Commit Graph
415 Commits
Author SHA1 Message Date
Joachim Wiberg ac63461bd8 confd: fix copy-paste error in dns-resolver
Found by Coverity Scan, CID 331048

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 123808d6bb confd: check return value of mktime()
Found by Coverity Scan, CID 331032

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg b2331dc8ce confd: minor, coding style
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 31bd1286a3 confd: minor, whitespace
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg da6b5a1950 confd: mark unchecked remove()/rename() as intentional
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 1b825d4ac6 confd: fix memory leak in handle_sr_shell_update()
Found by Coverity Scan, CID 331029

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 90af510092 confd: fix memory leak in handle_sr_passwd_update()
Found by Coverity Scan, CID 331033

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg c3045ecebb confd: fix obvious mistakes in checking return values
Found by Coverty Scan

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg f56baeb4fa confd: drop malplaced sr_free_values()
We haven't even called sr_get_items() yet.  Must've been a remnant
of an earlier refactor.

Fixes CID 331051

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 2191202f2a statd: null terminate recv() buffer from netlink
Fixes CID 331053

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 2caf729ee8 github: enable building local src in host mode for analysis
Install libyang and sysrepo from source, too old packages in ubuntu-latest.

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 18:04:18 +01:00
Joachim Wiberg 005eb58958 src: add support for host build check, for Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 12:59:39 +01:00
Joachim Wiberg ff69fcfa69 libsrx: make autogen.sh executable
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 10:40:18 +01:00
Joachim Wiberg 41a14d3ca6 statd: refactor Makefile for host build
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 10:40:18 +01:00
Joachim Wiberg c529f06cf0 statd: fix gcc warning, "format not a string literal"
error: format not a string literal and no format arguments [-Werror=format-security]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 10:40:17 +01:00
Joachim Wiberg 04046437d7 confd: fix gcc warnings, "format not a string literal"
error: format not a string literal and no format arguments [-Werror=format-security]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 10:40:17 +01:00
Joachim Wiberg f7d1a72511 confd: tell automake about generated files for cleaning
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 10:40:17 +01:00
Joachim Wiberg 5031ff6224 net: drop unused 'net' package, replaced by dagger
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 09:49:32 +01:00
Mattias WalströmandJoachim Wiberg 10b4b761c5 Routing: Limit to one instance per routing protocol 2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg a4cb66b642 infix-routing needs to be imported before infix-interfaces
Due to that infix-routing has a deviated node that depends on
a deviated node in infix-interfaces.
2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg 0b1bd9e8a0 Implement IPv4 static routing in ietf-routing
Only config no operational state yet.

routing
  routing/control-plane-protocols
     control-plane-protocol static name default
        static-routes
          ipv4 route 192.168.200.0/24 next-hop special-next-hop blackhole
2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg 03dbb409eb static-routing: Add model for ipv4/ipv6 routing 2023-11-17 07:19:28 +01:00
Joachim Wiberg e7c6f255fd .clang-format: drop green goblin alignment
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-16 10:35:43 +01:00
Joachim Wiberg e26208afeb confd: reindent with new .clang-format (example)
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-16 10:35:43 +01:00
Joachim Wiberg 36175f599e Some use-package help for Emacs users
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-16 10:35:43 +01:00
Joachim Wiberg 715d17f475 statd: minor, cleanup, license headers
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-16 10:35:43 +01:00
Joachim Wiberg 485e4256a3 confd: minor, whitespace
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-16 10:35:43 +01:00
Joachim Wiberg 8af048462d src: proposed coding style for C, Linux++
The intention of this is to serve as a help/guidance for both devs and
reviewers of pull requests.

Baseline is taken from Linux v6.5.6, with some (possibly) controversial
additions (at the end of the file):

 - Do not enforce max line length
 - Alignment of variables, both when assigning and declaring
 - Use spaces to adjust when leading tabs are not enough (as Emacs)

I've also added a couple of exceptions for macros like TAILQ_FOREACH()
which are used as control statments (if, while, for), so the opening
brace should be on the same line -- otherwise clang-format thinkts we
are creating a recursive function ...

