Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7f25bb681c | ||
|
|
5da05a519d | ||
|
|
4f193cac05 | ||
|
|
24879fcc90 | ||
|
|
5df0fd5972 |
Generated
+1144
-762
File diff suppressed because it is too large
Load Diff
+22
-23
@@ -12,7 +12,7 @@ members = [
|
||||
]
|
||||
|
||||
[workspace.package]
|
||||
version = "0.5.9"
|
||||
version = "0.6.3"
|
||||
edition = "2021"
|
||||
rust-version = "1.95"
|
||||
license = "MIT OR Apache-2.0"
|
||||
@@ -20,21 +20,23 @@ repository = "https://gitea.milesward.dev/mward4/OpenPXE"
|
||||
authors = ["OpenPXE contributors"]
|
||||
|
||||
[workspace.dependencies]
|
||||
tokio = { version = "1.40", features = ["full"] }
|
||||
tokio = { version = "1.52", features = ["full"] }
|
||||
tokio-util = { version = "0.7", features = ["io"] }
|
||||
tokio-stream = { version = "0.1", features = ["sync"] }
|
||||
futures = "0.3"
|
||||
async-trait = "0.1"
|
||||
|
||||
dhcproto = "0.12"
|
||||
socket2 = { version = "0.5", features = ["all"] }
|
||||
# v0.6.2: dhcproto 0.15 drops the deprecated trust-dns-proto dependency
|
||||
# (replaced by hickory-proto) and carries three releases of DHCP option
|
||||
# coverage accumulated upstream — both directly relevant to the proxy core.
|
||||
dhcproto = "0.15"
|
||||
socket2 = { version = "0.6", features = ["all"] }
|
||||
bytes = "1.7"
|
||||
nom = "7.1"
|
||||
|
||||
axum = { version = "0.7", features = ["macros", "multipart", "http2"] }
|
||||
axum = { version = "0.8", features = ["macros", "multipart", "http2"] }
|
||||
tower = "0.5"
|
||||
tower-http = { version = "0.6", features = ["fs", "trace", "cors", "limit"] }
|
||||
hyper = "1.4"
|
||||
hyper = "1.9"
|
||||
reqwest = { version = "0.12", default-features = false, features = ["rustls-tls", "stream", "json"] }
|
||||
|
||||
serde = { version = "1.0", features = ["derive"] }
|
||||
@@ -52,9 +54,11 @@ thiserror = "2.0"
|
||||
clap = { version = "4.5", features = ["derive", "env"] }
|
||||
uuid = { version = "1.10", features = ["v4", "serde"] }
|
||||
time = { version = "0.3", features = ["serde", "serde-human-readable", "formatting", "macros"] }
|
||||
# sha2 stays 0.10 deliberately: bergshamra-crypto requires ^0.10, and
|
||||
# bumping to 0.11 would split the RustCrypto digest stack in the tree.
|
||||
sha2 = "0.10"
|
||||
hex = "0.4"
|
||||
bcrypt = "0.15"
|
||||
bcrypt = "0.19"
|
||||
parking_lot = "0.12"
|
||||
rust-embed = { version = "8.5", features = ["include-exclude"] }
|
||||
|
||||
@@ -76,7 +80,7 @@ lettre = { version = "0.11", default-features = false, features = ["smtp-transpo
|
||||
# C deps), so the static musl binary stays OpenSSL-free — samael was
|
||||
# rejected precisely because it hard-requires OpenSSL. We build the thin
|
||||
# SP layer (AuthnRequest, metadata parse, SAMLResponse semantics) on top.
|
||||
bergshamra = "0.4"
|
||||
bergshamra = "0.5"
|
||||
roxmltree = "0.21"
|
||||
quick-xml = "0.40"
|
||||
x509-parser = "0.18"
|
||||
@@ -95,24 +99,19 @@ base64 = "0.22"
|
||||
# binary via rustls + bergshamra — so SFTP adds ZERO new C/crypto deps
|
||||
# and the static-musl build stays OpenSSL-free.
|
||||
#
|
||||
# CRITICAL #2 — pinned to EXACTLY 0.55.0, the newest russh that
|
||||
# coexists with bergshamra-crypto (our SAML core). The RustCrypto
|
||||
# ecosystem is mid-transition: bergshamra-crypto pins a constellation of
|
||||
# release-CANDIDATE crates (`pkcs8 =0.11.0-rc.11` and its matching
|
||||
# pkcs5/spki RCs) that are API-incompatible with the STABLE versions of
|
||||
# the same crates in the same semver bucket. russh 0.56+ pulls those
|
||||
# stable crates (`pkcs5 0.8`), which silently replaces bergshamra's RC
|
||||
# copies and breaks compilation. russh ≤0.55 stays on the previous stable
|
||||
# generation (`pkcs5 0.7`, `ssh-key 0.6`), which unifies with bergshamra's
|
||||
# *stable* deps and leaves the RC bucket untouched — verified to compile.
|
||||
# 0.55 still has the merged `russh::keys` API (keys merged at 0.50).
|
||||
# IMPORTANT: do NOT bump russh past 0.55 until bergshamra-crypto adopts
|
||||
# the stable RustCrypto generation; 0.56+ will not compile in this tree.
|
||||
# CRITICAL #2 — history: this was pinned to =0.55.0 from v0.5.5 until
|
||||
# v0.6.3 because bergshamra-crypto pinned release-candidate RustCrypto
|
||||
# crates that conflicted with the stable generation russh 0.56+ pulls.
|
||||
# bergshamra 0.5 (2026-06) moved to the stable generation (pkcs8 0.11),
|
||||
# lifting the pin. v0.6.3 bumps to 0.61+, which also closes a batch of
|
||||
# RUSTSEC advisories reachable from the SFTP *client* path (unbounded
|
||||
# allocations in packet parsing — CVE-2026-48110/-46702/-46673 et al.)
|
||||
# and drops mlock on non-secret buffers (~21% SSH throughput upstream).
|
||||
#
|
||||
# SCP was deliberately rejected: the protocol is sequential-only (no
|
||||
# random access → no HTTP Range, unlike SFTP/NFS) and the mature SCP
|
||||
# crates wrap libssh2 (C + OpenSSL), which would break this build.
|
||||
russh = { version = "=0.55.0", default-features = false, features = ["ring"] }
|
||||
russh = { version = "0.61", default-features = false, features = ["ring"] }
|
||||
russh-sftp = "2.3"
|
||||
|
||||
openpxe-core = { path = "crates/core" }
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
</p>
|
||||
|
||||
<p align="center">
|
||||
<img alt="release" src="https://img.shields.io/badge/release-v0.5.8-2874d7" />
|
||||
<img alt="release" src="https://img.shields.io/badge/release-v0.6.0-2874d7" />
|
||||
<img alt="license" src="https://img.shields.io/badge/license-MIT%20%7C%20Apache--2.0-59824f" />
|
||||
<img alt="rust" src="https://img.shields.io/badge/built%20with-Rust-fb8841?logo=rust&logoColor=white" />
|
||||
<img alt="container" src="https://img.shields.io/badge/container--native-OCI%20%C2%B7%20OpenShift-2496ED?logo=docker&logoColor=white" />
|
||||
@@ -32,7 +32,7 @@ Upload `.iso` files (or point at a remote share), and any machine on the network
|
||||
them — Linux installers, live tools, or stock Windows setup — with **zero iPXE knowledge
|
||||
required by the operator.**
|
||||
|
||||
> **Status — v0.5.5, late pre-beta.** The full PXE stack, web UI, remote ISO libraries
|
||||
> **Status — v0.6.0, late pre-beta.** The full PXE stack, web UI, remote ISO libraries
|
||||
> (SMB/NFS/SFTP), Windows deployment, queued fleet rollout, SAML SSO, and Prometheus
|
||||
> metrics are implemented and test-covered. The release checklist gates every tag on the
|
||||
> full test suite + `clippy`. Currently in real-hardware validation.
|
||||
|
||||
+110
-10
@@ -23,6 +23,25 @@ pub enum ClientArch {
|
||||
Unknown(u16),
|
||||
}
|
||||
|
||||
/// Which iPXE network backend to advertise to a client (v0.6.1).
|
||||
///
|
||||
/// OpenPXE serves [`DriverMode::Firmware`] first (the firmware's own NIC
|
||||
/// stack, via `snponly`/`undionly`) and only escalates a specific MAC to
|
||||
/// [`DriverMode::Builtin`] (iPXE's bundled NIC drivers) automatically, when a
|
||||
/// firmware-net boot fails to chainload. There is no operator toggle — the
|
||||
/// DHCP proxy decides per client.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Default, Serialize, Deserialize)]
|
||||
#[serde(rename_all = "snake_case")]
|
||||
pub enum DriverMode {
|
||||
/// Reuse the firmware UNDI/SNP NIC stack (`snponly.efi`, `undionly.kpxe`).
|
||||
/// Default, smallest, most reliable for chainloading.
|
||||
#[default]
|
||||
Firmware,
|
||||
/// iPXE's own bundled NIC drivers (`ipxe.efi`, `ipxe.pxe`). Fallback for
|
||||
/// hardware whose firmware NIC stack is missing or buggy.
|
||||
Builtin,
|
||||
}
|
||||
|
||||
impl ClientArch {
|
||||
#[must_use]
|
||||
pub fn from_option_93(value: u16) -> Self {
|
||||
@@ -39,18 +58,47 @@ impl ClientArch {
|
||||
/// Default iPXE binary filename to return via TFTP for this architecture.
|
||||
/// Uses `snponly` variants which reuse the firmware's UNDI/SNP network
|
||||
/// stack — smaller binaries and broader hardware compatibility than the
|
||||
/// all-drivers-included `ipxe.efi`.
|
||||
/// all-drivers-included `ipxe.efi`. Equivalent to
|
||||
/// [`Self::ipxe_bootfile_mode`] with [`DriverMode::Firmware`]; kept as a
|
||||
/// convenience for the common firmware-net path.
|
||||
#[must_use]
|
||||
pub fn ipxe_bootfile(self) -> Option<&'static str> {
|
||||
Some(match self {
|
||||
Self::LegacyX86 => "undionly.kpxe",
|
||||
Self::Ia32Uefi => "snponly-i386.efi",
|
||||
Self::X64Uefi => "snponly.efi",
|
||||
// ARM32 UEFI: upstream boot.ipxe.org does not publish a prebuilt
|
||||
// snponly variant for this arch. We return None so the DHCP
|
||||
// proxy declines rather than advertising a file we can't serve.
|
||||
Self::Arm32Uefi | Self::Unknown(_) => return None,
|
||||
Self::Arm64Uefi => "snponly-arm64.efi",
|
||||
self.ipxe_bootfile_mode(DriverMode::Firmware)
|
||||
}
|
||||
|
||||
/// iPXE binary filename for this architecture under a given network
|
||||
/// [`DriverMode`].
|
||||
///
|
||||
/// * [`DriverMode::Firmware`] — the `snponly`/`undionly` builds that reuse
|
||||
/// the firmware's UNDI/SNP NIC stack. Smallest, and the most reliable
|
||||
/// choice for chainloading because the firmware just proved its network
|
||||
/// works by downloading the NBP. This is the default first attempt.
|
||||
/// * [`DriverMode::Builtin`] — the all-drivers `ipxe.efi`/`ipxe.pxe`
|
||||
/// builds that carry iPXE's *own* NIC drivers. The automatic fallback
|
||||
/// for clients whose firmware NIC stack is missing or buggy (v0.6.1):
|
||||
/// the DHCP proxy escalates a MAC to this mode when a firmware-net boot
|
||||
/// never completes the iPXE handoff. iPXE still includes the `snp`
|
||||
/// driver here too, so it degrades gracefully.
|
||||
#[must_use]
|
||||
pub fn ipxe_bootfile_mode(self, mode: DriverMode) -> Option<&'static str> {
|
||||
Some(match (self, mode) {
|
||||
// Legacy x86 BIOS: UNDI (firmware) vs full native-driver build.
|
||||
(Self::LegacyX86, DriverMode::Firmware) => "undionly.kpxe",
|
||||
(Self::LegacyX86, DriverMode::Builtin) => "ipxe.pxe",
|
||||
// IA32 UEFI.
|
||||
(Self::Ia32Uefi, DriverMode::Firmware) => "snponly-i386.efi",
|
||||
(Self::Ia32Uefi, DriverMode::Builtin) => "ipxe-i386.efi",
|
||||
// x86_64 UEFI — the overwhelmingly common modern client.
|
||||
(Self::X64Uefi, DriverMode::Firmware) => "snponly.efi",
|
||||
(Self::X64Uefi, DriverMode::Builtin) => "ipxe.efi",
|
||||
// ARM64 UEFI.
|
||||
(Self::Arm64Uefi, DriverMode::Firmware) => "snponly-arm64.efi",
|
||||
(Self::Arm64Uefi, DriverMode::Builtin) => "ipxe-arm64.efi",
|
||||
// ARM32 UEFI: upstream boot.ipxe.org publishes no prebuilt binary
|
||||
// for this arch in either mode. Unknown arches likewise. Return
|
||||
// None so the DHCP proxy declines rather than advertising a file
|
||||
// we can't serve.
|
||||
(Self::Arm32Uefi | Self::Unknown(_), _) => return None,
|
||||
})
|
||||
}
|
||||
|
||||
@@ -133,6 +181,58 @@ mod tests {
|
||||
assert_eq!(ClientArch::Unknown(0xFFFF).ipxe_bootfile(), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn bootfile_default_is_firmware_mode() {
|
||||
// The convenience method must equal the explicit Firmware mode.
