Compare commits

...
7 Commits
Author SHA1 Message Date
Miles WardandClaude Opus 4.8 06695c3d77 v0.5.9: El Torito boot detection + retroactive re-introspect; static SSO login button
Storage / boot detection
- Add El Torito boot-catalog detection to ISO introspection. This is the
  authoritative "can this boot at all?" signal: any ISO with a boot catalog
  (BSDs, ESXi, firmware tools, custom spins) is bootable via iPXE sanboot;
  a data/appliance ISO (e.g. a VMware vCenter bundle) has none and is
  honestly flagged. Replaces the crude ">1.5 GB ⇒ unbootable" size guess.
- Re-introspect stale LOCAL ISOs on startup via an introspection-revision
  gate (INTROSPECT_REV). ISOs uploaded by an older binary carried a frozen
  family/boot profile — most visibly a Windows 11 ISO tagged Unknown before
  the UDF/UTF-16 detection landed, which then showed "won't boot" forever.
  An upgrade now re-probes and fixes them in place; no delete-and-re-upload.
- WebUI bootability() keys off family / kernel / el_torito / remote-source
  instead of the size heuristic; dashboard family counts now bucket
  Windows / Linux / other honestly instead of lumping everything non-Windows
  under "Linux".

SSO login button
- The "Sign in with …" button keyed off the auth-gated /api/sso, which 401s
  pre-auth — so the button only survived on a stale in-memory config and
  vanished instance-wide on any fresh login-page load. Ship a minimal,
  non-sensitive SSO descriptor (enabled + idp_name + idp_logo_url, no
  metadata/entity-ID) on the public /api/me; the login card reads that.
  The button is now static whenever SSO is usable.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-06-05 11:47:41 -04:00
mward4 cb51b8db75 Update README.md 2026-06-05 04:34:28 -04:00
Miles Ward d6a9df85d7 chore: drop local editor settings folder from the repo 2026-06-05 04:30:41 -04:00
Miles WardandClaude Opus 4.8 9fc9a9a1af v0.5.8: Windows ISOs just work (HTTP sanboot) + Storage UX
Windows boot, the "less is more" way. Windows ISOs now boot via iPXE
HTTP sanboot of the raw image — iPXE exposes the unmodified ISO as an
emulated CD backed by on-demand HTTP range reads, and Windows Setup
boots from it. This replaces the wimboot+SMB chain, which needed an SMB
server the host often can't provide (:445 collisions), served in-ISO
files via an ISO9660 lookup that failed on UDF-only Win11 ISOs, and was
gated behind a Settings toggle the WebUI never even exposed (so Windows
never booted). Now it needs only the HTTP port — works in any
environment, SMB or not — and nothing is injected into Windows (no
httpdisk.sys, no test certs, no trust-store changes; fully within the
project's hard rules).

- iso-store/store.rs: WindowsPe boot entry -> BootKind::SanBootIso of the
  raw iso/<id>.iso (render_entry already emits `sanboot --no-describe`).
- iso-store/introspect.rs: broaden Windows detection for UDF-only Win10/11
  ISOs — UTF-16LE markers (boot.wim/bootmgr/install.wim/microsoft),
  extra ASCII markers, and a filename heuristic, since their volume
  labels are cryptic and filenames are UTF-16. + unit tests.
- http-api/ipxe_script.rs: Windows installers submenu shows whenever a
  Windows ISO is present — no toggle, no "disabled in Settings".
- webui: dashboard no longer flags Windows ISOs (they boot now); the
  generic large-ISO warning reworded to read sensibly for genuinely
  non-bootable images (e.g. VMware VCSA appliance bundles).

Storage UX:
- Available images listed alphabetically by filename.
- Upload gains a Cancel button (aborts the chunk + discards the partial).
- beforeunload warning while an upload is in flight.

263 tests pass, clippy clean. NOTE: actual Windows boot is validated on
real hardware — code/script/range-serving are validated here.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-06-04 21:24:15 -04:00
Miles WardandClaude Opus 4.8 ac433b30e9 v0.5.7: skip PNG boot-menu background on legacy BIOS clients
The menu emitted `console --picture … || console`, relying on the
trailing `|| console` to recover on iPXE builds without IMAGE_PNG +
CONSOLE_FRAMEBUFFER. On legacy BIOS (`undionly.kpxe`, no PNG) the
`--picture` attempt misbehaves before the fallback can recover — it
tries to set a framebuffer mode the BIOS console can't honour — so the
boot menu fails to render on BIOS clients.

Fix: gate the command on `iseq ${platform} efi`, so BIOS (`pcbios`)
clients never issue `console --picture` at all and drop straight to the
plain text menu, while UEFI clients still get the graphical background.
This is automatic and per-client — a mixed BIOS+UEFI fleet each gets the
right treatment with no operator toggle. A PNG-less UEFI build (upstream
i386-efi) still falls back gracefully through the same `|| console`.

Menu snapshot updated to match. 254 tests pass, clippy clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-06-03 19:28:02 -04:00
Miles WardandClaude Opus 4.8 c0d17fa9ca v0.5.6: advertise the HTTP port in client-facing boot URLs
The base URL handed to PXE clients was built as `http://{ip}` with no
port, ignoring OPENPXE_HTTP_PORT. Every client-facing URL derives from
it — the DHCP-proxy iPXE filename, UEFI HTTP boot, and the boot menu's
kernel/initrd/ISO links — so any non-80 deployment told clients to fetch
:80 (the wrong service). On Unraid that's the webGUI, which 301s to
https; iPXE (no TLS) then fails the chain with "Operation not supported".
This broke the exact configuration the Unraid template recommends
(HTTP port 4200, to avoid the webGUI on :80).

Fix: build_public_base_url(ip, port) includes the port unless it's 80,
so http://10.0.0.5 stays clean while http://10.0.0.5:4200 is reachable.
One source of truth, so the whole URL surface is corrected at once.
Regression-tested (port included for 4200/8080, omitted for 80).

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-06-03 18:49:50 -04:00
Miles WardandClaude Opus 4.8 edf3a69daa docs: rewrite README — production/VC-ready, logo + v0.5.5 feature set
Replaces the stale v0.4.1 README with a polished, accurate overview:
centered brand-mark header + tagline + badges, a "Why OpenPXE" pitch,
a scannable Highlights section, and a "Built in Rust" section framed on
real properties (single ~18MB static musl binary, no GC, async Tokio,
workspace-wide unsafe deny, OpenSSL-free pure-Rust crypto, sub-minute
zigbuild images).

Surfaces everything shipped since v0.4.1: SMB + NFS + SFTP remote ISO
libraries (with a comparison table), SAML SSO, branding, notifications,
unattended installs, per-MAC host bindings, and layered figment config.
Quick-start, env table, OpenShift, and health/observability all updated
to v0.5.5. Adds docs/openpxe-logo.svg (render-safe static copy of the
web-UI mark) for the header.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-06-03 12:07:31 -04:00
18 changed files with 711 additions and 361 deletions
+3
View File
@@ -11,3 +11,6 @@ data/work/
.claude/settings.local.json .claude/settings.local.json
.claude/worktrees/ .claude/worktrees/
.claude/scheduled_tasks.lock .claude/scheduled_tasks.lock
# local editor / agent settings (not part of the project)
.claude/
Generated
+8 -8
View File
@@ -2669,7 +2669,7 @@ checksum = "c08d65885ee38876c4f86fa503fb49d7b507c2b62552df7c70b2fce627e06381"
[[package]] [[package]]
name = "openpxe" name = "openpxe"
version = "0.5.5" version = "0.5.9"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"axum", "axum",
@@ -2691,7 +2691,7 @@ dependencies = [
[[package]] [[package]]
name = "openpxe-core" name = "openpxe-core"
version = "0.5.5" version = "0.5.9"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"base64", "base64",
@@ -2718,7 +2718,7 @@ dependencies = [
[[package]] [[package]]
name = "openpxe-dhcp-proxy" name = "openpxe-dhcp-proxy"
version = "0.5.5" version = "0.5.9"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"bytes", "bytes",
@@ -2732,7 +2732,7 @@ dependencies = [
[[package]] [[package]]
name = "openpxe-http-api" name = "openpxe-http-api"
version = "0.5.5" version = "0.5.9"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"axum", "axum",
@@ -2768,7 +2768,7 @@ dependencies = [
[[package]] [[package]]
name = "openpxe-ipxe-assets" name = "openpxe-ipxe-assets"
version = "0.5.5" version = "0.5.9"
dependencies = [ dependencies = [
"openpxe-core", "openpxe-core",
"rust-embed", "rust-embed",
@@ -2778,7 +2778,7 @@ dependencies = [
[[package]] [[package]]
name = "openpxe-iso-store" name = "openpxe-iso-store"
version = "0.5.5" version = "0.5.9"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"bcrypt", "bcrypt",
@@ -2807,7 +2807,7 @@ dependencies = [
[[package]] [[package]]
name = "openpxe-tftp" name = "openpxe-tftp"
version = "0.5.5" version = "0.5.9"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"bytes", "bytes",
@@ -2821,7 +2821,7 @@ dependencies = [
[[package]] [[package]]
name = "openpxe-webui" name = "openpxe-webui"
version = "0.5.5" version = "0.5.9"
[[package]] [[package]]
name = "p256" name = "p256"
+1 -1
View File
@@ -12,7 +12,7 @@ members = [
] ]
[workspace.package] [workspace.package]
version = "0.5.5" version = "0.5.9"
edition = "2021" edition = "2021"
rust-version = "1.95" rust-version = "1.95"
license = "MIT OR Apache-2.0" license = "MIT OR Apache-2.0"
+200 -231
View File
@@ -1,301 +1,270 @@
# OpenPXE <p align="center">
<img src="docs/openpxe-logo.svg" alt="OpenPXE" width="104" height="104" />
</p>
Container-native PXE boot server. A Rust reimplementation of <h1 align="center">OpenPXE</h1>
[iVentoy (ventoy/PXE)](https://github.com/ventoy/PXE), designed from scratch
for Docker/OCI and OpenShift. Upload `.iso` files via the web UI; network
clients PXE-boot them.
> **Status:** v0.4.1 / pre-beta. Phases 15 complete: full PXE stack, <p align="center">
> Queued Deployment queue, NFS-share ISO sources, live tracing log + an <strong>Container-native network boot &amp; OS deployment — built in Rust.</strong>
> operator terminal, per-MAC host bindings, Prometheus `/metrics`, </p>
> light/dark theme toggle, animated OpenPXE imaging-progress widget,
> chunked ISO uploads, and per-ISO boot passwords. The test suite and
> clippy are part of the release checklist. Ready for real-hardware validation.
## Design non-negotiables <p align="center">
Drag in an ISO. PXE-boot and image an entire fleet from a browser.<br/>
No iPXE scripting. No <code>dnsmasq</code> + <code>tftpd</code> + Samba glue. No glibc. No garbage collector.
