All new accounts created on Gitlab now require administrator approval. If you invite any collaborators, please let Flux staff know so they can approve the accounts.

setup-lib.sh 48.4 KB
Newer Older
1 2
#!/bin/sh

David Johnson's avatar
David Johnson committed
3 4
DIRNAME=`dirname $0`

5 6 7 8 9 10 11 12 13 14
#
# Setup our core vars
#
OURDIR=/root/setup
SETTINGS=$OURDIR/settings
LOCALSETTINGS=$OURDIR/settings.local
TOPOMAP=$OURDIR/topomap
BOOTDIR=/var/emulab/boot
TMCC=/usr/local/etc/emulab/tmcc

15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48
# Setup time logging stuff early
TIMELOGFILE=$OURDIR/setup-time.log
FIRSTTIME=0
if [ ! -f $OURDIR/setup-lib-first ]; then
    touch $OURDIR/setup-lib-first
    FIRSTTIME=`date +%s`
fi

logtstart() {
    area=$1
    varea=`echo $area | sed -e 's/[^a-zA-Z_0-9]/_/g'`
    stamp=`date +%s`
    date=`date`
    eval "LOGTIMESTART_$varea=$stamp"
    echo "START $area $stamp $date" >> $TIMELOGFILE
}

logtend() {
    area=$1
    #varea=${area//-/_}
    varea=`echo $area | sed -e 's/[^a-zA-Z_0-9]/_/g'`
    stamp=`date +%s`
    date=`date`
    eval "tss=\$LOGTIMESTART_$varea"
    tsres=`expr $stamp - $tss`
    resmin=`perl -e 'print '"$tsres"' / 60.0 . "\n"'`
    echo "END $area $stamp $date" >> $TIMELOGFILE
    echo "TOTAL $area $tsres $resmin" >> $TIMELOGFILE
}

if [ $FIRSTTIME -ne 0 ]; then
    logtstart "libfirsttime"
fi

49 50 51 52 53 54
mkdir -p $OURDIR
touch $SETTINGS
touch $LOCALSETTINGS
cd $OURDIR

#LOCKFILE="lockfile -1 -r -1 "
55
LOCKFILE="lockfile-create --retry 65535 "
56
RMLOCKFILE="lockfile-remove "
57
PSWDGEN="openssl rand -hex 10"
58 59
SSH="ssh -o StrictHostKeyChecking=no"
SCP="scp -p -o StrictHostKeyChecking=no"
60

61 62 63
#
# Our default configuration
#
64 65 66
CONTROLLER="ctl"
NETWORKMANAGER="nm"
STORAGEHOST="ctl"
67
SHAREHOST="ctl"
68
OBJECTHOST="ctl"
69
COMPUTENODES=""
70
BAREMETALNODES=""
71 72 73 74 75 76
BLOCKNODES=""
OBJECTNODES=""
DATALAN="lan-1"
MGMTLAN="lan-2"
BLOCKLAN=""
OBJECTLAN=""
77 78 79
DATATUNNELS=1
DATAFLATLANS="lan-1"
DATAVLANS=""
80
DATAVXLANS=0
81
DATAOTHERLANS=""
82
USE_EXISTING_IPS=1
83
DO_APT_INSTALL=1
84
DO_APT_UPGRADE=0
David Johnson's avatar
David Johnson committed
85
DO_APT_DIST_UPGRADE=0
86
DO_APT_UPDATE=1
87 88
UBUNTUMIRRORHOST=""
UBUNTUMIRRORPATH=""
David Johnson's avatar
David Johnson committed
89
ENABLE_NEW_SERIAL_SUPPORT=0
David Johnson's avatar
David Johnson committed
90
DO_UBUNTU_CLOUDARCHIVE=0
91
DO_UBUNTU_CLOUDARCHIVE_STAGING=0
92
BUILD_AARCH64_FROM_CORE=0
93
DISABLE_SECURITY_GROUPS=0
94
ENABLE_HOST_PASSTHROUGH=0
95
DEFAULT_SECGROUP_ENABLE_SSH_ICMP=1
96 97
VERBOSE_LOGGING="False"
DEBUG_LOGGING="False"
98
SUPPORT_DYNAMIC_NODES=0
99 100 101
KEYSTONEAPIVERSION=""
TOKENTIMEOUT=14400
SESSIONTIMEOUT=14400
102 103
GLANCE_LV_SIZE=32
SWIFT_LV_SIZE=4
104
CEILOMETER_USE_WSGI=0
105
QUOTASOFF=1
106 107
# Off by default; seems to cause intermittent keystone unavailability.
KEYSTONEUSEMEMCACHE=0
108 109
# Off by default for Juno; on for Kilo and on by default.
KEYSTONEUSEWSGI=""
110 111 112
# On by default; users will have to take full disk images of the
# compute nodes if they have this enabled.
COMPUTE_EXTRA_NOVA_DISK_SPACE="1"
113 114 115
# Support linuxbridge plugin too, but still default to openvswitch.
ML2PLUGIN="openvswitch"
MANILADRIVER="generic"
116
EXTRAIMAGEURLS=""
117
LINUXBRIDGE_STATIC=0
118 119 120 121 122
# If set to 1, and if OSRELEASE >= OSNEWTON, the physical machines will
# use the MGMTIP as the primary DNS server (in preference to the real
# control net DNS server).  The local domain will also be searched prior
# to the cluster's domain.
USE_DESIGNATE_AS_RESOLVER=1
123
# If set to 1, and if OSRELEASE >= OSNEWTON, then setup Neutron LBaaS.
124
USE_NEUTRON_LBAAS=1
125 126 127
# We are not currently using the ceilometer stats, and they do not work
# as of Pike due to the switch to Gnocchi as the measurement DB.
ENABLE_OPENSTACK_SLOTHD=0
David Johnson's avatar
David Johnson committed
128 129
# The input OpenStack release, if any, from profile params.
OSRELEASE=""
130 131 132 133 134
# If "", no resizing.  If set to number, that is GB.  Even if you
# specify MB, the MB will be stripped and assumed to be GB.  If set to
# 0, the max amount of space after removing swap and extra partitions
# will be used.
RESIZEROOT=""
135

136 137 138 139 140 141 142 143 144 145 146 147
#
# We have an 'adminapi' user that gets a random password.  Then, we have
# the dashboard and instance password, that comes in from geni-lib/rspec as a
# hash, that defaults to the same as the old default profile.
#
# /root/setup/admin-openrc.sh contains the adminapi user, not admin!  We do it
# this way because we need a real passwd so that various CLI tools and openstack
# components have a real user/pass to auth as.
#
ADMIN_API='adminapi'
ADMIN_API_PASS=`$PSWDGEN`
ADMIN='admin'
148 149 150
ADMIN_PASS=''
#ADMIN_PASS_HASH='$6$kOIVUcvsnrD/hETx$JahyKoIJf1EFNI2AWCtfzn3ZBoBfaJrRQkjC0kW6VkTwPI9K3TtEWTh/axrHP.e5mmcM96/bTQs1.e7HSKIk10'
ADMIN_PASS_HASH=''
151 152 153

SWAPPER=`cat $BOOTDIR/swapper`

154 155 156 157 158
##
## Are we updating?
##
if [ "x$UPDATING" = "x" ]; then
    UPDATING=0
159
elif [ ! $UPDATING -eq 0 ]; then
160 161 162 163 164 165 166
    $LOCKFILE $OURDIR/UPDATING
fi
# We might store any new nodes here
NEWNODELIST=""
# We might store any missing nodes here
OLDNODELIST=""

167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184
#
# Setup apt-get to not prompt us
#
if [ ! -e $OURDIR/apt-configured ]; then
    echo "force-confdef" > /etc/dpkg/dpkg.cfg.d/cloudlab
    echo "force-confold" >> /etc/dpkg/dpkg.cfg.d/cloudlab
    touch $OURDIR/apt-configured
fi
export DEBIAN_FRONTEND=noninteractive
# -o Dpkg::Options::="--force-confold" -o Dpkg::Options::="--force-confdef" 
DPKGOPTS=''
APTGETINSTALLOPTS='-y'
APTGETINSTALL="apt-get $DPKGOPTS install $APTGETINSTALLOPTS"
# Don't install/upgrade packages if this is not set
if [ ${DO_APT_INSTALL} -eq 0 ]; then
    APTGETINSTALL="/bin/true ${APTGETINSTALL}"
fi

