Commit Graph
602 Commits
Author SHA1 Message Date
Joachim Wiberg 6f185cdfb5 confd: refactor gen-interfaces for hybrid bridge/iface setups
Simplify interface generation by collapsing eth_ and ethlike_ifaces to a
single list.  Let gen_iface_json() determine interface type by querying
each interface.  This allows us to create bridge setups also for qemu
use-cases.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-11 14:37:49 +01:00
Joachim Wiberg ad9060e99c confd: minor, grammar fix
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-10 11:37:17 +01:00
Joachim Wiberg 32635364aa package/mcd: new package, replaces querierd
Update all package references and confd:ietf-interfaces

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-09 11:58:40 +01:00
Joachim WibergandMattias Walström f2cc620941 confd: restrict mdb group to iana-rt-types:ip-multicast-group-address
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-07 12:45:55 +01:00
Joachim WibergandMattias Walström b19047e320 confd: detect bridge per-VLAN interfaces and start querierd
In a VLAN filtering bridge setup we want to be able to support an
external IGMP/MLD querier running from userspace, because the bridge
multicast code can only generate proxy/NULL querys per VLAN.

This patch is a refactor to allow just that.  If a VLAN on the bridge
has an upper interface, matching the bridge name and VID, we generate
a profile for querierd and enable the service.

For all other cases we try to disable any running querierd.  It is up
to the daemon to figure out if it has a usable IP address to use as
the query source IP or use 0.0.0.0.

Since the logic for selecting a proper IP address must be handled by
the daemon in the per-VLAN setup, we revert back to also use it for
the stand-alone unfiltered bridge case as well.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-07 12:45:55 +01:00
Joachim WibergandMattias Walström cb0954ec19 confd: always flood unknown IP/MAC multicast according to mcast_flood
An RFC conforming multicast snooping bridge should forward all unknown
multicast (IP & MAC) on ports where the mcast_flood flag is set.  The
upstream kernel does not (yet) support this, but the KernelKit branch
of the kernel and iproute2 now support it.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-07 12:45:55 +01:00
Joachim WibergandMattias Walström 4bfedf7a98 confd: disable IPv4LL & IPv6LL on bridge port interfaces
A bridge port cannot communicate on layer-3 while acting as a bridge
port.  Removing the port from the bridge re-enables the link-local
addresses, if any, from the configuration.

Fix #327

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-07 12:45:55 +01:00
Joachim WibergandMattias Walström 12eae1ec2b confd: initial mdb support, per bridge and per VLAN
Note, no VLAN id, or other VLAN specific information is contained in the
MDB entries, only forwarding information and per-port state.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-07 12:45:55 +01:00
Joachim WibergandMattias Walström ec3b08524c confd: add support for bridge port flooding control
This patch adds BUM flooding control per port.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-07 12:45:55 +01:00
Joachim WibergandMattias Walström 6d65eff33d confd: improve debug messages, include ifname everywhere
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-07 12:45:55 +01:00
Joachim WibergandMattias Walström afdc6fe582 confd: disable bridge's dumpster diving when vlan filtering
With VLAN filtering on a bridge we cannot use the mcast_query_use_ifaddr
mechanism.  This because even if the bridge may have an address it is
likely not on the same subnet as that of the VLAN, and the multicast
code in the kernel does not look at VLAN interfaecs on top of bridge
for a relevant adddress.

For these cases we have to use querierd, or a multicast router.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-07 12:45:55 +01:00
Joachim WibergandMattias Walström 1782b12514 confd: initial multicast filtering support for bridge model
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-07 12:45:55 +01:00
Mattias WalströmandJoachim Wiberg c5d53d10a4 yang: Bump infix-routing revision 2024-03-06 18:39:27 +01:00
Mattias WalströmandJoachim Wiberg 28846dd332 Fix inconsistent naming in infix-routing model
in container: default-route-advertise
Obsolete leaf: enable
Add new leaf: enabled

enable is preferred if exist, else it use enabled.

Also update klish-plugin-sysrepo to not show the obsoleted node
in autocompletion.