</p>
1. **Fully offline / air-gap deployable.** Zero CDN assets. Zero external <p align="center">
HTTP calls from the server, the browser, or the generated iPXE scripts. <img alt="release" src="https://img.shields.io/badge/release-v0.5.8-2874d7" />
Build the container once, run forever disconnected. <img alt="license" src="https://img.shields.io/badge/license-MIT%20%7C%20Apache--2.0-59824f" />
2. **iPXE is a backend implementation detail.** No `.ipxe` upload path, no <img alt="rust" src="https://img.shields.io/badge/built%20with-Rust-fb8841?logo=rust&logoColor=white" />
manual script editing, no iPXE terminology in the UI. Every knob in the <img alt="container" src="https://img.shields.io/badge/container--native-OCI%20%C2%B7%20OpenShift-2496ED?logo=docker&logoColor=white" />
web UI maps to a specific script-generation behavior inside the binary. <img alt="binary" src="https://img.shields.io/badge/static-musl%20%C2%B7%20~18MB-330f1f" />
3. **The client trust store is off-limits.** No test-signed drivers, no </p>
`bcdedit /set testsigning on`, no certificates injected into WinPE or
the target OS.
## What it does ---
1. **DHCP proxy** (RFC 4578). Coexists with your existing DHCP server — OpenPXE turns bare-metal provisioning into a single container with a web UI. It's a
never assigns IPs. Listens on UDP 67 + UDP 4011. ground-up Rust reimplementation of [iVentoy (ventoy/PXE)](https://github.com/ventoy/PXE),
2. **TFTP server** (RFC 1350 + RFC 2347/2348/2349/7440 option negotiation) designed for Docker/OCI and OpenShift instead of a Windows desktop — so it drops onto
that serves architecture-specific iPXE binaries to firmware PXE ROMs. an Unraid box, a Linux server, or a Kubernetes cluster and just runs.
3. **HTTP server** that serves the web UI, the generated iPXE boot scripts,
raw ISOs (with Range), and files inside ISOs without prior extraction.
4. **ISO introspection**: auto-detects the distro family and generates the
appropriate kernel+initrd or wimboot chain. No manual config.
5. **Hierarchical PXE menu** mirroring the Phase 2 spec:
```
Default > Boot from Local HDD
Installers > Linux Installers / Windows Installers
Tools > Utilities / OpenPXE Shell / Network Card Info
Queued Deployment
```
6. **Queued Deployment queue** — the coordinated launch flow. A client that
selects *Queued Deployment* gets a numbered position and waits. The
operator picks an ISO in the web UI and fires it to every waiting
client simultaneously.
7. **Web UI** (Netbox-style): sidebar nav (Dashboard / Network / Queue /
Storage / Hosts / Terminal / About), light + dark themes
(toggle top-right or press `T`), animated OpenPXE progress
widget when devices are imaging. All assets served from the binary —
no external requests.
8. **Per-MAC host bindings.** Pin a MAC to a boot target and the client
skips the menu, chains straight through.
9. **Prometheus metrics** at `/metrics` — DHCP replies by arch, TFTP
transfer counts and bytes, HTTP request counts by route, queue /
imaging gauges, uptime, build info. Plain text exposition format,
no external metrics framework dependency.
8. **Settings API** lets you change the default boot-menu timeout (default
600s), the timeout action (stay / Local HDD / Queued Deployment), and
feature toggles like Windows ISO support. The iPXE scripts regenerate
on every request using current settings.
### Architectures supported on day one Upload `.iso` files (or point at a remote share), and any machine on the network boots
them — Linux installers, live tools, or stock Windows setup — with **zero iPXE knowledge
required by the operator.**
| DHCP option 93 | Architecture | Binary served | > **Status — v0.5.5, late pre-beta.** The full PXE stack, web UI, remote ISO libraries
|----------------|-----------------|-------------------------| > (SMB/NFS/SFTP), Windows deployment, queued fleet rollout, SAML SSO, and Prometheus
| `0x0000` | Legacy x86 BIOS | `undionly.kpxe` | > metrics are implemented and test-covered. The release checklist gates every tag on the
| `0x0006` | IA32 UEFI | `snponly-i386.efi` | > full test suite + `clippy`. Currently in real-hardware validation.
| `0x0007`/`0x0009` | x86_64 UEFI | `snponly.efi` |
| `0x000B` | ARM64 UEFI | `snponly-arm64.efi` |
UEFI firmware that sends `HTTPClient` in option 60 is handled too — we ## Why OpenPXE
skip TFTP and respond with an HTTP URL.
## Quick start — MVP container (recommended) Standing up network boot the traditional way means hand-wiring `dnsmasq`, a TFTP daemon,
hand-written iPXE menu scripts, an HTTP server, and Samba — then keeping that fragile
stack alive, and discovering none of it containerizes cleanly (kernel-mount NFS, raw
sockets, `CAP_SYS_ADMIN`). iVentoy solved the UX beautifully, but it's a Windows GUI app.
OpenPXE collapses that whole stack into **one statically-linked binary in one container**:
- **A web UI does everything.** iPXE is an internal implementation detail — there is no
script upload, no `.ipxe` editing, no PXE jargon in the interface.
- **It runs anywhere a container runs.** No kernel modules, no privileged mode — proxy-mode
DHCP + `NET_BIND_SERVICE` is the entire requirement. Verified on Unraid, plain Docker,
and OpenShift's restricted SCC.
- **It's air-gap native.** Zero CDN assets, zero outbound calls from the server, browser,
or generated boot scripts. Build the image once, run it forever, disconnected.
## Highlights
#### Boot stack
- **DHCP proxy** (RFC 4578) that coexists with your existing DHCP — it never hands out IPs.
- **TFTP** (RFC 1350 + 2347/2348/2349/7440 option negotiation) serving arch-correct iPXE firmware.
- **HTTP** serving the UI, generated boot scripts, raw ISOs (with byte-range), and files
*inside* ISOs with no prior extraction.
- **Graphical iPXE boot menu** built from your uploads, with a PNG background and a clean
hierarchy — generated fresh on every request from current settings.
#### ISO management & remote libraries
- **Drag-and-drop chunked uploads** that don't 502 on multi-GB images.
- **Automatic introspection** — detects the distro family and generates the right
kernel+initrd or Windows `wimboot` chain. No manual config.
- **Remote ISO libraries, streamed on demand** (no local cache) over **SMB, NFS, or SFTP**
see the table below.
#### Fleet deployment
- **Queued Deployment** — clients join a queue and wait; the operator fires one image at
every waiting machine simultaneously.
- **Per-MAC host bindings** — pin a MAC straight to a target (with optional auto hostname,
auto IP, and an unattended answer file); it skips the menu and chains through.
- **Unattended installs** — upload Kickstart / Preseed / Autoinstall / Windows answer files;
they're templated per-host (hostname / IP / MAC) and served only to booting clients.
- **Windows deployment** from a stock Microsoft ISO — **every binary the client runs stays
Microsoft-signed** (details below).
#### Operations & access
- **SAML 2.0 single sign-on** (pure-Rust SP, no OpenSSL/xmlsec) alongside local accounts.
- **Custom branding** — light / dark / PXE-client logos and favicon.
- **Notifications** — Slack / Teams / Discord webhooks and SMTP email on boot events.
- **Prometheus `/metrics`**, a built-in operator **terminal**, live tracing log, and
`/healthz` · `/readyz` probes.
- **Layered config** — defaults → TOML file → `OPENPXE_*` env, in that order.
## Built in Rust
Rust isn't a checkbox here — it's why OpenPXE deploys the way it does:
- **One static binary, ~18 MB.** Compiled to `x86_64-unknown-linux-musl` — no glibc, no
interpreter, no sidecar runtime. The runtime image is "binary + a few CLI tools."
- **No garbage collector, async throughout.** A Tokio runtime drives DHCP, TFTP, HTTP, and
many concurrent multi-GB ISO streams on a tiny, predictable memory footprint — it idles
near-zero and never GC-pauses mid-transfer.
- **Memory-safe by construction.** `unsafe` is **denied workspace-wide**; the only
exceptions are two small, individually-audited FFI calls (`statvfs` for disk usage and a
Samba `SIGHUP`).
- **OpenSSL-free, pure-Rust crypto.** TLS via `rustls`/`ring`; the SAML Service Provider
does XML-DSig verification with RustCrypto — no `xmlsec`, no `libxml2`, no C crypto to
CVE-patch. Even the SMB/NFS/SFTP clients avoid C libraries.
- **Sub-minute, reproducible container builds.** Cross-compiled with `cargo-zigbuild`
(zig as the linker) — a full image builds in well under a minute on a warm cache, with
no QEMU emulation.
## Quick start
### Run the container
```bash ```bash
# 1. Pull bundled iPXE binaries (~2 MB, one-time). # Build the self-contained image (iPXE binaries are fetched + built inside the Dockerfile).
./scripts/fetch-ipxe.sh docker build -f deploy/docker/Dockerfile -t openpxe:0.5.5 .
# 2. Build the container image (~3 min first time). # Run it on the box plugged into your PXE network. Host networking is required in
docker buildx build -f deploy/docker/Dockerfile -t openpxe:0.4.1 --load . # proxy mode so the container sees DHCPDISCOVER broadcasts; set PUBLIC_IP to this
# host's LAN address so advertised boot URLs are reachable.
# 3. Run it on the box plugged into your PXE network. Set PUBLIC_IP to docker run -d --name openpxe --network host \
# this host's LAN address so advertised iPXE URLs are reachable.
docker run -d --name openpxe \
--network host \
-e OPENPXE_PUBLIC_IP=10.0.0.5 \ -e OPENPXE_PUBLIC_IP=10.0.0.5 \
-e OPENPXE_DHCP_MODE=proxy \ -e OPENPXE_DHCP_MODE=proxy \
-v $PWD/data/isos:/var/lib/openpxe/isos \ -v $PWD/data/isos:/var/lib/openpxe/isos \
-v $PWD/data/work:/var/lib/openpxe/work \ -v $PWD/data/work:/var/lib/openpxe/work \
openpxe:0.4.1 openpxe:0.5.5
# 4. Open the UI and drop an ISO in. # Open the UI and drop an ISO in.
open http://10.0.0.5 open http://10.0.0.5
``` ```
Host networking is required in proxy mode so the container sees DHCPDISCOVER > On macOS/Windows, Docker runs inside a Linux VM, so "host network" means the VM — use
broadcasts from the PXE VLAN. On macOS/Windows hosts Docker runs in a Linux > the `openpxe-dev` service in `docker-compose.yml` for API-only testing on a laptop:
VM, so "host" means the VM — use `openpxe-dev` in `docker-compose.yml` for > `OPENPXE_PUBLIC_IP=127.0.0.1 docker compose up openpxe-dev`.
API-only testing on a laptop.
