Commit Graph
650 Commits
Author SHA1 Message Date
Joachim Wiberg d1fe3b1311 confd: generate mDNS service records on hostname changes
This commit implements Infix mDNS TXT records, version 1, for available
services.  Hard coded for the moment.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg b33294950f netbrowse: prestudy of available txt records, use adminurl for Infix
This commit includes a small prestudy, done over a period of two weeks,
to gather information about common txt records used by hosts.  The most
well-documented is the Apple Printing Spec, which among other things
defines adminurl.  A proposed version 1 of the Infix txt record spec is
included in the document.  I'm recommending alternative 2:

"vv=1" "vendor=Qemu" "product=VM" "ty=x86-64" "vn=KernelKit" "on=Infix" "ov=v24.03.0"

Including this information would enable quickly scanning a network to
see if the latest version of the software has been deployed.  Please
note, I've not included the U-Boot firmware version in this proposal,
but it could be included as "vs=2023.10-kkit3", or similar.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 92d3db46a7 netbrowse: convert to gunicorn and factor out mdns-alias app
Converting to gunicorn, which is the recommended production server for
Flask apps, means app main() function is no longer called at startup, so
we have to factor out the mDNS CNAME functionality for infix.local and
network.local to a separate app.

We take this opportunity to collapse the structure, move non-class
methods to __init.py__, and rename the AvahiAlias class.  A prototype
for replacing the overhead of mdns-alias with a C daemon is in its
early stages.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 5d128d74f5 netbrowse: migrate from setup.py to pyproject.toml
This change also requires another restructure for netbrowse itself, hence
the relocation of files in the tree.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg d2b370b44d netbrowse: open links to mDNS hosts in new tab
Also, disable debug logging.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg eef60de999 netbrowse: add cool little favicon
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 83d18eb988 netbrowse: convert to jinja2 templates and address review comments
- Convert to use jinja2 templates instead of HTML/CSS inline
 - Address review comments:
   - Support for a foldout of details with link being key
   - Support for a Show All checkbutton
 - Styling and neat background by kjpargeter[1]

[1]: https://www.freepik.com/free-vector/network-connections-background_2533758.htm

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 64d63c08df netbrowse: convert to flask
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 282e7b08a3 netbrowse: drop misc services, keep http/https, ssh/sftp, netconf
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg bff0417be8 confd: reload netbrowse on hostname changes
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg c1836af7cc package/netbrowse: new package
- Advertises the build-time $hostname.local as a CNAME to the A and
   AAAA records already advertised by Avahi
 - Advertises a special network.local CNAME and provides a fastcgi
   service on unix:/tmp/netbrowse.sock for browsing mDNS services

This commit also activates netbrowse by default with nginx listeing
to port 80 on IPv4 and IPv6 /browse by default but also / if called
with server name network.local.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 1a99118a78 cli: ensure admin user can scp to & from /cfg/startup-config.cfg
With an increase in requests to confine users to the CLI, access using
SSH/SCP/SFTP to the configuration is becoming more and more important.
The admin role in Infix is mapped to the UNIX group 'wheel', meaning we
want all users in that group to be able to read and write files with
that ownership.

This patch fixes the initial ownership of startup-config, and /cfg, and
ensures the copy command in the CLI retain wheel group permissions.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-15 15:36:41 +02:00
Joachim Wiberg 280190ac24 confd: drop redundant (and wrong) strlcpy(), found by Coverity Scan
The new strdupa() code handles copying the new->xpath.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-12 07:54:05 +02:00
Joachim Wiberg 140379190c confd: fix segfault when calling 'no dhcp-client'
Fixes #384

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-11 06:19:07 +02:00
Joachim Wiberg 512da8c3f3 package/keyack: add missing license file
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-11 06:19:07 +02:00
Mattias WalströmandJoachim Wiberg cc8221a22a Refactor cli-pretty for show bridge mdb 2024-04-09 20:22:26 +02:00
Joachim Wiberg 50359b0808 statd: filter mdb entries per vid *and* bridge
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-09 20:22:26 +02:00
Joachim Wiberg a48edc74d8 statd: always use mctl -p (plain) output mode
The plain output mode prevents garbled JSON output due to the built-in
pretty-printer in mctl.  Fixed in v2.1

