blob: 52a82faf0a32664cea71100b60f124a6a6f59f76 [file] [log] [blame]
Sean Daguee263c822014-12-05 14:25:28 -05001#!/bin/bash
2#
Dean Troyerdff49a22014-01-30 15:37:40 -06003# functions - DevStack-specific functions
Dean Troyer13dc5cc2012-03-27 14:50:45 -05004#
Dean Troyer4a43b7b2012-08-28 17:43:40 -05005# The following variables are assumed to be defined by certain functions:
Adam Spiers6a5aa7c2013-10-24 11:27:02 +01006#
Dean Troyerd8864fe2014-02-17 11:00:42 -06007# - ``DATABASE_BACKENDS``
Adam Spiers6a5aa7c2013-10-24 11:27:02 +01008# - ``ENABLED_SERVICES``
Adam Spiers6a5aa7c2013-10-24 11:27:02 +01009# - ``FILES``
10# - ``GLANCE_HOSTPORT``
Dean Troyerd8864fe2014-02-17 11:00:42 -060011#
Dean Troyer13dc5cc2012-03-27 14:50:45 -050012
Ian Wienand4ffb4542015-06-30 11:00:32 +100013# ensure we don't re-source this in the same environment
14[[ -z "$_DEVSTACK_FUNCTIONS" ]] || return 0
Sean Dagueafef8bf2017-03-06 14:07:23 -050015declare -r -g _DEVSTACK_FUNCTIONS=1
Ian Wienand4ffb4542015-06-30 11:00:32 +100016
Dean Troyerdff49a22014-01-30 15:37:40 -060017# Include the common functions
18FUNC_DIR=$(cd $(dirname "${BASH_SOURCE:-$0}") && pwd)
19source ${FUNC_DIR}/functions-common
Dean Troyerbf2ad702015-03-09 15:16:10 -050020source ${FUNC_DIR}/inc/ini-config
Dean Troyer490430d2015-01-30 14:38:35 -060021source ${FUNC_DIR}/inc/python
Dean Troyer32d6bc62015-03-29 14:16:44 -050022source ${FUNC_DIR}/inc/rootwrap
Dean Troyer7f9aa712012-01-31 12:11:56 -060023
Dean Troyer27e32692012-03-16 16:16:56 -050024# Save trace setting
Ian Wienand523f4882015-10-13 11:03:03 +110025_XTRACE_FUNCTIONS=$(set +o | grep xtrace)
Dean Troyer27e32692012-03-16 16:16:56 -050026set +o xtrace
27
Ian Wienand54e39102014-06-03 16:05:12 +100028# Check if a function already exists
29function function_exists {
30 declare -f -F $1 > /dev/null
31}
Dean Troyer7f9aa712012-01-31 12:11:56 -060032
Sean Dague646085d2016-03-21 17:00:51 -040033# short_source prints out the current location of the caller in a way
34# that strips redundant directories. This is useful for PS4 usage.
35function short_source {
36 saveIFS=$IFS
37 IFS=" "
38 called=($(caller 0))
39 IFS=$saveIFS
40 file=${called[2]}
41 file=${file#$RC_DIR/}
42 printf "%-40s " "$file:${called[1]}:${called[0]}"
43}
John L. Villalovosdaa7a412016-05-05 12:50:52 -070044# PS4 is exported to child shells and uses the 'short_source' function, so
45# export it so child shells have access to the 'short_source' function also.
46export -f short_source
Sean Dague646085d2016-03-21 17:00:51 -040047
48
Adam Spierscb961592013-10-05 12:11:07 +010049# Retrieve an image from a URL and upload into Glance.
Dean Troyerca0e3d02012-04-13 15:58:37 -050050# Uses the following variables:
Adam Spierscb961592013-10-05 12:11:07 +010051#
52# - ``FILES`` must be set to the cache dir
53# - ``GLANCE_HOSTPORT``
54#
Peter Stachowski5aeea6a2015-09-22 19:38:02 +000055# upload_image image-url
Ian Wienandaee18c72014-02-21 15:35:08 +110056function upload_image {
Dean Troyerca0e3d02012-04-13 15:58:37 -050057 local image_url=$1
Dean Troyerca0e3d02012-04-13 15:58:37 -050058
Dean Troyere9f76672014-07-25 11:09:36 -050059 local image image_fname image_name
60
Dean Troyerca0e3d02012-04-13 15:58:37 -050061 # Create a directory for the downloaded image tarballs.
62 mkdir -p $FILES/images
Dean Troyere9f76672014-07-25 11:09:36 -050063 image_fname=`basename "$image_url"`
Arnaud Legendre3e439442013-11-15 16:06:03 -080064 if [[ $image_url != file* ]]; then
Sreeram Yerrapragada314af0a2014-03-03 21:34:45 -080065 # Downloads the image (uec ami+akistyle), then extracts it.
Dean Troyere9f76672014-07-25 11:09:36 -050066 if [[ ! -f $FILES/$image_fname || "$(stat -c "%s" $FILES/$image_fname)" = "0" ]]; then
Attila Fazekas057d6ae2015-01-13 14:01:26 +010067 wget --progress=dot:giga -c $image_url -O $FILES/$image_fname
Isaku Yamahata6681a4f2014-01-10 15:28:29 +090068 if [[ $? -ne 0 ]]; then
69 echo "Not found: $image_url"
70 return
71 fi
Arnaud Legendre3e439442013-11-15 16:06:03 -080072 fi
Dean Troyere9f76672014-07-25 11:09:36 -050073 image="$FILES/${image_fname}"
Arnaud Legendre3e439442013-11-15 16:06:03 -080074 else
Dean Troyer3324f192014-09-18 09:26:39 -050075 # File based URL (RFC 1738): ``file://host/path``
Arnaud Legendre3e439442013-11-15 16:06:03 -080076 # Remote files are not considered here.