### Quick start — docker compose ### Build from source
```bash ```bash
# MVP / API testing on a laptop (no DHCP, high ports): ./scripts/fetch-ipxe.sh # populate assets/ipxe/ (embedded at compile time)
OPENPXE_PUBLIC_IP=127.0.0.1 docker compose up openpxe-dev cargo run --release # needs root or CAP_NET_BIND_SERVICE for :80/:69
# Real PXE deployment on a Linux host (host network, DHCP proxy on):
OPENPXE_PUBLIC_IP=10.0.0.5 docker compose up openpxe
``` ```
### Multi-arch build + push ### Pre-seed ISOs from a directory
For deploying to x86_64 servers, build both arches in one manifest:
```bash
# One-time: bootstrap a multi-arch builder.
docker buildx create --name openpxe-multi --driver docker-container --use
# Build + push both linux/amd64 and linux/arm64 under one tag.
docker buildx build --builder openpxe-multi \
--platform linux/amd64,linux/arm64 \
-t ghcr.io/YOUR-ORG/openpxe:0.4.1 \
--push \
-f deploy/docker/Dockerfile .
```
On an Apple Silicon host, the amd64 stage runs under QEMU emulation (~10-15 min for a cold cache). On a Linux x86_64 host, both arches build natively at normal speed. CI runners on GitHub Actions with `docker/build-push-action@v5` handle this cleanly.
### Build from source (no container)
```bash
./scripts/fetch-ipxe.sh
cargo run --release # needs NET_BIND_SERVICE or root for :80/:69
```
### Container health probes
| Endpoint | Purpose |
|-------------|---------------------------------------------------------------|
| `/healthz` | Liveness — HTTP stack alive. Always 200. |
| `/readyz` | Readiness — 200 only if iPXE binaries bundled + ISO dir OK. |
| `/api/status` | Full JSON status: versions, assets, counts, live settings, SMB state. |
### Pre-seeding ISOs from a directory
For CI, pre-baked homelab deployments, or a fresh PVC, the binary has a
`seed` subcommand that imports every `*.iso` from a host path through the
same pipeline the web UI uses (introspection + boot-entry generation):
```bash ```bash
docker run --rm \ docker run --rm \
-v /my/iso-library:/seed:ro \ -v /my/iso-library:/seed:ro \
-v openpxe-data:/var/lib/openpxe/isos \ -v openpxe-data:/var/lib/openpxe/isos \
-e OPENPXE_PUBLIC_IP=10.0.0.5 \ -e OPENPXE_PUBLIC_IP=10.0.0.5 \
openpxe:0.4.1 seed --from /seed openpxe:0.5.5 seed --from /seed # add --dry-run to preview
# Dry run first to see what would be imported:
docker run --rm -v /my/iso-library:/seed:ro openpxe:0.4.1 seed --from /seed --dry-run
``` ```
### Environment overrides ## Remote ISO libraries
| Var | Default | Meaning | Point OpenPXE at a NAS and boot ISOs straight off it — **read on demand, no local copy**,
|------------------------|-----------------------------|----------------------------------------| so a 50-ISO library costs zero disk on the OpenPXE host. All three clients are userspace
| `OPENPXE_HTTP_PORT` | `80` | Web UI + boot script HTTP port | (no kernel mounts, no `CAP_SYS_ADMIN`); pick whichever your storage speaks.
| `OPENPXE_TFTP_PORT` | `69` | TFTP port |
| `OPENPXE_DHCP_PORT` | `67` | DHCP server-side port |
| `OPENPXE_DHCP_MODE` | `proxy` | `proxy` or `disabled` |
| `OPENPXE_PUBLIC_IP` | auto-detect | Advertised IP for clients. Startup **fails** if unset and auto-detect returns loopback. |
| `OPENPXE_ISO_DIR` | `/var/lib/openpxe/isos` | Where uploaded ISOs live |
| `OPENPXE_WORK_DIR` | `/var/lib/openpxe/work` | Scratch + runtime settings |
| `OPENPXE_LOG` | `info,openpxe=debug` | `tracing` filter |
## What the boot menu looks like on a real client | Protocol | Implementation | Auth | HTTP Range¹ |
|----------|----------------|------|-------------|
| **NFS** (v3) | Pure-Rust in-process client | Client-IP (server export list) | ✅ |
| **SFTP** (SSH) | Pure-Rust in-process client (`russh`) | Password **or** SSH key · host-key TOFU | ✅ |
| **SMB** / CIFS | Userspace `smbclient` | Guest or username/password | — |
¹ Range support lets clients seek into a multi-GB ISO without downloading what comes
before it — needed for kernel/initrd extraction and `httpdisk`-style boots. NFS and SFTP
expose explicit offsets; the SMB CLI streams sequentially, so SMB-sourced ISOs serve whole-file.
## Supported client architectures
| DHCP option 93 | Architecture | Firmware served |
|----------------|--------------|-----------------|
| `0x0000` | Legacy x86 BIOS | `undionly.kpxe` |
| `0x0006` | IA32 UEFI | `snponly-i386.efi` |
| `0x0007` / `0x0009` | x86_64 UEFI | `snponly.efi` |
| `0x000B` | ARM64 UEFI | `snponly-arm64.efi` |
UEFI firmware that advertises `HTTPClient` (option 60) skips TFTP entirely and is handed an HTTP URL.
## The boot menu, on a real client
``` ```
OpenPXE - network boot menu OpenPXE network boot menu
------------------------- Default ------------------------- ------------------------- Default -------------------------
Boot from Local HDD Boot from Local HDD
----------------------- Installers ----------------------- ----------------------- Installers ------------------------
Linux Installers > Linux Installers >
Windows Installers > (only if enabled in Settings) Windows Installers > (only if enabled in Settings)
-------------------------- Tools -------------------------- -------------------------- Tools --------------------------
Tools > Utilities / Shell / Tools > Utilities / OpenPXE Shell / NIC Info / Reboot
NIC Info / Reboot /
Exit and continue BIOS
---------------------- Queued Deployment ------------------ ---------------------- Queued Deployment ------------------
Queued Deployment (join queue) Queued Deployment (join queue)
``` ```
Linux/Windows submenus show file sizes iVentoy-style: Linux/Windows submenus list images iVentoy-style with sizes:
``` ```
OpenPXE - Linux Installers OpenPXE Linux Installers
[ 4376 MB] CentOS-7-x86_64-DVD-1810
[ 2002 MB] Fedora-Workstation-Live-x86_64-38-1.6
[ 4699 MB] ubuntu-22.04.2-desktop-amd64 [ 4699 MB] ubuntu-22.04.2-desktop-amd64
[ 2002 MB] Fedora-Workstation-Live-x86_64-38-1.6
< Back to main menu < Back to main menu
``` ```
iPXE never appears in the UI — the whole hierarchy above is generated from The entire hierarchy is generated from what you upload and toggle — iPXE never surfaces.
ISOs you upload via drag-and-drop in the web UI plus toggles in Settings.
## Windows deployment
Enable **Windows ISO support** in Settings, then upload a **stock, unmodified** Microsoft ISO:
1. On upload, OpenPXE uses `wimlib-imagex` to inject exactly two plain-text files into the
WinPE image (`winpeshl.ini` + `startnet.cmd`) — no drivers, no certificates.
2. The container's Samba `smbd` serves the extracted install tree on `:445`.
3. The client chainloads `wimboot` → patched WinPE → Windows Setup running off the share.
**Every executable the client runs is stock Microsoft-signed.** OpenPXE never ships
drivers, never installs certificates into the client trust store, and never recommends
`bcdedit /set testsigning on`. The SMB approach is adapted (re-implemented, not copied)
from [Bootimus](https://github.com/garybowers/bootimus) (Apache-2.0). Port `445` must be
directly reachable from clients; Windows 10/11 client SKUs are the tested target.
## Configuration
All settings have defaults and layer **defaults → TOML (`--config` / `OPENPXE_CONFIG`) →
`OPENPXE_*` env**. The common knobs:
| Var | Default | Meaning |
|-----|---------|---------|
| `OPENPXE_PUBLIC_IP` | auto-detect | IP advertised to clients. **Startup fails** if unset and auto-detect yields loopback. |
| `OPENPXE_DHCP_MODE` | `proxy` | `proxy` or `disabled` |
| `OPENPXE_HTTP_PORT` | `80` | Web UI + boot-script HTTP port |
| `OPENPXE_TFTP_PORT` | `69` | TFTP port |
| `OPENPXE_DHCP_PORT` | `67` | DHCP server-side port |
| `OPENPXE_ISO_DIR` | `/var/lib/openpxe/isos` | Uploaded ISOs |
| `OPENPXE_WORK_DIR` | `/var/lib/openpxe/work` | Scratch, settings, share + branding state |
| `OPENPXE_LOG` | `info,openpxe=info` | `tracing` filter |
## OpenShift ## OpenShift
```bash ```bash
oc apply -f deploy/openshift/ oc apply -f deploy/openshift/
oc -n openpxe get all
oc -n openpxe get route openpxe -o jsonpath='{.spec.host}' oc -n openpxe get route openpxe -o jsonpath='{.spec.host}'
``` ```
### Why a custom SCC? The bundled `openpxe-scc` grants exactly `hostNetwork` (CNI overlays don't deliver L2
broadcast into pod netns) and `NET_BIND_SERVICE` (to bind ports <1024) — nothing else.
No raw sockets, no privileged mode. The Route covers `80/TCP`; PXE clients reach UDP
67/69/4011 on the node's host IP directly.
The default `restricted-v2` blocks `hostNetwork` and all capabilities. PXE ## Health & observability
cannot work without host network (CNI overlays don't deliver L2 broadcast
into pod netns), and we need `NET_BIND_SERVICE` to bind <1024. The custom
`openpxe-scc` grants exactly those two and nothing else. No raw sockets,
no privileged mode — proxy-mode DHCP sidesteps the usual requirements.
### What's on host ports | Endpoint | Purpose |
|----------|---------|
| Port | Proto | Purpose | | `/healthz` | Liveness — always 200 if the HTTP stack is up. |
|----------|-------|---------------------------------| | `/readyz` | Readiness — 200 only once iPXE firmware is bundled and the ISO dir is reachable. |
| 67 | UDP | DHCP server (proxy replies) | | `/api/status` | Full JSON: version, assets, counts, live settings, share + SMB state. |
| 69 | UDP | TFTP | | `/metrics` | Prometheus text format — DHCP replies by arch, TFTP/HTTP counts, queue gauges, uptime. |
| 4011 | UDP | PXE Boot Server discovery |
| 80 | TCP | Web UI + HTTP boot assets |
The OpenShift Route only covers 80/TCP. Clients on the PXE network talk to
the node's host IP directly for UDP.
## Windows support
Enabled by toggling **Windows ISO support** under Settings. The flow:
1. Upload a stock Microsoft Windows install ISO (vanilla, no pre-processing).
2. On upload, OpenPXE extracts the ISO and uses `wimlib-imagex` to rewrite
image index 2 (WinPE) of `sources/boot.wim`. It injects exactly two
plain-text files:
- `Windows/System32/winpeshl.ini` — tells WinPE to run `startnet.cmd`.
- `Windows/System32/startnet.cmd` — runs `wpeinit`, waits for the SMB
host to be reachable, `net use Z: \\<server>\<share> /user:guest`,
then `Z:\setup.exe`.
3. The container's Samba `smbd` serves the extracted install tree on :445.
4. The client gets chainloaded into wimboot → patched WinPE → Windows Setup
running off the SMB share. **Every binary the client executes is stock
Microsoft-signed.**
### What we never do
- Ship drivers — signed, test-signed, or otherwise — that load on the client.
