mirror of
https://github.com/kernelkit/infix.git
synced 2026-07-27 11:13:02 +02:00
Compare commits
25
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f6f6381eaf | ||
|
|
e5754b4001 | ||
|
|
6838cc9c25 | ||
|
|
d869f6c478 | ||
|
|
f37d29aa21 | ||
|
|
982a754472 | ||
|
|
931ae71019 | ||
|
|
c69a617ecb | ||
|
|
c79beea4ec | ||
|
|
cf1e81c8d1 | ||
|
|
e04937a0f7 | ||
|
|
e838f6dfd8 | ||
|
|
7ccddc086b | ||
|
|
fb9a1fa1a5 | ||
|
|
386ca9618e | ||
|
|
abe571d32c | ||
|
|
131177f3c9 | ||
|
|
c3d396b5fe | ||
|
|
b341d37267 | ||
|
|
cbe8315508 | ||
|
|
a5687bda7f | ||
|
|
8fac3720fb | ||
|
|
a4715debe8 | ||
|
|
da06ca14d4 | ||
|
|
9946357285 |
@@ -167,8 +167,8 @@ APIs.
|
||||
[0]: https://www.kernel.org
|
||||
[1]: https://buildroot.org/ "Buildroot Homepage"
|
||||
[2]: https://www.sysrepo.org/ "Sysrepo Homepage"
|
||||
[3]: https://kernelkit.org/infix/latest/cli/introduction/
|
||||
[4]: https://kernelkit.org/infix/
|
||||
[3]: https://www.kernelkit.org/infix/latest/cli/introduction/
|
||||
[4]: https://www.kernelkit.org/infix/
|
||||
[5]: https://github.com/kernelkit/infix/releases
|
||||
[Latest Build]: https://github.com/kernelkit/infix/releases/tag/latest "Latest build"
|
||||
[License]: https://en.wikipedia.org/wiki/GPL_license
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
config BR2_PACKAGE_ALDER_ALDER
|
||||
bool "Alder"
|
||||
depends on BR2_aarch64
|
||||
select BR2_PACKAGE_LINUX_FIRMWARE_INSIDE_SECURE_MINIFW
|
||||
help
|
||||
Alder
|
||||
|
||||
@@ -262,8 +262,8 @@ make aarch64
|
||||
./utils/mkimage.sh -odt emmc bananapi-bpi-r3
|
||||
```
|
||||
|
||||
[0]: https://kernelkit.org/posts/flashing-sdcard/
|
||||
[1]: https://kernelkit.org/infix/latest/
|
||||
[0]: https://www.kernelkit.org/posts/flashing-sdcard/
|
||||
[1]: https://www.kernelkit.org/infix/latest/
|
||||
[2]: https://github.com/kernelkit/infix/releases/download/latest-boot/infix-bpi-r3-sdcard.img
|
||||
[3]: https://github.com/kernelkit/infix/releases/download/latest-boot/infix-bpi-r3-emmc.img
|
||||
[4]: https://github.com/kernelkit/infix/releases/download/latest-boot/bpi-r3-emmc-boot-2025.01-latest.tar.gz
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
config BR2_PACKAGE_MARVELL_CN9130_CRB
|
||||
bool "Marvell CN9130-CRB"
|
||||
depends on BR2_aarch64
|
||||
select BR2_PACKAGE_LINUX_FIRMWARE_INSIDE_SECURE_MINIFW
|
||||
help
|
||||
Customer Reference Board for CN9130
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
config BR2_PACKAGE_MARVELL_ESPRESSOBIN
|
||||
bool "Marvell ESPRESSObin"
|
||||
depends on BR2_aarch64
|
||||
select BR2_PACKAGE_LINUX_FIRMWARE_INSIDE_SECURE_MINIFW
|
||||
help
|
||||
Marvell ESPRESSObin
|
||||
|
||||
@@ -312,13 +312,13 @@ While capable of basic routing tasks, be aware of limitations:
|
||||
For applications requiring multiple ports or high performance, consider
|
||||
dedicated networking hardware like the [Banana Pi R3][12].
|
||||
|
||||
[0]: https://kernelkit.org/posts/flashing-sdcard/
|
||||
[1]: https://kernelkit.org/infix/latest/
|
||||
[0]: https://www.kernelkit.org/posts/flashing-sdcard/
|
||||
[1]: https://www.kernelkit.org/infix/latest/
|
||||
[2]: https://github.com/kernelkit/infix/releases/download/latest-boot/infix-rpi64-sdcard.img
|
||||
[3]: https://kernelkit.org/infix/latest/container/#content-mounts
|
||||
[4]: https://kernelkit.org/infix/latest/scripting-restconf/
|
||||
[3]: https://www.kernelkit.org/infix/latest/container/#content-mounts
|
||||
[4]: https://www.kernelkit.org/infix/latest/scripting-restconf/
|
||||
[8]: https://github.com/kernelkit/infix/releases/tag/latest-boot
|
||||
[9]: https://kernelkit.org/infix/latest/networking/#wifi
|
||||
[9]: https://www.kernelkit.org/infix/latest/networking/#wifi
|
||||
[10]: https://www.raspberrypi.com/products/raspberry-pi-touch-display/
|
||||
[11]: https://www.raspberrypi.com/documentation/
|
||||
[12]: https://kernelkit.org/infix/latest/hardware/#banana-pi-bpi-r3
|
||||
[12]: https://www.kernelkit.org/infix/latest/hardware/#banana-pi-bpi-r3
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
config BR2_PACKAGE_STYX_DCP_SC_28P
|
||||
bool "Styx DCP-SC-28P"
|
||||
depends on BR2_aarch64
|
||||
select BR2_PACKAGE_LINUX_FIRMWARE_INSIDE_SECURE_MINIFW
|
||||
help
|
||||
Styx DCP-SC-28P
|
||||
|
||||
@@ -112,5 +112,5 @@ Connect a USB-to-serial adapter to the board's debug UART header.
|
||||
> [!WARNING]
|
||||
> Use only 3.3V serial adapters.
|
||||
|
||||
[0]: https://kernelkit.org/posts/flashing-sdcard/
|
||||
[0]: https://www.kernelkit.org/posts/flashing-sdcard/
|
||||
[1]: https://www.microchip.com/en-us/development-tool/EV21H18A
|
||||
|
||||
@@ -91,5 +91,5 @@ Serial settings: 115200 8N1
|
||||
> [!WARNING]
|
||||
> Use only 3.3V serial adapters. 5V adapters will damage your Raspberry Pi!
|
||||
|
||||
[0]: https://kernelkit.org/posts/flashing-sdcard/
|
||||
[0]: https://www.kernelkit.org/posts/flashing-sdcard/
|
||||
[1]: https://www.raspberrypi.com/products/raspberry-pi-2-model-b/
|
||||
|
||||
@@ -12,7 +12,7 @@ cat <<EOF >"${gns3a}"
|
||||
"category": "router",
|
||||
"description": "${ARTIFACT} development appliance",
|
||||
"vendor_name": "Kernelkit",
|
||||
"vendor_url": "https://kernelkit.org",
|
||||
"vendor_url": "https://www.kernelkit.org",
|
||||
"product_name": "${ARTIFACT} devel",
|
||||
"registry_version": 6,
|
||||
"status": "experimental",
|
||||
|
||||
@@ -50,7 +50,7 @@ The default credentials for the demo builds is
|
||||
Password:
|
||||
.-------.
|
||||
| . . | Infix OS — Immutable.Friendly.Secure
|
||||
|-. v .-| https://kernelkit.org
|
||||
|-. v .-| https://www.kernelkit.org
|
||||
'-'---'-'
|
||||
|
||||
Run the command 'cli' for interactive OAM
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
.-------.
|
||||
| . . | Infix OS — Immutable.Friendly.Secure
|
||||
|-. v .-| https://kernelkit.org
|
||||
|-. v .-| https://www.kernelkit.org
|
||||
'-'---'-'
|
||||
|
||||
@@ -23,7 +23,8 @@ dir=""
|
||||
all=""
|
||||
env=""
|
||||
port=""
|
||||
force=
|
||||
force=${force:-}
|
||||
reset_volumes=
|
||||
|
||||
# Variable shared across subshells
|
||||
export meta_sha=""
|
||||
@@ -227,7 +228,7 @@ fetch()
|
||||
|
||||
if out=$(eval "$cmd" 2>&1); then
|
||||
log "$file downloaded successfully."
|
||||
if check "$file"; then
|
||||
if [ -n "$force" ] || check "$file"; then
|
||||
echo "$dst"
|
||||
return 0
|
||||
fi
|
||||
@@ -897,6 +898,9 @@ while [ "$1" != "" ]; do
|
||||
shift
|
||||
restart=$1
|
||||
;;
|
||||
-R | --reset-volumes)
|
||||
reset_volumes=true
|
||||
;;
|
||||
-s | --simple)
|
||||
simple=true
|
||||
;;
|
||||
@@ -1108,7 +1112,8 @@ case $cmd in
|
||||
# Remove the old image if it's not used by any other containers
|
||||
if [ -n "$old_image_id" ]; then
|
||||
# Check if the old image is still in use by any containers
|
||||
if ! podman ps -a --format '{{.ImageID}}' | grep -q "^${old_image_id}$"; then
|
||||
old_image_id=${old_image_id:0:12}
|
||||
if ! podman ps -a --format '{{.ImageID}}' | grep -q "^${old_image_id}"; then
|
||||
log "Removing old image $old_image_id"
|
||||
podman rmi "$old_image_id" 2>/dev/null || true
|
||||
else
|
||||
@@ -1250,8 +1255,22 @@ case $cmd in
|
||||
container stop "$name"
|
||||
echo "done"
|
||||
|
||||
# If --reset-volumes requested, delete named volumes so they re-initialize from new image
|
||||
if [ -n "$reset_volumes" ]; then
|
||||
printf ">> Resetting named volumes (all configuration will be lost): "
|
||||
grep -oE -- '-v [^ ]+' "$script" | awk '{print $2}' | cut -d: -f1 | \
|
||||
while read -r vol_name; do
|
||||
if podman volume exists "$vol_name" 2>/dev/null; then
|
||||
printf "%s " "$vol_name"
|
||||
log "Removing volume $vol_name"
|
||||
podman volume rm -f "$vol_name" >/dev/null || true
|
||||
fi
|
||||
done
|
||||
echo "done"
|
||||
fi
|
||||
|
||||
# Set force flag to ensure fresh pull/fetch of image
|
||||
force="-f"
|
||||
export force="-f"
|
||||
|
||||
# For remote images, force re-pull
|
||||
case "$img" in
|
||||
@@ -1273,14 +1292,17 @@ case $cmd in
|
||||
# Recreate container by running the script
|
||||
echo ">> Recreating container ..."