185 186 187 188 189
##
## Detect if this was a geni experiment
##
grep GENIUSER $SETTINGS
if [ ! $? -eq 0 ]; then
190 191 192 193 194 195
    which python
    if [ ! $? -eq 0 ]; then
	# We need python to continue; install it.
	apt-get update
	apt-get $DPKGOPTS install $APTGETINSTALLOPTS python
    fi
196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212
    geni-get slice_urn >/dev/null 2>&1
    if [ $? -eq 0 ]; then
	GENIUSER=1
	echo "GENIUSER=1" >> $SETTINGS
    else
	GENIUSER=0
	echo "GENIUSER=0" >> $SETTINGS
    fi
else
    grep GENIUSER=1 $SETTINGS
    if [ $? -eq 0 ]; then
	GENIUSER=1
    else
	GENIUSER=0
    fi
fi

213 214 215 216
##
## Grab our geni creds, and create a GENI credential cert
##
#
David Johnson's avatar
David Johnson committed
217
# NB: force the install of python-cryptography if geniuser
218
#
219
if [ $GENIUSER -eq 1 ]; then
David Johnson's avatar
David Johnson committed
220
    dpkg -s python-cryptography >/dev/null 2>&1
221
    if [ ! $? -eq 0 ]; then
David Johnson's avatar
David Johnson committed
222
	apt-get $DPKGOPTS install $APTGETINSTALLOPTS python-cryptography
223 224 225 226 227
	# Keep trying again with updated cache forever;
	# we must have this package.
	success=$?
	while [ ! $success -eq 0 ]; do
	    apt-get update
David Johnson's avatar
David Johnson committed
228
	    apt-get $DPKGOPTS install $APTGETINSTALLOPTS python-cryptography
229 230
	    success=$?
	done
231 232 233 234
    fi

    if [ ! -e $OURDIR/geni.key ]; then
	geni-get key > $OURDIR/geni.key
235 236 237 238 239 240
	cat $OURDIR/geni.key | grep -q END\ .\*\PRIVATE\ KEY
	if [ $? -eq 0 ]; then
	    HAS_GENI_KEY=1
	else
	    HAS_GENI_KEY=0
	fi
241 242
    else
	HAS_GENI_KEY=1
243 244 245
    fi
    if [ ! -e $OURDIR/geni.certificate ]; then
	geni-get certificate > $OURDIR/geni.certificate
246 247 248 249 250 251
	cat $OURDIR/geni.certificate | grep -q END\ CERTIFICATE
	if [ $? -eq 0 ]; then
	    HAS_GENI_CERT=1
	else
	    HAS_GENI_CERT=0
	fi
252 253
    else
	HAS_GENI_CERT=1
254 255 256 257 258 259 260 261 262 263
    fi

    if [ ! -e /root/.ssl/encrypted.pem ]; then
	mkdir -p /root/.ssl
	chmod 600 /root/.ssl

	cat $OURDIR/geni.key > /root/.ssl/encrypted.pem
	cat $OURDIR/geni.certificate >> /root/.ssl/encrypted.pem
    fi

264
    if [ ! -e $OURDIR/manifests.xml -o $UPDATING -ne 0 ]; then
265 266 267 268 269 270 271
	if [ $HAS_GENI_CERT -eq 1 ]; then
	    python $DIRNAME/getmanifests.py $OURDIR/manifests
	else
	    # Fall back to geni-get
	    echo "WARNING: falling back to getting manifest from AM, not Portal -- multi-site experiments will not work fully!"
	    geni-get manifest > $OURDIR/manifests.0.xml
	fi
272
    fi
273 274 275 276 277

    if [ ! -e $OURDIR/encrypted_admin_pass ]; then
	cat /root/setup/manifests.0.xml | perl -e '@lines = <STDIN>; $all = join("",@lines); if ($all =~ /^.+<[^:]+:password[^>]*>([^<]+)<\/[^:]+:password>.+/igs) { print $1; }' > $OURDIR/encrypted_admin_pass
    fi

278
    if [ ! -e $OURDIR/decrypted_admin_pass -a -s $OURDIR/encrypted_admin_pass ]; then
279 280
	openssl smime -decrypt -inform PEM -inkey geni.key -in $OURDIR/encrypted_admin_pass -out $OURDIR/decrypted_admin_pass
    fi
281 282
fi

283 284 285 286 287
#
# Suck in user configuration overrides, if we haven't already
#
if [ ! -e $OURDIR/parameters ]; then
    touch $OURDIR/parameters
288
    if [ $GENIUSER -eq 1 ]; then
289
	cat $OURDIR/manifests.0.xml | sed -n -e 's/^[^<]*<[^:]*:parameter>\([^<]*\)<\/[^:]*:parameter>/\1/p' > $OURDIR/parameters
290 291 292
    fi
fi
. $OURDIR/parameters
293

294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319
#
# Ok, to be absolutely safe, if the ADMIN_PASS_HASH we got from params was "",
# and if admin pass wasn't sent as an encrypted string to us, we have we have
# to generate a random admin pass and hash it.
#
if [ "x${ADMIN_PASS_HASH}" = "x" ] ; then
    DEC_ADMIN_PASS=`cat $OURDIR/decrypted_admin_pass`
    if [ "x${DEC_ADMIN_PASS}" = "x" ]; then
	ADMIN_PASS=`$PSWDGEN`
	ADMIN_PASS_HASH="`echo \"${ADMIN_PASS}\" | openssl passwd -1 -stdin`"

	# Save it off so we can email the user -- because nobody has the
	# random pass we just generated!
	echo "${ADMIN_PASS}" > $OURDIR/random_admin_pass
    else
	ADMIN_PASS="${DEC_ADMIN_PASS}"
	ADMIN_PASS_HASH="`echo \"${ADMIN_PASS}\" | openssl passwd -1 -stdin`"
    fi

    #
    # Overwrite the params.
    #
    echo "ADMIN_PASS='${ADMIN_PASS}'" >> $OURDIR/parameters
    echo "ADMIN_PASS_HASH='${ADMIN_PASS_HASH}'" >> $OURDIR/parameters
fi

320 321 322 323 324 325 326 327 328 329
CREATOR=`cat $BOOTDIR/creator`
SWAPPER=`cat $BOOTDIR/swapper`
NODEID=`cat $BOOTDIR/nickname | cut -d . -f 1`
PNODEID=`cat $BOOTDIR/nodeid`
EEID=`cat $BOOTDIR/nickname | cut -d . -f 2`
EPID=`cat $BOOTDIR/nickname | cut -d . -f 3`
OURDOMAIN=`cat $BOOTDIR/mydomain`
NFQDN="`cat $BOOTDIR/nickname`.$OURDOMAIN"
PFQDN="`cat $BOOTDIR/nodeid`.$OURDOMAIN"
MYIP=`cat $BOOTDIR/myip`
330
EXTERNAL_NETWORK_INTERFACE=`cat $BOOTDIR/controlif`
David Johnson's avatar
David Johnson committed
331
HOSTNAME=`cat ${BOOTDIR}/nickname | cut -f1 -d.`
332
ARCH=`uname -m`
333

David Johnson's avatar
David Johnson committed
334 335 336 337
# Check if our init is systemd
dpkg-query -S /sbin/init | grep -q systemd
HAVE_SYSTEMD=`expr $? = 0`

338 339 340 341 342 343
#
# Figure out which OS/OpenStack this is.
#
OSJUNO=10
OSKILO=11
OSLIBERTY=12
344
OSMITAKA=13
David Johnson's avatar
David Johnson committed
345
OSNEWTON=14
346
OSOCATA=15
David Johnson's avatar
David Johnson committed
347
OSPIKE=16
David Johnson's avatar
David Johnson committed
348
OSQUEENS=17
David Johnson's avatar
David Johnson committed
349
OSROCKY=18
David Johnson's avatar
David Johnson committed
350
OSSTEIN=19
351

