blob: 76b387adf821eacd47858a9c24dfab9d1464f8c4 [file] [log] [blame]
rspangler@google.comd74220d2009-10-09 20:56:14 +00001#!/bin/bash
2
Darin Petkov47974d42011-03-03 15:55:04 -08003# Copyright (c) 2011 The Chromium OS Authors. All rights reserved.
rspangler@google.comd74220d2009-10-09 20:56:14 +00004# Use of this source code is governed by a BSD-style license that can be
5# found in the LICENSE file.
6
7# Script to enter the chroot environment
8
J. Richard Barnette8e6750d2011-08-22 12:35:52 -07009SCRIPT_ROOT=$(readlink -f $(dirname "$0")/..)
10. "${SCRIPT_ROOT}/common.sh" || exit 1
rspangler@google.comd74220d2009-10-09 20:56:14 +000011
Brian Harringfeb04f72012-02-03 21:22:50 -080012enable_strict_sudo
13
derat@google.com86dcc8e2009-11-21 19:49:49 +000014# Script must be run outside the chroot and as a regular user.
rspangler@google.comd74220d2009-10-09 20:56:14 +000015assert_outside_chroot
derat@google.com86dcc8e2009-11-21 19:49:49 +000016assert_not_root_user
rspangler@google.comd74220d2009-10-09 20:56:14 +000017
18# Define command line flags
19# See http://code.google.com/p/shflags/wiki/Documentation10x
20DEFINE_string chroot "$DEFAULT_CHROOT_DIR" \
21 "The destination dir for the chroot environment." "d"
22DEFINE_string trunk "$GCLIENT_ROOT" \
23 "The source trunk to bind mount within the chroot." "s"
David McMahon03aeb202009-12-08 12:47:08 -080024DEFINE_string build_number "" \
25 "The build-bot build number (when called by buildbot only)." "b"
Andrew de los Reyes6d0ca162010-02-12 14:36:08 -080026DEFINE_string chrome_root "" \
27 "The root of your chrome browser source. Should contain a 'src' subdir."
Sean Parent2898f752010-05-25 15:06:33 -070028DEFINE_string chrome_root_mount "/home/$USER/chrome_root" \
29 "The mount point of the chrome broswer source in the chroot."
Brian Harring7b6f3772012-09-23 14:01:13 -070030DEFINE_string cache_dir "" "Directory to use for caching."
rspangler@google.comd74220d2009-10-09 20:56:14 +000031
Chris Sosaaa1a7fd2010-04-02 14:06:29 -070032DEFINE_boolean official_build $FLAGS_FALSE \
33 "Set CHROMEOS_OFFICIAL=1 for release builds."
rspangler@google.comd74220d2009-10-09 20:56:14 +000034DEFINE_boolean mount $FLAGS_FALSE "Only set up mounts."
35DEFINE_boolean unmount $FLAGS_FALSE "Only tear down mounts."
Elly Jones7990a062010-09-02 09:23:23 -040036DEFINE_boolean ssh_agent $FLAGS_TRUE "Import ssh agent."
Brian Harring35767822012-02-01 23:50:45 -080037DEFINE_boolean early_make_chroot $FLAGS_FALSE \
38 "Internal flag. If set, the command is run as root without sudo."
Don Garrettad3f0592011-02-04 14:59:56 -080039DEFINE_boolean verbose $FLAGS_FALSE "Print out actions taken"
rspangler@google.comd74220d2009-10-09 20:56:14 +000040
41# More useful help
Doug Anderson9362fa82010-12-16 14:44:12 -080042FLAGS_HELP="USAGE: $0 [flags] [VAR=value] [-- command [arg1] [arg2] ...]
rspangler@google.comd74220d2009-10-09 20:56:14 +000043
44One or more VAR=value pairs can be specified to export variables into
45the chroot environment. For example:
46
47 $0 FOO=bar BAZ=bel
48
Doug Anderson9362fa82010-12-16 14:44:12 -080049If [-- command] is present, runs the command inside the chroot,
50after changing directory to /$USER/trunk/src/scripts. Note that neither
51the command nor args should include single quotes. For example:
rspangler@google.comd74220d2009-10-09 20:56:14 +000052
Doug Anderson9362fa82010-12-16 14:44:12 -080053 $0 -- ./build_platform_packages.sh
rspangler@google.comd74220d2009-10-09 20:56:14 +000054
55Otherwise, provides an interactive shell.
56"
57
Peter Mayo4411efe2012-09-21 04:41:27 -040058CROS_LOG_PREFIX=cros_sdk:enter_chroot
59
Don Garrettad3f0592011-02-04 14:59:56 -080060# Version of info from common.sh that only echos if --verbose is set.
Mike Frysinger6b1abb22012-05-11 13:44:06 -040061debug() {
Don Garrettad3f0592011-02-04 14:59:56 -080062 if [ $FLAGS_verbose -eq $FLAGS_TRUE ]; then
David Rochberg351a76f2011-02-16 11:14:00 -050063 info "$*"
Don Garrettad3f0592011-02-04 14:59:56 -080064 fi
65}
66
rspangler@google.comd74220d2009-10-09 20:56:14 +000067# Parse command line flags
68FLAGS "$@" || exit 1
69eval set -- "${FLAGS_ARGV}"
70
Greg Spencer798d75f2011-02-01 22:04:49 -080071if [ $FLAGS_official_build -eq $FLAGS_TRUE ]; then
David McMahon857dbb52009-12-09 18:21:05 -080072 CHROMEOS_OFFICIAL=1
73fi
74
Brian Harring7b6f3772012-09-23 14:01:13 -070075[ -z "${FLAGS_cache_dir}" ] && \
76 die "--cache_dir is required"
Brian Harring7ee892d2012-02-02 09:33:10 -080077
rspangler@google.comd74220d2009-10-09 20:56:14 +000078# Only now can we die on error. shflags functions leak non-zero error codes,
Brian Harring7f175a52012-03-02 05:37:00 -080079# so will die prematurely if 'switch_to_strict_mode' is specified before now.
rspangler@google.comd74220d2009-10-09 20:56:14 +000080# TODO: replace shflags with something less error-prone, or contribute a fix.