- Install certificates into the target's trust store or WinPE boot policy.
- Recommend `bcdedit /set testsigning on` or any equivalent signing-policy
weakening.
### Credit & limitations
The SMB-based approach is adapted from [Bootimus](https://github.com/garybowers/bootimus)
(Apache-2.0). Re-implemented in Rust; no code was copied verbatim. Known
operational constraints inherited from the design:
- **Port 445 must be directly reachable from PXE clients.** `net use`
ignores alternate ports. In OpenShift this means `hostPort: 445` on the
deployment; on a host that already runs SMB it will collide.
- Windows 10/11 client SKUs are the tested target. Server SKUs untested.
- Hardware with NICs/storage controllers missing from WinPE's bundled
drivers will need a driver-pack injection step (not yet implemented).
## Queued Deployment
The coordinated launch flow, end to end:
1. A client boots and picks **Queued Deployment** in the PXE menu (or falls
through on timeout with the default `timeout_action`).
2. The client joins the queue, gets a numbered queue position, and enters a
long-poll loop (25s per request, auto-renewed).
3. In the web UI's **Queued Deployment** tab, the operator sees each waiting
client with its MAC, IP, arch, and position.
4. The operator selects an image and clicks **Launch for all waiting**.
The server broadcasts the assignment to every queued client via a
`tokio::sync::Notify`; each client's next poll returns the boot script
for the chosen image.
5. Every client chains the same image at effectively the same moment. The
queue stays visible until the operator releases entries, which keeps a
useful audit trail during hardware testing.
No user-facing iPXE anywhere in this flow. The client only ever runs
scripts we generate; the operator only interacts with the web UI.
## Architecture ## Architecture
See [`docs/architecture.md`](docs/architecture.md) for the protocol stack, Workspace of focused crates — `core`, `dhcp-proxy`, `tftp`, `http-api`, `iso-store`,
crate layout, and the full decision log. `ipxe-assets`, `webui`, and the `openpxe` binary. See
[`docs/architecture.md`](docs/architecture.md) for the protocol stack, crate layout, and
the full decision log.
## Licence ## License
MIT OR Apache-2.0. Dual-licensed under **MIT OR Apache-2.0** — use whichever fits your project.
+1 -1
View File
@@ -36,4 +36,4 @@ pub use profile::DeployProfile;
pub use queue::{DeploymentQueue, QueueEntry}; pub use queue::{DeploymentQueue, QueueEntry};
pub use saml::{IdpMetadata, SamlError, SpParams, VerifiedPrincipal, VerifiedResponse}; pub use saml::{IdpMetadata, SamlError, SpParams, VerifiedPrincipal, VerifiedResponse};
pub use settings::{Settings, SettingsStore, TimeoutAction}; pub use settings::{Settings, SettingsStore, TimeoutAction};
pub use sso::{SsoConfig, SsoStore}; pub use sso::{SsoConfig, SsoLoginInfo, SsoStore};
+30
View File
@@ -73,6 +73,23 @@ impl SsoConfig {
} }
} }
/// The minimal, non-sensitive slice of the SSO config that the **pre-auth**
/// login screen needs to render the "Sign in with …" button. Carries only
/// the display affordances — never the metadata XML/URL or entity ID, which
/// stay behind the auth-gated `/api/sso`. Served as part of the public
/// `/api/me` so the button renders reliably whether or not anyone is signed
/// in (v0.5.9: fixes the button vanishing because `/api/sso` 401s pre-auth).
#[derive(Debug, Clone, Default, Serialize, Deserialize)]
pub struct SsoLoginInfo {
/// True only when SSO is *usable* (enabled AND a metadata source is
/// present) — i.e. clicking the button will actually reach an IdP.
pub enabled: bool,
/// Button label, e.g. "STC AD". Empty falls back to "SSO" in the UI.
pub idp_name: String,
/// Optional IdP logo rendered on the button. Empty = no image.
pub idp_logo_url: String,
}
/// In-memory + on-disk SSO settings registry. /// In-memory + on-disk SSO settings registry.
#[derive(Debug, Clone)] #[derive(Debug, Clone)]
pub struct SsoStore { pub struct SsoStore {
@@ -111,6 +128,19 @@ impl SsoStore {
self.inner.read().clone() self.inner.read().clone()
} }
/// Public, non-sensitive descriptor for the login screen. Safe to
/// expose pre-auth — it's exactly what the "Sign in with …" button
/// keys off, with no metadata/entity-ID leakage. v0.5.9.
#[must_use]
pub fn login_info(&self) -> SsoLoginInfo {
let cfg = self.inner.read();
SsoLoginInfo {
enabled: cfg.is_usable(),
idp_name: cfg.idp_name.clone(),
idp_logo_url: cfg.idp_logo_url.clone(),
}
}
/// Replace the whole config in one shot. Light validation: metadata /// Replace the whole config in one shot. Light validation: metadata
/// XML and URL are length-capped so an operator can't OOM us by /// XML and URL are length-capped so an operator can't OOM us by
/// pasting a 10 GiB blob; the IdP UI tab clamps the input visually, /// pasting a 10 GiB blob; the IdP UI tab clamps the input visually,
+9
View File
@@ -319,6 +319,12 @@ pub async fn api_me(State(state): State<AppState>, headers: axum::http::HeaderMa
// and the logo asset is public, so this leaks nothing sensitive. // and the logo asset is public, so this leaks nothing sensitive.
let has_custom_logo = state.branding.has_any_web_logo(); let has_custom_logo = state.branding.has_any_web_logo();
let logo_rev = state.branding.logo_rev(); let logo_rev = state.branding.logo_rev();
// v0.5.9: ship the non-sensitive SSO descriptor with every /api/me so
// the pre-auth login screen can render the "Sign in with …" button
// reliably. Previously the button keyed off the auth-gated /api/sso,
// which 401s when logged out — the button only survived on a stale
// in-memory config and vanished on any fresh login-page load.
let sso = state.sso.login_info();
if !state.admin.is_configured() { if !state.admin.is_configured() {
return ( return (
StatusCode::OK, StatusCode::OK,
@@ -327,6 +333,7 @@ pub async fn api_me(State(state): State<AppState>, headers: axum::http::HeaderMa
"authenticated": false, "authenticated": false,
"has_custom_logo": has_custom_logo, "has_custom_logo": has_custom_logo,
"logo_rev": logo_rev, "logo_rev": logo_rev,
"sso": sso,
})), })),
) )
.into_response(); .into_response();
@@ -343,6 +350,7 @@ pub async fn api_me(State(state): State<AppState>, headers: axum::http::HeaderMa
"session_user": u, "session_user": u,
"has_custom_logo": has_custom_logo, "has_custom_logo": has_custom_logo,
"logo_rev": logo_rev, "logo_rev": logo_rev,
"sso": sso,
})), })),
) )
.into_response(), .into_response(),
@@ -353,6 +361,7 @@ pub async fn api_me(State(state): State<AppState>, headers: axum::http::HeaderMa
"authenticated": false, "authenticated": false,
"has_custom_logo": has_custom_logo, "has_custom_logo": has_custom_logo,
"logo_rev": logo_rev, "logo_rev": logo_rev,
"sso": sso,
})), })),
) )
.into_response(), .into_response(),
+21 -12
View File
@@ -61,16 +61,24 @@ pub fn render_menu(isos: &[IsoMeta], settings: &Settings, base_url: &str) -> Str
// returns a full-screen 1024×768 PNG now — the operator's logo on a // returns a full-screen 1024×768 PNG now — the operator's logo on a
// dark field, or a default OpenPXE mark when none is uploaded. The // dark field, or a default OpenPXE mark when none is uploaded. The
// `--top 290` reserves the top band (where the logo paints) so the // `--top 290` reserves the top band (where the logo paints) so the
// menu text lands below it. On an iPXE build *with* `IMAGE_PNG` + // menu text lands below it.
// `CONSOLE_FRAMEBUFFER` (our x86_64 UEFI binaries, built from source //
// — see deploy/docker/Dockerfile) this paints the background and // v0.5.7: gate the whole command behind `iseq ${platform} efi`.
// overlays the menu. On a build *without* PNG support (the fetched // `console --picture` needs IMAGE_PNG + CONSOLE_FRAMEBUFFER, which
// BIOS/i386/arm64 binaries) the whole `console --picture …` command // only our from-source UEFI binaries carry (x86_64/arm64 UEFI — see
// fails and the `|| console` resets to a clean full-screen text // deploy/docker/Dockerfile). The fetched BIOS `undionly.kpxe` has
// menu. Either way there's no ASCII placeholder anymore. // neither, and on legacy BIOS the `--picture` attempt misbehaves
// *before* the trailing `|| console` fallback can recover (it tries
// to set a framebuffer mode the BIOS console can't honour). Guarding
// on platform means BIOS clients never issue the command at all —
// they drop straight to the plain text menu — while UEFI clients
// still get the graphical background. A PNG-less UEFI build (e.g. the
// upstream i386-efi baseline) still falls back gracefully through the
// same `|| console`. No operator toggle needed; mixed BIOS+UEFI
// fleets each get the right treatment automatically.
let _ = writeln!( let _ = writeln!(
s, s,
"console --picture {base}/branding/pxe-logo --top 290 || console" "iseq ${{platform}} efi && console --picture {base}/branding/pxe-logo --top 290 || console"
); );
// Map iPXE's ${{buildarch}} + ${{platform}} into the human form the // Map iPXE's ${{buildarch}} + ${{platform}} into the human form the
// user asked for (e.g. "x86 BIOS", "x86_64 UEFI", "arm64 UEFI"). // user asked for (e.g. "x86 BIOS", "x86_64 UEFI", "arm64 UEFI").