|
||||
for a in [
|
||||
ClientArch::LegacyX86,
|
||||
ClientArch::Ia32Uefi,
|
||||
ClientArch::X64Uefi,
|
||||
ClientArch::Arm64Uefi,
|
||||
ClientArch::Arm32Uefi,
|
||||
ClientArch::Unknown(0x99),
|
||||
] {
|
||||
assert_eq!(
|
||||
a.ipxe_bootfile(),
|
||||
a.ipxe_bootfile_mode(DriverMode::Firmware)
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn builtin_mode_maps_to_all_drivers_binaries() {
|
||||
assert_eq!(
|
||||
ClientArch::LegacyX86.ipxe_bootfile_mode(DriverMode::Builtin),
|
||||
Some("ipxe.pxe")
|
||||
);
|
||||
assert_eq!(
|
||||
ClientArch::X64Uefi.ipxe_bootfile_mode(DriverMode::Builtin),
|
||||
Some("ipxe.efi")
|
||||
);
|
||||
assert_eq!(
|
||||
ClientArch::Ia32Uefi.ipxe_bootfile_mode(DriverMode::Builtin),
|
||||
Some("ipxe-i386.efi")
|
||||
);
|
||||
assert_eq!(
|
||||
ClientArch::Arm64Uefi.ipxe_bootfile_mode(DriverMode::Builtin),
|
||||
Some("ipxe-arm64.efi")
|
||||
);
|
||||
// No binary for ARM32 / unknown in either mode.
|
||||
assert_eq!(
|
||||
ClientArch::Arm32Uefi.ipxe_bootfile_mode(DriverMode::Builtin),
|
||||
None
|
||||
);
|
||||
assert_eq!(
|
||||
ClientArch::Unknown(0x99).ipxe_bootfile_mode(DriverMode::Builtin),
|
||||
None
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn driver_mode_default_is_firmware() {
|
||||
assert_eq!(DriverMode::default(), DriverMode::Firmware);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn firmware_class_detects_ipxe_over_pxeclient() {
|
||||
let c = FirmwareClass::classify(Some(b"PXEClient:Arch:00007"), Some(b"iPXE"));
|
||||
|
||||
@@ -125,9 +125,7 @@ impl AdminStore {
|
||||
{
|
||||
let mut g = self.inner.write();
|
||||
if g.admin.is_some() {
|
||||
return Err(Error::Invalid(
|
||||
"admin account already configured".into(),
|
||||
));
|
||||
return Err(Error::Invalid("admin account already configured".into()));
|
||||
}
|
||||
g.admin = Some(admin.clone());
|
||||
}
|
||||
@@ -346,7 +344,7 @@ mod tests {
|
||||
assert!(s.bootstrap("", "hunter2hunter2").is_err());
|
||||
assert!(s.bootstrap("ad:min", "hunter2hunter2").is_err()); // ':' reserved
|
||||
assert!(s.bootstrap("admin", "short").is_err()); // <8 chars
|
||||
// 65-char username is too long.
|
||||
// 65-char username is too long.
|
||||
let long = "a".repeat(65);
|
||||
assert!(s.bootstrap(&long, "hunter2hunter2").is_err());
|
||||
}
|
||||
|
||||
@@ -12,11 +12,9 @@ use time::OffsetDateTime;
|
||||
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||
pub enum ClientEvent {
|
||||
DhcpDiscover,
|
||||
DhcpRequest,
|
||||
PxeBootServerRequest,
|
||||
TftpRead { file: String },
|
||||
HttpScriptFetch { target: String },
|
||||
HttpIsoAsset { file: String },
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||
@@ -32,8 +30,6 @@ pub struct ClientSnapshot {
|
||||
// Events are left with default serialization (9-tuple) — they're
|
||||
// diagnostic only and not consumed by the UI today.
|
||||
pub events: Vec<(OffsetDateTime, ClientEvent)>,
|
||||
/// The boot target (ISO id) last selected via the iPXE menu, if any.
|
||||
pub selected_target: Option<String>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Default)]
|
||||
@@ -66,7 +62,6 @@ impl ClientRegistry {
|
||||
first_seen: now,
|
||||
last_seen: now,
|
||||
events: Vec::new(),
|
||||
selected_target: None,
|
||||
});
|
||||
entry.last_seen = now;
|
||||
if ip.is_some() {
|
||||
@@ -84,13 +79,6 @@ impl ClientRegistry {
|
||||
}
|
||||
}
|
||||
|
||||
pub fn set_selected_target(&self, mac: &str, target: Option<String>) {
|
||||
let mut guard = self.inner.write();
|
||||
if let Some(c) = guard.get_mut(mac) {
|
||||
c.selected_target = target;
|
||||
}
|
||||
}
|
||||
|
||||
#[must_use]
|
||||
pub fn list(&self) -> Vec<ClientSnapshot> {
|
||||
let guard = self.inner.read();
|
||||
@@ -99,9 +87,4 @@ impl ClientRegistry {
|
||||
v.sort_by_key(|c| std::cmp::Reverse(c.last_seen));
|
||||
v
|
||||
}
|
||||
|
||||
#[must_use]
|
||||
pub fn get(&self, mac: &str) -> Option<ClientSnapshot> {
|
||||
self.inner.read().get(mac).cloned()
|
||||
}
|
||||
}
|
||||
|
||||
@@ -40,10 +40,6 @@ pub struct NetworkConfig {
|
||||
pub dhcp_port: u16,
|
||||
/// UDP port for PXE Boot Server discovery. Standard is 4011.
|
||||
pub pxe_port: u16,
|
||||
/// Optional allowlist of client MAC prefixes (OUI). Empty = serve everyone.
|
||||
pub mac_allowlist: Vec<String>,
|
||||
/// Optional allowlist of subnets (CIDR). Empty = serve everyone.
|
||||
pub subnet_allowlist: Vec<String>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize, Default)]
|
||||
@@ -105,8 +101,6 @@ impl Default for NetworkConfig {
|
||||
dhcp_bind: IpAddr::V4(Ipv4Addr::UNSPECIFIED),
|
||||
dhcp_port: 67,
|
||||
pxe_port: 4011,
|
||||
mac_allowlist: Vec::new(),
|
||||
subnet_allowlist: Vec::new(),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -21,7 +21,7 @@ pub mod settings;
|
||||
pub mod sso;
|
||||
pub mod wol;
|
||||
|
||||
pub use arch::{ClientArch, FirmwareClass};
|
||||
pub use arch::{ClientArch, DriverMode, FirmwareClass};
|
||||
pub use auth::{AdminAccount, AdminPublic, AdminStore};
|
||||
pub use boot_log::{BootEvent, BootLog};
|
||||
pub use branding::{ext_for_mime, BrandingStore, LogoSlot, ALLOWED_LOGO_MIMES, MAX_LOGO_BYTES};
|
||||
|
||||
@@ -303,7 +303,10 @@ mod tests {
|
||||
smtp_host: "smtp.example.com".into(),
|
||||
..Default::default()
|
||||
});
|
||||
assert!(matches!(r, Err(Error::Invalid(_))), "missing recipient should reject");
|
||||
assert!(
|
||||
matches!(r, Err(Error::Invalid(_))),
|
||||
"missing recipient should reject"
|
||||
);
|
||||
s.replace(NotifyConfig {
|
||||
enabled: true,
|
||||
kind: NotifyKind::Smtp,
|
||||
|
||||
@@ -181,10 +181,7 @@ mod tests {
|
||||
Ipv4Addr::new(192, 168, 1, 255)
|
||||
);
|
||||
assert_eq!(
|
||||
subnet_broadcast(
|
||||
Ipv4Addr::new(10, 5, 3, 7),
|
||||
Ipv4Addr::new(255, 255, 0, 0)
|
||||
),
|
||||
subnet_broadcast(Ipv4Addr::new(10, 5, 3, 7), Ipv4Addr::new(255, 255, 0, 0)),
|
||||
Ipv4Addr::new(10, 5, 255, 255)
|
||||
);
|
||||
}
|
||||
@@ -196,7 +193,8 @@ mod tests {
|
||||
// and confirm send_magic transmits the exact 102-byte packet.
|
||||
let rx = UdpSocket::bind(SocketAddrV4::new(Ipv4Addr::LOCALHOST, 0)).unwrap();
|
||||
let port = rx.local_addr().unwrap().port();
|
||||
rx.set_read_timeout(Some(std::time::Duration::from_secs(2))).unwrap();
|
||||
rx.set_read_timeout(Some(std::time::Duration::from_secs(2)))
|
||||
.unwrap();
|
||||
|
||||
let packet = magic_packet([0x0a, 0x1b, 0x2c, 0x3d, 0x4e, 0x5f]);
|
||||
let sent = send_magic(&packet, &[Ipv4Addr::LOCALHOST], port).unwrap();
|
||||
|
||||
@@ -18,3 +18,4 @@ tracing.workspace = true
|
||||
thiserror.workspace = true
|
||||
anyhow.workspace = true
|
||||
bytes.workspace = true
|
||||
parking_lot.workspace = true
|
||||
|
||||
@@ -0,0 +1,237 @@
|
||||
//! Automatic per-MAC NIC driver-mode escalation (v0.6.1).
|
||||
//!
|
||||
//! OpenPXE serves the firmware-net iPXE build (`snponly`/`undionly`) by
|
||||
//! default — it's the most reliable choice for chainloading because the
|
||||
//! firmware just proved its network works by downloading the NBP. A minority
|
||||
//! of NICs have a missing or buggy firmware UNDI/SNP stack; those clients
|
||||
//! TFTP the binary fine, but then iPXE can't bring the link up, so the
|
||||
//! tell-tale second DHCP DISCOVER carrying the `iPXE` user-class never arrives
|
||||
//! and the machine eventually re-PXE-boots.
|
||||
//!
|
||||
//! We detect exactly that: a *fresh* firmware DISCOVER from a MAC whose
|
||||
//! previous firmware attempt was never confirmed by an iPXE handoff means the
|
||||
//! firmware-net build failed → escalate that MAC to [`DriverMode::Builtin`]
|
||||
//! (iPXE's own NIC drivers). The decision is sticky — once a MAC settles on a
|
||||
//! mode that completes the handoff, later boots go straight to it. There is no
|
||||
//! operator toggle; it just works, and the default (firmware) path is
|
||||
//! unchanged so hardware that already boots never regresses.
|
||||
|
||||
use openpxe_core::DriverMode;
|
||||
use parking_lot::Mutex;
|
||||
use std::collections::HashMap;
|
||||
use std::time::{Duration, Instant};
|
||||
|
||||
/// Multiple DISCOVERs within this window belong to the *same* boot (DHCP
|
||||
/// retransmits, plus the :4011 PXE Boot Server query that follows the :67
|
||||
/// DISCOVER). They must not be mistaken for a failed-and-retried boot.
|
||||
const SAME_BOOT_DEBOUNCE: Duration = Duration::from_secs(8);
|
||||
|
||||
/// Forget a MAC's state after this long with no activity, so a transient
|
||||
/// escalation doesn't pin a client to Builtin forever and the map stays
|
||||
/// bounded over a long-running deployment.
|
||||
const ENTRY_TTL: Duration = Duration::from_mins(30);
|
||||
|
||||
/// Hard cap on tracked MACs. Past this we evict the least-recently-seen
|
||||
/// entry — escalation is best-effort, never a memory-growth vector.
|
||||
const MAX_ENTRIES: usize = 4096;
|
||||
|
||||
/// How often (at most) the whole map is swept for expired entries.
|
||||
/// Correctness doesn't depend on the sweep — a stale entry is also
|
||||
/// detected inline when its MAC next appears — so the sweep only bounds
|
||||
/// memory for MACs that never return, and amortizing it keeps the
|
||||
/// per-packet path O(1) instead of O(map).
|
||||
const PRUNE_INTERVAL: Duration = Duration::from_mins(1);
|
||||
|
||||
#[derive(Debug, Clone, Copy)]
|
||||
struct Entry {
|
||||
mode: DriverMode,
|
||||
/// True once we've served `mode` and are waiting for the iPXE handoff to
|
||||
/// confirm it worked. A *new* boot arriving while this is still true means
|
||||
/// the previous attempt failed and we should escalate.
|
||||
awaiting_confirm: bool,
|
||||
last_seen: Instant,
|
||||
}
|
||||
|
||||
#[derive(Debug)]
|
||||
struct Inner {
|
||||
map: HashMap<String, Entry>,
|
||||
/// When the last full TTL sweep ran — see [`PRUNE_INTERVAL`].
|
||||
last_prune: Instant,
|
||||
}
|
||||
|
||||
impl Default for Inner {
|
||||
fn default() -> Self {
|
||||
Self {
|
||||
map: HashMap::new(),
|
||||
last_prune: Instant::now(),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Tracks per-MAC driver-mode escalation. Cheap to share via `Arc`.
|
||||
#[derive(Debug, Default)]
|
||||
pub struct DriverEscalation {
|
||||
inner: Mutex<Inner>,
|
||||
}
|
||||
|
||||
impl DriverEscalation {
|
||||
#[must_use]
|
||||
pub fn new() -> Self {
|
||||
Self::default()
|
||||
}
|
||||
|
||||
/// Decide the driver mode for a firmware (PXEClient/HTTPClient) boot from
|
||||
/// `mac`. `primary` is true for the main DHCP DISCOVER (:67) and false for
|
||||
/// the PXE Boot Server query (:4011); only the primary path drives
|
||||
/// escalation, and only when it's clearly a *new* boot (outside the
|
||||
/// same-boot debounce). The :4011 path just echoes the current mode.
|
||||
pub fn mode_for_firmware_attempt(&self, mac: &str, primary: bool) -> DriverMode {
|
||||
self.decide_at(mac, primary, Instant::now())
|
||||
}
|
||||
|
||||
/// Record that `mac` completed the iPXE handoff (a DISCOVER carrying the
|
||||
/// `iPXE` user-class). The mode we last served worked, so stop awaiting
|
||||
/// confirmation and keep it sticky for next time.