Brian Harring7f175a52012-03-02 05:37:00 -080081switch_to_strict_mode
rspangler@google.comd74220d2009-10-09 20:56:14 +000082
Matt Tennant298f61a2012-06-25 21:54:33 -070083# These config files are to be copied into chroot if they exist in home dir.
84FILES_TO_COPY_TO_CHROOT=(
85 .gdata_cred.txt # User/password for Google Docs on chromium.org
86 .gdata_token # Auth token for Google Docs on chromium.org
87 .disable_build_stats_upload # Presence of file disables command stats upload
88)
89
Sean Parent2898f752010-05-25 15:06:33 -070090INNER_CHROME_ROOT=$FLAGS_chrome_root_mount # inside chroot
Andrew de los Reyes6d0ca162010-02-12 14:36:08 -080091CHROME_ROOT_CONFIG="/var/cache/chrome_root" # inside chroot
Andrew de los Reyes5d0248f2010-02-12 16:12:31 -080092INNER_DEPOT_TOOLS_ROOT="/home/$USER/depot_tools" # inside chroot
Chris Sosaaa1a7fd2010-04-02 14:06:29 -070093FUSE_DEVICE="/dev/fuse"
Chris Masone162f6542010-05-12 14:58:37 -070094AUTOMOUNT_PREF="/apps/nautilus/preferences/media_automount"
95SAVED_AUTOMOUNT_PREF_FILE="/tmp/.automount_pref"
Andrew de los Reyes6d0ca162010-02-12 14:36:08 -080096
Mike Frysinger82649172011-09-21 00:18:14 -040097# Avoid the sudo call if possible since it is a little slow.
98if [ $(stat -c %a "$FLAGS_chroot/var/lock") != 777 ]; then
99 sudo chmod 0777 "$FLAGS_chroot/var/lock"
100fi
Andrew de los Reyesc9317ea2010-02-10 13:16:36 -0800101
102LOCKFILE="$FLAGS_chroot/var/lock/enter_chroot"
Zdenek Behane28239d2011-04-07 00:37:20 +0200103SYNCERPIDFILE="${FLAGS_chroot}/var/tmp/enter_chroot_sync.pid"
Andrew de los Reyesc9317ea2010-02-10 13:16:36 -0800104
David Rochberg351a76f2011-02-16 11:14:00 -0500105
Mike Frysinger0a0e6ec2011-09-28 11:57:21 -0400106MOUNTED_PATH=$(readlink -f "$FLAGS_chroot")
Mike Frysinger6b1abb22012-05-11 13:44:06 -0400107mount_queue_init() {
Mike Frysinger286b5922011-09-28 11:59:53 -0400108 MOUNT_QUEUE=()
109}
110
Mike Frysinger6b1abb22012-05-11 13:44:06 -0400111queue_mount() {
David Rochberg351a76f2011-02-16 11:14:00 -0500112 # If necessary, mount $source in the host FS at $target inside the
113 # chroot directory with $mount_args.
114 local source="$1"
115 local mount_args="$2"
116 local target="$3"
117
Mike Frysinger0a0e6ec2011-09-28 11:57:21 -0400118 local mounted_path="${MOUNTED_PATH}$target"
David Rochberg351a76f2011-02-16 11:14:00 -0500119
Mike Frysinger9e5b0a42012-05-16 17:30:24 -0400120 case " ${MOUNT_CACHE} " in
121 *" ${mounted_path} "*)
Mike Frysinger2a970592011-09-20 22:49:01 -0400122 # Already mounted!
123 ;;
124 *)
Michael Krebs04c4f732012-09-07 18:31:46 -0700125 MOUNT_QUEUE+=( "mkdir -p '${mounted_path}'" )
126 # The args are left unquoted on purpose.
127 if [[ -n ${source} ]]; then
128 MOUNT_QUEUE+=( "mount ${mount_args} '${source}' '${mounted_path}'" )
129 else
130 MOUNT_QUEUE+=( "mount ${mount_args} '${mounted_path}'" )
131 fi
Mike Frysinger2a970592011-09-20 22:49:01 -0400132 ;;
133 esac
David Rochberg351a76f2011-02-16 11:14:00 -0500134}
135
Mike Frysinger6b1abb22012-05-11 13:44:06 -0400136process_mounts() {
Mike Frysinger286b5922011-09-28 11:59:53 -0400137 if [[ ${#MOUNT_QUEUE[@]} -eq 0 ]]; then
138 return 0
139 fi
140 sudo_multi "${MOUNT_QUEUE[@]}"
141 mount_queue_init
142}
143
Mike Frysinger6b1abb22012-05-11 13:44:06 -0400144env_sync_proc() {
Zdenek Behane28239d2011-04-07 00:37:20 +0200145 # This function runs and performs periodic updates to the chroot env, if
146 # necessary.
147
148 local poll_interval=10
Mike Frysinger7f7a7632011-09-28 11:48:20 -0400149 local sync_files=( etc/resolv.conf etc/hosts )
Zdenek Behane28239d2011-04-07 00:37:20 +0200150
Mike Frysinger4d8c2852012-05-16 15:22:49 -0400151 # Make sure the files exist before the find -- they might not in a
152 # fresh chroot which results in warnings in the build output.
153 local chown_cmd=(
154 # Make sure the files exists first -- they might not in a fresh chroot.
155 "touch ${sync_files[*]/#/${FLAGS_chroot}/}"
156 # Make sure the files are writable by normal user so that we don't have
157 # to execute sudo in the main loop below.
