Commit Graph
617 Commits
Author SHA1 Message Date
Joachim Wiberg 918353dcc7 confd: drop 'enabled' node from IPv4 autoconf container
Neither the IPv6 autonconf container, nor the recently moved DHCP client
container have an 'enabled' flag.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-02 14:12:10 +01:00
Joachim Wiberg d53a35b867 confd: relocate /dhcp-client to /interfaces/interface/ipv4/dhcp
Please note, this change drops not only the global enabled flag, but also the
per-interface enabled flag, converting it to a presence container.  The name
of the container is also shortened from dhcp-client -> dhcp.  A pattern that
expected to be reused also for the DHCPv6 client.

Fixes #1109

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-02 14:11:53 +01:00
Joachim WibergandGitHub ed2355833e Merge pull request #1209 from kernelkit/confd-refactor-callbacks
Major refactor of how sysrepo callbacks is used in confd

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-31 17:49:53 +01:00
Joachim Wiberg 4b55e38741 board/aarch64: use %m modifier in default xPi hostnames
The xPi's usually don't have a VPD so the chassis mac-address probed at
boot is usually null in /run/system.json.  This commit adds a fallbkack
mechanism to populate this field so it can be used for unique hostnames
even on these boards.

Ths ietf-hardware.yang model does not have a notion of physical address,
so we augment one tht is generic enought to be used for other hardware
components than Ethernet, similar to what ietf-interfaces.yang use.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-31 13:26:08 +01:00
Joachim Wiberg 20d09febeb test: fix container-upgrade $ARCH mapping on Aarch64 systems
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-31 13:26:05 +01:00
Joachim Wiberg 921c4c809d test: update mock data for 'show hardware'
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-31 13:26:05 +01:00
Mattias Walström 021e864a6f all.yaml: meta/bootorder.py needs to be run after ietf-system (where upgrade resides)
To verify the bootorder is still valid after that part of the suite has run.
2025-10-30 12:28:02 +01:00
Mattias Walström 9aba65e14b test: ntp: Make NTP tests more robust 2025-10-30 12:28:00 +01:00
Mattias Walström 489487be16 test: syslog: Make syslog/remote test more robust 2025-10-29 22:05:29 +01:00
Joachim WibergandGitHub 9d271eb7c6 Merge pull request #1033 from kernelkit/yang-add-services
Add new operational support for services

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-29 09:59:33 +01:00
Joachim Wiberg d80186a556 test/docker: security analysis of GHSA-cq46-m9x9-j8w2 for scapy
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-28 17:31:32 +01:00
Richard Alpe b6d7e4f24e test: add unit tests for system services
Signed-off-by: Richard Alpe <richard@bit42.se>
2025-10-28 16:59:08 +01:00
Richard Alpe c119436f97 confd: augment new services container to ietf-system
This patch adds operational data support for system services. The
data is in a generic format but is intended to be able to represent
finit information (initctl) nicely.

The reason for augmenting this to ietf-system and not to
infix-services is that we consider this generic system information
which is totally disconnected from what ever services infix might
provide.

In this first state we only support pid, name, description and state.
Making the data look something like:

  "infix-system:services": {
    "service": [
      {
        "pid": 1185,
        "name": "udevd",
        "status": "running",
        "description": "Device event daemon (udev)"
      }]

Signed-off-by: Richard Alpe <richard@bit42.se>
2025-10-27 15:30:29 +01:00
Joachim Wiberg ce8dc0de9c test: update firewall/basic topology and doc
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-23 15:23:57 +02:00
Joachim Wiberg 9273f4cd1e test: remove redundant container_ prefix from test directories
Rename test directories in infix_containers/ to remove the redundant
'container_' prefix since they already live under infix_containers/:

  container_basic          -> basic
  container_bridge         -> bridge
  container_enabled        -> enabled
  container_environment    -> environment
  container_firewall_basic -> firewall_basic
  container_host_commands  -> host_commands
  container_phys           -> phys
  container_veth           -> veth
  container_volume         -> volume

Also update references in all.yaml and Readme.adoc files.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-23 15:23:56 +02:00
Joachim Wiberg 905df0dab7 test: verify container upgrade
This commit adds four (small) container images to the Infamy test container
which are used in the new container upgrade test.  The test verifies that a
mutable container can be upgraded and that old images are properly cleaned
up from the container store.

Fixes #624

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-23 15:23:56 +02:00
Joachim Wiberg 640a47bceb test: add support for 'make V=1 test-spec' to debug
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-23 15:23:56 +02:00
Joachim Wiberg f53d26bf34 container: upgrade fixes for mutable images
Container instances that run with mutable images, e.g., tagged with `:latest`
or similar non-versioned tags, can be upgraded without changing the config.

