Commit Graph
824 Commits
Author SHA1 Message Date
Joachim Wiberg 445ca0a9d6 board/common: restore 'show' script from 493be97 sync with present
The intention is to provide a similar set of commands as klish
admin-exec.  However, instead of trying to make the Linux tools
more accessible, we now make the Infix tooling more accessible.

E.g., instead of "show ip route" mapping to "ip route show", we
map it to:

sysrepocfg -f json -X -d operational -x "/ietf-routing:routing/ribs" | \
      /usr/libexec/statd/cli-pretty "show-routing-table"

As a spin-off we alos get a much more readable infix.xml for klish:
 - Relocate logic to shell script wrapper 'show'
 - Introduce Cisco style "show ip route" and "show ipv6 route"

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-09-26 15:49:45 +02:00
Joachim Wiberg cc8e31f74f board/common: adjust metric on IPv4LL and DHCP routes to match Frr
Apply a distance adjustment to routes retrieved from IPv4LL/ZeroConf and
DHCP to ensure that Frr (Zebra) can compare other protocol routes, e.g.,
static.  Without this Frr will consider all routes read from the kernel
to have a protocol distance of 0, meaning better than static routes that
have a distance of 1.

Initial proposal to fix issue #640

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-09-26 15:49:45 +02:00
Joachim Wiberg 4ed4fa5052 board/common: simplify avahi-autoipd.action script
- We know we always have iproute2 tools
 - We only use one ipv4ll client per interface, so UNBIND can be
   simplified to flush ifname:avahi
 - Log all events handled by script for troubleshooting

Note: on BIND event we may be called without first getting UNBIND on
      previous address, hence the flush there too.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-09-26 15:49:45 +02:00
Joachim Wiberg af1a86f10a board/common: reactivate scp/sftp and drop non-working cli subsystem
The sftp subsystem was lost in 61213c7.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-09-26 15:49:45 +02:00
Ahmed KaricandAhmed Karic 621e76c925 Revert "board/common: introduce image test-mode"
This reverts commit 241f3f224f.
2024-09-23 15:35:21 +02:00
Mattias WalströmandJoachim Wiberg ef81abeae2 configuration migrate: Remove duplicate infix-meta:version when migrate config
when migrate configs the yang data produced was this:
  "infix-meta:meta": {
    version: "1.0"
    "infix-meta:version": "1.1"
  },

duplicate node, resulting in failed migration of startup configuration, always replace
whole node.
2024-09-21 08:47:02 +02:00
Tobias WaldekranzandJoachim Wiberg 7d1a708274 board/aarch64: styx: Remove unconnected LED
Only one (green) LED per port is available.
2024-09-19 14:27:22 +02:00
Tobias WaldekranzandJoachim Wiberg c263ff102d board/aarch64: styx: Trivial cleanup in dts
Require an explicit addr-of when using GSWP, which makes it clearer
for a reader that the argument passed is a node reference.
2024-09-19 14:27:22 +02:00
Tobias WaldekranzandJoachim Wiberg cbd615ec78 board/aarch64: styx: Revision B Support
The rewiring of the backplane in revision B necessitates two distinct
device trees.

Co-developed-by: Henrik Nordström <henrik.nordstrom@addiva.se>
2024-09-19 14:27:22 +02:00
Joachim Wiberg db136bce32 Fix container upgrade regression
In 0edc2d5 and afbe5ca, just prior to v24.06.0-rc1, support for deleting
containers in the background was added.  However, this also broke support
for upgrading containers.

In afbe5ca the start script for containers was renamed from NAME.sh to
S01-NAME.sh, but the container wrapper script's upgrade command was not
updated.  Neither was the cleanup and post-hook callbacks in confd!  So
when a container had been added to the system, the cleanup callback just
simply deleted the script, preventing it from being recreated at ugprade

This patch fixes the container identification code and also refactors
the execd code to ensure that kill scripts (for deleting in background)
and start scripts are run in the proper order *and* ensuring that execd
also does not accidentally remove the container start script.

Some cosmetic changes to the output at upgrade have also been added.