|
||||
if ! "$script"; then
|
||||
force=
|
||||
echo ">> Failed recreating container $name"
|
||||
exit 1
|
||||
fi
|
||||
force=
|
||||
|
||||
# Remove the old image if it's not used by any other containers
|
||||
if [ -n "$old_image_id" ]; then
|
||||
# Check if the old image is still in use by any containers
|
||||
if ! podman ps -a --format '{{.ImageID}}' | grep -q "^${old_image_id}$"; then
|
||||
old_image_id=${old_image_id:0:12}
|
||||
if ! podman ps -a --format '{{.ImageID}}' | grep -q "^${old_image_id}"; then
|
||||
log "Removing old image $old_image_id"
|
||||
podman rmi "$old_image_id" 2>/dev/null || true
|
||||
else
|
||||
|
||||
@@ -27,7 +27,7 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.14"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.16"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -41,9 +41,6 @@ BR2_PACKAGE_DBUS_CXX=y
|
||||
BR2_PACKAGE_DBUS_GLIB=y
|
||||
BR2_PACKAGE_EUDEV_RULES_GEN=y
|
||||
# BR2_PACKAGE_EUDEV_ENABLE_HWDB is not set
|
||||
BR2_PACKAGE_GPSD_DEVICES="/dev/gps0"
|
||||
BR2_PACKAGE_GPSD_MAX_CLIENT_VALUE=2
|
||||
BR2_PACKAGE_GPSD_MAX_DEV_VALUE=1
|
||||
BR2_PACKAGE_GPTFDISK=y
|
||||
BR2_PACKAGE_GPTFDISK_SGDISK=y
|
||||
BR2_PACKAGE_MDIO_TOOLS=y
|
||||
@@ -143,10 +140,10 @@ BR2_PACKAGE_MARVELL_CN9130_CRB=y
|
||||
BR2_PACKAGE_MARVELL_ESPRESSOBIN=y
|
||||
BR2_PACKAGE_RASPBERRYPI_RPI64=y
|
||||
BR2_PACKAGE_STYX_DCP_SC_28P=y
|
||||
INFIX_VENDOR_HOME="https://kernelkit.org"
|
||||
INFIX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
INFIX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://kernelkit.org/infix/"
|
||||
INFIX_DOC="https://www.kernelkit.org/infix/"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_FEATURE_GPS=y
|
||||
BR2_PACKAGE_FEATURE_WIFI_MEDIATEK=y
|
||||
|
||||
@@ -27,7 +27,7 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.14"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.16"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -41,9 +41,6 @@ BR2_PACKAGE_DBUS_CXX=y
|
||||
BR2_PACKAGE_DBUS_GLIB=y
|
||||
BR2_PACKAGE_EUDEV_RULES_GEN=y
|
||||
# BR2_PACKAGE_EUDEV_ENABLE_HWDB is not set
|
||||
BR2_PACKAGE_GPSD_DEVICES="/dev/gps0"
|
||||
BR2_PACKAGE_GPSD_MAX_CLIENT_VALUE=2
|
||||
BR2_PACKAGE_GPSD_MAX_DEV_VALUE=1
|
||||
BR2_PACKAGE_GPTFDISK=y
|
||||
BR2_PACKAGE_GPTFDISK_SGDISK=y
|
||||
BR2_PACKAGE_MDIO_TOOLS=y
|
||||
@@ -121,12 +118,11 @@ BR2_PACKAGE_MARVELL_CN9130_CRB=y
|
||||
BR2_PACKAGE_MARVELL_ESPRESSOBIN=y
|
||||
BR2_PACKAGE_RASPBERRYPI_RPI64=y
|
||||
BR2_PACKAGE_STYX_DCP_SC_28P=y
|
||||
INFIX_VENDOR_HOME="https://kernelkit.org"
|
||||
INFIX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
INFIX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://kernelkit.org/infix/"
|
||||
INFIX_DOC="https://www.kernelkit.org/infix/"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_FEATURE_GPS=y
|
||||
BR2_PACKAGE_CONFD=y
|
||||
BR2_PACKAGE_NETD=y
|
||||
BR2_PACKAGE_CONFD_TEST_MODE=y
|
||||
|
||||
@@ -28,7 +28,7 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.14"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.16"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/arm/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -43,9 +43,6 @@ BR2_PACKAGE_DBUS_CXX=y
|
||||
BR2_PACKAGE_DBUS_GLIB=y
|
||||
BR2_PACKAGE_EUDEV_RULES_GEN=y
|
||||
# BR2_PACKAGE_EUDEV_ENABLE_HWDB is not set
|
||||
BR2_PACKAGE_GPSD_DEVICES="/dev/gps0"
|
||||
BR2_PACKAGE_GPSD_MAX_CLIENT_VALUE=2
|
||||
BR2_PACKAGE_GPSD_MAX_DEV_VALUE=1
|
||||
BR2_PACKAGE_GPTFDISK=y
|
||||
BR2_PACKAGE_GPTFDISK_SGDISK=y
|
||||
BR2_PACKAGE_MDIO_TOOLS=y
|
||||
@@ -139,10 +136,10 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
BR2_PACKAGE_MICROCHIP_SAMA7G54_EK=y
|
||||
BR2_PACKAGE_RASPBERRYPI_RPI2=y
|
||||
INFIX_VENDOR_HOME="https://kernelkit.org"
|
||||
INFIX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
INFIX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://kernelkit.org/infix/"
|
||||
INFIX_DOC="https://www.kernelkit.org/infix/"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_FEATURE_GPS=y
|
||||
BR2_PACKAGE_FEATURE_WIFI_MEDIATEK=y
|
||||
|
||||
@@ -28,7 +28,7 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.14"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.16"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/arm/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -43,9 +43,6 @@ BR2_PACKAGE_DBUS_CXX=y
|
||||
BR2_PACKAGE_DBUS_GLIB=y
|
||||
BR2_PACKAGE_EUDEV_RULES_GEN=y
|
||||
# BR2_PACKAGE_EUDEV_ENABLE_HWDB is not set
|
||||
BR2_PACKAGE_GPSD_DEVICES="/dev/gps0"
|
||||
BR2_PACKAGE_GPSD_MAX_CLIENT_VALUE=2
|
||||
BR2_PACKAGE_GPSD_MAX_DEV_VALUE=1
|
||||
BR2_PACKAGE_GPTFDISK=y
|
||||
BR2_PACKAGE_GPTFDISK_SGDISK=y
|
||||
BR2_PACKAGE_MDIO_TOOLS=y
|
||||
@@ -121,12 +118,11 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
BR2_PACKAGE_MICROCHIP_SAMA7G54_EK=y
|
||||
BR2_PACKAGE_RASPBERRYPI_RPI2=y
|
||||
INFIX_VENDOR_HOME="https://kernelkit.org"
|
||||
INFIX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
INFIX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://kernelkit.org/infix/"
|
||||
INFIX_DOC="https://www.kernelkit.org/infix/"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_FEATURE_GPS=y
|
||||
BR2_PACKAGE_CONFD=y
|
||||
BR2_PACKAGE_NETD=y
|
||||
BR2_PACKAGE_CONFD_TEST_MODE=y
|
||||
|
||||
@@ -52,9 +52,6 @@ BR2_PACKAGE_DBUS_CXX=y
|
||||
BR2_PACKAGE_DBUS_GLIB=y
|
||||
BR2_PACKAGE_EUDEV_RULES_GEN=y
|
||||
# BR2_PACKAGE_EUDEV_ENABLE_HWDB is not set
|
||||
BR2_PACKAGE_GPSD_DEVICES="/dev/gps0"
|
||||
BR2_PACKAGE_GPSD_MAX_CLIENT_VALUE=2
|
||||
BR2_PACKAGE_GPSD_MAX_DEV_VALUE=1
|
||||
BR2_PACKAGE_GPTFDISK=y
|
||||
BR2_PACKAGE_GPTFDISK_SGDISK=y
|
||||
BR2_PACKAGE_MDIO_TOOLS=y
|
||||
@@ -170,10 +167,10 @@ BR2_PACKAGE_HOST_BMAP_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
INFIX_VENDOR_HOME="https://kernelkit.org"
|
||||
INFIX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
INFIX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://kernelkit.org/infix/"
|
||||
INFIX_DOC="https://www.kernelkit.org/infix/"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_FEATURE_GPS=y
|
||||
BR2_PACKAGE_FEATURE_WIFI=y
|
||||
|
||||
@@ -26,7 +26,7 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.14"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.16"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -41,9 +41,6 @@ BR2_PACKAGE_DBUS_CXX=y
|
||||
BR2_PACKAGE_DBUS_GLIB=y
|
||||
BR2_PACKAGE_EUDEV_RULES_GEN=y
|
||||
# BR2_PACKAGE_EUDEV_ENABLE_HWDB is not set
|
||||
BR2_PACKAGE_GPSD_DEVICES="/dev/gps0"
|
||||
BR2_PACKAGE_GPSD_MAX_CLIENT_VALUE=2
|
||||
BR2_PACKAGE_GPSD_MAX_DEV_VALUE=1
|
||||
BR2_PACKAGE_GPTFDISK=y
|
||||
BR2_PACKAGE_GPTFDISK_SGDISK=y
|
||||
BR2_PACKAGE_RNG_TOOLS=y
|
||||
@@ -142,10 +139,10 @@ BR2_PACKAGE_HOST_MTOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
INFIX_VENDOR_HOME="https://kernelkit.org"
|
||||
INFIX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
INFIX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://kernelkit.org/infix/"
|
||||
INFIX_DOC="https://www.kernelkit.org/infix/"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_FEATURE_GPS=y
|
||||
BR2_PACKAGE_FEATURE_WIFI=y
|
||||
|
||||
@@ -26,7 +26,7 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.14"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.16"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -41,9 +41,6 @@ BR2_PACKAGE_DBUS_CXX=y
|
||||
BR2_PACKAGE_DBUS_GLIB=y
|
||||
BR2_PACKAGE_EUDEV_RULES_GEN=y
|
||||
# BR2_PACKAGE_EUDEV_ENABLE_HWDB is not set
|
||||
BR2_PACKAGE_GPSD_DEVICES="/dev/gps0"
|
||||
BR2_PACKAGE_GPSD_MAX_CLIENT_VALUE=2
|
||||
BR2_PACKAGE_GPSD_MAX_DEV_VALUE=1
|
||||
BR2_PACKAGE_GPTFDISK=y
|
||||
BR2_PACKAGE_GPTFDISK_SGDISK=y
|
||||
BR2_PACKAGE_RNG_TOOLS=y
|
||||
@@ -120,12 +117,11 @@ BR2_PACKAGE_HOST_MTOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
INFIX_VENDOR_HOME="https://kernelkit.org"
|
||||
INFIX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
INFIX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://kernelkit.org/infix/"
|
||||
INFIX_DOC="https://www.kernelkit.org/infix/"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_FEATURE_GPS=y
|
||||
BR2_PACKAGE_CONFD=y
|
||||
BR2_PACKAGE_NETD=y
|
||||
BR2_PACKAGE_CONFD_TEST_MODE=y
|
||||
|
||||
+37
-13
@@ -3,25 +3,47 @@ Change Log
|
||||
|
||||
All notable changes to the project are documented in this file.
