A container's command line, as reported by podman, may comtain environment
variables, which the current regexp (added in ed4fe58) does not support.
Extend the regexp to allow environment variables and add an operational,
config false, 'cmdline' leaf node to allow any characters to be reported
for the full command line in the operational output.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The setting 'stratumweight 0.0' disables stratum in Chrony source
selection (pure distance-based), making client_stratum_selection
non-deterministic on a LAN. Setting it to 1.0 gives srv1 a 1-second
effective advantage per stratum level, which no realistic distance
fluctuation can overcome.
Also correct the YANG descriptions in infix-system and infix-ntp which
had the semantics backwards — claiming 0.0 "ensures lower stratum is
always preferred" when in fact higher values do that.
Fixes#1361
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Add x509-public-key-format identity to crypto-types
- Add certificate node to web services container
- Use certificate from ietf-keystore as web cert
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add a must expression to ensure users do not set static neighbors when
the interface type is not point-to-multipoint or non-broadcast.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add a `hostname` leaf to the `mdns` YANG container with default `"%h"`,
allowing operators to override the avahi host-name used for mDNS A/AAAA
records without reflashing. The default expands to DEFAULT_HOSTNAME from
os-release, preserving existing behaviour for unconfigured deployments.
Format specifiers %h/%i/%m are supported via the existing hostnamefmt()
infrastructure, which is also fixed to copy the const fmt argument to a
local buffer before modification (UB when called with a libyang-owned
string).
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This patch adds support for chronyd's stratumpweight both in the NTP
client (ietf-system) and client+server (ietf-ntp) should fix the flaky
NTP stratum test.
Also, make sure to *not* 'rm -rf /etc/chrony/conf.d/*' in system.c to
prevent clobbering settings potentially made in ntp.c
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add input validation patterns to string-type leaves in container,
firewall, DHCP, and interface YANG models. Also use mkdtemp() for
temporary key files in keystore.
Signed-off-by: Mattias Walström <lazzer@gmail.com>
Add documentation noting that at least one side of a VETH pair must
remain in the host namespace. Both ends cannot be assigned to different
containers.
Updates:
- container.md: Added IMPORTANT note in Container Host Interface section
- infix-if-veth.yang: Added note in module description
- infix-if-container.yang: Added note in host identity description
Fixes: #947
Related: #941
Co-authored-by: troglobit <183517+troglobit@users.noreply.github.com>
Infix key format identities now derive from the IETF bases, so the standard
identityref accepts them without any need for deviations. This also preserves
the nacm default rules, which were inadvertently dropped before.
Also rename format identities for generality:
- wifi-preshared-key-format -> renamed: 'passphrase-key-format'
- wireguard-symmetric-key-format -> use IETF 'octet-string-key-format'
Since cleartext-symmetric-key is now type binary (base64-encoded), the
WiFi backends (station and AP) decode values before passing them to
wpa_supplicant and hostapd.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
RSSI is a vendor-specific relative index (0-255), while dBm is an
absolute power measurement. Since we report dBm values from iw,
rename the leaf to signal-strength for accuracy.
Extend the WiFi station mode with rx-speed and tx-speed leaves,
mirroring what already exists for AP mode connected stations.
Display bitrates in 'show interface <wifi>' detailed view.
Also standardize speed units to kbps/Mbps across the YANG model.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This is obsolete. By remove this we expose radio as mandatory.
This since a Wi-Fi interface is not possible to create without
a radio to connect it to.
This is a decision right now, that we support multi ssid AP, but
only one station interface, this is the only thing the c-code support
right now, so only allow this in the yang validation.
Almost full support for WireGuard
admin@server:/> show interface wg0
name : wg0
type : wireguard
index : 10
mtu : 1420
operational status : up
ipv4 addresses : 10.0.0.1/24 (static)
ipv6 addresses : fd00::1/64 (static)
peers : 2
Peer 1:
public key : ROaZyvJc5DzA2XUAAeTj2YlwDsy2w0lr3t+rWj2imAk=
status : UP
endpoint : 192.168.10.2:51821
latest handshake : 2025-12-09T22:51:38+00:00
transfer tx : 1412 bytes
transfer rx : 1324 bytes
Peer 2:
public key : Om9CPLYdK3l93GauKrq5WXo/gbcD+1CeqFpobRLLkB4=
status : UP
endpoint : 2001:db8:3c4d:20::2:51822
latest handshake : 2025-12-09T22:51:38+00:00
transfer tx : 1812 bytes
transfer rx : 428 bytes
in-octets : 1752
out-octets : 3224
admin@server:/>
Schema node "type" for parent "/ietf-routing:routing/control-plane-protocols/control-plane-protocol/ietf-ospf:ospf" not found;
in expr "derived-from-or-self(../../rt:type"
Add resource-limit and resource-usage containers to YANG model. Podman,
and later conmon, enforce CPU and memory limits in a delegated cgroupsv2
hierarchy managed by Finit.
Resource usage is queried from 'podman inspect', which has more nodes
than what is currently possible to limit.
Requires Finit 4.15, or later.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add statistics container to service model with memory usage, uptime,
and restart count tracking.
Updates YANG revision to 2025-12-02.
Signed-off-by: Richard Alpe <richard@bit42.se>
We previously run a draft version of a lot of YANG models,
netconf-server,ssh-server and mode. Now they are released
with minor changes.
infix-meta is an exception, here we had to remove the obsolete
marker of the node and value, since this is no longer allowed in
libyang.
Previously rousette did not install the yang models so we kept a copy
of them in confd. Now it is implemented in rousette, let them install
their models.
This patch unlocks "routing interfaces" support in the ietf-routing yang
model. An array of interface with IP forwarding enabled.
Note, because of #515 we skip IPv6 forwarding for now. This will in the
near future be handled by a per-interface force_forwarding sysctl flag.
The 'show interface [ifname]' admin-exec command has been extended with
a Flags field for a quick overview of which interfaces have forwarding
currently enabled.
Fixes#647
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This is the last commit in the series that extend syslog matching and sorting
to the level of sysklogd 2.7.0 and later. Like hostname filtering, property
based filtering is not supported natively in the IETF RFC, and the modeling is
unfortunately a bit clunky. The most confusing part is probably 'negate'
which is the '!' operator that inverts the matching, e.g., !icase_regex match
everthing *not* in the regexp.
Fixes#1091
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Unlock more of the optional features in ietf-syslog.yang: select-match and
select-adv-compare, for regexp and advanced severity comparison operators.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The vendor-class option was previously hard-coded to "Infix vXX.YY.Z",
but since this option usually describes the type of the device asking
for a lease, the default has been changed to use the product-name.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>