Commit Graph
20 Commits
Author SHA1 Message Date
Mattias WalströmandJoachim Wiberg 4e7bdc58d4 Add OSPFv2 support
A very limited part of the YANG model is implemented so far, basicly it is OSPFv2 with multiple areas and you can change timers
for the interfaces. Limited operational support.

admin@infix-00-00-00:/config/> edit routing control-plane-protocol ietf-ospf:ospfv2 name default
admin@infix-00-00-00:/config/routing/control-plane-protocol/ietf-ospf:ospfv2/name/default/> set ospf area 0.0.0.0 interface e0 enabled true
admin@infix-00-00-00:/config/routing/control-plane-protocol/ietf-ospf:ospfv2/name/default/> leave
2023-12-18 17:28:00 +01:00
Tobias Waldekranz 445fbf7873 confd: Notify user of all bootstrapping issues via login banners
Collect all bootstrapping issues in all banner-like files during boot,
so that they are presented to the user when logging in. This should
make it harder to miss overlook the fact that a system is running in a
degraded state.
2023-11-30 11:39:42 +01:00
Joachim Wiberg 9b1739283d confd: missing admin password, set error in /etc/issue & /etc/banner
The bootstrap script gets feedback from gen-admin-auth, on error we no
longer bail out but instead log the error and continue booting.  This
way a developer build with root login can diagnose the error.

When logging the error we also set /etc/issue, /etc/issue.net for local
and remote login services, as well as the dedicated /etc/banner used by
OpenSSH, to hold the error summary.  So when attaching to the console
port, or attempting to log in remotely with SSH, the error is printed
to indicate the device is not healthy.

Finally, since factory-config may be missing we need to bootstrap the
sysrepo db with something else, and fortunately we will always have a
failure-config to fall back on.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg 8141cc13d1 confd: minor shellcheck fixes
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg ff12ba72b5 confd: exctract password also for failure-config
This patch adds generation of the 20-authentication.json snippet also
for failure-config.  The gen-admin-auth script is extended with shell
parameter, since the default shell differs from factory-config.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Richard AlpeandJoachim Wiberg 63a34d570d Use default pwd hash from VPD in QEMU
This commit does several things. Its end goal is to fetch the admin
password hash from VPD memory during factory bootstrap.

To accomplish this probe creates a new file /run/system.json with
information read from a fw_cfg QEMU partition. The data from
/run/system.json is then later used during config bootstrap to fill in
the factory administrator password.

The idea is to make QEMU behave the same way hardware does, i.e. a
default/factory password should be fetched and used from
"hardware memory". The hardware portion of this is yet to be done.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-24 08:55:57 +01:00
Mattias Walström a0a80c8b77 Rename infix-routing to correct date
Should be 2023 not 2013.
2023-11-23 10:30:26 +01:00
Jon-Olov VatnandJoachim Wiberg 6cfcf3ca10 Fixing and activating ieee802-ethernet yang deviations 2023-11-22 13:44:28 +01:00
Mattias WalströmandJoachim Wiberg a4cb66b642 infix-routing needs to be imported before infix-interfaces
Due to that infix-routing has a deviated node that depends on
a deviated node in infix-interfaces.
2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg 0b1bd9e8a0 Implement IPv4 static routing in ietf-routing
Only config no operational state yet.

routing
  routing/control-plane-protocols
     control-plane-protocol static name default
        static-routes
          ipv4 route 192.168.200.0/24 next-hop special-next-hop blackhole
2023-11-17 07:19:28 +01:00
Joachim WibergandTobias Waldekranz 87378b4fe3 confd: fix and simplify .json snippet collation to factory-config
First, fix collation of .json snippets to ensure they are sorted by
number, regardless of which directory they originate from.

Second, and with an unexpected twist, use /etc as the target directory
for factory-config.cfg and failure-config.cfg.  At first just to avoid
having the resulting .gen and .cfg files in /run/confd/, but it also
unintentionally gives us a way to provide a static /etc/factory-confg
in the image.  As the TODO says, not perfect but better than before.

Third, update load script to use the same base path as bootstrap by
sourcing the system /etc/confdrc.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-01 21:50:47 +01:00
Joachim WibergandTobias Waldekranz 7fd7a2e430 confd: regenerate failure-config and factory-config on each boot
Operational experience shows that the current Infix Fail Secure mode,
introduced in ca9daef, does not work in practice.

The factory datastore in sysrepo is created at boot with the YANG models
and the factory-config file.  When the factory-config file is generated
from older versions of these models, the resulting datastore may fail to
pass the validation and system will end up in an unrecoverable state.

Instead, both the factory-config and failure-config must be created at
every boot to match the YANG models in the active Linux image.  This
ensures loading the YANG models will always work and the system can
proceed to attempt to load startup-config to the running datastore.

