Commit Graph
701 Commits
Author SHA1 Message Date
Joachim WibergandTobias Waldekranz 0df778a5f6 confd: fix custom mac support for veth interfaces
This patch adds support for setting the mac address already when
creating veth interfaces.  Necessary to cooperate with containers.

Fixes #453

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-18 09:58:19 +02:00
Joachim WibergandTobias Waldekranz 0a7f8ce216 confd: always create factory bridges with multicast snooping enabled
The confd `gen-interfaces` script is called for some customers with a
default to create a bridge with all, or a subset of all, ports.  The
safe default, which incidentally coincides with the same customer's
requirements, is to have IGMP/MLD snooping enabled by default.

Fixes #454

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-18 09:58:19 +02:00
Joachim WibergandTobias Waldekranz 9d7817356f statd: support for enabling DEBUG() logs with env, like confd
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-13 11:42:27 +02:00
Joachim WibergandTobias Waldekranz aa20f29b36 confd: fix missing /etc/resolv.conf after 'no system'
When a CLI user performs the following command, the DNS resolver was
left in an undefined state.

    admin@infix-00-00-00:/config/> no system
    admin@infix-00-00-00:/config/> leave
    admin@infix:/>

The avahi-daemon reported the missing /etc/resolv.conf and the fix is to
ensure `resolvconf -u` runs on every major change ot ietf-system, even
if there is no new resolv.conf to roll in.  At bootstrap this has been
handled by another mechanism so has not been seen by most users.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-13 11:42:27 +02:00
Joachim WibergandTobias Waldekranz c6b818d0bc confd: fix error handling for sr_get_data()
The sr_get_data() API may return SR_ERR_OK and still set the cfg pointer
to NULL!  This happens when, e.g., executing 'no system' from the CLI.

This patch adds a check for this in all occurrences of sr_get_data().

Also, in ietf-routing.c there was *no* error handling for this API, this
required some restructuring to ensure a FILE *fp was closed properly in
all cases.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-13 11:42:27 +02:00
Joachim WibergandTobias Waldekranz 89c9a12db2 confd: on failure to load startup-config, reset and regroup
With the sysrepo patch from the previous commit, we can now properly
detect if a callback failed to apply its changes in SR_EV_DONE.  When
this occurs the system may be in an undefined state, so we must try
to recover it before loading failure-config.

This patch tries to perform a factory-default RPC, which is an Infix
specifc RPC that does "copy factory-config running-config".  We give
sysrepocfg some time to clean up any stale SHM connections before we
do a hard scratch of the db state and restart sysrepo-plugind.

Fixes #429

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-13 11:42:27 +02:00
Joachim WibergandTobias Waldekranz d0cfe429c4 confd: fix regression, loss of admin account after upgrade to v24.04
Fix regression introduced in 3f87945, which tries to map a user to an
existing home directory.  The root cause for the problem is basically an
invalid check of the /home/admin UID being in use by any system account
or not.  This patch uses the same check used by the BusyBox adduser
command.

In addition to the uid-already-in-use fix, several other checks have
been added to ensure we do not end up with an invalid system state:

 - If reusing an existing /home/admin fails in the 'adduser admin'
   command, wipe out /home/admin and retry adding the user cleanly
 - Always delete any group with the same name before trying to add
   the user, regardless if /home/$user exists or not, this prevents
   issues with stale group records if we end up failing to load the
   startup-config and need to load failure-config
 - For the same reason (failure-config), make sure to always clean
   up any stale user in the retry step.  The same step is used when
   there is a uid:gid mismapping (the original bug)

Fixes #428

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-13 11:42:27 +02:00
Joachim WibergandTobias Waldekranz adf37394f4 confd: follow-up to 2412fff3, simplify chown of startup-config
Instead of having a chown process started by Finit in runlevel S, we can
just chown in the confd load script instead.

Issue #415

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-13 11:42:27 +02:00
Joachim WibergandTobias Waldekranz ad8a74fa7b confd: minor, fix variable shadowing
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-13 11:42:27 +02:00
Joachim WibergandTobias Waldekranz 3315a46423 confd: minor, skip shell update when deleting user
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-13 11:42:27 +02:00
Joachim WibergandTobias Waldekranz 334d222f7c confd: minor, logging cleanup
- Drop unnecessary \n
 - Drop needless ERROR() message triggered when deleting users

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-13 11:42:27 +02:00
Joachim WibergandTobias Waldekranz d624203815 confd: minor, match syslog tag with other log messages
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-13 11:42:27 +02:00
Joachim WibergandTobias Waldekranz ab21eff6c8 confd: minor, use initial hostname from /etc/os-release as fallback
Instead of hard-coding the fallback hostname we can now use the one
generated to /etc/os-release (for netbrowse).

