Commit Graph
564 Commits
Author SHA1 Message Date
Tobias Waldekranz f4a604f63c Prevent non-essential services from running in runlevels > 6
In case failure-config fails to load, we park the system in runlevel
9. In this state, we only want the most essential services running.
2023-11-30 11:39:42 +01:00
Tobias WaldekranzandJoachim Wiberg e1db5bad78 rauc: Start after D-Bus
On occasion, rauc has problems registering with D-Bus. Ensure that the
D-Bus daemon is running before starting rauc.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg be728accbb rauc: Remove unsupported argument from finit service stanza
Fixes: 0f410eb ("rauc: add support for tftp:// for bundles and syslog for logging")
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg e53fd91c7f common: probe: Support default passwords on devicetree based systems
In addition to QEMU, we can now source the factory default password
from real VPD EEPROMs, on systems that use a devicetree.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg 17d1a529e8 common: qemu: Run without VPD by default
Infix will fallback to admin/admin on a QEMU system.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg 0a746a9795 common: qemu: Only create VPD if it does not exist
This let's you create a custom one to test out different scenarios
without it being clobbered by qemu.sh.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg b7cc0935ac common: qemu: Simplify VPD generation
Also, remove the "VBD" terminology. We will only emulate a single VPD
anyway.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg b5ba1602ec common: onieprom: Don't read more data than needed when decoding TLV
There's little point in reading a 32kB EEPROM do decode a 100B
TLV. Instead figure out how much we need to read from the header.
2023-11-25 20:37:15 +01:00
Joachim Wiberg 9655f98903 Fix #222: operational status b0rks on unknown route proto
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 14:29:16 +01:00
Joachim Wiberg 748996dad8 Replace firmware with Linux OS, operating system, or software
We should avoid the use of the ambigous word 'firmware'.

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg 0f410eb3b2 rauc: add support for tftp:// for bundles and syslog for logging
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim WibergandTobias Waldekranz c55d38df9a Use Kernelkit's IANA Enterprise Number
[skip ci]

Co-authored-by: Tobias Waldekranz <tobias@waldekranz.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg 9b1739283d confd: missing admin password, set error in /etc/issue & /etc/banner
The bootstrap script gets feedback from gen-admin-auth, on error we no
longer bail out but instead log the error and continue booting.  This
way a developer build with root login can diagnose the error.

When logging the error we also set /etc/issue, /etc/issue.net for local
and remote login services, as well as the dedicated /etc/banner used by
OpenSSH, to hold the error summary.  So when attaching to the console
port, or attempting to log in remotely with SSH, the error is printed
to indicate the device is not healthy.

Finally, since factory-config may be missing we need to bootstrap the
sysrepo db with something else, and fortunately we will always have a
failure-config to fall back on.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg 8141cc13d1 confd: minor shellcheck fixes
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg fdaface79f probe: use fallback password hash also for qeneth (regression tests)
Break fallback hash to a separate function and allow gen_qemu_system_file()
to return the status.  We'd like to update the qeneth templates to include
the same VPD data as is used with qemu.sh, but for now this is sufficient.

The Qemu detection has been changed to the, slightly more, secure detection
of qemu_fw_cfg filesystem.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Richard AlpeandJoachim Wiberg 63a34d570d Use default pwd hash from VPD in QEMU
This commit does several things. Its end goal is to fetch the admin
password hash from VPD memory during factory bootstrap.

To accomplish this probe creates a new file /run/system.json with
information read from a fw_cfg QEMU partition. The data from
/run/system.json is then later used during config bootstrap to fill in
the factory administrator password.

The idea is to make QEMU behave the same way hardware does, i.e. a
default/factory password should be fetched and used from
"hardware memory". The hardware portion of this is yet to be done.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-24 08:55:57 +01:00
Tobias Waldekranz 1e9cd310f8 board/common: Add self-provisioning scripts
This let's you netboot a system with a blank block device, and setup
all partitions, filesystems, images etc.
2023-11-23 12:18:28 +01:00
Tobias Waldekranz 252b894d55 rauc: Source service arguments from /etc/default, if available
This is need by upcoming provisioning scripts.
2023-11-23 12:18:28 +01:00
Tobias WaldekranzandJoachim Wiberg 7e7d25d82e board/common: mnt: Remove old clixon remnants 2023-11-21 08:05:02 +01:00
Tobias WaldekranzandJoachim Wiberg 0a51b5e8e9 board/common: mnt: Be slightly less inconsistent with quoting 2023-11-21 08:05:02 +01:00
Tobias WaldekranzandJoachim Wiberg 2bfc524546 board/common: mnt: Correctly reset /var as part of a factory-reset
Before this change, the following would happen in /lib/infix/mnt if a
factory-reset was performed:

1. Copy the contents of /var from Squash into /mnt/var and bind mount
   /mnt/var over /var
2. Check for factory-reset
3. Clear /mnt/cfg/* and /mnt/var/*
4. Mount overlays

This ordering leaves the system with a completely empty /var on the
boot when a factory-reset is executed. Finit will fixup some of this
via its tmpfiles scripts, but we want the ability to ship files under
/var as part of the Squash and have these be available after the bind
mount, just like what happens at every other boot, when we don't
perform a factory-reset.

