Allow particular boards or platforms install hardware specific scripts
in /etc/support.d, via the usual /usr/share/product logic, which are
then run by /sbin/support and included in the resulting bundle.
This lets us collect hardware specific information, e.g., SoC-specific
error counters, without /sbin/support needing to know about all the
nitty gritty details.
Store historical snapshots as compressed .json.gz files to reduce disk
usage. The operational.json file remains uncompressed for easy access.
Signed-off-by: Richard Alpe <richard@bit42.se>
Dump operational datastore to timestamped JSON snapshots every 5 minutes
(in /var/lib/statd/). The operational.json symlink always points to the
latest snapshot.
Implement hierarchical retention policy that keeps the first snapshot of
each time period (hour/day/week/month/year), providing fine-grained recent
history while preventing unbounded disk usage.
This will allow us to plot / track how the system state evolves as
well as give us somewhat fine-grained info in the case of an event,
such as a crash.
Add unit test simulating months of snapshots to verify retention
behavior using a statd stub that only runs the retention code locally
(unit test)
Signed-off-by: Richard Alpe <richard@bit42.se>
This patch adds diagnostic data and additional logging to catch the root
cause for issue #1303:
- Exactly when and why cleanup is called
- Whether the cd /tmp command succeeds
- The actual tar exit code (not just 255 from SSH)
- Whether cleanup happens before tar completes (race condition)
- The full collection.log showing the sequence of events
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch unlocks "routing interfaces" support in the ietf-routing yang
model. An array of interface with IP forwarding enabled.
Note, because of #515 we skip IPv6 forwarding for now. This will in the
near future be handled by a per-interface force_forwarding sysctl flag.
The 'show interface [ifname]' admin-exec command has been extended with
a Flags field for a quick overview of which interfaces have forwarding
currently enabled.
Fixes#647
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit adds optional support for encrypting the tarball before it
leaves the target system. Documentation and usage text updated.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This fixes the following log message on systems w/o firewall enabled
dumping operational data:
Dec 2 09:24:57 test-00-02-00 yanger[5352]: Failed to connect to firewalld D-Bus: org.freedesktop.DBus.Error.ServiceUnknown: The name org.fedoraproject.FirewallD1 was not provided by any .service files
[skip ci]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Validate keys in gen_hostkey() before passing empty keys to shell scripts,
preventing:
Nov 04 2024 10:54:25 confd[2697]: SSH key (genkey) does not exist, generating...
Nov 04 2024 10:54:25 confd[2697]: writing RSA key
Nov 04 2024 10:54:26 confd[2697]: do_convert_from_pkcs8: /tmp/tmp.FH1Hr1 is not a recognised public key format
Also, fix base64 content formatting with proper 64-character line wrapping
using printf+fold instead of echo.
Use PKCS#1 RSA format for public keys as required by netopeer2-server, while
keeping PKCS#8 format for private keys. Use proper ssh-keygen format flag
(PKCS8) for correct conversion.
Fixes#1289
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Due to their nature we cannot read out the RPM of the pwm fans on the
BPi-R3. But we can at least show it's alive, or steering out a signal
to the fan.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The EXPIRES column was misaligned due to multiple issues:
- Column header used width 10 while data rows used width 9
- Expiry values had leading space intended for the narrower width
- CLIENT ID column width (19) was too narrow for typical client IDs
like "01:00:a0:85:00:01:05" (20 chars), causing overflow
Fixed by using consistent width for EXPIRES, removing the leading
space from expiry values, and widening CLIENT ID column to 22.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The isoformat() method already includes the timezone offset when the
datetime object has timezone info. Appending "+00:00" created an
invalid double-timezone suffix like "2025-11-30T13:13:49+00:00+00:00"
which failed YANG validation.
Error was:
admin@bpi-26-60-00:/> show dhcp-server
Error running sysrepocfg: Command '['sysrepocfg', '-f', 'json', '-X',
'-d', 'operational', '-x', '/infix-dhcp-server:dhcp-server']' returned
non-zero exit status 1.
No interface data retrieved.