David Johnson's avatar
David Johnson committed
352
. /etc/lsb-release
David Johnson's avatar
David Johnson committed
353 354 355 356 357 358 359 360 361 362
#
# Allow a specific release to trump the image defaults, maybe.
#
if [ ! "x$OSRELEASE" = "x" ]; then
    OSCODENAME="$OSRELEASE"
    if [ $OSCODENAME = "juno" ]; then OSVERSION=$OSJUNO ; fi
    if [ $OSCODENAME = "kilo" ]; then OSVERSION=$OSKILO ; fi
    if [ $OSCODENAME = "liberty" ]; then OSVERSION=$OSLIBERTY ; fi
    if [ $OSCODENAME = "mitaka" ]; then OSVERSION=$OSMITAKA ; fi
    if [ $OSCODENAME = "newton" ]; then OSVERSION=$OSNEWTON ; fi
363
    if [ $OSCODENAME = "ocata" ]; then OSVERSION=$OSOCATA ; fi
David Johnson's avatar
David Johnson committed
364
    if [ $OSCODENAME = "pike" ]; then OSVERSION=$OSPIKE ; fi
David Johnson's avatar
David Johnson committed
365
    if [ $OSCODENAME = "queens" ]; then OSVERSION=$OSQUEENS ; fi
David Johnson's avatar
David Johnson committed
366
    if [ $OSCODENAME = "rocky" ]; then OSVERSION=$OSROCKY ; fi
David Johnson's avatar
David Johnson committed
367
    if [ $OSCODENAME = "stein" ]; then OSVERSION=$OSSTEIN ; fi
David Johnson's avatar
David Johnson committed
368 369 370 371 372 373 374 375 376

    #
    # We only use cloudarchive for LTS images!
    #
    echo "$DISTRIB_DESCRIPTION" | grep -qi LTS
    if [ $? -eq 0 ]; then
	DO_UBUNTU_CLOUDARCHIVE=1
    fi
elif [ ${DISTRIB_CODENAME} = "wily" ]; then
377 378 379
    OSCODENAME="liberty"
    OSVERSION=$OSLIBERTY
elif [ ${DISTRIB_CODENAME} = "vivid" ]; then
David Johnson's avatar
David Johnson committed
380
    OSCODENAME="kilo"
381
    OSVERSION=$OSKILO
382 383 384
elif [ ${DISTRIB_CODENAME} = "xenial" ]; then
    OSCODENAME="mitaka"
    OSVERSION=$OSMITAKA
David Johnson's avatar
David Johnson committed
385 386
else
    OSCODENAME="juno"
387
    OSVERSION=$OSJUNO
David Johnson's avatar
David Johnson committed
388
fi
389
DISTRIB_MAJOR=`echo $DISTRIB_RELEASE | cut -d. -f1`
David Johnson's avatar
David Johnson committed
390

391 392 393 394 395 396 397
#
# Default memcached fully on for Mitaka or greater.  Too slow without it.
#
if [ $OSVERSION -ge $OSMITAKA ]; then
    KEYSTONEUSEMEMCACHE=1
fi

David Johnson's avatar
David Johnson committed
398
if [ $OSVERSION -eq $OSJUNO ]; then
399
    REGION="regionOne"
David Johnson's avatar
David Johnson committed
400 401
else
    REGION="RegionOne"
David Johnson's avatar
David Johnson committed
402 403
fi

404 405 406 407 408 409 410 411
#
# Stop using auth_uri in favor of www_authenticate_uri at Stein.
#
AUTH_URI_KEY="auth_uri"
if [ $OSVERSION -ge $OSSTEIN ]; then
    AUTH_URI_KEY="www_authenticate_uri"
fi

412 413 414 415 416
#
# We started using Python 3 packages at Stein.
#
PYPKGPREFIX="python"
ISPYTHON3=0
417
PYTHONBINNAME="python"
418 419 420
if [ $OSVERSION -ge $OSSTEIN ]; then
    PYPKGPREFIX="python3"
    ISPYTHON3=1
421
    PYTHONBINNAME="python3"
422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443

    #
    # If our openstack python libs will be python3, we also need
    # python3-cryptography for setup-user-info.py, because that file
    # must be run by whatever python version contains the novaclient
    # library.  And we don't know that we need that until here, unlike
    # above where we install the v2 python-cryptography.
    #
    if [ $GENIUSER -eq 1 ]; then
	dpkg -s python-cryptography >/dev/null 2>&1
	if [ ! $? -eq 0 ]; then
	    apt-get $DPKGOPTS install $APTGETINSTALLOPTS ${PYTHONBINNAME}-cryptography
	    # Keep trying again with updated cache forever;
	    # we must have this package.
	    success=$?
	    while [ ! $success -eq 0 ]; do
		apt-get update
		apt-get $DPKGOPTS install $APTGETINSTALLOPTS ${PYTHONBINNAME}-cryptography
		success=$?
	    done
	fi
    fi
444 445
fi

446 447 448 449 450
#
# See which keystone port has the admin capabilities.  This changed in
# Queens to fully drop 35357 because it's now irrelevant and not
# configured by default.
#
451
if [ $OSVERSION -ge $OSQUEENS ]; then
452 453 454 455 456
    KADMINPORT=5000
else
    KADMINPORT=35357
fi

457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474
#
# Figure out if we got told to use keystone v2 or v3, or what our
# default should be if not.
#
if [ "x$KEYSTONEAPIVERSION" = "x3" ]; then
    # Let them force v3.
    KAPISTR='v3'
elif [ "$KEYSTONEAPIVERSION" != "2" -a $OSVERSION -ge $OSLIBERTY ]; then
    # If they didn't force v2 or v3, if we're on Liberty or higher, make
    # v3 the default
    KAPISTR='v3'
    KEYSTONEAPIVERSION=3
else
    # Otherwise, use version 2 by default (or choice)
    KEYSTONEAPIVERSION=2
    KAPISTR='v2.0'
fi

David Johnson's avatar
David Johnson committed
475 476 477 478
#
# Figure out Nova API string.
#
NAPISTR="v2"
479
if [ $OSVERSION -ge $OSMITAKA ]; then
David Johnson's avatar
David Johnson committed
480 481 482
    NAPISTR="v2.1"
fi

483 484 485 486 487 488 489 490 491 492 493 494
#
# Figure out if we got told to use keystone wsgi or not, or what our
# default should be if not.
#
if [ "x$KEYSTONEUSEWSGI" = "x" -a $OSVERSION -ge $OSKILO ]; then
    KEYSTONEUSEWSGI=1
elif [ "x$KEYSTONEUSEWSGI" = "x1" ]; then
    # Let them force WSGI
    KEYSTONEUSEWSGI=1
else
    KEYSTONEUSEWSGI=0
fi
495

496 497 498 499 500 501 502 503 504 505 506 507 508 509 510
#
# The keystone auth_token parameter names are project_domain_name and
# user_domain_name as of Mitaka.  The auth_token parameter name has
# also changed.
#
if [ $OSVERSION -ge $OSMITAKA ]; then
    PROJECT_DOMAIN_PARAM="project_domain_name"
    USER_DOMAIN_PARAM="user_domain_name"
    AUTH_TYPE_PARAM="auth_type"
else
    PROJECT_DOMAIN_PARAM="project_domain_id"
    USER_DOMAIN_PARAM="user_domain_id"
    AUTH_TYPE_PARAM="auth_plugin"
fi

511 512 513 514 515 516 517 518 519 520
#
# Set the database package name and driver string.
#
if [ $OSVERSION -ge $OSNEWTON ]; then
    DBDPACKAGE="python-pymysql"
    DBDSTRING="mysql+pymysql"
else
    DBDPACKAGE="python-mysqldb"
    DBDSTRING="mysql"
fi
521

522
if [ $GENIUSER -eq 1 ]; then
David Johnson's avatar
David Johnson committed
523
    SWAPPER_EMAIL=`geni-get slice_email`
524 525 526 527
else
    SWAPPER_EMAIL="$SWAPPER@$OURDOMAIN"
fi

528
if [ $GENIUSER -eq 1 ]; then
529
    PUBLICADDRS=`cat $OURDIR/manifests.*.xml | perl -e '$found = 0; while (<STDIN>) { if ($_ =~ /\<[\d\w:]*routable_pool [^\>\<]*\/>/) { print STDERR "DEBUG: found empty pool: $_\n"; next; } if ($_ =~ /\<[\d\w:]*routable_pool [^\>]*client_id=['"'"'"]'$NETWORKMANAGER'['"'"'"]/) { $found = 1; print STDERR "DEBUG: found: $_\n" } if ($found) { while ($_ =~ m/\<emulab:ipv4 address="([\d.]+)\" netmask=\"([\d\.]+)\"/g) { print "$1\n"; } } if ($found && $_ =~ /routable_pool\>/) { print STDERR "DEBUG: end found: $_\n"; $found = 0; } }' | xargs`
530 531 532 533 534 535 536
    PUBLICCOUNT=0
    for ip in $PUBLICADDRS ; do
	PUBLICCOUNT=`expr $PUBLICCOUNT + 1`
    done
else
    PUBLICADDRS=""
    PUBLICCOUNT=0
David Johnson's avatar
David Johnson committed
537 538
fi

