Commit Graph
3974 Commits
Author SHA1 Message Date
Joachim Wiberg 64aa3b544c package/klish-plugin-sysrepo: fix regression in release cycle
Fix regression in line-drawing characters, introduced in c38c8a4.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-27 14:04:45 +01:00
Tobias Waldekranz e0144ef9a3 board/aarch64: alder: Swap LED colors on 1G ports
On the P2's the only reasonable way (in terms of hardware patching
effort) of driving the LEDs is to have the green LEDs at the top and
the yellow ones at the bottom.
2023-11-27 12:31:58 +01:00
Tobias Waldekranz cf31a2642d board/aarch64: alder: Wire up IRQ to power board GPIOs
Turns out that the gpio-charger doesn't have polled fallback if the
GPIO pin can't function as an interrupt controller.

Fortunately, we have access to the IRQ pin, so we can just use that
for now and leave the driver as-is.
2023-11-27 12:31:58 +01:00
Tobias Waldekranz 1281edbee6 board/aarch64: alder: Swap VIN1/2 to match hardware 2023-11-27 12:31:58 +01:00
Joachim Wiberg 9415c0fb64 src/confd: drop /interfaces/interface/eth:ethernet config deviation
Drop this deviation for v23.11 since it clashes with pyang + NETCONFc client.
We expect to support configuration of speed+duplex in v23.12.

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-27 10:03:03 +01:00
Joachim Wiberg f679ed7191 Update documentation, interfaces interface foo -> interface foo
With the latest bump of klish-plugin-sysrepo we no longer need the extra
container name in commands and paths.

Also, update the "show interfaces" example in the top-level README.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-27 10:03:03 +01:00
Joachim Wiberg e73e9d75e1 package/klish-plugin-sysrepo: bump for container-list collapse
This adds support for collapsing container-lists where applicable.
E.g., 'edit interfaces interface eth0' -> 'edit interface eth0'.

Great care has been taken to not mess up when container-lists are
critical, like ipv4/ipv6 routes.

Fix #187

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-27 10:03:03 +01:00
Joachim Wiberg 2365ab273a klish-plugin-infix: minor, help help text
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-27 10:03:03 +01:00
Mattias WalströmandJoachim Wiberg 35aa7a37e1 Documentation for routing support 2023-11-27 10:03:03 +01:00
Tobias WaldekranzandJoachim Wiberg e1db5bad78 rauc: Start after D-Bus
On occasion, rauc has problems registering with D-Bus. Ensure that the
D-Bus daemon is running before starting rauc.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg be728accbb rauc: Remove unsupported argument from finit service stanza
Fixes: 0f410eb ("rauc: add support for tftp:// for bundles and syslog for logging")
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg 2da2e7fd5e confd: Fix failure-config generation when password is missing
Setting admin's password to "!" is not accepted by the model, which
means we end up in RMA mode, even in cases when a valid startup
exists.