|
||||
|
||||
[v26.02.0][UNRELEASED] -
|
||||
[v26.02.1][] - 2026-03-11
|
||||
-------------------------
|
||||
|
||||
### Changes
|
||||
|
||||
- Upgrade Linux kernel to 6.18.14 (LTS)
|
||||
- Upgrade Buildroot to 2025.02.11 (LTS)
|
||||
- Upgrade FRR to 10.5.1
|
||||
- Add support for Microchip SAMA7G54-EK Evaluation Kit, Arm Cortex-A7
|
||||
- Add GPS/GNSS receiver support with NTP reference clock integration
|
||||
- Add support for [Banana Pi R3 Mini][BPI-R3-MINI], a 2 port router with 2 WiFi chip,
|
||||
uses the same bootloader as BPI-R3 (eMMC-version)
|
||||
- Upgrade Linux kernel to 6.18.16 (LTS)
|
||||
- Add support for disabling WiFi and GPS features in builds
|
||||
- Add OSPF point-to-multipoint (P2MP) and hybrid interface type support. This
|
||||
also includes support for setting static neighbors, issue #1426
|
||||
|
||||
### Fixes
|
||||
|
||||
N/A
|
||||
- Fix #1389: legacy name limit in firewalld triggered problems with policy names
|
||||
- Fix #1416: `show firewall` command show an error when the firewall is disabled
|
||||
- Fix instabilities in Zebra route manager after Frr upgrade in v26.02.0
|
||||
- Fix regression in MVEBU SafeXcel Crypto Engine for Marvell Armada SOCs (37xx,
|
||||
7k, 8k, and CN913x series). Firmware package lost in v26.01.0
|
||||
|
||||
[v26.02.0][] - 2026-03-01
|
||||
-------------------------
|
||||
|
||||
> [!NOTE]
|
||||
> The blog and User Guide have a new address: <https://www.kernelkit.org>
|
||||
|
||||
### Changes
|
||||
|
||||
- Upgrade Linux kernel to 6.18.15 (LTS)
|
||||
- Upgrade Buildroot to 2025.02.11 (LTS)
|
||||
- Upgrade FRR to 10.5.1
|
||||
- Add support for [Microchip SAMA7G54][SAMA7G54-EK] Evaluation Kit, Arm Cortex-A7
|
||||
- Add support for [Banana Pi R3 Mini][BPI-R3-MINI], a 2 port router with 2 WiFi chip,
|
||||
uses the same bootloader as BPI-R3 (eMMC-version)
|
||||
- Add GPS/GNSS receiver support with NTP reference clock integration
|
||||
- Add `reset-volumes` option to `container upgrade foo` command
|
||||
|
||||
### Fixes
|
||||
|
||||
- Fix CLI `copy` command problem to copy to scp/sftp destinations
|
||||
|
||||
[BPI-R3-MINI]: https://wiki.banana-pi.org/Banana_Pi_BPI-R3_Mini
|
||||
|
||||
[SAMA7G54-EK]: https://www.microchip.com/en-us/development-tool/ev21h18a
|
||||
|
||||
[v26.01.0][] - 2026-02-03
|
||||
-------------------------
|
||||
@@ -106,7 +128,7 @@ Noteworthy changes and additions in this release are marked below in bold text.
|
||||
- Prevent MOTD from showing on non-shell user login attempts
|
||||
- Fix mDNS reflector.
|
||||
|
||||
[wifi]: https://kernelkit.org/infix/latest/wifi/
|
||||
[wifi]: https://www.kernelkit.org/infix/latest/wifi/
|
||||
[sd card image]: https://github.com/kernelkit/infix/releases/download/latest-boot/infix-rpi64-sdcard.img
|
||||
|
||||
|
||||
@@ -724,7 +746,7 @@ renamed to ease maintenance, more info below.
|
||||
not supported (yet) in Infix, issue #709
|
||||
- The default builds now include the curiOS nftables container image,
|
||||
which can be used for advanced firewall setups. For an introduction
|
||||
see <https://kernelkit.org/posts/firewall-container/>
|
||||
see <https://www.kernelkit.org/posts/firewall-container/>
|
||||
|
||||
### Fixes
|
||||
|
||||
@@ -1927,7 +1949,9 @@ Supported YANG models in addition to those used by sysrepo and netopeer:
|
||||
- N/A
|
||||
|
||||
[buildroot]: https://buildroot.org/
|
||||
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v26.01.0...HEAD
|
||||
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v26.02.0...HEAD
|
||||
[v26.02.1]: https://github.com/kernelkit/infix/compare/v26.02.0...v26.02.1
|
||||
[v26.02.0]: https://github.com/kernelkit/infix/compare/v26.01.0...v26.02.0
|
||||
[v26.01.0]: https://github.com/kernelkit/infix/compare/v25.11.0...v26.01.0
|
||||
[v25.11.0]: https://github.com/kernelkit/infix/compare/v25.10.0...v25.11.0
|
||||
[v25.10.0]: https://github.com/kernelkit/infix/compare/v25.09.0...v26.10.0
|
||||
|
||||
+2
-2
@@ -295,7 +295,7 @@ linux-pc:# ssh admin@infix-c0-ff-ee.local
|
||||
(admin@infix-c0-ff-ee.local) Password:
|
||||
.-------.
|
||||
| . . | Infix OS — Immutable.Friendly.Secure
|
||||
|-. v .-| https://kernelkit.org
|
||||
|-. v .-| https://www.kernelkit.org
|
||||
'-'---'-
|
||||
|
||||
Run the command 'cli' for interactive OAM
|
||||
@@ -335,7 +335,7 @@ linux-pc:# ssh admin@infix.local
|
||||
(admin@infix.local) Password:
|
||||
.-------.
|
||||
| . . | Infix OS — Immutable.Friendly.Secure
|
||||
|-. v .-| https://kernelkit.org
|
||||
|-. v .-| https://www.kernelkit.org
|
||||
'-'---'-
|
||||
|
||||
Run the command 'cli' for interactive OAM
|
||||
|
||||
+1
-1
@@ -87,7 +87,7 @@ example login: <b>admin</b>
|
||||
Password:
|
||||
.-------.
|
||||
| . . | Infix OS — Immutable.Friendly.Secure
|
||||
|-. v .-| https://kernelkit.org
|
||||
|-. v .-| https://www.kernelkit.org
|
||||
'-'---'-'
|
||||
|
||||
Run the command 'cli' for interactive OAM
|
||||
|
||||
@@ -131,6 +131,66 @@ an Ethernet interface can be done as follows.
|
||||
admin@example:/config/routing/…/ospf/area/0.0.0.0/interface/e0/>
|
||||
</code></pre>
|
||||
|
||||
|
||||
### Point-to-Multipoint
|
||||
|
||||
Point-to-Multipoint (P2MP) is used when multiple OSPF routers share a
|
||||
common network segment but should form individual adjacencies rather
|
||||
than electing a Designated Router (DR). This is common in NBMA-like
|
||||
environments, DMVPN, or hub-and-spoke topologies.