We solve this by delaying the bind mount (1) until after the reset has
been performed, together with all the overlays (4). While we're here,
make the fallback case, where no persistent /var is available, use a
bind mount as well. This should allow containers to be tested on such
setups, and it's one less flavor to test.

New order:

1. Check for factory-reset
2. Clear /mnt/cfg/* and /mnt/var/*
3. Mount overlays
4. Copy the contents of /var from Squash into /mnt/var and bind mount
   /mnt/var over /var

Now the only difference between a regular boot and a
"factory-reset-boot" is whether (2) executed or not.
2023-11-21 08:05:02 +01:00
Tobias WaldekranzandJoachim Wiberg 55afbb2a94 board/netconf: Only use iitod on netconf builds
None of the panic/failure/startup conditions make any sense on classic
builds where confd is not running.
2023-11-19 08:50:19 +01:00
Joachim Wiberg cc6232bf38 package/iito: relocate Finit conf and add tmpfiles.d for /run/led
Relocate Finit conf to package, like klish and confd.  Add condition to
ensure it is not started before mdev/udevd are up and kernel LED modules
have been loaded properly.

Also, add tmpfiles.conf to ensure /run/led is recreated at every boot.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-18 14:49:56 +01:00
Tobias WaldekranzandJoachim Wiberg de5b0061a8 common: Define standard LED behavior
Provide a set of standard rules for commonly available LEDs.
2023-11-14 16:41:03 +01:00
Tobias WaldekranzandJoachim Wiberg 9feed50d08 common: onieprom: Encode/decode ONIE EEPROMs from/to JSON 2023-11-14 16:41:03 +01:00
Joachim WibergandMattias Walström 608f82afd6 Mark known services as 'notify:none', no readiness notification
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-13 10:28:47 +01:00
Joachim WibergandGitHub 4930fa78a8 board/common/rootfs/etc/nginx: drop, unused
[skip ci]
2023-11-13 10:16:17 +01:00
Mattias Walström 4889d402ec Use proper mkfs.ext4 when creating /var and /cfg partitions
Without this it used an genimage internal one, which did not set
the filetype feature on the filesystem. This caused
podman to refuse to start
2023-11-08 14:16:57 +01:00
Joachim Wiberg 42ad40f905 rootfs: minor adjustments to /bin/yorn output formatting
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-08 11:17:41 +01:00
Joachim WibergandTobias Waldekranz 62401377b0 Check for factory-reset condition from bootloader
Refactor factory-reset check slightly to check for a Finit condition
from the bootloader, as well as a custom check for br2-externals.

Note, the chgrp call has been extended to ensure admin users have
permission to create any file or directory in any overlay.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-03 12:55:44 +01:00
Joachim Wiberg 72b0f9f3eb board/common: add missing $VERSION to /etc/os-release PRETTY_NAME
Per spec[1], the PRETTY_NAME "May or may not contain a release code name
or OS version of some kind, as suitable." and seeing as this is not only
a common practice, Finit use this string in the heading when booting.

We've had this already in Infix a while back so it must have been lost
in one of many refactoring rounds.

[1]: https://www.freedesktop.org/software/systemd/man/latest/os-release.html

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-02 07:00:49 +01:00
Joachim Wiberg 69a3663a82 board/common: expose settings for Qemu machine and its RAM size
A customer specific build required more RAM to boot (bigger image and
more features), but there was no way to modify this as an end user.

This patch opens this up and should give our users a more smooth ride!