Dean Troyer3324f192014-09-18 09:26:39 -050077 # unix: ``file:///home/user/path/file``
78 # windows: ``file:///C:/Documents%20and%20Settings/user/path/file``
Dean Troyere9f76672014-07-25 11:09:36 -050079 image=$(echo $image_url | sed "s/^file:\/\///g")
80 if [[ ! -f $image || "$(stat -c "%s" $image)" == "0" ]]; then
Dean Troyerca0e3d02012-04-13 15:58:37 -050081 echo "Not found: $image_url"
82 return
83 fi
84 fi
85
86 # OpenVZ-format images are provided as .tar.gz, but not decompressed prior to loading
87 if [[ "$image_url" =~ 'openvz' ]]; then
Dean Troyere9f76672014-07-25 11:09:36 -050088 image_name="${image_fname%.tar.gz}"
Victor Ryzhenkin878d7d82016-04-27 15:15:52 +030089 openstack --os-cloud=devstack-admin --os-region-name="$REGION_NAME" image create "$image_name" --public --container-format ami --disk-format ami < "${image}"
Dean Troyerca0e3d02012-04-13 15:58:37 -050090 return
91 fi
92
Sreeram Yerrapragadacbaff862013-07-24 19:49:23 -070093 # vmdk format images
94 if [[ "$image_url" =~ '.vmdk' ]]; then
Dean Troyere9f76672014-07-25 11:09:36 -050095 image_name="${image_fname%.vmdk}"
Ryan Hsua6273b92013-09-04 23:51:29 -070096
97 # Before we can upload vmdk type images to glance, we need to know it's
98 # disk type, storage adapter, and networking adapter. These values are
Ryan Hsubfb3e5e2013-11-11 21:20:14 -080099 # passed to glance as custom properties.
Arnaud Legendre5ea53ee2013-11-01 16:42:54 -0700100 # We take these values from the vmdk file if populated. Otherwise, we use
Ryan Hsua6273b92013-09-04 23:51:29 -0700101 # vmdk filename, which is expected in the following format:
102 #
Ryan Hsubfb3e5e2013-11-11 21:20:14 -0800103 # <name>-<disk type>;<storage adapter>;<network adapter>
Ryan Hsua6273b92013-09-04 23:51:29 -0700104 #
105 # If the filename does not follow the above format then the vsphere
106 # driver will supply default values.
Arnaud Legendre5ea53ee2013-11-01 16:42:54 -0700107
Dean Troyere9f76672014-07-25 11:09:36 -0500108 local vmdk_disktype=""
Sabari Kumar Murugesan88cde0b2014-12-04 17:48:26 -0800109 local vmdk_net_adapter="e1000"
Dean Troyere9f76672014-07-25 11:09:36 -0500110 local path_len
Ryan Hsubfb3e5e2013-11-11 21:20:14 -0800111
Arnaud Legendre5ea53ee2013-11-01 16:42:54 -0700112 # vmdk adapter type
Ian Wienand7ae97292016-02-16 14:50:53 +1100113 local vmdk_adapter_type
114 vmdk_adapter_type="$(head -25 $image | { grep -a -F -m 1 'ddb.adapterType =' $image || true; })"
Arnaud Legendre5ea53ee2013-11-01 16:42:54 -0700115 vmdk_adapter_type="${vmdk_adapter_type#*\"}"
116 vmdk_adapter_type="${vmdk_adapter_type%?}"
117
118 # vmdk disk type
Ian Wienand7ae97292016-02-16 14:50:53 +1100119 local vmdk_create_type
120 vmdk_create_type="$(head -25 $image | { grep -a -F -m 1 'createType=' $image || true; })"
Arnaud Legendre5ea53ee2013-11-01 16:42:54 -0700121 vmdk_create_type="${vmdk_create_type#*\"}"
Arnaud Legendre8dad4bd2014-02-03 17:57:39 -0800122 vmdk_create_type="${vmdk_create_type%\"*}"
Arnaud Legendre90bcd2f2013-11-22 16:05:39 -0800123
124 descriptor_data_pair_msg="Monolithic flat and VMFS disks "`
Isaku Yamahata6681a4f2014-01-10 15:28:29 +0900125 `"should use a descriptor-data pair."
Arnaud Legendre5ea53ee2013-11-01 16:42:54 -0700126 if [[ "$vmdk_create_type" = "monolithicSparse" ]]; then
127 vmdk_disktype="sparse"
Dean Troyere9f76672014-07-25 11:09:36 -0500128 elif [[ "$vmdk_create_type" = "monolithicFlat" || "$vmdk_create_type" = "vmfs" ]]; then
Dean Troyer3324f192014-09-18 09:26:39 -0500129 # Attempt to retrieve the ``*-flat.vmdk``
Ian Wienand7ae97292016-02-16 14:50:53 +1100130 local flat_fname
131 flat_fname="$(head -25 $image | { grep -G 'RW\|RDONLY [0-9]+ FLAT\|VMFS' $image || true; })"
Arnaud Legendre90bcd2f2013-11-22 16:05:39 -0800132 flat_fname="${flat_fname#*\"}"
133 flat_fname="${flat_fname%?}"
Sreeram Yerrapragada9c6d2842014-03-10 14:12:58 -0700134 if [[ -z "$flat_fname" ]]; then
Dean Troyere9f76672014-07-25 11:09:36 -0500135 flat_fname="$image_name-flat.vmdk"
Arnaud Legendre90bcd2f2013-11-22 16:05:39 -0800136 fi
Dean Troyere9f76672014-07-25 11:09:36 -0500137 path_len=`expr ${#image_url} - ${#image_fname}`
138 local flat_url="${image_url:0:$path_len}$flat_fname"
Arnaud Legendre90bcd2f2013-11-22 16:05:39 -0800139 warn $LINENO "$descriptor_data_pair_msg"`
Isaku Yamahata6681a4f2014-01-10 15:28:29 +0900140 `" Attempt to retrieve the *-flat.vmdk: $flat_url"
Arnaud Legendre90bcd2f2013-11-22 16:05:39 -0800141 if [[ $flat_url != file* ]]; then
142 if [[ ! -f $FILES/$flat_fname || \
143 "$(stat -c "%s" $FILES/$flat_fname)" = "0" ]]; then
Attila Fazekas057d6ae2015-01-13 14:01:26 +0100144 wget --progress=dot:giga -c $flat_url -O $FILES/$flat_fname
Arnaud Legendre90bcd2f2013-11-22 16:05:39 -0800145 fi
Dean Troyere9f76672014-07-25 11:09:36 -0500146 image="$FILES/${flat_fname}"
Arnaud Legendre90bcd2f2013-11-22 16:05:39 -0800147 else
Dean Troyere9f76672014-07-25 11:09:36 -0500148 image=$(echo $flat_url | sed "s/^file:\/\///g")
149 if [[ ! -f $image || "$(stat -c "%s" $image)" == "0" ]]; then
