dracut

Harald Hoyer

Revision History
Revision 3.0October 2013HH

Table of Contents

I. Introduction
1. Definition
2. Rationale
3. Implementation
4. Mount preparations
5. Dracut on shutdown
II. User Manual
6. DRACUT(8)
NAME
SYNOPSIS
DESCRIPTION
USAGE
Inspecting the Contents
Adding dracut Modules
Omitting dracut Modules
Adding Kernel Modules
Boot parameters
Injecting custom Files
Network Boot
Troubleshooting
Identifying your problem area
Information to include in your report
Debugging dracut
OPTIONS
ENVIRONMENT
FILES
Configuration in the initramfs
AVAILABILITY
AUTHORS
SEE ALSO
7. DRACUT.CONF(5)
NAME
SYNOPSIS
Description
Files
AUTHOR
See Also
8. DRACUT.CMDLINE(7)
NAME
DESCRIPTION
Standard
iso-scan/filename
Misc
Debug
I18N
LVM
crypto LUKS
crypto LUKS - key on removable device support
MD RAID
DM RAID
MULTIPATH
FIPS
Network
NFS
CIFS
iSCSI
FCoE
NBD
DASD
ZFCP
ZNET
Booting live images
ZIPL
CIO_IGNORE
Plymouth Boot Splash
Kernel keys
Deprecated, renamed Options
Configuration in the Initramfs
AUTHOR
SEE ALSO
9. LSINITRD(1)
NAME
SYNOPSIS
DESCRIPTION
OPTIONS
AVAILABILITY
AUTHORS
SEE ALSO
10. MKINITRD(8)
NAME
SYNOPSIS
DESCRIPTION
OPTIONS
AVAILABILITY
AUTHORS
SEE ALSO
11. Developer Manual
12. DRACUT.MODULES(7)
NAME
DESCRIPTION
Boot Process Stages
Hook: cmdline
Hook: pre-udev
Start Udev
Hook: pre-trigger
Trigger Udev
Main Loop
Hook: pre-mount
Hook: mount
Hook: pre-pivot
Hook: cleanup
Cleanup and switch_root
Network Infrastructure
Writing a Module
module-setup.sh: check()
module-setup.sh: depends()
module-setup.sh: cmdline()
module-setup.sh: install()
module-setup.sh: installkernel()
Creation Functions
Initramfs Functions
Network Modules
AUTHOR
SEE ALSO
13. DRACUT.BOOTUP(7)
NAME
DESCRIPTION
AUTHOR
SEE ALSO
A. License

Part I. Introduction

This section is a modified version of http://en.wikipedia.org/wiki/Initrd which is licensed under the Creative Commons Attribution/Share-Alike License.

Chapter 1. Definition

An initial ramdisk is a temporary file system used in the boot process of the Linux kernel. initrd and initramfs refer to slightly different schemes for loading this file system into memory. Both are commonly used to make preparations before the real root file system can be mounted.

Chapter 2. Rationale

Many Linux distributions ship a single, generic kernel image that is intended to boot as wide a variety of hardware as possible. The device drivers for this generic kernel image are included as loadable modules, as it is not possible to statically compile them all into the one kernel without making it too large to boot from computers with limited memory or from lower-capacity media like floppy disks.

This then raises the problem of detecting and loading the modules necessary to mount the root file system at boot time (or, for that matter, deducing where or what the root file system is).

To further complicate matters, the root file system may be on a software RAID volume, LVM, NFS (on diskless workstations), or on an encrypted partition. All of these require special preparations to mount.

Another complication is kernel support for hibernation, which suspends the computer to disk by dumping an image of the entire system to a swap partition or a regular file, then powering off. On next boot, this image has to be made accessible before it can be loaded back into memory.

To avoid having to hardcode handling for so many special cases into the kernel, an initial boot stage with a temporary root file system —now dubbed early user space— is used. This root file system would contain user-space helpers that would do the hardware detection, module loading and device discovery necessary to get the real root file system mounted.

Chapter 3. Implementation

An image of this initial root file system (along with the kernel image) must be stored somewhere accessible by the Linux bootloader or the boot firmware of the computer. This can be:

  • The root file system itself
  • A boot image on an optical disc
  • A small ext2/ext3 or FAT-formatted partition on a local disk (a boot partition)
  • A TFTP server (on systems that can boot from Ethernet)

The bootloader will load the kernel and initial root file system image into memory and then start the kernel, passing in the memory address of the image.

Depending on which algorithms were compiled statically into it, the kernel can currently unpack initrd/initramfs images compressed with gzip, bzip2 and LZMA.

