This commit reverts 477f7ae and bb19d06, which intended to fix an issue
with lingering old images, see #1098. However, as detailed in #1147,
this caused severe side effects while working with multiple larger
containers. Basically, the prune operation of one container removed
images of other containers that are just being created in parallel.
Instead of using the podman prune command we can use the meta datain the
start script to pinpoint exactly which image(s) to remove, including any
downloaded OCI archives when the container instance is removed.
Fixes#1147
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit adds metadata to track loaded OCI archives to allow skipping
'delete + load' of OCI images when restarting either the container or the
system as a whole. The sha256 of all loaded OCI archives is stored in a
sidecar file in our downloads directory. Then we verify the checksum of
the OCI archives against their same-named sidecar to determine if the OCI
archive is already loaded or not.
Additionally, the instance using the image is labled with metadata to detect
changes in the container configuration. This in turn allow skipping the
delete + create phase also of the instance.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The default timeout for 'podman stop foo' is 10 seconds, which for
heavily loaded systems with intricate shutdown process is *waaaay*
too short. Increase it to the container script default 30s, which
coincidentally is also the container@.conf template's kill delay.
Fixes#1149
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Not only great for debugging, but also allows users to start their
containers manually in another way. But yeah, mostly for debug.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This rectifies an omission from the initial yang model. Not all
charachters are supported in container and volume names. E.g.,
simply attempting to create a volume or container with a space
in the name causes this error message from podman:
podman: Error: running volume create option: names must match [a-zA-Z0-9][a-zA-Z0-9_.-]*: invalid argument
In addition to the regexp, the new 'ident' type also enforces a
minimum and maximum length. Sure, technically a single char is
allowed, but let's be reasonable, and who in their right mind
wants an identifier > 64 chars? We have description for that.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Slight refactor of page, adding another badge for the latest release,
and restructuring the Technical Details section a bit.
[skip ci]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The curl.sh wrapper script had several issues:
- Used 'shift 2' incorrectly without proper argument validation
- Required hostname as enviroment variable instead of option
- Lacked proper option parsing, should behave like a cross between
curl and sysrepocfg
All examples have been updated to match the refactored script, and
a local copy in utils/curl.sh has been added.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Fixes a minor regression after merge of BPi-R3. The RPi4 device tree,
specifically regulator-sd-io-1v8 in bcm2711-rpi-4-b.dts, requires the
GPIO voltage regulator be built-in for the SD card controller.
Fixes#1197
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Coverity scan detected a memory leak in the new firewall change() cb
where allocated memory from ietf_interfaces_get_all_l3() was not freed
on error paths when srx_get_diff() failed or returned NULL.
This commit consolidates all cleanup paths to use the 'done:' label,
ensuring ifaces, diff, and cfg are properly freed in all exit scenarios.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add supoprt for infix-firewall.yang, modeled on the zone-based firewalld
The terminology is a mix of firewalld, classic netfilter and inspired by
Ubiquity. E.g., zone 'policy' -> 'action', and the zone matrix overview.
- Port forwarding allows forwarding a range of ports
- Operational data comes from firewalld active rules
- Firewall logging goes to /var/log/firewall.log
- Show implicit/built-in rules and zones (HOST) in firewall matrix,
includes "locked" policy for the default-drop behavior
- The zone services field in admin-exec 'show firewall' shows ANY when
the zone default action is set to 'accept'
- Zone 'forwarding' and 'masquerade' settings live in Infix in the
policys instead, meaning users need to explicitly add a policy
to allow both intra-zone and inter-zone forwarding
- Support for emergency lockdown (kill switch)
- Pre-defined services (xml+enums) are filtered and included as a
separate YANG model, extensions added for netconf and restconf
- Includes initial support for firewalld rich rules
firewalld policy rules, including rich rules, have an obnoxious priority
field which is extremely hard to get right, so in Infix we use the far
superior YANG construct 'ordered-by user;'. This ensure all rules are
generated in that order by setting the priority field, on read-back from
firewalld (operational) the priority field is used to sort the output
of rules in the CLI.
Fixes#448
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Used by infix-firewall.c when figuring out interfaces that are not
explicitly assigned to any zone. Placing them in the default zone
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>