539 540
#
# Grab our topomap so we can see how many nodes we have.
David Johnson's avatar
David Johnson committed
541
# NB: only safe to use topomap for non-fqdn things.
542
#
543 544 545 546
if [ ! -f $TOPOMAP -o $UPDATING -ne 0 ]; then
    if [ -f $TOPOMAP ]; then
	cp -p $TOPOMAP $TOPOMAP.old
    fi
547 548 549 550 551 552 553 554 555 556

    # First try via manifest; fall back to tmcc if necessary (although
    # that will break multisite exps with >1 second cluster node(s)).
    python2 $DIRNAME/manifest-to-topomap.py $OURDIR/manifests.0.xml > $TOPOMAP
    if [ ! $? -eq 0 ]; then
	echo "ERROR: could not extract topomap from manifest; aborting to tmcc"
	rm -f $TOPOMAP
	$TMCC topomap | gunzip > $TOPOMAP
    fi

557 558 559 560 561
    # Filter out blockstore nodes
    cat $TOPOMAP | grep -v '^bsnode,' > $TOPOMAP.no.bsnode
    mv $TOPOMAP.no.bsnode $TOPOMAP
    cat $TOPOMAP | grep -v '^bslink,' > $TOPOMAP.no.bslink
    mv $TOPOMAP.no.bslink $TOPOMAP
562 563 564 565 566 567 568 569 570 571 572
    if [ -f $TOPOMAP.old ]; then
	diff -u $TOPOMAP.old $TOPOMAP > $TOPOMAP.diff
	#
	# NB: this does assume that nodes either leave all the lans, or join
	# all the lans.  We don't try to distinguish anything else.
	#
	NEWNODELIST=`cat topomap.diff | sed -n -e 's/^\+\([a-zA-Z0-9\-]*\),.*:.*$/\1/p' | uniq | xargs`
	OLDNODELIST=`cat topomap.diff | sed -n -e 's/^\-\([a-zA-Z0-9\-]*\),.*:.*$/\1/p' | uniq | xargs`

	# Just remove the fqdn map and let it be recalculated below
	rm -f $OURDIR/fqdn.map
573
	rm -f $OURDIR/fqdn.physical.map
574
    fi
575
fi
576 577

#
578 579 580
# Since some of our testbeds only have one experiment interface per node,
# just do this little hack job -- if MGMTLAN was specified, but it's not in
# the topomap, we null it out and use the VPN Management setup instead.
581
#
582 583 584 585 586 587 588
if [ ! -z "$MGMTLAN" ] ; then
    cat $TOPOMAP | grep "$MGMTLAN"
    if [ $? -ne 0 ] ; then
	echo "*** Cannot find Management LAN $MGMTLAN ; falling back to VPN!"
	MGMTLAN=""
    fi
fi
589

David Johnson's avatar
David Johnson committed
590
#
591 592
# Create a map of node nickname to FQDN (and another one of pnode id to FQDN).
# This supports geni multi-site experiments.
David Johnson's avatar
David Johnson committed
593
#
594 595 596 597 598 599
if [ \( -s $OURDIR/manifests.xml \) -a \( ! \( -s $OURDIR/fqdn.map \) \) ]; then
    cat manifests.xml | tr -d '\n' | sed -e 's/<node /\n<node /g'  | sed -n -e "s/^<node [^>]*client_id=['\"]*\([^'\"]*\)['\"].*<host name=['\"]\([^'\"]*\)['\"].*$/\1\t\2/p" > $OURDIR/fqdn.map
    # Add a newline if we wrote anything.
    if [ -s $OURDIR/fqdn.map ]; then
	echo '' >> $OURDIR/fqdn.map
    fi
600 601 602 603 604 605 606 607 608 609 610 611
    # Filter out any blockstore nodes
    # XXX: this strategy doesn't work, because only the NM node makes
    # the fqdn.map file.  So, just look for bsnode for now.
    #BSNODES=`cat /var/emulab/boot/tmcc/storageconfig | sed -n -e 's/^.* HOSTID=\([^ \t]*\) .*$/\1/p' | xargs`
    #for bs in $BSNODES ; do
    #	cat $OURDIR/fqdn.map | grep -v "^${bs}"$'\t' > $OURDIR/fqdn.map.tmp
    #	mv $OURDIR/fqdn.map.tmp $OURDIR/fqdn.map
    #done
    # XXX: why doesn't the tab grep work here, sigh...
    #cat $OURDIR/fqdn.map | grep -v '^bsnode'$'\t' > $OURDIR/fqdn.map.tmp
    cat $OURDIR/fqdn.map | grep -v '^bsnode' > $OURDIR/fqdn.map.tmp
    mv $OURDIR/fqdn.map.tmp $OURDIR/fqdn.map
612 613 614 615
    cat $OURDIR/fqdn.map | grep -v '^fw[ \t]*' > $OURDIR/fqdn.map.tmp
    mv $OURDIR/fqdn.map.tmp $OURDIR/fqdn.map
    cat $OURDIR/fqdn.map | grep -v '^fw-s2[ \t]*' > $OURDIR/fqdn.map.tmp
    mv $OURDIR/fqdn.map.tmp $OURDIR/fqdn.map
616 617 618 619 620 621 622

    cat manifests.xml | tr -d '\n' | sed -e 's/<node /\n<node /g'  | sed -n -e "s/^<node [^>]*component_id=['\"]*[a-zA-Z0-9:\+\.]*node+\([^'\"]*\)['\"].*<host name=['\"]\([^'\"]*\)['\"].*$/\1\t\2/p" > $OURDIR/fqdn.physical.map
    # Add a newline if we wrote anything.
    if [ -s $OURDIR/fqdn.physical.map ]; then
	echo '' >> $OURDIR/fqdn.physical.map
    fi
    # Filter out any blockstore nodes
623 624 625 626 627 628
    cat $OURDIR/fqdn.physical.map | grep -v '[ \t]bsnode\.' > $OURDIR/fqdn.physical.map.tmp
    mv $OURDIR/fqdn.physical.map.tmp $OURDIR/fqdn.physical.map
    # Filter out any firewall nodes
    cat $OURDIR/fqdn.physical.map | grep -v '[ \t]*fw\.' > $OURDIR/fqdn.physical.map.tmp
    mv $OURDIR/fqdn.physical.map.tmp $OURDIR/fqdn.physical.map
    cat $OURDIR/fqdn.physical.map | grep -v '[ \t]*fw-s2\.' > $OURDIR/fqdn.physical.map.tmp
629
    mv $OURDIR/fqdn.physical.map.tmp $OURDIR/fqdn.physical.map
David Johnson's avatar
David Johnson committed
630 631 632 633 634 635
fi

#
# Setup the fqdn map the non-geni way if necessary!
#
if [ ! -s $OURDIR/fqdn.map ]; then
636
    TNODES=`cat $TOPOMAP | grep -v '^#' | sed -n -e 's/^\([a-zA-Z0-9\-]*\),.*:.*$/\1/p' | xargs`
David Johnson's avatar
David Johnson committed
637
    FQDNS=""
638 639 640 641 642 643 644
    NODES=""
    for n in $TNODES ; do
	# Filter out any blockstore nodes
	grep -q "HOSTID=$n " /var/emulab/boot/tmcc/storageconfig
	if [ $? -eq 0 ] ; then
	    continue
	fi
645 646 647 648 649
	# Filter out any firewall nodes
	if [ "$n" = "fw" -o "$n" = "fw-s2" ]; then
	    continue
	fi

David Johnson's avatar
David Johnson committed
650 651
	fqdn="$n.$EEID.$EPID.$OURDOMAIN"
	FQDNS="${FQDNS} $fqdn"
652
	NODES="${NODES} $n"
David Johnson's avatar
David Johnson committed
653 654 655 656 657 658 659 660 661 662 663 664 665

	/bin/echo -e "$n\t$fqdn" >> $OURDIR/fqdn.map
    done
fi

#
# Grab our list of short-name and FQDN nodes.  One way or the other, we have
# an fqdn map.  First we tried the GENI way; then the old Emulab way with
# topomap.
#
NODES=`cat $OURDIR/fqdn.map | cut -f1 | xargs`
FQDNS=`cat $OURDIR/fqdn.map | cut -f2 | xargs`