158 "chown ${USER} ${sync_files[*]/#/${FLAGS_chroot}/}"
159 )
160 sudo_multi "${chown_cmd[@]}"
Zdenek Behane28239d2011-04-07 00:37:20 +0200161
David James412b9022011-07-15 19:54:16 -0700162 # Drop stdin, stderr, stdout, and chroot lock.
163 # This is needed for properly daemonizing the process.
164 exec 0>&- 1>&- 2>&- 200>&-
165
Zdenek Behane28239d2011-04-07 00:37:20 +0200166 while true; do
167 # Sync files
Ryan Cuife573cd2012-09-27 15:58:42 -0700168 for file in "${sync_files[@]}"; do
Zdenek Behane28239d2011-04-07 00:37:20 +0200169 if ! cmp /${file} ${FLAGS_chroot}/${file} &> /dev/null; then
170 cp -f /${file} ${FLAGS_chroot}/${file}
171 fi
172 done
173
174 sleep ${poll_interval}
175 done
176}
177
Mike Frysinger6b1abb22012-05-11 13:44:06 -0400178copy_ssh_config() {
Vadim Bendebury0779f522011-06-12 12:09:16 -0700179 # Copy user .ssh/config into the chroot filtering out strings not supported
180 # by the chroot ssh. The chroot .ssh directory is passed in as the first
181 # parameter.
182
183 # ssh options to filter out. The entire strings containing these substrings
184 # will be deleted before copying.
185 local bad_options=(
Matt Tennant63c3cc52011-11-22 11:23:06 -0800186 'UseProxyIf'
187 'GSSAPIAuthentication'
188 'GSSAPIKeyExchange'
189 'ProxyUseFdpass'
Vadim Bendebury0779f522011-06-12 12:09:16 -0700190 )
191 local sshc="${HOME}/.ssh/config"
192 local chroot_ssh_dir="${1}"
193 local filter
194 local option
195
196 if [ ! -f "${sshc}" ]; then
197 return # Nothing to copy.
198 fi
199
200 for option in "${bad_options[@]}"
201 do
202 if [ -z "${filter}" ]; then
203 filter="${option}"
204 else
205 filter+="\\|${option}"
206 fi
207 done
208
209 sed "/^.*\(${filter}\).*$/d" "${sshc}" > "${chroot_ssh_dir}/config"
210}
211
Mike Frysinger6b1abb22012-05-11 13:44:06 -0400212copy_into_chroot_if_exists() {
Matt Tennantf7c9e772012-02-08 17:06:26 -0800213 # $1 is file path outside of chroot to copy to path $2 inside chroot.
214 [ -e "$1" ] || return
215 cp "$1" "${FLAGS_chroot}/$2"
216}
217
Peter Mayo4411efe2012-09-21 04:41:27 -0400218# Usage: promote_api_keys
219# This takes care of getting the developer API keys into the chroot where
220# chrome can build with them. It needs to take it from the places a dev
221# is likely to put them, and recognize that older chroots may or may not
222# have been used since the concept of keys got added, as well as before
223# and after the developer decding to grab his own keys.
224promote_api_keys() {
225 local destination="${FLAGS_chroot}/home/${USER}/.googleapikeys"
226 # Don't disturb existing keys. They could be set differently
227 if [[ -s "${destination}" ]]; then
228 return 0
229 fi
230 if [[ -r "${HOME}/.googleapikeys" ]]; then
231 cp "${HOME}/.googleapikeys" "${destination}"
232 if [[ -s "${destination}" ]] ; then
233 info "Copied Google API keys into chroot."
234 fi
235 elif [[ -r "${HOME}/.gyp/include.gypi" ]]; then
236 local NAME="('google_(api_key|default_client_(id|secret))')"
237 local WS="[[:space:]]*"
238 local CONTENTS="('[^\\\\']*')"
239 sed -nr -e "/^${WS}${NAME}${WS}[:=]${WS}${CONTENTS}.*/{s//\1: \4,/;p;}" \
240 "${HOME}/.gyp/include.gypi" >"${destination}"
241 if [[ -s "${destination}" ]]; then
242 info "Put discovered Google API keys into chroot."
243 fi
244 fi
245}
246
Mike Frysinger6b1abb22012-05-11 13:44:06 -0400247setup_env() {
Doug Andersona8d9cc12011-02-02 15:47:00 -0800248 # Validate sudo timestamp before entering the critical section so that we
249 # don't stall for a password while we have the lockfile.
Doug Anderson3d7fa3a2011-02-02 16:10:34 -0800250 # Don't use sudo -v since that has issues on machines w/ no password.
251 sudo echo "" > /dev/null
Doug Andersona8d9cc12011-02-02 15:47:00 -0800252
Andrew de los Reyesc9317ea2010-02-10 13:16:36 -0800253 (
254 flock 200
255 echo $$ >> "$LOCKFILE"
rspangler@google.comd74220d2009-10-09 20:56:14 +0000256
Taylor Hutt25bf9492011-07-27 13:54:35 -0700257 # If there isn't a syncer daemon started already, start one. The
258 # daemon is considered to not be started under the following
259 # conditions:
260 #
261 # o There is no PID file
262 #
263 # o The PID file is 0 bytes in size, which might be a partial
264 # manifestation of chromium-os:17680. This situation will not
265 # occur anymore, but you might have a chroot which was already
266 # affected.
267 #
268 # o The /proc node for the process named by the PID file does
269 # not exist.
270 #
271 # Note: This does not address PID recycling. While
272 # increasingly unlikely, it is possible for the PID in
273 # the PID file to refer to a running process that is not
274 # the syncer process. Since the PID file is now
275 # removed, I think it is only possible for this to occur
276 # if your system crashes and the PID file exists after
277 # restart.