Fixes #623

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-09-13 16:31:39 +02:00
Joachim Wiberg 3003044601 board/common: add container --net IFNAME locate
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-09-13 16:31:39 +02:00
Joachim Wiberg b6472766b1 board/common: spellcheck path to downloaded OCI files
Check correct path for downloaded container images.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-09-13 16:31:39 +02:00
Tobias Waldekranz eb3f8ce711 confd: Break out front-end timeout to common environment file
While sysrepo's architecture places the responsibility of choosing a
timeout on each front-end, we want to control it centrally since the
majority of the time is spend actually applying the config to the
system - which is front-end agnostic.

Therefore, create a single definition of the timeout, which can be
included by all front-ends.
2024-09-05 23:41:19 +02:00
Joachim Wiberg d856fc8dbc board/common: shellcheck fixes to 'doas' sudo wrapper
Passing $@ to sudo requires quoting to prevent splitting arguments like
this:

    admin@R2:~$ doas vtysh -c 'show ip ospf routes'
    % Command incomplete: show

After this patch:

    admin@R2:~$ doas vtysh -c 'show ip ospf route'
    ============ OSPF network routing table ============
    N    192.168.50.0/24       [1] area: 0.0.0.0
			       directly attached to e7

    ============ OSPF router routing table =============
    R    192.168.100.1         [1] area: 0.0.0.0, ASBR
			       via 192.168.50.1, e7

    ============ OSPF external routing table ===========
    N E2 192.168.10.0/24       [1/20] tag: 0
			       via 192.168.50.1, e7
    N E2 192.168.100.1/32      [1/20] tag: 0
			       via 192.168.50.1, e7

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-09-05 10:38:06 +02:00
Joachim Wiberg d0f3a5c8b4 board/common: include .config as /usr/share/infix/config.gz
Issue #597

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-09-05 07:04:58 +02:00
Joachim Wiberg cf1c4c32f1 board/common: disable unused pam_lastlog.so from PAM login
Fixes the following recurring login warning in syslog.  (We cannot use
pam_lastlog.so since it does not rotate its /var/log/lastlog file.)

login[2819]: PAM unable to dlopen(/lib/security/pam_lastlog.so): /lib/security/pam_lastlog.so: cannot open shared object file: No such file or directory

Follow-up to issue #542

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-30 15:29:11 +02:00
Joachim Wiberg d05a64913e configs: drop pam_lastlog.so, does not rotate its log
The PAM plugin lastlog, previously used (optional) by Netopeer2 and
Rousette, does not rotate /var/log/lastlog, and since we don't have
cron and logrotate this can potentially fill up /var.

This patch disables pam_lastlog.so from the build and drops the two
matching session lines for both Netopeer2 and Rousette.  Both still
log user access to sysrepo, so no critical functionality is lost.

Follow-up to issue #542

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-28 19:14:47 +02:00
Joachim Wiberg 69e9cde1e9 doc: update project URL in motd and docs
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-28 19:14:47 +02:00
Joachim Wiberg 4c81ac978e confd: adjust Frr logging for staticd and ospfd
Ensure Frr logs to the local2 syslog facility to allow sorting all
Frr (staticd, ospfd) logs into a dedicated /var/log/routing log file.

We activate OSPF debugging, but keep log level at 'informational' for
the time being.  The YANG model needs some sort of "knob" to toggle
debug messages when troubleshooting OSPF.

Fixes #541

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-28 19:14:47 +02:00
Joachim Wiberg 8cafd6f568 board/common: disable all debug log messages from /var/log/syslog
Infix has the catch-all /var/log/debug, and now also /var/log/routing
for debug messages from Frr.

The log file /var/log/syslog now catches *all* messages except auth*,
which may contain secrets, except debug messages.  Contrast this with
/var/log/messages which only logs info/notice/warn -- i.e., no error
and above log messages.