666
if [ -z "${COMPUTENODES}" ]; then
667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685
    # Figure out which networkmanager (netmgr) and controller (ctrl) names we have
    for node in $NODES
    do
	if [ "$node" = "networkmanager" ]; then
	    NETWORKMANAGER="networkmanager"
	fi
	if [ "$node" = "controller" ]; then
	    # If we were using the controller as storage and object host, then
	    # keep using it (just use the old name we've detected).
	    if [ "$STORAGEHOST" = "$CONTROLLER" ]; then
		STORAGEHOST="controller"
	    fi
	    if [ "$OBJECTHOST" = "$CONTROLLER" ]; then
		OBJECTHOST="controller"
	    fi
	    CONTROLLER="controller"
	fi
    done
    # Figure out which ones are the compute nodes
686 687 688 689 690 691 692 693
    for node in $NODES
    do
	if [ "$node" != "$CONTROLLER" -a "$node" != "$NETWORKMANAGER" \
	     -a "$node" != "$STORAGEHOST" -a "$node" != "$OBJECTHOST" ]; then
	    COMPUTENODES="$COMPUTENODES $node"
	fi
    done
fi
694

695 696 697 698
OTHERNODES=""
for node in $NODES
do
    [ "$node" = "$NODEID" ] && continue
699

700 701
    OTHERNODES="$OTHERNODES $node"
done
702

703 704 705 706 707 708 709 710
# Save the node stuff off to settings
grep CONTROLLER $SETTINGS
if [ ! $? = 0 ]; then
    echo "CONTROLLER=\"${CONTROLLER}\"" >> $SETTINGS
    echo "NETWORKMANAGER=\"${NETWORKMANAGER}\"" >> $SETTINGS
    echo "STORAGEHOST=\"${STORAGEHOST}\"" >> $SETTINGS
    echo "OBJECTHOST=\"${OBJECTHOST}\"" >> $SETTINGS
    echo "COMPUTENODES=\"${COMPUTENODES}\"" >> $SETTINGS
711 712 713 714 715 716
elif [ $UPDATING -ne 0 ]; then
    sed -i -e "s/^\(CONTROLLER=\"[^\"]*\"\)\$/CONTROLLER=\"$CONTROLLER\"/" $SETTINGS
    sed -i -e "s/^\(NETWORKMANAGER=\"[^\"]*\"\)\$/NETWORKMANAGER=\"$NETWORKMANAGER\"/" $SETTINGS
    sed -i -e "s/^\(STORAGEHOST=\"[^\"]*\"\)\$/STORAGEHOST=\"$STORAGEHOST\"/" $SETTINGS
    sed -i -e "s/^\(OBJECTHOST=\"[^\"]*\"\)\$/OBJECTHOST=\"$OBJECTHOST\"/" $SETTINGS
    sed -i -e "s/^\(COMPUTENODES=\"[^\"]*\"\)\$/COMPUTENODES=\"$COMPUTENODES\"/" $SETTINGS
717 718
fi

719 720 721 722 723 724 725 726 727 728 729
#
# 0 (true) if networkmanager node is also the controller; 1 if not.
#
unified() {
    if [ "$NETWORKMANAGER" = "$CONTROLLER" ]; then
	return 0
    else
	return 1
    fi
}

730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750
##
## Setup our Ubuntu package mirror, if necessary.
##
grep MIRRORSETUP $SETTINGS
if [ ! $? -eq 0 ]; then
    if [ ! "x${UBUNTUMIRRORHOST}" = "x" ]; then
	oldstr='us.archive.ubuntu.com'
	newstr="${UBUNTUMIRRORHOST}"

	if [ ! "x${UBUNTUMIRRORPATH}" = "x" ]; then
	    oldstr='us.archive.ubuntu.com/ubuntu'
	    newstr="${UBUNTUMIRRORHOST}/${UBUNTUMIRRORPATH}"
	fi

	echo "*** Changing Ubuntu mirror from $oldstr to $newstr ..."
	sed -E -i.us.archive.ubuntu.com -e "s|(${oldstr})|$newstr|" /etc/apt/sources.list
    fi

    echo "MIRRORSETUP=1" >> $SETTINGS
fi

751
if [ ! -f $OURDIR/apt-updated -a "${DO_APT_UPDATE}" = "1" ]; then
752 753 754 755 756 757 758 759
    #
    # Attempt to handle old EOL releases; so far only need to handle utopic
    #
    . /etc/lsb-release
    grep -q old-releases /etc/apt/sources.list
    if [  $? != 0 -a "x${DISTRIB_CODENAME}" = "xutopic" ]; then
	sed -i -re 's/([a-z]{2}\.)?archive.ubuntu.com|security.ubuntu.com/old-releases.ubuntu.com/g' /etc/apt/sources.list
    fi
760 761 762
    apt-get update
    touch $OURDIR/apt-updated
fi
763

764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804
are_packages_installed() {
    retval=1
    while [ ! -z "$1" ] ; do
	dpkg -s "$1" >/dev/null 2>&1
	if [ ! $? -eq 0 ] ; then
	    retval=0
	fi
	shift
    done
    return $retval
}

maybe_install_packages() {
    if [ ! ${DO_APT_UPGRADE} -eq 0 ] ; then
        # Just do an install/upgrade to make sure the package(s) are installed
	# and upgraded; we want to try to upgrade the package.
	$APTGETINSTALL $@
	return $?
    else
	# Ok, check if the package is installed; if it is, don't install.
	# Otherwise, install (and maybe upgrade, due to dependency side effects).
	# Also, optimize so that we try to install or not install all the
	# packages at once if none are installed.
	are_packages_installed $@
	if [ $? -eq 1 ]; then
	    return 0
	fi

	retval=0
	while [ ! -z "$1" ] ; do
	    are_packages_installed $1
	    if [ $? -eq 0 ]; then
		$APTGETINSTALL $1
		retval=`expr $retval \| $?`
	    fi
	    shift
	done
	return $retval
    fi
}

David Johnson's avatar
David Johnson committed
805 806 807 808 809 810 811 812 813 814
if [ ! -f $OURDIR/cloudarchive-added -a "${DO_UBUNTU_CLOUDARCHIVE}" = "1" ]; then
    #if [ "${DISTRIB_CODENAME}" = "trusty" ] ; then
    #	$APTGETINSTALL install -y ubuntu-cloud-keyring
    #	echo "deb http://ubuntu-cloud.archive.canonical.com/ubuntu" "${DISTRIB_CODENAME}-updates/${OSCODENAME} main" > /etc/apt/sources.list.d/cloudarchive-${OSCODENAME}.list
    #	apt-get update
    #elif [ "${DISTRIB_CODENAME}" = "xenial" ] ; then
	maybe_install_packages software-properties-common
	# Disable unattended upgrades!
	rm -fv /etc/apt/apt.conf.d/*unattended-upgrades
	add-apt-repository -y cloud-archive:$OSRELEASE
815
	if [ "${DO_UBUNTU_CLOUDARCHIVE_STAGING}" = "1" ]; then
816
	    add-apt-repository -y cloud-archive:${OSRELEASE}-proposed
817
	fi
818
	apt-get update
David Johnson's avatar
David Johnson committed
819
    #fi
820 821 822 823

    touch $OURDIR/cloudarchive-added
fi

David Johnson's avatar
David Johnson committed
824 825 826 827 828 829 830 831 832 833 834 835 836 837
if [ ! -f $OURDIR/apt-dist-upgraded -a "${DO_APT_DIST_UPGRADE}" = "1" ]; then
    # First, mark grub packages not to be upgraded; we don't want an
    # install going to the wrong place.
    PKGS="grub-common grub-gfxpayload-lists grub-pc grub-pc-bin grub2-common"
    for pkg in $PKGS; do
	apt-mark hold $pkg
    done
    apt-get dist-upgrade -y
    for pkg in $PKGS; do
	apt-mark unhold $pkg
    done
    touch $OURDIR/apt-dist-upgraded
fi

838 839 840
#
# We rely on crudini in a few spots, instead of sed whacking.
#
841
maybe_install_packages crudini
842

843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860
netmask2prefix() {
    nm=$1
    bits=0
    IFS=.
    read -r i1 i2 i3 i4 <<EOF
$nm
EOF
    unset IFS
    for n in $i1 $i2 $i3 $i4 ; do
	v=128
	while [ $v -gt 0 ]; do
	    bits=`expr $bits + \( \( $n / $v \) % 2 \)`
	    v=`expr $v / 2`
	done
    done
    echo $bits
}

