Commit Graph
454 Commits
Author SHA1 Message Date
Joachim WibergandMattias Walström c10e5797e9 confd: update DHCP YANG model, new options, arping, and route metric
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-14 16:40:41 +01:00
Joachim WibergandMattias Walström c14b4e4152 confd: initial enhancements to DHCP client
- Add support for option 12, provide current hostname to server for
   registering the lease with -- this allows registering in local DNS
   for some DHCP servers.
 - Add support for option 50, request any previously cached IP address
 - Override option 60, vendor class identifier, with Infix vYY.MM
 - Adjust timers and retry options to be more persistant
 - Include initial metric as environment variable to client
 - Disable all default options, set a hard-coded subset, which will be
   replaced in a later commit by a generated list.
 - Ensure udhcpc creates a pid file, in case we may need to start any
   other service/task in sync with the DHCP client

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-14 16:40:41 +01:00
Joachim WibergandMattias Walström 945716bdf1 confd: refactor ntp client setup
Move from everything in a single /etc/chrony.conf to a split up with
configuration and server snippets.  The latter comes in the form of
configured (static) and DHCP client (dynamic) server setup.

To accomodate this new scheme we need to detect when serves are removed
from the configuration, so not only have the whole change_ntp() been
refactored, it has been extended with a new pass.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-14 16:40:41 +01:00
Joachim WibergandMattias Walström 66037ae2de cli: add 'show ntp [sources]' command to admin-exec
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-14 16:40:41 +01:00
Mattias WalströmandJoachim Wiberg 86557e447f Routing: Fix regression when adding static routes
Add autotest to regresssion suite to catch this
2023-12-07 14:52:00 +01:00
Mattias WalströmandJoachim Wiberg eab3c4d191 Add support for IPv6 static routing
admin@example:/> configure
admin@example:/config/> edit routing control-plane-protocol static name default
admin@example:/config/routing/control-plane-protocol/static/name/default/> set ipv6 route 2001:db8:3c4d:200::/64 next-hop next-hop-address 2001:db8:3c4d:1::1
admin@example:/config/routing/control-plane-protocol/static/name/default/> leave
admin@example:/>

admin@infix-00-01-00:/> show routes ipv6
PREFIX                        NEXT-HOP                      METRIC    PROTOCOL
2001:db8:3c4d:50::/64         eth4                          256       kernel
2001:db8:3c4d:200::1/128      lo                            256       kernel
fe80::/64                     eth3                          256       kernel
fe80::/64                     eth2                          256       kernel
fe80::/64                     eth1                          256       kernel
fe80::/64                     eth0                          256       kernel
fe80::/64                     eth5                          256       kernel
fe80::/64                     eth4                          256       kernel
::/0                          2001:db8:3c4d:50::1           20        static
2023-12-07 14:52:00 +01:00
Richard AlpeandMattias Walström ce37b33390 yanger: use argparse in yanger
This should be a non-functional change in preparation for upcoming
patches.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-12-05 10:02:51 +01:00
Joachim WibergandMattias Walström 415632f3b7 Fix #177: ensure bridge is not bridge port to itself
admin@infix-00-00-00:/> configure
admin@infix-00-00-00:/config/> edit interface br0
admin@infix-00-00-00:/config/interface/br0/> set bridge-port bridge br0
admin@infix-00-00-00:/config/interface/br0/> leave
Error: Must refer to a bridge interface (and not itself). (Data location "/ietf-interfaces:interfaces/interface[name='br0']/infix-interfaces:bridge-port/bridge".)
Failed committing candidate to running: Validation failed

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-05 10:02:25 +01:00
Joachim WibergandTobias Waldekranz d69f51a173 Fix #224: relocate /lib/infix to /libexec/infix
The /lib directory is not intended for executable scripts and programs.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-04 10:24:35 +01:00
Tobias Waldekranz 445fbf7873 confd: Notify user of all bootstrapping issues via login banners
Collect all bootstrapping issues in all banner-like files during boot,
so that they are presented to the user when logging in. This should
make it harder to miss overlook the fact that a system is running in a
degraded state.
2023-11-30 11:39:42 +01:00
Tobias Waldekranz af2b1f95a9 confd: Only move to runlevel 9 if failure-config fails to load
Before this change, the system would move to runlevel 9 as soon as
startup-config failed to load, in which no getty is allowed to run.

