Wrap wpa_cli operations in try-except blocks to ensure WiFi errors don't
cause sysrepocfg to fail. Interface queries now return data for working
interfaces even when WiFi has issues.
Fixes:
admin@rpi-79-41-1d:/> show interfaces
Error running sysrepocfg: Command '['sysrepocfg', '-f', 'json', '-X', '-d', 'operational', '-x', '/ietf-interfaces:interfaces']' returned non-zero exit status 1.
No interface data retrieved.
admin@rpi-79-41-1d:/>
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add new interface quirk to allow skipping disabling of flow control on
all RPi 3B/4B devices that have the smsc95xx driver.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The xPi's usually don't have a VPD so the chassis mac-address probed at
boot is usually null in /run/system.json. This commit adds a fallbkack
mechanism to populate this field so it can be used for unique hostnames
even on these boards.
Ths ietf-hardware.yang model does not have a notion of physical address,
so we augment one tht is generic enought to be used for other hardware
components than Ethernet, similar to what ietf-interfaces.yang use.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit consolidates all BSP support files into the Buildroot standard
board/ directory. The concept of selectable boards in menuconfig remains
as-is but now lives in board/ instead.
Drop support for board-specific post-build.sh scripts, not needed atm. and
we should really use Buildroot _POST_INSTALL_HOOKS in the board .mk files
instead.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
With the additional support for RPi3, including Zero 2W, this commit renames
all relevant directories and Config.In options to match.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
For more advanced hardware with multiple sensor types per device
(e.g., SFP modules with temperature, voltage, current, and power
sensors), use the YANG parent/child relationship to group related
sensors together for better presentation.
Changes:
- Remove parent/parent-rel-pos deviations from infix-hardware.yang
- Create parent components (class: module) for multi-sensor devices
- Add parent references to child sensor components
- Add human-readable descriptions from hwmon labels
- Extend hwmon discovery to support voltage, current, and power
- Normalize sensor names: strip vendor prefixes (mt7915_phy0 -> phy0)
- Remove redundant TYPE column, clarify units (V -> VDC, add spaces)
- Simplify child sensor display by stripping parent prefix
- Fix "show system" to only show CPU temperature and fan speed
Example output from "show hardware":
NAME VALUE STATUS
===================================================
sfp1:
Rx Power 0.000 W ok
Tx Power 0.001 W ok
Vcc 3.35 VDC ok
Bias 0.006 A ok
Temperature 30.3 °C ok
sfp2:
Rx Power 0.000 W ok
Tx Power 0.001 W ok
Vcc 3.34 VDC ok
Bias 0.006 A ok
Temperature 32.0 °C ok
cpu 42.8 °C ok
phy0 47.0 °C ok
phy1 53.0 °C ok
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit adds resource usage: memory, loadavg, and filesystem usage
by augmenting ietf-system:/system-state.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Remove class deviation to allow iana-hardware:sensor
- Populate sensor operational data from /sys/class/thermal
- Extend 'show hardware'
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Usually, when upgrading a system, you want to reboot it so the upgrade
takes effect. This commit adds a 'reboot' option/flag, alongside the
'force' option, to facilitate this.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit refactors USB port probing to:
- Eliminate duplicates: previously, 'authorized' and 'authorized_default'
were listed as separate USB port entries (confusing). Now each USB
port is represented once, with the path pointing to the USB device
directory, confd appends the appropriate attribute file as needed
- Add support for Raspberry Pi 4B and CM4 USB port(s) using a generic
discovery function that scans /sys/bus/usb/devices for USB root hubs.
This should work seamlessly across all platforms
- For backwards compatibility and better UX:
- Single USB port systems: Named "USB" (no number)
- Multi-port systems: Named "USB1", "USB2", etc.