278 #
279 # The daemon is killed by the enter_chroot that exits last.
Taylor Hutt18594a82011-07-28 11:45:50 -0700280 if [ -f "${SYNCERPIDFILE}" ] && [ ! -s "${SYNCERPIDFILE}" ] ; then
Taylor Hutt25bf9492011-07-27 13:54:35 -0700281 info "You may have suffered from chromium-os:17680 and";
282 info "could have stray 'enter_chroot.sh' processes running.";
283 info "You must manually kill any such stray processes.";
284 info "Exit all chroot shells; remaining 'enter_chroot.sh'";
285 info "processes are probably stray.";
Taylor Hutt18594a82011-07-28 11:45:50 -0700286 sudo rm -f "${SYNCERPIDFILE}";
Taylor Hutt25bf9492011-07-27 13:54:35 -0700287 fi;
David James412b9022011-07-15 19:54:16 -0700288 if ! [ -f "${SYNCERPIDFILE}" ] || \
Mike Frysinger61e4f282011-09-20 22:37:22 -0400289 ! [ -d /proc/$(<"${SYNCERPIDFILE}") ]; then
David James412b9022011-07-15 19:54:16 -0700290 debug "Starting sync process"
291 env_sync_proc &
292 echo $! > "${SYNCERPIDFILE}"
293 disown $!
294 fi
295
Don Garretta0e7ea12011-02-07 18:39:59 -0800296 debug "Mounting chroot environment."
Mike Frysinger9e5b0a42012-05-16 17:30:24 -0400297 MOUNT_CACHE=$(echo $(awk '{print $2}' /proc/mounts))
Mike Frysinger286b5922011-09-28 11:59:53 -0400298 mount_queue_init
299 queue_mount none "-t proc" /proc
300 queue_mount none "-t sysfs" /sys
301 queue_mount /dev "--bind" /dev
302 queue_mount none "-t devpts" /dev/pts
Aaron Plattner130d3632011-10-18 08:54:57 -0700303 if [ -d /run ]; then
Mike Frysinger286b5922011-09-28 11:59:53 -0400304 queue_mount /run "--bind" /run
Aaron Plattner130d3632011-10-18 08:54:57 -0700305 if [ -d /run/shm ]; then
Mike Frysinger286b5922011-09-28 11:59:53 -0400306 queue_mount /run/shm "--bind" /run/shm
Aaron Plattner130d3632011-10-18 08:54:57 -0700307 fi
308 fi
Brian Harringf264b822012-09-01 01:39:03 -0700309 # Get path overrides for the chroot in place now- it's possible
310 # that they may be needed for early teardown.
311 queue_mount "${FLAGS_trunk}/src/scripts/path-overrides" "--bind" \
312 "/usr/local/path-overrides"
Brian Harringdd7d7932011-12-23 04:21:33 -0800313
Brian Harringf264b822012-09-01 01:39:03 -0700314 queue_mount "${FLAGS_trunk}" "--bind" "${CHROOT_TRUNK_DIR}"
Chris Sosa389634d2012-09-05 19:56:53 -0700315
Brian Harringdd7d7932011-12-23 04:21:33 -0800316 debug "Setting up referenced repositories if required."
317 REFERENCE_DIR=$(git config --file \
318 "${FLAGS_trunk}/.repo/manifests.git/config" \
319 repo.reference)
320 if [ -n "${REFERENCE_DIR}" ]; then
321
Brian Harring334050f2012-06-08 17:40:58 -0700322 ALTERNATES="${FLAGS_trunk}/.repo/alternates"
323
324 # Ensure this directory exists ourselves, and has the correct ownership.
325 [ -d "${ALTERNATES}" ] || mkdir "${ALTERNATES}"
326 [ -w "${ALTERNATES}" ] || sudo chown -R "${USER}" "${ALTERNATES}"
327
328 unset ALTERNATES
329
Brian Harringdd7d7932011-12-23 04:21:33 -0800330 IFS=$'\n';
331 required=( $( "${FLAGS_trunk}/chromite/lib/rewrite_git_alternates.py" \
332 "${FLAGS_trunk}" "${REFERENCE_DIR}" "${CHROOT_TRUNK_DIR}" ) )
333 unset IFS
334
335 queue_mount "${FLAGS_trunk}/.repo/chroot/alternates" --bind \
336 "${CHROOT_TRUNK_DIR}/.repo/alternates"
337
338 # Note that as we're bringing up each referened repo, we also
339 # mount bind an empty directory over its alternates. This is
340 # required to suppress git from tracing through it- we already
341 # specify the required alternates for CHROOT_TRUNK_DIR, no point
342 # in having git try recursing through each on their own.
343 #
344 # Finally note that if you're unfamiliar w/ chroot/vfs semantics,
345 # the bind is visible only w/in the chroot.
346 mkdir -p ${FLAGS_trunk}/.repo/chroot/empty
347 position=1
348 for x in "${required[@]}"; do
349 base="${CHROOT_TRUNK_DIR}/.repo/chroot/external${position}"
350 queue_mount "${x}" "--bind" "${base}"
351 if [ -e "${x}/.repo/alternates" ]; then
352 queue_mount "${FLAGS_trunk}/.repo/chroot/empty" "--bind" \
353 "${base}/.repo/alternates"
354 fi
355 position=$(( ${position} + 1 ))
356 done
357 unset required position base
358 fi
359 unset REFERENCE_DIR
360
Brian Harring7b6f3772012-09-23 14:01:13 -0700361 chroot_cache='/var/cache/chromeos-cache'
362 debug "Setting up shared cache dir directory."
363 mkdir -p "${FLAGS_cache_dir}"/distfiles/{target,host}
364 sudo mkdir -p "${FLAGS_chroot}/${chroot_cache}"
365 queue_mount "${FLAGS_cache_dir}" "--bind" "${chroot_cache}"
366 # TODO(build): remove this as of 12/01/12.