Instead, we want to reserve that runlevel for when failure-config
itself also fails to load, since the system will have no valid login
credentials at that point.
2023-11-30 11:39:42 +01:00
Joachim Wiberg f0c99b14dd src/confd: add support for routes set by ZeroConf agent
This fixes [ERR] from CLI `show routes`, and broken operational status
in setups with DHCP client enabled by default.

Feature (static routing) introduced in release cycle, no need to bring
up in release notes.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-30 11:03:16 +01:00
Tobias WaldekranzandJoachim Wiberg 10ece4378b confd: Don't cache libyang module references
As it turns out, references to module objects are not safe to keep
across callbacks. In particular: loading a new model into sysrepo at
runtime may cause it to move objects around in memory.

Therefore, fetch a valid reference to "infix-system" on every callback
instead.
2023-11-29 23:52:37 +01:00
Joachim Wiberg 0ff5b94ec6 klish-plugin-infix: rename command 'erase' -> 'remove' file
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-28 11:15:32 +01:00
Joachim Wiberg 09032dc4bb klish-plugin-infix: extend copy command with curl
Allow copy from/to with either datastore, file (in /cfg), or curl.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-28 11:15:32 +01:00
Joachim Wiberg 8f68a35b7b klish-plugin-infix: minor, rename type portar -> ifaces
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-28 11:15:32 +01:00
Joachim WibergandGitHub ada60bd705 src/klish-plugin-infix: fix 'show version' command 2023-11-28 09:43:10 +01:00
Joachim Wiberg 9415c0fb64 src/confd: drop /interfaces/interface/eth:ethernet config deviation
Drop this deviation for v23.11 since it clashes with pyang + NETCONFc client.
We expect to support configuration of speed+duplex in v23.12.

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-27 10:03:03 +01:00
Joachim Wiberg 2365ab273a klish-plugin-infix: minor, help help text
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-27 10:03:03 +01:00
Tobias WaldekranzandJoachim Wiberg 2da2e7fd5e confd: Fix failure-config generation when password is missing
Setting admin's password to "!" is not accepted by the model, which
means we end up in RMA mode, even in cases when a valid startup
exists.

Not supplying a password will cause confd to generate a locked
account, which is what we want.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg e53fd91c7f common: probe: Support default passwords on devicetree based systems
In addition to QEMU, we can now source the factory default password
from real VPD EEPROMs, on systems that use a devicetree.
2023-11-25 20:37:15 +01:00
Joachim Wiberg 2be779718e Fix #221: set MFD_NOEXEC_SEAL flag on memfd
Silence kernel warning seems to be most secure option.  Also, set
MFD_CLOEXEC, because if we ever fork off a child it should never
get a copy of this fd.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 13:42:54 +01:00
Joachim Wiberg 630a005bef cli: add 'show software' command
New command 'show software' to display software versions on each
partition, install date, and which one is currently booted.

admin@infix-00-00-00:/> show software
NAME      STATE     VERSION                DATE
primary   booted    v23.10.0-132           2023-11-23T22:24:33+00:00
secondary inactive  v23.10.0-132           2023-11-23T22:24:33+00:00

admin@infix-00-00-00:/> show software name primary
Name      : primary
State     : booted
Version   : v23.10.0-132-gfd6e8ea
Size      : 61992960
SHA-256   : ed6146aec462b77fb8631b14c48d281dd0f4fdb9c062f9482d863ee854081358
Installed : 2023-11-23T22:24:33+00:00

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg df76b4820f klish-plugin-infix: add 'upgrade' command to install software updates
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg 938c8aa8c5 klish-plugin-infix: update terse help text for basic commands
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg 9b1739283d confd: missing admin password, set error in /etc/issue & /etc/banner
The bootstrap script gets feedback from gen-admin-auth, on error we no
longer bail out but instead log the error and continue booting.  This
way a developer build with root login can diagnose the error.

When logging the error we also set /etc/issue, /etc/issue.net for local
and remote login services, as well as the dedicated /etc/banner used by
OpenSSH, to hold the error summary.  So when attaching to the console
port, or attempting to log in remotely with SSH, the error is printed
to indicate the device is not healthy.

Finally, since factory-config may be missing we need to bootstrap the
sysrepo db with something else, and fortunately we will always have a
failure-config to fall back on.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg f53f985dbc confd: do not fail if pwhash is missing in VPD, instead lock account
If pwhash is missing from system.json, lock account.  This allows for
more extensive diagnosis on developer builds with a root login.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg 8141cc13d1 confd: minor shellcheck fixes
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg ff12ba72b5 confd: exctract password also for failure-config
This patch adds generation of the 20-authentication.json snippet also
for failure-config.  The gen-admin-auth script is extended with shell
parameter, since the default shell differs from factory-config.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Richard AlpeandJoachim Wiberg 63a34d570d Use default pwd hash from VPD in QEMU
This commit does several things. Its end goal is to fetch the admin
password hash from VPD memory during factory bootstrap.