Due to the way syslogd parses /etc/syslog.conf et al, we override the
default in Infix to disable the default /var/log/syslog, otherwise we
would get duplicates to the same log file.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-28 19:14:47 +02:00
Joachim Wiberg fb00719069 package/klish: bump for droprivs refactor of script plugin
As of KernelKit Klish @ 710a631 the script plugin has been refactored to
run all commands as the logged in user instead of as root.  The default
admin user is member of the wheel group, which allows access to sysrepo
and sudo access to containers thanks to NOPASSWD rights.

The doas script is a dummy wrapper to silence 'sudo -n' output for users
without any privileges.

As of this commit, unprivileged users can no longer copy, show, or in
any other way manipulate the system configuraiton.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-26 20:54:49 +02:00
Joachim Wiberg e912ca5d3b board/common: fix missing mkpasswd argument in askpass tool
Fixes #570

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-26 20:54:49 +02:00
Joachim Wiberg f0506c6cd5 package/skeleton-init-finit: drop log rotation from command line
With the latest sysklogd backports syslogd now supports log rotation
settings in the .conf files, which we'll add yang support for later in
this patch series.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-26 20:54:49 +02:00
Joachim Wiberg 5272f56827 board/common: add 'log' and 'follow' alias for displaying syslog
These changes mirror the changes made to the CLI in an attempt to create
a better user experience for working with log files even from the shell.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-26 20:54:49 +02:00
Joachim Wiberg 6d03e7ef3c src/klish-plugin-infix: fixes to 'dir' and 'show log' commands
These changes are designed to make the experience working with log files
easier.  Both listing available log files and viewing them.

 - replace C dir@infix with a shell script for easier extensions,
   e.g., we want to show both available .cfg and log files
 - add support for gunzipping .gz log files before viewing them

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-26 20:54:49 +02:00
Ahmed KaricandMattias Walström 241f3f224f board/common: introduce image test-mode
To support testing, the test-config.cfg file has been introduced in Infix.
Additionally, a "test mode" for the running image is required for this
configuration to be applied.

Basically the test-config will only be loaded when the device is in test mode,
which is determined by the presence of the /mnt/aux/test-mode file.
However, placing this file via the Qeneth system proved to be
inconvenient in the test environment. Therefore, it the entire image is
built in test mode, with the 'test-mode' file preloaded onto the disk
image (specifically in the auxiliary partition).
To support this, a new variable, (bool) DISK_IMAGE_TEST_MODE, has been
introduced:

 enabled: the image will be built in the test mode;
 disabled: the image will be built in the standard mode.

Part of issue #568
2024-08-26 13:59:49 +02:00
Tobias Waldekranz 6a7900c6d1 board/aarch64: styx: Source product data from VPD
In order for the probe logic to source product data from a VPD, it
must be marked as such. Otherwise we end up in a scenario where the
data is collected, but not hoisted up to the system level, leaving the
system without a defined base-MAC for instance.
2024-08-19 14:07:39 +02:00
Joachim WibergandTobias Waldekranz e8e9f7c0a1 board/aarch64/r2s: control WAN LED with a simple DHCP client monitor
When the interface is up and has a 'proto dhcp' address the WAN LED is
lit up.  When the interface goes down, or loses its DHCP lease, the LED
is turned off.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Joachim WibergandTobias Waldekranz af5169e286 board/aarch64/r2s: add u-boot factory-reset button detect
Allow reset button on the R2S to be used for factory reset at power-on.
See board README for details.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Joachim WibergandTobias Waldekranz 8353963b40 board/common: factory reset using shred and LED indication
This patch greatly improves the security of the Infix factory reset by
replacing 'rm' with 'shred'.  The shred tool overwrites the contents of
files three times.  With the -z and -u options the last pass writes
zeroes and then uninks the files.

On the NanoPi R2S the factory-reset now takes 24 seconds:

   Aug 11 16:00:34 infix mnt[121]: Resetting to factory defaults.
   Aug 11 16:00:58 infix mnt[173]: Factory reset complete.

A visual aid is also added, setting *all* LEDs to on, that can be found
mounted on the device, before starting the file shredders.  The LEDs are
reset back to off and SYS red blinking as soon as the wipe has completed
and iitod has been started.