@@ -101,12 +109,13 @@ pub fn render_menu(isos: &[IsoMeta], settings: &Settings, base_url: &str) -> Str
} else { } else {
let _ = writeln!(s, "item --gap -- (no Linux ISOs uploaded)"); let _ = writeln!(s, "item --gap -- (no Linux ISOs uploaded)");
} }
if settings.windows_enabled && has_family(isos, is_windows_family) { // v0.5.8: Windows just works — no Settings toggle. Show the Windows
// installers submenu whenever a Windows ISO is present; entries boot
// via HTTP sanboot of the raw ISO, so no SMB/extraction is required.
if has_family(isos, is_windows_family) {
let _ = writeln!(s, "item windows Windows Installers >"); let _ = writeln!(s, "item windows Windows Installers >");
} else if settings.windows_enabled {
let _ = writeln!(s, "item --gap -- (no Windows ISOs uploaded)");
} else { } else {
let _ = writeln!(s, "item --gap -- (Windows support disabled in Settings)"); let _ = writeln!(s, "item --gap -- (no Windows ISOs uploaded)");
} }
let _ = writeln!( let _ = writeln!(
s, s,
@@ -7,7 +7,7 @@ expression: rendered
set base-url http://10.0.0.5 set base-url http://10.0.0.5
set esc:hex 1b set esc:hex 1b
set cls ${esc:string}[2J set cls ${esc:string}[2J
console --picture http://10.0.0.5/branding/pxe-logo --top 290 || console iseq ${platform} efi && console --picture http://10.0.0.5/branding/pxe-logo --top 290 || console
set arch-label ${buildarch} ${platform} set arch-label ${buildarch} ${platform}
iseq ${buildarch} i386 && iseq ${platform} pcbios && set arch-label x86 BIOS || iseq ${buildarch} x86_64 && iseq ${platform} efi && set arch-label x86_64 UEFI || iseq ${buildarch} arm64 && iseq ${platform} efi && set arch-label arm64 UEFI || true iseq ${buildarch} i386 && iseq ${platform} pcbios && set arch-label x86 BIOS || iseq ${buildarch} x86_64 && iseq ${platform} efi && set arch-label x86_64 UEFI || iseq ${buildarch} arm64 && iseq ${platform} efi && set arch-label arm64 UEFI || true
:menu :menu
@@ -17,7 +17,7 @@ item --gap -- ------------------------- Default -------------------------
item local Boot from Local HDD item local Boot from Local HDD
item --gap -- ----------------------- Installers ----------------------- item --gap -- ----------------------- Installers -----------------------
item --gap -- (no Linux ISOs uploaded) item --gap -- (no Linux ISOs uploaded)
item --gap -- (Windows support disabled in Settings) item --gap -- (no Windows ISOs uploaded)
item --gap -- -------------------------- Tools -------------------------- item --gap -- -------------------------- Tools --------------------------
item tools Tools > item tools Tools >
item --gap -- ---------------------- Queued Deployment --------------------- item --gap -- ---------------------- Queued Deployment ---------------------
+20 -23
View File
@@ -693,7 +693,7 @@ async fn log_recent_returns_buffered_lines() {
} }
#[tokio::test] #[tokio::test]
async fn windows_iso_renders_clean_wimboot_script_with_no_trust_store_writes() { async fn windows_iso_renders_clean_sanboot_script_with_no_trust_store_writes() {
// Synthesize an ISO with a Windows volume label + the sources/boot.wim // Synthesize an ISO with a Windows volume label + the sources/boot.wim
// sentinel so introspection labels it WindowsPe with has_boot_wim. // sentinel so introspection labels it WindowsPe with has_boot_wim.
let mut buf = vec![0u8; 32 * 2048]; let mut buf = vec![0u8; 32 * 2048];
@@ -763,38 +763,35 @@ async fn windows_iso_renders_clean_wimboot_script_with_no_trust_store_writes() {
"introspection should detect sources/boot.wim sentinel" "introspection should detect sources/boot.wim sentinel"
); );
// The boot entry should be a wimboot kind with the canonical 5-file // v0.5.8: Windows boots via iPXE HTTP sanboot of the raw ISO — no SMB,
// chain documented in the LinusTechTips iPXE-Windows guide. // no extraction, no in-ISO file serving, no operator toggle. The boot
// entry is a `san_boot_iso` kind pointing at the raw image.
let entry = &meta["boot_entries"][0]; let entry = &meta["boot_entries"][0];
assert_eq!(entry["kind"]["kind"], "wimboot"); assert_eq!(entry["kind"]["kind"], "san_boot_iso");
let files = entry["kind"]["files"].as_array().unwrap(); let iso_url = entry["kind"]["iso_url"].as_str().unwrap();
let names: Vec<&str> = files.iter().map(|f| f[0].as_str().unwrap()).collect(); assert!(
assert!(names.contains(&"bootmgr")); std::path::Path::new(iso_url)
assert!(names.contains(&"bootmgr.efi")); .extension()
assert!(names.contains(&"bcd")); .is_some_and(|e| e.eq_ignore_ascii_case("iso")),
assert!(names.contains(&"boot.sdi")); "sanboot should target the raw ISO, got: {iso_url}"
assert!(names.contains(&"boot.wim")); );
// Render the entry script and verify: // Render the entry script and verify:
// 1. It uses wimboot // 1. It uses `sanboot` against the raw ISO over HTTP
// 2. All 5 files are referenced via `initrd --name` // 2. NO trust-store / driver / testsigning operations slip in
// 3. NO trust-store / driver / testsigning operations slip in
let entry_id = entry["id"].as_str().unwrap(); let entry_id = entry["id"].as_str().unwrap();
let url = format!("/boot/{entry_id}.ipxe"); let url = format!("/boot/{entry_id}.ipxe");
let (s, body) = get(&app, &url).await; let (s, body) = get(&app, &url).await;
assert_eq!(s, StatusCode::OK); assert_eq!(s, StatusCode::OK);
let script = String::from_utf8(body).unwrap(); let script = String::from_utf8(body).unwrap();
assert!(script.contains("kernel "), "missing kernel line:\n{script}");
assert!( assert!(
script.contains("ipxe/wimboot"), script.contains("sanboot"),
"missing wimboot loader:\n{script}" "missing sanboot line:\n{script}"
);
assert!(
script.contains(&format!("/{iso_url}")),
"sanboot should reference the raw ISO url:\n{script}"
); );
for tag in ["bootmgr", "bootmgr.efi", "bcd", "boot.sdi", "boot.wim"] {
assert!(
script.contains(&format!("initrd --name {tag}")),
"missing `initrd --name {tag}` line:\n{script}"
);
}
// Hard guarantees we never want to see in any client-facing script. // Hard guarantees we never want to see in any client-facing script.
let lower = script.to_lowercase(); let lower = script.to_lowercase();
for forbidden in [ for forbidden in [
+208 -10
View File
@@ -13,7 +13,7 @@ use serde::{Deserialize, Serialize};
use std::io::{Read, Seek, SeekFrom}; use std::io::{Read, Seek, SeekFrom};
use std::path::Path; use std::path::Path;
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)] #[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize, Default)]
#[serde(rename_all = "snake_case")] #[serde(rename_all = "snake_case")]
pub enum DistroFamily { pub enum DistroFamily {
DebianUbuntu, DebianUbuntu,
@@ -22,10 +22,22 @@ pub enum DistroFamily {
Arch, Arch,
Alpine, Alpine,
WindowsPe, WindowsPe,
#[default]
Unknown, Unknown,
} }
#[derive(Debug, Clone, Serialize, Deserialize)] /// Bumped whenever the introspection logic changes in a way that should
/// re-classify already-uploaded ISOs. On startup the store re-runs
/// `introspect` on any *local* ISO whose persisted report predates this
/// revision (see `IsoStore::load_from_disk`), so an upgrade fixes stale
/// metadata — e.g. a Windows 11 ISO tagged `Unknown` by an older binary —
/// without the operator having to delete and re-upload it.
///
/// rev 1 (v0.5.9): added El Torito boot-catalog detection + broadened
/// Windows (UDF/UTF-16) detection becomes retroactive.
pub const INTROSPECT_REV: u32 = 1;
#[derive(Debug, Clone, Default, Serialize, Deserialize)]
pub struct IntrospectionReport { pub struct IntrospectionReport {
pub family: DistroFamily, pub family: DistroFamily,
pub volume_label: Option<String>, pub volume_label: Option<String>,
@@ -35,17 +47,28 @@ pub struct IntrospectionReport {
pub initrd_paths: Vec<String>, pub initrd_paths: Vec<String>,
/// True if `sources/boot.wim` present — Windows install media. /// True if `sources/boot.wim` present — Windows install media.
pub has_boot_wim: bool, pub has_boot_wim: bool,
/// True if the ISO carries an El Torito boot catalog — i.e. it is
/// bootable by BIOS/UEFI firmware and therefore by iPXE `sanboot`
/// (emulated CD). This is the authoritative "can this boot at all?"
/// signal for ISOs we can't classify as Linux or Windows (BSDs, ESXi,
/// firmware tools, custom spins). A *data* ISO (e.g. a VMware vCenter
/// appliance bundle) has no boot catalog and reports `false`. v0.5.9.
#[serde(default)]
pub el_torito: bool,
/// Revision of the introspection logic that produced this report. Old
/// `meta.json` files without the field deserialize as 0, which is
/// below [`INTROSPECT_REV`], triggering a one-time re-introspect on
/// the next startup. v0.5.9.
#[serde(default)]
pub introspect_rev: u32,
} }
/// Probe an ISO file on disk. Never fails — on unrecoverable IO error we log /// Probe an ISO file on disk. Never fails — on unrecoverable IO error we log
/// and return an `Unknown` family so the uploader still sees a record. /// and return an `Unknown` family so the uploader still sees a record.
pub fn introspect(path: &Path) -> IntrospectionReport { pub fn introspect(path: &Path) -> IntrospectionReport {
let mut report = IntrospectionReport { let mut report = IntrospectionReport {
family: DistroFamily::Unknown, introspect_rev: INTROSPECT_REV,
volume_label: None, ..Default::default()
kernel_path: None,
initrd_paths: Vec::new(),
has_boot_wim: false,
}; };
let Ok(mut f) = std::fs::File::open(path) else { let Ok(mut f) = std::fs::File::open(path) else {
@@ -68,6 +91,11 @@ pub fn introspect(path: &Path) -> IntrospectionReport {
} }
} }
// Does the ISO have an El Torito boot catalog? This is what decides
// whether an ISO we *can't* otherwise classify is bootable at all —
// a bootable ISO sanboots; a data/appliance ISO (no catalog) can't.
report.el_torito = detect_el_torito(&mut f);
// Cheap content scan: read the first ~64 MiB, look for signature filenames. // Cheap content scan: read the first ~64 MiB, look for signature filenames.
// This is enough to identify `sources/boot.wim` (Windows) and common // This is enough to identify `sources/boot.wim` (Windows) and common
// kernel/initrd paths for the major Linux distros. // kernel/initrd paths for the major Linux distros.
@@ -85,12 +113,37 @@ pub fn introspect(path: &Path) -> IntrospectionReport {
read_total += n; read_total += n;
} }
// `sources/boot.wim` is the definitive Windows-install-media marker
// when the ISO exposes ASCII (ISO9660/Joliet) names. `contains_ascii`
// is case-insensitive, so one form covers BOOT.WIM / boot.wim and the
// backslash variant.
if contains_ascii(&haystack, b"sources/boot.wim") if contains_ascii(&haystack, b"sources/boot.wim")
|| contains_ascii(&haystack, b"SOURCES/BOOT.WIM") || contains_ascii(&haystack, b"sources\\boot.wim")
|| contains_ascii(&haystack, b"SOURCES\\BOOT.WIM")
{ {
report.has_boot_wim = true; report.has_boot_wim = true;
if report.family == DistroFamily::Unknown { report.family = DistroFamily::WindowsPe;
}
// v0.5.8: broaden Windows detection. Modern Windows 10/11 ISOs are
// UDF — filenames are stored as UTF-16 (so the ASCII scan above misses
// them) and the volume label is a cryptic Microsoft string (so
// `family_from_label` misses it too). Booting is via HTTP sanboot of
// the raw ISO (no boot.wim extraction), so we only need the *family*.
