Commit Graph
176 Commits
Author SHA1 Message Date
Ahmed Karic 8bc7858694 Upgrade Linux kernel to 6.12.30 (LTS) 2025-05-22 18:28:23 +02:00
Mattias Walström 2303fc08aa Bump kernel to 6.12.28 (LTS) 2025-05-12 08:10:41 +02:00
Mattias Walström a0b06b2593 Upgrade kernel to 6.12.26 (LTS) 2025-05-02 10:51:36 +02:00
Richard Alpe ac89f94580 sysrepo: allow non-wheel users access to sysrepo data
Non-privileged users in the sys-cli group can now access sysrepo data.

The data is now solely protected by the NCAM rules and not Unix file
permissions. Any stray user that's not part of the (default) sys-cli
group still can't access syrepo, like users added from the shell.

Fixes #932

Signed-off-by: Richard Alpe <richard@bit42.se>
2025-04-28 15:41:09 +02:00
Mattias Walström 7a5c9d0324 Upgrade kernel to 6.12.25 (LTS)
Also backport some fixes for freescale-imx8mp-evk
2025-04-25 13:04:37 +02:00
Mattias Walström c6b44db18a statd: Move operational from confd to statd (yanger) 2025-04-23 13:45:48 +02:00
Mattias Walström 50f955c242 Upgrade linux kernel to 6.12.23 (LTS) 2025-04-10 15:21:36 +02:00
Mattias Walström b2525e29e1 Upgrade linux kernel to 6.12.22 (LTS) 2025-04-07 18:26:07 +02:00
Mattias Walström c7c2998e33 Require a valid sha256 checksum for all package downloaded 2025-04-07 16:57:17 +02:00
Richard Alpe c584af356b show: add new show tool written in python3
The reason for this is:
1) We want to use the same fetch tool for all operational data, to
   avoid having duplicated xpaths scattered across the repo.
2) We want to call this directly from the CLI, which means it need to
   be escape safe. A unprivileged user shall be able to use it but not
   escape into a shell or do other malicious stuff.

Signed-off-by: Richard Alpe <richard@bit42.se>
2025-04-07 09:06:26 +02:00
Mattias Walström 6bbf2d02a8 Upgrade linux kernel to 6.12.21 (LTS) 2025-03-30 21:40:43 +02:00
Mattias Walström f698d5f0ee Use prebuilt GO toolchain
Do NOT built it from source
2025-03-20 08:53:53 +01:00
Mattias Walström 4f54cbe975 Update kernel to 6.12.19 (LTS) 2025-03-13 13:31:54 +01:00
Mattias Walström 3f3fb4eeb4 Upgrade kernel to 6.12.18 (LTS) 2025-03-09 19:27:12 +01:00
Mattias Walström 1bbd62c021 Upgrade linux kernel to 6.12.17 (LTS) 2025-02-28 09:29:28 +01:00
Mattias Walström 7127caf6b5 Upgrade linux kernel to 6.12.16 (LTS) 2025-02-24 09:15:12 +01:00
Mattias Walström b4c648229a Update kernel to 6.12.14 (LTS) 2025-02-17 20:08:26 +01:00
Mattias Walström 05510c5001 Upgrade Linux kernel to 6.12.13 (LTS) 2025-02-09 15:40:22 +01:00
Mattias Walström 131c0b1d4b Update kernel to latest LTS (6.12.11) 2025-01-24 21:35:16 +01:00
Tobias Waldekranz f041d009b5 defconfig: all: Build mstpd 2025-01-08 09:57:55 +01:00
Mattias Walström 5608e9457d Move operational data about software state from confd => yanger
Statd is now responsible for operational, move last big part
(infix-system-software) to yanger.
2024-12-13 20:32:07 +01:00
Tobias Waldekranz ad32129a13 linux: Upgrade to 6.12.3 2024-12-06 08:22:10 +01:00
Tobias Waldekranz 88f7c6070a package/board: Let the user select the set of boards to support
Introduce a new approach to dtb-building:

Old way: `rsync` an overlay containing our dt source to the kernel,
and then build via buildroot's `_INTREE_DTS_NAME`. This does not work
in recent kernels (at least since 6.12), which requires all dtb's to
be explicitly listed in a `Makefile`.