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-13 11:42:27 +02:00
Joachim Wiberg f5b0f37386 confd: rename 10-infix-system.json -> 10-infix-services.json
Mislabled from the start, the file holds default services.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-05 18:20:03 +02:00
Joachim WibergandMattias Walström 39f868fc61 gencert: C replacement for python+rust gencert
Smaller, fewer dependencies, and quicker to cross-compile.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-03 15:33:00 +02:00
Joachim WibergandMattias Walström 71e63de0c1 execd: minor, drop dummy line from configure summary
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-03 15:33:00 +02:00
Joachim WibergandTobias Waldekranz 9609fc144d confd: add timestamps to dagger .log files
Sample output:

    root@infix-00-00-00:~# cat /run/net/0/action/init/lo/45-init.sysctl.log
    May 02 13:45:58 net.ipv6.conf.lo.autoconf = 1
    May 02 13:45:58 net.ipv6.conf.lo.dad_transmits = 1
    May 02 13:45:58 net.ipv6.conf.lo.temp_prefered_lft = 86400
    May 02 13:45:58 net.ipv6.conf.lo.temp_valid_lft = 604800
    May 02 13:45:58 [exit:0]

Fixes #374

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-03 07:54:48 +02:00
Joachim WibergandTobias Waldekranz a0df130852 board/common: relocate dagger script to confd tree
The dagger tool is a helper for scripts generated by confd and should
therefore be installed by confd instead of the rootfs overlay.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-03 07:54:48 +02:00
Joachim WibergandTobias Waldekranz 22c911f85e package/landing: new package
Relocate the default landing page from the rootfs overlay to a package
so that customer repos can override it.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-03 07:54:48 +02:00
Joachim WibergandTobias Waldekranz 0629022b1f confd: minor, adjust log levels and drop duplicate log messages
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-30 15:51:17 +02:00
Joachim WibergandTobias Waldekranz dee36ce801 confd: fix mDNS service type generation
In the 34fa6a3 refactor we lost announcement of mDNS completely:

 - The type of all services was set to 'all', instead of, e.g., _ssh._tcp
 - The web console service was not added properly
 - Web services for plain HTTP/HTTPS were not created at all

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-30 15:51:17 +02:00
Joachim WibergandTobias Waldekranz 3f87945f75 confd: map new users to existing home directories
UNIX home directories are persistent across reboots, but user accounts
are not.  If multiple users exist in startup-config and one or more are
removed, we must use the UID of their $HOME on the next reboot to ensure
they do not lose their files.

If a home directory exists and its UID is already in /etc/passwd we have
triggered an unsupported use-case and must remove the home directory on
disk before recreating it empty.  This should not happen, but may occur
on upgrades from a time before UIDs started at 1000 and instead shared
the UID range with reserved system accounts.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-30 15:51:17 +02:00
Joachim WibergandTobias Waldekranz fbeeed7a2c confd: refactor add/remove user from UNIX sysadmin group (wheel)
In review discussions we've decided to go for Augeas to modify the file
/etc/group instead of relying on the BusyBox tools adduser and delgroup,
which check for the existence of the user in /etc/passwd -- which we, at
the point in time the NACM callback runs, cannot guarantee.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-30 15:51:17 +02:00
Joachim WibergandTobias Waldekranz b03db7f994 confd: disable shell for non-admin users
A user that is not part of the 'admin' group may only have /bin/false or
/bin/clish as login shells for ssh/console.  Any POSIX shell is reserved
for administrators.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-30 15:51:17 +02:00
Joachim WibergandTobias Waldekranz 26820111f7 confd: add basic support for nacm
This patch adds basic NACM support to detect users assigned to a group
granting full access privileges.  Full privileges require membership of
at least one group listed in an ACL rule with:

   module-name=*
   access-operations=*
   action=permit

This matches the `admin-acl` rule in factory-config, which the 'admin'
group is part of, and in turn the 'admin' *user* is a member of.

Also, drop unused guest and limited ACLs from factory-config.  Added
from the RFC as an example, but is likely more confusing than helpful.

Note: this does not add all NACM groups to the system, it maps users
      with administrator privileges to the UNIX 'wheel' group, which
      grants access to all IPC sockets (klish, finit, mctl), and sudo
      access to all other parts of the system.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-30 15:51:17 +02:00
Joachim WibergandTobias Waldekranz e395c90958 confd: create admin user without -S flag to adduser
After the upgrade to Buildroot 2024.02 a new system user was added to
/etc/passwd, sshd.  Used for drop-privs sshd.  This caused files that
were previously owned by the 'admin' user to now be owned by 'sshd'.

This patch drops the `-S` flag from adduser for the adin user, ensuring
no future clashes with system system users and instead mapping the uid
to a range starting from uid 1000 (default for BusyBox adduser).

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-30 15:51:17 +02:00
Tobias Waldekranz 5e2475c742 confd: Avoid needless Ethernet flow-control reconfigurations
Unless some configuration has changed that affects flow-control (only
auto-neg for now, until we allow actual configuration of flow-control
itself), do not issue any commands that might trigger a link down/up
cycle.