|
||||
pub fn mark_ipxe_success(&self, mac: &str) {
|
||||
self.confirm_at(mac, Instant::now());
|
||||
}
|
||||
|
||||
fn decide_at(&self, mac: &str, primary: bool, now: Instant) -> DriverMode {
|
||||
let mut g = self.inner.lock();
|
||||
if now.duration_since(g.last_prune) >= PRUNE_INTERVAL {
|
||||
g.map
|
||||
.retain(|_, e| now.duration_since(e.last_seen) < ENTRY_TTL);
|
||||
g.last_prune = now;
|
||||
}
|
||||
// Inline staleness check: a MAC whose entry outlived the TTL starts
|
||||
// fresh even when the amortized sweep above hasn't caught it yet.
|
||||
if g.map
|
||||
.get(mac)
|
||||
.is_some_and(|e| now.duration_since(e.last_seen) >= ENTRY_TTL)
|
||||
{
|
||||
g.map.remove(mac);
|
||||
}
|
||||
|
||||
match g.map.get_mut(mac) {
|
||||
None => {
|
||||
g.map.insert(
|
||||
mac.to_owned(),
|
||||
Entry {
|
||||
mode: DriverMode::Firmware,
|
||||
// Only the primary DISCOVER opens a confirmation window.
|
||||
awaiting_confirm: primary,
|
||||
last_seen: now,
|
||||
},
|
||||
);
|
||||
if g.map.len() > MAX_ENTRIES {
|
||||
evict_oldest(&mut g.map);
|
||||
}
|
||||
DriverMode::Firmware
|
||||
}
|
||||
Some(entry) => {
|
||||
let recent = now.duration_since(entry.last_seen) < SAME_BOOT_DEBOUNCE;
|
||||
if primary && !recent {
|
||||
// A genuinely new boot. If the previous attempt was never
|
||||
// confirmed, the firmware-net build failed → escalate to
|
||||
// the all-drivers build. Builtin is the most capable build
|
||||
// we have, so it's the single escalation target (and a MAC
|
||||
// already on Builtin simply stays there).
|
||||
if entry.awaiting_confirm {
|
||||
entry.mode = DriverMode::Builtin;
|
||||
}
|
||||
entry.awaiting_confirm = true;
|
||||
}
|
||||
entry.last_seen = now;
|
||||
entry.mode
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn confirm_at(&self, mac: &str, now: Instant) {
|
||||
let mut g = self.inner.lock();
|
||||
if let Some(e) = g.map.get_mut(mac) {
|
||||
e.awaiting_confirm = false;
|
||||
e.last_seen = now;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn evict_oldest(map: &mut HashMap<String, Entry>) {
|
||||
if let Some(oldest) = map
|
||||
.iter()
|
||||
.min_by_key(|(_, e)| e.last_seen)
|
||||
.map(|(k, _)| k.clone())
|
||||
{
|
||||
map.remove(&oldest);
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn firmware_first_then_escalates_on_unconfirmed_retry() {
|
||||
let e = DriverEscalation::new();
|
||||
let t0 = Instant::now();
|
||||
// Boot 1, primary DISCOVER: firmware.
|
||||
assert_eq!(e.decide_at("aa", true, t0), DriverMode::Firmware);
|
||||
// Same boot's :4011 query (+1s, within debounce): still firmware, no escalation.
|
||||
assert_eq!(
|
||||
e.decide_at("aa", false, t0 + Duration::from_secs(1)),
|
||||
DriverMode::Firmware
|
||||
);
|
||||
// Firmware net failed → no iPXE handoff → machine re-PXE-boots much
|
||||
// later: escalate to builtin drivers.
|
||||
assert_eq!(
|
||||
e.decide_at("aa", true, t0 + Duration::from_mins(1)),
|
||||
DriverMode::Builtin
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn builtin_is_sticky_after_success() {
|
||||
let e = DriverEscalation::new();
|
||||
let t0 = Instant::now();
|
||||
assert_eq!(e.decide_at("bb", true, t0), DriverMode::Firmware);
|
||||
assert_eq!(
|
||||
e.decide_at("bb", true, t0 + Duration::from_mins(1)),
|
||||
DriverMode::Builtin
|
||||
);
|
||||
// Builtin worked this time — confirm the handoff.
|
||||
e.confirm_at("bb", t0 + Duration::from_secs(61));
|
||||
// Next cold boot goes straight to builtin (no wasted firmware attempt).
|
||||
assert_eq!(
|
||||
e.decide_at("bb", true, t0 + Duration::from_mins(2)),
|
||||
DriverMode::Builtin
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn confirmed_firmware_never_escalates() {
|
||||
let e = DriverEscalation::new();
|
||||
let t0 = Instant::now();
|
||||
assert_eq!(e.decide_at("cc", true, t0), DriverMode::Firmware);
|
||||
// snponly worked: handoff confirmed.
|
||||
e.confirm_at("cc", t0 + Duration::from_secs(2));
|
||||
// A later boot stays on firmware — no spurious escalation.
|
||||
assert_eq!(
|
||||
e.decide_at("cc", true, t0 + Duration::from_mins(5)),
|
||||
DriverMode::Firmware
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn stale_entry_is_forgotten_and_resets_to_firmware() {
|
||||
let e = DriverEscalation::new();
|
||||
let t0 = Instant::now();
|
||||
assert_eq!(e.decide_at("dd", true, t0), DriverMode::Firmware);
|
||||
assert_eq!(
|
||||
e.decide_at("dd", true, t0 + Duration::from_mins(1)),
|
||||
DriverMode::Builtin
|
||||
);
|
||||
// After the TTL with no activity the entry is pruned → fresh firmware.
|
||||
let later = t0 + Duration::from_mins(1) + ENTRY_TTL + Duration::from_secs(1);
|
||||
assert_eq!(e.decide_at("dd", true, later), DriverMode::Firmware);
|
||||
}
|
||||
}
|
||||
@@ -17,7 +17,9 @@
|
||||
//! clients silently drop them.
|
||||
#![forbid(unsafe_code)]
|
||||
|
||||
pub mod escalation;
|
||||
pub mod reply;
|
||||
pub mod server;
|
||||
|
||||
pub use escalation::DriverEscalation;
|
||||
pub use server::DhcpProxyServer;
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
//! pass, or the HTTP URL of the boot script once iPXE has chained.
|
||||
|
||||
use dhcproto::v4::{DhcpOption, Message, MessageType, Opcode, OptionCode};
|
||||
use openpxe_core::{ClientArch, FirmwareClass};
|
||||
use openpxe_core::{ClientArch, DriverMode, FirmwareClass};
|
||||
use std::net::Ipv4Addr;
|
||||
|
||||
/// Where the reply directs the client next.
|
||||
@@ -31,6 +31,11 @@ pub struct ReplyContext<'a> {
|
||||
pub our_ip: Ipv4Addr,
|
||||
pub arch: ClientArch,
|
||||
pub class: FirmwareClass,
|
||||
/// Which iPXE network backend to advertise for this client. The DHCP
|
||||
/// proxy fills this from the automatic per-MAC escalation state: normally
|
||||
/// [`DriverMode::Firmware`], escalated to [`DriverMode::Builtin`] for a
|
||||
/// MAC whose firmware-net boot failed to chainload (v0.6.1).
|
||||
pub driver_mode: DriverMode,
|
||||
/// Public base URL (scheme://host[:port]) used in HTTP directives.
|
||||
pub public_base_url: &'a str,
|
||||
}
|
||||
@@ -52,9 +57,13 @@ pub fn decide(ctx: &ReplyContext<'_>) -> BootDirective {
|
||||
},
|
||||
FirmwareClass::HttpClient => {
|
||||
// UEFI HTTP boot: client wants an http:// URL in option 67
|
||||
// pointing at an EFI executable. We serve ipxe.efi over HTTP;
|
||||
// it'll then do the same script-fetch the iPXE path does.
|
||||
let name = ctx.arch.ipxe_bootfile().unwrap_or("snponly.efi");
|
||||
// pointing at an EFI executable. We serve the iPXE EFI build for
|
||||
// the negotiated driver mode over HTTP; it'll then do the same
|
||||
// script-fetch the iPXE path does.
|
||||
let name = ctx
|
||||
.arch
|
||||
.ipxe_bootfile_mode(ctx.driver_mode)
|
||||
.unwrap_or("snponly.efi");
|
||||
BootDirective::HttpScript {
|
||||
url: format!(
|
||||
"{}/ipxe/{}",
|
||||
@@ -63,7 +72,7 @@ pub fn decide(ctx: &ReplyContext<'_>) -> BootDirective {
|
||||
),
|
||||
}
|
||||
}
|
||||
FirmwareClass::PxeClient => match ctx.arch.ipxe_bootfile() {
|
||||
FirmwareClass::PxeClient => match ctx.arch.ipxe_bootfile_mode(ctx.driver_mode) {
|
||||
Some(name) => BootDirective::TftpIpxe {
|
||||
filename: name.to_string(),
|
||||
},
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
//! UDP listener loop for the DHCP proxy. Accepts on :67 (and :4011 on a
|
||||
//! second socket) and dispatches each datagram through the pure reply logic.
|
||||
|
||||
use crate::escalation::DriverEscalation;
|
||||
use crate::reply::{build_reply, decide, BootDirective, ReplyContext};
|
||||
use dhcproto::v4::{DhcpOption, Message, OptionCode};
|
||||
use dhcproto::{Decodable, Decoder, Encodable, Encoder};
|
||||
use openpxe_core::{ClientArch, ClientEvent, ClientRegistry, FirmwareClass};
|
||||
use openpxe_core::{ClientArch, ClientEvent, ClientRegistry, DriverMode, FirmwareClass};
|
||||
use socket2::{Domain, Protocol, Socket, Type};
|
||||
use std::net::{IpAddr, Ipv4Addr, SocketAddr, SocketAddrV4};
|
||||
use std::sync::Arc;
|
||||
@@ -18,6 +19,9 @@ pub struct DhcpProxyServer {
|
||||
public_base_url: String,
|
||||
clients: Arc<ClientRegistry>,
|
||||
metrics: openpxe_core::Metrics,
|
||||
/// Automatic per-MAC NIC driver-mode escalation (v0.6.1). Shared across
|
||||
/// the :67 and :4011 listener tasks via the server `Arc`.
|
||||
escalation: DriverEscalation,
|
||||
}
|
||||
|
||||
impl DhcpProxyServer {
|
||||
@@ -38,6 +42,7 @@ impl DhcpProxyServer {
|
||||
public_base_url,
|
||||
clients,
|
||||
metrics,
|
||||
escalation: DriverEscalation::new(),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -126,11 +131,30 @@ impl DhcpProxyServer {
|
||||
},
|
||||
);
|
||||
|
||||
// Automatic NIC driver-mode selection (v0.6.1). The default is
|
||||
// firmware-net (snponly/undionly). A successful iPXE handoff confirms
|
||||
// the current mode works for this MAC; a fresh firmware boot whose
|
||||
// predecessor never handed off escalates the MAC to iPXE's built-in
|
||||
// NIC drivers. No operator toggle — the firmware path is unchanged so
|
||||
// hardware that already boots never regresses.
|
||||
let driver_mode = match class {
|
||||
FirmwareClass::IpxeUserClass => {
|
||||
self.escalation.mark_ipxe_success(&mac);
|
||||
DriverMode::Firmware // unused: this path serves the HTTP script
|
||||
}
|
||||
FirmwareClass::PxeClient | FirmwareClass::HttpClient => self
|
||||
.escalation
|
||||
.mode_for_firmware_attempt(&mac, label == "67"),
|
||||
// Unreachable: FirmwareClass::Other returned above.
|
||||
FirmwareClass::Other => DriverMode::Firmware,
|
||||
};
|
||||
|
||||
let ctx = ReplyContext {
|
||||
request: &request,
|
||||
our_ip: self.our_ip,
|
||||
arch,
|
||||
class,
|
||||
driver_mode,
|
||||
public_base_url: &self.public_base_url,
|
||||
};
|
||||
let directive = decide(&ctx);
|
||||
@@ -154,7 +178,7 @@ impl DhcpProxyServer {
|
||||
sock.send_to(&out, dest).await?;
|
||||
tracing::info!(
|
||||
target: "openpxe::dhcp",
|
||||
mac=%mac, arch=arch.as_str(), class=?class, dest=%dest, directive=?directive,
|
||||
mac=%mac, arch=arch.as_str(), class=?class, driver=?driver_mode, dest=%dest, directive=?directive,
|
||||
"PXE reply sent"
|
||||
);
|
||||
Ok(())
|
||||
@@ -213,11 +237,16 @@ fn bind_udp(bind: IpAddr, port: u16, broadcast: bool) -> anyhow::Result<UdpSocke
|
||||
}
|
||||
|
||||
fn format_mac(chaddr: &[u8]) -> String {
|
||||
let take = chaddr.iter().take(6).copied().collect::<Vec<_>>();
|
||||
take.iter()
|
||||
.map(|b| format!("{b:02x}"))
|
||||
.collect::<Vec<_>>()
|
||||
.join(":")
|
||||
use std::fmt::Write;
|
||||
// One allocation — this runs for every PXE datagram we answer.