|
||||
|
||||
Infix supports two P2MP variants via the `interface-type` setting:
|
||||
|
||||
| **Interface Type** | **Behavior** |
|
||||
|:----------------------|:-----------------------------------------------|
|
||||
| `hybrid` | P2MP with multicast Hellos (broadcast-capable) |
|
||||
| `point-to-multipoint` | P2MP with unicast Hellos (non-broadcast) |
|
||||
|
||||
#### Hybrid (broadcast-capable P2MP)
|
||||
|
||||
Use `hybrid` when all neighbors on the segment can receive multicast.
|
||||
Hello packets are sent to the standard OSPF multicast address (224.0.0.5)
|
||||
and neighbors are discovered automatically — no manual neighbor
|
||||
configuration is needed.
|
||||
|
||||
<pre class="cli"><code>admin@example:/config/> <b>edit routing control-plane-protocol ospfv2 name default ospf</b>
|
||||
admin@example:/config/routing/…/ospf/> <b>set area 0.0.0.0 interface e0 interface-type hybrid</b>
|
||||
admin@example:/config/routing/…/ospf/> <b>leave</b>
|
||||
admin@example:/>
|
||||
</code></pre>
|
||||
|
||||
#### Non-broadcast P2MP
|
||||
|
||||
Use `point-to-multipoint` when the network does not support multicast.
|
||||
Hello packets are sent as unicast directly to each configured neighbor.
|
||||
Since neighbors cannot be discovered automatically, they must be
|
||||
configured explicitly using static neighbors (see below).
|
||||
|
||||
<pre class="cli"><code>admin@example:/config/> <b>edit routing control-plane-protocol ospfv2 name default ospf</b>
|
||||
admin@example:/config/routing/…/ospf/> <b>set area 0.0.0.0 interface e0 interface-type point-to-multipoint</b>
|
||||
admin@example:/config/routing/…/ospf/> <b>leave</b>
|
||||
admin@example:/>
|
||||
</code></pre>
|
||||
|
||||
|
||||
### Static Neighbors
|
||||
|
||||
When using non-broadcast interface types (such as `point-to-multipoint`),
|
||||
OSPF cannot discover neighbors via multicast. Static neighbors must be
|
||||
configured so the router knows where to send unicast Hello packets.
|
||||
|
||||
<pre class="cli"><code>admin@example:/config/> <b>edit routing control-plane-protocol ospfv2 name default ospf</b>
|
||||
admin@example:/config/routing/…/ospf/> <b>set area 0.0.0.0 interface e0 static-neighbors neighbor 10.0.123.2</b>
|
||||
admin@example:/config/routing/…/ospf/> <b>set area 0.0.0.0 interface e0 static-neighbors neighbor 10.0.123.3</b>
|
||||
admin@example:/config/routing/…/ospf/> <b>leave</b>
|
||||
admin@example:/>
|
||||
</code></pre>
|
||||
|
||||
> [!NOTE]
|
||||
> Static neighbors are only needed for non-broadcast interface types.
|
||||
> With `hybrid` (or `broadcast`), neighbors are discovered automatically
|
||||
> via multicast.
|
||||
|
||||
### OSPF global settings
|
||||
|
||||
In addition to *area* and *interface* specific settings, OSPF provides
|
||||
|
||||
@@ -336,7 +336,7 @@ It should now be possible to access the switch from the PC via SSH (or NETCONF).
|
||||
admin@fe80::0053:00ff:fe06:1101%eth1's password:
|
||||
.-------.
|
||||
| . . | Infix OS — Immutable.Friendly.Secure
|
||||
|-. v .-| https://kernelkit.org
|
||||
|-. v .-| https://www.kernelkit.org
|
||||
'-'---'-'
|
||||
|
||||
Run the command 'cli' for interactive OAM
|
||||
|
||||
+1
-1
@@ -88,7 +88,7 @@ Warning: Permanently added 'fe80::ff:fe00:0%eth0' (ED25519) to the list of known
|
||||
admin@fe80::ff:fe00:0%eth0's password: *****
|
||||
.-------.
|
||||
| . . | Infix OS — Immutable.Friendly.Secure
|
||||
|-. v .-| https://kernelkit.org
|
||||
|-. v .-| https://www.kernelkit.org
|
||||
'-'---'-'
|
||||
|
||||
Run the command 'cli' for interactive OAM
|
||||
|
||||
+1
-1
@@ -152,7 +152,7 @@ infix-00-00-00 login: admin
|
||||
Password:
|
||||
.-------.
|
||||
| . . | Infix OS — Immutable.Friendly.Secure
|
||||
|-. v .-| https://kernelkit.org
|
||||
|-. v .-| https://www.kernelkit.org
|
||||
'-'---'-'
|
||||
|
||||
Run the command 'cli' for interactive OAM
|
||||
|
||||
+1
-1
@@ -170,7 +170,7 @@ example login: <b>admin</b>
|
||||
Password:
|
||||
.-------.
|
||||
| . . | Infix OS — Immutable.Friendly.Secure
|
||||
|-. v .-| https://kernelkit.org
|
||||
|-. v .-| https://www.kernelkit.org
|
||||
'-'---'-'
|
||||
|
||||
Run the command 'cli' for interactive OAM
|
||||
|
||||
+1
-1
@@ -170,6 +170,6 @@ plugins:
|
||||
|
||||
extra:
|
||||
generator: false
|
||||
homepage: https://kernelkit.org/
|
||||
homepage: https://www.kernelkit.org/
|
||||
version:
|
||||
provider: mike
|
||||
|
||||
@@ -30,6 +30,11 @@ CONFD_CONF_OPTS += --enable-wifi
|
||||
else
|
||||
CONFD_CONF_OPTS += --disable-wifi
|
||||
endif
|
||||
ifeq ($(BR2_PACKAGE_FEATURE_GPS),y)
|
||||
CONFD_CONF_OPTS += --enable-gps
|
||||
else
|
||||
CONFD_CONF_OPTS += --disable-gps
|
||||
endif
|
||||
define CONFD_INSTALL_EXTRA
|
||||
for fn in confd.conf resolvconf.conf; do \
|
||||
cp $(CONFD_PKGDIR)/$$fn $(FINIT_D)/available/; \
|
||||
@@ -80,6 +85,12 @@ define CONFD_INSTALL_YANG_MODULES_WIFI
|
||||
$(BR2_EXTERNAL_INFIX_PATH)/utils/srload $(@D)/yang/wifi.inc
|
||||
endef
|
||||
endif
|
||||
ifeq ($(BR2_PACKAGE_FEATURE_GPS),y)
|
||||
define CONFD_INSTALL_YANG_MODULES_GPS
|
||||
$(COMMON_SYSREPO_ENV) \
|
||||
$(BR2_EXTERNAL_INFIX_PATH)/utils/srload $(@D)/yang/gps.inc
|
||||
endef
|
||||
endif
|
||||
|
||||
# PER_PACKAGE_DIR
|
||||
# Since the last package in the dependency chain that runs sysrepoctl is confd, we need to
|
||||
@@ -109,6 +120,7 @@ CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_EXTRA
|
||||
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_YANG_MODULES
|
||||
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_YANG_MODULES_CONTAINERS
|
||||
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_YANG_MODULES_WIFI
|
||||
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_YANG_MODULES_GPS
|
||||
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_IN_ROMFS
|
||||
CONFD_TARGET_FINALIZE_HOOKS += CONFD_CLEANUP
|
||||
|
||||
|
||||
@@ -1,2 +1,2 @@
|
||||
# --log-level debug
|
||||
ZEBRA_ARGS="-A 127.0.0.1 -u frr -g frr --log syslog --log-level err"
|
||||
ZEBRA_ARGS="-A 127.0.0.1 -a -s 90000000 -u frr -g frr --log syslog --log-level err"
|
||||
|
||||
@@ -1,2 +1,3 @@
|
||||
service <!> pid:!/run/frr/mgmtd.pid env:-/etc/default/mgmtd \
|
||||
[2345] mgmtd $MGMTD_ARGS -- FRR MGMT daemon
|
||||
[2345] mgmtd $MGMTD_ARGS \
|
||||
-- FRR MGMT daemon
|
||||
|
||||
@@ -1,2 +1,3 @@
|
||||
service <!pid/zebra> env:-/etc/default/ospfd \
|
||||
[2345] ospfd $OSPFD_ARGS -- OSPF daemon
|
||||
service <!pid/zebra> pid:!/run/frr/ospfd.pid env:-/etc/default/ospfd \
|
||||
[2345] ospfd $OSPFD_ARGS \
|
||||
-- OSPF daemon
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
service <pid/zebra> env:-/etc/default/ripd \
|
||||
[2345] ripd $RIPD_ARGS
|
||||
service <pid/zebra> pid:!/run/frr/ripd.pid env:-/etc/default/ripd \
|
||||
[2345] ripd $RIPD_ARGS \
|
||||
-- RIP daemon
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
service <!pid/mgmtd> pid:!/run/frr/zebra.pid env:-/etc/default/zebra \
|
||||
[2345] zebra $ZEBRA_ARGS
|
||||
service <!pid/mgmtd> pid:!/run/frr/zebra.pid env:-/etc/default/zebra \
|
||||
[2345] zebra $ZEBRA_ARGS \
|
||||
-- Zebra routing daemon
|
||||
|
||||
+1
-3
@@ -1,5 +1,4 @@
|
||||
# Default FRR daemons file for Infix - confd overwrites on routing changes.
|
||||
# watchfrr, zebra, mgmtd, and staticd are always started by frrinit.sh.
|
||||
# Default FRR daemons file used with watchfrr, started by frrinit.sh.
|
||||
ospfd=no
|
||||
ripd=no
|
||||
bfdd=no
|
||||
@@ -25,4 +24,3 @@ staticd_options="-A 127.0.0.1"
|
||||
bfdd_options=" -A 127.0.0.1"
|
||||
|
||||
frr_profile="traditional"
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
! Empty stub — mgmtd reads its own config at startup; file must exist to avoid log noise.