Additionally, make sure that we always configure it on boot, as the
driver defaults might not necessarily line up with our defaults.
2024-04-29 14:31:40 +02:00
Tobias Waldekranz 824b911f49 confd: Unify determination of Ethernet auto-negotiation config
As detailed in the block comment in iface_uses_autoneg(), we make some
special considerations around this, so make sure we always reach the
same conclusion.
2024-04-29 14:31:40 +02:00
Joachim WibergandTobias Waldekranz 66ae2eb2e8 Update src/confd/src/ietf-interfaces.c
Co-authored-by: Tobias Waldekranz <tobias@waldekranz.com>
2024-04-29 14:31:40 +02:00
Joachim WibergandTobias Waldekranz 0f7983008e confd: allow admin user to send factory reset rpc using sysrepocfg
Fixes #416

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-29 14:31:40 +02:00
Joachim WibergandTobias Waldekranz 2412fff39c confd: ensure correct ownership of startup-config after factory reset
Fixes #415

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-29 14:31:40 +02:00
Joachim WibergandTobias Waldekranz 809e6b44be confd: spellcheck infix-hardware.yang
Fixes #414

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-29 14:31:40 +02:00
Joachim WibergandTobias Waldekranz 7c7b9ee1f6 confd: fix missing support for globally disable dhcp client
Fixes #412

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-29 14:31:40 +02:00
Joachim WibergandTobias Waldekranz 8a007d61d0 Disable Ethernet flow-control completely by default
We have previously stated configuration and status flow-control as not
supported, see infix-ethernet-interface.yang.  This is also the default
for flow-control in the ieee-ethernet-interface.yang model.

This patch change the actual value to disabled, so that devices properly
advertise flow-control as disabled/not-supported in auto-negotiation.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-29 14:31:40 +02:00
Joachim WibergandTobias Waldekranz c3a227289d confd: allow setting factory hostname from qemu_fw_cfg
This patch adds support for overriding the default hostname generation
on Qemu systems with the /sys/firmware/qemu_fw_cfg/by_name/opt/hostname
file.  E.g., virtual Infamy test systems using Qeneth.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-29 08:44:44 +02:00
Joachim WibergandTobias Waldekranz e59bab16c0 confd: set mcast_vlan_snooping and correct IGMP/MLD versions
As described in issue #396, multicast filtering on VLAN filtering
bridges did not work at all.  This because bridge_mcast_settings()
exited when no global multicast settings were found -- a change to
the YANG model made previously triggered this fauled behavior.

Also, the initial IGMP/MLD versions were set to 2/1 (kernel default)
instead of 3/2 (Infix default).

Fixes #396

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-29 08:44:44 +02:00
Joachim Wiberg c3900ec710 confd: allow VLAN interfaces as bridge ports
Fixes #406

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-25 09:20:32 +02:00
Mattias Walström 8c9c432847 Add a new packet python-statd
Actually a part of statd, but had to make
a separarate package to get it to work.

Statd helper-scripts are now pre-compiled instead of doing it
in runtime.

Fixes #379
2024-04-16 12:47:16 +02:00
Mattias Walström 4f40db6ee8 confd: Infer VID when create a VLAN interface called vlan<vid>
This fixes #391
2024-04-16 12:47:16 +02:00
Mattias Walström 82236b7f5a confd: Fix memory leak on candidate config changes 2024-04-16 12:47:16 +02:00
Mattias Walström 5e9975f4c9 YANG: Allow any name for a routing protocol instance
Remove old limitation that only allow default

Fixes #369
2024-04-16 12:47:16 +02:00
Joachim Wiberg 9605252be8 package/mdns-alias: replace with lightweight C daemon
The replacement is a complete rewrite in C using the Avahi client API.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 34fa6a327d confd: refactor, stop announcing netbrowse cname when disabled
Refactor mDNS service record generation for improved control of
announcing services.  All to add support for modifying the cname
aliases we announce.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 551f1ae548 libsrx: two new helpers, unquoute() and fgetkey()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 76c8c69231 confd: refactor, relocate mdns record generation to infix-services
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 4ad2948b9b confd: add deviation for /system/hostname, max 64 chars on Linux
Both IETF and POSIX allow longer hostname, 253 and 255, which Linux does
not support.  Since Linux 1.0 the maximum has been 64 US-ASCII characters.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 0c0b7f0532 confd: introduce secondary/monitor change callbacks
These callback are not the primary responisble for the property, but
want to be informed of any changes.  E.g., /system/hostname changes
should also update the adminurl in all mDNS records.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 4ae641d65f confd: refactor services stop/start and add web netbrowse
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg da67ea3695 libsrx: factor out new function lydx_vdescend()
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg b3bb8a3075 confd: enable/disable nginx servers using available/enabled symlinks
Relocate all nginx .conf files to board/common/rootfs/etc/nginx/ and
introduce available/*.conf with symlinks to enabled/*.conf

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00