367 # Because of how distfiles -> cache_dir was deployed, if this isn't
368 # a symlink, we *know* the ondisk pathways aren't compatible- thus
369 # fix it now.
370 distfiles_path="${FLAGS_chroot}/var/cache/distfiles"
371 if [ ! -L "${distfiles_path}" ]; then
372 # While we're at it, ensure the var is exported w/in the chroot; it
373 # won't exist if distfiles isn't a symlink.
Paul Drewsb688cbe2012-10-08 15:33:43 -0700374 p="${FLAGS_chroot}/etc/profile.d/chromeos-cachedir.sh"
Brian Harring7b6f3772012-09-23 14:01:13 -0700375 sudo_multi "rm -rf '${distfiles_path}'" \
376 "ln -s chromeos-cache/distfiles '${distfiles_path}'" \
Paul Drewsb688cbe2012-10-08 15:33:43 -0700377 "mkdir -p -m 775 '${p%/*}'" \
Brian Harring7b6f3772012-09-23 14:01:13 -0700378 "echo 'export CHROMEOS_CACHEDIR=${chroot_cache}' > '${p}'" \
379 "chmod 0644 '${p}'"
380 fi
Brian Harring7ee892d2012-02-02 09:33:10 -0800381
Elly Jones7990a062010-09-02 09:23:23 -0400382 if [ $FLAGS_ssh_agent -eq $FLAGS_TRUE ]; then
Greg Spencer798d75f2011-02-01 22:04:49 -0800383 if [ -n "${SSH_AUTH_SOCK}" -a -d "${HOME}/.ssh" ]; then
Mike Frysinger61e4f282011-09-20 22:37:22 -0400384 TARGET_DIR="${FLAGS_chroot}/home/${USER}/.ssh"
Elly Jones7990a062010-09-02 09:23:23 -0400385 mkdir -p "${TARGET_DIR}"
Mike Frysinger40bb0c32011-10-31 17:14:15 -0400386 # Ignore errors as some people won't have these files to copy.
387 cp "${HOME}"/.ssh/{known_hosts,*.pub} "${TARGET_DIR}/" 2>/dev/null || :
Vadim Bendebury0779f522011-06-12 12:09:16 -0700388 copy_ssh_config "${TARGET_DIR}"
Mike Frysinger9de707f2011-12-12 14:21:44 -0500389
390 # Don't try to bind mount the ssh agent dir if it has gone stale.
Mike Frysinger61e4f282011-09-20 22:37:22 -0400391 ASOCK=${SSH_AUTH_SOCK%/*}
Mike Frysinger9de707f2011-12-12 14:21:44 -0500392 if [ -d "${ASOCK}" ]; then
393 queue_mount "${ASOCK}" "--bind" "${ASOCK}"
394 fi
Elly Jones7990a062010-09-02 09:23:23 -0400395 fi
396 fi
397
Mike Frysinger286b5922011-09-28 11:59:53 -0400398 if [ -d "$HOME/.subversion" ]; then
399 TARGET="/home/${USER}/.subversion"
400 mkdir -p "${FLAGS_chroot}${TARGET}"
401 queue_mount "${HOME}/.subversion" "--bind" "${TARGET}"
Paul Drewsb4605b42012-10-11 23:10:43 -0700402 # Symbolic-link the .subversion directory so sandboxed subversion.class
403 # clients can use it.
404 local cmds=()
405 for d in \
406 "${FLAGS_cache_dir}"/distfiles/{host,target}/svn-src/"${USER}"; do
407 if [[ ! -L "${d}/.subversion" ]]; then
408 cmds+=(
409 "mkdir -p '${d}'"
410 "ln -sf /home/${USER}/.subversion '${d}/.subversion'"
411 "chown -R ${USER}:250 '${d%/*}'"
412 )
413 fi
414 done
415 if [[ ${#cmds[@]} -gt 0 ]]; then
416 sudo_multi "${cmds[@]}"
417 fi
Mike Frysinger286b5922011-09-28 11:59:53 -0400418 fi
419
420 if DEPOT_TOOLS=$(type -P gclient) ; then
421 DEPOT_TOOLS=${DEPOT_TOOLS%/*} # dirname
422 debug "Mounting depot_tools"
423 queue_mount "$DEPOT_TOOLS" --bind "$INNER_DEPOT_TOOLS_ROOT"
424 fi
425
Michael Krebs04c4f732012-09-07 18:31:46 -0700426 # Mount additional directories as specified in .local_mounts file.
427 local local_mounts="${FLAGS_trunk}/src/scripts/.local_mounts"
428 if [[ -f ${local_mounts} ]]; then
429 info "Mounting local folders (read-only for safety concern)"
430 # format: mount_source
431 # or mount_source mount_point
432 # or # comments
433 local mount_source mount_point
434 while read mount_source mount_point; do
435 if [[ -z ${mount_source} ]]; then
436 continue
437 fi
438 # if only source is assigned, use source as mount point.
439 : ${mount_point:=${mount_source}}
440 debug " mounting ${mount_source} on ${mount_point}"
441 queue_mount "${mount_source}" "--bind" "${mount_point}"
442 # --bind can't initially be read-only so we have to do it via remount.