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-09 20:22:26 +02:00
Joachim Wiberg c7e8b8f33d confd: bump infix-if-bridge version and add revision
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-09 20:22:26 +02:00
Mattias WalströmandJoachim Wiberg 320410b950 yanger: Allow manufactering date to be day 1-9
When the day of month is 1-9 the format did not match the
yang model
2024-04-06 13:00:13 +02:00
Mattias WalströmandJoachim Wiberg f9e9822b52 Implement MDB and IGMP status in operational 2024-04-05 15:34:21 +02:00
Mattias Walström 81745a1625 Add configuration of static multicast entries
Both L2 and L3 is supported.

With VLAN-filtering:
admin@infix-00-00-00:/config/interface/br0/> set bridge vlans  vlan 1  multicast-filter 224.1.3.4 ports e0

Without VLAN-filtering:
admin@infix-00-00-00:/config/interface/br0/> set bridge multicast-filter 224.1.2.3 ports e0
2024-04-04 17:27:11 +02:00
Mattias Walström c7ab09cb73 infix-if-bridge: Major refactor regarding multicast
- Rename mdb -> multicast-filters
- Add support for L2 multicast groups
- Change vlan, multicast and mulitcast-filters containers to presence
  containers. This will result in that snooping will be disabled when
  creating a bridge (or a vlan if vlan-filtered)
- Force the user to choose between VLANs and Multicast on top level bridge configuration
- Force L2 multicast to be state permanent
2024-04-04 17:27:11 +02:00
Joachim Wiberg 3c75608839 klish-plugin-infix: allow absolute UNIX paths in copy command
If an absolute path contains '../' we disallow it because what are you
doing, possible security violation.

Built-ins for running, startup, etc. remain as-is.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg 1dcbea52b9 confd: handle ip/route additions to container networks at runtime
On any change to a container network interface we should schedule a
restart of the container to activate the changes.  This code triggers
also at boot, when applying the whole startup-config, which initctl
handles by queuing any create/touch events for services.

This patch depends on the two previous commtis backporing fixes to
Finit's initctl tool and an upgrade of the k8s-logger.

Fixes #375

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg 596edd23aa confd: minor, whitespace
Add whitespace for readability, and as hinted by in the kernel coding style.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg 761fae8d03 confd: fix "no bridge-port" regression from 4bfedf7a9
In 4bfedf7a9 support for disabling IPv6/IPv4 link-local addresses was
added, which in turn caused this regression.

Regression in the v24.03 release cycle, not released -- low severity.

Fixes #353

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg 84c28aab00 src: ensure 'make dep' is called first for 'make check'
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg 528671c4cd confd: save updated system time also to RTC
Fixes #367

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg d112f0bb29 statd: xlate LOWER-LAYER-DOWN -> LOWER-DOWN in CLI "show interfaces"
Translate LOWER-LAYER-DOWN -> LOWER-DOWN in "show interfaces" overview
and keep LOWER-LAYER-DOWN in detailed "show interfaces name eth0".

Issue #358

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg b400a6aaa9 statd: restore MAC address for bridges in CLI "show interfaces"
Fixes #358

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg fad75575e4 confd: add limited support for container capabilities
This change adds limited support for container capabilities.  It allows
a more fine-grained control than priviliged mode does.

Fixes #365

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg 662719a47f confd: fix static routes from container host interfaces (static)
In a host interface setup, i.e., moving an interface from the host to a
container, often using VETH pairs, any route should only be set when an
IP address has been set.  This because the CNI ipam plugin, which we
use, require routes be part of ipam, which in turn requires an address.