New way: Create a separate package for every board, and build the
device trees via the kernel's standard interface for building external
modules. This has two main advantages:

1. We can easily interpose a patched version of an upstream device
   tree. E.g., we can easily set the factory password.

2. It is much easier to get an overview of which boards are enabled,
   rather than scrolling back and forth in the `_INTREE_DTS_NAME` list.

Enable all fully supported boards in the defconfigs.
2024-12-04 11:27:03 +01:00
Tobias Waldekranz a3f85a3872 linux: Upgrade to 6.12.1
Exploratory change to smoke out any regressions that this might
introduce.
2024-12-04 11:27:03 +01:00
Tobias WaldekranzandJoachim Wiberg 36d9056e8f board/common: Use finit's log: to capture output from containers
Since `conmon` only logs the output from the monitored container's
`stdout`/`stderr`, we might as well get rid of `k8s-logger`, and let
the output pass through to finit, which will then pipe the messages to
syslog.

Fix #836
2024-11-28 16:36:56 +01:00
Joachim Wiberg ca0e54b50b configs: drop execd from defconfigs, not needed anymore
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-11-28 16:36:56 +01:00
Joachim Wiberg 79d7e8bbab configs: allow aarch64 targets to save system clock to a file
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-11-04 11:10:53 +01:00
Joachim Wiberg 60b8f97ad6 package/test-mode: rename to confd-test-mode
Declare that confd-test-mode depends on confd, otherwise with 'select',
a call to `make update-defconfig` will remove BR2_PACKAGE_CONFD=y, which
we feel is very confusing -- in particular when comparing any defconfig
that does not have test-mode package.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-10-11 15:02:49 +02:00
Joachim Wiberg 8b75022696 configs: re-enable OpenSSL backend for libssh/libssh2
NETOPEER2 requries the OpenSSL backend of libssh.  By default, except on
minimal builds, is to use GCrypt backend.  Gcrypt is selected because of
Podman, which is not in the minimal builds.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-10-11 14:23:34 +02:00
Joachim Wiberg 374d24a547 configs: update and add LIBMNL to x86_64 targets
- Sync (make update-defconfig)
   - test-mode selects confd
   - gencert seclets openssl which in turn selects LIBSSH*_OPENSSL
   - rest is relocaations according to Config.in
 - Add LIBMNL to x86_64 targets, otherwise iproute2 does not install devlink

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-10-10 23:55:13 +02:00
Joachim Wiberg 458c1f8795 configs: include nftables container image in default builds
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-10-07 17:09:30 +02:00
Tobias Waldekranz 059e22c85f board/aarch64: styx: Update board name
Now that the name question has been settled, call the board by its
proper name. Provide symlinks to keep older bootloaders happy.
2024-09-30 09:28:08 +02:00
Mattias Walström aefaf94244 Bump linux kernel to 6.6.52 2024-09-25 11:32:45 +02:00
Tobias WaldekranzandJoachim Wiberg cbd615ec78 board/aarch64: styx: Revision B Support
The rewiring of the backplane in revision B necessitates two distinct
device trees.

Co-developed-by: Henrik Nordström <henrik.nordstrom@addiva.se>
2024-09-19 14:27:22 +02:00
Mattias Walström 710f6b82ce Upgrade linux kernel to 6.6.51 (LTS) 2024-09-16 12:43:33 +02:00
Mattias Walström 3c045460ef Add implementation to control test mode functions using an action
This intoduce a new sysrepo plugin to handle a new YANG
model 'infix-test'. Today only contains the actions.

This is required to run tests on infix using infamy.

This is a part of #561

Signed-off-by: Mattias Walström <lazzer@gmail.com>
2024-08-30 17:40:02 +02:00
Joachim Wiberg d05a64913e configs: drop pam_lastlog.so, does not rotate its log
The PAM plugin lastlog, previously used (optional) by Netopeer2 and
Rousette, does not rotate /var/log/lastlog, and since we don't have
cron and logrotate this can potentially fill up /var.

