Commit Graph
1081 Commits
Author SHA1 Message Date
Richard AlpeandJoachim Wiberg d6152ce6ea cli: add graceful error for missing json in cli-pretty
Print a graceful error message if the json data is missing of invalid.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-17 18:17:59 +02:00
Richard AlpeandJoachim Wiberg 1a3105c06d cli: pretty print existing Ethernet frame stats
Pretty print all Ethernet frame statistics from the operational
datastore. Only in the detailed interface view.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-17 18:17:59 +02:00
Richard AlpeandJoachim Wiberg 14dc3cf8a0 statd: add ethtool frame counters to op datastore
This patch adds the framework for reading ethtool statistics and
inserting it into the operational datastore.

The ethtool data we rely on is "group data" such as "eth-mac" or
"rmon".

This data can be displayed using:
ethtool --json -S e0 --all-groups

The "group data" is still missing for most common drivers, so testing
this will require a firmware which has support for it.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-17 18:17:54 +02:00
Joachim Wiberg 9292231674 .github: switch to ncipollo/release-action for latest build
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-17 18:08:07 +02:00
Joachim Wiberg 52023e918a confd: regenerate factory-config if factory-config.gen is missing
Regenerate if either factory-config.gen or failure-config.gen is missing.
This should not happen, but is better to check for the result rather than
the intermediate result.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
latest
2023-10-17 16:32:41 +02:00
Joachim Wiberg c6fae88268 Fix #166: drop SSDP entirely from Infix
mDNS-SD was added in Windows 10 Creators Update[1] (build 1703), relased
April 11, 2017.  This makes SSDP no longer critical for finding an Infix
device in Windows, both ping infix-01-02-03.local and using Chrome work.

Since all major operating systems now support mDNS-SD[2] we've decided
to standardize on that and LLDP for Infix and its derivatives.  Other
reasons for dropping it include, but is not limited to: lack of IPv6 in
the implementation we use, and potential security implications[3].

[1]: https://en.wikipedia.org/wiki/Windows_10,_version_1703
[2]: https://techcommunity.microsoft.com/t5/networking-blog/mdns-in-the-enterprise/ba-p/3275777
[3]: https://blog.cloudflare.com/ssdp-100gbps/

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-17 16:32:41 +02:00
Joachim Wiberg aa655abdc7 Fix #159: hacky generation of /etc/resolv.conf at boot
To be able to run "resolvconf -u" at boot we need dnsmasq up and running
and startup-config having been loaded successfully.  (No point when we
hare in fail secure mode.)

If this bugs out it can be pinpointed by an empty /etc/resolv.conf

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-17 13:26:26 +02:00
Joachim Wiberg cefe24c467 confd: support mixed bridge/router use-case in inteface generator
Fix #160

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-17 13:26:26 +02:00
Joachim Wiberg b4d760906f .github: disable actions by default [skip ci]
Enable actions by setting local variables in your fork of Infix.

Fix #170

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-17 13:26:26 +02:00
Joachim Wiberg acecbe7e5d Allow custom image filename being set in menuconfig
This adds support for the two /etc/os-release variables:

 - IMAGE_ID
 - IMAGE_VERSION

The former is configurable, with fallback to name-arch, and the latter
is only set for relase builds.  During releae builds the release will
be appended to the image name.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-17 13:26:26 +02:00
Joachim WibergandGitHub f6acc44104 doc: add Integration section [skip ci]
Detail operational experience with integrating 3rd party software, PROFINET.
2023-10-17 13:20:11 +02:00
Henrik NordstromandJoachim Wiberg 7b09b2524d greenpak-programmer: Bump to v1.1 which adds LICENSE.txt 2023-10-16 15:07:03 +02:00
Henrik NordstromandJoachim Wiberg 62131528ba Use single-word for CONFIG_PACKAGE.. bool 2023-10-16 15:07:03 +02:00
Henrik NordstromandJoachim Wiberg 5eb25e968b Add greenpak-programmer package 2023-10-16 15:07:03 +02:00
Joachim Wiberg 1698c6645c Disable bridge multicast snooping (IGMP/MLD) by default
The Marvell mv88e6xxx switch driver currently used in active projects do
not support multicast router ports properly yet.  Considering that Infix
do not yet have YANG support for configuring IGMP/MLD snooping, we have
decided to disable it in bridge setups by default.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-13 13:38:09 +02:00
Joachim Wiberg 830c885c2e confd: minor, fix comment
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-13 12:50:02 +02:00
Joachim Wiberg 17b6c234c1 confd: fix copy-paste error in runtime condition [skip ci]
We should only call 'error' in case loading failure-config fails, not if
loading startup-config fails. Unclear how this passed testing, must have
been a last minute change that got untested.