Arnaud Legendre90bcd2f2013-11-22 16:05:39 -0800150 echo "Flat disk not found: $flat_url"
Sreeram Yerrapragada9c6d2842014-03-10 14:12:58 -0700151 return 1
Arnaud Legendre90bcd2f2013-11-22 16:05:39 -0800152 fi
153 fi
Dean Troyere9f76672014-07-25 11:09:36 -0500154 image_name="${flat_fname}"
Arnaud Legendre90bcd2f2013-11-22 16:05:39 -0800155 vmdk_disktype="preallocated"
Arnaud Legendre8dad4bd2014-02-03 17:57:39 -0800156 elif [[ "$vmdk_create_type" = "streamOptimized" ]]; then
157 vmdk_disktype="streamOptimized"
Arnaud Legendre90bcd2f2013-11-22 16:05:39 -0800158 elif [[ -z "$vmdk_create_type" ]]; then
159 # *-flat.vmdk provided: attempt to retrieve the descriptor (*.vmdk)
160 # to retrieve appropriate metadata
Dean Troyere9f76672014-07-25 11:09:36 -0500161 if [[ ${image_name: -5} != "-flat" ]]; then
Arnaud Legendre90bcd2f2013-11-22 16:05:39 -0800162 warn $LINENO "Expected filename suffix: '-flat'."`
Dean Troyere9f76672014-07-25 11:09:36 -0500163 `" Filename provided: ${image_name}"
Sreeram Yerrapragada9c6d2842014-03-10 14:12:58 -0700164 else
Dean Troyere9f76672014-07-25 11:09:36 -0500165 descriptor_fname="${image_name:0:${#image_name} - 5}.vmdk"
166 path_len=`expr ${#image_url} - ${#image_fname}`
167 local flat_path="${image_url:0:$path_len}"
168 local descriptor_url=$flat_path$descriptor_fname
Sreeram Yerrapragada9c6d2842014-03-10 14:12:58 -0700169 warn $LINENO "$descriptor_data_pair_msg"`
170 `" Attempt to retrieve the descriptor *.vmdk: $descriptor_url"
171 if [[ $flat_path != file* ]]; then
172 if [[ ! -f $FILES/$descriptor_fname || \
173 "$(stat -c "%s" $FILES/$descriptor_fname)" = "0" ]]; then
174 wget -c $descriptor_url -O $FILES/$descriptor_fname
175 fi
176 descriptor_url="$FILES/$descriptor_fname"
177 else
178 descriptor_url=$(echo $descriptor_url | sed "s/^file:\/\///g")
179 if [[ ! -f $descriptor_url || \
180 "$(stat -c "%s" $descriptor_url)" == "0" ]]; then
181 echo "Descriptor not found: $descriptor_url"
182 return 1
Arnaud Legendre90bcd2f2013-11-22 16:05:39 -0800183 fi
184 fi
Ryan Hsu99b622a2014-03-05 15:35:49 -0800185 vmdk_adapter_type="$(head -25 $descriptor_url | { grep -a -F -m 1 'ddb.adapterType =' $descriptor_url || true; })"
186 vmdk_adapter_type="${vmdk_adapter_type#*\"}"
187 vmdk_adapter_type="${vmdk_adapter_type%?}"
188 fi
Isaku Yamahata6681a4f2014-01-10 15:28:29 +0900189 vmdk_disktype="preallocated"
Arnaud Legendre5ea53ee2013-11-01 16:42:54 -0700190 else
Arnaud Legendre5ea53ee2013-11-01 16:42:54 -0700191 vmdk_disktype="preallocated"
192 fi
Ryan Hsubfb3e5e2013-11-11 21:20:14 -0800193
194 # NOTE: For backwards compatibility reasons, colons may be used in place
195 # of semi-colons for property delimiters but they are not permitted
196 # characters in NTFS filesystems.
Dean Troyere9f76672014-07-25 11:09:36 -0500197 property_string=`echo "$image_name" | { grep -oP '(?<=-)(?!.*-).*[:;].*[:;].*$' || true; }`
Ryan Hsubfb3e5e2013-11-11 21:20:14 -0800198 IFS=':;' read -a props <<< "$property_string"
199 vmdk_disktype="${props[0]:-$vmdk_disktype}"
200 vmdk_adapter_type="${props[1]:-$vmdk_adapter_type}"
201 vmdk_net_adapter="${props[2]:-$vmdk_net_adapter}"
Ryan Hsua6273b92013-09-04 23:51:29 -0700202
Victor Ryzhenkin878d7d82016-04-27 15:15:52 +0300203 openstack --os-cloud=devstack-admin --os-region-name="$REGION_NAME" image create "$image_name" --public --container-format bare --disk-format vmdk --property vmware_disktype="$vmdk_disktype" --property vmware_adaptertype="$vmdk_adapter_type" --property hw_vif_model="$vmdk_net_adapter" < "${image}"
Sreeram Yerrapragadacbaff862013-07-24 19:49:23 -0700204 return
205 fi
206
Mate Lakatbc2ef922013-08-15 18:06:59 +0100207 # XenServer-vhd-ovf-format images are provided as .vhd.tgz
Davanum Srinivas316ed6c2013-02-06 15:29:49 -0500208 # and should not be decompressed prior to loading
209 if [[ "$image_url" =~ '.vhd.tgz' ]]; then
Dean Troyere9f76672014-07-25 11:09:36 -0500210 image_name="${image_fname%.vhd.tgz}"
211 local force_vm_mode=""
212 if [[ "$image_name" =~ 'cirros' ]]; then
Bob Ballf1a2dbf2014-03-19 11:08:54 +0000213 # Cirros VHD image currently only boots in PV mode.
214 # Nova defaults to PV for all VHD images, but
215 # the glance setting is needed for booting
216 # directly from volume.
Dean Troyere9f76672014-07-25 11:09:36 -0500217 force_vm_mode="--property vm_mode=xen"
Bob Ballf1a2dbf2014-03-19 11:08:54 +0000218 fi
Steve Martinelli8d3ac2d2014-08-02 23:47:15 -0400219 openstack \
Victor Ryzhenkin878d7d82016-04-27 15:15:52 +0300220 --os-cloud=devstack-admin --os-region-name="$REGION_NAME" \
Steve Martinelli8d3ac2d2014-08-02 23:47:15 -0400221 image create \
222 "$image_name" --public \
Bob Ballf1a2dbf2014-03-19 11:08:54 +0000223 --container-format=ovf --disk-format=vhd \
Dean Troyere9f76672014-07-25 11:09:36 -0500224 $force_vm_mode < "${image}"
Davanum Srinivas316ed6c2013-02-06 15:29:49 -0500225 return
226 fi
227
Mate Lakatbc2ef922013-08-15 18:06:59 +0100228 # .xen-raw.tgz suggests a Xen capable raw image inside a tgz.
229 # and should not be decompressed prior to loading.
230 # Setting metadata, so PV mode is used.