Not supplying a password will cause confd to generate a locked
account, which is what we want.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg e53fd91c7f common: probe: Support default passwords on devicetree based systems
In addition to QEMU, we can now source the factory default password
from real VPD EEPROMs, on systems that use a devicetree.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg 17d1a529e8 common: qemu: Run without VPD by default
Infix will fallback to admin/admin on a QEMU system.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg 0a746a9795 common: qemu: Only create VPD if it does not exist
This let's you create a custom one to test out different scenarios
without it being clobbered by qemu.sh.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg b7cc0935ac common: qemu: Simplify VPD generation
Also, remove the "VBD" terminology. We will only emulate a single VPD
anyway.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg b5ba1602ec common: onieprom: Don't read more data than needed when decoding TLV
There's little point in reading a 32kB EEPROM do decode a 100B
TLV. Instead figure out how much we need to read from the header.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg 7679c4137e board/aarch64: alder: Tag VPD memories with board information
This is needed to make informed decisions about which hardware is
available, and what trust level it has.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg 42d4079c06 board/aarch64: alder: Remove old definition of DDR_TEN MPP
Fixes: b7aa560 ("board/aarch64: alder: Remap SFP9_RX_LOS and DDR_TEN MPPs")
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg cb0f8739ad kernel: Import latest kkit-linux-6.5.y
- Fixes the locking warnings when configuring LEDs on 6393X
- Correctly power up 3310X PHYs strapped to start powered down
- Fix kernel oops when reading from blank NVMEM configured with an
  ONIE layout
2023-11-25 20:37:15 +01:00
Joachim Wiberg 6c6ae844f3 board/netconf: allow default metric 0 for kernel + dhcp routes
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 14:29:56 +01:00
Joachim Wiberg 9655f98903 Fix #222: operational status b0rks on unknown route proto
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 14:29:16 +01:00
Joachim Wiberg 2be779718e Fix #221: set MFD_NOEXEC_SEAL flag on memfd
Silence kernel warning seems to be most secure option.  Also, set
MFD_CLOEXEC, because if we ever fork off a child it should never
get a copy of this fd.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 13:42:54 +01:00
Joachim Wiberg 748996dad8 Replace firmware with Linux OS, operating system, or software
We should avoid the use of the ambigous word 'firmware'.

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg b544778cfe doc: update CLI tutorial with a software upgrade section
Also, refresh the list of available commands.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg 56c3b4a880 doc: minor updates to the CLI online help text
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg 630a005bef cli: add 'show software' command
New command 'show software' to display software versions on each
partition, install date, and which one is currently booted.

admin@infix-00-00-00:/> show software
NAME      STATE     VERSION                DATE
primary   booted    v23.10.0-132           2023-11-23T22:24:33+00:00
secondary inactive  v23.10.0-132           2023-11-23T22:24:33+00:00

admin@infix-00-00-00:/> show software name primary
Name      : primary
State     : booted
Version   : v23.10.0-132-gfd6e8ea
Size      : 61992960
SHA-256   : ed6146aec462b77fb8631b14c48d281dd0f4fdb9c062f9482d863ee854081358
Installed : 2023-11-23T22:24:33+00:00

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg 23e4ca3f48 cli-pretty: whitespace fixup only
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg df76b4820f klish-plugin-infix: add 'upgrade' command to install software updates
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg 938c8aa8c5 klish-plugin-infix: update terse help text for basic commands
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg 0f410eb3b2 rauc: add support for tftp:// for bundles and syslog for logging
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim WibergandTobias Waldekranz c55d38df9a Use Kernelkit's IANA Enterprise Number
[skip ci]

Co-authored-by: Tobias Waldekranz <tobias@waldekranz.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg 9b1739283d confd: missing admin password, set error in /etc/issue & /etc/banner
The bootstrap script gets feedback from gen-admin-auth, on error we no
longer bail out but instead log the error and continue booting.  This
way a developer build with root login can diagnose the error.

When logging the error we also set /etc/issue, /etc/issue.net for local
and remote login services, as well as the dedicated /etc/banner used by
OpenSSH, to hold the error summary.  So when attaching to the console
port, or attempting to log in remotely with SSH, the error is printed
to indicate the device is not healthy.

Finally, since factory-config may be missing we need to bootstrap the
sysrepo db with something else, and fortunately we will always have a
failure-config to fall back on.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg f53f985dbc confd: do not fail if pwhash is missing in VPD, instead lock account
If pwhash is missing from system.json, lock account.  This allows for
more extensive diagnosis on developer builds with a root login.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg 8141cc13d1 confd: minor shellcheck fixes
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg fdaface79f probe: use fallback password hash also for qeneth (regression tests)
Break fallback hash to a separate function and allow gen_qemu_system_file()
to return the status.  We'd like to update the qeneth templates to include
the same VPD data as is used with qemu.sh, but for now this is sufficient.