Found during integration in customer's br2-external.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 17:22:49 +02:00
Joachim Wiberg b44e303775 board/common: basic feature probe
Currently does not need any conditions, but may later need to check for
loaded modules and other capabilities.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 16:35:00 +02:00
Joachim Wiberg 3a3274c371 confd: ensure "word splitting" otherwise gen-interfaces fails
Overzealous shellcheck application lead to gen-intefaces not creating a
bridge when GEN_IFACE_OPTS was uncommented in /etc/confdrc

Verified in customer br2-external.

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 14:56:00 +02:00
Joachim Wiberg 46bd3df13e board/common: fix string comparison operator [skip ci]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 14:28:18 +02:00
Joachim WibergandTobias Waldekranz 138c9f3378 Update board/common/mkgns3a.sh
As @wkz says, better to use this construct if/when we add more archs.

[skip ci]

Co-authored-by: Tobias Waldekranz <tobias@waldekranz.com>
2023-10-12 11:22:55 +02:00
Joachim Wiberg 8c20bb2829 configs: enable disk image and update metadata for /etc/os-release
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 11:22:55 +02:00
Joachim Wiberg 606b87b4b3 configs: sync aarch64 classic build with changes from cbaa599 & C:o
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 11:22:55 +02:00
Joachim Wiberg 230c2adae7 board/common: rename disk.img and update .gns3a
- Create per-arch unique distribution file names
 - Source .gns3a information from /etc/os-release

Instead of attempting to create unique file names by hard-coding an
'infix-' prefix and extracting the "board" or "arch" part from the
defconfig, let's use the branding information from /etc/os-release
along with $BR2_ARCH.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 11:22:55 +02:00
Joachim Wiberg 09d48b35ee board/common: parameterized branding using menuconfig
This makes it possible for projects using Infix as a br2-external to
override lots of OS-specific strings and contact information that
previously was hard coded.

The generated /etc/os-release now takes most of its data from .config
Worth noting is the changes in VERSION and BUILD_ID fields.  The former
will be INFIX_RELEASE, during release builds, and the latter is always
the output from `git descibe ...`, or rather GIT_VERSION.  This variable
can be overloaded as well.

See the help text and the new doc/branding.md document for details.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 11:22:55 +02:00
Joachim Wiberg f2e30943ee board/common: generate images/Config.in and reduce x86 ram
The default arch and disk image filename needs to be generated
to be unique per, at least, each architecture build.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 11:22:55 +02:00
Joachim Wiberg f852afc9c6 Enable GNS3 appliance file for all builds
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 11:22:55 +02:00
Joachim Wiberg c6d4fbf341 board/common: generate a simplified .gns3a for aarch64 builds
Due to problems with using u-boot as loader¹ we decided to start the
system by calling the kernel image directly.  The downside to that is
that, even though RAUC upgrades would work, the kernel would remain
the same.

Improvements to this are of course welcome.

________
¹) Must extract the built-in .dtb and merge with the Qemu .dtb at runtime
   to be able to boot primary (or secondry) image.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 11:22:55 +02:00
Joachim Wiberg b40484e262 board/common: fix load_cfg key=value extraction
Calling `load_cfg BR2_EXTERNAL_INFIX_PATH` from post-image.sh caused
warnings due to multiple hits in the .config file:

post-image.sh: 12: /tmp/tmp.5a3xhQQVc8: BR2_EXTERNAL_INFIX_PATH: not found
post-image.sh: 13: /tmp/tmp.5a3xhQQVc8: BR2_EXTERNAL_INFIX_PATH: not found