- Device tree-based discovery is tried first (for boards like Alder with
explicit DT USB port definitions), with fallback to generic discovery
for boards without DT
Fixes: #315
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit adds support for the Raspberry Pi CM4 based mini DFRobot IoT
Router board, SKU:DFR0767. It comes with an additional RTL8111 PCIe NIC
hence the addidtional kernel module and firmware. The latter fixes:
r8169 0000:01:00.0: Direct firmware load for rtl_nic/rtl8168h-2.fw failed with error -2
r8169 0000:01:00.0: Unable to load firmware rtl_nic/rtl8168h-2.fw (-2)
Please note, the change in BCMGENET from module to built-in is to ensure
it is probed before any PCIe NIC, both this board and the CM4-based NVME
NAS base board enumerate the built-in MAC as eth0.
Also, unlike the RPi 3B/4B, it is not a given fact that a CM4 based board
comes with WiFi onboard, and since most compute module setups are DYI, we
take the easy way out and leave it as an exercise to the user to add WiFi
interface to the config.
https://wiki.dfrobot.com/Compute_Module_4_IoT_Router_Board_Mini_SKU_DFR0767
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The BCM2837 core is used not just in the RPi 3B but also in the Zero 2W,
both device trees have been added to the board config.
The BCM2711 support has been extended to include RPi 400 and CM4 I/O.
To support the BCM2837 family more firmware options habe been enabled,
since the RPi3 does not have bootcode.bin flashed in the SoC. The SD
card image now uses a hybrid GPT/MBR format so the RPi3 bootcode.bin
can read all files from the first VFAT partition.
The default device tree for Linux is now chosen by the U-Boot probe and
the only exception is the "laundry room" detector that looks for a RPi4
with a 7" touch screen, which then selects the DSI enabled RPi4 variant.
This is enough to properly load an RPi 3B and a CM4 based router board.
The BCM2837 does not have PCI/PCIe or a built-in MAC so it relies on the
USB to Ethernet LAN78xx which does not support disabling pause frames.
I have opted for checking for EOPNOTSUPP instead of adding yet another
quirk, because it is likely to be a common limitation of more drivers
and chipsets, and this code is best-effort anyway.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Sysrepo lack the functionallity for if change in model A also
should demand actions of model B. Previous we have handled this by
having callbacks for keystore changes in for example infix-services
to be able to reconfigure SSH on asymmetric key changes.
This commit instead add a pass where dependencies are found and added
to the diff.
Sysrepo only care about model changes, but we want the system
configuration. Therefore add a common callback for all modules
and handle dependencies between the modules, if someone should be
run before another for example.
This will make sure to apply NACM rules for all the data. It also
makes it possible for a luser access a subset of the data, even if
they to do not have read access to /cfg/startup-config.cfg.
Bridge ports should not have IP addresses configured. The IP address
should be configured on the bridge interface itself, not its member ports.
Add YANG must expression to enforce this rule at configuration time.
Fixes#1122
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A valid DHCP server setup for a subnet is one of pool and/or at least one
static host entry/lease. If pool is enabled the pool must have a start
and an end address.
To allow setting up a DHCP server with no pool and at least one static host
entry/lease, we make the pool a presence container, otherwise the pool will
always be set and trigger the below inference.
When an interactive CLI/Web user enables the address pool we infer a default
range .100-.250, but only for /24, C-class networks. This is what most users
know and expect.
The YANG model now validates that:
- If an address pool is created, both start-address and end-address must be set
- Each subnet must have either a pool or at least one static host entry
- The pool container is now a presence container, so "no pool" fully deletes it
Fixes#1121
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Multiple services can have PID 0 when stopped/done, making PID
unsuitable as a unique key. There could also be multiple services with
the same name (I would assume?).
Signed-off-by: Richard Alpe <richard@bit42.se>
This patch adds operational data support for system services. The
data is in a generic format but is intended to be able to represent
finit information (initctl) nicely.
The reason for augmenting this to ietf-system and not to
infix-services is that we consider this generic system information
which is totally disconnected from what ever services infix might
provide.
In this first state we only support pid, name, description and state.
