Commit Graph
17 Commits
Author SHA1 Message Date
Joachim WibergandMattias Walström 23dc237403 Switch to PAM for system authentication
- Add sshd 'UsePAM yes'
 - Buildroot automatically adds and enables:
   - /etc/pam.d/ with authentication for login, sshd, and sudo
   - PAM support in BusyBox login

Also, prepare for adding RADIUS authentication support to ietf-system
the only tricky part is testing against a RADIUS server.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-15 16:06:08 +02:00
Joachim WibergandMattias Walström 6a8eaacc6e Replace python + rust based gencert2 with C based gencert3
Also, sync r2s_defconfig with latest major changes.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-03 15:33:00 +02:00
Joachim WibergandTobias Waldekranz 22c911f85e package/landing: new package
Relocate the default landing page from the rootfs overlay to a package
so that customer repos can override it.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-03 07:54:48 +02:00
Mattias Walström 0c917ab37e Revert "Change toolchaing from bleeding edge => stable"
This reverts commit 66ec55b7e8.

Whit this, crun failed in mysterius ways. Revert to bleeding edge.
2024-04-16 12:47:16 +02:00
Mattias Walström d3e653d480 Change toolchaing from bleeding edge => stable
This fixes #383
2024-04-16 12:47:16 +02:00
Joachim Wiberg e06bcb64a5 configs: run Finit getty on @console instead of /dev/console
The Finit @console construct detects what your actual serial console is
by looking it up in /sys/class/tty/console/active.  This to avoid any
weird problems that might occur when using /dev/console.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg fc7d9bacac board/common: enable ttyd, web console app
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 92d3db46a7 netbrowse: convert to gunicorn and factor out mdns-alias app
Converting to gunicorn, which is the recommended production server for
Flask apps, means app main() function is no longer called at startup, so
we have to factor out the mDNS CNAME functionality for infix.local and
network.local to a separate app.

We take this opportunity to collapse the structure, move non-class
methods to __init.py__, and rename the AvahiAlias class.  A prototype
for replacing the overhead of mdns-alias with a C daemon is in its
early stages.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg c1836af7cc package/netbrowse: new package
- Advertises the build-time $hostname.local as a CNAME to the A and
   AAAA records already advertised by Avahi
 - Advertises a special network.local CNAME and provides a fastcgi
   service on unix:/tmp/netbrowse.sock for browsing mDNS services

This commit also activates netbrowse by default with nginx listeing
to port 80 on IPv4 and IPv6 /browse by default but also / if called
with server name network.local.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Tobias Waldekranz 2bd3b508ee kernel: Bump to 6.6.22 + kkit-linux-6.6.y 2024-03-20 14:41:25 +01:00
Mattias WalströmandJoachim Wiberg 5ced70435b Replace querierd with mcd in defconfigs 2024-03-09 11:58:40 +01:00
Joachim Wiberg 360d3b322d confd: use podman stop/start to prevent container corruption
Sending SIGTERM to conmon is not a safe shutdown of a podman container.
To handle gracefully handle shutdown, restarting and provide an orderly
start of dependencies, we use the Finit sysv trick via container script
wrapper to call 'podman stop foo'.

However, since podman does not support syslog as output for containers
we employ an old FIFO trick with another program, k8s-logger, to allow
logs to reach syslog.  Please note that k8s-logger must have properly
started before we call `podman start` -- this makes us fully dependent
on the 'container' wrapper script.  Hence the documentation update.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 0f0c119553 configs: sync r2s defconfig with latest changes
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg f0f0e737a9 board/common: BusyBox ash != bash, set bash as root default shell
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim WibergandTobias Waldekranz 236f3ec183 board/aarch64/r2s: patch device tree for factory-password-hash
Since the Nanopi R2S does not have a VPD, we use this mechanism to set
the default admin password.  Without one, Infix will refuse to generate
the factory- and failure-config files, and thus refuse to start.

On custom boards in production we have VPD in ONIE format that contains
a per-device unique SHA256 hashed admin user password.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-22 11:20:01 +01:00
Joachim WibergandTobias Waldekranz 2ade7fd9ab configs/r2s_defconfig: resort/make update-defconfig
Loss of BusyBox "show others", uboot-tools, and e2fsprogs, are likely
due to resolved dependencies from other packages.  E.g., Frr requires
bash.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-22 11:20:01 +01:00
Joachim WibergandTobias Waldekranz 10ec9089bc Initial support for Nanopi R2S from FriendlyELEC
Support for this is based on the upstream Buildroot R2S defconfig and
the myLinux extensions and stripped-down kernel defconfig.  For more
information about the Nanopi R2S, see the FriendlyELC wiki at:

    https://wiki.friendlyelec.com/wiki/index.php/NanoPi_R2S

Please note, due to the lack of a VPD on the board, and some very poor
devicetree skills by yours truly, Infix currently refuse to boot on this
board.  An in-devicetree factory-password-hash node has to be added, and
will be done soon.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-22 11:20:01 +01:00