Commit Graph
1241 Commits
Author SHA1 Message Date
Tobias Waldekranz 15aa98b7e3 support: Exec hardware specific scripts from /etc/support.d
Allow particular boards or platforms install hardware specific scripts
in /etc/support.d, via the usual /usr/share/product logic, which are
then run by /sbin/support and included in the resulting bundle.

This lets us collect hardware specific information, e.g., SoC-specific
error counters, without /sbin/support needing to know about all the
nitty gritty details.
2025-12-16 14:26:46 +01:00
Richard Alpe cb9aeea351 statd: compress journal snapshots with gzip
Store historical snapshots as compressed .json.gz files to reduce disk
usage. The operational.json file remains uncompressed for easy access.

Signed-off-by: Richard Alpe <richard@bit42.se>
2025-12-15 11:07:45 +01:00
Richard Alpe c767a6f9a0 statd: add operational data journal with retention policy
Dump operational datastore to timestamped JSON snapshots every 5 minutes
(in /var/lib/statd/). The operational.json symlink always points to the
latest snapshot.

Implement hierarchical retention policy that keeps the first snapshot of
each time period (hour/day/week/month/year), providing fine-grained recent
history while preventing unbounded disk usage.

This will allow us to plot / track how the system state evolves as
well as give us somewhat fine-grained info in the case of an event,
such as a crash.

Add unit test simulating months of snapshots to verify retention
behavior using a statd stub that only runs the retention code locally
(unit test)

Signed-off-by: Richard Alpe <richard@bit42.se>
2025-12-09 16:16:53 +01:00
Joachim WibergandGitHub 2d35f15242 Merge pull request #1306 from kernelkit/rip 2025-12-06 20:44:58 +01:00
Joachim Wiberg 69bbf6fafc support: use $0 in usage text and error messages
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-05 16:33:06 +01:00
Joachim Wiberg c89c1f689b support: diagnostic debug for flaky test
This patch adds diagnostic data and additional logging to catch the root
cause for issue #1303:

  - Exactly when and why cleanup is called
  - Whether the cd /tmp command succeeds
  - The actual tar exit code (not just 255 from SSH)
  - Whether cleanup happens before tar completes (race condition)
  - The full collection.log showing the sequence of events

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-05 14:40:02 +01:00
Joachim Wiberg 024b51cc6a statd: add support for ip forwarding operational state
This patch unlocks "routing interfaces" support in the ietf-routing yang
model.  An array of interface with IP forwarding enabled.

Note, because of #515 we skip IPv6 forwarding for now.  This will in the
near future be handled by a per-interface force_forwarding sysctl flag.

The 'show interface [ifname]' admin-exec command has been extended with
a Flags field for a quick overview of which interfaces have forwarding
currently enabled.

Fixes #647

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-05 11:12:03 +01:00
Joachim Wiberg 1cbc9a49a2 confd: initial support for rip
Fixes #582

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-05 10:58:35 +01:00
Joachim WibergandGitHub ec0ed82b71 Merge pull request #1267 from kernelkit/post-post-image
Move to a post post-image world

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-03 20:32:36 +01:00
Tobias Waldekranz 94f5463504 onieprom: Create proper package 2025-12-03 16:46:10 +01:00
Joachim Wiberg 7edc3c19f7 confd: add support for toggling OSPF debug logs
Fixes #1281

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-02 17:06:10 +01:00
Joachim Wiberg cfeb875b2b bin: collect data by default to /var/lib/support
Also, adjust file suffix for json files.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-02 13:58:25 +01:00
Joachim Wiberg 9ce47017d8 bin: add optional support for encrypting the support tarball
This commit adds optional support for encrypting the tarball before it
leaves the target system.  Documentation and usage text updated.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-02 13:38:42 +01:00
Joachim Wiberg a1067fd049 bin: add system support data collection
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-02 13:38:41 +01:00
Joachim Wiberg 51f289a273 statd: reduce log warning to debug
This fixes the following log message on systems w/o firewall enabled
dumping operational data:

Dec  2 09:24:57 test-00-02-00 yanger[5352]: Failed to connect to firewalld D-Bus: org.freedesktop.DBus.Error.ServiceUnknown: The name org.fedoraproject.FirewallD1 was not provided by any .service files

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-02 11:02:06 +01:00
Joachim WibergandGitHub cd0a5f3063 Merge pull request #1290 from kernelkit/hostkey-warning
Fix SSH host key generation warnings
2025-12-02 10:59:57 +01:00
Joachim Wiberg d23f9ea25b confd: fix SSH host key generation warnings
Validate keys in gen_hostkey() before passing empty keys to shell scripts,
preventing:

Nov 04 2024 10:54:25 confd[2697]: SSH key (genkey) does not exist, generating...
Nov 04 2024 10:54:25 confd[2697]: writing RSA key
Nov 04 2024 10:54:26 confd[2697]: do_convert_from_pkcs8: /tmp/tmp.FH1Hr1 is not a recognised public key format

Also, fix base64 content formatting with proper 64-character line wrapping
using printf+fold instead of echo.

Use PKCS#1 RSA format for public keys as required by netopeer2-server, while
keeping PKCS#8 format for private keys.  Use proper ssh-keygen format flag
(PKCS8) for correct conversion.

Fixes #1289

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-02 09:50:24 +01:00
Joachim Wiberg fdb02895fb statd: add pwm fan support
Due to their nature we cannot read out the RPM of the pwm fans on the
BPi-R3.  But we can at least show it's alive, or steering out a signal
to the fan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-30 17:16:21 +01:00
Joachim Wiberg 8c291d3a94 statd: fix EXPIRES column alignment in 'show dhcp-server'
The EXPIRES column was misaligned due to multiple issues:
- Column header used width 10 while data rows used width 9
- Expiry values had leading space intended for the narrower width
- CLIENT ID column width (19) was too narrow for typical client IDs
  like "01:00:a0:85:00:01:05" (20 chars), causing overflow

Fixed by using consistent width for EXPIRES, removing the leading
space from expiry values, and widening CLIENT ID column to 22.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-30 13:37:08 +01:00
Joachim Wiberg 6c194007a1 statd: fix double timezone in DHCP lease expiry timestamps
The isoformat() method already includes the timezone offset when the
datetime object has timezone info.  Appending "+00:00" created an
invalid double-timezone suffix like "2025-11-30T13:13:49+00:00+00:00"
which failed YANG validation.

Error was:
  admin@bpi-26-60-00:/> show dhcp-server
  Error running sysrepocfg: Command '['sysrepocfg', '-f', 'json', '-X',
  '-d', 'operational', '-x', '/infix-dhcp-server:dhcp-server']' returned
  non-zero exit status 1.
  No interface data retrieved.

With syslog showing:
  statd[4291]: libyang[0]: Invalid union value
  "2025-11-30T13:13:49+00:00+00:00" - no matching subtype found

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-30 13:36:44 +01:00
Joachim Wiberg 173daf8fce statd: skip CAN interfaces in IETF interface model
Skip CAN interfaces that don't fit the IETF interface model.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-27 17:03:08 +01:00
Joachim Wiberg e01888f3d9 Fix Coverity Scan build target
When PR #1271 was merged (commit c34c8db4), it:

 1. Created a new coverity-build target in src/Makefile
 2. Updated .github/workflows/coverity.yml to call make coverity-build
 3. Forgot to add coverity-build as an explicit target in the top-level Makefile

This commit also simplifies src/Makfile a lot for readability.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-22 21:37:08 +01:00
Joachim WibergandGitHub c592b26b94 Merge pull request #1271 from kernelkit/scanbuild
Reclaim 'make check' for manual use, add scan-build support

[skip ci]
2025-11-21 10:58:40 +01:00
Joachim Wiberg b9a56924ac confd: drop ietf/infix prefix from function names
SIMPLIFY, Simplify, simplify ... as my uni English professor always said.