The Qemu detection has been changed to the, slightly more, secure detection
of qemu_fw_cfg filesystem.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg ff12ba72b5 confd: exctract password also for failure-config
This patch adds generation of the 20-authentication.json snippet also
for failure-config.  The gen-admin-auth script is extended with shell
parameter, since the default shell differs from factory-config.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Richard AlpeandJoachim Wiberg 63a34d570d Use default pwd hash from VPD in QEMU
This commit does several things. Its end goal is to fetch the admin
password hash from VPD memory during factory bootstrap.

To accomplish this probe creates a new file /run/system.json with
information read from a fw_cfg QEMU partition. The data from
/run/system.json is then later used during config bootstrap to fill in
the factory administrator password.

The idea is to make QEMU behave the same way hardware does, i.e. a
default/factory password should be fetched and used from
"hardware memory". The hardware portion of this is yet to be done.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-24 08:55:57 +01:00
Richard AlpeandJoachim Wiberg 17093eba22 confd: disable admin login in failure config
Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-24 08:55:57 +01:00
Tobias Waldekranz 1e9cd310f8 board/common: Add self-provisioning scripts
This let's you netboot a system with a blank block device, and setup
all partitions, filesystems, images etc.
2023-11-23 12:18:28 +01:00
Tobias Waldekranz 252b894d55 rauc: Source service arguments from /etc/default, if available
This is need by upcoming provisioning scripts.
2023-11-23 12:18:28 +01:00
Tobias Waldekranz 98b9ca99cd defconfig: Build tools needed to self-provision Infix
Upcoming changes will add scripts to provision Infix to a blank block
device, which need these tools.
2023-11-23 12:18:28 +01:00
Tobias Waldekranz f258e030bd confd: Fix shellcheck warnings in gen-interfaces 2023-11-23 12:18:28 +01:00
Tobias Waldekranz 7f049db21f confd: Remove -6 option from gen-interfaces
With the behavior introduced in the referenced commit, port
interfaces (i.e. all ports on many systems) no longer get any SLAAC
address, leaving the user with no way of reaching the system.

Comment says this is by design, but that seems like an awkward
default.

Remove the option, and simplify gen_interfaces to either
- Enable SLAAC, if the port is not going to be part of any bridge, or
- Disabel SLAAC, if the port is going to be part of a bridge

If necessary, we can add an inverse option at a later date.

Fixes: d0f3960 ("confd: add -6 option to gen-interfaces for SLACC on port interfaces")
2023-11-23 12:18:28 +01:00
Tobias Waldekranz b7aa56071d board/aarch64: alder: Remap SFP9_RX_LOS and DDR_TEN MPPs
Layout changed from P1 to P2 becasue DDR_TEN must be connected to an
MPP with an internal pull-down, which MPP24 (old SFP9_RX_LOS) has.
2023-11-23 12:18:28 +01:00
Mattias Walström a0a80c8b77 Rename infix-routing to correct date
Should be 2023 not 2013.
2023-11-23 10:30:26 +01:00
Mattias Walström 37f7b5ba92 Add support for reading routing operational data for IPv4
In the CLI:
admin@infix-00-00-00:/> show routes
PREFIX                        DESTINATION                   PROTOCOL  METRIC
1.1.1.0/24                    e0                            kernel
192.168.100.0/24              1.1.1.1                       static    20
192.168.110.2/32              blackhole                     static    20
192.168.120.2/32              blackhole                     static    20
192.168.130.2/32              unreachable                   static    20
2023-11-23 10:30:26 +01:00
Jon-Olov VatnandJoachim Wiberg 6cfcf3ca10 Fixing and activating ieee802-ethernet yang deviations 2023-11-22 13:44:28 +01:00
Jon-Olov VatnandJoachim Wiberg 6669fee728 Draft infix deviations for ieee802-ethernet-interfaces
- Add deviations for non-supported statistics
- Limit config, currently we only have ro support
- Add deviations for non-supported configs and status leafs

[skip ci]
2023-11-22 13:44:28 +01:00
Joachim Wiberg 4bcac85e69 doc: helpful note to devs about re-enabling the root user for debug
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-22 12:04:05 +01:00