This commit fixes two issues found with this support:

- force container image re-fetch on upgrade, even if the file exists locally
- surgically remove old image from container store after upgrade

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-23 15:23:54 +02:00
Joachim Wiberg 23ed6e2f03 test: new test, zone migration, custom service, and IPv6
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:15 +02:00
Joachim Wiberg e6d945b77c test: new test, IPv6 version of lan-wan firewall
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:14 +02:00
Joachim Wiberg c069308c27 test: new test, wan-dmz-lan firewall with snat and dnat
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:14 +02:00
Joachim Wiberg a81f7c82e9 test: new test, lan-wan gateway with snat
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:14 +02:00
Joachim Wiberg 47c4ddfb7d test: new test, basic firewall zone verification
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:13 +02:00
Joachim Wiberg 1735a97dce test/infamy: add nmap to test container
- Sort packages alphabetically
 - Add nmap for firewall tests

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:13 +02:00
Joachim Wiberg 3224f49b65 confd: initial zone-based firewall support, based on firewalld
Add supoprt for infix-firewall.yang, modeled on the zone-based firewalld
The terminology is a mix of firewalld, classic netfilter and inspired by
Ubiquity.  E.g., zone 'policy' -> 'action', and the zone matrix overview.

 - Port forwarding allows forwarding a range of ports
 - Operational data comes from firewalld active rules
 - Firewall logging goes to /var/log/firewall.log
 - Show implicit/built-in rules and zones (HOST) in firewall matrix,
   includes "locked" policy for the default-drop behavior
 - The zone services field in admin-exec 'show firewall' shows ANY when
   the zone default action is set to 'accept'
 - Zone 'forwarding' and 'masquerade' settings live in Infix in the
   policys instead, meaning users need to explicitly add a policy
   to allow both intra-zone and inter-zone forwarding
 - Support for emergency lockdown (kill switch)
 - Pre-defined services (xml+enums) are filtered and included as a
   separate YANG model, extensions added for netconf and restconf
 - Includes initial support for firewalld rich rules

firewalld policy rules, including rich rules, have an obnoxious priority
field which is extremely hard to get right, so in Infix we use the far
superior YANG construct 'ordered-by user;'.  This ensure all rules are
generated in that order by setting the priority field, on read-back from
firewalld (operational) the priority field is used to sort the output
of rules in the CLI.

Fixes #448

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:12 +02:00
Joachim Wiberg 5f51ef065e test: verify ospf neighbors in setup with non-ospf interface
Extend OSPF basic with a regression test for issue #1169

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-03 12:55:43 +02:00
Joachim Wiberg dcc39da87d test/9m: bump to latest version
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-02 10:30:14 +02:00
Joachim Wiberg a0a4051c8a test/infamy: fix xpath_to_uri() to handle multiple predicates
The xpath_to_uri() method only processed the first predicate in XPath
expressions with multiple [key='value'] patterns.  Each re.sub() call
was performed on the original xpath instead of the result the previous
substitutions, causing subsequent predicates to be ignored.

Example XPath that would fail:

    /infix-firewall:firewall/zone[name='untrusted']/interface[.='e2']

Would incorrectly convert to:

    /infix-firewall:firewall/zone[name='untrusted']/interface=e2

Instead of the correct RESTCONF URL:

    /infix-firewall:firewall/zone=untrusted/interface=e2

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-28 22:02:58 +02:00
Joachim Wiberg 9d9e099cdb test/infamy: slight improvement to tap.py::Test.__exit__()
Before this change:

  ok 2 - Configure basic end-device firewall
  not ok 3 - Verify unused interface assigned to default zone
  # Exiting (2025-09-25 11:33:00)
  # Traceback (most recent call last):
  #   File "/home/jocke/src/x-misc/test/./case/infix_firewall/basic/test.py", line 127, in <module>
  #     assert unused_if not in public_zone["interface"], \
  #            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  # AssertionError: Unused interface e4 should be in default zone 'public', got interfaces: ['e2', 'e3', 'e5', 'e7', 'e8']

After this change:

  ok 2 - Configure basic end-device firewall
  not ok 3 - Verify unused interface assigned to default zone
  # Exiting (2025-09-25 11:35:00)
  #   File "/home/jocke/src/x-misc/test/./case/infix_firewall/basic/test.py", line 127, in <module>
  #     assert unused_if not in public_zone["interface"], \
  #            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  # Unused interface e4 should be in default zone 'public', got interfaces: ['e2', 'e3', 'e5', 'e7', 'e8']

Slightly shorter and arguably easier to read for a non-pythonic human.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-28 21:35:32 +02:00
Joachim Wiberg a9430070d2 test/infamy: add optional msg support to tap.py::Test.fail()
A very common pattern in our tests is:

  if (condition):
    print(f"the condition failed with {output}")
    test.fail()