If loading startup-config fails we can fall back to failure-config,
which like factory-config, will then provide a way to log in an dianose
the system.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-30 12:48:14 +01:00
Mattias WalströmandJoachim Wiberg 941fc31581 infix-vlan: Create a custom vlan model
This implements the new model infix-if-vlan.
The new CLI is:

root@infix-00-00-00:/config/interfaces/interface/vlan10/> set vlan id 10 lower-layer-if eth0

with an possible extra option for tag-type, default tag-type is c-vlan.
2023-10-27 10:53:55 +02:00
Mattias WalströmandJoachim Wiberg d66740250c confd: Add support for timezone-utc-offset
Some deviations has been done the yang model to comply with tzdata
on linux.

This fixes #106
2023-10-20 12:55:02 +02:00
Richard AlpeandJoachim Wiberg 14dc3cf8a0 statd: add ethtool frame counters to op datastore
This patch adds the framework for reading ethtool statistics and
inserting it into the operational datastore.

The ethtool data we rely on is "group data" such as "eth-mac" or
"rmon".

This data can be displayed using:
ethtool --json -S e0 --all-groups

The "group data" is still missing for most common drivers, so testing
this will require a firmware which has support for it.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-17 18:17:54 +02:00
Joachim Wiberg 52023e918a confd: regenerate factory-config if factory-config.gen is missing
Regenerate if either factory-config.gen or failure-config.gen is missing.
This should not happen, but is better to check for the result rather than
the intermediate result.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-17 16:32:41 +02:00
Joachim Wiberg c6fae88268 Fix #166: drop SSDP entirely from Infix
mDNS-SD was added in Windows 10 Creators Update[1] (build 1703), relased
April 11, 2017.  This makes SSDP no longer critical for finding an Infix
device in Windows, both ping infix-01-02-03.local and using Chrome work.

Since all major operating systems now support mDNS-SD[2] we've decided
to standardize on that and LLDP for Infix and its derivatives.  Other
reasons for dropping it include, but is not limited to: lack of IPv6 in
the implementation we use, and potential security implications[3].

[1]: https://en.wikipedia.org/wiki/Windows_10,_version_1703
[2]: https://techcommunity.microsoft.com/t5/networking-blog/mdns-in-the-enterprise/ba-p/3275777
[3]: https://blog.cloudflare.com/ssdp-100gbps/

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-17 16:32:41 +02:00
Joachim Wiberg 3a3274c371 confd: ensure "word splitting" otherwise gen-interfaces fails
Overzealous shellcheck application lead to gen-intefaces not creating a
bridge when GEN_IFACE_OPTS was uncommented in /etc/confdrc

Verified in customer br2-external.

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 14:56:00 +02:00
Joachim WibergandTobias Waldekranz ca9daef15a confd: add support for generating /cfg/failure-config.cfg
This rather huge change is a refactor of the factory-config generataion to add
support for also generating a failure-config.

The confd bootstrap script has been given an rc file.  This both eases manual
testing, when modifying the script(s), and also makes it easier to override
from a br2-external.  Infix default is router/end-device, but a br2-external
may be a switch firmware and want to default to all ports in a bridge.

The generated failure-config creates a fail-safe "do no harm" config to boot
with in case startup-config for some reason is broken or cannot be applied,
e.g., bug in confd.  Meaning, for both the router and switch use-cases the
device will start up with all interfaces isolated¹, with an IPv6 SLAAC (EUI64)
address per interface.

Services enabled in this fail-safe mode are: LLDP, mDNS/SD, SSH, and NETCONF.
All to facilitate diagnostics, troubleshooting and device recovery.

Other noteworthy changes include:

 - rename factory/failure directories again -> factory.d/failure.d.  Use
   same naming as we do on target for directories holding generated files
 - The bootstrap script no longer regenerates /cfg/factory.d on each boot
 - The bootstrap script copies all static templates to /cfg/factory.d in
   case a newer image changes the contents of them.  For troubleshooting
 - Support for overriding the 20-interfaces.json generation by br2-external
 - Support for additional 30-config.json (ovrride/extend) by br2-external
 - Expand gen-interfaces to support bridge use-case.
_____
¹ For a switch this means "no switchport", i.e., no switching between ports
  otherwise connected to a switchcore (or bridge) in startup-config.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-09 10:41:46 +02:00
Joachim WibergandTobias Waldekranz 3e48af6c36 confd: relocate auto-factory templates and prepare fail secure mode
The template and scripts for generating per-device factory-config have
been spread out across the repo.  This is an attempt to gather all the
pieces to a single location for better overview.

Parts of factory-config will be reused for the new fail secure mode, in
the file failure-config.  The beginnings of which are in this commit.

Other changes:
 - cfg-bootstrap and confd-bootstrap have been collapsed into one
 - let gen-hostname + gen-interfaces save to /cfg instead of /etc,
   we've moved the /etc directory to read-only storage in /usr/share
 - delay start of bootstrap and sysrepo-plugind after syslogd barrier
 - set 'norestart' when loading startup-confg and failure-config,
   no point in retrying if that fails, just go to error immediately

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-09 10:41:46 +02:00