|
||||
let mut s = String::with_capacity(17);
|
||||
for (i, b) in chaddr.iter().take(6).enumerate() {
|
||||
if i > 0 {
|
||||
s.push(':');
|
||||
}
|
||||
let _ = write!(s, "{b:02x}");
|
||||
}
|
||||
s
|
||||
}
|
||||
|
||||
/// Walk raw DHCP options looking for option 93 (Client System Architecture)
|
||||
|
||||
+120
-61
@@ -35,7 +35,7 @@ use openpxe_core::{
|
||||
encoding::pct_encode, ext_for_mime, wol, BootEvent, ClientEvent, DeployProfile, Error,
|
||||
LogoSlot, NotifyConfig, Settings, SsoConfig, ALLOWED_LOGO_MIMES, MAX_LOGO_BYTES,
|
||||
};
|
||||
use openpxe_ipxe_assets::asset_bytes;
|
||||
use openpxe_ipxe_assets::asset_slice;
|
||||
use openpxe_iso_store::{
|
||||
render_template, IsoCategory, IsoMeta, IsoSource, NfsAddRequest, SftpAddRequest, SmbAddRequest,
|
||||
SmbState, UnattendedKind, UnattendedMeta,
|
||||
@@ -71,7 +71,7 @@ pub fn build_router(state: AppState) -> Router {
|
||||
.route("/branding/pxe-logo", get(ui_pxe_logo))
|
||||
// iPXE script endpoints.
|
||||
.route("/boot.ipxe", get(boot_top_menu))
|
||||
.route("/boot/:filename", get(boot_sub))
|
||||
.route("/boot/{filename}", get(boot_sub))
|
||||
// v0.5.2: unattended answer-file *serving* — public (like /iso),
|
||||
// because the booting installer fetches these with no session.
|
||||
// `/unattended/:id` serves a Kickstart/Preseed with `{{HOSTNAME}}`
|
||||
@@ -80,12 +80,12 @@ pub fn build_router(state: AppState) -> Router {
|
||||
// autoinstall (`…/<ctx>/user-data` + `/meta-data`), where `<ctx>`
|
||||
// base64url-encodes the per-host hostname/ip/mac. Management
|
||||
// (upload/list/delete) lives under the gated `/api/unattended`.
|
||||
.route("/unattended/:id", get(serve_unattended))
|
||||
.route("/unattended/:id/:ctx/:sub", get(serve_unattended_seed))
|
||||
.route("/unattended/{id}", get(serve_unattended))
|
||||
.route("/unattended/{id}/{ctx}/{sub}", get(serve_unattended_seed))
|
||||
// Bundled binaries and raw ISO access.
|
||||
.route("/ipxe/:name", get(ipxe_binary))
|
||||
.route("/iso/:filename", get(iso_raw))
|
||||
.route("/iso/:id/*path", get(iso_file))
|
||||
.route("/ipxe/{name}", get(ipxe_binary))
|
||||
.route("/iso/{filename}", get(iso_raw))
|
||||
.route("/iso/{id}/{*path}", get(iso_file))
|
||||
// Container health/readiness probes. `/healthz` is always 200 OK
|
||||
// while the HTTP task is alive. `/readyz` additionally requires at
|
||||
// least one bundled iPXE binary (without one, no client can PXE).
|
||||
@@ -93,23 +93,23 @@ pub fn build_router(state: AppState) -> Router {
|
||||
.route("/readyz", get(readyz))
|
||||
// JSON API.
|
||||
.route("/api/isos", get(api_list_isos).post(api_upload_iso))
|
||||
.route("/api/isos/:id", delete(api_delete_iso))
|
||||
.route("/api/isos/{id}", delete(api_delete_iso))
|
||||
.route("/api/uploads", post(api_upload_begin))
|
||||
.route(
|
||||
"/api/uploads/:upload_id",
|
||||
"/api/uploads/{upload_id}",
|
||||
put(api_upload_chunk).delete(api_upload_abort),
|
||||
)
|
||||
// Per-ISO password prompt. PUT body `{ "password": "..." }`
|
||||
// sets, `{ "password": null }` (or DELETE) clears.
|
||||
.route(
|
||||
"/api/isos/:id/password",
|
||||
"/api/isos/{id}/password",
|
||||
axum::routing::put(api_set_iso_password).delete(api_clear_iso_password),
|
||||
)
|
||||
// v0.4.4: per-ISO menu category (Os / Tools). Drives whether the
|
||||
// image appears under Linux/Windows Installers (default) or in
|
||||
// the Tools submenu next to memtest / shell / NIC info.
|
||||
.route(
|
||||
"/api/isos/:id/category",
|
||||
"/api/isos/{id}/category",
|
||||
axum::routing::put(api_set_iso_category),
|
||||
)
|
||||
// v0.4.4: filesystem free-space telemetry for the ISO directory's
|
||||
@@ -120,7 +120,7 @@ pub fn build_router(state: AppState) -> Router {
|
||||
// logo). v0.5.2: split into three slots — `light` / `dark` /
|
||||
// `client`. Multipart upload to POST; DELETE clears one slot.
|
||||
.route(
|
||||
"/api/branding/logo/:slot",
|
||||
"/api/branding/logo/{slot}",
|
||||
post(api_branding_upload).delete(api_branding_clear),
|
||||
)
|
||||
// v0.5.2: unattended-install answer-file management (gated).
|
||||
@@ -130,7 +130,7 @@ pub fn build_router(state: AppState) -> Router {
|
||||
"/api/unattended",
|
||||
get(api_unattended_list).post(api_unattended_upload),
|
||||
)
|
||||
.route("/api/unattended/:id", delete(api_unattended_delete))
|
||||
.route("/api/unattended/{id}", delete(api_unattended_delete))
|
||||
// v0.4.4: self-rendered API reference, served as JSON so the UI
|
||||
// can format it consistently with the rest of the chrome. Lives
|
||||
// under the Settings tab — operators chasing an integration get
|
||||
@@ -161,12 +161,12 @@ pub fn build_router(state: AppState) -> Router {
|
||||
.route("/api/settings", get(api_get_settings).put(api_put_settings))
|
||||
.route("/api/queue", get(api_list_queue))
|
||||
.route("/api/queue/join", get(api_queue_join))
|
||||
.route("/api/queue/poll/:entry_id", get(api_queue_poll))
|
||||
.route("/api/queue/poll/{entry_id}", get(api_queue_poll))
|
||||
.route("/api/queue/assign", post(api_queue_assign))
|
||||
// v0.5.2: per-device deployment profile (auto hostname / IP /
|
||||
// unattended file) set from the queue "Profile" button.
|
||||
.route("/api/queue/:entry_id/profile", put(api_queue_set_profile))
|
||||
.route("/api/queue/:entry_id", delete(api_queue_release))
|
||||
.route("/api/queue/{entry_id}/profile", put(api_queue_set_profile))
|
||||
.route("/api/queue/{entry_id}", delete(api_queue_release))
|
||||
// v0.4.65: SMB share manager (userspace via smbclient). The
|
||||
// kernel-mount NFS routes that v0.4.64 shipped are gone — they
|
||||
// didn't work on hosts whose kernel lacked the nfs client
|
||||
@@ -177,8 +177,8 @@ pub fn build_router(state: AppState) -> Router {
|
||||
"/api/smb-shares",
|
||||
get(api_smb_shares_list).post(api_smb_shares_add),
|
||||
)
|
||||
.route("/api/smb-shares/:id", delete(api_smb_shares_remove))
|
||||
.route("/api/smb-shares/:id/scan", post(api_smb_shares_scan))
|
||||
.route("/api/smb-shares/{id}", delete(api_smb_shares_remove))
|
||||
.route("/api/smb-shares/{id}/scan", post(api_smb_shares_scan))
|
||||
// v0.4.67: NFSv3 share manager (pure-Rust in-process client).
|
||||
// Ships alongside SMB. Routes are parallel so the UI can
|
||||
// reuse the same form/error/hint rendering for both.
|
||||
@@ -186,8 +186,8 @@ pub fn build_router(state: AppState) -> Router {
|
||||
"/api/nfs-shares",
|
||||
get(api_nfs_shares_list).post(api_nfs_shares_add),
|
||||
)
|
||||
.route("/api/nfs-shares/:id", delete(api_nfs_shares_remove))
|
||||
.route("/api/nfs-shares/:id/scan", post(api_nfs_shares_scan))
|
||||
.route("/api/nfs-shares/{id}", delete(api_nfs_shares_remove))
|
||||
.route("/api/nfs-shares/{id}/scan", post(api_nfs_shares_scan))
|
||||
// v0.5.5: SFTP-over-SSH share manager (pure-Rust russh client).
|
||||
// Parallel to SMB/NFS so the UI reuses the same form/error/hint
|
||||
// rendering. Like NFS, SFTP-sourced ISOs support Range requests.
|
||||
@@ -195,8 +195,8 @@ pub fn build_router(state: AppState) -> Router {
|
||||
"/api/sftp-shares",
|
||||
get(api_sftp_shares_list).post(api_sftp_shares_add),
|
||||
)
|
||||
.route("/api/sftp-shares/:id", delete(api_sftp_shares_remove))
|
||||
.route("/api/sftp-shares/:id/scan", post(api_sftp_shares_scan))
|
||||
.route("/api/sftp-shares/{id}", delete(api_sftp_shares_remove))
|
||||
.route("/api/sftp-shares/{id}/scan", post(api_sftp_shares_scan))
|
||||
// Phase 4: Network info (read-only) + DNS edit.
|
||||
.route("/api/network", get(api_network).put(api_network_put))
|
||||
// Phase 4: live-log stream + recent buffer for the Terminal tab.
|
||||
@@ -208,10 +208,10 @@ pub fn build_router(state: AppState) -> Router {
|
||||
// Phase 5: per-MAC host bindings. Operator
|
||||
// pins a MAC to a boot entry; /boot.ipxe?mac=... chains directly.
|
||||
.route("/api/hosts", get(api_hosts_list).post(api_hosts_upsert))
|
||||
.route("/api/hosts/:mac", delete(api_hosts_remove))
|
||||
.route("/api/hosts/{mac}", delete(api_hosts_remove))
|
||||
// v0.5.0: Wake-on-LAN a bound host. Sends a magic packet to the
|
||||
// limited broadcast + the server's own subnet broadcast.
|
||||
.route("/api/hosts/:mac/wol", post(api_hosts_wol))
|
||||
.route("/api/hosts/{mac}/wol", post(api_hosts_wol))
|
||||
// Rolling "host log" of boot events: what image actually
|
||||
// started installing on what MAC/IP, and when. Persisted to disk.
|
||||
.route("/api/boot-log", get(api_boot_log))
|
||||
@@ -406,6 +406,22 @@ fn bundled_logo_response() -> Response {
|
||||
/// brand mark falls back to the *default* background for the PXE screen
|
||||
/// (the WebUI still renders the SVG natively in the top-left).
|
||||
async fn ui_pxe_logo(State(state): State<AppState>) -> Response {
|
||||
// The composite is a pure function of the uploaded logo, so the
|
||||
// encoded PNG is cached keyed on the branding revision — an upload
|
||||
// or clear bumps the rev and invalidates it. The response headers
|
||||
// stay `no-cache` (clients must refetch); only the server-side
|
||||
// ~50-200 ms decode/compose/encode is skipped per boot.
|
||||
let rev = state.branding.logo_rev();
|
||||
let cached = state
|
||||
.pxe_bg_cache
|
||||
.lock()
|
||||
.as_ref()
|
||||
.filter(|(r, _)| *r == rev)
|
||||
.map(|(_, png)| png.clone());
|
||||
if let Some(png) = cached {
|
||||
return pxe_png_response(png);
|
||||
}
|
||||
|
||||
// Resolve the operator's raster upload, if any and if it's a format
|
||||
// iPXE/our compositor can consume. SVG (or a missing/unreadable
|
||||
// file) yields `None`, which composes the default background.
|
||||
@@ -450,6 +466,12 @@ async fn ui_pxe_logo(State(state): State<AppState>) -> Response {
|
||||
.into_response();
|
||||
}
|
||||
};
|
||||
let png = bytes::Bytes::from(composed);
|
||||
*state.pxe_bg_cache.lock() = Some((rev, png.clone()));
|
||||
pxe_png_response(png)
|
||||
}
|
||||
|
||||
fn pxe_png_response(png: bytes::Bytes) -> Response {
|
||||
(
|
||||
[
|
||||
(header::CONTENT_TYPE, HeaderValue::from_static("image/png")),
|
||||
@@ -460,7 +482,7 @@ async fn ui_pxe_logo(State(state): State<AppState>) -> Response {
|
||||
HeaderValue::from_static("no-cache, max-age=0"),
|
||||
),
|
||||
],
|
||||
composed,
|
||||
png,
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
@@ -498,14 +520,15 @@ fn text_plain(body: String) -> Response {
|
||||
/// to the bound target instead of rendering the menu.
|
||||
async fn boot_top_menu(
|
||||
State(state): State<AppState>,
|
||||
peer: Option<ConnectInfo<SocketAddr>>,
|
||||
peer: Result<ConnectInfo<SocketAddr>, axum::extract::rejection::ExtensionRejection>,
|
||||
Query(p): Query<BootMenuParams>,
|
||||
) -> Response {
|
||||
// `ConnectInfo` is only populated when axum was started with
|
||||
// `into_make_service_with_connect_info` (production path). Tests
|
||||
// call the router via `oneshot`, which skips that wiring — we
|
||||
// tolerate it by treating the peer as unknown rather than 500ing.
|
||||
let peer_ip = peer.map(|c| c.0.ip());
|
||||
// (axum 0.8: `Result<T, Rejection>` is the optional-extractor form.)