861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882
#
# Create IP addresses for the Management and Data networks, as necessary.
#
if [ ! -f $OURDIR/nextsparesubnet ] ; then
    #
    # This is horrible, but for openstack networks that need IP addrs, that
    # were not specified in our experiment description (i.e., by Emulab,
    # Cloudlab, or the geni-lib based rspec file), we have to generate them.
    # We stay away from 172.16 because Emulab/Cloudlab use it internally for
    # virtual machine IP addresses.  We also know that Emulab/Cloudlab/geni-lib
    # always allocate addresses starting at 10.1.1.1, and increment the second
    # octet for a new subnet.  We assume that 1) no subnet will ever be larger
    # than 255*255 hosts, and 2) that we can start our subnets at 10.254.0.0
    # and decrement the second octet any time we need to IP a new openstack
    # network.
    #
    NEXTSPARESUBNET=254
    echo ${NEXTSPARESUBNET} > $OURDIR/nextsparesubnet
else
    NEXTSPARESUBNET=`cat $OURDIR/nextsparesubnet`
fi

883
if [ ! -f $OURDIR/mgmt-hosts -o $UPDATING -ne 0 ] ; then
884 885 886
    echo "*** Setting up Management and Data Network IP Addresses"

    if [ -z "${MGMTLAN}" -o ${USE_EXISTING_IPS} -eq 0 ]; then
887 888 889
	if [ $UPDATING -eq 0 ]; then
	    echo "255.255.0.0" > $OURDIR/mgmt-netmask
	    echo "192.168.0.1 $NETWORKMANAGER" > $OURDIR/mgmt-hosts
890 891 892
	    if ! unified ; then
		echo "192.168.0.3 $CONTROLLER" >> $OURDIR/mgmt-hosts
	    fi
893 894 895 896 897 898 899
	    o3=0
	    o4=5
	else
	    o3=`cat $OURDIR/mgmt-o3`
	    o4=`cat $OURDIR/mgmt-o4`
	fi

900 901 902 903 904
	for node in $NODES
	do
	    [ "$node" = "$CONTROLLER" -o "$node" = "$NETWORKMANAGER" ] \
		&& continue

905 906 907 908 909 910
	    # If it already exists, skip it.
	    grep -q ${node}\$ $OURDIR/mgmt-hosts
	    if [ $? -eq 0 ]; then
		continue
	    fi

911 912 913 914 915 916 917 918 919
	    echo "192.168.$o3.$o4 $node" >> $OURDIR/mgmt-hosts

            # Skip 2 for openvpn tun tunnels
	    o4=`expr $o4 + 2`
	    if [ $o4 -gt 253 ] ; then
		o4=10
		o3=`expr $o3 + 1`
	    fi
	done
920 921 922 923

	# Save off our octets for later
	echo "$o3" > $OURDIR/mgmt-o3
	echo "$o4" > $OURDIR/mgmt-o4
924 925 926 927
    else
	cat $TOPOMAP | grep -v '^#' | sed -e 's/,/ /' \
	    | sed -n -e "s/\([a-zA-Z0-9_\-]*\) .*${MGMTLAN}:\([0-9\.]*\).*\$/\2\t\1/p" \
	    > $OURDIR/mgmt-hosts
David Johnson's avatar
David Johnson committed
928
	cat ${BOOTDIR}/tmcc/ifconfig \
929 930 931 932 933 934 935 936 937 938 939 940 941 942 943 944 945
	    | sed -n -e "s/^.* MASK=\([0-9\.]*\) .* LAN=${MGMTLAN}.*$/\1/p" \
	    > $OURDIR/mgmt-netmask
    fi

    #
    # If USE_EXISTING_IPS is set to 0, we will re-IP those data lan
    # interfaces: networkmanager:eth1 gets 10.z.0.1/8, and controller gets
    # 10.z.0.3/8; and the compute nodes get 10.z.x.y, where x starts at 1,
    # and y starts at 1 and does not exceed 254.
    #
    # We only assign IPs to flat networks because they are the only networks
    # that the physical hosts (i.e., controller, networkmanager, compute nodes)
    # have an interface on.  Technically, we don't *need* to do this, but do it.
    # One thing it gives us is the ability to run GRE or VXLAN networks over the
    # flat networks.
    #
    if [ ${USE_EXISTING_IPS} -eq 0 ]; then
946
	for lan in $DATAFLATLANS $DATAVLANS $DATAOTHERLANS ; do
947 948 949 950
	    if [ $UPDATING -eq 0 ]; then
		prefix="10.$NEXTSPARESUBNET"
		echo "$prefix" > $OURDIR/data-prefix.$lan
		echo "255.255.0.0" > $OURDIR/data-netmask.$lan
951
		echo "$prefix.0.0/16" > $OURDIR/data-cidr.$lan
952 953
		echo "$prefix.0.0" > $OURDIR/data-network.$lan
		echo "$prefix.0.1 $NETWORKMANAGER" > $OURDIR/data-hosts.$lan
954 955 956
		if ! unified ; then
		    echo "$prefix.0.3 $CONTROLLER" >> $OURDIR/data-hosts.$lan
		fi
957 958 959 960 961 962 963 964 965 966 967 968

                #
                # Now set static IPs for the compute nodes.
                #
		o3=1
		o4=1
	    else
		prefix=`cat $OURDIR/data-prefix.$lan`
		o3=`cat $OURDIR/data-o3.$lan`
		o4=`cat $OURDIR/data-o4.$lan`
	    fi

969 970 971 972 973
	    for node in $NODES
	    do
		[ "$node" = "$CONTROLLER" -o "$node" = "$NETWORKMANAGER" ] \
		    && continue

974 975 976 977 978 979 980
                # If it already exists, skip it.
		grep -q ${node}\$ $OURDIR/data-hosts.$lan
		if [ $? -eq 0 ]; then
		    continue
		fi

		echo "$prefix.$o3.$o4 $node" >> $OURDIR/data-hosts
981 982 983 984 985 986 987 988 989

                # Skip 2 for openvpn tun tunnels
		o4=`expr $o4 + 1`
		if [ $o4 -gt 254 ] ; then
		    o4=10
		    o3=`expr $o3 + 1`
		fi
	    done

990 991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015
	    if [ $o3 -gt 128 ]; then
		echo "ERROR: more physical hosts than $prefix.$o3 ; aborting!"
		exit 1
	    fi

	    # Save off our octets for later
	    echo $o3 > $OURDIR/data-o3.$lan
	    echo $o4 > $OURDIR/data-o4.$lan

	    if [ $UPDATING -eq 0 ]; then
	        # Start the pool at the next availble addr!  Don't skip.
	        # XXX: could cause problems for adding new phys hosts... oh well.
		o3=`expr $o3 + 10`
		if [ $SUPPORT_DYNAMIC_NODES -eq 1 ]; then
		    # Well, ok, so, let's just start at 128.  Why?  That
		    # leaves us room for 128*255-N physical hosts, plus
		    # 128*255 virtual machines at any time (and
		    # openstack will reuse ip addrs I'm sure).  So we
		    # have a long time before phys node wraparound...
		    echo "*** Changing from calculated o3=$o3/o4=$o4 to o3=128/o4=$o4 to support dynamic nodes..."
		    o3=128
		fi
	        # Also save two addrs, one for the dhcp agent, and one for the
	        # router interface
		echo "start=$prefix.$o3.3,end=10.$NEXTSPARESUBNET.254.254" \
		    > $OURDIR/data-allocation-pool.$lan
1016

1017 1018
		echo "$prefix.$o3.1" > $OURDIR/router-ipaddr.$lan
		echo "$prefix.$o3.2" > $OURDIR/dhcp-agent-ipaddr.$lan
1019