// Catch the common cases: well-known Windows markers in either ASCII
// or UTF-16LE within the first 16 MiB, plus a filename hint.
if report.family == DistroFamily::Unknown {
let head = &haystack[..haystack.len().min(16 * 1024 * 1024)];
let ascii_markers: [&[u8]; 4] = [
b"bootmgr",
b"sources/install.wim",
b"sources/install.esd",
b"efi/microsoft",
];
let utf16_markers = ["bootmgr", "boot.wim", "install.wim", "microsoft"];
let looks_windows = ascii_markers.iter().any(|m| contains_ascii(head, m))
|| utf16_markers.iter().any(|m| contains_utf16le_ci(head, m))
|| filename_looks_windows(path);
if looks_windows {
report.family = DistroFamily::WindowsPe; report.family = DistroFamily::WindowsPe;
} }
} }
@@ -158,6 +211,83 @@ fn contains_ascii(haystack: &[u8], needle: &[u8]) -> bool {
.any(|w| w.eq_ignore_ascii_case(needle)) .any(|w| w.eq_ignore_ascii_case(needle))
} }
/// Case-insensitive search for an ASCII string encoded as UTF-16LE — the
/// way UDF (and thus modern Windows ISOs) store filenames. Each character
/// is two bytes: the ASCII low byte (compared case-insensitively) followed
/// by a 0 high byte. v0.5.8.
fn contains_utf16le_ci(haystack: &[u8], ascii: &str) -> bool {
let n = ascii.len();
if n == 0 || haystack.len() < n * 2 {
return false;
}
let lower: Vec<u8> = ascii.bytes().map(|b| b.to_ascii_lowercase()).collect();
haystack.windows(n * 2).any(|w| {
lower
.iter()
.enumerate()
.all(|(i, &c)| w[i * 2 + 1] == 0 && w[i * 2].to_ascii_lowercase() == c)
})
}
/// Filename heuristic: a stock Windows ISO almost always carries an obvious
/// token in its name (e.g. `..._windows_11_...`, `Win10`, `winserver`).
/// Used only as a last-resort family hint when the content scan and volume
/// label are inconclusive. v0.5.8.
fn filename_looks_windows(path: &Path) -> bool {
let name = path
.file_name()
.and_then(|s| s.to_str())
.unwrap_or("")
.to_ascii_lowercase();
const TOKENS: [&str; 6] = [
"windows",
"winpe",
"win10",
"win11",
"winserver",
"win-server",
];
TOKENS.iter().any(|t| name.contains(t))
}
/// The boot-system identifier string in an El Torito Boot Record Volume
/// Descriptor (offset 7, NUL-padded to 32 bytes).
const EL_TORITO_ID: &[u8] = b"EL TORITO SPECIFICATION";
/// Detect an El Torito boot catalog — the marker that an ISO is bootable
/// by BIOS/UEFI firmware (and thus by iPXE `sanboot`).
///
/// The ISO9660 Volume Descriptor Set starts at LBA 16 (offset 0x8000) and
/// runs one 2048-byte descriptor per sector until a Set Terminator
/// (type 0xFF). A Boot Record descriptor (type 0x00) whose 32-byte boot
/// system identifier reads "EL TORITO SPECIFICATION" means the image
/// declares an El Torito boot catalog. We only confirm its presence — we
/// don't parse the catalog (sanboot/the firmware does that). The walk is
/// capped so a malformed/huge image can't spin us. v0.5.9.
fn detect_el_torito(f: &mut std::fs::File) -> bool {
let mut vd = [0u8; 2048];
for lba in 16u64..32 {
if f.seek(SeekFrom::Start(lba * 2048)).is_err() || f.read_exact(&mut vd).is_err() {
return false;
}
// Every descriptor in the set carries the "CD001" magic; once it's
// missing we've walked off the end of a valid set.
if &vd[1..6] != b"CD001" {
return false;
}
match vd[0] {
// Boot Record descriptor carrying the El Torito signature.
0x00 if vd[7..7 + EL_TORITO_ID.len()] == *EL_TORITO_ID => return true,
// Volume Descriptor Set Terminator — nothing bootable found.
0xFF => return false,
// Any other descriptor (incl. a non-El-Torito boot record) —
// keep walking the set.
_ => {}
}
}
false
}
#[cfg(test)] #[cfg(test)]
mod tests { mod tests {
use super::*; use super::*;
@@ -179,4 +309,72 @@ mod tests {
assert_eq!(family_from_label("ARCH_202604"), DistroFamily::Arch); assert_eq!(family_from_label("ARCH_202604"), DistroFamily::Arch);
assert_eq!(family_from_label("weird-custom"), DistroFamily::Unknown); assert_eq!(family_from_label("weird-custom"), DistroFamily::Unknown);
} }
#[test]
fn utf16le_marker_matches_case_insensitively() {
// "boot.wim" encoded UTF-16LE, mixed case — UDF stores Windows
// filenames this way, which the ASCII scan can't see.
let s = "BOOT.WIM";
let utf16: Vec<u8> = s.bytes().flat_map(|b| [b, 0]).collect();
let mut hay = vec![0u8; 8];
hay.extend_from_slice(&utf16);
hay.extend_from_slice(&[1, 2, 3]);
assert!(contains_utf16le_ci(&hay, "boot.wim"));
assert!(contains_utf16le_ci(&hay, "Boot.Wim"));
assert!(!contains_utf16le_ci(&hay, "install.wim"));
// An ASCII (not UTF-16) occurrence must NOT match the UTF-16 scan.
assert!(!contains_utf16le_ci(b"boot.wim plain ascii", "boot.wim"));
}
#[test]
fn el_torito_boot_catalog_detected() {
let dir = tempfile::tempdir().unwrap();
// Helper: stamp a 2048-byte descriptor at `lba` with type + magic.
let stamp = |img: &mut [u8], lba: usize, ty: u8| {
let off = lba * 2048;
img[off] = ty;
img[off + 1..off + 6].copy_from_slice(b"CD001");
};
// Bootable image: PVD @16, El Torito Boot Record @17, terminator @18.
let mut boot = vec![0u8; 2048 * 19];
stamp(&mut boot, 16, 0x01);
stamp(&mut boot, 17, 0x00);
boot[17 * 2048 + 7..17 * 2048 + 7 + EL_TORITO_ID.len()].copy_from_slice(EL_TORITO_ID);
stamp(&mut boot, 18, 0xFF);
let bp = dir.path().join("boot.iso");
std::fs::write(&bp, &boot).unwrap();
let mut f = std::fs::File::open(&bp).unwrap();
assert!(
detect_el_torito(&mut f),
"El Torito boot record should match"
);
// Data/appliance image: PVD @16, terminator @17, no boot record.
let mut data = vec![0u8; 2048 * 18];
stamp(&mut data, 16, 0x01);
stamp(&mut data, 17, 0xFF);
let dp = dir.path().join("data.iso");
std::fs::write(&dp, &data).unwrap();
let mut f2 = std::fs::File::open(&dp).unwrap();
assert!(!detect_el_torito(&mut f2), "data ISO has no boot catalog");
}
#[test]
fn filename_hint_catches_windows_isos() {
use std::path::Path;
assert!(filename_looks_windows(Path::new(
"en-us_windows_11_iot_enterprise_ltsc_2024_x64_dvd.iso"
)));
assert!(filename_looks_windows(Path::new(
"Win10_22H2_English_x64.iso"
)));
assert!(filename_looks_windows(Path::new("winserver2022.iso")));
assert!(!filename_looks_windows(Path::new(
"ubuntu-24.04-desktop.iso"
)));
assert!(!filename_looks_windows(Path::new(
"Rocky-9.4-x86_64-dvd.iso"
)));
}
} }
+2 -8
View File
@@ -57,7 +57,7 @@
//! UI to ask for. (If a future server needs Kerberos or non-default //! UI to ask for. (If a future server needs Kerberos or non-default
//! uid mapping we can add those, but for ISO read access nobody does.) //! uid mapping we can add those, but for ISO read access nobody does.)
use crate::introspect::{DistroFamily, IntrospectionReport}; use crate::introspect::IntrospectionReport;
use crate::store::{generate_boot_entries_for, slugify_str, IsoSource, IsoStore}; use crate::store::{generate_boot_entries_for, slugify_str, IsoSource, IsoStore};
use bytes::Bytes; use bytes::Bytes;
use nfs3_client::tokio::TokioConnector; use nfs3_client::tokio::TokioConnector;
@@ -399,13 +399,7 @@ impl NfsShareManager {
// Same approach as SMB: no real introspection over the // Same approach as SMB: no real introspection over the
// network in v0.4.67. The boot-entry generator falls back // network in v0.4.67. The boot-entry generator falls back
// to filename-based sanboot detection. // to filename-based sanboot detection.
let report = IntrospectionReport { let report = IntrospectionReport::default();
family: DistroFamily::Unknown,
volume_label: None,
kernel_path: None,
initrd_paths: Vec::new(),
has_boot_wim: false,
};
let boot_entries = generate_boot_entries_for(&iso_id, &entry.filename, &report); let boot_entries = generate_boot_entries_for(&iso_id, &entry.filename, &report);
let source = IsoSource::Nfs { let source = IsoSource::Nfs {
share_id: share.id.clone(), share_id: share.id.clone(),
+2 -8
View File
@@ -56,7 +56,7 @@
//! hint}` error shape is shared so the storage tab renders all three //! hint}` error shape is shared so the storage tab renders all three
//! protocols through one code path. //! protocols through one code path.
use crate::introspect::{DistroFamily, IntrospectionReport}; use crate::introspect::IntrospectionReport;
use crate::store::{generate_boot_entries_for, slugify_str, IsoSource, IsoStore}; use crate::store::{generate_boot_entries_for, slugify_str, IsoSource, IsoStore};
use bytes::Bytes; use bytes::Bytes;
use openpxe_core::{Error, Result}; use openpxe_core::{Error, Result};
@@ -480,13 +480,7 @@ impl SftpShareManager {
// register `Unknown` and let the boot-entry generator fall // register `Unknown` and let the boot-entry generator fall
// back to filename-based detection. SFTP *could* do bounded // back to filename-based detection. SFTP *could* do bounded
// PVD reads (it has random access) — a follow-up can add it. // PVD reads (it has random access) — a follow-up can add it.
let report = IntrospectionReport { let report = IntrospectionReport::default();
family: DistroFamily::Unknown,
volume_label: None,
kernel_path: None,
initrd_paths: Vec::new(),
has_boot_wim: false,
};
let boot_entries = generate_boot_entries_for(&iso_id, &entry.filename, &report); let boot_entries = generate_boot_entries_for(&iso_id, &entry.filename, &report);
let source = IsoSource::Sftp { let source = IsoSource::Sftp {
share_id: share.id.clone(), share_id: share.id.clone(),
+2 -8
View File
@@ -56,7 +56,7 @@
//! streaming. A follow-up release can add libsmbclient-based seek if //! streaming. A follow-up release can add libsmbclient-based seek if
//! a real workload needs it. //! a real workload needs it.