|
||||
let peer_ip = peer.ok().map(|c| c.0.ip());
|
||||
state
|
||||
.metrics
|
||||
.record_http(openpxe_core::HttpRoute::BootScript);
|
||||
@@ -597,11 +620,12 @@ struct BootSubParams {
|
||||
|
||||
async fn boot_sub(
|
||||
State(state): State<AppState>,
|
||||
peer: Option<ConnectInfo<SocketAddr>>,
|
||||
peer: Result<ConnectInfo<SocketAddr>, axum::extract::rejection::ExtensionRejection>,
|
||||
AxumPath(filename): AxumPath<String>,
|
||||
Query(p): Query<BootSubParams>,
|
||||
) -> Response {
|
||||
let peer_ip = peer.map(|c| c.0.ip());
|
||||
// axum 0.8: `Result<T, Rejection>` is the optional-extractor form.
|
||||
let peer_ip = peer.ok().map(|c| c.0.ip());
|
||||
// `/boot/<name>.ipxe` where `<name>` is either one of our reserved
|
||||
// submenu names (prefixed `_`) or a boot entry id.
|
||||
let name = filename.strip_suffix(".ipxe").unwrap_or(&filename);
|
||||
@@ -638,7 +662,23 @@ async fn boot_sub(
|
||||
));
|
||||
}
|
||||
Some(token) => {
|
||||
match state.iso_store.verify_password(&iso.id, token) {
|
||||
// bcrypt verify costs ~100-200 ms of pure
|
||||
// CPU and this path is unauthenticated —
|
||||
// run it on the blocking pool so password
|
||||
// probes can't stall the workers that are
|
||||
// streaming ISO bytes to imaging machines.
|
||||
let store = state.iso_store.clone();
|
||||
let iso_id = iso.id.clone();
|
||||
let tok = token.to_string();
|
||||
let verdict = match tokio::task::spawn_blocking(move || {
|
||||
store.verify_password(&iso_id, &tok)
|
||||
})
|
||||
.await
|
||||
{
|
||||
Ok(v) => v,
|
||||
Err(e) => Err(openpxe_core::Error::Other(e.into())),
|
||||
};
|
||||
match verdict {
|
||||
Ok(true) => { /* fall through to render the entry */ }
|
||||
Ok(false) => {
|
||||
// Don't log the candidate — just the
|
||||
@@ -735,9 +775,15 @@ async fn ipxe_binary(AxumPath(name): AxumPath<String>) -> Response {
|
||||
if name.contains('/') || name.contains('\\') {
|
||||
return (StatusCode::BAD_REQUEST, "invalid name").into_response();
|
||||
}
|
||||
let Some(bytes) = asset_bytes(&name) else {
|
||||
let Some(data) = asset_slice(&name) else {
|
||||
return (StatusCode::NOT_FOUND, "no such ipxe asset").into_response();
|
||||
};
|
||||
// Release builds embed the asset in rodata — serve it without the
|
||||
// ~1 MiB per-request heap copy `into_owned` would cost.
|
||||
let bytes = match data {
|
||||
std::borrow::Cow::Borrowed(b) => bytes::Bytes::from_static(b),
|
||||
std::borrow::Cow::Owned(v) => bytes::Bytes::from(v),
|
||||
};
|
||||
(
|
||||
[
|
||||
(
|
||||
@@ -768,7 +814,10 @@ async fn iso_raw(
|
||||
};
|
||||
match &meta.source {
|
||||
IsoSource::Local => {
|
||||
let Some(path) = state.iso_store.iso_path_for(id) else {
|
||||
// `local_path(&meta)` reuses the meta we already cloned —
|
||||
// `iso_path_for(id)` would re-lock and deep-clone it again,
|
||||
// hundreds of times per sanboot install.
|
||||
let Some(path) = state.iso_store.local_path(&meta) else {
|
||||
return (StatusCode::NOT_FOUND, "no such iso").into_response();
|
||||
};
|
||||
match stream_file_range(&path, headers.get(header::RANGE)).await {
|
||||
@@ -1027,15 +1076,25 @@ fn parse_range(h: Option<&HeaderValue>, total: u64) -> Option<(u64, u64, bool)>
|
||||
return Some((total.saturating_sub(n), total.saturating_sub(1), true));
|
||||
}
|
||||
}
|
||||
let mut parts = spec.splitn(2, '-');
|
||||
let start = parts
|
||||
.next()
|
||||
.and_then(|s| s.parse::<u64>().ok())
|
||||
.unwrap_or(0);
|
||||
let end = parts
|
||||
.next()
|
||||
.and_then(|s| s.parse::<u64>().ok())
|
||||
.unwrap_or(total.saturating_sub(1));
|
||||
// RFC 7233 §3.1: a Range header we can't parse is *ignored* (200 +
|
||||
// full body), never coerced into a bogus 206 claiming the whole
|
||||
// file. Only `first-pos[-last-pos]` with numeric positions reaches
|
||||
// the partial path; `None` is reserved for syntactically valid but
|
||||
// unsatisfiable ranges (→ 416).
|
||||
let full = Some((0, total.saturating_sub(1), false));
|
||||
let Some((start_s, end_s)) = spec.split_once('-') else {
|
||||
return full;
|
||||
};
|
||||
let Ok(start) = start_s.trim().parse::<u64>() else {
|
||||
return full;
|
||||
};
|
||||
let end = if end_s.trim().is_empty() {
|
||||
total.saturating_sub(1)
|
||||
} else if let Ok(e) = end_s.trim().parse::<u64>() {
|
||||
e
|
||||
} else {
|
||||
return full;
|
||||
};
|
||||
if start >= total {
|
||||
return None;
|
||||
}
|
||||
@@ -1503,13 +1562,13 @@ async fn api_docs() -> Json<serde_json::Value> {
|
||||
"summary": "List ISOs (local + NFS) with size, family, boot entries, category."},
|
||||
{"method": "POST", "path": "/api/isos",
|
||||
"summary": "Legacy single-shot multipart upload. Prefer /api/uploads for big files."},
|
||||
{"method": "DELETE", "path": "/api/isos/:id",
|
||||
{"method": "DELETE", "path": "/api/isos/{id}",
|
||||
"summary": "Delete a local ISO and its sidecar metadata."},
|
||||
{"method": "PUT", "path": "/api/isos/:id/password",
|
||||
{"method": "PUT", "path": "/api/isos/{id}/password",
|
||||
"summary": "Set or update an ISO's boot password (bcrypt-hashed; plaintext never stored)."},
|
||||
{"method": "DELETE", "path": "/api/isos/:id/password",
|
||||
{"method": "DELETE", "path": "/api/isos/{id}/password",
|
||||
"summary": "Clear an ISO's boot password."},
|
||||
{"method": "PUT", "path": "/api/isos/:id/category",
|
||||
{"method": "PUT", "path": "/api/isos/{id}/category",
|
||||
"summary": "Set the menu category. Body: { \"category\": \"os\" | \"tools\" }."},
|
||||
],
|
||||
},
|
||||
@@ -1518,9 +1577,9 @@ async fn api_docs() -> Json<serde_json::Value> {
|
||||
"endpoints": [
|
||||
{"method": "POST", "path": "/api/uploads",
|
||||
"summary": "Begin a chunked upload session. Body: { \"filename\", \"size_bytes\" }."},
|
||||
{"method": "PUT", "path": "/api/uploads/:upload_id",
|
||||
{"method": "PUT", "path": "/api/uploads/{upload_id}",
|
||||
"summary": "Append a chunk. Headers: x-openpxe-upload-offset, x-openpxe-upload-complete."},
|
||||
{"method": "DELETE", "path": "/api/uploads/:upload_id",
|
||||
{"method": "DELETE", "path": "/api/uploads/{upload_id}",
|
||||
"summary": "Abort a chunked upload session and remove the .partial file."},
|
||||
],
|
||||
},
|
||||
@@ -1531,9 +1590,9 @@ async fn api_docs() -> Json<serde_json::Value> {
|
||||
"summary": "List configured SMB shares with connection state and iso counts."},
|
||||
{"method": "POST", "path": "/api/smb-shares",
|
||||
"summary": "Register an SMB share. Body: { server, share, guest, username?, password?, port? }."},
|
||||
{"method": "DELETE", "path": "/api/smb-shares/:id",
|
||||
{"method": "DELETE", "path": "/api/smb-shares/{id}",
|
||||
"summary": "Forget a share and drop its entries from the ISO store."},
|
||||
{"method": "POST", "path": "/api/smb-shares/:id/scan",
|
||||
{"method": "POST", "path": "/api/smb-shares/{id}/scan",
|
||||
"summary": "Re-list a share for new ISOs."},
|
||||
],
|
||||
},
|
||||
@@ -1544,9 +1603,9 @@ async fn api_docs() -> Json<serde_json::Value> {
|
||||
"summary": "List configured NFSv3 shares with connection state and iso counts."},
|
||||
{"method": "POST", "path": "/api/nfs-shares",
|
||||
"summary": "Register an NFSv3 share. Body: { server, export, port? }. Auth is AUTH_SYS only; access control is by client IP on the server side."},
|
||||
{"method": "DELETE", "path": "/api/nfs-shares/:id",
|
||||
{"method": "DELETE", "path": "/api/nfs-shares/{id}",
|
||||
"summary": "Forget a share and drop its entries from the ISO store."},
|
||||
{"method": "POST", "path": "/api/nfs-shares/:id/scan",
|
||||
{"method": "POST", "path": "/api/nfs-shares/{id}/scan",
|
||||
"summary": "Re-list a share for new ISOs."},
|
||||
],
|
||||
},
|
||||
@@ -1557,9 +1616,9 @@ async fn api_docs() -> Json<serde_json::Value> {
|
||||
"summary": "List configured SFTP-over-SSH shares with connection state and iso counts."},
|
||||
{"method": "POST", "path": "/api/sftp-shares",
|
||||
"summary": "Register an SFTP share. Body: { server, export, username, port?, password? | private_key? + passphrase? }. The server's SSH host key is pinned trust-on-first-use."},
|
||||
{"method": "DELETE", "path": "/api/sftp-shares/:id",
|
||||
{"method": "DELETE", "path": "/api/sftp-shares/{id}",
|
||||
"summary": "Forget a share, drop its entries from the ISO store, and scrub its credentials file."},
|
||||
{"method": "POST", "path": "/api/sftp-shares/:id/scan",
|
||||
{"method": "POST", "path": "/api/sftp-shares/{id}/scan",
|
||||
"summary": "Re-list a share for new ISOs."},
|
||||
],
|
||||
},
|
||||
@@ -1579,9 +1638,9 @@ async fn api_docs() -> Json<serde_json::Value> {
|
||||
"summary": "Current runtime settings (Windows toggle, timeout, dns hint, …)."},
|
||||
{"method": "PUT", "path": "/api/settings",
|
||||
"summary": "Replace runtime settings. Guards against enabling Windows when wimboot isn't bundled."},
|
||||
{"method": "POST", "path": "/api/branding/logo/:slot",
|
||||
{"method": "POST", "path": "/api/branding/logo/{slot}",
|
||||
"summary": "Upload a custom logo for a slot (light | dark | client). Multipart 'file', PNG/SVG/JPEG/WebP/GIF up to 2 MB. The client slot is raster-only."},
|
||||
{"method": "DELETE", "path": "/api/branding/logo/:slot",
|
||||
{"method": "DELETE", "path": "/api/branding/logo/{slot}",
|
||||
"summary": "Remove the custom logo for a slot and revert to the bundled mark."},
|
||||
{"method": "GET", "path": "/branding/pxe-logo",
|
||||
"summary": "Raster form of the operator's 'client' logo for the iPXE menu's `console --picture`. Default background when unset/SVG."},
|
||||
@@ -1622,9 +1681,9 @@ async fn api_docs() -> Json<serde_json::Value> {
|
||||
"summary": "List uploaded answer files (Kickstart / Preseed / Autoinstall / Windows answer file)."},
|
||||
{"method": "POST", "path": "/api/unattended",
|
||||
"summary": "Upload an answer file (multipart 'file', .ks/.cfg/.seed/.yaml/.yml/.xml/user-data, up to 1 MB)."},
|
||||
{"method": "DELETE", "path": "/api/unattended/:id",
|
||||
{"method": "DELETE", "path": "/api/unattended/{id}",
|
||||
"summary": "Delete an uploaded answer file."},
|
||||
{"method": "GET", "path": "/unattended/:id",
|
||||
{"method": "GET", "path": "/unattended/{id}",
|
||||
"summary": "Public: serve an answer file with {{HOSTNAME}}/{{IP}}/{{MAC}} substituted from the query string."},
|
||||
],
|
||||
},
|
||||
@@ -1635,9 +1694,9 @@ async fn api_docs() -> Json<serde_json::Value> {
|
||||
"summary": "List queue entries (waiting + assigned, with any deployment profile)."},
|
||||
{"method": "POST", "path": "/api/queue/assign",
|
||||
"summary": "Assign a target image to queued clients. Body: { target, entry_ids }."},
|
||||
{"method": "PUT", "path": "/api/queue/:entry_id/profile",
|
||||
{"method": "PUT", "path": "/api/queue/{entry_id}/profile",
|
||||
"summary": "Set a queued device's deployment profile. Body: { auto_hostname?, auto_ip?, unattended_file? }."},
|
||||
{"method": "DELETE", "path": "/api/queue/:entry_id",
|
||||
{"method": "DELETE", "path": "/api/queue/{entry_id}",
|
||||
"summary": "Release a queue entry without assigning."},
|
||||
],
|
||||
},
|
||||
@@ -1648,9 +1707,9 @@ async fn api_docs() -> Json<serde_json::Value> {
|
||||
"summary": "List per-MAC boot bindings."},
|
||||
{"method": "POST", "path": "/api/hosts",
|
||||
"summary": "Pin a MAC to a boot target. Body: { mac, target, label, auto_hostname?, auto_ip?, unattended_file? }."},
|
||||
{"method": "DELETE", "path": "/api/hosts/:mac",
|
||||
{"method": "DELETE", "path": "/api/hosts/{mac}",
|
||||
"summary": "Remove a binding."},
|
||||
{"method": "POST", "path": "/api/hosts/:mac/wol",
|
||||
{"method": "POST", "path": "/api/hosts/{mac}/wol",
|
||||
"summary": "Send a Wake-on-LAN magic packet to a bound MAC (limited + subnet broadcast)."},
|
||||
{"method": "GET", "path": "/api/boot-log",
|
||||
"summary": "Ring of recent boot events (timestamp, mac, ip, target)."},
|
||||
|
||||
@@ -154,10 +154,15 @@ pub fn session_cookie(session: &str) -> String {
|
||||
|
||||
fn parse_cookie(headers: &axum::http::HeaderMap) -> Option<String> {
|
||||
// `Cookie: a=b; c=d` parsing — small enough not to drag in a crate.