This fixes #331
2024-03-06 18:39:27 +01:00
Joachim Wiberg e8ff54cb67 Revert "confd: check return value on failure to read pvid from a bridge-port"
This reverts commit f5e37bba58 because it
causes a regression in setting up VLAN filtering bridges.  The bridge
itself, e.g., br0 currently does not have a bridge-port context at the
same time as it being bridge.  The model does not account for that and
thus srx_get_int() for the br0 PVID will always fail.

Reverting this commit allows br0 to be tagged member in all VLANs by
default, for now.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-06 10:51:19 +01:00
Joachim Wiberg 3ab33cebe4 confd: fix bogus warning about not updating /etc/motd properly
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-06 09:12:36 +01:00
Joachim Wiberg 6ce44b0788 libsrx: reduce noise in syslog
The srx_*() family of APIs are for some callbacks in confd used to check
if a setting exists or not.  The root helper function srx_vaget() always
logged an error if sr_get_items() failed.  This has now been fixed and
only the srx_enabled() function still triggers this, because it has no
way of determining an error condition -- otoh it should never fail.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-06 08:54:59 +01:00
Joachim Wiberg c4f3cbf5e1 libsrx: minor, rename function argument, result -> value
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-06 08:53:50 +01:00
Joachim Wiberg f5e37bba58 confd: check return value on failure to read pvid from a bridge-port
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-06 08:49:23 +01:00
Mattias WalströmandJoachim Wiberg c3e707788d Fix VLAN infer when using interface name IFNAME.VID for naming
Then set all VLAN settings properly as well

This fixes #329
2024-03-06 06:59:46 +01:00
Joachim Wiberg 1e4a88e0b9 doc: new text-editor topic for cli
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-01 14:14:33 +01:00
Joachim Wiberg ba25914cbe confd: add support for changing text-editor backend
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-01 14:13:43 +01:00
Joachim Wiberg 9847a8fdd1 confd: migrate infix-system:motd -> infix-system:motd-banner
Inspired by openconfig-system[1], except the infix-system type is binary
to allow encoding an entire file, with optional control characters.

The openconfig-system model also carries login-banner, which is displayed
before login.  This could be added later to infix-system to let the user
set an OpenSSH login Banner.

[1]:  https://openconfig.net/projects/models/schemadocs/yangdoc/openconfig-system.html

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-01 10:04:19 +01:00
Joachim Wiberg 87bffb3816 confd: import base64 encode/decode functions, 3-clause BSD licensed
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-01 10:04:19 +01:00
Mattias Walström f0c23ca048 Update revision for infix-if-type 2024-02-29 10:22:32 +01:00
Joachim Wiberg 9c203f614b confd: log error when failing to record changes to NTP client
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-29 09:14:53 +01:00
Joachim Wiberg 92744b7318 statd: fix string length comparison
Calling strlen() returns a size that's one byte less than what's needed
to store the string, so when comparing with sizeof(), which returns the
number of available bytes, we must compare >= and not just >.

Found by GCC using 'make check'.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-29 08:45:23 +01:00
Joachim Wiberg be7b434d74 Update list of 'make check' packages
- new: execd, keyack
 - statd has been converted to autotools

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-29 08:44:08 +01:00
Joachim Wiberg a47e8b6d4a statd: fix library ordering for linker
When building for cppcheck/coverity we may get a stupid linker that can
wind up not finding, e.g., fexist() in libite (-lite) if it's not added
last in the list of libraries.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-29 08:42:07 +01:00
Richard AlpeandMattias Walström 27a4278cce statd: add good-octets counters
This patch adds out-good-octets and in-good-octets as augment in
the infix-ethernet-interface yang model. These counters represents
OctetsTransmittedOK and OctetsReceivedOK from ethtool.