This change allows us to write:

  if (condition):
    test.fail(f"the condition failed with {output}")

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-28 21:35:32 +02:00
Joachim Wiberg a3d30eb32f test/infamy: minor, whitespace only
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-28 21:35:31 +02:00
Joachim Wiberg c42b0b536d test: minor, cleanup of specifications
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-28 07:26:45 +02:00
Joachim Wiberg c61b4361ab test: simplify and skip UNIX backup files
- Drop 'local', not available in POSIX shell scripts
 - Check for an assortment of backup file combos
 - Simplify nested if-statements, skip whitelist first

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-28 07:26:45 +02:00
Joachim Wiberg 805acdf782 test: bump 9pm for test ID and meta data section in report
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-15 16:23:20 +02:00
Joachim Wiberg 142e4e95b7 test: consistent naming for all yaml files
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-15 14:26:06 +02:00
Joachim Wiberg 44d37808f1 test/case: use 9pm 'name:' for all test names
To reduce the duplication of effort between 9pm and the Infamy framework
this change consolidates the move from local 'infamy: title:' extension
to 9pm 'name:'.

For the parameterized tunnel tests we leverage the 9pm dynamic test-spec
variable, which looks for a correspodning <case>.adoc instead of static
Readme.adoc, when generating the test report.

Each test documentation should cover all aspects of the test, much like
the usage text of a UNIX program.  To this end, the tunnel test docs are
now more spelled out, including all invariants.

Some refactoring of these tests were also necessary, e.g., replacing any
reserved Python keywords like 'type', and other PEP-8 fixes.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-15 14:26:06 +02:00
Joachim Wiberg eb3e64d243 test/case: rename foo.adoc -> test.adoc and update all Readme.adoc
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-15 14:26:05 +02:00
Joachim Wiberg 2171fd12ca test/case/infix_dhcp: allow generating subsystem test resports
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-15 14:26:04 +02:00
Joachim Wiberg 249af70dcd test: add intro blurb to each subsystem
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-15 14:26:04 +02:00
Joachim Wiberg b4a5b35c0e test/spec: refactor test spec & report generation
Import new 9pm version for improved test report generation.  With this
in place we can take the opportunity to also refactor and simplify the
test spec. generation.

Fixes #1129

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-15 14:26:03 +02:00
Joachim Wiberg fe2d0f488d test/case: simplify AsciiDoc image references
This commit greatly simplifies AsciiDoc image references in generated
Readme.adoc files.  The two focused use-cases that remain after this
change are working references in:

 - Generated output/images/test-report.pdf
 - Viewing test's Readme.adoc from GitHub

Previously we aimed to have working images also when the test's Readme
was included in the parent directory's Readme.adoc.  This, however, is
not supported as of this commit.  It seems unlikely also to ever be a
supported feature of AsciiDoc on GitHub, for details, see the following
issue: <https://github.com/github/markup/issues/1095>

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-15 06:40:38 +02:00
Joachim Wiberg c14140a8fe test: relocate logic for creating test-report.pdf from workflow
It should be possible to create test reports manually, so logically
the GitHub workflow should call a make rule in test.mk

Untested: branding, or any case where Infix is used as a BR2_EXTERNAL

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-15 06:40:38 +02:00
Joachim Wiberg 9fe661f422 test/infamy: silence schema download in restconf backend
NETCONF backedn already silenced.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-15 06:40:38 +02:00
Joachim Wiberg 87f9b58957 test/spec: pep-8 fixes, minor cleanup only
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-15 06:40:37 +02:00
Joachim Wiberg b657183209 test/case/infix_services: refactor mdns-allow-deny
Major refactor to redesign how listeners and traffic is started in parallel.

Fixes #1130

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-15 06:40:37 +02:00
Joachim Wiberg 1aad255846 test/case/infix_container: refactor container-environment
Refactor test to use httpd container instead and return ENV with a CGI.

Fixes #1131

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-15 06:40:36 +02:00
Joachim Wiberg 52beeb5814 test/infamy: refactor Furl class to support list of needles
Also, add some documentation to lower barrier of entry/use.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-15 06:40:35 +02:00
Mattias Walström dce9a9c53d test: Add new sanity check tests
One to verify it is the correct version on the duts and one
that check that it is the correct bootorder.
2025-09-05 16:34:11 +02:00
Joachim Wiberg fc7e1d0745 test/case/infix_containers: extend retry for containers
For a heavily loaded system, 10 seconds/retries is not enough time to
expect containers to have started up.  Particularly after the changes
done recently to do prune before and after a container is started.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-02 10:53:49 +02:00
Joachim Wiberg 950a6ef794 test/case/infix_containers: new test, verify environment
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-09-02 10:53:48 +02:00