|
||||
// Two-step strip (name, then '=') keeps this allocation-free per
|
||||
// candidate and can't match a longer cookie name sharing the prefix.
|
||||
let raw = headers.get(header::COOKIE)?.to_str().ok()?;
|
||||
for part in raw.split(';') {
|
||||
let part = part.trim();
|
||||
if let Some(v) = part.strip_prefix(&format!("{SESSION_COOKIE}=")) {
|
||||
if let Some(v) = part
|
||||
.strip_prefix(SESSION_COOKIE)
|
||||
.and_then(|rest| rest.strip_prefix('='))
|
||||
{
|
||||
return Some(v.to_string());
|
||||
}
|
||||
}
|
||||
@@ -246,7 +251,14 @@ pub async fn api_setup(State(state): State<AppState>, Json(body): Json<SetupBody
|
||||
)
|
||||
.into_response();
|
||||
}
|
||||
match state.admin.bootstrap(&body.username, &body.password) {
|
||||
// bcrypt hashing is ~100-200 ms of pure CPU (and `bootstrap` also
|
||||
// persists to disk synchronously) — keep it off the async workers.
|
||||
let admin = state.admin.clone();
|
||||
let result =
|
||||
tokio::task::spawn_blocking(move || admin.bootstrap(&body.username, &body.password))
|
||||
.await
|
||||
.unwrap_or_else(|e| Err(openpxe_core::Error::Other(e.into())));
|
||||
match result {
|
||||
Ok(pub_) => {
|
||||
let session = state.sessions.create(&pub_.username);
|
||||
login_response(StatusCode::CREATED, &pub_, &session)
|
||||
@@ -271,8 +283,13 @@ pub struct LoginBody {
|
||||
pub async fn api_login(State(state): State<AppState>, Json(body): Json<LoginBody>) -> Response {
|
||||
// Brief, deliberately vague — "invalid credentials" rather than
|
||||
// "no such user" / "wrong password". Same anti-enumeration posture
|
||||
// as Sonarr/Radarr.
|
||||
let pub_ = match state.admin.verify(&body.username, &body.password) {
|
||||
// as Sonarr/Radarr. The bcrypt verify is ~100-200 ms of pure CPU on
|
||||
// an unauthenticated endpoint, so it runs on the blocking pool.
|
||||
let admin = state.admin.clone();
|
||||
let verdict = tokio::task::spawn_blocking(move || admin.verify(&body.username, &body.password))
|
||||
.await
|
||||
.unwrap_or_else(|e| Err(openpxe_core::Error::Other(e.into())));
|
||||
let pub_ = match verdict {
|
||||
Ok(Some(u)) => u,
|
||||
Ok(None) => {
|
||||
return (
|
||||
@@ -394,11 +411,18 @@ pub async fn api_update_credentials(
|
||||
)
|
||||
.into_response();
|
||||
}
|
||||
let result = state.admin.update_credentials(
|
||||
&body.current_password,
|
||||
body.new_username.as_deref(),
|
||||
body.new_password.as_deref(),
|
||||
);
|
||||
// Two bcrypt operations (verify current + hash new) plus a sync disk
|
||||
// persist — run the lot on the blocking pool.
|
||||
let admin = state.admin.clone();
|
||||
let result = tokio::task::spawn_blocking(move || {
|
||||
admin.update_credentials(
|
||||
&body.current_password,
|
||||
body.new_username.as_deref(),
|
||||
body.new_password.as_deref(),
|
||||
)
|
||||
})
|
||||
.await
|
||||
.unwrap_or_else(|e| Err(openpxe_core::Error::Other(e.into())));
|
||||
match result {
|
||||
Ok(pub_) => {
|
||||
state.sessions.revoke_all();
|
||||
|
||||
@@ -105,7 +105,11 @@ async fn send_email(cfg: &NotifyConfig, subject: &str, body: &str) -> Result<(),
|
||||
.trim()
|
||||
.parse()
|
||||
.map_err(|e| format!("invalid To address '{}': {e}", cfg.smtp_to))?)
|
||||
.subject(if subject.is_empty() { "OpenPXE" } else { subject })
|
||||
.subject(if subject.is_empty() {
|
||||
"OpenPXE"
|
||||
} else {
|
||||
subject
|
||||
})
|
||||
.body(body.to_string())
|
||||
.map_err(|e| format!("could not build email: {e}"))?;
|
||||
|
||||
|
||||
@@ -11,6 +11,10 @@ use openpxe_iso_store::{
|
||||
use std::sync::Arc;
|
||||
use time::OffsetDateTime;
|
||||
|
||||
/// Cached composited PXE boot-menu background: `(logo_rev, encoded PNG)`.
|
||||
/// See `AppState::pxe_bg_cache`.
|
||||
pub type PxeBgCache = Arc<parking_lot::Mutex<Option<(u64, bytes::Bytes)>>>;
|
||||
|
||||
#[derive(Clone)]
|
||||
pub struct AppState {
|
||||
pub iso_store: IsoStore,
|
||||
@@ -29,6 +33,12 @@ pub struct AppState {
|
||||
/// operator hasn't uploaded anything, the WebUI serves the bundled
|
||||
/// rainbow-horizon mark.
|
||||
pub branding: BrandingStore,
|
||||
/// v0.6.2: cache of the composited PXE boot-menu background PNG,
|
||||
/// keyed on the branding logo revision. Composing costs ~50-200 ms
|
||||
/// of image decode/encode and **every** booting client fetches it
|
||||
/// for `console --picture` — caching makes that one compose per
|
||||
/// logo change instead of one per boot.
|
||||
pub pxe_bg_cache: PxeBgCache,
|
||||
/// Forms-auth admin record + first-run bootstrap state. When
|
||||
/// `admin.is_configured() == false`, the auth middleware passes
|
||||
/// every request through and `/api/me` reports `setup_required`.
|
||||
|
||||
@@ -116,6 +116,7 @@ async fn build_state() -> (AppState, tempfile::TempDir) {
|
||||
hosts,
|
||||
boot_log,
|
||||
branding,
|
||||
pxe_bg_cache: openpxe_http_api::state::PxeBgCache::default(),
|
||||
admin,
|
||||
sessions,
|
||||
sso,
|
||||
@@ -1488,9 +1489,10 @@ async fn api_docs_lists_known_endpoints() {
|
||||
}
|
||||
for needle in [
|
||||
"/api/isos",
|
||||
"/api/isos/:id/category",
|
||||
// v0.6.3: docs use axum 0.8's `{param}` capture syntax.
|
||||
"/api/isos/{id}/category",
|
||||
"/api/storage/disk",
|
||||
"/api/branding/logo/:slot",
|
||||
"/api/branding/logo/{slot}",
|
||||
"/api/unattended",
|
||||
"/api/boot-log",
|
||||
"/metrics",
|
||||
|
||||
@@ -6,43 +6,40 @@
|
||||
//! missing, that architecture simply won't have PXE support — we log at
|
||||
//! startup and serve what we have.
|
||||
//!
|
||||
//! Filename convention (matches `ClientArch::ipxe_bootfile`):
|
||||
//! Filename convention (matches `ClientArch::ipxe_bootfile_mode`):
|
||||
//!
|
||||
//! DriverMode::Firmware (default — reuse the firmware UNDI/SNP NIC stack):
|
||||
//! - `undionly.kpxe` — Legacy x86 BIOS
|
||||
//! - `snponly-i386.efi` — IA32 UEFI
|
||||
//! - `snponly.efi` — x86_64 UEFI
|
||||
//! - `snponly-arm32.efi` — ARM32 UEFI
|
||||
//! - `snponly-arm64.efi` — ARM64 UEFI
|
||||
//! - `ipxe.efi` (fallback) — UEFI with bundled drivers, if snponly fails on a NIC
|
||||
//!
|
||||
//! DriverMode::Builtin (v0.6.1 automatic fallback — iPXE's own NIC drivers,
|
||||
//! advertised when a firmware-net boot fails to chainload):
|
||||
//! - `ipxe.pxe` — Legacy x86 BIOS
|
||||
//! - `ipxe-i386.efi` — IA32 UEFI
|
||||
//! - `ipxe.efi` — x86_64 UEFI (built from source with PNG)
|
||||
//! - `ipxe-arm64.efi` — ARM64 UEFI
|
||||
//!
|
||||
//! - `wimboot` — Windows boot shim (fetched separately for WIM chains)
|
||||
#![forbid(unsafe_code)]
|
||||
|
||||
use openpxe_core::ClientArch;
|
||||
use openpxe_core::{ClientArch, DriverMode};
|
||||
use rust_embed::Embed;
|
||||
|
||||
#[derive(Embed)]
|
||||
#[folder = "../../assets/ipxe/"]
|
||||
#[include = "*.kpxe"]
|
||||
#[include = "*.efi"]
|
||||
#[include = "*.pxe"]
|
||||
#[include = "wimboot"]
|
||||
pub struct IpxeAssets;
|
||||
|
||||
/// Return the embedded iPXE binary for `arch`, or `None` if we didn't bundle
|
||||
/// one for that architecture.
|
||||
#[must_use]
|
||||
pub fn bootfile_bytes(arch: ClientArch) -> Option<Vec<u8>> {
|
||||
let name = arch.ipxe_bootfile()?;
|
||||
IpxeAssets::get(name).map(|f| f.data.into_owned())
|
||||
}
|
||||
|
||||
/// Return a named asset directly (e.g. `wimboot`, or a fallback `ipxe.efi`).
|
||||
#[must_use]
|
||||
pub fn asset_bytes(name: &str) -> Option<Vec<u8>> {
|
||||
IpxeAssets::get(name).map(|f| f.data.into_owned())
|
||||
}
|
||||
|
||||
/// Same as [`asset_bytes`] but returns the embedded slice directly,
|
||||
/// avoiding the heap copy when the caller only needs to read the
|
||||
/// payload. Falls back to None for unknown names.
|
||||
/// Return a named embedded asset (e.g. `snponly.efi`, `wimboot`) as a
|
||||
/// `Cow` over the embedded bytes. In release builds the data is borrowed
|
||||
/// straight from the binary's rodata — **zero copy** — which matters
|
||||
/// because the TFTP and HTTP serving paths hit this for every boot
|
||||
/// (`ipxe.efi` is ~1 MiB). Debug builds read from disk and return Owned.
|
||||
#[must_use]
|
||||
pub fn asset_slice(name: &str) -> Option<std::borrow::Cow<'static, [u8]>> {
|
||||
IpxeAssets::get(name).map(|f| f.data)
|
||||
@@ -56,25 +53,42 @@ pub fn list_assets() -> Vec<String> {
|
||||
.collect()
|
||||
}
|
||||
|
||||
/// Log at startup which iPXE binaries are present and which are missing.
|
||||
/// Log at startup which iPXE binaries are present and which are missing, for
|
||||
/// both driver modes. The Firmware-mode binaries are required for PXE on each
|
||||
/// arch; the Builtin-mode binaries are the optional automatic NIC-driver
|
||||
/// fallback (v0.6.1) — without one, escalation simply can't help that arch.
|
||||
pub fn log_availability() {
|
||||
let have: std::collections::HashSet<String> = list_assets().into_iter().collect();
|
||||
let needed = [
|
||||
(ClientArch::LegacyX86, "undionly.kpxe"),
|
||||
(ClientArch::Ia32Uefi, "snponly-i386.efi"),
|
||||
(ClientArch::X64Uefi, "snponly.efi"),
|
||||
// ARM32 UEFI deferred — no upstream snponly binary published.
|
||||
(ClientArch::Arm64Uefi, "snponly-arm64.efi"),
|
||||
let arches = [
|
||||
ClientArch::LegacyX86,
|
||||
ClientArch::Ia32Uefi,
|
||||
ClientArch::X64Uefi,
|
||||
// ARM32 UEFI deferred — no upstream binary published in either mode.
|
||||
ClientArch::Arm64Uefi,
|
||||
];
|
||||
for (arch, name) in needed {
|
||||
if have.contains(name) {
|
||||
tracing::info!(target: "openpxe::ipxe", "bundled iPXE for {}: {}", arch.as_str(), name);
|
||||
} else {
|
||||
tracing::warn!(
|
||||
target: "openpxe::ipxe",
|
||||
"MISSING iPXE binary for {}: {} — clients of this arch will not PXE boot",
|
||||
arch.as_str(), name
|
||||
);
|
||||
for arch in arches {
|
||||
for mode in [DriverMode::Firmware, DriverMode::Builtin] {
|
||||
let Some(name) = arch.ipxe_bootfile_mode(mode) else {
|
||||
continue;
|
||||
};
|
||||
if have.contains(name) {
|
||||
tracing::info!(
|
||||
target: "openpxe::ipxe",
|
||||
"bundled iPXE for {} [{mode:?}]: {name}", arch.as_str()
|
||||
);
|
||||
} else if mode == DriverMode::Firmware {
|
||||
tracing::warn!(
|
||||
target: "openpxe::ipxe",
|
||||
"MISSING iPXE binary for {} [{mode:?}]: {name} — clients of this arch will not PXE boot",
|
||||
arch.as_str()
|
||||
);
|
||||
} else {
|
||||
tracing::info!(
|
||||
target: "openpxe::ipxe",
|
||||
"no built-in-driver fallback for {} [{mode:?}]: {name} — auto NIC driver escalation unavailable for this arch",
|
||||
arch.as_str()
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -25,9 +25,11 @@ pub enum BootKind {
|
||||
wimboot_url: String,
|
||||
files: Vec<(String, String)>,
|
||||
},
|
||||
/// Last-resort: SAN-boot the ISO as an emulated CD. Only works for small
|
||||
/// ISOs (<~1 GiB) and older distros. Kept for completeness, not the
|
||||
/// default.