Chapter 4. Mount preparations

dracut can generate a customized initrams image which contains only whatever is necessary to boot some particular computer, such as ATA, SCSI and filesystem kernel modules (host-only mode).

dracut can also generate a more generic initramfs image (default mode).

dracut’s initramfs starts only with the device name of the root file system (or its UUID) and must discover everything else at boot time. A complex cascade of tasks must be performed to get the root file system mounted:

  • Any hardware drivers that the boot process depends on must be loaded. All kernel modules for common storage devices are packed onto the initramfs and then udev pulls in modules matching the computer’s detected hardware.
  • On systems which display a boot rd.splash screen, the video hardware must be initialized and a user-space helper started to paint animations onto the display in lockstep with the boot process.
  • If the root file system is on NFS, dracut does then:

    • Bring up the primary network interface.
    • Invoke a DHCP client, with which it can obtain a DHCP lease.
    • Extract the name of the NFS share and the address of the NFS server from the lease.
    • Mount the NFS share.
  • If the root file system appears to be on a software RAID device, there is no way of knowing which devices the RAID volume spans; the standard MD utilities must be invoked to scan all available block devices with a raid signature and bring the required ones online.
  • If the root file system appears to be on a logical volume, the LVM utilities must be invoked to scan for and activate the volume group containing it.
  • If the root file system is on an encrypted block device:

    • Invoke a helper script to prompt the user to type in a passphrase and/or insert a hardware token (such as a smart card or a USB security dongle).
  • Create a decryption target with the device mapper.

dracut uses udev, an event-driven hotplug agent, which invokes helper programs as hardware devices, disk partitions and storage volumes matching certain rules come online. This allows discovery to run in parallel, and to progressively cascade into arbitrary nestings of LVM, RAID or encryption to get at the root file system.

When the root file system finally becomes visible:

  • Any maintenance tasks which cannot run on a mounted root file system are done.
  • The root file system is mounted read-only.
  • Any processes which must continue running (such as the rd.splash screen helper and its command FIFO) are hoisted into the newly-mounted root file system.

The final root file system cannot simply be mounted over /, since that would make the scripts and tools on the initial root file system inaccessible for any final cleanup tasks. On an initramfs, the initial root file system cannot be rotated away. Instead, it is simply emptied and the final root file system mounted over the top.

If the systemd module is used in the initramfs, the ordering of the services started looks like Chapter 13, DRACUT.BOOTUP(7).

Chapter 5. Dracut on shutdown

On a systemd driven system, the dracut initramfs is also used for the shutdown procedure.

The following steps are executed during a shutdown:

  • systemd switches to the shutdown.target
  • systemd starts $prefix/lib/systemd/system/shutdown.target.wants/dracut-shutdown.service
  • dracut-shutdown.service executes /usr/lib/dracut/dracut-initramfs-restore which unpacks the initramfs to /run/initramfs
  • systemd finishes shutdown.target
  • systemd kills all processes
  • systemd tries to unmount everything and mounts the remaining read-only
  • systemd checks, if there is a /run/initramfs/shutdown executable
  • if yes, it does a pivot_root to /run/initramfs and executes ./shutdown. The old root is then mounted on /oldroot. /usr/lib/dracut/modules.d/99shutdown/shutdown.sh is the shutdown executable.
  • shutdown will try to umount every /oldroot mount and calls the various shutdown hooks from the dracut modules

This ensures, that all devices are disassembled and unmounted cleanly.

Part II. User Manual

Chapter 6. DRACUT(8)

NAME

dracut - low-level tool for generating an initramfs/initrd image

SYNOPSIS

dracut [OPTION…] [<image> [<kernel version>]]

DESCRIPTION

Create an initramfs <image> for the kernel with the version <kernel version>. If <kernel version> is omitted, then the version of the actual running kernel is used. If <image> is omitted or empty, then the default location /boot/initramfs-<kernel version>.img is used.

dracut creates an initial image used by the kernel for preloading the block device modules (such as IDE, SCSI or RAID) which are needed to access the root filesystem, mounting the root filesystem and booting into the real system.

At boot time, the kernel unpacks that archive into RAM disk, mounts and uses it as initial root file system. All finding of the root device happens in this early userspace.

Initramfs images are also called "initrd".

For a complete list of kernel command line options see dracut.cmdline(7).

If you are dropped to an emergency shell, while booting your initramfs, the file /run/initramfs/rdsosreport.txt is created, which can be saved to a (to be mounted by hand) partition (usually /boot) or a USB stick. Additional debugging info can be produced by adding rd.debug to the kernel command line. /run/initramfs/rdsosreport.txt contains all logs and the output of some tools. It should be attached to any report about dracut problems.