|
||||
@@ -0,0 +1 @@
|
||||
! Empty stub — mgmtd reads per-daemon configs at startup; file must exist to avoid log noise.
|
||||
@@ -0,0 +1 @@
|
||||
! Empty stub — mgmtd reads per-daemon configs at startup; file must exist to avoid log noise.
|
||||
@@ -0,0 +1 @@
|
||||
! Empty stub — mgmtd reads per-daemon configs at startup; file must exist to avoid log noise.
|
||||
@@ -0,0 +1 @@
|
||||
! Empty stub — mgmtd reads per-daemon configs at startup; file must exist to avoid log noise.
|
||||
@@ -1,7 +1,7 @@
|
||||
From 03f273fc540082d1eaa23bd9b5847e695afd8283 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Thu, 25 Sep 2025 15:00:54 +0200
|
||||
Subject: [PATCH] Silence warnings about old backends
|
||||
Subject: [PATCH 1/2] Silence warnings about old backends
|
||||
Organization: Wires
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
|
||||
+95
@@ -0,0 +1,95 @@
|
||||
From 6ab218fe7f2c7027cc5347e3b082285870c502e6 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Fri, 6 Mar 2026 07:44:38 +0100
|
||||
Subject: [PATCH 2/2] fix(functions): lift iptables name length limit when
|
||||
using nftables
|
||||
Organization: Wires
|
||||
|
||||
The max_zone_name_len() and max_policy_name_len() functions return 17
|
||||
and 18 respectively, derived from iptables' 28-char netfilter chain name
|
||||
limit. These limits are applied unconditionally in Zone.check_name()
|
||||
and Policy.check_name() regardless of the active backend.
|
||||
|
||||
When FirewallBackend=nftables nftables imposes no such restriction, so
|
||||
user-defined zone and policy names (e.g. "appletv-to-lan-guest", 20
|
||||
chars) that exceed the iptables-derived limit are incorrectly rejected.
|
||||
|
||||
Add _nftables_backend() which reads firewalld.conf directly so the check
|
||||
can be skipped without threading backend context through to check_name()
|
||||
call sites, which have no access to all_io_objects. When nftables is
|
||||
active, both functions return sys.maxsize, effectively disabling the
|
||||
length check.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
src/firewall/functions.py | 31 ++++++++++++++++++++++++++++++-
|
||||
1 file changed, 30 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/firewall/functions.py b/src/firewall/functions.py
|
||||
index 27c862fd..1b8a32ce 100644
|
||||
--- a/src/firewall/functions.py
|
||||
+++ b/src/firewall/functions.py
|
||||
@@ -10,9 +10,10 @@ import os
|
||||
import os.path
|
||||
import shlex
|
||||
import string
|
||||
+import sys
|
||||
import tempfile
|
||||
from firewall.core.logger import log
|
||||
-from firewall.config import FIREWALLD_TEMPDIR, FIREWALLD_PIDFILE
|
||||
+from firewall.config import FIREWALLD_CONF, FIREWALLD_TEMPDIR, FIREWALLD_PIDFILE
|
||||
|
||||
NOPRINT_TRANS_TABLE = {
|
||||
# Limit to C0 and C1 code points. Building entries for all unicode code
|
||||
@@ -576,12 +577,35 @@ def ppid_of_pid(pid):
|
||||
return pid
|
||||
|
||||
|
||||
+def _nftables_backend():
|
||||
+ """Return True if FirewallBackend=nftables is configured in firewalld.conf.
|
||||
+
|
||||
+ When using nftables the iptables-derived 28-char chain name limit does not
|
||||
+ apply. Reading the config file directly avoids threading backend context
|
||||
+ through check_name() call sites, which have no access to all_io_objects.
|
||||
+ """
|
||||
+ try:
|
||||
+ with open(FIREWALLD_CONF) as f:
|
||||
+ for line in f:
|
||||
+ line = line.strip()
|
||||
+ if line.startswith("FirewallBackend="):
|
||||
+ return line.split("=", 1)[1].strip() == "nftables"
|
||||
+ except OSError:
|
||||
+ pass
|
||||
+ return False
|
||||
+
|
||||
+
|
||||
def max_policy_name_len():
|
||||
"""
|
||||
iptables limits length of chain to (currently) 28 chars.
|
||||
The longest chain we create is POST_<policy>_allow,
|
||||
which leaves 28 - 11 = 17 chars for <policy>.
|
||||
+
|
||||
+ When using the nftables backend, nftables imposes no practical name length
|
||||
+ restriction, so we return sys.maxsize to lift the check entirely.
|
||||
"""
|
||||
+ if _nftables_backend():
|
||||
+ return sys.maxsize
|
||||
from firewall.core.ipXtables import POLICY_CHAIN_PREFIX
|
||||
from firewall.core.base import SHORTCUTS
|
||||
|
||||
@@ -594,7 +618,12 @@ def max_zone_name_len():
|
||||
Netfilter limits length of chain to (currently) 28 chars.
|
||||
The longest chain we create is POST_<zone>_allow,
|
||||
which leaves 28 - 11 = 17 chars for <zone>.
|
||||
+
|
||||
+ When using the nftables backend, nftables imposes no practical name length
|
||||
+ restriction, so we return sys.maxsize to lift the check entirely.
|
||||
"""
|
||||
+ if _nftables_backend():
|
||||
+ return sys.maxsize
|
||||
from firewall.core.base import SHORTCUTS
|
||||
|
||||
longest_shortcut = max(map(len, SHORTCUTS.values()))
|
||||
--
|
||||
2.43.0
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 00f89f3ba9f41a1c495dddcb83b2f6bb9f938a0c Mon Sep 17 00:00:00 2001
|
||||
From 2ca55761d22dbc39d26862cf94577cf44f4b85a0 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 19 Sep 2023 18:38:10 +0200
|
||||
Subject: [PATCH 01/33] net: phy: marvell10g: Support firmware loading on
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 2a31d49efc597de1f30f3067076a77750d29a15f Mon Sep 17 00:00:00 2001
|
||||
From 554729f2a8c83f617663c097cc389b5c791db8aa Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 21 Nov 2023 20:15:24 +0100
|
||||
Subject: [PATCH 02/33] net: phy: marvell10g: Fix power-up when strapped to
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 6b0e8831d0a6303daa38e92f6cf557e476f17539 Mon Sep 17 00:00:00 2001
|
||||
From 7090bf6cbf332d9a38e04a58b026d2d00701ca67 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Wed, 15 Nov 2023 20:58:42 +0100
|
||||
Subject: [PATCH 03/33] net: phy: marvell10g: Add LED support for 88X3310
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From b5c0e5112b0d3e01af0f67c383cb981d83c185d0 Mon Sep 17 00:00:00 2001
|
||||
From 7776e8acf62062136892b9623c24898c09778e48 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 12 Dec 2023 09:51:05 +0100
|
||||
Subject: [PATCH 04/33] net: phy: marvell10g: Support LEDs tied to a single
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 81a6a60b94c633a4c2e3c11ab77252f827f8ea65 Mon Sep 17 00:00:00 2001
|
||||
From 96ce164208881c981e9e8b1231e2b45957a89b5e Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Wed, 27 Mar 2024 10:10:19 +0100
|
||||
Subject: [PATCH 05/33] net: phy: Do not resume PHY when attaching
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From d1187bd54f9d346e1037621822738548e167a668 Mon Sep 17 00:00:00 2001
|
||||
From 74ce9cb9a4845537644a67769ee9f441bf9d3a78 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Mon, 4 Mar 2024 16:47:28 +0100
|
||||
Subject: [PATCH 06/33] net: bridge: avoid classifying unknown multicast as
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From d292a3a9ad8ef75d589d51bc7fe11f39371781c0 Mon Sep 17 00:00:00 2001
|
||||
From e7b3717762434f780616a0b641169f5cfa1a2398 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Tue, 5 Mar 2024 06:44:41 +0100
|
||||
Subject: [PATCH 07/33] net: bridge: Ignore router ports when forwarding L2
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 8786298e55fc4b5f108ad18dad5be21acd4ba911 Mon Sep 17 00:00:00 2001
|
||||
From fabc6f846e244fd2b67d26155d644238505b949b Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Thu, 4 Apr 2024 16:36:30 +0200
|
||||
Subject: [PATCH 08/33] net: bridge: drop delay for applying strict multicast
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From be0a8a1d4d6ba0bbf046cd72ebe1710800869ee5 Mon Sep 17 00:00:00 2001
|
||||
From 4ee3858a7d7f02746187d8bbc6011038747cab35 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Thu, 16 May 2024 14:51:54 +0200
|
||||
Subject: [PATCH 09/33] net: bridge: Differentiate MDB additions from
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 75070ac3fb6fdd403039bfc9b14d9edc6c3133dc Mon Sep 17 00:00:00 2001
|
||||
From 319ed7a2257bd18b5b0d23c9f24af9fd127b7667 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Fri, 24 Nov 2023 23:29:55 +0100
|
||||
Subject: [PATCH 10/33] nvmem: layouts: onie-tlv: Let device probe even when
|
||||
+3
-3
@@ -1,4 +1,4 @@
|
||||
From 931afb4a82cce9b479f3377a78519ad20a5e2175 Mon Sep 17 00:00:00 2001
|
||||
From 0ee33120c15d36ea49121936acb0b9cb860e0f5f Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Sun, 11 Aug 2024 11:27:35 +0200
|
||||
Subject: [PATCH 11/33] net: usb: r8152: add r8153b support for link/activity
|
||||
@@ -18,7 +18,7 @@ Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
1 file changed, 8 insertions(+)
|
||||
|
||||
diff --git a/drivers/net/usb/r8152.c b/drivers/net/usb/r8152.c
|
||||
index 6a43054d5171..ef8bcb4a7339 100644
|
||||
index da8de7b1a489..36d79a77316c 100644
|
||||
--- a/drivers/net/usb/r8152.c
|
||||
+++ b/drivers/net/usb/r8152.c
|
||||
@@ -41,6 +41,11 @@
|
||||
@@ -33,7 +33,7 @@ index 6a43054d5171..ef8bcb4a7339 100644
|
||||
#define R8152_PHY_ID 32
|
||||
|
||||
#define PLA_IDR 0xc000
