From 5e1828a524eeada0cd597354b8d852b88008787b Mon Sep 17 00:00:00 2001 From: Michael Scherer Date: Sun, 15 Sep 2013 17:21:29 +0200 Subject: [PATCH 1/2] add jail module, based on lxc and chroot connexion plugin --- lib/ansible/runner/connection_plugins/jail.py | 144 ++++++++++++++++++ 1 file changed, 144 insertions(+) create mode 100644 lib/ansible/runner/connection_plugins/jail.py diff --git a/lib/ansible/runner/connection_plugins/jail.py b/lib/ansible/runner/connection_plugins/jail.py new file mode 100644 index 00000000000..7c34a284f30 --- /dev/null +++ b/lib/ansible/runner/connection_plugins/jail.py @@ -0,0 +1,144 @@ +# Based on local.py (c) 2012, Michael DeHaan +# and chroot.py (c) 2013, Maykel Moya +# (c) 2013, Michael Scherer +# +# This file is part of Ansible +# +# Ansible is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, either version 3 of the License, or +# (at your option) any later version. +# +# Ansible is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with Ansible. If not, see . + +import distutils.spawn +import traceback +import os +import shutil +import subprocess +from ansible import errors +from ansible.callbacks import vvv + +class Connection(object): + ''' Local chroot based connections ''' + + def _search_executable(self, executable): + cmd = distutils.spawn.find_executable(executable) + if not cmd: + raise errors.AnsibleError("%s command not found in PATH") % executable + return cmd + + def list_jails(self): + p = subprocess.Popen([self.jls_cmd, '-q', 'name'], + cwd=self.runner.basedir, + stdin=subprocess.PIPE, + stdout=subprocess.PIPE, stderr=subprocess.PIPE) + + stdout, stderr = p.communicate() + + return stdout.split() + + def get_jail_path(self): + p = subprocess.Popen([self.jls_cmd, '-j', self.jail, '-q', 'path'], + cwd=self.runner.basedir, + stdin=subprocess.PIPE, + stdout=subprocess.PIPE, stderr=subprocess.PIPE) + + stdout, stderr = p.communicate() + # remove \n + return stdout[:-1] + + + + def __init__(self, runner, host, port, *args, **kwargs): + self.jail = host + self.runner = runner + self.host = host + + if os.geteuid() != 0: + raise errors.AnsibleError("jail connection requires running as root") + + self.jls_cmd = self._search_executable('jls') + self.jexec_cmd = self._search_executable('jexec') + + if not self.jail in self.list_jails(): + raise errors.AnsibleError("incorrect jail name %s" % self.jail) + + + self.host = host + # port is unused, since this is local + self.port = port + + def connect(self, port=None): + ''' connect to the chroot; nothing to do here ''' + + vvv("THIS IS A LOCAL CHROOT DIR", host=self.jail) + + return self + + # a modifier + def _generate_cmd(self, executable, cmd): + if executable: + local_cmd = [self.jexec_cmd, self.jail, executable, '-c', cmd] + else: + local_cmd = '%s "%s" %s' % (self.jexec_cmd, self.jail, cmd) + return local_cmd + + def exec_command(self, cmd, tmp_path, sudo_user, sudoable=False, executable='/bin/sh'): + ''' run a command on the chroot ''' + + # We enter chroot as root so sudo stuff can be ignored + local_cmd = self._generate_cmd(executable, cmd) + + vvv("EXEC %s" % (local_cmd), host=self.jail) + p = subprocess.Popen(local_cmd, shell=isinstance(local_cmd, basestring), + cwd=self.runner.basedir, + stdin=subprocess.PIPE, + stdout=subprocess.PIPE, stderr=subprocess.PIPE) + + stdout, stderr = p.communicate() + return (p.returncode, '', stdout, stderr) + + def _normalize_path(self, path, prefix): + if not path.startswith(os.path.sep): + path = os.path.join(os.path.sep, path) + normpath = os.path.normpath(path) + return os.path.join(prefix, normpath[1:]) + + def _copy_file(self, in_path, out_path): + if not os.path.exists(in_path): + raise errors.AnsibleFileNotFound("file or module does not exist: %s" % in_path) + try: + shutil.copyfile(in_path, out_path) + except shutil.Error: + traceback.print_exc() + raise errors.AnsibleError("failed to copy: %s and %s are the same" % (in_path, out_path)) + except IOError: + traceback.print_exc() + raise errors.AnsibleError("failed to transfer file to %s" % out_path) + + def put_file(self, in_path, out_path): + ''' transfer a file from local to chroot ''' + + out_path = self._normalize_path(out_path, self.get_jail_path() ) + vvv("PUT %s TO %s" % (in_path, out_path), host=self.jail) + + self._copy_file(in_path, out_path) + + def fetch_file(self, in_path, out_path): + ''' fetch a file from chroot to local ''' + + in_path = self._normalize_path(in_path, self.get_jail_path()) + vvv("FETCH %s TO %s" % (in_path, out_path), host=self.jail) + + self._copy_file(in_path, out_path) + + def close(self): + ''' terminate the connection; nothing to do here ''' + pass From a6be1edd96ed304d70d26548d331f71966ef1784 Mon Sep 17 00:00:00 2001 From: Michael Scherer Date: Sun, 15 Sep 2013 17:41:20 +0200 Subject: [PATCH 2/2] add inventory script for listing jails on *bsd --- plugins/inventory/jail.py | 37 +++++++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) create mode 100755 plugins/inventory/jail.py diff --git a/plugins/inventory/jail.py b/plugins/inventory/jail.py new file mode 100755 index 00000000000..c6caf38289a --- /dev/null +++ b/plugins/inventory/jail.py @@ -0,0 +1,37 @@ +#!/usr/bin/env python + +# (c) 2013, Michael Scherer +# +# This file is part of Ansible, +# +# Ansible is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, either version 3 of the License, or +# (at your option) any later version. +# +# Ansible is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with Ansible. If not, see . + +from subprocess import Popen,PIPE +import sys +import json + +result = {} +result['all'] = {} + +pipe = Popen(['jls', '-q', 'name'], stdout=PIPE, universal_newlines=True) +result['all']['hosts'] = [x[:-1] for x in pipe.stdout.readlines()] +result['all']['vars'] = {} +result['all']['vars']['ansible_connection'] = 'jail' + +if len(sys.argv) == 2 and sys.argv[1] == '--list': + print json.dumps(result) +elif len(sys.argv) == 3 and sys.argv[1] == '--host': + print json.dumps({'ansible_connection': 'jail'}) +else: + print "Need a argument, either --list or --host "