USAGE

To create a initramfs image, the most simple command is:

# dracut

This will generate a general purpose initramfs image, with all possible functionality resulting of the combination of the installed dracut modules and system tools. The image is /boot/initramfs-<kernel version>.img and contains the kernel modules of the currently active kernel with version <kernel version>.

If the initramfs image already exists, dracut will display an error message, and to overwrite the existing image, you have to use the --force option.

# dracut --force

If you want to specify another filename for the resulting image you would issue a command like:

# dracut foobar.img

To generate an image for a specific kernel version, the command would be:

# dracut foobar.img 2.6.40-1.rc5.f20

A shortcut to generate the image at the default location for a specific kernel version is:

# dracut --kver 2.6.40-1.rc5.f20

If you want to create lighter, smaller initramfs images, you may want to specify the --hostonly or -H option. Using this option, the resulting image will contain only those dracut modules, kernel modules and filesystems, which are needed to boot this specific machine. This has the drawback, that you can’t put the disk on another controller or machine, and that you can’t switch to another root filesystem, without recreating the initramfs image. The usage of the --hostonly option is only for experts and you will have to keep the broken pieces. At least keep a copy of a general purpose image (and corresponding kernel) as a fallback to rescue your system.

Inspecting the Contents

To see the contents of the image created by dracut, you can use the lsinitrd tool.

# lsinitrd | less

To display the contents of a file in the initramfs also use the lsinitrd tool:

# lsinitrd -f /etc/ld.so.conf
include ld.so.conf.d/*.conf

Adding dracut Modules

Some dracut modules are turned off by default and have to be activated manually. You can do this by adding the dracut modules to the configuration file /etc/dracut.conf or /etc/dracut.conf.d/myconf.conf. See dracut.conf(5). You can also add dracut modules on the command line by using the -a or --add option:

# dracut --add bootchart initramfs-bootchart.img

To see a list of available dracut modules, use the --list-modules option:

# dracut --list-modules

Omitting dracut Modules

Sometimes you don’t want a dracut module to be included for reasons of speed, size or functionality. To do this, either specify the omit_dracutmodules variable in the dracut.conf or /etc/dracut.conf.d/myconf.conf configuration file (see dracut.conf(5)), or use the -o or --omit option on the command line:

# dracut -o "multipath lvm" no-multipath-lvm.img

Adding Kernel Modules

If you need a special kernel module in the initramfs, which is not automatically picked up by dracut, you have the use the --add-drivers option on the command line or the drivers vaiable in the /etc/dracut.conf or /etc/dracut.conf.d/myconf.conf configuration file (see dracut.conf(5)):

# dracut --add-drivers mymod initramfs-with-mymod.img

Boot parameters

An initramfs generated without the "hostonly" mode, does not contain any system configuration files (except for some special exceptions), so the configuration has to be done on the kernel command line. With this flexibility, you can easily boot from a changed root partition, without the need to recompile the initramfs image. So, you could completly change your root partition (move it inside a md raid with encryption and LVM on top), as long as you specify the correct filesystem LABEL or UUID on the kernel command line for your root device, dracut will find it and boot from it.

The kernel command line can also be provided by the dhcp server with the root-path option. See the section called “Network Boot”.

For a full reference of all kernel command line parameters, see dracut.cmdline(5).

To get a quick start for the suitable kernel command line on your system, use the --print-cmdline option:

# dracut --print-cmdline
 root=UUID=8b8b6f91-95c7-4da2-831b-171e12179081 rootflags=rw,relatime,discard,data=ordered rootfstype=ext4

Specifying the root Device

This is the only option dracut really needs to boot from your root partition. Because your root partition can live in various environments, there are a lot of formats for the root= option. The most basic one is root=<path to device node>:

root=/dev/sda2

Because device node names can change, dependent on the drive ordering, you are encouraged to use the filesystem identifier (UUID) or filesystem label (LABEL) to specify your root partition:

root=UUID=19e9dda3-5a38-484d-a9b0-fa6b067d0331

or

root=LABEL=myrootpartitionlabel

To see all UUIDs or LABELs on your system, do:

# ls -l /dev/disk/by-uuid

or

# ls -l /dev/disk/by-label

If your root partition is on the network see the section called “Network Boot”.

Keyboard Settings

If you have to input passwords for encrypted disk volumes, you might want to set the keyboard layout and specify a display font.

A typical german kernel command would contain:

rd.vconsole.font=latarcyrheb-sun16 rd.vconsole.keymap=de-latin1-nodeadkeys rd.locale.LANG=de_DE.UTF-8

Setting these options can override the setting stored on your system, if you use a modern init system, like systemd.