|
||||
@@ -7277,6 +7282,9 @@ static void r8153b_init(struct r8152 *tp)
|
||||
@@ -7279,6 +7284,9 @@ static void r8153b_init(struct r8152 *tp)
|
||||
ocp_data &= ~(RX_AGG_DISABLE | RX_ZERO_EN);
|
||||
ocp_write_word(tp, MCU_TYPE_USB, USB_USB_CTRL, ocp_data);
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 23a3579ca235bbc5c4b3417176aef7846ba022b3 Mon Sep 17 00:00:00 2001
|
||||
From cf134950928be5c5955cc70c69e273a316bac69f Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Sun, 10 Aug 2025 18:52:54 +0200
|
||||
Subject: [PATCH 12/33] arm64: dts: mediatek: mt7986a: rename BPi R3 ports to
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From b3eb28e66efdbe13153c13ee492b56e284dd7cc7 Mon Sep 17 00:00:00 2001
|
||||
From 799998c00feee44d4c74556022904ba7a0bdfac8 Mon Sep 17 00:00:00 2001
|
||||
From: Mattias Walström <lazzer@gmail.com>
|
||||
Date: Wed, 20 Aug 2025 21:38:24 +0200
|
||||
Subject: [PATCH 13/33] drm/panel-simple: Add a timing for the Raspberry Pi 7"
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 18b1eb460fefbd0a6dff47dc6900a5948df40a8f Mon Sep 17 00:00:00 2001
|
||||
From f01bf9ba38f75e3ef290cdd2a22df025768dd8b8 Mon Sep 17 00:00:00 2001
|
||||
From: Mattias Walström <lazzer@gmail.com>
|
||||
Date: Thu, 21 Aug 2025 11:20:23 +0200
|
||||
Subject: [PATCH 14/33] input:touchscreen:edt-ft5x06: Add polled mode
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 70a3642435e2510a8f16e2115a7b555dc3ec64b4 Mon Sep 17 00:00:00 2001
|
||||
From dd7bb94f604192615f1f73a362fb0e2471ff8e1b Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 12 Mar 2024 10:27:24 +0100
|
||||
Subject: [PATCH 15/33] [FIX] net: dsa: mv88e6xxx: Fix timeout on waiting for
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From a8f89c96786d6dfc6d7c728b92e7ad33ec7cc12b Mon Sep 17 00:00:00 2001
|
||||
From 5dbb37d98861fab5cdf35947406133b494850d07 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Wed, 27 Mar 2024 15:52:43 +0100
|
||||
Subject: [PATCH 16/33] net: dsa: mv88e6xxx: Improve indirect register access
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From c1ff82cfcd6786690edce944c5a44616d42426fb Mon Sep 17 00:00:00 2001
|
||||
From ef510ee5006cb4d34bbf53edc2c5d82cee557a56 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Mon, 22 Apr 2024 23:18:01 +0200
|
||||
Subject: [PATCH 17/33] net: dsa: mv88e6xxx: Honor ports being managed via
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From dc2e3d0dc7bb298fb4fb25cd9befbac2cadbaa36 Mon Sep 17 00:00:00 2001
|
||||
From cb18e0e47ef6696d7e2949af53c6f224ff112160 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Wed, 24 Apr 2024 22:41:04 +0200
|
||||
Subject: [PATCH 18/33] net: dsa: mv88e6xxx: Limit rsvd2cpu policy to user
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 7b41de01eeac05ef76798168f1bf2aebb303410b Mon Sep 17 00:00:00 2001
|
||||
From 68e1ad6de79b30163ee9c610174e704db44f9c29 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 28 May 2024 10:38:42 +0200
|
||||
Subject: [PATCH 19/33] net: dsa: tag_dsa: Use tag priority as initial
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 2993149c029e9c53d1538850173b585ae39b69d7 Mon Sep 17 00:00:00 2001
|
||||
From 973d7b6c0928d41ed86702c4b7e9d140c7acb443 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 16 Jan 2024 16:00:55 +0100
|
||||
Subject: [PATCH 20/33] net: dsa: Support MDB memberships whose L2 addresses
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 3402c2bee5c28a7c7e0e16cc75304749ec57895e Mon Sep 17 00:00:00 2001
|
||||
From f23311c2898a40e0f330c3d21907d2d14ab66b85 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Thu, 21 Mar 2024 19:12:15 +0100
|
||||
Subject: [PATCH 21/33] net: dsa: Support EtherType based priority overrides
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 103e7309ed96e845cbd2075a89e0e10b962490fa Mon Sep 17 00:00:00 2001
|
||||
From 02a6215df9d126dbe0079eab7b4b95a49be072fe Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Fri, 22 Mar 2024 16:15:43 +0100
|
||||
Subject: [PATCH 22/33] net: dsa: mv88e6xxx: Support EtherType based priority
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 0ebdd84bda066b82db85280a266e8d01e0872115 Mon Sep 17 00:00:00 2001
|
||||
From 8de2cab0aef8e63e6f95d49ccf50aac05e3834d1 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 28 May 2024 11:04:22 +0200
|
||||
Subject: [PATCH 23/33] net: dsa: mv88e6xxx: Add mqprio qdisc support
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 216d17528054c744b76f68731cdc61c2a7f16bf0 Mon Sep 17 00:00:00 2001
|
||||
From 0de73e629b8fabb852a239a67e91954d15326c1b Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Wed, 29 May 2024 13:20:41 +0200
|
||||
Subject: [PATCH 24/33] net: dsa: mv88e6xxx: Use VLAN prio over IP when both
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From e0e692a81515e6111a0d60a679dff7d1d382700c Mon Sep 17 00:00:00 2001
|
||||
From 3caaed0cca0c4ca5719b0434a30aa8dec77ef717 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 26 Nov 2024 19:45:59 +0100
|
||||
Subject: [PATCH 25/33] [FIX] net: dsa: mv88e6xxx: Trap locally terminated
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From b609b6ac8841e77f1c1b51bb8d20ba8c6aff28a1 Mon Sep 17 00:00:00 2001
|
||||
From bd10307b97efc72d331b5fdf56721954e834df48 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Thu, 16 Jan 2025 12:35:12 +0100
|
||||
Subject: [PATCH 26/33] net: dsa: mv88e6xxx: collapse disabled state into
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 47c2f59a47315c3032e936b58a83fe6cb905b970 Mon Sep 17 00:00:00 2001
|
||||
From 85b575912a77253cc45a8a50d75999b34ab8aa43 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Wed, 12 Feb 2025 22:03:14 +0100
|
||||
Subject: [PATCH 27/33] net: dsa: mv88e6xxx: Only activate LAG offloading when
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 09fcae28ec65a3b3c8e82a1ebffcefd1ef2f3076 Mon Sep 17 00:00:00 2001
|
||||
From 971b21f938d66b6c6f1f5d54b20c4d732e5cf3d6 Mon Sep 17 00:00:00 2001
|
||||
From: Mattias Walström <lazzer@gmail.com>
|
||||
Date: Wed, 14 Jan 2026 18:22:41 +0100
|
||||
Subject: [PATCH 28/33] net: dsa: mv88e6xxx: Add LED support for 6393X
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 3fd13d10d7153f700233e4f91b2070bfa280c265 Mon Sep 17 00:00:00 2001
|
||||
From 86a58b0b4b1d60d40a80f058e4f09c87da4093b4 Mon Sep 17 00:00:00 2001
|
||||
From: Mattias Walström <lazzer@gmail.com>
|
||||
Date: Thu, 15 Jan 2026 22:47:37 +0100
|
||||
Subject: [PATCH 29/33] wifi: brcmfmac: support deletion and recreation of
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From e30fdea3ea2c1d52b258d78796e8a2d5307c8e57 Mon Sep 17 00:00:00 2001
|
||||
From 924750050148d937cf62e94f4a706a0be6f5ed02 Mon Sep 17 00:00:00 2001
|
||||
From: Mattias Walström <lazzer@gmail.com>
|
||||
Date: Mon, 19 Jan 2026 13:06:53 +0100
|
||||
Subject: [PATCH 30/33] wifi: brcmfmac: check connection state before querying
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 03fbaedfaef56f23862d6b390eeb4a53830ba5b9 Mon Sep 17 00:00:00 2001
|
||||
From 17a580919c5be64b94ccc9e11d0c52b990053485 Mon Sep 17 00:00:00 2001
|
||||
From: Mattias Walström <lazzer@gmail.com>
|
||||
Date: Tue, 20 Jan 2026 20:12:10 +0100
|
||||
Subject: [PATCH 31/33] wifi: brcmfmac: suppress log spam for
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From e0da4bfce5f50959b9e1874019cfe242970a9071 Mon Sep 17 00:00:00 2001
|
||||
From 544345cb92b080c77a62eadccb92d07190bac7d1 Mon Sep 17 00:00:00 2001
|
||||
From: Mattias Walström <lazzer@gmail.com>
|
||||
Date: Tue, 20 Jan 2026 20:18:45 +0100
|
||||
Subject: [PATCH 32/33] wifi: brcmfmac: reduce log noise during AP to station
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
From 384b9a4f22df36918c26f893a3e808a6c7879ba7 Mon Sep 17 00:00:00 2001
|
||||
From 5a1dbf99922519d4c36b93c16128c4419da35f30 Mon Sep 17 00:00:00 2001
|
||||
From: Mattias Walström <lazzer@gmail.com>
|
||||
Date: Tue, 17 Feb 2026 21:59:59 +0100
|
||||
Subject: [PATCH 33/33] net: phy: air_en8811h: add OF device table for
|
||||
@@ -1,2 +1,2 @@
|
||||
# Calculated with utils/kernel-refresh.sh
|
||||
sha256 8d1934a72a185f1be6b56e3ad8ea31fd9a381ffec0346c69f06c90d776da7cb8 linux-6.18.14.tar.xz
|
||||
sha256 4f21c01f4d04c1d1b3ed794153f8900802c92497be620b07c4869530f2d28ee3 linux-6.18.16.tar.xz
|
||||
|
||||
+4
-3
@@ -466,7 +466,7 @@ static int curl(char *op, const char *path, const char *uri)
|
||||
{
|
||||
char *argv[10] = { "curl", "-L", NULL };
|
||||
int err = 1, i = 2;
|
||||
int path_i, uri_i, user_i = 0;
|
||||
int path_i, uri_i = 0, user_i = 0;
|
||||
|
||||
argv[i++] = op;
|
||||
|
||||
@@ -492,7 +492,8 @@ static int curl(char *op, const char *path, const char *uri)
|
||||
|
||||
out:
|
||||
free(argv[path_i]);
|
||||
free(argv[uri_i]);
|
||||
if (uri_i)
|
||||
free(argv[uri_i]);
|
||||
if (user_i)
|
||||
free(argv[user_i]);
|
||||
return err;
|
||||
@@ -752,7 +753,7 @@ static int copy(const char *src, const char *dst)
|
||||
* meaningful name instead: the datastore's on-disk filename, or the
|
||||
* source file's own basename.