|
||||
/// SAN-boot the raw ISO as an emulated CD (iPXE `sanboot`). The emulated
|
||||
/// CD is backed by on-demand HTTP range reads, so ISO size is *not* a
|
||||
/// constraint — this is the primary path for Windows (v0.5.8) and for any
|
||||
/// El Torito-bootable image we don't special-case: ESXi/VMvisor
|
||||
/// installers, BSDs, firmware/diagnostic tools, custom spins (v0.6.0).
|
||||
SanBootIso { iso_url: String },
|
||||
}
|
||||
|
||||
|
||||
@@ -103,7 +103,13 @@ pub fn introspect(path: &Path) -> IntrospectionReport {
|
||||
let scan_bytes = 64 * 1024 * 1024;
|
||||
let mut buf = vec![0u8; 1024 * 1024];
|
||||
let mut read_total = 0usize;
|
||||
let mut haystack = Vec::with_capacity(scan_bytes.min(32 * 1024 * 1024));
|
||||
// Size the haystack to what will actually be read — the scan cap or
|
||||
// the file itself, whichever is smaller — so the fill never reallocs
|
||||
// and a small ISO doesn't reserve the full 64 MiB.
|
||||
let file_len = f.metadata().map_or(usize::MAX, |m| {
|
||||
usize::try_from(m.len()).unwrap_or(usize::MAX)
|
||||
});
|
||||
let mut haystack = Vec::with_capacity(scan_bytes.min(file_len));
|
||||
while read_total < scan_bytes {
|
||||
let n = f.read(&mut buf).unwrap_or(0);
|
||||
if n == 0 {
|
||||
|
||||
@@ -63,8 +63,8 @@ use bytes::Bytes;
|
||||
use nfs3_client::tokio::TokioConnector;
|
||||
use nfs3_client::Nfs3ConnectionBuilder;
|
||||
use nfs3_types::nfs3::{
|
||||
self as nfs3, diropargs3, entry3, filename3, nfs_fh3, GETATTR3args, LOOKUP3args,
|
||||
Nfs3Result, READ3args, READDIR3args,
|
||||
self as nfs3, diropargs3, entry3, filename3, nfs_fh3, GETATTR3args, LOOKUP3args, Nfs3Result,
|
||||
READ3args, READDIR3args,
|
||||
};
|
||||
use nfs3_types::rpc::{auth_unix, opaque_auth};
|
||||
use nfs3_types::xdr_codec::Opaque;
|
||||
@@ -220,10 +220,7 @@ impl NfsShareManager {
|
||||
/// Register an NFS share. Validates, probes connectivity by
|
||||
/// performing a real MOUNT3 + READDIR3, and registers the
|
||||
/// resulting ISOs with the store.
|
||||
pub async fn add(
|
||||
&self,
|
||||
req: NfsAddRequest,
|
||||
) -> std::result::Result<NfsShare, NfsShareError> {
|
||||
pub async fn add(&self, req: NfsAddRequest) -> std::result::Result<NfsShare, NfsShareError> {
|
||||
let server = normalize_server(&req.server);
|
||||
let export = req.export.trim().to_string();
|
||||
if server.is_empty() {
|
||||
@@ -258,7 +255,9 @@ impl NfsShareManager {
|
||||
if let Err(e) = self.rescan_inner(&id).await {
|
||||
let m = self.get(&id);
|
||||
return Err(NfsShareError {
|
||||
error: m.as_ref().and_then(|m| m.last_error.clone())
|
||||
error: m
|
||||
.as_ref()
|
||||
.and_then(|m| m.last_error.clone())
|
||||
.unwrap_or_else(|| e.to_string()),
|
||||
stderr: String::new(),
|
||||
hint: m.and_then(|m| m.last_hint),
|
||||
@@ -333,8 +332,7 @@ impl NfsShareManager {
|
||||
return Err(Error::Invalid(format!("invalid filename '{filename}'")));
|
||||
}
|
||||
|
||||
let (tx, rx) =
|
||||
tokio::sync::mpsc::channel::<std::io::Result<Bytes>>(STREAM_BUFFER_DEPTH);
|
||||
let (tx, rx) = tokio::sync::mpsc::channel::<std::io::Result<Bytes>>(STREAM_BUFFER_DEPTH);
|
||||
let server = share.server.clone();
|
||||
let export = share.export.clone();
|
||||
let port = share.port;
|
||||
@@ -358,16 +356,11 @@ impl NfsShareManager {
|
||||
if let Err(e) = result {
|
||||
// Best-effort signal of the error to the consumer.
|
||||
// If the receiver has already dropped we just exit.
|
||||
let _ = tx
|
||||
.send(Err(std::io::Error::other(e.to_string())))
|
||||
.await;
|
||||
let _ = tx.send(Err(std::io::Error::other(e.to_string()))).await;
|
||||
}
|
||||
});
|
||||
|
||||
Ok(NfsStream {
|
||||
rx,
|
||||
_task: task,
|
||||
})
|
||||
Ok(NfsStream { rx, _task: task })
|
||||
}
|
||||
|
||||
// ── internals ─────────────────────────────────────────────────────
|
||||
@@ -982,8 +975,14 @@ mod tests {
|
||||
// the allow-list and the secure/insecure angle.
|
||||
let h = hint_for("connect failed: MNT3ERR_ACCES").unwrap();
|
||||
let lc = h.to_lowercase();
|
||||
assert!(lc.contains("insecure") || lc.contains("privileged"), "got: {h}");
|
||||
assert!(lc.contains("allow") || lc.contains("permission"), "got: {h}");
|
||||
assert!(
|
||||
lc.contains("insecure") || lc.contains("privileged"),
|
||||
"got: {h}"
|
||||
);
|
||||
assert!(
|
||||
lc.contains("allow") || lc.contains("permission"),
|
||||
"got: {h}"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
|
||||
@@ -231,10 +231,7 @@ impl SmbShareManager {
|
||||
|
||||
/// Add or refresh a share. Validates the input, writes a creds
|
||||
/// file, probes connectivity, and scans for ISOs.
|
||||
pub async fn add(
|
||||
&self,
|
||||
req: SmbAddRequest,
|
||||
) -> std::result::Result<SmbShare, SmbShareError> {
|
||||
pub async fn add(&self, req: SmbAddRequest) -> std::result::Result<SmbShare, SmbShareError> {
|
||||
let server = normalize_server(&req.server);
|
||||
let share = req.share.trim().trim_start_matches('/').to_string();
|
||||
if server.is_empty() {
|
||||
@@ -309,7 +306,9 @@ impl SmbShareManager {
|
||||
if let Err(e) = self.rescan_inner(&id).await {
|
||||
let m = self.get(&id);
|
||||
return Err(SmbShareError {
|
||||
error: m.as_ref().and_then(|m| m.last_error.clone())
|
||||
error: m
|
||||
.as_ref()
|
||||
.and_then(|m| m.last_error.clone())
|
||||
.unwrap_or_else(|| e.to_string()),
|
||||
stderr: String::new(),
|
||||
hint: m.and_then(|m| m.last_hint),
|
||||
@@ -365,11 +364,7 @@ impl SmbShareManager {
|
||||
/// throttling concurrent smbclients) would need to await without
|
||||
/// changing the call sites.
|
||||
#[allow(clippy::unused_async)]
|
||||
pub async fn stream_iso(
|
||||
&self,
|
||||
share_id: &str,
|
||||
filename: &str,
|
||||
) -> Result<SmbStream> {
|
||||
pub async fn stream_iso(&self, share_id: &str, filename: &str) -> Result<SmbStream> {
|
||||
let share = self
|
||||
.get(share_id)
|
||||
.ok_or_else(|| Error::Invalid(format!("no such SMB share '{share_id}'")))?;
|
||||
@@ -377,9 +372,7 @@ impl SmbShareManager {
|
||||
// share root. smbclient itself accepts only filenames at the
|
||||
// share root in our `get` form, but belt-and-suspenders.
|
||||
if filename.contains('/') || filename.contains('\\') || filename.contains("..") {
|
||||
return Err(Error::Invalid(format!(
|
||||
"invalid filename '{filename}'"
|
||||
)));
|
||||
return Err(Error::Invalid(format!("invalid filename '{filename}'")));
|
||||
}
|
||||
let creds = share
|
||||
.creds_path
|
||||
@@ -537,10 +530,7 @@ impl SmbShareManager {
|
||||
} else {
|
||||
String::new()
|
||||
};
|
||||
return Err((
|
||||
format!("could not exec smbclient: {e}"),
|
||||
stderr,
|
||||
));
|
||||
return Err((format!("could not exec smbclient: {e}"), stderr));
|
||||
}
|
||||
};
|
||||
if !output.status.success() {
|
||||
@@ -751,10 +741,7 @@ fn parse_ls_iso(out: &str) -> Vec<SmbListEntry> {
|
||||
|
||||
/// Pre-flight TCP probe to `server:port`. Format matches v0.4.64 NFS
|
||||
/// probe so the UI banner reads consistently.
|
||||
async fn tcp_probe(
|
||||
server: &str,
|
||||
port: u16,
|
||||
) -> std::result::Result<(), (String, String)> {
|
||||
async fn tcp_probe(server: &str, port: u16) -> std::result::Result<(), (String, String)> {
|
||||
use tokio::net::TcpStream;
|
||||
let addr = format!("{server}:{port}");
|
||||
match tokio::time::timeout(PROBE_TIMEOUT, TcpStream::connect(&addr)).await {
|
||||
@@ -931,8 +918,8 @@ mod tests {
|
||||
// exec error in `error` plus an empty `stderr`. The
|
||||
// SmbShareError constructor's hint_for fallback checks error
|
||||
// too, so this pattern needs to translate as well.
|
||||
let h2 = hint_for("could not exec smbclient: No such file or directory (os error 2)")
|
||||
.unwrap();
|
||||
let h2 =
|
||||
hint_for("could not exec smbclient: No such file or directory (os error 2)").unwrap();
|
||||
assert!(h2.contains("smbclient"));
|
||||
}
|
||||
|
||||
|
||||
@@ -342,9 +342,18 @@ impl IsoStore {
|
||||
/// SMB sources or when the file is missing.
|
||||
pub fn iso_path_for(&self, id: &str) -> Option<PathBuf> {
|
||||
let meta = self.get(id)?;
|
||||
self.local_path(&meta)
|
||||
}
|
||||
|
||||
/// Same resolution as [`Self::iso_path_for`], but for a meta the
|
||||
/// caller already holds — skips the second registry lock + deep
|
||||
/// clone, which matters on the per-range-request ISO serving path
|
||||
/// (a sanboot install issues hundreds of those).
|
||||
#[must_use]
|
||||
pub fn local_path(&self, meta: &IsoMeta) -> Option<PathBuf> {
|
||||
match &meta.source {
|
||||
IsoSource::Local => {
|
||||
let path = self.iso_path(id);
|
||||
let path = self.iso_path(&meta.id);
|
||||
if path.exists() {
|
||||
Some(path)
|
||||
} else {
|
||||
@@ -639,15 +648,33 @@ fn generate_boot_entries(id: &str, filename: &str, r: &IntrospectionReport) -> V
|
||||
}]
|
||||
}
|
||||
_ => {
|
||||
// Last-resort SAN boot. Won't work for large modern ISOs, but
|
||||
// lets the ISO at least appear in the menu.
|
||||
vec![BootEntry {
|
||||
id: format!("{id}-sanboot"),
|
||||
title: format!("{title} (SAN boot — may fail for >1GiB ISOs)"),
|
||||
kind: BootKind::SanBootIso {
|
||||
iso_url: format!("iso/{id}.iso"),
|
||||
},
|
||||
}]
|
||||
// No Windows-install media and no Linux kernel/initrd. Decide
|
||||
// whether the ISO is bootable at all (v0.6.0):
|
||||
// * `el_torito` — it carries a boot catalog, so iPXE sanboots
|
||||
// the raw image as an emulated CD: BSDs, ESXi/VMvisor
|
||||
// installers, firmware tools, custom spins. The emulated CD
|
||||
// is backed by HTTP range reads, so ISO size is a non-issue
|
||||
// (this is the same path Windows uses since v0.5.8) — hence
|
||||
// no more "may fail for >1GiB ISOs" disclaimer.
|
||||
// * `introspect_rev == 0` — a remote-share ISO we couldn't
|
||||
// introspect (SMB/NFS/SFTP listings don't seek into the ISO).
|
||||
// Offer sanboot optimistically rather than hide a
|
||||
// likely-bootable installer.
|
||||
// Otherwise it's a local image we *did* introspect and found to
|
||||
// carry no boot catalog — a data/appliance ISO (e.g. a VMware
|
||||
// vCenter Server Appliance bundle). It genuinely cannot boot, so
|
||||
// we expose no menu entry; the dashboard flags it instead.