Fixes #158

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Joachim WibergandTobias Waldekranz 9a67a95067 board/common: shellcheck, quote variables to prevent word splitting
Fixes to SC2086 mostly.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Joachim WibergandTobias Waldekranz 890d812b69 board/common: allow device specific compat strings for .pkg files
This patch allows us to define the rauc manifest compatibility string with
menuconfig.  The INFIX_IMAGE_ID is a direct replacement for the previously
composed "infix-$ARCH" in mkrauc.sh.

For example, the compatibility string "infix-aarch64" is replaced for the
NanoPi R2S with "infix-r2s" to ensure users get a proper warning if they
try upgrading to an image that maybe boots, but is not likely to work.

The CLI upgrade command gets a 'force' flag to override the compat string.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Joachim WibergandTobias Waldekranz df89b22062 board/aarch64/r2s: add support for reset button
This patch further cleans up the r2s kernel config and also enables the
input event framework for the gpio0 reset button on the device.

The very simple input-event-daemon is introduced, with the only purpose
of listening to /dev/input/event1 for KEY_RESTART and trigger reboot.

Some helpful tooling is also added to help debug events (evtest).

Issue #276

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Joachim WibergandTobias Waldekranz 4d90565838 board/aarch64/r2s: add static factory-config.cfg
This serves as an example of how a board specific builds in Infix can
carry a static factory-config.  This will be extended upon as we add
support for DHCP server, WiFi access point, and firewall support.

For now the following features are added:

 - Default hostname: r2s instead of infix-00-00-00
 - LAN port always at 192.168.2.1/24, IPv6 SLAAC enabled
 - WAN port has DHCP enabled for IPv4, IPv6 SLAAC disabled
 - NTP client enabled, default server pool.ntp.org
 - DHCP client is set up to request and allow ntp server

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Joachim WibergandTobias Waldekranz 01a4eedcad board/aarch64/r2s: map board LEDs to Infix system LEDs
The R2S has a minimal set of system LEDs, all of which are single color.
This commit tries to distill and map the essence of the Infix functions
to available LEDs.

The SYS LED is turned on (fainy red) at power-on, when U-Boot has loaded
the kernel it turns the SYS LED bright red on.  The idea is then to turn
the red SYS LED off as soon as the system has successfully loaded system
startup-config, and then turn the green LAN LED on.  Indicating that the
both the device is operational and that the user can connect to the LAN
port.

The WAN LED is given a "wan-up" input condition, with the intention of
turning it on (green) when the device has acquired a DHCP address.

The failure modes, which in many ways is the essence of Infix signaling,
are fail-safe and panic, triggered by loading failure-config, or failing
to loadd failure-config, respectively.  In fail-safe mode the SYS LED is
blinking red at 5 Hz and in panic mode *all* LEDs blink at 5 Hz.

Issue #276

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Joachim WibergandTobias Waldekranz 760e7d0683 board/aarch64/r2s: rename interfaces to match case and LEDs
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Joachim WibergandTobias Waldekranz fb41249a11 board: quick fix for too small primary/secondary on sd cards
With new features & fixes, Infix grows.  With the latest support for
rauc upgrades introduced with the VisionFive2, and now also for R2S,
we need to reserve room for future upgrades even when running from
an SD card.

This is a quick fix for genimge generated SD card imaages before we
get a proper installer in place that can be used both on the target
and host systems to partition and provision an eMMC, NVME, SSD, or
an SD card.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Joachim WibergandTobias Waldekranz 9b6dedbe08 board/aarch64/r2s: add README for the NanoPi R2S board
Fixes #275

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Joachim WibergandTobias Waldekranz 094a1ac4f1 board/aarch64/r2s: enable force check of package hashes
- Enable BR2_DOWNLOAD_FORCE_CHECK_HASHES for R2S
 - Relocate VisionFive2 patches to global patch dir for sharing with R2S
 - Add hash for ATF v2.9

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Joachim WibergandTobias Waldekranz 97eab18349 board/aarch64/r2s: allow saving U-Boot environment
This change allows modifying and saving the U-Boot environment to the
aux partition on the NanoPi R2S.  Required to able to safely maintain
multiple R2S devices on the same LAN.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Joachim WibergandTobias Waldekranz e7394a89d3 board/common: disable metadata checksumming for aux partition
U-Boot (2024.07) does not yet support the 'metadata_csum' feature flag
to Ext4 file systems.  So let's disable it for now in mkaux.sh so we
can allow builds for, e.g., the R2S and VisionFive2 boards to modify
and save their U-Boot environment.

