Commit Graph
564 Commits
Author SHA1 Message Date
Joachim Wiberg b55f74395b board/netconf: simplify and relocate to board/common
With Classic builds out of the way we can move everything back to common
again to simplify and reduce our collective cognitive overhead a bit.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-11 06:19:07 +02:00
Joachim Wiberg 493be97769 Drop legacy Classic builds
The Classic builds served for a while as an introduction to classic
embedded systems, with a user managed read-writable /etc.  Today we
decided to firmly take the plunge into the future with NETCONF and
focus on our core platforms aarch64 and x86_64 (for Qemu).

The reasons are several: reduce overhead, simplify build and release
work, as well as manual testing, since Classic builds do not have any
automated regression testing.

The Classic builds may be resurrected later in a dedicated project.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-11 06:19:07 +02:00
Mattias WalströmandJoachim Wiberg b350483617 Always enable coredumps
They will be availible in /var/crash/ (maximum one per process name)
2024-04-05 15:34:21 +02:00
Joachim Wiberg 1dcbea52b9 confd: handle ip/route additions to container networks at runtime
On any change to a container network interface we should schedule a
restart of the container to activate the changes.  This code triggers
also at boot, when applying the whole startup-config, which initctl
handles by queuing any create/touch events for services.

This patch depends on the two previous commtis backporing fixes to
Finit's initctl tool and an upgrade of the k8s-logger.

Fixes #375

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg ea3bfda2de board/common: fix issue where containers without network get network
Also, log the actual `podman create` arguments to the container log so
we can see what the script actually does when customers report bizarre
happenings with containers.

Fixes #370

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg fad75575e4 confd: add limited support for container capabilities
This change adds limited support for container capabilities.  It allows
a more fine-grained control than priviliged mode does.

Fixes #365

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg 9575e03dc9 board/common: fix container upgrde for oci-archive:/ images
Add exception for local images, the "pull" step must be handled by the
operator, i.e., wget of the latest image to the same location as set up
in the image configuration, e.g., for oci-archive:/tmp/foo.tar.gz that
/tmp/foo.tar.gz exists when issuing the upgrade command.

Fixes #368

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Mattias Walström a0f09a1c06 Add script that generates a certificate with unlimited expiredate
Primary use is to generate default HTTPS certificate.

Sample usage:
/bin/gencert --country SE --state Vastmanland --city Vasteras --organisation ACME --organisation-unit Second  --common-name switch.local --out-certificate /tmp/out.cert --out-key /tmp/out.key
2024-03-20 14:19:52 +01:00
Joachim Wiberg eec5546100 board/common: add missing newline at end of /etc/motd
With the changes in 9847a8f we can keep the /etc/motd file with a proper
newline at EOF so that also Classic builds make sense.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-01 20:19:17 +01:00
Joachim Wiberg 84391c18a4 board/common: introduce Debian-like alternatives system
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-01 14:13:06 +01:00
Mattias Walström 103398f070 make run: Increase default memory for qemu
This since the image has gotten larger.
2024-02-28 13:13:32 +01:00
Joachim Wiberg 360d3b322d confd: use podman stop/start to prevent container corruption
Sending SIGTERM to conmon is not a safe shutdown of a podman container.
To handle gracefully handle shutdown, restarting and provide an orderly
start of dependencies, we use the Finit sysv trick via container script
wrapper to call 'podman stop foo'.

However, since podman does not support syslog as output for containers
we employ an old FIFO trick with another program, k8s-logger, to allow
logs to reach syslog.  Please note that k8s-logger must have properly
started before we call `podman start` -- this makes us fully dependent
on the 'container' wrapper script.  Hence the documentation update.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg a530db9ae5 board/common: confine containers in their own parent cgroup
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 337f39a74d board/common: quiet flag and check if running for start/stop
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 3b5c0248d7 confd: handle factory-default RPC better wrt. container networks
Because sysrepo callbacks are threaded and factory-default RPC is called
from a separate subscription (to prevent blocking), we cannot prevent
ietf-intefaces.c from being called before infix-containers.c, regardless
of the priority we set for our subscriptions.

When assigning a physical network interface this becomes a bit of a pain
during factory-default RPC since the physical interface is hidden from
the host network namespace.

So, when applying factory to running, we check each interface if it was
a container-network previously, if so we call on the container script in
the exit of the current dagger generation to move the interface back to
the host netns.

This affects all other functions that assume interfaces only live in the
host netns.  To that end a set of new helper functions have been added
to wrap iproute2 commands in nsenter when the interface lives elsewhere.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 61cba2615f confd: make container privileged mode configurable
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg a6f6fcac6a confd: add support for oci: and oci-archive: images
1. add support for extracting, and finding the directory holding the
    index.json metadata file in, OCI images.  An archive in Infix is either
    a .tar or .tar.gz archive, which we need to unpack for this version of
    podman to be able to load them.
 2. new RPC '/infix-containers:oci-load' calls 'container load' of an
    OCI archive (tarball), optionally gzipped.  The resulting image uses
    the directory name of the unpacked tarball, so the container script
    offers a way to retag the image after loading it.