Let's grep for a "key.*=" instead of "key" to drop those warnings, while
still acting as a catch-all for partial matches.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-12 11:22:55 +02:00
Richard AlpeandJoachim Wiberg 7d8b876cc7 cli: handle missing oper-status
Use known data from .self to avoid crashing if the oper-status is
missing for a interface.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-12 10:10:30 +02:00
Jon-Olov VatnandJoachim Wiberg fdcc6d35a4 Doc: Fixing hostname in examples
Fixing hostname to state admin@example where this was missed.
And some typos.
2023-10-11 13:17:11 +02:00
Jon-Olov VatnandJoachim Wiberg 2c21943ebf Doc: Updating IP address config examples after origin fixes
Fixes to IPv6 address origin (type 'random' rather than 'other')
now reflected in documentation.
Also using 'admin' instead of 'root' user in examples.
2023-10-11 13:17:11 +02:00
Tobias WaldekranzandJoachim Wiberg 2f1c383602 board/aarch64: alder: Initial add
- Device tree
- Enable needed drivers
- Include in aarch64_defconfig
- 88X3310P Firmware
2023-10-10 14:54:50 +02:00
Tobias WaldekranzandJoachim Wiberg 5f37b8acd3 board/aarch64: Build kernel and modules with debug info
This costs nothing on target, and it means that we always have debug
symbols ready when we need them, without having to do a complete
rebuild.
2023-10-10 14:54:50 +02:00
Tobias WaldekranzandJoachim Wiberg 5891c0f2b3 board/aarch64: Build all network related drivers as modules
As we may need to load firmware to the PHYs, we can't load those
modules until we have access to the rootfs. In order for that to work,
the MDIO driver must not be built-in, as that will cause the kernel to
bind devices with missing (built-in) drivers to bind to the genphy
driver.

Therefore, build everything as modules and let udev load it during
boot.
2023-10-10 14:54:50 +02:00
Tobias WaldekranzandJoachim Wiberg 7d1580ca21 board/common: nameif: Make switch port marking more robust
Let's operate on JSON data, so that we're less vulnerable to output
changes in devlink.
2023-10-10 14:54:50 +02:00
Tobias WaldekranzandJoachim Wiberg c5eed505fe board/common: Add convenience macros 'hd' and 'llping'
'hd':
    Hexdump, in canonical format

'llping':
    Ping any IPv6 neighbors using the link-local all-nodes group

    Usage: llping <IFACE>
2023-10-10 14:54:50 +02:00
Tobias WaldekranzandJoachim Wiberg cbaa599c68 aarch64: Use DTS overlay directory
Now that buildroot supports overlay directories for DT sources, use it
in the aarch64 build.
2023-10-10 14:54:50 +02:00
Tobias WaldekranzandJoachim Wiberg a485f15468 buildroot: DTS overlay directories 2023-10-10 14:54:50 +02:00
Tobias WaldekranzandJoachim Wiberg 558c2a40ee kernel: Bump to 6.5.6 + kkit-linux-6.5.y
In order get the ONIE EEPROM support and some mv88e6xxx related fixes,
move to 6.5.6, with the intention of upgrading again, to the next
longterm kernel, as soon as one becomes available.

Also, import patches from kkit-linux-6.5.y.
2023-10-10 14:54:50 +02:00
Joachim WibergandTobias Waldekranz db1d7f41e7 confd: rename Finit sysrepo.conf -> confd.conf
Everything else is named confd, even syslog messages are logged as
confd, and we've talked about not using sysrepo-plugind one day, so
let's prepare for a world where everthing is like that.

Also, and even more importantly, fix the sysrepo-plugind condition.
We cannot use <pid/syslogd>, because it can be restarted and thus
consequently Finit will stop sysrepo-plugind.  This first caused a
bit of head scratching because it cause a lot of very odd errors in
the execution of sysrepo-plugind, transactions being abruptly aborted
for instace.

Whatt we can do, however, is use a static condition, which Finit has
support for since a few releases now.  We want to guard the start of
our sysrepo-plugind service behind YANG /usr/libexec/confd/bootstrap.
So we can use <run/bootstrap/success>.  In case the bootstrap fails,
we catch that in the row before using if:<run/bootstrap/failure> to
trigger the /usr/libexec/confd/error script (described previously).

The other run/task/services can be guarded behind <pid/confd> and now
everything suddenly makes sense.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-09 10:41:46 +02:00
Joachim WibergandTobias Waldekranz 787955d877 confd: add error handling in case of failed bootstrap or load
- New script 'error' that can be overridden by a br2-external
 - Call 'error' if YANG model bootstap or factory-config.gen fails
 - Call 'error' if loading startup-config or failure-config fails

The 'error' script calls syslog¹ to log the error messge:

    The device has reached an unrecoverable error, please RMA.
____
¹ to get a timestamp log message, and send remote in case a
  br2-external has somehow hard-coded network for remote syslog

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-09 10:41:46 +02:00
Joachim WibergandTobias Waldekranz f357b1df3b confd: log [PID] to syslog
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-09 10:41:46 +02:00
Joachim WibergandTobias Waldekranz ca9daef15a confd: add support for generating /cfg/failure-config.cfg
This rather huge change is a refactor of the factory-config generataion to add
support for also generating a failure-config.