With syslog showing:
statd[4291]: libyang[0]: Invalid union value
"2025-11-30T13:13:49+00:00+00:00" - no matching subtype found
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When PR #1271 was merged (commit c34c8db4), it:
1. Created a new coverity-build target in src/Makefile
2. Updated .github/workflows/coverity.yml to call make coverity-build
3. Forgot to add coverity-build as an explicit target in the top-level Makefile
This commit also simplifies src/Makfile a lot for readability.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
SIMPLIFY, Simplify, simplify ... as my uni English professor always said.
> “Perfection is achieved not when there is nothing more to add, but when
> there is nothing left to take away.” -- Antoine de Saint-Exupéry
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Let's give Coverity Scan its own make target so we can reuse 'make check'
for our own scan-build or cppcheck needs.
[skip ci]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This is the last commit in the series that extend syslog matching and sorting
to the level of sysklogd 2.7.0 and later. Like hostname filtering, property
based filtering is not supported natively in the IETF RFC, and the modeling is
unfortunately a bit clunky. The most confusing part is probably 'negate'
which is the '!' operator that inverts the matching, e.g., !icase_regex match
everthing *not* in the regexp.
Fixes#1091
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Unlock more of the optional features in ietf-syslog.yang: select-match and
select-adv-compare, for regexp and advanced severity comparison operators.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The vendor-class option was previously hard-coded to "Infix vXX.YY.Z",
but since this option usually describes the type of the device asking
for a lease, the default has been changed to use the product-name.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Resolve race condition between DHCP and configured hostname by introducing
priority-based hostname management using /etc/hostname.d/ directory pattern.
Priority order (highest wins):
90-dhcp-<iface> - DHCP assigned hostname
50-configured - YANG /system/hostname config
10-default - Bootstrap/factory default
The new /usr/libexec/infix/hostname helper reads all sources and applies the
highest priority hostname. It exits early if hostname unchanged, preventing
unnecessary service restarts.
Fixes#1112
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Basic DHCPv6 support as a per-interface ipv6 setting, not in line with
the IETF YANG model, which has this as a root container.
Note, this also fixes DHCPv4 option inference after the relocation of
/dhcp-client to /interfaces, in 764bd8e.
Fixes#1110
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
We use the infinitive, or basic form, in configure context, as do most
other network vendors, so let's do the same in admin exec context.
Also, drop the 'name' qualifier, it is not needed in configure context
so we shouldn't have to use it in admin exec either.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
In an effort to consolidate and use familiar command paths for our most
common commands, let's follow suite with Cisco, vtysh, et al.
Add deprecation warning to legacy 'show route [ip|ipv6]' command.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Since we just un-deviated this node to be able to create operational
data for ospf interfaces, we should also allow users to set it.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Collect more data from FRR to the OSPF and BFD operational datastore.
Refactor CLI commands to use the YANG datastore instead of vtysh.
Additionally, the BFD command(s) have been moved to the top level of
admin-exec, which is where vtysh has them.
Finally, preparing for future OSPFv3 support, all commands have been
given a new context under 'show ip ospf'. Deprecation warnings have
been added to the existing 'show ospf' commands.
Also, for consistency, all commands names in plural have been changed to
their singular form: routes -> route, interfaes -> interface, etc. This
is what vtysh, Cisco, and others do as well.
Fixes#1190
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Silently drop any area-type setting for ospf backbone in a migrate
script to prevent any field issues after upgrading to this fix.
Fixes#1247
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Adds support for configuring TTL, ToS/DSCP, and Path MTU Discovery
on GRE and VXLAN tunnels. TTL defaults to 64 instead of inherit to
prevent issues with routing protocols like OSPF that use TTL=1.
Refactors tunnel YANG models by merging local-remote into a unified
tunnel-common grouping for cleaner organization.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The callback refactoring forgot to call ietf_interfaces_cand_init(),
breaking inference of interface types and DHCP client options.
Also fixes UPDATE event handling for ietf-keystore and infix-meta.
Fixes#1244
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Neither the IPv6 autonconf container, nor the recently moved DHCP client
container have an 'enabled' flag.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Please note, this change drops not only the global enabled flag, but also the
per-interface enabled flag, converting it to a presence container. The name
of the container is also shortened from dhcp-client -> dhcp. A pattern that
expected to be reused also for the DHCPv6 client.
Fixes#1109
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This fixes the annoying libyang warning after commit da29771.
confd[3375]: libyang[0]: Invalid argument ctx_node (lyd_find_xpath()).
This happens when the diff is used in the wrong event when it is NULL.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>