|
||||
*/
|
||||
if (is_ssh_uri(dst) && dst[strlen(dst) - 1] == '/') {
|
||||
if (dst && is_ssh_uri(dst) && dst[strlen(dst) - 1] == '/') {
|
||||
const char *bn, *slash;
|
||||
|
||||
if (srcds && srcds->path) {
|
||||
|
||||
@@ -46,6 +46,10 @@ AC_ARG_ENABLE(wifi,
|
||||
AS_HELP_STRING([--enable-wifi], [Enable support for Wi-Fi]),,[
|
||||
enable_wifi=no])
|
||||
|
||||
AC_ARG_ENABLE(gps,
|
||||
AS_HELP_STRING([--enable-gps], [Enable support for GPS receivers]),,[
|
||||
enable_gps=no])
|
||||
|
||||
AC_ARG_WITH(login-shell,
|
||||
AS_HELP_STRING([--with-login-shell=shell], [Login shell for new users, default: /bin/false]),
|
||||
[login_shell=$withval], [login_shell=yes])
|
||||
@@ -60,6 +64,9 @@ AS_IF([test "x$enable_containers" = "xyes"], [
|
||||
AS_IF([test "x$enable_wifi" = "xyes"], [
|
||||
AC_DEFINE(HAVE_WIFI, 1, [Built with Wi-Fi support])])
|
||||
|
||||
AS_IF([test "x$enable_gps" = "xyes"], [
|
||||
AC_DEFINE(HAVE_GPS, 1, [Built with GPS receiver support])])
|
||||
|
||||
AS_IF([test "x$with_login_shell" != "xno"], [
|
||||
AS_IF([test "x$login_shell" = "xyes"], [login_shell=/bin/false])
|
||||
AC_DEFINE_UNQUOTED(LOGIN_SHELL, "$login_shell", [Default: /bin/false])],[
|
||||
@@ -131,6 +138,7 @@ cat <<EOF
|
||||
Optional features:
|
||||
Container support ....: $enable_containers
|
||||
Wi-Fi support ........: $enable_wifi
|
||||
GPS support ..........: $enable_gps
|
||||
Login shell ..........: $login_shell
|
||||
Default crypt algo ...: $crypt
|
||||
|
||||
|
||||
@@ -144,7 +144,7 @@ static void add(const char *ifname, struct lyd_node *cfg)
|
||||
|
||||
fprintf(fp, "# Generated by Infix confd\n");
|
||||
fprintf(fp, "metric=%s\n", metric);
|
||||
fprintf(fp, "service <!> name:dhcp-client :%s <net/%s/running> \\\n"
|
||||
fprintf(fp, "service <!pid/netd> name:dhcp-client :%s <net/%s/running> \\\n"
|
||||
" [2345] udhcpc -f -p /run/dhcp-client-%s.pid -t 3 -T 5 -A 30 %s -S -R \\\n"
|
||||
" %s%s \\\n"
|
||||
" -i %s %s %s \\\n"
|
||||
|
||||
+11
-12
@@ -695,18 +695,17 @@ int hardware_change(sr_session_ctx_t *session, struct lyd_node *config, struct l
|
||||
wifi_find_interfaces_on_radio(interfaces_config, name,
|
||||
&wifi_iface_list, &wifi_iface_count);
|
||||
|
||||
|
||||
if (!wifi_iface_count)
|
||||
continue;
|
||||
|
||||
/* Generate AP config (hostapd) for all APs on this radio */
|
||||
rc = wifi_gen_aps_on_radio(name, interfaces_config, cwifi_radio, config);
|
||||
if (rc != SR_ERR_OK)
|
||||
ERROR("Failed to generate AP config for radio %s", name);
|
||||
/* Free the interface list */
|
||||
free(wifi_iface_list);
|
||||
wifi_iface_list = NULL;
|
||||
wifi_iface_count = 0;
|
||||
if (wifi_iface_list) {
|
||||
if (wifi_iface_count) {
|
||||
/* Generate AP config (hostapd) for all APs on this radio */
|
||||
rc = wifi_gen_aps_on_radio(name, interfaces_config, cwifi_radio, config);
|
||||
if (rc != SR_ERR_OK)
|
||||
ERROR("Failed to generate AP config for radio %s", name);
|
||||
}
|
||||
free(wifi_iface_list);
|
||||
wifi_iface_list = NULL;
|
||||
wifi_iface_count = 0;
|
||||
}
|
||||
} else if (!strcmp(class, "infix-hardware:gps")) {
|
||||
if (event != SR_EV_DONE)
|
||||
continue;
|
||||
|
||||
+37
-3
@@ -154,6 +154,17 @@ int parse_rip(sr_session_ctx_t *session, struct lyd_node *rip, FILE *fp)
|
||||
return num_interfaces;
|
||||
}
|
||||
|
||||
static const char *ospf_network_type(const char *yang_type)
|
||||
{
|
||||
if (!strcmp(yang_type, "hybrid"))
|
||||
return "point-to-multipoint";
|
||||
if (!strcmp(yang_type, "point-to-multipoint"))
|
||||
return "point-to-multipoint non-broadcast";
|
||||
|
||||
/* broadcast, non-broadcast, point-to-point pass through unchanged */
|
||||
return yang_type;
|
||||
}
|
||||
|
||||
int parse_ospf_interfaces(sr_session_ctx_t *session, struct lyd_node *areas, FILE *fp)
|
||||
{
|
||||
struct lyd_node *interface, *interfaces, *area;
|
||||
@@ -203,7 +214,7 @@ int parse_ospf_interfaces(sr_session_ctx_t *session, struct lyd_node *areas, FIL
|
||||
if (passive)
|
||||
fputs(" ip ospf passive\n", fp);
|
||||
if (interface_type)
|
||||
fprintf(fp, " ip ospf network %s\n", interface_type);
|
||||
fprintf(fp, " ip ospf network %s\n", ospf_network_type(interface_type));
|
||||
if (cost)
|
||||
fprintf(fp, " ip ospf cost %s\n", cost);
|
||||
}
|
||||
@@ -226,6 +237,28 @@ int parse_ospf_redistribute(sr_session_ctx_t *session, struct lyd_node *redistri
|
||||
return 0;
|
||||
}
|
||||
|
||||
static void parse_ospf_static_neighbors(struct lyd_node *areas, FILE *fp)
|
||||
{
|
||||
struct lyd_node *area, *interface, *interfaces, *neighbors, *neighbor;
|
||||
|
||||
LY_LIST_FOR(lyd_child(areas), area) {
|
||||
interfaces = lydx_get_child(area, "interfaces");
|
||||
|
||||
LY_LIST_FOR(lyd_child(interfaces), interface) {
|
||||
neighbors = lydx_get_child(interface, "static-neighbors");
|
||||
if (!neighbors)
|
||||
continue;
|
||||
|
||||
LY_LIST_FOR(lyd_child(neighbors), neighbor) {
|
||||
const char *id = lydx_get_cattr(neighbor, "identifier");
|
||||
|
||||
if (id)
|
||||
fprintf(fp, " neighbor %s\n", id);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
int parse_ospf_areas(sr_session_ctx_t *session, struct lyd_node *areas, FILE *fp)
|
||||
{
|
||||
int areas_configured = 0;
|
||||
@@ -315,6 +348,7 @@ int parse_ospf(sr_session_ctx_t *session, struct lyd_node *ospf)
|
||||
fputs("router ospf\n", fp);
|
||||
num_areas = parse_ospf_areas(session, areas, fp);
|
||||
parse_ospf_redistribute(session, lydx_get_child(ospf, "redistribute"), fp);
|
||||
parse_ospf_static_neighbors(areas, fp);
|
||||
default_route = lydx_get_child(ospf, "default-route-advertise");
|
||||
if (default_route) {
|
||||
/* enable is obsolete in favor for enabled. */
|
||||
@@ -458,7 +492,8 @@ static void frr_daemons_write(int ospfd, int ripd, int bfdd)
|
||||
fp);
|
||||
|
||||
fclose(fp);
|
||||
rename(next, FRR_DAEMONS);
|
||||
if (rename(next, FRR_DAEMONS))
|
||||
ERROR("Failed to rename %s to %s: %m", next, FRR_DAEMONS);
|
||||
}
|
||||
|
||||
int routing_change(sr_session_ctx_t *session, struct lyd_node *config, struct lyd_node *diff, sr_event_t event, struct confd *confd)
|
||||
@@ -519,7 +554,6 @@ int routing_change(sr_session_ctx_t *session, struct lyd_node *config, struct ly
|
||||
num = parse_rip(session, lydx_get_child(cplane, "rip"), fp);