231 if [[ "$image_url" =~ '.xen-raw.tgz' ]]; then
Dean Troyere9f76672014-07-25 11:09:36 -0500232 image_name="${image_fname%.xen-raw.tgz}"
Steve Martinelli8d3ac2d2014-08-02 23:47:15 -0400233 openstack \
Victor Ryzhenkin878d7d82016-04-27 15:15:52 +0300234 --os-cloud=devstack-admin --os-region-name="$REGION_NAME" \
Steve Martinelli8d3ac2d2014-08-02 23:47:15 -0400235 image create \
236 "$image_name" --public \
Mate Lakatbc2ef922013-08-15 18:06:59 +0100237 --container-format=tgz --disk-format=raw \
Dean Troyere9f76672014-07-25 11:09:36 -0500238 --property vm_mode=xen < "${image}"
Mate Lakatbc2ef922013-08-15 18:06:59 +0100239 return
240 fi
241
Maxim Nestratov54ee8a82015-07-15 11:47:11 +0300242 if [[ "$image_url" =~ '.hds' ]]; then
243 image_name="${image_fname%.hds}"
244 vm_mode=${image_name##*-}
245 if [[ $vm_mode != 'exe' && $vm_mode != 'hvm' ]]; then
246 die $LINENO "Unknown vm_mode=${vm_mode} for Virtuozzo image"
247 fi
248
249 openstack \
Victor Ryzhenkin878d7d82016-04-27 15:15:52 +0300250 --os-cloud=devstack-admin --os-region-name="$REGION_NAME" \
Maxim Nestratov54ee8a82015-07-15 11:47:11 +0300251 image create \
252 "$image_name" --public \
253 --container-format=bare --disk-format=ploop \
Maxim Nestratovd565d622016-07-11 22:33:39 +0300254 --property hypervisor_type=vz \
Maxim Nestratov54ee8a82015-07-15 11:47:11 +0300255 --property vm_mode=$vm_mode < "${image}"
256 return
257 fi
258
Dean Troyere9f76672014-07-25 11:09:36 -0500259 local kernel=""
260 local ramdisk=""
261 local disk_format=""
262 local container_format=""
263 local unpack=""
264 local img_property=""
265 case "$image_fname" in
Dean Troyerca0e3d02012-04-13 15:58:37 -0500266 *.tar.gz|*.tgz)
267 # Extract ami and aki files
Dean Troyere9f76672014-07-25 11:09:36 -0500268 [ "${image_fname%.tar.gz}" != "$image_fname" ] &&
269 image_name="${image_fname%.tar.gz}" ||
270 image_name="${image_fname%.tgz}"
271 local xdir="$FILES/images/$image_name"
Dean Troyerca0e3d02012-04-13 15:58:37 -0500272 rm -Rf "$xdir";
273 mkdir "$xdir"
Dean Troyere9f76672014-07-25 11:09:36 -0500274 tar -zxf $image -C "$xdir"
275 kernel=$(for f in "$xdir/"*-vmlinuz* "$xdir/"aki-*/image; do
Sean Dague537d4022013-10-22 07:43:22 -0400276 [ -f "$f" ] && echo "$f" && break; done; true)
Dean Troyere9f76672014-07-25 11:09:36 -0500277 ramdisk=$(for f in "$xdir/"*-initrd* "$xdir/"ari-*/image; do
Sean Dague537d4022013-10-22 07:43:22 -0400278 [ -f "$f" ] && echo "$f" && break; done; true)
Dean Troyere9f76672014-07-25 11:09:36 -0500279 image=$(for f in "$xdir/"*.img "$xdir/"ami-*/image; do
Sean Dague537d4022013-10-22 07:43:22 -0400280 [ -f "$f" ] && echo "$f" && break; done; true)
Dean Troyere9f76672014-07-25 11:09:36 -0500281 if [[ -z "$image_name" ]]; then
282 image_name=$(basename "$image" ".img")
Dean Troyerca0e3d02012-04-13 15:58:37 -0500283 fi
284 ;;
285 *.img)
Dean Troyere9f76672014-07-25 11:09:36 -0500286 image_name=$(basename "$image" ".img")
Ian Wienandada886d2015-10-07 14:06:26 +1100287 local format
288 format=$(qemu-img info ${image} | awk '/^file format/ { print $3; exit }')
Dean Troyer636a3ff2012-09-14 11:36:07 -0500289 if [[ ",qcow2,raw,vdi,vmdk,vpc," =~ ",$format," ]]; then
Dean Troyere9f76672014-07-25 11:09:36 -0500290 disk_format=$format
Dean Troyer636a3ff2012-09-14 11:36:07 -0500291 else
Dean Troyere9f76672014-07-25 11:09:36 -0500292 disk_format=raw
Dean Troyer636a3ff2012-09-14 11:36:07 -0500293 fi
Dean Troyere9f76672014-07-25 11:09:36 -0500294 container_format=bare
Dean Troyerca0e3d02012-04-13 15:58:37 -0500295 ;;
296 *.img.gz)
Dean Troyere9f76672014-07-25 11:09:36 -0500297 image_name=$(basename "$image" ".img.gz")
298 disk_format=raw
299 container_format=bare
300 unpack=zcat
Dean Troyerca0e3d02012-04-13 15:58:37 -0500301 ;;
Hongbin Lu3feceb02016-04-17 11:11:58 -0400302 *.img.bz2)
303 image_name=$(basename "$image" ".img.bz2")
304 disk_format=qcow2
305 container_format=bare
306 unpack=bunzip2
307 ;;
Dean Troyerca0e3d02012-04-13 15:58:37 -0500308 *.qcow2)
Dean Troyere9f76672014-07-25 11:09:36 -0500309 image_name=$(basename "$image" ".qcow2")
310 disk_format=qcow2
311 container_format=bare
Dean Troyerca0e3d02012-04-13 15:58:37 -0500312 ;;
Angel Noamf24e2992017-05-11 15:13:29 +0300313 *.raw)
314 image_name=$(basename "$image" ".raw")
315 disk_format=raw
316 container_format=bare
317 ;;
Jonathan Michalon06802042013-03-21 14:29:58 +0100318 *.iso)
Dean Troyere9f76672014-07-25 11:09:36 -0500319 image_name=$(basename "$image" ".iso")
320 disk_format=iso
321 container_format=bare
Jonathan Michalon06802042013-03-21 14:29:58 +0100322 ;;
Alessandro Pilottica823942014-08-07 02:05:26 +0300323 *.vhd|*.vhdx|*.vhd.gz|*.vhdx.gz)
324 local extension="${image_fname#*.}"
325 image_name=$(basename "$image" ".$extension")
326 disk_format=vhd
327 container_format=bare
328 if [ "${image_fname##*.}" == "gz" ]; then
329 unpack=zcat
330 fi
331 ;;
Dean Troyere9f76672014-07-25 11:09:36 -0500332 *) echo "Do not know what to do with $image_fname"; false;;
Dean Troyerca0e3d02012-04-13 15:58:37 -0500333 esac
334
Rafael Folco72f530f2016-02-09 07:08:38 -0600335 if is_arch "ppc64le" || is_arch "ppc64" || is_arch "ppc"; then
