unattended-installation-of-windows-server-2012-on-kvm
*)
and make_unattend_iso os arch =
printf "enter Windows product key: ";
let product_key = read_line () in
let output_iso =
Sys.getcwd () // filename_of_os os arch "-unattend.iso" in
unlink_on_exit output_iso;
let d = Filename.get_temp_dir_name () // random8 () in
Unix.mkdir d 0o700;
let config_dir = d // "config" in
Unix.mkdir config_dir 0o700;
let f = config_dir // "autounattend.xml" in
let chan = open_out f in
let arch =
match arch with
| X86_64 -> "amd64"
| I686 -> "x86"
| _ ->
eprintf "%s: Windows architecture %s not supported\n"
prog (string_of_arch arch);
exit 1 in
(* Tip: If the install fails with a useless error "The answer file is
* invalid", type Shift + F10 into the setup screen and look for a
* file called \Windows\Panther\Setupact.log (NB:
* not \Windows\Setupact.log)
*)
fprintf chan "
<unattend xmlns=\"urn:schemas-microsoft-com:unattend\"
xmlns:ms=\"urn:schemas-microsoft-com:asm.v3\"
xmlns:wcm=\"http://schemas.microsoft.com/WMIConfig/2002/State\">
<settings pass=\"windowsPE\">
<component name=\"Microsoft-Windows-Setup\"
publicKeyToken=\"31bf3856ad364e35\"
language=\"neutral\"
versionScope=\"nonSxS\"
processorArchitecture=\"%s\">
<UserData>
<AcceptEula>true</AcceptEula>
<ProductKey>
<Key>%s</Key>
<WillShowUI>OnError</WillShowUI>
</ProductKey>
</UserData>
<DiskConfiguration>
<Disk wcm:action=\"add\">
<DiskID>0</DiskID>
<WillWipeDisk>true</WillWipeDisk>
<CreatePartitions>
<!-- System partition -->
<CreatePartition wcm:action=\"add\">
<Order>1</Order>
<Type>Primary</Type>
<Size>300</Size>
</CreatePartition>
<!-- Windows partition -->
<CreatePartition wcm:action=\"add\">
<Order>2</Order>
<Type>Primary</Type>
<Extend>true</Extend>
</CreatePartition>
</CreatePartitions>
<ModifyPartitions>
<!-- System partition -->
<ModifyPartition wcm:action=\"add\">
<Order>1</Order>
<PartitionID>1</PartitionID>
<Label>System</Label>
<Format>NTFS</Format>
<Active>true</Active>
</ModifyPartition>
<!-- Windows partition -->
<ModifyPartition wcm:action=\"add\">
<Order>2</Order>
<PartitionID>2</PartitionID>
<Label>Windows</Label>
<Letter>C</Letter>
<Format>NTFS</Format>
</ModifyPartition>
</ModifyPartitions>
</Disk>
<WillShowUI>OnError</WillShowUI>
</DiskConfiguration>
<ImageInstall>
<OSImage>
<WillShowUI>Never</WillShowUI>
<InstallFrom>
<MetaData>
<Key>/IMAGE/INDEX</Key>
<Value>1</Value>
</MetaData>
</InstallFrom>
<InstallTo>
<DiskID>0</DiskID>
<PartitionID>2</PartitionID>
</InstallTo>
</OSImage>
</ImageInstall>
</component>
<component name=\"Microsoft-Windows-International-Core-WinPE\"
publicKeyToken=\"31bf3856ad364e35\"
language=\"neutral\"
versionScope=\"nonSxS\"
processorArchitecture=\"%s\">
<SetupUILanguage>
<UILanguage>en-US</UILanguage>
</SetupUILanguage>
<SystemLocale>en-US</SystemLocale>
<UILanguage>en-US</UILanguage>
<UserLocale>en-US</UserLocale>
</component>
</settings>
</unattend>"
arch product_key arch;
close_out chan;
let cmd = sprintf "cd %s && mkisofs -o %s -J -r config"
(quote d) (quote output_iso) in
if Sys.command cmd <> 0 then exit 1;
let cmd = sprintf "rm -rf %s" (quote d) in
if Sys.command cmd <> 0 then exit 1;
(* Return the name of the unattend ISO. *)
output_iso
and make_boot_media os arch =
match os, arch with
| Alma (major, minor), X86_64 ->
(* UK mirror *)
Location (sprintf "http://mirror.cov.ukservers.com/almalinux/\
%d.%d/BaseOS/x86_64/kickstart/"
major minor)
| CentOS (major, _), Aarch64 ->
(* XXX This always points to the latest CentOS, so
* effectively the minor number is always ignored.
*)
Location (sprintf "http://mirror.centos.org/altarch/%d/os/aarch64/"
major)
| CentOS (7, _), X86_64 ->
(* For 6.x we rebuild this every time there is a new 6.x release, and bump
* the revision in the index.
* For 7.x this always points to the latest CentOS, so
* effectively the minor number is always ignored.