use crate::introspect::{DistroFamily, IntrospectionReport}; use crate::introspect::IntrospectionReport;
use crate::store::{generate_boot_entries_for, slugify_str, IsoSource, IsoStore}; use crate::store::{generate_boot_entries_for, slugify_str, IsoSource, IsoStore};
use openpxe_core::{Error, Result}; use openpxe_core::{Error, Result};
use parking_lot::Mutex; use parking_lot::Mutex;
@@ -470,13 +470,7 @@ impl SmbShareManager {
// and the operator gets *something* bootable. A follow-up // and the operator gets *something* bootable. A follow-up
// release can do a bounded `smbclient get` of the first // release can do a bounded `smbclient get` of the first
// 64 KiB for real detection. // 64 KiB for real detection.
let report = IntrospectionReport { let report = IntrospectionReport::default();
family: DistroFamily::Unknown,
volume_label: None,
kernel_path: None,
initrd_paths: Vec::new(),
has_boot_wim: false,
};
let boot_entries = generate_boot_entries_for(&iso_id, &entry.filename, &report); let boot_entries = generate_boot_entries_for(&iso_id, &entry.filename, &report);
let source = IsoSource::Smb { let source = IsoSource::Smb {
share_id: share.id.clone(), share_id: share.id.clone(),
+58 -23
View File
@@ -223,7 +223,8 @@ impl IsoStore {
continue; continue;
} }
if let Ok(text) = tokio::fs::read_to_string(&p).await { if let Ok(text) = tokio::fs::read_to_string(&p).await {
if let Ok(meta) = serde_json::from_str::<IsoMeta>(&text) { if let Ok(mut meta) = serde_json::from_str::<IsoMeta>(&text) {
self.reintrospect_if_stale(&mut meta).await;
self.insert(meta); self.insert(meta);
} }
} }
@@ -231,6 +232,46 @@ impl IsoStore {
Ok(()) Ok(())
} }
/// v0.5.9: re-run introspection on a *local* ISO whose persisted report
/// predates the current logic. ISOs uploaded by an older binary carry a
/// stale family/boot profile — most visibly a Windows 11 ISO tagged
/// `Unknown` before the UDF/El-Torito detection landed, which then shows
/// as "won't boot" forever. Re-probing on startup fixes them in place,
/// no delete-and-re-upload. Bounded: only `Local` sources (we have the
/// bytes locally) below [`introspect::INTROSPECT_REV`], so it runs at
/// most once per ISO per upgrade. The probe reads up to ~64 MiB, so we
/// push it onto the blocking pool to keep the async runtime responsive.
async fn reintrospect_if_stale(&self, meta: &mut IsoMeta) {
if !matches!(meta.source, IsoSource::Local)
|| meta.introspection.introspect_rev >= crate::introspect::INTROSPECT_REV
{
return;
}
let path = self.iso_path(&meta.id);
if !path.exists() {
return;
}
let Ok(fresh) = tokio::task::spawn_blocking(move || introspect(&path)).await else {
tracing::warn!(target: "openpxe::iso", id = %meta.id, "re-introspect task failed");
return;
};
let before = meta.introspection.family;
meta.introspection = fresh;
meta.boot_entries = generate_boot_entries(&meta.id, &meta.filename, &meta.introspection);
if let Err(e) = self.persist_meta(meta).await {
tracing::warn!(target: "openpxe::iso", id = %meta.id, "re-introspect persist: {e}");
return;
}
tracing::info!(
target: "openpxe::iso",
id = %meta.id,
from = ?before,
to = ?meta.introspection.family,
el_torito = meta.introspection.el_torito,
"re-introspected stale ISO metadata"
);
}
fn insert(&self, meta: IsoMeta) { fn insert(&self, meta: IsoMeta) {
self.inner.write().isos.insert(meta.id.clone(), meta); self.inner.write().isos.insert(meta.id.clone(), meta);
} }
@@ -557,22 +598,22 @@ fn generate_boot_entries(id: &str, filename: &str, r: &IntrospectionReport) -> V
.clone() .clone()
.unwrap_or_else(|| filename.to_string()); .unwrap_or_else(|| filename.to_string());
match r.family { match r.family {
DistroFamily::WindowsPe if r.has_boot_wim => { DistroFamily::WindowsPe => {
// Standard wimboot chain. Paths are in-ISO; the HTTP layer maps // v0.5.8: boot Windows directly via iPXE HTTP sanboot. iPXE
// `iso/<id>/<path>` to on-disk extraction via ISO9660 lookup. // exposes the raw ISO as an emulated CD backed by on-demand
let base = format!("iso/{id}"); // HTTP range reads, and Windows Setup boots from it. This
// replaces the old wimboot+SMB chain, which (a) needed an SMB
// server the host often can't provide (port 445 collisions),
// (b) served in-ISO files via an ISO9660 lookup that failed on
// UDF-only Windows 11 ISOs, and (c) required an operator
// toggle. sanboot needs none of that — just the HTTP port,
// which works in any environment. The unmodified, stock ISO is
// served at iso/<id>.iso; nothing is injected into Windows.
vec![BootEntry { vec![BootEntry {
id: format!("{id}-winpe"), id: format!("{id}-windows"),
title: format!("{title} (Windows / wimboot)"), title: format!("{title} (Windows)"),
kind: BootKind::Wimboot { kind: BootKind::SanBootIso {
wimboot_url: "ipxe/wimboot".to_string(), iso_url: format!("iso/{id}.iso"),
files: vec![
("bootmgr".into(), format!("{base}/bootmgr")),
("bootmgr.efi".into(), format!("{base}/bootmgr.efi")),
("bcd".into(), format!("{base}/boot/bcd")),
("boot.sdi".into(), format!("{base}/boot/boot.sdi")),
("boot.wim".into(), format!("{base}/sources/boot.wim")),
],
}, },
}] }]
} }
@@ -687,13 +728,7 @@ mod tests {
size_bytes: 0, size_bytes: 0,
sha256_hex: None, sha256_hex: None,
uploaded_at: OffsetDateTime::now_utc(), uploaded_at: OffsetDateTime::now_utc(),
introspection: IntrospectionReport { introspection: IntrospectionReport::default(),
family: DistroFamily::Unknown,
volume_label: None,
kernel_path: None,
initrd_paths: vec![],
has_boot_wim: false,
},
boot_entries: vec![], boot_entries: vec![],
source: IsoSource::Local, source: IsoSource::Local,
password_hash: None, password_hash: None,
+44 -1
View File
@@ -94,7 +94,13 @@ async fn main() -> anyhow::Result<()> {
} }
}, },
}; };
let public_base_url = format!("http://{our_ip}"); // v0.5.6: the advertised base URL must carry the HTTP port. Every
// client-facing URL (the DHCP-proxy iPXE filename, UEFI HTTP boot,
// and the menu's kernel/initrd/ISO links) is derived from this one
// string, so omitting the port silently pointed PXE clients at :80 —
// breaking every non-80 deployment (e.g. the Unraid template's 4200,
// chosen to dodge the webGUI). See `build_public_base_url`.
let public_base_url = build_public_base_url(our_ip, config.server.http_port);
let iso_store = IsoStore::new(config.paths.iso_dir.clone()); let iso_store = IsoStore::new(config.paths.iso_dir.clone());
iso_store.load_from_disk().await?; iso_store.load_from_disk().await?;
@@ -345,6 +351,20 @@ async fn seed_from_dir(
/// a loopback address (which would give every PXE client an unreachable /// a loopback address (which would give every PXE client an unreachable
/// `http://127.0.0.1/...`). Users in multi-homed setups should set /// `http://127.0.0.1/...`). Users in multi-homed setups should set
/// `OPENPXE_PUBLIC_IP` explicitly. /// `OPENPXE_PUBLIC_IP` explicitly.
/// Build the base URL advertised to PXE clients. The port is included
/// unless it's the HTTP default (80), keeping the common case clean
/// (`http://10.0.0.5`) while a remapped port (`http://10.0.0.5:4200`)
/// stays reachable. This is the single source of truth for every
/// client-facing URL — the DHCP-proxy iPXE filename, UEFI HTTP boot, and
/// the boot menu's kernel/initrd/ISO links all derive from it.
fn build_public_base_url(ip: Ipv4Addr, http_port: u16) -> String {
if http_port == 80 {
format!("http://{ip}")
} else {
format!("http://{ip}:{http_port}")
}
}
fn detect_primary_ipv4() -> Option<Ipv4Addr> { fn detect_primary_ipv4() -> Option<Ipv4Addr> {
// First try: route to the public internet. `UdpSocket::connect` to a // First try: route to the public internet. `UdpSocket::connect` to a
// well-known external address causes the OS to populate `local_addr` // well-known external address causes the OS to populate `local_addr`
@@ -478,3 +498,26 @@ fn prefix_to_dotted(prefix: u8) -> String {
mask & 0xff mask & 0xff
) )
} }
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn public_base_url_includes_non_default_port() {
// The v0.5.6 regression guard: a remapped HTTP port (e.g. the
// Unraid template's 4200) MUST appear in the advertised URL, or
// PXE clients fetch :80 — the wrong service — and boot fails.
let ip: Ipv4Addr = "192.168.1.49".parse().unwrap();
assert_eq!(build_public_base_url(ip, 4200), "http://192.168.1.49:4200");
assert_eq!(build_public_base_url(ip, 8080), "http://192.168.1.49:8080");
}
#[test]
fn public_base_url_omits_default_port() {
// Port 80 stays clean (no `:80`) so the common case reads nicely
// and matches what every browser/iPXE assumes by default.
let ip: Ipv4Addr = "10.0.0.5".parse().unwrap();
assert_eq!(build_public_base_url(ip, 80), "http://10.0.0.5");
}
}
+79 -25
View File
@@ -160,19 +160,35 @@
// tint borrowed from Bootimus v0.1.62. Returns {ok, reason}. // tint borrowed from Bootimus v0.1.62. Returns {ok, reason}.
function bootability(iso, settings) { function bootability(iso, settings) {
const fam = iso.introspection.family; const fam = iso.introspection.family;
const isWin = fam === 'windows_pe'; // v0.5.8: Windows ISOs boot via iPXE HTTP sanboot of the raw image —
if (isWin && !settings.windows_enabled) { // no Settings toggle, no SMB, no size limit. Always bootable.
return { ok: false, reason: 'Windows boot disabled in Settings' }; if (fam === 'windows_pe') {
return { ok: true };
} }
if (!isWin && !iso.introspection.kernel_path && fam !== 'windows_pe') { // Linux with a detected kernel/initrd — direct kernel+initrd boot.