Making the data look something like:
"infix-system:services": {
"service": [
{
"pid": 1185,
"name": "udevd",
"status": "running",
"description": "Device event daemon (udev)"
}]
Signed-off-by: Richard Alpe <richard@bit42.se>
Address two issues identified by Coverity Scan:
1. CID 550484 (TOCTOU): Remove access() check before realpath()
- realpath() already fails if file doesn't exist, making the
access() check redundant and introducing a TOCTOU race
- Simplifies code while improving security
2. CID 550483 (CHECKED_RETURN): Mark unchecked remove() calls
- Add (void) cast to two remove() calls to explicitly indicate
we don't care about the return value
- These are cleanup operations for temp files where failure
is acceptable, even expected
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add bash completion for the common datastores, like we already do in the
CLI, and update the usage text accordingly.
Also, make sure to install to /usr/bin, not /bin since we've now merged
the hierarchies since a while back.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The regular file-to-file copy, was missing calls to cfg_adjust(), this
commit fixes that and adds some helpful comments for each use-case.
Also, drop insecure mktemp() in favor of our own version which uses the
basename of the remote source file.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This is a follow-up to PR #717 where path traversal protection was
discussed. A year later and it's clear that having a user-friendly
copy tool in the shell is a good thing, but that we proably want to
restrict what it can do when called from the CLI.
A sanitize flag (-s) is added to control the behavior, when used in the
shell without -s, both commands act like traditional UNIX tools and do
assume . for relative paths, and allow ../, whereas when running from
the CLI only /media/ is allowed and otherwise files are assumed to be
in $HOME or /cfg
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit adds config file validation to the copy command, discussed
in #373. Allowing users to test their config files before restoring a
backup. The feature could also be used for the automatic rollback when
downgrading to an earlier version of the OS.
Fixes#373
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When copying to the running datastore we cannot use sr_copy_config(),
instead we must use sr_replace_config(). This fix covers both the case
of 'copy startup-config running-config' and 'copy FILE running-config'.
Fixes#1203
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Already supported in the CLI. This makes it official, and quite handy
for users that run mutable containers.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Shell script:
- Factor out big portions of code into more logical helper functions
- Simplify calling setup script by checking for remote image first
- Simplify meta/sha up-to-date handling and clarify terminology
- Consistent use of -f instead of -e in file-exists checks
- Fix unsafe use of 'mktemp -u'
C code:
- Clarify meta/sha terminology: rename meta-sha256 -> meta-image-sha256
- Refactor weird archive_offset() function to local_path() helper
- Factor out helper function calc_sha()
- Check len of sha256 >= 64
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Usually, when your system is up and running properly, you want to clean
up anything unused from your previous experiments. This change alllows
that by calling the interactive 'podman image prune -a -f' command from
the CLI command 'container remove all'
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit reverts 477f7ae and bb19d06, which intended to fix an issue
with lingering old images, see #1098. However, as detailed in #1147,
this caused severe side effects while working with multiple larger
containers. Basically, the prune operation of one container removed
images of other containers that are just being created in parallel.
Instead of using the podman prune command we can use the meta datain the
start script to pinpoint exactly which image(s) to remove, including any
downloaded OCI archives when the container instance is removed.
Fixes#1147
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit adds metadata to track loaded OCI archives to allow skipping
'delete + load' of OCI images when restarting either the container or the
system as a whole. The sha256 of all loaded OCI archives is stored in a
sidecar file in our downloads directory. Then we verify the checksum of
the OCI archives against their same-named sidecar to determine if the OCI
archive is already loaded or not.
Additionally, the instance using the image is labled with metadata to detect
changes in the container configuration. This in turn allow skipping the
delete + create phase also of the instance.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Not only great for debugging, but also allows users to start their
containers manually in another way. But yeah, mostly for debug.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This rectifies an omission from the initial yang model. Not all
charachters are supported in container and volume names. E.g.,
simply attempting to create a volume or container with a space
in the name causes this error message from podman:
podman: Error: running volume create option: names must match [a-zA-Z0-9][a-zA-Z0-9_.-]*: invalid argument
In addition to the regexp, the new 'ident' type also enforces a
minimum and maximum length. Sure, technically a single char is
allowed, but let's be reasonable, and who in their right mind
wants an identifier > 64 chars? We have description for that.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>