Needed on the NanoPi R2S to set ethaddr + eth1addr since it does not
have any VPD EEPROM mounted.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Joachim WibergandTobias Waldekranz d2457baf2b board/aarch64/r2s: generalized secure boot support
- Bump kernel to 6.10.3
   - Initial defconfig sync with aarch64
     - Enable kprobes, ksyms, and function tracer
     - Enable missing file systems for parity with Infix
     - Enable bridging, netfilter, and other Infix requirements
     - Initial virtion support for running in Qemu (untested)
     - Enable device mapper, required for rauc bundle install
   - Make dummy and tunnel drivers modules to be able to drop dummy0
     and tunl0 interfaces that otherwise mess up "show interfaces"
   - Disable suspend and hibernation, not supported in Infix
   - Disable unused GPIO, PHY, MDIO, and USB drivers
   - Disable RK3328 watchdog driver, cannot perform reset on R2S,
     enablle softdog instead as a seamless replacement for Infix.
     Even though not optimal (since it's software) reboot works
   - Disable ethtool netlink support, does not work and breaks
     interface configuration completely on R2S!
   - Enable netdev LED triggers, for LAN and WAN LEDs
 - Bump u-boot to 2024.07
   - Hard code developer mode to allow shell access
   - Disable factory reset button support (not yet supported)
 - Bump ATF to v2.9
 - Enable squashfs for rootfs image
 - Enable signing of images
 - Add secondary partition
 - Add dedicated var partition
 - Add aux partition for signatures and uboot env

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Tobias Waldekranz 3da46f7249 uboot: Support overriding the interface used for netbooting Infix
For systems with multiple paths to the network, different situations
may call for different paths to be used. Therefore, allow the user to
override the active interface via the environment on the auxiliary
partition.

The default (defined the bootloader's device tree) is still used in
cases when nothing else is specified in the environment.
2024-08-12 14:48:14 +02:00
Joachim Wiberg fa1cece60f Follow-up to 2194f7be: migrate /libexec to /usr/libexec
For consistency with the / + /usr merge, see 2194f7be, let's move the
last remnants in /: /libexec/infix to /usr/libexec/infix

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-08 13:35:27 +02:00
Joachim Wiberg 2201543090 package/finit: add support for BR2_ROOTFS_MERGED_USR
Ensure Finit installs its files to /usr/lib/finit when building with the
merged-usr config option.  For consistency we adjust --exec-prefix, which
is the base for $libdir, meaning also /libexec is moved to /usr/libexec.

Finit tracks the paths internally, we only need to update runparts probe.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-08 13:35:27 +02:00
Joachim Wiberg 95519212be board/riscv64: add README for the VisionFive2 board
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-08 13:35:27 +02:00
Joachim Wiberg 28b1ffe2ae board/riscv64: generalized secure boot support
- Enable squashfs for rootfs image
 - Enable signing of images
 - Add secondary partition
 - Add mkaux.sh script

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-08 13:35:27 +02:00
Joachim Wiberg 32f4f37281 board/common: riscv64 is also a 64-bit platform
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-08 13:35:27 +02:00
Joachim Wiberg ce417dedd7 Finalize board support for StarFive VisionFive2
- Sync defconfig with aarch64
 - Sync linux_defconfig with aarch64
   - ethtool w/ netlink not supported yet for the StarFice dwmac
   - note, waaay too many unused drivers still
 - Add aux/cfg/var partitions to sdcard, no rauc support yet
 - Add factory-password-hash to device tree

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-08 13:35:27 +02:00
Joachim Wiberg 12d969ab0c confd: log PID in migration and prodoct probe scripts
Like other scripts already do, makes it easier to read syslog.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-08 13:35:27 +02:00