336 img_property="--property hw_disk_bus=scsi --property hw_scsi_model=virtio-scsi --property hw_cdrom_bus=scsi --property os_command_line=console=hvc0"
Rafael Folcoab775872013-12-02 14:04:32 -0200337 fi
338
Clark Laughlinfcc3f6e2015-04-07 16:31:47 +0000339 if is_arch "aarch64"; then
Kevin Zhaoa9cc38a2016-06-24 04:30:12 -0400340 img_property="--property hw_machine_type=virt --property hw_cdrom_bus=scsi --property hw_scsi_model=virtio-scsi --property os_command_line='console=ttyAMA0'"
Clark Laughlinfcc3f6e2015-04-07 16:31:47 +0000341 fi
342
Dean Troyere9f76672014-07-25 11:09:36 -0500343 if [ "$container_format" = "bare" ]; then
344 if [ "$unpack" = "zcat" ]; then
Victor Ryzhenkin878d7d82016-04-27 15:15:52 +0300345 openstack --os-cloud=devstack-admin --os-region-name="$REGION_NAME" image create "$image_name" $img_property --public --container-format=$container_format --disk-format $disk_format < <(zcat --force "${image}")
Hongbin Lu3feceb02016-04-17 11:11:58 -0400346 elif [ "$unpack" = "bunzip2" ]; then
347 openstack --os-cloud=devstack-admin --os-region-name="$REGION_NAME" image create "$image_name" $img_property --public --container-format=$container_format --disk-format $disk_format < <(bunzip2 -cdk "${image}")
Dean Troyerca0e3d02012-04-13 15:58:37 -0500348 else
Victor Ryzhenkin878d7d82016-04-27 15:15:52 +0300349 openstack --os-cloud=devstack-admin --os-region-name="$REGION_NAME" image create "$image_name" $img_property --public --container-format=$container_format --disk-format $disk_format < "${image}"
Dean Troyerca0e3d02012-04-13 15:58:37 -0500350 fi
351 else
352 # Use glance client to add the kernel the root filesystem.
353 # We parse the results of the first upload to get the glance ID of the
354 # kernel for use when uploading the root filesystem.
Dean Troyere9f76672014-07-25 11:09:36 -0500355 local kernel_id="" ramdisk_id="";
356 if [ -n "$kernel" ]; then
Victor Ryzhenkin878d7d82016-04-27 15:15:52 +0300357 kernel_id=$(openstack --os-cloud=devstack-admin --os-region-name="$REGION_NAME" image create "$image_name-kernel" $img_property --public --container-format aki --disk-format aki < "$kernel" | grep ' id ' | get_field 2)
Dean Troyerca0e3d02012-04-13 15:58:37 -0500358 fi
Dean Troyere9f76672014-07-25 11:09:36 -0500359 if [ -n "$ramdisk" ]; then
Victor Ryzhenkin878d7d82016-04-27 15:15:52 +0300360 ramdisk_id=$(openstack --os-cloud=devstack-admin --os-region-name="$REGION_NAME" image create "$image_name-ramdisk" $img_property --public --container-format ari --disk-format ari < "$ramdisk" | grep ' id ' | get_field 2)
Dean Troyerca0e3d02012-04-13 15:58:37 -0500361 fi
Victor Ryzhenkin878d7d82016-04-27 15:15:52 +0300362 openstack --os-cloud=devstack-admin --os-region-name="$REGION_NAME" image create "${image_name%.img}" $img_property --public --container-format ami --disk-format ami ${kernel_id:+--property kernel_id=$kernel_id} ${ramdisk_id:+--property ramdisk_id=$ramdisk_id} < "${image}"
Dean Troyerca0e3d02012-04-13 15:58:37 -0500363 fi
364}
365
Dean Troyer1a6d4492013-06-03 16:47:36 -0500366
Dean Troyerc1b486a2012-11-05 14:26:09 -0600367# Set the database backend to use
368# When called from stackrc/localrc DATABASE_BACKENDS has not been
369# initialized yet, just save the configuration selection and call back later
370# to validate it.
Adam Spierscb961592013-10-05 12:11:07 +0100371#
372# ``$1`` - the name of the database backend to use (mysql, postgresql, ...)
Dean Troyerc1b486a2012-11-05 14:26:09 -0600373function use_database {
374 if [[ -z "$DATABASE_BACKENDS" ]]; then
Dean Troyerafc29fe2013-02-07 15:56:24 -0600375 # No backends registered means this is likely called from ``localrc``
376 # This is now deprecated usage
Dean Troyerc1b486a2012-11-05 14:26:09 -0600377 DATABASE_TYPE=$1
Sean Dague72ad9422015-10-07 11:51:40 -0400378 deprecated "The database backend needs to be properly set in ENABLED_SERVICES; use_database is deprecated localrc"
Attila Fazekas251d3b52012-12-16 15:05:44 +0100379 else
Dean Troyerafc29fe2013-02-07 15:56:24 -0600380 # This should no longer get called...here for posterity
Attila Fazekas251d3b52012-12-16 15:05:44 +0100381 use_exclusive_service DATABASE_BACKENDS DATABASE_TYPE $1
Dean Troyerc1b486a2012-11-05 14:26:09 -0600382 fi
Dean Troyerc1b486a2012-11-05 14:26:09 -0600383}
384
sridhargaddamb5ab6462015-02-24 07:23:24 +0000385#Macro for curl statements. curl requires -g option for literal IPv6 addresses.
386CURL_GET="${CURL_GET:-curl -g}"
Dean Troyer1a6d4492013-06-03 16:47:36 -0500387
Dean Troyer3a3a2ba2012-12-11 15:26:24 -0600388# Wait for an HTTP server to start answering requests
389# wait_for_service timeout url
Rob Crittenden21e3d1e2016-05-06 12:35:22 -0400390#
391# If the service we want is behind a proxy, the proxy may be available
392# before the service. Compliant proxies will return a 503 in this case
393# Loop until we get something else.
394# Also check for the case where there is no proxy and the service just
395# hasn't started yet. curl returns 7 for Failed to connect to host.