First class citizens in container transport are docker:// and the OCI
family of URI:s.  A docker:// URL, or a local docker-archive:path, is
assumed to be well formed, in which case we leave it up to podman to
handle.

Note: 'podman import' does not fully understand OCI formats.  It drops
      ENTRYPOINT and COMMAND, while 'podman load' handles things a lot
      better.  Only letdown is it does not support nameing the image.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 580599f549 confd: misc. fixes and cleanup
- drop debug logs
 - no need to restart upgraded containers, they restart automatically
 - fix ordering in volume prune (when containers are removed)
 - skip directories in container activation (inbox -> execd queue)
 - Fix 'container pull IMG creds USER[:PASS]' bug, extra '=' variable
   assignment inside infix.xml
 - Fix 'container run IMG CMD ARGS' to actually put the CMD in
   ENTRYPOINT and append ARGS to image.  The podman run and create
   commands are *not* behaving the same way
 - Rename 'attach' to 'exec', execute command inside an running container
 - Add 'container [shell | connect]' to start shell in -- " -- " -- " --
 - Add 'container [stat | cleanup | usage stats]' commands
 - Add in="tty" to commands thay may end up being interactive
 - Split <ACTION> line into multiple lines for readability
 - Fix container shift logic:

     root@infix-00-00-00:/> show container
     /usr/sbin/container: line 361: shift: shift count out of range

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg cd4e8b0a9f confd: add support for mounting read-only files in containers
In the container configuration context:

    edit file ntp.conf
    set path /etc/ntp.conf
    set content

The last command opens a text editor where you can paste the contents
of the file.  This is stored base64 encoded in the datastore as well
as in JSON/XML.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 31502c8aab confd: add support for upgrading container images
This patch adds a new CLI command 'container upgrade foo', where 'foo'
is the name of the container.  If more than one container use the same
image, multiple upgrades must be done because a container runs not on
the 'image:tag' but on the hash of the 'image:tag' it was created from.

Rename "done" queue to "active", since we want to recreate an active
container after fetching an updated base image.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg aafa88b648 confd: add support for container volumes
This commit adds support for writable container volumes.  A volume, when
compared to a mount, is a writable directory created when the container
starts and is automatically rsync'ed with the underlying directory it
is mounted on on first use.  A mount otoh does not rsync so it results
only in an empty directory inside the container.

The podman/docker mount feature will be used later to bind mount single
files or sharing directories from the host, e.g., /sys/class/leds/ to
one of more containers.

Note: unused volumes are automatically pruned.  Hence, a volume
      currently cannot be moved to another container.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 256c462c0c confd: add support for read-only containers
This creates a container without a writable layer.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg d8dde9cde2 confd: add support for custom container ENTRYPOINT
This was a tough nut to crack.  Turns out the trick to changing the
ENTRYPOINT is to set --entrypoint=command and then call 'podman create
... command args'.  Not entirely obvious since the documented approach
is to use a JSON array as the argument: podman create
--entrypoint='["command", "args" ]'.

Admittedly, encoding this in C to transfer it via a POSIX shell script
to the command line, is not the easiest task I've undertaken.  So I gave
up and found this workaround.

Worth noting, however, is that one *must* set `--entrypoint`, it is not
enough to just append the command to the 'podman create' command line.
Due to differences in docker and podman, we cannot supply the full args
to an alternate entrypoint command.  But for the command to actually run
we need to override the image's ENTRYPOINT and send the command and args
as the last arguments on the command line to podman create.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg f1bf02eda5 confd: refactor how container networks are sent to container helper
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg aa7ea66a0d confd: add support for setting container hostname
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 7a57d4f0fa confd: add support for container environment variables
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 3d85eba3fc confd: add support for publishing container ports
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg ffd2128614 confd: add support for container restart and restart policy
Also, ensure the deleted container is actually deleted before recreating
it with a new configuration.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 2b19b61068 confd: add support for manual start of containers
This commit adds 'manual:yes' to the container's Finit service
configuration and changes from pod: to container: prefix for a
unique namespace to prevent collision with regular services.

The prefix container: is more correct that pod:, which should
be reserved for any future pod support.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>

confd: fix missing variable in container script condition

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 9e801dfa2f confd: initial support for Docker containers using podman
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg b3e418c6a7 board/common: let qemu.sh take kernel/init args on command line
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg f0f0e737a9 board/common: BusyBox ash != bash, set bash as root default shell
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Joachim Wiberg 84f83d635b board/common: fix #294: drop 'v' from version in filenames
The files inside a release tarball, as well as the tarball name itself,
should not have the leading 'v', that's just for the tag.