The confd bootstrap script has been given an rc file.  This both eases manual
testing, when modifying the script(s), and also makes it easier to override
from a br2-external.  Infix default is router/end-device, but a br2-external
may be a switch firmware and want to default to all ports in a bridge.

The generated failure-config creates a fail-safe "do no harm" config to boot
with in case startup-config for some reason is broken or cannot be applied,
e.g., bug in confd.  Meaning, for both the router and switch use-cases the
device will start up with all interfaces isolated¹, with an IPv6 SLAAC (EUI64)
address per interface.

Services enabled in this fail-safe mode are: LLDP, mDNS/SD, SSH, and NETCONF.
All to facilitate diagnostics, troubleshooting and device recovery.

Other noteworthy changes include:

 - rename factory/failure directories again -> factory.d/failure.d.  Use
   same naming as we do on target for directories holding generated files
 - The bootstrap script no longer regenerates /cfg/factory.d on each boot
 - The bootstrap script copies all static templates to /cfg/factory.d in
   case a newer image changes the contents of them.  For troubleshooting
 - Support for overriding the 20-interfaces.json generation by br2-external
 - Support for additional 30-config.json (ovrride/extend) by br2-external
 - Expand gen-interfaces to support bridge use-case.
_____
¹ For a switch this means "no switchport", i.e., no switching between ports
  otherwise connected to a switchcore (or bridge) in startup-config.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-09 10:41:46 +02:00
Joachim WibergandTobias Waldekranz 3e48af6c36 confd: relocate auto-factory templates and prepare fail secure mode
The template and scripts for generating per-device factory-config have
been spread out across the repo.  This is an attempt to gather all the
pieces to a single location for better overview.

Parts of factory-config will be reused for the new fail secure mode, in
the file failure-config.  The beginnings of which are in this commit.

Other changes:
 - cfg-bootstrap and confd-bootstrap have been collapsed into one
 - let gen-hostname + gen-interfaces save to /cfg instead of /etc,
   we've moved the /etc directory to read-only storage in /usr/share
 - delay start of bootstrap and sysrepo-plugind after syslogd barrier
 - set 'norestart' when loading startup-confg and failure-config,
   no point in retrying if that fails, just go to error immediately

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-09 10:41:46 +02:00
Joachim WibergandTobias Waldekranz b7c4c251ca board/common: Finit dbus.conf override behind <pid/syslogd>
This ensures dbus is not started before any udevadm call has completed.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-09 10:41:46 +02:00
Joachim WibergandTobias Waldekranz 5bad7f472f Guard system critical bootstrap services behind <pid/syslogd>
This ensures they do not start earlier than the system log daemon.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-09 10:41:46 +02:00
Joachim WibergandTobias Waldekranz fd366e78f6 package/skeleton-init-finit: rename condition set by sysklogd -> syslogd
The sysklogd and BusyBox syslogd can not run at the same time.  Since they
provide the same service we standardize on them providing <pid/syslogd>.

Also, ensure syslogd does not start until the fifth udevadm has completed.
This creates a barrier preventing other run/task/services from starting
too early.  Thus guaranteeing a proper boot order.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-09 10:41:46 +02:00
Joachim WibergandTobias Waldekranz 0103b1a491 Ensure /bin/sh is a plain POSIX shell (BusyBox /bin/ash)
This commit fixes a regression introduced in 15572e9e where /bin/bash
was unintentionally set as the defalt /bin/sh in the system. This cause
several warnings and errors when a Bash-based /bin/sh tries to sources
/etc/profile because $SHELL identifies it as /bin/bash.

The ietf-system.yang model, with the infix-system.yang extensions,
declare a per-user SHELL that allow /bin/clish, /bin/bash, /bin/sh
and /bin/false.  There should be a clear distinction between them.

This change also helps us keep bashisms away.  If a script needs
Bash features, declare: #!/usr/bin/env bash

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-09 10:41:46 +02:00
Joachim WibergandTobias Waldekranz 11c157116b sec: drop sulogin and disable rescue mode in Finit (NETCONF)
This commit drops sulogin from BusyBox, as well as the Finit replacement,
in the NETCONF builds.  The classic builds retain the Finit sulogin.

Furthermore, the Finit rescue mode is disabled (which uses sulogin), so
in case of trouble at boot, e.g. missing fstab or failure to fsck, the
system will no longer go to sulogin but instead log error to console and
reboot.

  NOTE: the bootloader still needs to be locked down, otherwise a user
        could just as easily change kernel cmdline to 'shell=/bin/sh'

Misc. reshuffle and defaults updated are due to make foo-update-defconfig.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-09 10:41:46 +02:00