|
||||
if r.el_torito || r.introspect_rev == 0 {
|
||||
vec![BootEntry {
|
||||
id: format!("{id}-sanboot"),
|
||||
title,
|
||||
kind: BootKind::SanBootIso {
|
||||
iso_url: format!("iso/{id}.iso"),
|
||||
},
|
||||
}]
|
||||
} else {
|
||||
Vec::new()
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -721,6 +748,49 @@ mod tests {
|
||||
assert!(!s.contains(" --- "), "stray ---: {s}");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn boot_entries_respect_el_torito_and_source() {
|
||||
use crate::introspect::INTROSPECT_REV;
|
||||
|
||||
// ESXi / VMvisor installer shape: bootable (carries an El Torito
|
||||
// catalog) but not classifiable as Windows or Linux. Must yield a
|
||||
// single sanboot entry so it's selectable + boots via emulated CD.
|
||||
let esxi = IntrospectionReport {
|
||||
family: DistroFamily::Unknown,
|
||||
volume_label: Some("ESXI-7.0U3".into()),
|
||||
el_torito: true,
|
||||
introspect_rev: INTROSPECT_REV,
|
||||
..Default::default()
|
||||
};
|
||||
let e = generate_boot_entries("esxi", "VMware-VMvisor-Installer-7.0U3n.iso", &esxi);
|
||||
assert_eq!(e.len(), 1, "ESXi should get exactly one boot entry");
|
||||
assert!(matches!(e[0].kind, BootKind::SanBootIso { .. }));
|
||||
// Clean title — no stale ">1GiB may fail" disclaimer.
|
||||
assert!(!e[0].title.contains("may fail"), "title: {}", e[0].title);
|
||||
|
||||
// VCSA / data-appliance shape: locally introspected (rev set), no
|
||||
// boot catalog, not Windows/Linux. Genuinely unbootable → no entry,
|
||||
// so it stays out of the iPXE menu (the dashboard flags it instead).
|
||||
let vcsa = IntrospectionReport {
|
||||
family: DistroFamily::Unknown,
|
||||
el_torito: false,
|
||||
introspect_rev: INTROSPECT_REV,
|
||||
..Default::default()
|
||||
};
|
||||
assert!(
|
||||
generate_boot_entries("vcsa", "VMware-VCSA-all-8.0.iso", &vcsa).is_empty(),
|
||||
"data/appliance ISO must produce no boot entry"
|
||||
);
|
||||
|
||||
// Remote-share ISO: never introspected (rev 0, no random access over
|
||||
// SMB/NFS/SFTP). Assume bootable and offer sanboot rather than hide a
|
||||
// likely-bootable installer.
|
||||
let remote = IntrospectionReport::default();
|
||||
let r = generate_boot_entries("remote", "unknown-remote.iso", &remote);
|
||||
assert_eq!(r.len(), 1, "remote (uninspected) ISO keeps a sanboot entry");
|
||||
assert!(matches!(r[0].kind, BootKind::SanBootIso { .. }));
|
||||
}
|
||||
|
||||
fn fake_meta(id: &str) -> IsoMeta {
|
||||
IsoMeta {
|
||||
id: id.into(),
|
||||
|
||||
@@ -192,6 +192,7 @@ async fn main() -> anyhow::Result<()> {
|
||||
hosts: hosts.clone(),
|
||||
boot_log: boot_log.clone(),
|
||||
branding: branding.clone(),
|
||||
pxe_bg_cache: openpxe_http_api::state::PxeBgCache::default(),
|
||||
admin: admin.clone(),
|
||||
sessions: sessions.clone(),
|
||||
sso: sso.clone(),
|
||||
|
||||
+30
-16
@@ -7,12 +7,12 @@
|
||||
//! `tftpd`/`in.tftpd` works and is why TFTP is awkward behind stateful NAT:
|
||||
//! the ephemeral ports must be reachable from the client.
|
||||
//!
|
||||
//! We only serve files from `openpxe_ipxe_assets::asset_bytes` — that is,
|
||||
//! We only serve files from `openpxe_ipxe_assets::asset_slice` — that is,
|
||||
//! the bundled iPXE binaries and wimboot. No filesystem is ever opened, so
|
||||
//! `../` path traversal attempts simply return ENOENT.
|
||||
|
||||
use openpxe_core::{ClientEvent, ClientRegistry};
|
||||
use openpxe_ipxe_assets::asset_bytes;
|
||||
use openpxe_ipxe_assets::asset_slice;
|
||||
use socket2::{Domain, Protocol, Socket, Type};
|
||||
use std::net::{IpAddr, SocketAddr};
|
||||
use std::sync::Arc;
|
||||
@@ -21,6 +21,7 @@ use tokio::net::UdpSocket;
|
||||
|
||||
// TFTP opcodes.
|
||||
const OP_RRQ: u16 = 1;
|
||||
const OP_WRQ: u16 = 2;
|
||||
const OP_DATA: u16 = 3;
|
||||
const OP_ACK: u16 = 4;
|
||||
const OP_ERROR: u16 = 5;
|
||||
@@ -89,16 +90,34 @@ async fn handle_rrq(
|
||||
metrics: openpxe_core::Metrics,
|
||||
) -> anyhow::Result<()> {
|
||||
let Some(req) = parse_rrq(&packet) else {
|
||||
// Not a well-formed RRQ. A WRQ deserves an explicit refusal —
|
||||
// legacy clients retry a silently-dropped write until they time
|
||||
// out; an ERROR packet fails them fast with a readable reason.
|
||||
if packet.len() >= 2 && u16::from_be_bytes([packet[0], packet[1]]) == OP_WRQ {
|
||||
let sock = bind_udp(bind_ip, 0)?;
|
||||
let _ = send_error(&sock, peer, ERR_ILLEGAL_OP, "writes not supported").await;
|
||||
}
|
||||
return Ok(());
|
||||
};
|
||||
let Request {
|
||||
filename, options, ..
|
||||
filename,
|
||||
mode,
|
||||
options,
|
||||
} = req;
|
||||
|
||||
// Per-transfer ephemeral socket.
|
||||
let sock = bind_udp(bind_ip, 0)?;
|
||||
|
||||
let Some(file_bytes) = asset_bytes(&filename) else {
|
||||
// We serve binary boot artifacts; netascii line-ending translation
|
||||
// would corrupt them. Refuse loudly instead of timing out silently —
|
||||
// matters for legacy clients that default to netascii.
|
||||
if !mode.eq_ignore_ascii_case("octet") {
|
||||
let _ = send_error(&sock, peer, ERR_NOT_DEFINED, "only octet mode is supported").await;
|
||||
tracing::info!(target: "openpxe::tftp", peer=%peer, %mode, "rejected non-octet transfer");
|
||||
return Ok(());
|
||||
}
|
||||
|
||||
let Some(file_bytes) = asset_slice(&filename) else {
|
||||
let _ = send_error(&sock, peer, ERR_FILE_NOT_FOUND, "no such file").await;
|
||||
tracing::info!(target: "openpxe::tftp", peer=%peer, file=%filename, "404");
|
||||
clients.record(
|
||||
@@ -262,7 +281,6 @@ async fn handle_rrq(
|
||||
#[derive(Debug)]
|
||||
struct Request {
|
||||
filename: String,
|
||||
#[allow(dead_code)]
|
||||
mode: String,
|
||||
options: Vec<(String, String)>,
|
||||
}
|
||||
@@ -393,17 +411,13 @@ fn bind_udp(bind: IpAddr, port: u16) -> anyhow::Result<UdpSocket> {
|
||||
Ok(UdpSocket::from_std(std_sock)?)
|
||||
}
|
||||
|
||||
#[allow(dead_code)]
|
||||
const _UNUSED: (u16, u16) = (ERR_NOT_DEFINED, ERR_ILLEGAL_OP);
|
||||
|
||||
/// Pure-logic helper used by the unit tests below and (in a refactor) by
|
||||
/// `handle_rrq`. Given a position in the file and the window, return the
|
||||
/// (block_no, chunk_len) list this window will emit. Useful as a sanity
|
||||
/// check that our windowing math matches the wire behavior the spec
|
||||
/// requires — tested against edge cases (exact-blksize tail, short tail,
|
||||
/// single-block window).
|
||||
#[must_use]
|
||||
pub fn plan_window(
|
||||
/// Pure-logic mirror of `handle_rrq`'s windowing math, exercised by the
|
||||
/// unit tests below. Given a position in the file and the window, return
|
||||
/// the (block_no, chunk_len) list this window will emit — tested against
|
||||
/// edge cases (exact-blksize tail, short tail, single-block window,
|
||||
/// block-number wraparound).
|
||||
#[cfg(test)]
|
||||
fn plan_window(
|
||||
total: usize,
|
||||
offset: usize,
|
||||
blksize: usize,
|
||||
|
||||
@@ -365,7 +365,7 @@
|
||||
const settings = status.settings;
|
||||
const problems = isos.map(i => ({i, b: bootability(i, settings)})).filter(x => !x.b.ok);
|
||||
const problemsBlock = problems.length ? el('div', {class:'card'}, [
|
||||
el('header', {}, [el('h2', {}, 'Images that won\'t boot with current settings')]),
|
||||
el('header', {}, [el('h2', {}, 'Non-bootable images')]),
|
||||
el('div', {class:'body'},
|
||||
problems.map(({i, b}) => el('div', {class:'row-warn'},
|
||||
'⚠ ' + i.filename + ' — ' + b.reason)))
|
||||
|
||||
+23
-7
@@ -41,15 +41,31 @@ DEST="${1:-$ROOT/assets/ipxe}"
|
||||
WORK="$(mktemp -d)"
|
||||
trap 'rm -rf "$WORK"' EXIT
|
||||
|
||||
# Pinned upstream iPXE. Rolling master is fine functionally, but a pin
|
||||
# keeps builds reproducible and protects against a transient master
|
||||
# breakage. Bump deliberately.
|
||||
# Pinned upstream iPXE. Rolling master is fine functionally, but a pin keeps
|
||||
# builds reproducible, protects against a transient master breakage, and —
|
||||
# crucially for the Docker image — busting this value invalidates the cached
|
||||
# ipxe-build layer so an "update iPXE" release actually recompiles from the
|
||||
# new upstream. Bump deliberately to a recent master commit.
|
||||
#
|
||||
# v0.6.1: ipxe/ipxe master @ 2026-06-09 (newer NIC drivers + EFI fixes;
|
||||
# mirrors iVentoy 1.0.35 "Update iPXE").
|
||||
IPXE_REPO="https://github.com/ipxe/ipxe.git"
|
||||
IPXE_REF="${IPXE_REF:-master}"
|
||||
IPXE_REF="${IPXE_REF:-95ffbf4745553e8a207922389929e1943c0237c0}"
|
||||
|
||||
echo ">> cloning iPXE ($IPXE_REF)"
|
||||
git clone --depth 1 --branch "$IPXE_REF" "$IPXE_REPO" "$WORK/ipxe" 2>/dev/null \
|
||||
|| git clone "$IPXE_REPO" "$WORK/ipxe"
|
||||
echo ">> fetching iPXE ($IPXE_REF)"
|
||||
# Shallow-fetch the exact ref: works for a full commit SHA (GitHub allows
|
||||
# reachable-SHA1-in-want) and for branch/tag names. Fall back to a full
|
||||
# clone + checkout if the server refuses a direct fetch of this ref.
|
||||
git init -q "$WORK/ipxe"
|
||||
git -C "$WORK/ipxe" remote add origin "$IPXE_REPO"
|
||||
if git -C "$WORK/ipxe" fetch -q --depth 1 origin "$IPXE_REF"; then
|
||||
git -C "$WORK/ipxe" checkout -q FETCH_HEAD
|
||||
else
|
||||
echo " direct fetch failed; falling back to full clone + checkout"
|
||||
rm -rf "$WORK/ipxe"
|
||||
git clone -q "$IPXE_REPO" "$WORK/ipxe"
|
||||
git -C "$WORK/ipxe" checkout -q "$IPXE_REF"
|
||||
fi
|
||||
SRC="$WORK/ipxe/src"
|
||||
|
||||
echo ">> applying OpenPXE config overrides (PNG + framebuffer + console cmd)"
|
||||
|
||||
@@ -29,11 +29,19 @@ mkdir -p "$DEST"
|
||||
# Upstream uses arch-scoped subdirectories; we flatten to the names our
|
||||
# ClientArch::ipxe_bootfile() expects.
|
||||
declare -a MAP=(
|
||||
# DriverMode::Firmware (default) — reuse the firmware UNDI/SNP NIC stack.
|
||||
"undionly.kpxe=undionly.kpxe"
|
||||
"snponly.efi=x86_64-efi/snponly.efi"
|
||||
"snponly-i386.efi=i386-efi/snponly.efi"
|
||||
"snponly-arm64.efi=arm64-efi/snponly.efi"
|
||||
"ipxe.efi=x86_64-efi/ipxe.efi" # fallback with bundled drivers
|
||||
# DriverMode::Builtin (v0.6.1 automatic fallback) — iPXE's own all-drivers
|
||||
# builds, advertised by the DHCP proxy to a MAC whose firmware NIC stack
|
||||
# failed to chainload. (x86_64 ipxe.efi is rebuilt from source with PNG in
|
||||
# build-ipxe.sh and overlaid on top of this fetched baseline.)
|
||||
"ipxe.efi=x86_64-efi/ipxe.efi"
|
||||
"ipxe.pxe=ipxe.pxe"
|
||||
"ipxe-i386.efi=i386-efi/ipxe.efi"
|
||||
"ipxe-arm64.efi=arm64-efi/ipxe.efi"
|
||||
)
|
||||
|
||||
BASE="https://boot.ipxe.org"
|
||||
|
||||
Reference in New Issue
Block a user