Commit Graph
3734 Commits
Author SHA1 Message Date
Tobias WaldekranzandGitHub 365618526d Merge pull request #1204 from kernelkit/upgrade-kernel
Upgrade Linux kernel to 6.12.54 (LTS)
2025-10-20 14:04:43 +02:00
Joachim WibergandGitHub 30104bd1b6 Merge pull request #1201 from kernelkit/badge 2025-10-20 10:51:58 +02:00
Mattias Walström f5496b3c6a Upgrade Linux kernel to 6.12.54 (LTS) 2025-10-20 10:15:11 +02:00
Tobias WaldekranzandGitHub bafad20ef2 Merge pull request #1202 from kernelkit/upgrade-kernel
Upgrade Linux kernel to 6.12.53 (LTS)
2025-10-15 20:15:18 +02:00
Mattias Walström 5a4c676782 Upgrade Linux kernel to 6.12.53 (LTS) 2025-10-15 12:55:07 +02:00
Joachim Wiberg 57dd35f419 Add releae badge and reposition bitSign
Slight refactor of page, adding another badge for the latest release,
and restructuring the Technical Details section a bit.

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-14 21:57:35 +02:00
Mattias WalströmandGitHub 8e6323d663 Merge pull request #1199 from kernelkit/upgrade-kernel
Upgrade kernel and buildroot
2025-10-14 17:13:46 +02:00
Mattias Walström 7fd3a47bf1 Upgrade Buildroot to 2025.02.7 (LTS) 2025-10-14 14:22:59 +02:00
Mattias Walström e2aef716b3 Upgrade Linux kernel to 6.12.52 (LTS) 2025-10-14 13:10:04 +02:00
Joachim WibergandGitHub 042f9f8c51 Merge pull request #1198 from kernelkit/misc
Mixed bag of fixes mostly for RPi4

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-14 09:20:44 +02:00
Joachim Wiberg acb6cdc043 doc: update changelog with latest features and fixes in v25.10
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-13 21:24:18 +02:00
Joachim Wiberg 887e34e0ef doc: fix RESTCONF scripting examples and curl.sh wrapper
The curl.sh wrapper script had several issues:
- Used 'shift 2' incorrectly without proper argument validation
- Required hostname as enviroment variable instead of option
- Lacked proper option parsing, should behave like a cross between
  curl and sysrepocfg

All examples have been updated to match the refactored script, and
a local copy in utils/curl.sh has been added.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-13 21:24:17 +02:00
Joachim Wiberg c972eebaac doc: drop TODO.org file, replaced entirely with issues and project
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-13 21:24:17 +02:00
Joachim Wiberg 151f3491a2 cli: fix error handling in text-editor and change commands
Fixes #1194

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-13 21:24:16 +02:00
Joachim Wiberg 948247254b board/bpi: minor, whitespace cleanup
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-13 21:24:16 +02:00
Joachim Wiberg c76f3ea164 board/rpi: support standalone run of mkimage.sh
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-13 21:24:15 +02:00
Joachim Wiberg 4123074272 board/rpi: match bpi rootfs partition sizes
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-13 21:24:15 +02:00
Joachim Wiberg b3ea0f3207 board/aarch64: add support for std partition labels on cmdline
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-13 21:24:15 +02:00
Joachim Wiberg 391e971573 board/common: expand var partition on sdcard
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-13 21:24:14 +02:00
Joachim Wiberg 0957fc3c11 board/common: wait for mmc probe on rpi
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-13 21:24:14 +02:00
Joachim Wiberg 81f1da6272 package/board: fix RPi4 boot from aarch64 image
Fixes a minor regression after merge of BPi-R3.  The RPi4 device tree,
specifically regulator-sd-io-1v8 in bcm2711-rpi-4-b.dts, requires the
GPIO voltage regulator be built-in for the SD card controller.

Fixes #1197

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-13 21:24:11 +02:00
Joachim Wiberg 20316daf2d confd: fix possible resource leak in firewall conf change
Coverity scan detected a memory leak in the new firewall change() cb
where allocated memory from ietf_interfaces_get_all_l3() was not freed
on error paths when srx_get_diff() failed or returned NULL.

This commit consolidates all cleanup paths to use the 'done:' label,
ensuring ifaces, diff, and cfg are properly freed in all exit scenarios.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-13 11:31:47 +02:00
Richard AlpeandGitHub 5f00184bb1 Merge pull request #1162 from kernelkit/sign-with-bitsign
Add workflow for signing releases using bitSign (https://bitsign.se)
2025-10-13 11:20:24 +02:00
Joachim WibergandGitHub f91aa0b705 Merge pull request #1114 from kernelkit/fw
Add basic zone-based firewall
2025-10-10 16:25:33 +02:00
Joachim Wiberg 5903d36861 Minor, update slogan also in alt text
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:15 +02:00
Joachim Wiberg 23ed6e2f03 test: new test, zone migration, custom service, and IPv6
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:15 +02:00
Joachim Wiberg e6d945b77c test: new test, IPv6 version of lan-wan firewall
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:14 +02:00
Joachim Wiberg c069308c27 test: new test, wan-dmz-lan firewall with snat and dnat
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:14 +02:00
Joachim Wiberg a81f7c82e9 test: new test, lan-wan gateway with snat
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:14 +02:00
Joachim Wiberg 47c4ddfb7d test: new test, basic firewall zone verification
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:13 +02:00
Joachim Wiberg 1735a97dce test/infamy: add nmap to test container
- Sort packages alphabetically
 - Add nmap for firewall tests

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:13 +02:00
Joachim Wiberg 7c87034d5e doc: add firewall documentation
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:12 +02:00
Joachim Wiberg 3224f49b65 confd: initial zone-based firewall support, based on firewalld
Add supoprt for infix-firewall.yang, modeled on the zone-based firewalld
The terminology is a mix of firewalld, classic netfilter and inspired by
Ubiquity.  E.g., zone 'policy' -> 'action', and the zone matrix overview.

 - Port forwarding allows forwarding a range of ports
 - Operational data comes from firewalld active rules
 - Firewall logging goes to /var/log/firewall.log
 - Show implicit/built-in rules and zones (HOST) in firewall matrix,
   includes "locked" policy for the default-drop behavior
 - The zone services field in admin-exec 'show firewall' shows ANY when
   the zone default action is set to 'accept'
 - Zone 'forwarding' and 'masquerade' settings live in Infix in the
   policys instead, meaning users need to explicitly add a policy
   to allow both intra-zone and inter-zone forwarding
 - Support for emergency lockdown (kill switch)
 - Pre-defined services (xml+enums) are filtered and included as a
   separate YANG model, extensions added for netconf and restconf
 - Includes initial support for firewalld rich rules

firewalld policy rules, including rich rules, have an obnoxious priority
field which is extremely hard to get right, so in Infix we use the far
superior YANG construct 'ordered-by user;'.  This ensure all rules are
generated in that order by setting the priority field, on read-back from
firewalld (operational) the priority field is used to sort the output
of rules in the CLI.

Fixes #448

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 15:14:12 +02:00
Joachim Wiberg c4ac9e44a7 confd: new helper function, get all l3 interfaces
Used by infix-firewall.c when figuring out interfaces that are not
explicitly assigned to any zone.  Placing them in the default zone

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 12:57:22 +02:00
Joachim Wiberg d1f7abcc3e libsrx: new helper, srx_set_bool()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 12:57:22 +02:00
Joachim Wiberg 4790806d8d buildroot: bump firewalld, v2.0.2 to v2.3.1
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-10 12:57:19 +02:00
Joachim WibergandGitHub af2de7708a Merge pull request #1185 from kernelkit/fix-latest
Only publish to latest release from main branch
2025-10-03 16:19:57 +02:00
Joachim Wiberg 1ef8465095 .github; only publish to latest release from main branch
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-03 16:14:02 +02:00
Joachim WibergandGitHub 9bc5f06d4c Merge pull request #1183 from kernelkit/ospf-neigh-regression-test
Verify OSPF neighbors in setup with non-OSPF interface
2025-10-03 13:04:08 +02:00
Joachim Wiberg 5f51ef065e test: verify ospf neighbors in setup with non-ospf interface
Extend OSPF basic with a regression test for issue #1169

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-03 12:55:43 +02:00
Joachim WibergandGitHub 4cfd0eb7a0 Merge pull request #1182 from kernelkit/doc2
doc: update scripting with restconf and add similar for netconf
2025-10-03 08:59:58 +02:00
Joachim Wiberg e12920bd67 doc: update scripting with restconf and add similar for netconf
Fixes #1156

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-03 08:59:16 +02:00
Joachim WibergandGitHub e91ffebfda Merge pull request #1180 from kernelkit/misc
Build, test, and release workflow fixes
2025-10-02 19:47:38 +02:00
Joachim WibergandGitHub 701dcda535 Merge pull request #1181 from kernelkit/upgrade-kernel
Upgrade Linux kernel to 6.12.50 (LTS)
2025-10-02 18:15:14 +02:00
Joachim Wiberg 1125f3b549 .github: update release checklist
Fixes #1175

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-02 17:09:44 +02:00
Joachim Wiberg 0c52bac4d7 doc: sync example output from 'show interfaces'
The 'brief' keyword has been gone for a while now.  Also, update the
ouput to match the "new" cli-pretty formatting.

Fixes #1174

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-02 17:02:44 +02:00
Joachim Wiberg fcd2e15019 .github: include link to GNS3 appliance in Release changelog snippet.
Fixes #1173

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-02 17:02:43 +02:00
Joachim Wiberg 1ba91236b7 .github: clean up stale containers and ports
Fixes the following issue, see also https://devops.stackexchange.com/a/17853/26590:

make[1]: Entering directory '/home/github-jaffa/actions-runner/_work/infix/infix/buildroot'
/home/github-jaffa/actions-runner/_work/infix/infix/test/env -r -b /home/github-jaffa/actions-runner/_work/infix/infix
/home/github-jaffa/actions-runner/_work/infix/infix/test/9pm/9pm.py -v
/home/github-jaffa/actions-runner/_work/infix/infix/test/case/all-repo.yaml
/home/github-jaffa/actions-runner/_work/infix/infix/test/case/all-unit.yaml
Error: rootlessport conflict with ID 1
make[1]: *** [/home/github-jaffa/actions-runner/_work/infix/infix/test/test.mk:58: test-unit] Error 126
make[1]: Leaving directory '/home/github-jaffa/actions-runner/_work/infix/infix/buildroot'
make: *** [Makefile:31: test-unit] Error 2

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-02 17:02:42 +02:00
Joachim Wiberg 2d7cb12afe .github: new weekly workflow to verify release workflow
Fixes #1003

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-02 17:02:41 +02:00
Joachim Wiberg ff5b5f98b4 .github: simplify a bit now that we have a check-trigger
With all jobs now depending on check-trigger we can do the evaluations
there and set some variables that can be reused later.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-10-02 17:02:40 +02:00