Also, add -ver to GNS3 disk.img file as well.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-02-25 19:49:27 +01:00
Mattias Walström 420e0d5b36 qeumu: Add USB ports 2024-02-23 14:01:23 +01:00
Mattias Walström 2011f5cbf2 modprobe.d: Unauthorize all USB ports on boot 2024-02-23 14:01:23 +01:00
Joachim WibergandTobias Waldekranz fbe6accdf3 Clarify what happens without /plen
Co-authored-by: Tobias Waldekranz <tobias@waldekranz.com>
2024-01-30 15:32:38 +01:00
Joachim WibergandTobias Waldekranz 228891935d dhcp-client: allow setting hostname, and update /etc/hosts
This should be the last outstanding issue to fix #278.  Please note,
it is undefined what happens if you have two DHCP clients that request
hostname, and changing hostname from NETCONF at runtime will overwrite
any hostname set by the DHCP client.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-30 15:32:38 +01:00
Joachim WibergandTobias Waldekranz faa6ce849b dhcp-client: don't assume we got option 1 (subnet)
If we don't get subnet, then just set the IP address.

Issue #278

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-30 15:32:38 +01:00
Mattias Walström 0033a92c80 qemu.sh: Fix bug when emulate VPD
Wrong date format for manufacture-date
2024-01-23 15:30:40 +01:00
Joachim WibergandTobias Waldekranz 000811fced board/common: skip if not SIGN_ENABLED
All Infix builds should be signed, but for some test equipment, and
during board bringup, this may be too much of a hassle.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-22 11:20:01 +01:00
Tobias WaldekranzandMattias Walström 7081934473 Promote all members of wheel to sudoers
Install the sudo command, and let all members of the "wheel" group run
any command as the superuser.

This ensures that administrators have full access to the system,
primarily for troubleshooting, diagnostics, and remote scripting
purposes.
2024-01-18 10:28:32 +01:00
Tobias WaldekranzandJoachim Wiberg 6ef80d5847 Add a default message of the day (/etc/motd)
This is injected to the factory-config during bootstrap, and can then
be changed as usual via /system/motd.
2024-01-18 00:02:55 +01:00
Joachim WibergandTobias Waldekranz d70abc5f21 board/common: let dagger script set LOG_PID with parent PID
This adds [PPID] to the syslog lines to the dagger script.  After all,
the dagger script is a proxy for confd, so when reading the logs it
seems natural to see the PID of confd rather than a script that will
die soon anyway.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-09 21:24:41 +01:00
Joachim WibergandMattias Walström 2305f6adfd board: relocate prod scripts to netconf builds
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-27 06:36:48 +01:00
Joachim WibergandMattias Walström 4b6b90a79b board: fix breakage in classic builds
- Relocate python based probe to netconf builds, and
 - Restore basic shell script based probe for classic builds

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-27 06:36:48 +01:00
Joachim WibergandMattias Walström 2fa5dcfea0 board/common: major refactor of udhcpc script
- New log() function replaces stdout logging
 - New set_dhcp_routes() and clr_dhcp_routes() functions
   - Set all option 121 routes with same metric
   - Set all option 3 routers with increasing metric (this is what the
     reference udhcpc scripts do, and RFC says the routers should be
     listed in order of preference ...)
   - Clearing routes must, like IP addresses, be done both by interface
     and protocol.  This refactor makes sure to delete any DHCP routes
     set on the given interface (in case options change)
 - Use resolvconf per-interface search+nameserver
 - Cache IP lease so we can ask for it back later
 - On deconfig|leasefail|nak, make sure to clean up anything that might
   be lingering from this interface.  E.g., we can get leasefail when a
   server denies our request to prolong a lease.
 - On renew|bound, refresh routes, and set search+dns + NTP servers

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-14 16:40:41 +01:00
Joachim WibergandMattias Walström 49aec29a8d board/common: add support for acquiring NTP server from DHCP server
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-14 16:40:41 +01:00
Joachim WibergandMattias Walström 945716bdf1 confd: refactor ntp client setup
Move from everything in a single /etc/chrony.conf to a split up with
configuration and server snippets.  The latter comes in the form of
configured (static) and DHCP client (dynamic) server setup.

To accomodate this new scheme we need to detect when serves are removed
from the configuration, so not only have the whole change_ntp() been
refactored, it has been extended with a new pass.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-14 16:40:41 +01:00
Joachim WibergandMattias Walström 66037ae2de cli: add 'show ntp [sources]' command to admin-exec
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-14 16:40:41 +01:00
Joachim WibergandTobias Waldekranz d69f51a173 Fix #224: relocate /lib/infix to /libexec/infix
The /lib directory is not intended for executable scripts and programs.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-12-04 10:24:35 +01:00