Ian Wienandaee18c72014-02-21 15:35:08 +1100396function wait_for_service {
Dean Troyer3a3a2ba2012-12-11 15:26:24 -0600397 local timeout=$1
398 local url=$2
Rob Crittenden21e3d1e2016-05-06 12:35:22 -0400399 local rval=0
Atsushi SAKAI2ca8af42015-12-08 15:36:13 +0900400 time_start "wait_for_service"
Rob Crittenden21e3d1e2016-05-06 12:35:22 -0400401 timeout $timeout bash -x <<EOF || rval=$?
402 while [[ \$( ${CURL_GET} -k --noproxy '*' -s -o /dev/null -w '%{http_code}' ${url} ) == 503 || \$? -eq 7 ]]; do
403 sleep 1
404 done
405EOF
Atsushi SAKAI2ca8af42015-12-08 15:36:13 +0900406 time_stop "wait_for_service"
Rob Crittenden21e3d1e2016-05-06 12:35:22 -0400407 return $rval
Dean Troyer3a3a2ba2012-12-11 15:26:24 -0600408}
409
Dean Troyer1a6d4492013-06-03 16:47:36 -0500410
Nachi Uenofda946e2012-10-24 17:26:02 -0700411# ping check
Sean Dagueaf9bf862015-04-16 08:58:32 -0400412# Uses globals ``ENABLED_SERVICES``, ``TOP_DIR``, ``MULTI_HOST``, ``PRIVATE_NETWORK``
413# ping_check <ip> [boot-timeout] [from_net] [expected]
Ian Wienandaee18c72014-02-21 15:35:08 +1100414function ping_check {
Sean Dagueaf9bf862015-04-16 08:58:32 -0400415 local ip=$1
416 local timeout=${2:-30}
417 local from_net=${3:-""}
418 local expected=${4:-True}
419 local op="!"
420 local failmsg="[Fail] Couldn't ping server"
421 local ping_cmd="ping"
Nachi Uenofda946e2012-10-24 17:26:02 -0700422
Sean Dagueaf9bf862015-04-16 08:58:32 -0400423 # if we don't specify a from_net we're expecting things to work
424 # fine from our local box.
425 if [[ -n "$from_net" ]]; then
426 if is_service_enabled neutron; then
427 ping_cmd="$TOP_DIR/tools/ping_neutron.sh $from_net"
428 elif [[ "$MULTI_HOST" = "True" && "$from_net" = "$PRIVATE_NETWORK_NAME" ]]; then
429 # there is no way to address the multihost / private case, bail here for compatibility.
430 # TODO: remove this cruft and redo code to handle this at the caller level.
431 return
Nachi Ueno5db5bfa2012-10-29 11:25:29 -0700432 fi
Nachi Uenofda946e2012-10-24 17:26:02 -0700433 fi
Sean Dagueaf9bf862015-04-16 08:58:32 -0400434
435 # inverse the logic if we're testing no connectivity
436 if [[ "$expected" != "True" ]]; then
437 op=""
438 failmsg="[Fail] Could ping server"
439 fi
440
441 # Because we've transformed this command so many times, print it
442 # out at the end.
443 local check_command="while $op $ping_cmd -c1 -w1 $ip; do sleep 1; done"
444 echo "Checking connectivity with $check_command"
445
446 if ! timeout $timeout sh -c "$check_command"; then
447 die $LINENO $failmsg
448 fi
Nachi Uenofda946e2012-10-24 17:26:02 -0700449}
450
Nachi Ueno6769b162013-08-12 18:18:56 -0700451# Get ip of instance
Ian Wienandaee18c72014-02-21 15:35:08 +1100452function get_instance_ip {
Nachi Ueno6769b162013-08-12 18:18:56 -0700453 local vm_id=$1
454 local network_name=$2
Ian Wienand7ae97292016-02-16 14:50:53 +1100455 local nova_result
Ian Wienandada886d2015-10-07 14:06:26 +1100456 local ip
Ian Wienand7ae97292016-02-16 14:50:53 +1100457
458 nova_result="$(nova show $vm_id)"
Ian Wienandada886d2015-10-07 14:06:26 +1100459 ip=$(echo "$nova_result" | grep "$network_name" | get_field 2)
Nachi Ueno6769b162013-08-12 18:18:56 -0700460 if [[ $ip = "" ]];then
461 echo "$nova_result"
Atsushi SAKAI33c9a672015-11-12 19:50:00 +0900462 die $LINENO "[Fail] Couldn't get ipaddress of VM"
Nachi Ueno6769b162013-08-12 18:18:56 -0700463 fi
464 echo $ip
465}
Dean Troyer1a6d4492013-06-03 16:47:36 -0500466
Nachi Uenofda946e2012-10-24 17:26:02 -0700467# ssh check
Nachi Ueno5db5bfa2012-10-29 11:25:29 -0700468
Dean Troyer1a6d4492013-06-03 16:47:36 -0500469# ssh_check net-name key-file floating-ip default-user active-timeout
Ian Wienandaee18c72014-02-21 15:35:08 +1100470function ssh_check {
Mark McClainb05c8762013-07-06 23:29:39 -0400471 if is_service_enabled neutron; then
472 _ssh_check_neutron "$1" $2 $3 $4 $5
Nachi Ueno5db5bfa2012-10-29 11:25:29 -0700473 return
474 fi
475 _ssh_check_novanet "$1" $2 $3 $4 $5
476}
477
Ian Wienandaee18c72014-02-21 15:35:08 +1100478function _ssh_check_novanet {
Nachi Uenofda946e2012-10-24 17:26:02 -0700479 local NET_NAME=$1
480 local KEY_FILE=$2
481 local FLOATING_IP=$3
482 local DEFAULT_INSTANCE_USER=$4
483 local ACTIVE_TIMEOUT=$5
Dean Troyer6931c132012-11-07 16:51:21 -0600484 local probe_cmd=""
Dean Troyercc6b4432013-04-08 15:38:03 -0500485 if ! timeout $ACTIVE_TIMEOUT sh -c "while ! ssh -o StrictHostKeyChecking=no -i $KEY_FILE ${DEFAULT_INSTANCE_USER}@$FLOATING_IP echo success; do sleep 1; done"; then
Nachi Ueno07115eb2013-02-26 12:38:18 -0800486 die $LINENO "server didn't become ssh-able!"
Nachi Uenofda946e2012-10-24 17:26:02 -0700487 fi
488}
Dean Troyer13dc5cc2012-03-27 14:50:45 -0500489
Vincent Untz856a11e2012-11-21 16:04:12 +0100490
Vincent Untz856a11e2012-11-21 16:04:12 +0100491# Get the location of the $module-rootwrap executables, where module is cinder
492# or nova.