443 queue_mount "" "-o remount,ro" "${mount_point}"
444 done < <(sed -e 's:#.*::' "${local_mounts}")
445 fi
446
Mike Frysinger286b5922011-09-28 11:59:53 -0400447 process_mounts
448
Mike Frysinger9a50b642011-09-20 23:37:14 -0400449 CHROME_ROOT="$(readlink -f "$FLAGS_chrome_root" || :)"
450 if [ -z "$CHROME_ROOT" ]; then
451 CHROME_ROOT="$(cat "${FLAGS_chroot}${CHROME_ROOT_CONFIG}" \
452 2>/dev/null || :)"
453 CHROME_ROOT_AUTO=1
454 fi
455 if [[ -n "$CHROME_ROOT" ]]; then
456 if [[ ! -d "${CHROME_ROOT}/src" ]]; then
457 error "Not mounting chrome source"
458 sudo rm -f "${FLAGS_chroot}${CHROME_ROOT_CONFIG}"
459 if [[ ! "$CHROME_ROOT_AUTO" ]]; then
460 exit 1
Don Garretta0e7ea12011-02-07 18:39:59 -0800461 fi
Mike Frysinger9a50b642011-09-20 23:37:14 -0400462 else
463 debug "Mounting chrome source at: $INNER_CHROME_ROOT"
464 sudo bash -c "echo '$CHROME_ROOT' > \
465 '${FLAGS_chroot}${CHROME_ROOT_CONFIG}'"
Mike Frysinger286b5922011-09-28 11:59:53 -0400466 queue_mount "$CHROME_ROOT" --bind "$INNER_CHROME_ROOT"
Andrew de los Reyes6d0ca162010-02-12 14:36:08 -0800467 fi
468 fi
Andrew de los Reyes5d0248f2010-02-12 16:12:31 -0800469
Mike Frysinger286b5922011-09-28 11:59:53 -0400470 process_mounts
Chris Sosa317d8eb2010-04-05 15:45:28 -0700471
Mike Frysingeracc4c9b2011-09-15 18:06:25 -0400472 # Install fuse module. Skip modprobe when possible for slight
473 # speed increase when initializing the env.
474 if [ -c "${FUSE_DEVICE}" ] && ! grep -q fuse /proc/filesystems; then
Chris Sosa317d8eb2010-04-05 15:45:28 -0700475 sudo modprobe fuse 2> /dev/null ||\
Sean Ocd8b1d12010-09-02 17:34:49 +0200476 warn "-- Note: modprobe fuse failed. gmergefs will not work"
Chris Sosa317d8eb2010-04-05 15:45:28 -0700477 fi
478
David Jamesc9ca3db2012-07-09 08:12:26 -0700479 # Turn off automounting of external media when we enter the
480 # chroot; thus we don't have to worry about being able to unmount
481 # from inside.
482 if SAVED_PREF=$(gconftool-2 -g ${AUTOMOUNT_PREF} 2>/dev/null); then
483 if [ "${SAVED_PREF}" != "false" ]; then
484 if [ $(gconftool-2 -s --type=boolean ${AUTOMOUNT_PREF} false) ]; then
485 warn "-- Note: USB sticks may be automounted by your host OS."
486 warn "-- Note: If you plan to burn bootable media, you may need to"
487 warn "-- Note: unmount these devices manually, or run image_to_usb.sh"
488 warn "-- Note: outside the chroot."
489 fi
490 fi
491 fi
492 # Always write the temp file so we can read it when exiting
493 echo "${SAVED_PREF:-false}" > "${FLAGS_chroot}${SAVED_AUTOMOUNT_PREF_FILE}"
494
Mike Frysinger926a4b92012-06-27 15:22:28 -0400495 # Fix permissions on ccache tree. If this is a fresh chroot, then they
496 # might not be set up yet. Or if the user manually `rm -rf`-ed things,
497 # we need to reset it. Otherwise, gcc itself takes care of fixing things
498 # on demand, but only when it updates.
499 ccache_dir="${FLAGS_chroot}/var/cache/distfiles/ccache"
500 if [[ ! -d ${ccache_dir} ]]; then
501 sudo mkdir -p -m 2775 "${ccache_dir}"
502 fi
503 sudo find -H "${ccache_dir}" -type d -exec chmod 2775 {} + &
504 sudo find -H "${ccache_dir}" -gid 0 -exec chgrp 250 {} + &
505
Mike Frysinger94717e32011-09-21 00:10:44 -0400506 # Configure committer username and email in chroot .gitconfig. Change
507 # to the root directory first so that random $PWD/.git/config settings
508 # do not get picked up. We want to stick to ~/.gitconfig only.
509 ident=$(cd /; git var GIT_COMMITTER_IDENT || :)
510 ident_name=${ident%% <*}
511 ident_email=${ident%%>*}; ident_email=${ident_email##*<}
David James342f1562011-07-15 15:21:18 -0700512 git config -f ${FLAGS_chroot}/home/${USER}/.gitconfig --replace-all \
Mike Frysinger94717e32011-09-21 00:10:44 -0400513 user.name "${ident_name}" || true
David James342f1562011-07-15 15:21:18 -0700514 git config -f ${FLAGS_chroot}/home/${USER}/.gitconfig --replace-all \
Mike Frysinger94717e32011-09-21 00:10:44 -0400515 user.email "${ident_email}" || true
David James342f1562011-07-15 15:21:18 -0700516
Matt Tennant298f61a2012-06-25 21:54:33 -0700517 # Certain files get copied into the chroot when entering.