We can [skip ci] on this, no functional changes to the OS itself.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-31 18:21:09 +01:00
Joachim WibergandTobias Waldekranz afbf92c07e configs: drop x86_64_minimal_defconfig
Replaced with full build in GitHub Actions.  No other use-cases for it,
and too much of a hassle to maintain, so remove.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-31 09:28:28 +01:00
Joachim WibergandTobias Waldekranz 6503face19 package/finit: bump to v4.5
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-31 09:28:28 +01:00
Tobias WaldekranzandJoachim Wiberg 97747a95ea common/uboot: Use factory-reset and dev-mode buttons, if available
If the bootloader knows about a factory-reset or dev-mode button, use
them to allow stopping the boot process, and to signal the
factory-reset condition to infix.
2023-10-30 11:24:18 +01:00
Tobias WaldekranzandJoachim Wiberg 01e43896df common/uboot: Explicitly separate kernel/user arguments
This way, we avoid arguments intended for userspace to be accidentally
parsed by the kernel.
2023-10-30 11:24:18 +01:00
Tobias WaldekranzandJoachim Wiberg 60c777fb41 common/uboot: If no valid boot media exists, fall back to netboot
This means that a device with a valid bootloader, but a completely
empty eMMC is still salvageable.
2023-10-30 11:24:18 +01:00
Tobias WaldekranzandJoachim Wiberg 194aa5de8a common/uboot: Use correct name of netboot in default order 2023-10-30 11:24:18 +01:00
Joachim Wiberg e03ab9c81b board/common: add help text for Qemu interface model
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-24 13:37:28 +02:00
Mattias WalströmandJoachim Wiberg f224d0d03d ietf-factory-default: Implement factory reset
fixes #157, fixes #156
2023-10-24 12:25:38 +02:00
Joachim Wiberg acecbe7e5d Allow custom image filename being set in menuconfig
This adds support for the two /etc/os-release variables:

 - IMAGE_ID
 - IMAGE_VERSION

The former is configurable, with fallback to name-arch, and the latter
is only set for relase builds.  During releae builds the release will
be appended to the image name.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-17 13:26:26 +02:00
Joachim Wiberg b44e303775 board/common: basic feature probe
Currently does not need any conditions, but may later need to check for
loaded modules and other capabilities.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 16:35:00 +02:00
Joachim Wiberg 46bd3df13e board/common: fix string comparison operator [skip ci]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 14:28:18 +02:00
Joachim WibergandTobias Waldekranz 138c9f3378 Update board/common/mkgns3a.sh
As @wkz says, better to use this construct if/when we add more archs.

[skip ci]

Co-authored-by: Tobias Waldekranz <tobias@waldekranz.com>
2023-10-12 11:22:55 +02:00
Joachim Wiberg 230c2adae7 board/common: rename disk.img and update .gns3a
- Create per-arch unique distribution file names
 - Source .gns3a information from /etc/os-release

Instead of attempting to create unique file names by hard-coding an
'infix-' prefix and extracting the "board" or "arch" part from the
defconfig, let's use the branding information from /etc/os-release
along with $BR2_ARCH.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 11:22:55 +02:00
Joachim Wiberg 09d48b35ee board/common: parameterized branding using menuconfig
This makes it possible for projects using Infix as a br2-external to
override lots of OS-specific strings and contact information that
previously was hard coded.

The generated /etc/os-release now takes most of its data from .config
Worth noting is the changes in VERSION and BUILD_ID fields.  The former
will be INFIX_RELEASE, during release builds, and the latter is always
the output from `git descibe ...`, or rather GIT_VERSION.  This variable
can be overloaded as well.

See the help text and the new doc/branding.md document for details.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 11:22:55 +02:00
Joachim Wiberg f2e30943ee board/common: generate images/Config.in and reduce x86 ram
The default arch and disk image filename needs to be generated
to be unique per, at least, each architecture build.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 11:22:55 +02:00
Joachim Wiberg f852afc9c6 Enable GNS3 appliance file for all builds
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 11:22:55 +02:00
Joachim Wiberg c6d4fbf341 board/common: generate a simplified .gns3a for aarch64 builds
Due to problems with using u-boot as loader¹ we decided to start the
system by calling the kernel image directly.  The downside to that is
that, even though RAUC upgrades would work, the kernel would remain
the same.

Improvements to this are of course welcome.

________
¹) Must extract the built-in .dtb and merge with the Qemu .dtb at runtime
   to be able to boot primary (or secondry) image.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 11:22:55 +02:00
Joachim Wiberg b40484e262 board/common: fix load_cfg key=value extraction
Calling `load_cfg BR2_EXTERNAL_INFIX_PATH` from post-image.sh caused
warnings due to multiple hits in the .config file:

post-image.sh: 12: /tmp/tmp.5a3xhQQVc8: BR2_EXTERNAL_INFIX_PATH: not found
post-image.sh: 13: /tmp/tmp.5a3xhQQVc8: BR2_EXTERNAL_INFIX_PATH: not found

Let's grep for a "key.*=" instead of "key" to drop those warnings, while
still acting as a catch-all for partial matches.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 11:22:55 +02:00