493# get_rootwrap_location module
Ian Wienandaee18c72014-02-21 15:35:08 +1100494function get_rootwrap_location {
Vincent Untz856a11e2012-11-21 16:04:12 +0100495 local module=$1
496
Jakub Ruzicka4196d552013-01-30 15:35:54 +0100497 echo "$(get_python_exec_prefix)/$module-rootwrap"
Vincent Untz856a11e2012-11-21 16:04:12 +0100498}
499
Dean Troyer1a6d4492013-06-03 16:47:36 -0500500
Ian Wienand0488edd2013-04-11 12:04:36 +1000501# Path permissions sanity check
502# check_path_perm_sanity path
Ian Wienandaee18c72014-02-21 15:35:08 +1100503function check_path_perm_sanity {
Ian Wienand0488edd2013-04-11 12:04:36 +1000504 # Ensure no element of the path has 0700 permissions, which is very
505 # likely to cause issues for daemons. Inspired by default 0700
506 # homedir permissions on RHEL and common practice of making DEST in
507 # the stack user's homedir.
508
Ian Wienandada886d2015-10-07 14:06:26 +1100509 local real_path
510 real_path=$(readlink -f $1)
Ian Wienand0488edd2013-04-11 12:04:36 +1000511 local rebuilt_path=""
512 for i in $(echo ${real_path} | tr "/" " "); do
513 rebuilt_path=$rebuilt_path"/"$i
514
515 if [[ $(stat -c '%a' ${rebuilt_path}) = 700 ]]; then
516 echo "*** DEST path element"
517 echo "*** ${rebuilt_path}"
518 echo "*** appears to have 0700 permissions."
Dean Troyerdc97cb72015-03-28 08:20:50 -0500519 echo "*** This is very likely to cause fatal issues for DevStack daemons."
Ian Wienand0488edd2013-04-11 12:04:36 +1000520
521 if [[ -n "$SKIP_PATH_SANITY" ]]; then
522 return
523 else
524 echo "*** Set SKIP_PATH_SANITY to skip this check"
525 die $LINENO "Invalid path permissions"
526 fi
527 fi
528 done
529}
530
Dean Troyer1a6d4492013-06-03 16:47:36 -0500531
Ian Wienand2ba36cd2015-11-12 13:52:36 +1100532# vercmp ver1 op ver2
533# Compare VER1 to VER2
534# - op is one of < <= == >= >
535# - returns true if satisified
536# e.g.
537# if vercmp 1.0 "<" 2.0; then
538# ...
539# fi
540function vercmp {
541 local v1=$1
542 local op=$2
543 local v2=$3
544 local result
545
546 # sort the two numbers with sort's "-V" argument. Based on if v2
547 # swapped places with v1, we can determine ordering.
548 result=$(echo -e "$v1\n$v2" | sort -V | head -1)
549
550 case $op in
551 "==")
552 [ "$v1" = "$v2" ]
553 return
554 ;;
555 ">")
556 [ "$v1" != "$v2" ] && [ "$result" = "$v2" ]
557 return
558 ;;
559 "<")
560 [ "$v1" != "$v2" ] && [ "$result" = "$v1" ]
561 return
562 ;;
563 ">=")
564 [ "$result" = "$v2" ]
565 return
566 ;;
567 "<=")
568 [ "$result" = "$v1" ]
569 return
570 ;;
571 *)
572 die $LINENO "unrecognised op: $op"
573 ;;
574 esac
575}
Kyle Mestery51a3f1f2013-06-13 11:47:56 +0000576
Sean Dague9751be62016-04-05 12:08:57 -0400577# This sets up defaults we like in devstack for logging for tracking
578# down issues, and makes sure everything is done the same between
579# projects.
580function setup_logging {
581 local conf_file=$1
582 local other_cond=${2:-"False"}
Sean Dague5edae542017-03-21 20:50:24 -0400583 if [[ "$USE_SYSTEMD" == "True" ]]; then
584 setup_systemd_logging $conf_file
585 elif [ "$LOG_COLOR" == "True" ] && [ "$SYSLOG" == "False" ] && [ "$other_cond" == "False" ]; then
Sean Dague9751be62016-04-05 12:08:57 -0400586 setup_colorized_logging $conf_file
587 else
588 setup_standard_logging_identity $conf_file
589 fi
590}
591
Salvatore Orlando05ae8332013-08-20 14:51:08 -0700592# This function sets log formatting options for colorizing log
593# output to stdout. It is meant to be called by lib modules.
594# The last two parameters are optional and can be used to specify
595# non-default value for project and user format variables.
596# Defaults are respectively 'project_name' and 'user_name'
597#
598# setup_colorized_logging something.conf SOMESECTION
Ian Wienandaee18c72014-02-21 15:35:08 +1100599function setup_colorized_logging {
Salvatore Orlando05ae8332013-08-20 14:51:08 -0700600 local conf_file=$1
Sean Dagueb6753ce2016-04-05 11:52:44 -0400601 local conf_section="DEFAULT"
602 local project_var="project_name"
603 local user_var="user_name"
Salvatore Orlando05ae8332013-08-20 14:51:08 -0700604 # Add color to logging output
Sean Dagueb6753ce2016-04-05 11:52:44 -0400605 iniset $conf_file $conf_section logging_context_format_string "%(asctime)s.%(msecs)03d %(color)s%(levelname)s %(name)s [%(request_id)s %("$project_var")s %("$user_var")s%(color)s] %(instance)s%(color)s%(message)s"
Salvatore Orlando05ae8332013-08-20 14:51:08 -0700606 iniset $conf_file $conf_section logging_default_format_string "%(asctime)s.%(msecs)03d %(color)s%(levelname)s %(name)s [-%(color)s] %(instance)s%(color)s%(message)s"
607 iniset $conf_file $conf_section logging_debug_format_suffix "from (pid=%(process)d) %(funcName)s %(pathname)s:%(lineno)d"
608 iniset $conf_file $conf_section logging_exception_prefix "%(color)s%(asctime)s.%(msecs)03d TRACE %(name)s %(instance)s"
609}
610
Sean Dague5edae542017-03-21 20:50:24 -0400611function setup_systemd_logging {
612 local conf_file=$1
613 local conf_section="DEFAULT"
Sean Dagueb2bfe562017-05-03 09:58:21 -0400614 # NOTE(sdague): this is a nice to have, and means we're using the
615 # native systemd path, which provides for things like search on
616 # request-id. However, there may be an eventlet interaction here,
617 # so going off for now.