Blacklisting Kernel Modules

Sometimes it is required to prevent the automatic kernel module loading of a specific kernel module. To do this, just add rd.blacklist=<kernel module name>, with <kernel module name> not containing the .ko suffix, to the kernel command line. For example:

rd.driver.blacklist=mptsas rd.driver.blacklist=nouveau

The option can be specified multiple times on the kernel command line.

Speeding up the Boot Process

If you want to speed up the boot process, you can specify as much information for dracut on the kernel command as possible. For example, you can tell dracut, that you root partition is not on a LVM volume or not on a raid partition, or that it lives inside a specific crypto LUKS encrypted volume. By default, dracut searches everywhere. A typical dracut kernel command line for a plain primary or logical partition would contain:

rd.luks=0 rd.lvm=0 rd.md=0 rd.dm=0

This turns off every automatic assembly of LVM, MD raids, DM raids and crypto LUKS.

Of course, you could also omit the dracut modules in the initramfs creation process, but then you would lose the posibility to turn it on on demand.

Injecting custom Files

To add your own files to the initramfs image, you have several possibilities.

The --include option let you specify a source path and a target path. For example

# dracut --include cmdline-preset /etc/cmdline.d/mycmdline.conf initramfs-cmdline-pre.img

will create an initramfs image, where the file cmdline-preset will be copied inside the initramfs to /etc/cmdline.d/mycmdline.conf. --include can only be specified once.

# mkdir -p rd.live.overlay/etc/cmdline.d
# mkdir -p rd.live.overlay/etc/conf.d
# echo "ip=dhcp" >> rd.live.overlay/etc/cmdline.d/mycmdline.conf
# echo export FOO=testtest >> rd.live.overlay/etc/conf.d/testvar.conf
# echo export BAR=testtest >> rd.live.overlay/etc/conf.d/testvar.conf
# tree rd.live.overlay/
rd.live.overlay/
`-- etc
    |-- cmdline.d
    |   `-- mycmdline.conf
    `-- conf.d
        `-- testvar.conf

# dracut --include rd.live.overlay / initramfs-rd.live.overlay.img

This will put the contents of the rd.live.overlay directory into the root of the initramfs image.

The --install option let you specify several files, which will get installed in the initramfs image at the same location, as they are present on initramfs creation time.

# dracut --install 'strace fsck.ext3 ssh' initramfs-dbg.img

This will create an initramfs with the strace, fsck.ext3 and ssh executables, together with the libraries needed to start those. The --install option can be specified multiple times.

Network Boot

If your root partition is on a network drive, you have to have the network dracut modules installed to create a network aware initramfs image.

If you specify ip=dhcp on the kernel command line, then dracut asks a dhcp server about the ip adress for the machine. The dhcp server can also serve an additional root-path, which will set the root device for dracut. With this mechanism, you have static configuration on your client machine and a centralized boot configuration on your TFTP/DHCP server. If you can’t pass a kernel command line, then you can inject /etc/cmdline.d/mycmdline.conf, with a method described in the section called “Injecting custom Files”.

Reducing the Image Size

To reduce the size of the initramfs, you should create it with by ommitting all dracut modules, which you know, you don’t need to boot the machine.

You can also specify the exact dracut and kernel modules to produce a very tiny initramfs image.

For example for a NFS image, you would do:

# dracut -m "nfs network  base" initramfs-nfs-only.img

Then you would boot from this image with your target machine and reduce the size once more by creating it on the target machine with the --host-only option:

# dracut -m "nfs network base" --host-only initramfs-nfs-host-only.img

This will reduce the size of the initramfs image significantly.

Troubleshooting

If the boot process does not succeed, you have several options to debug the situation. Some of the basic operations are covered here. For more information you should also visit: https://www.kernel.org/pub/linux/utils/boot/dracut/dracut.html

Identifying your problem area

  1. Remove 'rhgb' and 'quiet' from the kernel command line
  2. Add 'rd.shell' to the kernel command line. This will present a shell should dracut be unable to locate your root device
  3. Add 'rd.shell rd.debug log_buf_len=1M' to the kernel command line so that dracut shell commands are printed as they are executed
  4. The file /run/initramfs/rdsosreport.txt is generated, which contains all the logs and the output of all significant tools, which are mentioned later.

If you want to save that output, simply mount /boot by hand or insert an USB stick and mount that. Then you can store the output for later inspection.

Information to include in your report

All bug reports

In all cases, the following should be mentioned and attached to your bug report:

  • The exact kernel command-line used. Typically from the bootloader configuration file (e.g. /boot/grub2/grub.cfg) or from /proc/cmdline.
  • A copy of your disk partition information from /etc/fstab, which might be obtained booting an old working initramfs or a rescue medium.
  • Turn on dracut