To accomplish this probe creates a new file /run/system.json with
information read from a fw_cfg QEMU partition. The data from
/run/system.json is then later used during config bootstrap to fill in
the factory administrator password.

The idea is to make QEMU behave the same way hardware does, i.e. a
default/factory password should be fetched and used from
"hardware memory". The hardware portion of this is yet to be done.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-24 08:55:57 +01:00
Richard AlpeandJoachim Wiberg 17093eba22 confd: disable admin login in failure config
Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-24 08:55:57 +01:00
Tobias Waldekranz f258e030bd confd: Fix shellcheck warnings in gen-interfaces 2023-11-23 12:18:28 +01:00
Tobias Waldekranz 7f049db21f confd: Remove -6 option from gen-interfaces
With the behavior introduced in the referenced commit, port
interfaces (i.e. all ports on many systems) no longer get any SLAAC
address, leaving the user with no way of reaching the system.

Comment says this is by design, but that seems like an awkward
default.

Remove the option, and simplify gen_interfaces to either
- Enable SLAAC, if the port is not going to be part of any bridge, or
- Disabel SLAAC, if the port is going to be part of a bridge

If necessary, we can add an inverse option at a later date.

Fixes: d0f3960 ("confd: add -6 option to gen-interfaces for SLACC on port interfaces")
2023-11-23 12:18:28 +01:00
Mattias Walström a0a80c8b77 Rename infix-routing to correct date
Should be 2023 not 2013.
2023-11-23 10:30:26 +01:00
Mattias Walström 37f7b5ba92 Add support for reading routing operational data for IPv4
In the CLI:
admin@infix-00-00-00:/> show routes
PREFIX                        DESTINATION                   PROTOCOL  METRIC
1.1.1.0/24                    e0                            kernel
192.168.100.0/24              1.1.1.1                       static    20
192.168.110.2/32              blackhole                     static    20
192.168.120.2/32              blackhole                     static    20
192.168.130.2/32              unreachable                   static    20
2023-11-23 10:30:26 +01:00
Jon-Olov VatnandJoachim Wiberg 6cfcf3ca10 Fixing and activating ieee802-ethernet yang deviations 2023-11-22 13:44:28 +01:00
Jon-Olov VatnandJoachim Wiberg 6669fee728 Draft infix deviations for ieee802-ethernet-interfaces
- Add deviations for non-supported statistics
- Limit config, currently we only have ro support
- Add deviations for non-supported configs and status leafs

[skip ci]
2023-11-22 13:44:28 +01:00
Joachim Wiberg 4c6d868627 Fix #215: impossible to enable NTP client
Regression introduced in ac0b0d5.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-21 19:24:05 +01:00
Joachim Wiberg 69d0c16e30 src/klish-plugin-infix: show JSON of running-config
The default srp_show@sysrepo function creates the stripped down version
of running-config that, in the context of showing startup-config or the
factory-config, is very difficult to explain to users why they differ in
format.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-21 08:06:06 +01:00
Joachim Wiberg ac63461bd8 confd: fix copy-paste error in dns-resolver
Found by Coverity Scan, CID 331048

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 123808d6bb confd: check return value of mktime()
Found by Coverity Scan, CID 331032

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg b2331dc8ce confd: minor, coding style
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 31bd1286a3 confd: minor, whitespace
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg da6b5a1950 confd: mark unchecked remove()/rename() as intentional
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 1b825d4ac6 confd: fix memory leak in handle_sr_shell_update()
Found by Coverity Scan, CID 331029

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 90af510092 confd: fix memory leak in handle_sr_passwd_update()
Found by Coverity Scan, CID 331033

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg c3045ecebb confd: fix obvious mistakes in checking return values
Found by Coverty Scan

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg f56baeb4fa confd: drop malplaced sr_free_values()
We haven't even called sr_get_items() yet.  Must've been a remnant
of an earlier refactor.

Fixes CID 331051

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 2191202f2a statd: null terminate recv() buffer from netlink
Fixes CID 331053

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 2caf729ee8 github: enable building local src in host mode for analysis
Install libyang and sysrepo from source, too old packages in ubuntu-latest.

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 18:04:18 +01:00