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-16 10:35:43 +01:00
Richard AlpeandRichard Alpe 090a852644 statd: rewrite "backend" in python3
There should be no functional change in this patch.

In this patch we rewrite the data collection in python3. This is the
new script called "yanger". It runs various commands on the system,
such as "ip" and "ethtool". It then mangles the output data from these
commands into valid YANG data.

The yanger script is started from the sysrepo callback in the statd c
code. Its output is parsed using lyd_parse_data_fd().

This means that the daemon part of statd is still written in c and the
new python code is only used when getting a query callback from
sysrepo. The c code still handles the interface netlink messages from
the kernel which controls what interfaces statd should do sysrepo
subscribe/unsubscribe to.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-15 14:35:17 +01:00
Richard AlpeandRichard Alpe 9f4e12f8f5 libsrx: expose fsystemv()
Expose fsystemv() in header and remove static. This function can be
useful for others that needs to be in control of any output stream.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-15 14:35:17 +01:00
Joachim WibergandMattias Walström 54ae8aaf8b src/klish-plugin-infix: change shell from /bin/sh to /bin/bash
Most defconfigs have Bash enabled, those that do not will have the
BusyBox symlink to ash.

This fixes the completion isses we've seen with initctl.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-13 10:28:47 +01:00
Joachim WibergandMattias Walström ab799c0622 src/klish-plugin-infix: minor, add missing keyword in help text
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-13 10:28:47 +01:00
Joachim WibergandTobias Waldekranz 32c2319311 Fix #198: no defult PVID for a VLAN filtering bridge
- drop bridge pvid setting in YANG model, we require bridge ports to
   have explicit VLAN assignment (security)
 - refactor bridge_vlan_settings(), do not enable vlan_filtering if
   there are no VLANs configured on the bridge

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-08 16:03:28 +01:00
Joachim Wiberg abb3952fb7 klish-plugin-infix: sync interactive command changes with upstream
Upstream has replaced interactive="true" with:

 - in="tty"
 - out="tty"
 - interrupt="true"

Also, disable Oneliners option since it's too confusing for users
compared to the regular JSON output for startup and factory-config

We can [skip ci] since we do not have any CLI tests yet.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-08 11:17:41 +01:00
Joachim Wiberg 829b4061f6 confd: drop developer debug message
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-07 23:36:51 +01:00
Joachim Wiberg 1f618a5193 Fix #111: upgrade Klish & C:o to fix inference callbacks
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-07 23:36:51 +01:00
Joachim Wiberg 500ae3f8dd Fix #125: improve feedback on invalid configure input
This is an attempt at improving the error reporting from klish-plugin-infix,
or more specifically commit@infix.  Previously none of the sysrepo errors were
shown, now all the latest errors, as well as a few new ones specific to
interfaces have been added.

Example (eth0 does not exist):

    admin@infix-00-00-00:/config/> edit interfaces interface eth0
    admin@infix-00-00-00:/config/interfaces/interface/eth0/> leave
    Error: Mandatory node "type" instance does not exist. (Data location "/ietf-interfaces:interfaces/interface[name='eth0']".)
    Failed committing candidate to running: Validation failed
    admin@infix-00-00-00:/config/interfaces/interface/eth0/> set type ethernet
    admin@infix-00-00-00:/config/interfaces/interface/eth0/> leave
    Error: Cannot create fixed Ethernet interface eth0, wrong type or name.
           Please check your changes, try 'diff' and 'do show interfaces'.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-07 23:36:51 +01:00
Richard AlpeandJoachim Wiberg ff7b8ec9bf cli: speedup detailed interface view
This affects CLI command such as:
> show interface name p1

Prior to this patch, this took roughly ~1200ms on hardware and with
the path it takes roughly 50ms.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-06 20:12:16 +01:00
Richard AlpeandJoachim Wiberg 13092757a1 statd: add auto-negotiation status to op datastore
Add a python3 script "ethtool-to-json" which runs ethtool locally and
converts output which we are interested in into json. The script
simply json encodes the output from ethtool, i.e. it does not print it
in YANG format. This might be a good idea to change in the future if
the C code has to do a lot of ethtool to YANG translations.