This patch disables pam_lastlog.so from the build and drops the two
matching session lines for both Netopeer2 and Rousette.  Both still
log user access to sysrepo, so no critical functionality is lost.

Follow-up to issue #542

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-28 19:14:47 +02:00
Joachim WibergandTobias Waldekranz a1ac456d08 configs: enable pam_lastlog.so
Backport pam-lastlog build fix from latest Buildroot master and enable
in all defconfigs to fix syslog warning:

   login[2819]: PAM unable to dlopen(/lib/security/pam_lastlog.so)

Fixes #542

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-16 16:47:28 +02:00
Mattias Walström 8d6bf14937 Upgrade kernel to 6.6.46 2024-08-16 16:32:22 +02:00
Mattias Walström 2194f7bebe Merge /usr/* directories into /
/usr/bin  -> /bin
/usr/sbin -> /sbin
/usr/lib  -> /lib
2024-08-06 11:15:38 +02:00
Joachim Wiberg c7c21b3f6e buildroot: bump to v2024.02.4 LTS
Adjust defconfigs after revert of OpenSSL engines before .4 release.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-08-02 22:51:21 +02:00
Joachim Wiberg ffb3af5533 buildroot: bump for security fixes
- OpenSSH CVE-2024-6387

 - GLIBC-SA-2024-0004:
     ISO-2022-CN-EXT: fix out-of-bound writes when writing escape
     sequence (CVE-2024-2961)

 - GLIBC-SA-2024-0005:
     nscd: Stack-based buffer overflow in netgroup cache (CVE-2024-33599)

 - GLIBC-SA-2024-0006:
     nscd: Null pointer crash after notfound response (CVE-2024-33600)

 - GLIBC-SA-2024-0007:
     nscd: netgroup cache may terminate daemon on memory allocation
     failure (CVE-2024-33601)

 - GLIBC-SA-2024-0008:
     nscd: netgroup cache assumes NSS callback uses in-buffer strings
     (CVE-2024-33602)

Please note, with this bump it is required to enable the new OpenSSL
option BR2_PACKAGE_LIBOPENSSL_ENGINES, otherwise libssh will not build.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-07-11 02:47:02 +02:00
Joachim Wiberg 10744c5116 board/common: extract YANG documentation for all builds
This change builds on top of the earlier work to bootstrap Infix YANG
modules at build time.  Adding a step at the end of post-build.sh to
call the yangdoc tool.  The resulting yangdoc.html is a stand-alone HTML
file of (almost) all YANG nodes.  Almost because some top-level nodes
are unused by Infix atm. and have been filtered out for readability.

Fixes #432

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-06-28 12:54:27 +02:00
Joachim Wiberg 3cbafd8ef4 confd: add supoprt for yescrypt
Fixes #447

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-06-25 17:22:36 +02:00
Mattias Walström ac70c6bffc kernel: Upgrade kernel to 6.6.34 2024-06-19 15:35:51 +02:00
Joachim WibergandMattias Walström 37506bcdd9 configs: enable rousette for RESTCONF support
Sync after `make update-defconfig`:

 - avahi selected by mdns-alias package (all)
 - iptables and ca-certs selected by other packages (r2s)

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-06-04 13:38:03 +02:00
Mattias Walström 44465b679f Add C.UTF-8 locale
Required by rousette
2024-06-04 13:38:03 +02:00
Mattias WalströmandJoachim Wiberg 06742cf825 kernel: Upgrade to 6.6.31 2024-05-22 12:01:30 +02:00
Joachim WibergandMattias Walström 23dc237403 Switch to PAM for system authentication
- Add sshd 'UsePAM yes'
 - Buildroot automatically adds and enables:
   - /etc/pam.d/ with authentication for login, sshd, and sudo
   - PAM support in BusyBox login

Also, prepare for adding RADIUS authentication support to ietf-system
the only tricky part is testing against a RADIUS server.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-15 16:06:08 +02:00
Joachim WibergandMattias Walström 6a8eaacc6e Replace python + rust based gencert2 with C based gencert3
Also, sync r2s_defconfig with latest major changes.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-05-03 15:33:00 +02:00