> “Perfection is achieved not when there is nothing more to add, but when
>  there is nothing left to take away.” -- Antoine de Saint-Exupéry

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-20 20:23:25 +01:00
Joachim Wiberg c398e42ca9 confd: drop leading ietf/infix prefix in source files
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-20 20:23:24 +01:00
Joachim Wiberg c34c8db435 src: reclaim 'make check' for manual use, add scan-build support
Let's give Coverity Scan its own make target so we can reuse 'make check'
for our own scan-build or cppcheck needs.

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-20 19:31:04 +01:00
Joachim Wiberg ed6db59e68 confd: extend syslogd support with property-based filtering
This is the last commit in the series that extend syslog matching and sorting
to the level of sysklogd 2.7.0 and later.  Like hostname filtering, property
based filtering is not supported natively in the IETF RFC, and the modeling is
unfortunately a bit clunky.  The most confusing part is probably 'negate'
which is the '!' operator that inverts the matching, e.g., !icase_regex match
everthing *not* in the regexp.

Fixes #1091

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-20 14:05:37 +01:00
Joachim Wiberg 18e80ceb11 confd: extend syslogd support with hostname-based filtering
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-20 14:05:36 +01:00
Joachim Wiberg c1b57c17bd confd: extend syslogd with regexp matching and advanced severity ops
Unlock more of the optional features in ietf-syslog.yang: select-match and
select-adv-compare, for regexp and advanced severity comparison operators.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-20 12:00:06 +01:00
Joachim Wiberg 52320a973a confd: add support for dhcpv4 vendor-class option
The vendor-class option was previously hard-coded to "Infix vXX.YY.Z",
but since this option usually describes the type of the device asking
for a lease, the default has been changed to use the product-name.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-20 09:33:59 +01:00
Joachim Wiberg 90f619bfa6 confd: add deterministic hostname management via /etc/hostname.d/
Resolve race condition between DHCP and configured hostname by introducing
priority-based hostname management using /etc/hostname.d/ directory pattern.

Priority order (highest wins):
  90-dhcp-<iface>  - DHCP assigned hostname
  50-configured    - YANG /system/hostname config
  10-default       - Bootstrap/factory default

The new /usr/libexec/infix/hostname helper reads all sources and applies the
highest priority hostname.  It exits early if hostname unchanged, preventing
unnecessary service restarts.

Fixes #1112

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-18 19:07:25 +01:00
Joachim Wiberg a568f31309 confd: add support for dhcpv6 client
Basic DHCPv6 support as a per-interface ipv6 setting, not in line with
the IETF YANG model, which has this as a root container.

Note, this also fixes DHCPv4 option inference after the relocation of
/dhcp-client to /interfaces, in 764bd8e.

Fixes #1110

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-18 13:28:15 +01:00
Joachim Wiberg 25d220ee1f cli: add 'show boot-order' and 'set boot-order a b c' commands
Fixes #1032

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-17 11:27:35 +01:00
Joachim Wiberg 101185934b cli: use infintive form of verb, interfaces -> interface
We use the infinitive, or basic form, in configure context, as do most
other network vendors, so let's do the same in admin exec context.

Also, drop the 'name' qualifier, it is not needed in configure context
so we shouldn't have to use it in admin exec either.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-12 23:59:54 +01:00
Joachim Wiberg 4b45fffc5f cli: add missing ipv6 commands available already for ipv4
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-12 23:59:53 +01:00
Joachim Wiberg fc0567e0ca cli: consolidate 'show [ip|ipv6] route' commands
In an effort to consolidate and use familiar command paths for our most
common commands, let's follow suite with Cisco, vtysh, et al.

Add deprecation warning to legacy 'show route [ip|ipv6]' command.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-12 23:59:53 +01:00
Joachim Wiberg 77de4d749a confd: add support for configuring ospf interface priority
Since we just un-deviated this node to be able to create operational
data for ospf interfaces, we should also allow users to set it.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-12 22:28:19 +01:00
Joachim Wiberg f79c0ee903 statd: extend ospf operational data to replace vtysh commands in cli
Collect more data from FRR to the OSPF and BFD operational datastore.
Refactor CLI commands to use the YANG datastore instead of vtysh.

Additionally, the BFD command(s) have been moved to the top level of
admin-exec, which is where vtysh has them.

Finally, preparing for future OSPFv3 support, all commands have been
given a new context under 'show ip ospf'.  Deprecation warnings have
been added to the existing 'show ospf' commands.

Also, for consistency, all commands names in plural have been changed to
their singular form: routes -> route, interfaes -> interface, etc.  This
is what vtysh, Cisco, and others do as well.

Fixes #1190

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-12 22:28:18 +01:00
Joachim Wiberg b1f83e5ce7 confd: add must expression to verify ospf backbone is not nssa/stub
Silently drop any area-type setting for ospf backbone in a migrate
script to prevent any field issues after upgrading to this fix.

Fixes #1247

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-12 22:28:18 +01:00
Joachim Wiberg a76b1adc1e confd: enable IFF_MULTICAST on GRE tunnel interfaces
Required for protocol daemons like ospfd to join multicast groups.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-07 14:46:54 +01:00
Joachim Wiberg 777650bbca confd: add tunnel ttl, tos, and pmtu-discovery settings
Adds support for configuring TTL, ToS/DSCP, and Path MTU Discovery
on GRE and VXLAN tunnels. TTL defaults to 64 instead of inherit to
prevent issues with routing protocols like OSPF that use TTL=1.

Refactors tunnel YANG models by merging local-remote into a unified
tunnel-common grouping for cleaner organization.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-07 14:46:54 +01:00
Joachim WibergandGitHub 764bd8ef66 Merge pull request #1223 from kernelkit/migrate-dhcp-client
Relocate /dhcp-client to /interfaces/interface/ipv4/dhcp
2025-11-06 20:03:12 +01:00
Joachim Wiberg 80e8ccf273 confd: fix inference from CLI, follow-up to ed235583
The callback refactoring forgot to call ietf_interfaces_cand_init(),
breaking inference of interface types and DHCP client options.

Also fixes UPDATE event handling for ietf-keystore and infix-meta.

Fixes #1244

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-06 17:42:39 +01:00
Joachim Wiberg 15a6f69e03 confd: drop 'enabled' node from IPv4 autoconf container
Neither the IPv6 autonconf container, nor the recently moved DHCP client
container have an 'enabled' flag.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-06 16:36:57 +01:00
Joachim Wiberg 7f555fd2bd confd: relocate /dhcp-client to /interfaces/interface/ipv4/dhcp
Please note, this change drops not only the global enabled flag, but also the
per-interface enabled flag, converting it to a presence container.  The name
of the container is also shortened from dhcp-client -> dhcp.  A pattern that
expected to be reused also for the DHCPv6 client.

Fixes #1109

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-06 16:36:56 +01:00
Tobias WaldekranzandGitHub 20673c3a84 Merge pull request #1236 from kernelkit/recopy
bin: copy: Fix various resource leaks introduced by refactor
2025-11-06 09:26:00 +01:00
Joachim Wiberg 5496258e54 confd: minor, silence libyang warning when built w/o containers
Silence confd[3582]: libyang[0]: Invalid argument ctx_node (lyd_find_xpath())
warning in syslog.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-06 09:08:22 +01:00
Tobias Waldekranz f83fbc6105 bin: copy: Fix various resource leaks introduced by refactor
Thanks coverity! <3

Fixes: d26e311c6d ("bin: copy: Refactor")
2025-11-06 08:03:49 +01:00
Joachim Wiberg f08947092b confd: fix update of /cfg/startup-config.cfg
Follow-up to ed23558

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-05 20:41:59 +01:00
Joachim Wiberg 33999ceebc confd: fix annoying warning in log
This fixes the annoying libyang warning after commit da29771.

    confd[3375]: libyang[0]: Invalid argument ctx_node (lyd_find_xpath()).

This happens when the diff is used in the wrong event when it is NULL.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-11-05 20:41:58 +01:00