The json output of the ethtool-to-json script is then parsed in C
using libjansson, translated to YANG and added to the operational
datastore.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-06 11:28:53 +01:00
Joachim WibergandTobias Waldekranz d0f3960d71 confd: add -6 option to gen-interfaces for SLACC on port interfaces
This change updates the documentation for the script, hopefully it is
more readable now than the previous wall of text.

Also, a new -6 option to toggle IPv6 SLACC option for port interfaces.
This, in combination with omitting the -b option, allows for enabling
SLACC on interfaces that would otherwise not get an address.

No functional change, tested manually [skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-03 12:55:44 +01:00
Joachim Wiberg a591eeebce confd: fix description whitespace in native model
No logical change, keeping modification date and revision.  We may be
stricted in the future with this.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-03 08:16:04 +01:00
Joachim WibergandTobias Waldekranz 202b08d34d confd: allow overriding confdrc settings in a confdrc.local
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-01 21:50:47 +01:00
Joachim WibergandTobias Waldekranz d05de543e4 klish: update system path to factory-config
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-01 21:50:47 +01:00
Joachim WibergandTobias Waldekranz 87378b4fe3 confd: fix and simplify .json snippet collation to factory-config
First, fix collation of .json snippets to ensure they are sorted by
number, regardless of which directory they originate from.

Second, and with an unexpected twist, use /etc as the target directory
for factory-config.cfg and failure-config.cfg.  At first just to avoid
having the resulting .gen and .cfg files in /run/confd/, but it also
unintentionally gives us a way to provide a static /etc/factory-confg
in the image.  As the TODO says, not perfect but better than before.

Third, update load script to use the same base path as bootstrap by
sourcing the system /etc/confdrc.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-01 21:50:47 +01:00
Richard AlpeandJoachim Wiberg 3bd104a46c cli: use pwgen secure and increase password length
Adhere to our recommendations and avoid pseudorandom passwords which
are "easy to remember". Also increase password length to 13 chars.

Side notes:
Knowing that a password contains at least one char, one number and so
on, lowers the number of possible passwords to test when brute forcing.

The entropy for the pwgen "easy to remember" passwords isn't good
(naturally).

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-31 13:16:37 +01:00
Richard AlpeandJoachim Wiberg 12462d5b17 statd: add more ethtool counters to op datastore
Add counters from Ethtool groups to the operational datastore. The
mapping from Linux / Ethtool to YANG is described in the included
document eth-counters.md.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-31 10:01:55 +01:00
Mattias Walström 90d94fe255 Remove ietf-if-vlan-encapsulation, it is replaced by infix-if-vlan
This is a followup for 941fc3158
2023-10-31 09:16:58 +01:00
Joachim WibergandTobias Waldekranz fc5310b3fd confd: adjust path to failure-config
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-30 12:48:14 +01:00
Joachim WibergandTobias Waldekranz 120e87ac99 confd: sort interfaces according to length and name
A list of interfaces: x10 x9 x8 x7 x6 x5 x4 x1 x2 x3 should be sorted in
order with x10 last.  Using the common 'sort -n' would generate: x1 x10
x2 ... so we use version sort.  This way we can ensure that the order of
bridge ports is natural and what end users expect.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-30 12:48:14 +01:00
Joachim WibergandTobias Waldekranz 7fd7a2e430 confd: regenerate failure-config and factory-config on each boot
Operational experience shows that the current Infix Fail Secure mode,
introduced in ca9daef, does not work in practice.

The factory datastore in sysrepo is created at boot with the YANG models
and the factory-config file.  When the factory-config file is generated
from older versions of these models, the resulting datastore may fail to
pass the validation and system will end up in an unrecoverable state.

Instead, both the factory-config and failure-config must be created at
every boot to match the YANG models in the active Linux image.  This
ensures loading the YANG models will always work and the system can
proceed to attempt to load startup-config to the running datastore.

If loading startup-config fails we can fall back to failure-config,
which like factory-config, will then provide a way to log in an dianose
the system.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-30 12:48:14 +01:00