518 for fn in "${FILES_TO_COPY_TO_CHROOT[@]}"; do
Matt Tennantf7c9e772012-02-08 17:06:26 -0800519 copy_into_chroot_if_exists "${HOME}/${fn}" "/home/${USER}/${fn}"
520 done
Peter Mayo4411efe2012-09-21 04:41:27 -0400521 promote_api_keys
Matt Tennantd4316fe2011-08-30 12:06:42 -0700522
Mike Frysinger6601c522011-08-15 11:05:39 -0400523 # Make sure user's requested locales are available
524 # http://crosbug.com/19139
Mike Frysinger4fc9c272011-08-17 15:23:19 -0400525 # And make sure en_US{,.UTF-8} are always available as
526 # that what buildbot forces internally
527 locales=$(printf '%s\n' en_US en_US.UTF-8 ${LANG} \
Mike Frysinger6601c522011-08-15 11:05:39 -0400528 $LC_{ADDRESS,ALL,COLLATE,CTYPE,IDENTIFICATION,MEASUREMENT,MESSAGES} \
529 $LC_{MONETARY,NAME,NUMERIC,PAPER,TELEPHONE,TIME} | \
530 sort -u | sed '/^C$/d')
531 gen_locales=()
532 for l in ${locales}; do
533 if [[ ${l} == *.* ]]; then
534 enc=${l#*.}
535 else
536 enc="ISO-8859-1"
537 fi
538 case $(echo ${enc//-} | tr '[:upper:]' '[:lower:]') in
539 utf8) enc="UTF-8";;
540 esac
541 gen_locales=("${gen_locales[@]}" "${l} ${enc}")
542 done
Mike Frysinger4d258cd2011-09-15 16:17:49 -0400543 if [[ ${#gen_locales[@]} -gt 0 ]] ; then
544 # Force LC_ALL=C to workaround slow string parsing in bash
545 # with long multibyte strings. Newer setups have this fixed,
546 # but locale-gen doesn't need to be run in any locale in the
547 # first place, so just go with C to keep it fast.
548 sudo -- chroot "$FLAGS_chroot" env LC_ALL=C locale-gen -q -u \
549 -G "$(printf '%s\n' "${gen_locales[@]}")"
550 fi
Mike Frysinger6601c522011-08-15 11:05:39 -0400551
Dale Curtis98631732011-05-05 16:16:59 -0700552 # Fix permissions on shared memory to allow non-root users access to POSIX
Mike Frysinger82649172011-09-21 00:18:14 -0400553 # semaphores. Avoid the sudo call if possible (sudo is slow).
554 if [ -n "$(find "${FLAGS_chroot}/dev/shm" ! -perm 777)" ] ; then
555 sudo chmod -R 777 "${FLAGS_chroot}/dev/shm"
556 fi
Chris Wolfe916b1f12012-04-30 16:03:06 -0400557
558 # If the private overlays are installed, gsutil can use those credentials.
Gilad Arnold264f64d2012-09-06 14:01:45 -0700559 # We're also installing credentials for use by sudoed invocations.
560 boto='src/private-overlays/chromeos-overlay/googlestorage_account.boto'
561 if [ -s "${FLAGS_trunk}/${boto}" ]; then
562 if [ ! -e "${FLAGS_chroot}/home/${USER}/.boto" ]; then
Chris Wolfe916b1f12012-04-30 16:03:06 -0400563 ln -s "trunk/${boto}" "${FLAGS_chroot}/home/${USER}/.boto"
564 fi
Gilad Arnold264f64d2012-09-06 14:01:45 -0700565 if [ ! -e "${FLAGS_chroot}/root/.boto" ]; then
566 sudo ln -s "../home/${USER}/trunk/${boto}" "${FLAGS_chroot}/root/.boto"
567 fi
Chris Wolfe916b1f12012-04-30 16:03:06 -0400568 fi
569
570 # Have found a few chroots where ~/.gsutil is owned by root:root, probably
571 # as a result of old gsutil or tools. This causes permission errors when
572 # gsutil cp tries to create its cache files, so ensure the user can
573 # actually write to their directory.
574 gsutil_dir="${FLAGS_chroot}/home/${USER}/.gsutil"
575 if [ -d "${gsutil_dir}" ] && [ ! -w "${gsutil_dir}" ]; then
576 sudo chown -R "${USER}:$(id -gn)" "${gsutil_dir}"
577 fi
David James546747b2010-03-23 15:19:43 -0700578 ) 200>>"$LOCKFILE" || die "setup_env failed"
rspangler@google.comd74220d2009-10-09 20:56:14 +0000579}
580
Mike Frysinger6b1abb22012-05-11 13:44:06 -0400581teardown_env() {
Doug Andersona8d9cc12011-02-02 15:47:00 -0800582 # Validate sudo timestamp before entering the critical section so that we
583 # don't stall for a password while we have the lockfile.
Doug Anderson3d7fa3a2011-02-02 16:10:34 -0800584 # Don't use sudo -v since that has issues on machines w/ no password.
585 sudo echo "" > /dev/null
Doug Andersona8d9cc12011-02-02 15:47:00 -0800586
Andrew de los Reyesc9317ea2010-02-10 13:16:36 -0800587 # Only teardown if we're the last enter_chroot to die
Andrew de los Reyesc9317ea2010-02-10 13:16:36 -0800588 (
589 flock 200
590
591 # check each pid in $LOCKFILE to see if it's died unexpectedly
592 TMP_LOCKFILE="$LOCKFILE.tmp"
593
594 echo -n > "$TMP_LOCKFILE" # Erase/reset temp file
595 cat "$LOCKFILE" | while read PID; do
596 if [ "$PID" = "$$" ]; then
597 # ourself, leave PROC_NAME empty
598 PROC_NAME=""
599 else
600 PROC_NAME=$(ps --pid $PID -o comm=)
601 fi
602
603 if [ ! -z "$PROC_NAME" ]; then
604 # All good, keep going
605 echo "$PID" >> "$TMP_LOCKFILE"
606 fi
607 done
608 # Remove any dups from lock file while installing new one
Mike Frysinger61e4f282011-09-20 22:37:22 -0400609 sort -u -n "$TMP_LOCKFILE" > "$LOCKFILE"
Andrew de los Reyesc9317ea2010-02-10 13:16:36 -0800610
David Jamesc9ca3db2012-07-09 08:12:26 -0700611 SAVED_PREF=$(<"${FLAGS_chroot}${SAVED_AUTOMOUNT_PREF_FILE}")
612 if [ "${SAVED_PREF}" != "false" ]; then
613 gconftool-2 -s --type=boolean ${AUTOMOUNT_PREF} ${SAVED_PREF} || \
614 warn "could not re-set your automount preference."