For details, see <https://www.cni.dev/plugins/current/ipam/static/>

Fixes #366

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-04-03 16:08:37 +02:00
Joachim Wiberg b6d661e40b confd: fix invalid printf argument, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-23 09:54:23 +01:00
Joachim Wiberg 12ab32c9d2 confd: fix resource leak, found by Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-23 09:54:01 +01:00
Joachim WibergandTobias Waldekranz e140d5917a klish-plugin-infix: add "show ip multicast" command
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-22 13:15:35 +01:00
Joachim WibergandTobias Waldekranz c16f8890a5 confd: adapt bridge multicast support to mcd v2.0
All querier functionality for IGMP now handled by mcd, even if there are
no VLAN interfaces on top of the bridge.  Also, mcd now handles unique
query interval per interface, or per VLAN, so we no longer need multiple
daemons running.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-22 13:15:35 +01:00
Joachim WibergandTobias Waldekranz a4176ce4d0 klish-plugin-infix: fix copy-paste in "show bridge vlan" command
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-22 13:15:35 +01:00
Joachim WibergandTobias Waldekranz 3ebbd0bf4f confd: handle small changes to bridge port properties
This patch adds support for small incremental changes to bridge ports.
Changes where the libyang diff does not include a bridge reference so
that it will have to be synthesized from the current configuration.

For example, forgetting to set a port's PVID in a VLAN filtering bridge
setup, changing a bridge port's multicast flooding properties, or any
other per-bridge-port setting after the fact.

Fixes #349.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-22 13:15:35 +01:00
Joachim WibergandTobias Waldekranz ce2e15e4d2 libsrx: new function, traverse the void to find an interface
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-22 13:15:35 +01:00
Mattias Walström d9ffff2b5a cli-pretty: Refactor to not take model as argument
Instead focus on the task to do 'show hardware', 'show interfaces' and more,
this to make it more logical.
2024-03-18 16:32:18 +01:00
Tobias Waldekranz 8fa910e8d9 klish-plugin-infix: Prettify 'show ip brief'
- Version sort interfaces ("e2" is listed before "e10")
- Remove "@dsa" from switch interfaces
2024-03-13 11:01:15 +01:00
Tobias Waldekranz 4e93e35c86 statd: cli-pretty: Version sort interfaces
Before this change:

e1
e10
e2
...
e9

After this change:

e1
e2
...
e9
e10
2024-03-13 11:01:15 +01:00
Joachim Wiberg 049f8d18f9 confd: only start mcd if there is a VLAN upper on the bridge
Temporary fix to prevent odd log messages.  The fix is to add RAW VLAN
support to mcd so it can run as a proxy querier even if there is no
upper VLAN interface or IP address.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-13 10:24:02 +01:00
Joachim Wiberg 7230c3532a confd: improve bridge port validation for VLAN filtering bridges
This patch adds validation of bridge port VLAN memberships and IP
addressing for VLAN filtering bridges:

  1. Ports must be a member of this bridge
  2. Ports cannot be tagged and untagged member at the same time
  3. A VLAN filtering bridge does not support IP addressing

A VLAN filtering bridge can only be a tagged member of a VLAN.  Any IP
addressing needs to be done using an upper VLAN interface.

NOTE: while technically possible break up these long must expressions
      into multiple must expressions per node (split at 'and'), it will
      break libyang in interesting ways that in turn make the confd
      inference functionality stop working.  E.g., creating VETH pairs.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-13 10:24:02 +01:00
Joachim Wiberg 21fd1e9442 Fix #328: drop default value for bridge-port PVID
A bridge port in a VLAN filtering bridge should be possible to configure
as "tagged only", i.e., to not assign ingressing untagged frames a VLAN
and instead drop them.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-13 10:24:02 +01:00
Joachim WibergandTobias Waldekranz b4690f3850 statd: skip container interfaces in status output, for now
This patch prevents statd from failing and logging errors on interfaces
currently in another network namespace.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-12 09:26:23 +01:00
Joachim WibergandTobias Waldekranz 8ca2d74566 confd: ensure we always return cni status
This patch fixes a runtime error triggered by modifying an interface
currently used by a container.  The CNI code must always return the
CNI status (reserved for container or not).

How to trigger:
 - Create veth pair
 - Make one end container-network and add to container
 - Leave
 - Return to configure and set an IP address on container interface
 - Leave - BOOM

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-12 09:26:23 +01:00
Joachim Wiberg 6f185cdfb5 confd: refactor gen-interfaces for hybrid bridge/iface setups
Simplify interface generation by collapsing eth_ and ethlike_ifaces to a
single list.  Let gen_iface_json() determine interface type by querying
each interface.  This allows us to create bridge setups also for qemu
use-cases.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-11 14:37:49 +01:00
Joachim Wiberg ad9060e99c confd: minor, grammar fix
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-10 11:37:17 +01:00