1020 1021
		NEXTSPARESUBNET=`expr $NEXTSPARESUBNET + 1`
	    fi
1022 1023
	done
    else
1024
	for lan in $DATAFLATLANS $DATAOTHERLANS ; do
1025 1026 1027
	    cat $TOPOMAP | grep -v '^#' | sed -e 's/,/ /' \
		| sed -n -e "s/\([a-zA-Z0-9_\-]*\) .*${lan}:\([0-9\.]*\).*\$/\2\t\1/p" \
		> $OURDIR/data-hosts.$lan
David Johnson's avatar
David Johnson committed
1028
	    netmask=`cat ${BOOTDIR}/tmcc/ifconfig \
1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040
  		         | sed -n -e "s/^.* MASK=\([0-9\.]*\) .* LAN=${lan}.*$/\1/p"`
	    echo "$netmask" > $OURDIR/data-netmask.$lan
	    nmdataip=`cat $OURDIR/data-hosts.${lan} | grep ${NETWORKMANAGER} | sed -n -e 's/^\([0-9]*.[0-9]*.[0-9]*.[0-9]*\).*$/\1/p'`
	    IFS=.
	    read -r i1 i2 i3 i4 <<EOF
$nmdataip
EOF
	    read -r m1 m2 m3 m4 <<EOF
$netmask
EOF
	    unset IFS
	    network=`printf "%d.%d.%d.%d\n" "$((i1 & m1))" "$((i2 & m2))" "$((i3 & m3))" "$((i4 & m4))"`
1041 1042
	    cidr=`python $DIRNAME/ipcalc.py mask2bits $netmask`
	    echo "$network/$cidr" > $OURDIR/data-cidr.$lan
1043 1044
	    echo "$network" > $OURDIR/data-network.$lan

1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055
	    if [ $UPDATING -eq 0 ]; then
	        #
	        # Setup our allocation pool
	        #
	        # First grab all our IP addresses
		allips=`cat $OURDIR/data-hosts.$lan | sed -n -e 's/^\([0-9]*.[0-9]*.[0-9]*.[0-9]*\).*$/\1/p'`
		gi1=0; gi2=0; gi3=0; gi4=0;
	        # Figure out the max currently-used IP in this subnet
		for ip in ${allips} ; do
		    IFS=.
		    read -r i1 i2 i3 i4 <<EOF
1056 1057
$ip
EOF
1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079
		    unset IFS
		    if [ $i1 -gt $gi1 ]; then gi1=$i1; gi2=0;gi3=0;gi4=0; fi
		    if [ $i2 -gt $gi2 ]; then gi2=$i2; gi3=0;gi4=0; fi
		    if [ $i3 -gt $gi3 ]; then gi3=$i3; gi4=0; fi
		    if [ $i4 -gt $gi4 ]; then gi4=$i4; fi
		done
	        # Get the next available one...
	        # Note, we don't try to stay inside the netmask :(
		gi4=`expr $gi4 + 1`
		if [ $gi4 = 255 ]; then gi4=1; gi3=`expr $gi3 + 1`; fi
		if [ $gi3 = 255 ]; then gi3=1; gi2=`expr $gi2 + 1`; fi
		if [ $gi2 = 255 ]; then gi2=1; gi1=`expr $gi1 + 1`; fi

		endaddr=`printf "%d.%d.%d.%d\n" "$((i1 | ((~m1)+256)))" "$((i2 | ((~m2)+256)))" "$((i3 | ((~m3)+256)))" "$((i4 | ((~m4)+256)))"`

	        #
                # So, this previous calculation is correct, but openstack doesn't
	        # like 255 in any of the octets!  Argh!  So, "fix" any that have it.
                # Argh...
                #
		IFS=.
		read -r i1 i2 i3 i4 <<EOF
1080 1081
$endaddr
EOF
1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110
		unset IFS
		if [ $i1 = 255 ]; then i1=254; fi
		if [ $i2 = 255 ]; then i2=254; fi
		if [ $i3 = 255 ]; then i3=254; fi
		if [ $i4 = 255 ]; then i4=254; fi
		endaddr="$i1.$i2.$i3.$i4"

	        # Also save two addrs, one for the dhcp agent, and one for the
	        # router interface
		echo "$gi1.$gi2.$gi3.$gi4" > $OURDIR/router-ipaddr.$lan
		gi4=`expr $gi4 + 1`
		echo "$gi1.$gi2.$gi3.$gi4" > $OURDIR/dhcp-agent-ipaddr.$lan
		gi4=`expr $gi4 + 1`
	        # Start the pool at the next availble addr!  Don't skip.
	        # XXX: could cause problems for adding new phys hosts... oh well.
		if [ $SUPPORT_DYNAMIC_NODES -eq 1 ]; then
		    # Well, ok, so, let's just start at 128.  Why?  That
		    # leaves us room for 128*255-N physical hosts, plus
		    # 128*255 virtual machines at any time (and
		    # openstack will reuse ip addrs I'm sure).  So we
		    # have a long time before phys node wraparound...
		    echo "*** Changing from gi3=$gi3/gi4=$gi4 to gi3=128/gi4=1 to support dynamic nodes..."
		    gi3=128
		    gi4=1
		fi
		# Write the allocation pool.
		echo "start=$gi1.$gi2.$gi3.$gi4,end=$endaddr" \
		    > $OURDIR/data-allocation-pool.$lan
	    fi
1111 1112 1113 1114 1115 1116 1117 1118 1119 1120 1121 1122 1123
	done
    fi

    # Save off nextsparesubnet
    echo "${NEXTSPARESUBNET}" > $OURDIR/nextsparesubnet
fi

#
# Setup IP configuration for neutron tunnel nets
#
if [ ${DATATUNNELS} -gt 0 ]; then
    i=0
    while [ $i -lt ${DATATUNNELS} ]; do
1124
	if [ -f "$OURDIR/ipinfo.tun${i}" ]; then
1125 1126 1127 1128
	    i=`expr $i + 1`
	    continue
	fi

1129 1130 1131
	LAN="tun${i}"
	subnet=${NEXTSPARESUBNET}

1132 1133
	echo "LAN='$LAN'" >> $OURDIR/ipinfo.$LAN
	echo "ALLOCATION_POOL='start=10.${subnet}.1.1,end=10.${subnet}.254.254'" >> $OURDIR/ipinfo.$LAN
1134
	echo "CIDR='10.$subnet.0.0/16'" >> $OURDIR/ipinfo.$LAN
1135 1136 1137 1138 1139 1140 1141 1142 1143 1144 1145 1146 1147

	NEXTSPARESUBNET=`expr ${NEXTSPARESUBNET} - 1`
	i=`expr $i + 1`
    done

    # Save off nextsparesubnet
    echo "${NEXTSPARESUBNET}" > $OURDIR/nextsparesubnet
fi

#
# Setup IP configuration for vlan networks
#
for lan in $DATAVLANS ; do
1148
    if [ -f $OURDIR/ipinfo.$lan ]; then
1149 1150 1151
	continue
    fi

1152 1153 1154
    LAN="$lan"
    subnet=${NEXTSPARESUBNET}

1155 1156
    echo "LAN='$LAN'" >> $OURDIR/ipinfo.$LAN
    echo "ALLOCATION_POOL='start=10.${subnet}.1.1,end=10.${subnet}.254.254'" >> $OURDIR/ipinfo.$LAN
1157
    echo "CIDR='10.$subnet.0.0/16'" >> $OURDIR/ipinfo.$LAN
1158 1159 1160 1161 1162 1163

    NEXTSPARESUBNET=`expr ${NEXTSPARESUBNET} - 1`
done
# Save off nextsparesubnet
echo "${NEXTSPARESUBNET}" > $OURDIR/nextsparesubnet

1164 1165 1166 1167 1168 1169
#
# Setup IP configuration for neutron vxlan nets
#
if [ ${DATAVXLANS} -gt 0 ]; then
    i=0
    while [ $i -lt ${DATAVXLANS} ]; do
1170
	if [ -f "$OURDIR/ipinfo.vxlan${i}" ]; then
1171 1172 1173 1174
	    i=`expr $i + 1`
	    continue
	fi

1175 1176 1177
	LAN="vxlan${i}"
	subnet=${NEXTSPARESUBNET}

1178 1179
	echo "LAN='$LAN'" >> $OURDIR/ipinfo.$LAN
	echo "ALLOCATION_POOL='start=10.${subnet}.1.1,end=10.${subnet}.254.254'" >> $OURDIR/ipinfo.$LAN
1180
	echo "CIDR='10.$subnet.0.0/16'" >> $OURDIR/ipinfo.$LAN
1181 1182 1183 1184 1185 1186 1187 1188 1189