Signed-off-by: Richard Alpe <richard@bit42.se>
2024-02-28 11:21:53 +01:00
Joachim Wiberg 954d26a7e2 statd: fix build without containers
Some customers do not need, or do not want, to be able to run
containers, so all NETCONF related daemons and applications
need to take this into consideration.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-27 11:47:07 +01:00
Joachim Wiberg eceeb8c59f confd: fix cni_popen() when building without container support
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-27 08:14:41 +01:00
Joachim Wiberg 7a52f49c7d execd: fix printf format specifier for systemf()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-27 08:14:41 +01:00
Joachim Wiberg ba76103c7f execd: refactor to autotools
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-27 08:14:41 +01:00
Joachim Wiberg b0b1a79aa5 statd: refactor to autotools, same as confd
Fix issue #299

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-27 08:14:41 +01:00
Joachim WibergandTobias Waldekranz 83821def3b confd: always create bridge with default_pvid 0
Fix #310
2024-02-26 16:36:29 +01:00
Joachim Wiberg 25c31ce218 src/klish-plugin-infix: improve log message on failed copy
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg bcdd311cb8 src/klish-plugin-infix: support for copying remote files with auth
This patch adds the optional 'user name' argument to the 'copy' command,
enabling using curl scp/sftp protocols for fetching and uploading files.

Changes to cfg_adjust() allow saving and referencing files in the user's
home directory.  Useful for both fetching upgrade bundles and container
images.

The 'dir' command now lists files in both $HOME and /cfg.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 3159d6c042 src/klish-plugin-infix: new symbol shell@infix with user tracking
This patch adds a new klish symbol, shell@infix, which performs proper
droprivs before calling the configured shell.

Fix #298: track user id so shell command gets correct user

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 8354997104 src/klish-plugin-infix: break out shell to optional shell.xml
Some customers don't want unprivileged CLI users to be able to exit to
a shell.  The shell is currently hard-coded to bash, but should be one
of the ietf-system shells, configurable --with-shell=foo.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg b0a0b31e68 src/klish-plugin-infix: refactor copy@infix, allow file -> file copy
This refactor is basically only an extra step after

   copy source-ds -> dest-ds

to also

   copy source-file -> dest-file

Which in the case of factory-config and startup-config is relevant.  We
want to update the startup datastore, in case of additional commands,
but also the file /cfg/startup-config.cfg in case of consecutive reboot.

Fix #259 copy factory-config startup-config

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 686f0bec03 confd: refactor, relocate container network code to cni.[ch]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 360d3b322d confd: use podman stop/start to prevent container corruption
Sending SIGTERM to conmon is not a safe shutdown of a podman container.
To handle gracefully handle shutdown, restarting and provide an orderly
start of dependencies, we use the Finit sysv trick via container script
wrapper to call 'podman stop foo'.

However, since podman does not support syslog as output for containers
we employ an old FIFO trick with another program, k8s-logger, to allow
logs to reach syslog.  Please note that k8s-logger must have properly
started before we call `podman start` -- this makes us fully dependent
on the 'container' wrapper script.  Hence the documentation update.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 3b5c0248d7 confd: handle factory-default RPC better wrt. container networks
Because sysrepo callbacks are threaded and factory-default RPC is called
from a separate subscription (to prevent blocking), we cannot prevent
ietf-intefaces.c from being called before infix-containers.c, regardless
of the priority we set for our subscriptions.

When assigning a physical network interface this becomes a bit of a pain
during factory-default RPC since the physical interface is hidden from
the host network namespace.

So, when applying factory to running, we check each interface if it was
a container-network previously, if so we call on the container script in
the exit of the current dagger generation to move the interface back to
the host netns.

This affects all other functions that assume interfaces only live in the
host netns.  To that end a set of new helper functions have been added
to wrap iproute2 commands in nsenter when the interface lives elsewhere.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 168fb24957 confd: handle building without containers
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg ec3e3b3322 confd: minor refactor, split hook, improve log messages
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 67bb7e5928 confd: simplify container network naming
The interface name is already a unique qualifier, so we can simplify CNI
network naming to ease the burden when debugging.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 214ca82bd6 confd: allow host container interfaces without IP address
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg a05a3609c5 confd: add sloppy inference of container-network type
"Sloppy" because, for some reason, we don't get sysrepo update callbacks
for presence containers.  I.e., when calling 'set container-network'
compared to 'edit container-network'.

Yes, I've gone over klish-plugins-sysrepo with a fine-toothed comb to
see if it's the culprit, but no, it seems to be sysrepo.  Hence the
defaulting of the type also in the change path.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg e4aa36dfe7 confd: tighten up container data validation in YANG model
Review found quite a few strings that could be given an obvious pattern
or specialized sub-type, e.g. inet:ip-address, to restrict the input
data validation.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00