// Linux without a detected kernel falls through to sanboot which if (iso.introspection.kernel_path) {
// rarely works for >1 GiB ISOs. return { ok: true };
if (iso.size_bytes > 1.5 * 1024 * 1024 * 1024) {
return { ok: false, reason: 'no kernel/initrd detected; ISO too large for sanboot fallback' };
}
return { ok: true, warn: 'no kernel detected — sanboot fallback may not work' };
} }
return { ok: true }; // v0.5.9: any other ISO that carries an El Torito boot catalog is
// bootable via iPXE sanboot (emulated CD) — BSDs, ESXi, firmware
// tools, custom Linux spins. This replaces the old "> 1.5 GB ⇒
// unbootable" size guess with the authoritative on-disk boot signal,
// so a large bootable ISO is no longer mislabeled and a Windows ISO
// re-introspected on upgrade lights up correctly.
if (iso.introspection.el_torito) {
return { ok: true, warn: 'generic bootable ISO — boots via sanboot (emulated CD)' };
}
// Remote-share ISOs aren't introspected (no random access over the
// network), so el_torito is unknown — assume bootable and let sanboot
// try rather than cry wolf.
const remote = iso.source && iso.source.kind && iso.source.kind !== 'local';
if (remote) {
return { ok: true, warn: 'remote ISO — not introspected; sanboot is attempted at boot' };
}
// Local ISO with no Windows/Linux boot files and no El Torito catalog:
// a data/appliance image (e.g. a VMware vCenter bundle), not a bootable
// installer.
return { ok: false, reason: 'data/appliance ISO — no El Torito boot catalog and no Windows/Linux installer files, so it cant be PXE-booted' };
} }
// v0.5.2: pretty label for an unattended file's detected kind. // v0.5.2: pretty label for an unattended file's detected kind.
@@ -288,14 +304,23 @@
el('div', {class: 'card'}, el('div', {class: 'stat'}, [ el('div', {class: 'card'}, el('div', {class: 'stat'}, [
el('div', {class: 'label'}, 'Images available'), el('div', {class: 'label'}, 'Images available'),
el('div', {class: 'value'}, String(isos.length)), el('div', {class: 'value'}, String(isos.length)),
el('div', {class: 'trend'}, el('div', {class: 'trend'}, (() => {
isos.filter(i => i.introspection.family === 'windows_pe').length + ' Windows · ' + // v0.5.9: count families honestly. Anything that isn't a known
isos.filter(i => i.introspection.family !== 'windows_pe').length + ' Linux · ' + // Linux family or Windows lands in "other" (data/appliance ISOs
// like VMware VCSA, or as-yet-unclassified images) instead of
// being lumped under "Linux".
const LINUX = ['debian_ubuntu', 'rhel_fedora', 'opensuse', 'arch', 'alpine'];
const win = isos.filter(i => i.introspection.family === 'windows_pe').length;
const lin = isos.filter(i => LINUX.includes(i.introspection.family)).length;
const other = isos.length - win - lin;
// v0.4.67+v0.5.5: count all remote-share protocols. Label // v0.4.67+v0.5.5: count all remote-share protocols. Label
// generically since operators may use any mix of SMB/NFS/SFTP. // generically since operators may use any mix of SMB/NFS/SFTP.
((status.smb_share_reachable || 0) + (status.nfs_share_reachable || 0) + (status.sftp_share_reachable || 0)) + const remote = (status.smb_share_reachable || 0) + (status.nfs_share_reachable || 0) + (status.sftp_share_reachable || 0);
' remote share' + const parts = [win + ' Windows', lin + ' Linux'];
(((status.smb_share_reachable || 0) + (status.nfs_share_reachable || 0) + (status.sftp_share_reachable || 0)) === 1 ? '' : 's')), if (other > 0) parts.push(other + ' other');
parts.push(remote + ' remote share' + (remote === 1 ? '' : 's'));
return parts.join(' · ');
})()),
])), ])),
el('div', {class: 'card'}, el('div', {class: 'stat'}, [ el('div', {class: 'card'}, el('div', {class: 'stat'}, [
el('div', {class: 'label'}, 'Uptime'), el('div', {class: 'label'}, 'Uptime'),
@@ -533,6 +558,9 @@
style:'display:none', id:'file'}); style:'display:none', id:'file'});
const prog = el('div', {class:'progress', id:'prog'}, el('div', {class:'bar', id:'bar'})); const prog = el('div', {class:'progress', id:'prog'}, el('div', {class:'bar', id:'bar'}));
const upMsg = el('div', {class:'msg', id:'upmsg'}); const upMsg = el('div', {class:'msg', id:'upmsg'});
// v0.5.8: cancel button — shown only while an upload is in flight.
const cancelUpload = el('button', {class:'danger', type:'button',
style:'display:none;margin-top:12px', id:'cancel-upload'}, 'Cancel upload');
drop.onclick = () => file.click(); drop.onclick = () => file.click();
drop.addEventListener('dragover', e => { e.preventDefault(); drop.classList.add('hover'); }); drop.addEventListener('dragover', e => { e.preventDefault(); drop.classList.add('hover'); });
@@ -575,6 +603,16 @@
}; };
let uploadId = null; let uploadId = null;
// v0.5.8: cancel + leave-page guard. The AbortController stops the
// in-flight chunk; the beforeunload listener warns the operator
// that navigating away aborts the upload (the server-side partial
// is then cleaned up by the DELETE in the catch below).
const ac = new AbortController();
let canceled = false;
const warnLeave = (e) => { e.preventDefault(); e.returnValue = ''; return ''; };
window.addEventListener('beforeunload', warnLeave);
cancelUpload.style.display = '';
cancelUpload.onclick = () => { canceled = true; ac.abort(); };
setStatus('Preparing upload for ' + f.name + ' (' + fmtBytes(f.size) + ')'); setStatus('Preparing upload for ' + f.name + ' (' + fmtBytes(f.size) + ')');
prog.classList.add('active'); prog.classList.add('active');
bar.style.width = '1%'; bar.style.width = '1%';
@@ -601,6 +639,7 @@
'x-openpxe-upload-complete': complete ? 'true' : 'false', 'x-openpxe-upload-complete': complete ? 'true' : 'false',
}, },
body: f.slice(offset, end), body: f.slice(offset, end),
signal: ac.signal,
}); });
if (!r.ok) throw new Error(await failText(r)); if (!r.ok) throw new Error(await failText(r));
const j = await r.json(); const j = await r.json();
@@ -616,8 +655,15 @@
try { await fetch('/api/uploads/' + encodeURIComponent(uploadId), {method: 'DELETE'}); } try { await fetch('/api/uploads/' + encodeURIComponent(uploadId), {method: 'DELETE'}); }
catch {} catch {}
} }
setStatus('Upload failed: ' + (err && err.message ? err.message : String(err)), 'err'); if (canceled || (err && err.name === 'AbortError')) {
setStatus('Upload canceled — partial file discarded.', '');
} else {
setStatus('Upload failed: ' + (err && err.message ? err.message : String(err)), 'err');
}
} finally { } finally {
window.removeEventListener('beforeunload', warnLeave);
cancelUpload.style.display = 'none';
cancelUpload.onclick = null;
prog.classList.remove('active'); prog.classList.remove('active');
if (!upMsg.className.includes('ok')) bar.style.width = '0'; if (!upMsg.className.includes('ok')) bar.style.width = '0';
} }
@@ -629,7 +675,11 @@
// *next* row of the table. Keeps the markup flat and avoids the // *next* row of the table. Keeps the markup flat and avoids the
// overhead of a real modal. // overhead of a real modal.
const rowsAndEditors = []; const rowsAndEditors = [];
isos.forEach(i => { // v0.5.8: list Available images alphabetically by filename
// (case-insensitive, natural numeric order) instead of newest-first.
const sortedIsos = [...isos].sort((a, b) =>
(a.filename || '').localeCompare(b.filename || '', undefined, { sensitivity: 'base', numeric: true }));
sortedIsos.forEach(i => {
const b = bootability(i, settings); const b = bootability(i, settings);
// v0.4.65: SMB userspace consumer (smbclient). // v0.4.65: SMB userspace consumer (smbclient).
// v0.4.67: NFS back as in-process Rust client (nfs3_client). // v0.4.67: NFS back as in-process Rust client (nfs3_client).
@@ -1164,7 +1214,7 @@
diskCard, diskCard,
el('div', {class:'card'}, [ el('div', {class:'card'}, [
el('header', {}, el('h2', {}, 'Upload ISO')), el('header', {}, el('h2', {}, 'Upload ISO')),
el('div', {class:'body'}, [drop, file, prog, upMsg]), el('div', {class:'body'}, [drop, file, prog, upMsg, cancelUpload]),
]), ]),
// v0.5.1: SMB + NFS unified into one "Remote shares" card with a // v0.5.1: SMB + NFS unified into one "Remote shares" card with a
// protocol dropdown. Backend endpoints are unchanged; this is a // protocol dropdown. Backend endpoints are unchanged; this is a
@@ -2252,7 +2302,9 @@
// own self-contained <form>; when SSO is enabled, a distinct // own self-contained <form>; when SSO is enabled, a distinct
// "Sign in with …" button sits below a divider — the credential // "Sign in with …" button sits below a divider — the credential
// fields no longer double as the SSO trigger. // fields no longer double as the SSO trigger.
const ssoLive = ssoConfig && ssoConfig.enabled && (ssoConfig.metadata_url || ssoConfig.metadata); // `enabled` from /api/me already means "usable" (enabled AND a metadata
// source is configured), so the button only shows when SSO will work.
const ssoLive = !!(ssoConfig && ssoConfig.enabled);
const ssoBlock = ssoLive const ssoBlock = ssoLive
? el('div', {class:'sso-block'}, [ ? el('div', {class:'sso-block'}, [
el('div', {class:'auth-divider'}, el('span', {}, 'or')), el('div', {class:'auth-divider'}, el('span', {}, 'or')),
@@ -2497,10 +2549,12 @@
]))); ])));
return; return;
} }
// Preload the SSO config so the login card can offer the operator // v0.5.9: the login card's "Sign in with …" button keys off the SSO
// an "Sign in with X" button when configured. Failure is harmless. // descriptor that /api/me now carries (public, non-sensitive: enabled
try { ssoConfig = await fetch('/api/sso').then(r => r.ok ? r.json() : null); } // + idp_name + idp_logo_url). It's available signed in or out, so the
catch { ssoConfig = null; } // button is static — it no longer relied on the auth-gated /api/sso,
// which 401s pre-auth and made the button vanish on fresh login loads.
ssoConfig = me.sso || null;
if (me.setup_required) { if (me.setup_required) {
showAuthScreen('setup'); showAuthScreen('setup');
+21
View File
@@ -0,0 +1,21 @@
<svg viewBox="0 0 24 24" xmlns="http://www.w3.org/2000/svg" role="img" aria-label="OpenPXE">
<title>OpenPXE</title>
<!-- Static README mark: the "rainbow-horizon" medallion from the web UI,
with the SMIL animation removed so it renders reliably as an <img>
on Gitea/GitHub. -->
<defs>
<linearGradient id="opxRainbow" x1="0" y1="0" x2="1" y2="0">
<stop offset="0%" stop-color="#330f1f"/>
<stop offset="12.56%" stop-color="#c83228"/>
<stop offset="25.06%" stop-color="#fb8841"/>
<stop offset="37.56%" stop-color="#d3dd92"/>
<stop offset="50.06%" stop-color="#59824f"/>
<stop offset="62.06%" stop-color="#002414"/>
<stop offset="74.06%" stop-color="#00143d"/>
<stop offset="86.06%" stop-color="#2874d7"/>
<stop offset="100%" stop-color="#99c2ff"/>
</linearGradient>
</defs>
<circle cx="12" cy="12" r="10.5" fill="url(#opxRainbow)"
stroke="rgba(0,0,0,0.18)" stroke-width="0.6"/>
</svg>

After

Width:  |  Height:  |  Size: 984 B