618 USE_JOURNAL=$(trueorfalse USE_JOURNAL False)
Eric Fried8cd310d2017-05-16 13:52:03 -0500619 local pidstr=""
Sean Dagueb2bfe562017-05-03 09:58:21 -0400620 if [[ "$USE_JOURNAL" == "True" ]]; then
621 iniset $conf_file $conf_section use_journal "True"
622 # if we are using the journal directly, our process id is already correct
Sean Dagueb2bfe562017-05-03 09:58:21 -0400623 else
Eric Fried8cd310d2017-05-16 13:52:03 -0500624 pidstr="(pid=%(process)d) "
Sean Dagueb2bfe562017-05-03 09:58:21 -0400625 fi
Eric Fried8cd310d2017-05-16 13:52:03 -0500626 iniset $conf_file $conf_section logging_debug_format_suffix "{{${pidstr}%(funcName)s %(pathname)s:%(lineno)d}}"
Sean Dagueb2bfe562017-05-03 09:58:21 -0400627
Eric Fried8cd310d2017-05-16 13:52:03 -0500628 iniset $conf_file $conf_section logging_context_format_string "%(color)s%(levelname)s %(name)s [%(request_id)s %(project_name)s %(user_name)s%(color)s] %(instance)s%(color)s%(message)s"
629 iniset $conf_file $conf_section logging_default_format_string "%(color)s%(levelname)s %(name)s [-%(color)s] %(instance)s%(color)s%(message)s"
630 iniset $conf_file $conf_section logging_exception_prefix "ERROR %(name)s %(instance)s"
Sean Dague5edae542017-03-21 20:50:24 -0400631}
632
Sean Dague9751be62016-04-05 12:08:57 -0400633function setup_standard_logging_identity {
634 local conf_file=$1
635 iniset $conf_file DEFAULT logging_user_identity_format "%(project_name)s %(user_name)s"
636}
637
Ian Wienand54e39102014-06-03 16:05:12 +1000638# These functions are provided for basic fall-back functionality for
Dean Troyerdc97cb72015-03-28 08:20:50 -0500639# projects that include parts of DevStack (Grenade). stack.sh will
640# override these with more specific versions for DevStack (with fancy
Ian Wienand54e39102014-06-03 16:05:12 +1000641# spinners, etc). We never override an existing version
642if ! function_exists echo_summary; then
643 function echo_summary {
644 echo $@
645 }
646fi
647if ! function_exists echo_nolog; then
648 function echo_nolog {
649 echo $@
650 }
651fi
Dean Troyerdff49a22014-01-30 15:37:40 -0600652
Sébastien Han36f2f022014-01-06 18:09:26 +0100653
654# create_disk - Create backing disk
655function create_disk {
656 local node_number
657 local disk_image=${1}
658 local storage_data_dir=${2}
659 local loopback_disk_size=${3}
660
661 # Create a loopback disk and format it to XFS.
662 if [[ -e ${disk_image} ]]; then
663 if egrep -q ${storage_data_dir} /proc/mounts; then
664 sudo umount ${storage_data_dir}/drives/sdb1
665 sudo rm -f ${disk_image}
666 fi
667 fi
668
669 sudo mkdir -p ${storage_data_dir}/drives/images
670
671 sudo truncate -s ${loopback_disk_size} ${disk_image}
672
673 # Make a fresh XFS filesystem. Use bigger inodes so xattr can fit in
674 # a single inode. Keeping the default inode size (256) will result in multiple
675 # inodes being used to store xattr. Retrieving the xattr will be slower
676 # since we have to read multiple inodes. This statement is true for both
677 # Swift and Ceph.
678 sudo mkfs.xfs -f -i size=1024 ${disk_image}
679
680 # Mount the disk with mount options to make it as efficient as possible
681 if ! egrep -q ${storage_data_dir} /proc/mounts; then
682 sudo mount -t xfs -o loop,noatime,nodiratime,nobarrier,logbufs=8 \
683 ${disk_image} ${storage_data_dir}
684 fi
685}
686
Ihar Hrachyshka7b5c7dc2016-07-15 20:17:13 +0200687
688# set_mtu - Set MTU on a device
689function set_mtu {
690 local dev=$1
691 local mtu=$2
692 sudo ip link set mtu $mtu dev $dev
693}
694
695
Denis Buliga0bf75a42017-02-06 16:56:46 +0200696# running_in_container - Returns true otherwise false
697function running_in_container {
kesperd18d7c82017-03-23 05:52:33 +0000698 [[ $(systemd-detect-virt --container) != 'none' ]]
Denis Buliga0bf75a42017-02-06 16:56:46 +0200699}
700
701
Ihar Hrachyshkab3a210f2016-09-29 13:26:30 +0000702# enable_kernel_bridge_firewall - Enable kernel support for bridge firewalling
703function enable_kernel_bridge_firewall {
704 # Load bridge module. This module provides access to firewall for bridged
705 # frames; and also on older kernels (pre-3.18) it provides sysctl knobs to
706 # enable/disable bridge firewalling
707 sudo modprobe bridge
708 # For newer kernels (3.18+), those sysctl settings are split into a separate
709 # kernel module (br_netfilter). Load it too, if present.
710 sudo modprobe br_netfilter 2>> /dev/null || :
711 # Enable bridge firewalling in case it's disabled in kernel (upstream
712 # default is enabled, but some distributions may decide to change it).
713 # This is at least needed for RHEL 7.2 and earlier releases.
Ihar Hrachyshka3f771b72016-12-17 04:12:24 +0000714 for proto in ip ip6; do
Ihar Hrachyshkab3a210f2016-09-29 13:26:30 +0000715 sudo sysctl -w net.bridge.bridge-nf-call-${proto}tables=1
716 done
717}
718
719
Dan Smith1f55d382017-05-16 08:50:53 -0700720# Set a systemd system override
721#
722# This sets a system-side override in system.conf. A per-service
723# override would be /etc/systemd/system/${service}.service/override.conf
724function set_systemd_override {
725 local key="$1"
726 local value="$2"
727
728 local sysconf="/etc/systemd/system.conf"
729 iniset -sudo "${sysconf}" "Manager" "$key" "$value"
730 echo "Set systemd system override for ${key}=${value}"
731
732 sudo systemctl daemon-reload
733}
734
735
Dean Troyer27e32692012-03-16 16:16:56 -0500736# Restore xtrace
Ian Wienand523f4882015-10-13 11:03:03 +1100737$_XTRACE_FUNCTIONS
Dean Troyer4a43b7b2012-08-28 17:43:40 -0500738
Dean Troyer4a43b7b2012-08-28 17:43:40 -0500739# Local variables:
Sean Dague584d90e2013-03-29 14:34:53 -0400740# mode: shell-script
Andrew Laskif900bd72012-09-05 17:23:14 -0400741# End: