Commit Graph
449 Commits
Author SHA1 Message Date
Joachim Wiberg 256c462c0c confd: add support for read-only containers
This creates a container without a writable layer.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg d8dde9cde2 confd: add support for custom container ENTRYPOINT
This was a tough nut to crack.  Turns out the trick to changing the
ENTRYPOINT is to set --entrypoint=command and then call 'podman create
... command args'.  Not entirely obvious since the documented approach
is to use a JSON array as the argument: podman create
--entrypoint='["command", "args" ]'.

Admittedly, encoding this in C to transfer it via a POSIX shell script
to the command line, is not the easiest task I've undertaken.  So I gave
up and found this workaround.

Worth noting, however, is that one *must* set `--entrypoint`, it is not
enough to just append the command to the 'podman create' command line.
Due to differences in docker and podman, we cannot supply the full args
to an alternate entrypoint command.  But for the command to actually run
we need to override the image's ENTRYPOINT and send the command and args
as the last arguments on the command line to podman create.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg f1bf02eda5 confd: refactor how container networks are sent to container helper
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg aa7ea66a0d confd: add support for setting container hostname
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 7a57d4f0fa confd: add support for container environment variables
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 3d85eba3fc confd: add support for publishing container ports
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg ffd2128614 confd: add support for container restart and restart policy
Also, ensure the deleted container is actually deleted before recreating
it with a new configuration.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 2b19b61068 confd: add support for manual start of containers
This commit adds 'manual:yes' to the container's Finit service
configuration and changes from pod: to container: prefix for a
unique namespace to prevent collision with regular services.

The prefix container: is more correct that pod:, which should
be reserved for any future pod support.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>

confd: fix missing variable in container script condition

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 9e801dfa2f confd: initial support for Docker containers using podman
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 58ebae5624 yanger: pep-8 style fixes and cleanup
- reserved words: map -> xlate
 - add missing docstrings
 - convert to recommended constructs: proto in (foo, bar)
 - drop unused 'f' format strings: f""
 - too short exception vars: e -> err, d -> entry
 - drop unnecessary () in if expressions
 - add whitespace for readability and navigation

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg b3e418c6a7 board/common: let qemu.sh take kernel/init args on command line
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg f0f0e737a9 board/common: BusyBox ash != bash, set bash as root default shell
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 84f83d635b board/common: fix #294: drop 'v' from version in filenames
The files inside a release tarball, as well as the tarball name itself,
should not have the leading 'v', that's just for the tag.

Also, add -ver to GNS3 disk.img file as well.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 51dc940059 package/klish-plugin-sysrepo: new commands 'change' + 'text-editor'
This bump adds support for 'set foo' to set foo=true, but also two new
commands from srp_helper@: 'change password', 'text-editor content'.

 - ietf-system: 'change password' now starts an interactive session that
   results in a random-salted sha512 encrypted hash.
 - 'text-editor <node-of-binary-type>', starts 'editor file | base64'
 - 'set <node-of-bool-type>', sets node=true

A prototype askpass script has been added as a proof-of-concept.  It
follows the design of other askpass style programs, like ssh-askpass,
that pass the resulting password on stdout.  With the additional support
for also writing it to an output file, e.g., a pipe.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Mattias Walström acc39b1b15 yanger: usb: Refactor to only check authorized_default if locked/unlocked
authorized is unreliable on boot.
2024-02-23 14:01:23 +01:00
Mattias Walström ddd0fc5a35 yanger: vpd: set class to vpd for all vpd nodes
class is mandatory in the standard.
2024-02-23 14:01:23 +01:00
Mattias Walström b66b56f504 probe: rename usb-ports-names => usb-port-names 2024-02-23 14:01:23 +01:00
Mattias Walström caea3132c9 probe: Change to return the sysfs path for authorized and authorized_default
Leave it to confd to check if the file exist.
2024-02-23 14:01:23 +01:00
Mattias Walström 746392cac5 x86_64: Update linux_defconfig with USB as module
This to be able to control USB ports in infix using authorized in /sys
2024-02-23 14:01:23 +01:00
Mattias Walström 420e0d5b36 qeumu: Add USB ports 2024-02-23 14:01:23 +01:00
Mattias Walström 69eae34203 probe: Add support for virtual USB ports (qemu) 2024-02-23 14:01:23 +01:00
Mattias Walström c0a071e87a Add 'show hardware' only show USB port status for now 2024-02-23 14:01:23 +01:00
Mattias Walström 2011f5cbf2 modprobe.d: Unauthorize all USB ports on boot 2024-02-23 14:01:23 +01:00
Mattias Walström b0f2388153 probe: Add support for multiple /sys nodes for a of-node 2024-02-23 14:01:23 +01:00
Mattias Walström 6f41ea5ccb probe: Read information about external ports (usb)
from Device tree and put it into system.json
2024-02-23 14:01:23 +01:00
Mattias Walström c58bd5ead4 aarch64: Configure USB_CORE as a module
This to be able to control the USB ports in infix using authorized in /sys
2024-02-23 14:01:23 +01:00
Mattias Walström bd9acd003d Alder: DTS: Add information about external ports (USB) 2024-02-23 14:01:23 +01:00
Richard AlpeandTobias Waldekranz 0cb1459f43 cli-pretty: only print stp state if oper status is up
Only print bridge port stp state if operational status of the
interface is up.

Signed-off-by: Richard Alpe <richard@bit42.se>
2024-02-20 21:43:48 +01:00
Richard AlpeandTobias Waldekranz 1807306178 cli-pretty: print vlan filtering bridge
Handle printing a vlan filtering bridge in "show interfaces".

Example output:
br0             bridge     DOWN        vlan:10u,20t
│               ipv4                   192.168.1.1/24 (static)
├ e0            bridge     DISABLED    vlan:10u,20t pvid:10
└ e1            bridge     DISABLED    vlan:10t,20u pvid:20
br1             bridge
└ e2            bridge     FORWARDING  vlan:30u pvid:30
e3              ethernet   UP          02:00:00:00:00:03
                ipv6                   fe80::ff:fe00:3/64 (link-layer)
e4              ethernet   UP          02:00:00:00:00:04
                ipv6                   fe80::ff:fe00:4/64 (link-layer)
lo              ethernet   UP          00:00:00:00:00:00
                ipv4                   127.0.0.1/8 (static)
                ipv6                   ::1/128 (static)

Signed-off-by: Richard Alpe <richard@bit42.se>
2024-02-20 21:43:48 +01:00
Richard AlpeandTobias Waldekranz 475a3a2919 yanger: add bridge vlan, pvid and stp-state
This patch adds information about a vlan filtering bridge to the
operational datastore.

The information included is vlans, pvid and stp-state. These changes
reflects what can be configured though confd.

NOTE: pvid is still missing for bridge interfaces. Discussions on how
to best add this is ongoing. It's currently not configurable due to an
existing self check in the infix-if-bridge yang model.

Signed-off-by: Richard Alpe <richard@bit42.se>
2024-02-20 21:43:48 +01:00
Richard AlpeandJoachim Wiberg debcf81a7a yanger: only fill eth info for Ethernet interfaces
Signed-off-by: Richard Alpe <richard@bit42.se>
2024-02-05 18:01:30 +01:00
Richard AlpeandJoachim Wiberg ee50a7c061 yanger: identify new interface type "etherlike"
Signed-off-by: Richard Alpe <richard@bit42.se>
2024-02-05 18:01:30 +01:00
Joachim WibergandTobias Waldekranz fbe6accdf3 Clarify what happens without /plen
Co-authored-by: Tobias Waldekranz <tobias@waldekranz.com>
2024-01-30 15:32:38 +01:00
Joachim WibergandTobias Waldekranz 228891935d dhcp-client: allow setting hostname, and update /etc/hosts
This should be the last outstanding issue to fix #278.  Please note,
it is undefined what happens if you have two DHCP clients that request
hostname, and changing hostname from NETCONF at runtime will overwrite
any hostname set by the DHCP client.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-30 15:32:38 +01:00
Joachim WibergandTobias Waldekranz faa6ce849b dhcp-client: don't assume we got option 1 (subnet)
If we don't get subnet, then just set the IP address.

Issue #278

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-30 15:32:38 +01:00
Henrik NordstromandJoachim Wiberg 4c5d5fb045 board/aarch64: alder: Remove Micro-SD support
There is no Micro-SD slot on the alder board. Not even an
optional one.
2024-01-29 18:05:07 +01:00
Mattias WalströmandTobias Waldekranz 0aeae9d8e8 dts: Add factory reset button as keybord (button)
Also add a tool useful to test the reset button.
2024-01-27 23:53:54 +01:00
Mattias Walström 0033a92c80 qemu.sh: Fix bug when emulate VPD
Wrong date format for manufacture-date
2024-01-23 15:30:40 +01:00
Mattias Walström 22269b6057 Yanger: Implement ietf-hardware
Wrap all VPD data and show them as components in ietf-hardware.
2024-01-23 15:30:40 +01:00
Joachim WibergandTobias Waldekranz 236f3ec183 board/aarch64/r2s: patch device tree for factory-password-hash
Since the Nanopi R2S does not have a VPD, we use this mechanism to set
the default admin password.  Without one, Infix will refuse to generate
the factory- and failure-config files, and thus refuse to start.

On custom boards in production we have VPD in ONIE format that contains
a per-device unique SHA256 hashed admin user password.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-22 11:20:01 +01:00
Joachim WibergandTobias Waldekranz 10ec9089bc Initial support for Nanopi R2S from FriendlyELEC
Support for this is based on the upstream Buildroot R2S defconfig and
the myLinux extensions and stripped-down kernel defconfig.  For more
information about the Nanopi R2S, see the FriendlyELC wiki at:

    https://wiki.friendlyelec.com/wiki/index.php/NanoPi_R2S

Please note, due to the lack of a VPD on the board, and some very poor
devicetree skills by yours truly, Infix currently refuse to boot on this
board.  An in-devicetree factory-password-hash node has to be added, and
will be done soon.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-22 11:20:01 +01:00
Joachim WibergandTobias Waldekranz 000811fced board/common: skip if not SIGN_ENABLED
All Infix builds should be signed, but for some test equipment, and
during board bringup, this may be too much of a hassle.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-22 11:20:01 +01:00
Tobias WaldekranzandMattias Walström 7081934473 Promote all members of wheel to sudoers
Install the sudo command, and let all members of the "wheel" group run
any command as the superuser.

This ensures that administrators have full access to the system,
primarily for troubleshooting, diagnostics, and remote scripting
purposes.
2024-01-18 10:28:32 +01:00
Tobias WaldekranzandJoachim Wiberg f3678ac93f Provide a hint of how to access the CLI when other shells are used
For users with a shell other than clish, such as bash, print out a
hint of how to enter clish, when logging in.
2024-01-18 00:02:55 +01:00
Tobias WaldekranzandJoachim Wiberg 6ef80d5847 Add a default message of the day (/etc/motd)
This is injected to the factory-config during bootstrap, and can then
be changed as usual via /system/motd.
2024-01-18 00:02:55 +01:00
Mattias WalströmandJoachim Wiberg 43fbe4e8b1 OSPF: Add operational support to se router state per interface 2024-01-15 16:29:06 +01:00
Mattias WalströmandJoachim Wiberg aa68cd73c7 OSPF: Fix nasty bug when router-ids was converted to host routes
Caused collision with the key (prefix) in the list
2024-01-15 16:29:06 +01:00
Mattias WalströmandJoachim Wiberg 9788046c64 OSPF: Add area-type to operational 2024-01-15 16:29:06 +01:00
Mattias WalströmandJoachim Wiberg 4801c1f060 OSPF: Fix bug with ospf-status script did not work with NSSA or Stub areas
For some reason FRR put [NSSA] and [Stub] in the key with the area id
2024-01-15 16:29:06 +01:00
Mattias WalströmandJoachim Wiberg 388c02b29a test: Create a larger OSPF test
This will test, multiple areas with cost and BFD (requires link
breakers in infamy, not yet implemented there yet)

Also test NSSA-areas.
2024-01-15 16:29:06 +01:00