	NEXTSPARESUBNET=`expr ${NEXTSPARESUBNET} - 1`
	i=`expr $i + 1`
    done

    # Save off nextsparesubnet
    echo "${NEXTSPARESUBNET}" > $OURDIR/nextsparesubnet
fi

1190 1191 1192 1193
#
# NB: this IP/mask is only valid after setting up the management network IP
# addresses because they might not be the Emulab ones.
#
1194 1195 1196
if [ ! -e $OURDIR/info.mgmt ]; then
    MGMTIP=`grep -E "$NODEID$" $OURDIR/mgmt-hosts | head -1 | sed -n -e 's/^\\([0-9]*\\.[0-9]*\\.[0-9]*\\.[0-9]*\\).*$/\\1/p'`
    MGMTNETMASK=`cat $OURDIR/mgmt-netmask`
1197
    MGMTPREFIX=`netmask2prefix $MGMTNETMASK`
1198
    if [ -z "$MGMTLAN" ] ; then
David Johnson's avatar
David Johnson committed
1199
	MGMTVLAN=0
1200 1201 1202 1203 1204 1205 1206 1207 1208 1209
	MVMTVLANDEV=
	MGMTMAC=""
	MGMT_NETWORK_INTERFACE="tun0"
    else
	cat ${BOOTDIR}/tmcc/ifconfig | grep "IFACETYPE=vlan" | grep "${MGMTLAN}"
	if [ $? = 0 ]; then
	    MGMTVLAN=1
	    MGMTMAC=`cat ${BOOTDIR}/tmcc/ifconfig | sed -n -e "s/^.* VMAC=\([0-9a-f:\.]*\) .* LAN=${MGMTLAN}.*\$/\1/p"`
	    MGMT_NETWORK_INTERFACE=`/usr/local/etc/emulab/findif -m $MGMTMAC`
	    MGMTVLANDEV=`ip link show ${MGMT_NETWORK_INTERFACE} | sed -n -e "s/^.*${MGMT_NETWORK_INTERFACE}\@\([0-9a-zA-Z_]*\): .*\$/\1/p"`
1210
	    MGMTVLANTAG=`cat ${BOOTDIR}/tmcc/ifconfig | sed -n -e "s/^.* LAN=${MGMTLAN} VTAG=\([0-9]*\).*\$/\1/p"`
1211 1212 1213 1214 1215 1216
	else
	    MGMTVLAN=0
	    MGMTMAC=`cat ${BOOTDIR}/tmcc/ifconfig | sed -n -e "s/.* MAC=\([0-9a-f:\.]*\) .* LAN=${MGMTLAN}/\1/p"`
	    MGMT_NETWORK_INTERFACE=`/usr/local/etc/emulab/findif -m $MGMTMAC`
	    MGMTVLANDEV=
	fi
David Johnson's avatar
David Johnson committed
1217
    fi
1218 1219
    echo "MGMTIP='$MGMTIP'" >> $OURDIR/info.mgmt
    echo "MGMTNETMASK='$MGMTNETMASK'" >> $OURDIR/info.mgmt
1220
    echo "MGMTPREFIX='$MGMTPREFIX'" >> $OURDIR/info.mgmt
1221 1222 1223 1224
    echo "MGMTVLAN=$MGMTVLAN" >> $OURDIR/info.mgmt
    echo "MGMTMAC='$MGMTMAC'" >> $OURDIR/info.mgmt
    echo "MGMT_NETWORK_INTERFACE='$MGMT_NETWORK_INTERFACE'" >> $OURDIR/info.mgmt
    echo "MGMTVLANDEV='$MGMTVLANDEV'" >> $OURDIR/info.mgmt
1225
    echo "MGMTVLANTAG='$MGMTVLANTAG'" >> $OURDIR/info.mgmt
1226 1227
else
    . $OURDIR/info.mgmt
1228
fi
1229 1230 1231 1232 1233

#
# NB: this IP/mask is only valid after data ips have been assigned, because
# they might not be the Emulab ones.
#
1234
for lan in $DATAFLATLANS $DATAOTHERLANS ; do
1235 1236 1237 1238
    if [ -e $OURDIR/info.$lan ] ; then
	continue
    fi

1239
    DATAIP=`cat $OURDIR/data-hosts.$lan | grep -E "$NODEID$" | sed -n -e 's/^\([0-9]*.[0-9]*.[0-9]*.[0-9]*\).*$/\1/p'`
1240
    DATANETMASK=`cat $OURDIR/data-netmask.$lan`
1241
    DATAPREFIX=`netmask2prefix $DATANETMASK`
David Johnson's avatar
David Johnson committed
1242
    cat ${BOOTDIR}/tmcc/ifconfig | grep "IFACETYPE=vlan" | grep "${lan}"
1243 1244
    if [ $? = 0 ]; then
	DATAVLAN=1
David Johnson's avatar
David Johnson committed
1245
	DATAMAC=`cat ${BOOTDIR}/tmcc/ifconfig | sed -n -e "s/^.* VMAC=\([0-9a-f:\.]*\) .* LAN=${lan}.*\$/\1/p"`
1246 1247
	DATADEV=`/usr/local/etc/emulab/findif -m $DATAMAC`
	DATAVLANDEV=`ip link show ${DATADEV} | sed -n -e "s/^.*${DATADEV}\@\([0-9a-zA-Z_]*\): .*\$/\1/p"`
David Johnson's avatar
David Johnson committed
1248
	DATAVLANTAG=`cat ${BOOTDIR}/tmcc/ifconfig | sed -n -e "s/^.* LAN=${lan} VTAG=\([0-9]*\).*\$/\1/p"`
1249
	DATAPMAC=`cat ${BOOTDIR}/tmcc/ifconfig | sed -n -e "s/^.* PMAC=\([0-9a-f:\.]*\) .* LAN=${lan}.*\$/\1/p"`
1250 1251 1252 1253
    else
	DATAVLAN=0
	DATAVLANDEV=""
	DATAVLANTAG=0
David Johnson's avatar
David Johnson committed
1254
	DATAMAC=`cat ${BOOTDIR}/tmcc/ifconfig | sed -n -e "s/^.* MAC=\([0-9a-f:\.]*\) .* LAN=${lan}.*$/\1/p"`
1255
	DATADEV=`/usr/local/etc/emulab/findif -m $DATAMAC`
1256
	DATAPMAC=
1257 1258 1259 1260 1261
    fi

    echo "DATABRIDGE=br-${lan}" >> $OURDIR/info.$lan
    echo "DATAIP=${DATAIP}" >> $OURDIR/info.$lan
    echo "DATANETMASK=${DATANETMASK}" >> $OURDIR/info.$lan
1262
    echo "DATAPREFIX=${DATAPREFIX}" >> $OURDIR/info.$lan
1263 1264 1265 1266
    echo "DATAVLAN=${DATAVLAN}" >> $OURDIR/info.$lan
    echo "DATAVLANTAG=${DATAVLANTAG}" >> $OURDIR/info.$lan
    echo "DATAVLANDEV=${DATAVLANDEV}" >> $OURDIR/info.$lan
    echo "DATAMAC=${DATAMAC}" >> $OURDIR/info.$lan
1267
    echo "DATAPMAC=${DATAPMAC}" >> $OURDIR/info.$lan
1268 1269 1270 1271 1272 1273 1274 1275
    echo "DATADEV=${DATADEV}" >> $OURDIR/info.$lan
done

for lan in $DATAVLANS ; do
    if [ -e $OURDIR/info.$lan ] ; then
	continue
    fi

1276
    #DATAIP=`cat $OURDIR/data-hosts.$lan | grep -E "$NODEID$" | sed -n -e 's/^\([0-9]*.[0-9]*.[0-9]*.[0-9]*\).*$/\1/p'`
1277
    #DATANETMASK=`cat $OURDIR/data-netmask.$lan`
David Johnson's avatar
David Johnson committed
1278
    DATAVLAN=1
David Johnson's avatar
David Johnson committed
1279
    DATAMAC=`cat ${BOOTDIR}/tmcc/ifconfig | sed -n -e "s/^.* VMAC=\([0-9a-f:\.]*\) .* LAN=${lan}.*\$/\1/p"`
1280 1281
    DATADEV=`/usr/local/etc/emulab/findif -m $DATAMAC`
    DATAVLANDEV=`ip link show ${DATADEV} | sed -n -e "s/^.*${DATADEV}\@\([0-9a-zA-Z_]*\): .*\$/\1/p"`
David Johnson's avatar
David Johnson committed
1282
    DATAVLANTAG=`cat ${BOOTDIR}/tmcc/ifconfig | sed -n -e "s/^.* LAN=${lan} VTAG=\([0-9]*\).*\$/\1/p"`