*)
Location "http://mirror.centos.org/centos-7/7/os/x86_64/"
| CentOS (8, _), X86_64 ->
(* This is probably the last CentOS 8 release. *)
Location "https://vault.centos.org/8.5.2111/BaseOS/x86_64/kickstart/"
| CentOSStream 8, X86_64 ->
Location (sprintf "http://mirror.centos.org/centos/8-stream/BaseOS/\
x86_64/os")
| CentOSStream ver, X86_64 ->
Location (sprintf "http://mirror.stream.centos.org/%d-stream/BaseOS/\
x86_64/os" ver)
| Debian (_, dist), arch ->
Location (sprintf "http://deb.debian.org/debian/dists/%s/main/installer-%s"
dist (debian_arch_of_arch arch))
(* Fedora primary architectures. *)
| Fedora ver, Armv7 ->
Location (sprintf "https://lon.mirror.rackspace.com/fedora/releases/\
%d/Server/armhfp/os/" ver)
| Fedora ver, X86_64 when ver < 21 ->
Location (sprintf "https://lon.mirror.rackspace.com/fedora/releases/\
releases/%d/Fedora/x86_64/os/" ver)
| Fedora ver, X86_64 ->
Location (sprintf "https://lon.mirror.rackspace.com/fedora/releases/\
%d/Server/x86_64/os/" ver)
| Fedora ver, Aarch64 ->
Location (sprintf "https://lon.mirror.rackspace.com/fedora/releases/\
%d/Server/aarch64/os/" ver)
(* Fedora secondary architectures.
* By using dl.fedoraproject.org we avoid randomly using mirrors
* which might have incomplete copies.
*)
| Fedora ver, I686 ->
Location (sprintf "https://dl.fedoraproject.org/pub/fedora-secondary/\
releases/%d/Server/i386/os/" ver)
| Fedora ver, PPC64 ->
Location (sprintf "https://dl.fedoraproject.org/pub/fedora-secondary/\
releases/%d/Server/ppc64/os/" ver)
| Fedora ver, PPC64le ->
Location (sprintf "https://dl.fedoraproject.org/pub/fedora-secondary/\
releases/%d/Server/ppc64le/os/" ver)
| Fedora ver, S390X ->
Location (sprintf "https://dl.fedoraproject.org/pub/fedora-secondary/\
releases/%d/Server/s390x/os/" ver)
| RHEL (3, minor), X86_64 ->
Location (sprintf "http://download.devel.redhat.com/released/RHEL-3/\
U%d/AS/x86_64/tree" minor)
| RHEL (4, minor), X86_64 ->
Location (sprintf "http://download.devel.redhat.com/released/RHEL-4/\
U%d/AS/x86_64/tree" minor)
| RHEL (5, minor), I686 ->
Location (sprintf "http://download.devel.redhat.com/released/\
RHEL-5-Server/U%d/i386/os" minor)
| RHEL (5, minor), X86_64 ->
Location (sprintf "http://download.devel.redhat.com/released/\
RHEL-5-Server/U%d/x86_64/os" minor)
| RHEL (6, minor), I686 ->
Location (sprintf "http://download.devel.redhat.com/released/\
RHEL-6/6.%d/Server/i386/os" minor)
| RHEL (6, minor), X86_64 ->
Location (sprintf "http://download.devel.redhat.com/released/\
RHEL-6/6.%d/Server/x86_64/os" minor)
| RHEL (7, minor), X86_64 ->
Location (sprintf "http://download.devel.redhat.com/released/\
rhel-6-7-8/rhel-7/RHEL-7/7.%d/Server/x86_64/os" minor)
| RHEL (7, minor), PPC64 ->
Location (sprintf "http://download.devel.redhat.com/released/\
rhel-6-7-8/rhel-7/RHEL-7/7.%d/Server/ppc64/os" minor)
| RHEL (7, minor), PPC64le ->
Location (sprintf "http://download.devel.redhat.com/released/\
rhel-6-7-8/rhel-7/RHEL-7/7.%d/Server/ppc64le/os" minor)
| RHEL (7, minor), S390X ->
Location (sprintf "http://download.devel.redhat.com/released/\
rhel-6-7-8/rhel-7/RHEL-7/7.%d/Server/s390x/os" minor)
| RHEL (7, minor), Aarch64 ->
Location (sprintf "http://download.eng.bos.redhat.com/released/\
RHEL-ALT-7/7.%d/Server/aarch64/os" minor)
| RHEL (8, minor), arch ->
Location (sprintf "http://download.eng.bos.redhat.com/released/\
rhel-6-7-8/rhel-8/RHEL-8/8.%d.0/BaseOS/%s/os"
minor (string_of_arch arch))
| RHEL (9, minor), arch ->
Location (sprintf "http://download.eng.bos.redhat.com/released/\
RHEL-9/9.%d.0/BaseOS/%s/os" minor (string_of_arch arch))
| Ubuntu (_, dist), X86_64 ->
Location (sprintf "http://archive.ubuntu.com/ubuntu/dists/\
%s/main/installer-amd64" dist)
| Ubuntu (_, dist), PPC64le ->
Location (sprintf "http://ports.ubuntu.com/ubuntu-ports/dists/\
%s/main/installer-ppc64el" dist)
| FreeBSD (major, minor), X86_64 ->
let iso = sprintf "FreeBSD-%d.%d-RELEASE-amd64-disc1.iso"
major minor in
let iso_xz = sprintf "ftp://ftp.freebsd.org/pub/FreeBSD/releases/\
amd64/amd64/ISO-IMAGES/%d.%d/%s.xz"
major minor iso in
let cmd = sprintf "wget -nc %s" (quote iso_xz) in