615 fi
616
Andrew de los Reyesc9317ea2010-02-10 13:16:36 -0800617 if [ -s "$LOCKFILE" ]; then
Don Garretta0e7ea12011-02-07 18:39:59 -0800618 debug "At least one other pid is running in the chroot, so not"
619 debug "tearing down env."
Andrew de los Reyesc9317ea2010-02-10 13:16:36 -0800620 else
Zdenek Behane28239d2011-04-07 00:37:20 +0200621 debug "Stopping syncer process"
Taylor Hutt25bf9492011-07-27 13:54:35 -0700622 # If another process entering the chroot is blocked on this
623 # flock in setup_env(), it can be a race condition.
624 #
625 # When this locked region is exited, the setup_env() flock can
626 # be entered before the script can exit and the /proc entry for
627 # the PID is removed. The newly-created chroot will not end up
628 # with a syncer process. To avoid that situation, remove the
629 # syncer PID file.
630 #
631 # The syncer PID file should also be removed because the kernel
632 # will reuse PIDs. It's possible that the PID in the syncer PID
633 # has been reused by another process; make sure we don't skip
634 # starting the syncer process when this occurs by deleting the
635 # PID file.
Mike Frysinger61e4f282011-09-20 22:37:22 -0400636 kill $(<"${SYNCERPIDFILE}") && \
Mike Frysinger470be992011-09-28 11:53:56 -0400637 { rm -f "${SYNCERPIDFILE}" 2>/dev/null || \
638 sudo rm -f "${SYNCERPIDFILE}" ; } ||
639 debug "Unable to clean up syncer process.";
Zdenek Behane28239d2011-04-07 00:37:20 +0200640
Don Garretta0e7ea12011-02-07 18:39:59 -0800641 debug "Unmounting chroot environment."
Mike Frysinger1aa61242011-09-15 17:46:44 -0400642 safe_umount_tree "${MOUNTED_PATH}/"
Andrew de los Reyesc9317ea2010-02-10 13:16:36 -0800643 fi
David James546747b2010-03-23 15:19:43 -0700644 ) 200>>"$LOCKFILE" || die "teardown_env failed"
rspangler@google.comd74220d2009-10-09 20:56:14 +0000645}
646
Greg Spencer798d75f2011-02-01 22:04:49 -0800647if [ $FLAGS_mount -eq $FLAGS_TRUE ]; then
rspangler@google.comd74220d2009-10-09 20:56:14 +0000648 setup_env
Don Garretta0e7ea12011-02-07 18:39:59 -0800649 info "Make sure you run"
650 info " $0 --unmount"
651 info "before deleting $FLAGS_chroot"
652 info "or you'll end up deleting $FLAGS_trunk too!"
rspangler@google.comd74220d2009-10-09 20:56:14 +0000653 exit 0
654fi
655
Greg Spencer798d75f2011-02-01 22:04:49 -0800656if [ $FLAGS_unmount -eq $FLAGS_TRUE ]; then
rspangler@google.comd74220d2009-10-09 20:56:14 +0000657 teardown_env
658 exit 0
659fi
660
661# Make sure we unmount before exiting
662trap teardown_env EXIT
663setup_env
664
Brian Harring35767822012-02-01 23:50:45 -0800665CHROOT_PASSTHRU=(
666 "BUILDBOT_BUILD=$FLAGS_build_number"
Brian Harring35767822012-02-01 23:50:45 -0800667 "CHROMEOS_RELEASE_APPID=${CHROMEOS_RELEASE_APPID:-{DEV-BUILD}}"
Brian Harring35767822012-02-01 23:50:45 -0800668 "EXTERNAL_TRUNK_PATH=${FLAGS_trunk}"
Brian Harring35767822012-02-01 23:50:45 -0800669)
Liam McLoughlin3b11b452011-03-14 16:04:07 -0700670
Brian Harring06d3c2e2012-08-23 07:35:43 -0700671# Add the standard proxied variables, and a few we specifically
672# export for script usage; USE/GCC_GITHASH are for ebuilds/portage,
673# CHROMEOS_VERSION_* is for cros_set_lsb_release and local AU server
674# (builders export this for marking reasons).
675KEEP_VARS=(
676 CHROMEOS_VERSION_{TRACK,AUSERVER,DEVSERVER}
677 USE GCC_GITHASH
678)
679for var in "${ENVIRONMENT_WHITELIST[@]}" "${KEEP_VARS[@]}"; do
680 [ "${!var+set}" = "set" ] && CHROOT_PASSTHRU+=( "${var}=${!var}" )
Mario Limonciello7052ae12011-05-05 12:00:49 -0500681done
682
derat@google.com4e7a92b2009-11-21 23:44:14 +0000683# Run command or interactive shell. Also include the non-chrooted path to
684# the source trunk for scripts that may need to print it (e.g.
685# build_image.sh).
Brian Harring35767822012-02-01 23:50:45 -0800686
687if [ $FLAGS_early_make_chroot -eq $FLAGS_TRUE ]; then
688 cmd=( /bin/bash -l -c 'env "$@"' -- )
689elif [ ! -x "${FLAGS_chroot}/usr/bin/sudo" ]; then
690 # Complain that sudo is missing.
691 error "Failing since the chroot lacks sudo."
692 error "Requested enter_chroot command was: $@"
693 exit 127
694else
695 cmd=( sudo -i -u "$USER" )
696fi
697
698sudo -- chroot "${FLAGS_chroot}" "${cmd[@]}" "${CHROOT_PASSTHRU[@]}" "$@"
rspangler@google.comd74220d2009-10-09 20:56:14 +0000699
700# Remove trap and explicitly unmount
701trap - EXIT
702teardown_env