|
||||
if (num > 0) {
|
||||
touch(RIPD_SIGNAL_NEXT);
|
||||
ripd_enabled = 1;
|
||||
netd_enabled = 1;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -14,7 +14,7 @@ MODULES=(
|
||||
"ietf-routing@2018-03-13.yang"
|
||||
"ietf-ipv6-unicast-routing@2018-03-13.yang"
|
||||
"ietf-ipv4-unicast-routing@2018-03-13.yang"
|
||||
"ietf-ospf@2022-10-19.yang -e bfd -e explicit-router-id"
|
||||
"ietf-ospf@2022-10-19.yang -e bfd -e explicit-router-id -e hybrid-interface"
|
||||
"ietf-rip@2020-02-20.yang"
|
||||
"iana-bfd-types@2021-10-21.yang"
|
||||
"ietf-bfd-types@2022-09-22.yang"
|
||||
@@ -31,7 +31,7 @@ MODULES=(
|
||||
"ieee802-dot1q-types@2022-10-29.yang"
|
||||
"infix-ip@2025-11-02.yang"
|
||||
"infix-if-type@2026-01-07.yang"
|
||||
"infix-routing@2025-12-02.yang"
|
||||
"infix-routing@2026-03-11.yang"
|
||||
"ieee802-dot1ab-lldp@2022-03-15.yang"
|
||||
"infix-lldp@2025-05-05.yang"
|
||||
"infix-dhcp-common@2025-12-21.yang"
|
||||
|
||||
@@ -45,6 +45,13 @@ module infix-hardware {
|
||||
description "Initial";
|
||||
reference "internal";
|
||||
}
|
||||
feature wifi {
|
||||
description "WiFi support is an optional build-time feature in Infix.";
|
||||
}
|
||||
|
||||
feature gps {
|
||||
description "GPS support is an optional build-time feature in Infix.";
|
||||
}
|
||||
|
||||
typedef country-code {
|
||||
type string {
|
||||
@@ -104,11 +111,13 @@ module infix-hardware {
|
||||
description "This identity is used to a VPD memory on the device.";
|
||||
}
|
||||
identity wifi {
|
||||
if-feature wifi;
|
||||
base iahw:hardware-class;
|
||||
description "This identity is used to describe a WiFi radio/PHY";
|
||||
}
|
||||
|
||||
identity gps {
|
||||
if-feature gps;
|
||||
base iahw:hardware-class;
|
||||
description "GPS/GNSS receiver for time synchronization";
|
||||
}
|
||||
@@ -211,6 +220,7 @@ module infix-hardware {
|
||||
*/
|
||||
|
||||
container wifi-radio {
|
||||
if-feature wifi;
|
||||
when "derived-from-or-self(../iehw:class, 'ih:wifi')";
|
||||
presence "WiFi radio configuration";
|
||||
description
|
||||
@@ -534,6 +544,7 @@ module infix-hardware {
|
||||
*/
|
||||
|
||||
container gps-receiver {
|
||||
if-feature gps;
|
||||
when "derived-from-or-self(../iehw:class, 'ih:gps')";
|
||||
presence "GPS receiver configuration";
|
||||
description
|
||||
|
||||
@@ -26,6 +26,12 @@ module infix-routing {
|
||||
contact "kernelkit@googlegroups.com";
|
||||
description "Deviations and augments for ietf-routing, ietf-ospf, and ietf-rip.";
|
||||
|
||||
revision 2026-03-11 {
|
||||
description "Remove interface-type deviation to expose standard ietf-ospf
|
||||
interface types including point-to-multipoint and hybrid.
|
||||
Un-deviate static-neighbors for non-broadcast P2MP support.";
|
||||
}
|
||||
|
||||
revision 2025-12-02 {
|
||||
description "Add configurable OSPF debug logging container.
|
||||
Add RIP (Routing Information Protocol) support.";
|
||||
@@ -247,18 +253,6 @@ module infix-routing {
|
||||
}
|
||||
|
||||
/* OSPF */
|
||||
typedef infix-ospf-interface-type {
|
||||
type enumeration {
|
||||
enum broadcast {
|
||||
description
|
||||
"Specifies an OSPF broadcast multi-access network.";
|
||||
}
|
||||
enum point-to-point {
|
||||
description
|
||||
"Specifies an OSPF point-to-point network.";
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
deviation "/rt:routing/rt:control-plane-protocols/rt:control-plane-protocol" {
|
||||
@@ -367,11 +361,6 @@ module infix-routing {
|
||||
}
|
||||
}
|
||||
|
||||
deviation "/rt:routing/rt:control-plane-protocols/rt:control-plane-protocol/ospf:ospf/ospf:areas/ospf:area/ospf:interfaces/ospf:interface/ospf:interface-type" {
|
||||
deviate replace {
|
||||
type infix-ospf-interface-type;
|
||||
}
|
||||
}
|
||||
|
||||
deviation "/rt:routing/rt:control-plane-protocols/rt:control-plane-protocol/ospf:ospf/ospf:auto-cost" {
|
||||
deviate not-supported;
|
||||
@@ -463,9 +452,12 @@ module infix-routing {
|
||||
}
|
||||
|
||||
/* OSPF Area Interface */
|
||||
deviation "/rt:routing/rt:control-plane-protocols/rt:control-plane-protocol/ospf:ospf/ospf:areas/ospf:area/ospf:interfaces/ospf:interface/ospf:static-neighbors"
|
||||
{
|
||||
deviate not-supported;
|
||||
deviation "/rt:routing/rt:control-plane-protocols/rt:control-plane-protocol/ospf:ospf/ospf:areas/ospf:area/ospf:interfaces/ospf:interface/ospf:static-neighbors/ospf:neighbor" {
|
||||
deviate add {
|
||||
must "../../ospf:interface-type = 'point-to-multipoint' or ../../ospf:interface-type = 'non-broadcast'" {
|
||||
error-message "Static neighbors are only applicable to point-to-multipoint or non-broadcast interface types.";
|
||||
}
|
||||
}
|
||||
}
|
||||
deviation "/rt:routing/rt:control-plane-protocols/rt:control-plane-protocol/ospf:ospf/ospf:areas/ospf:area/ospf:interfaces/ospf:interface/ospf:multi-areas" {
|
||||
deviate not-supported;
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
MODULES=(
|
||||
"infix-hardware -e gps"
|
||||
)
|
||||
@@ -1,4 +1,5 @@
|
||||
MODULES=(
|
||||
"infix-interfaces -e wifi"
|
||||
"infix-hardware -e wifi"
|
||||
"infix-if-type -e wifi"
|
||||
)
|
||||
|
||||
@@ -178,9 +178,15 @@
|
||||
</COMMAND>
|
||||
|
||||
<COMMAND name="upgrade" help="Upgrade image of a container (writable layer is lost!)">
|
||||
<PARAM name="name" ptype="/CONTAINERS" help="Container name" />
|
||||
<PARAM name="name" ptype="/CONTAINERSa" help="Container name" />
|
||||
<SWITCH name="optional" min="0" max="1">
|
||||
<COMMAND name="reset-volumes" help="Delete named volumes, re-initialize from new image (all config lost!)" />
|
||||
</SWITCH>
|
||||
<ACTION sym="script" out="tty" interrupt="true">
|
||||
doas container upgrade $KLISH_PARAM_name
|
||||
if env | grep -q 'reset-volumes' >/dev/null; then
|
||||
opt="-R"
|
||||
fi
|
||||
doas container $opt upgrade $KLISH_PARAM_name
|
||||
</ACTION>
|
||||
</COMMAND>
|
||||
</COMMAND>
|
||||
|
||||
@@ -461,7 +461,7 @@ echo "Public: $pub"
|
||||
<ACTION sym="printl">peer</ACTION>
|
||||
</COMPL>
|
||||
</PARAM>
|
||||
<PARAM name="peer_addr" ptype="/STRING" help="Peer IP address" min="0" max="1"/>
|
||||
<PARAM name="peer" ptype="/STRING" help="Peer IP address" min="0" max="1"/>
|
||||
<SWITCH name="optional" min="0">
|
||||
<COMMAND name="brief" help="Show brief output" mode="switch"/>
|
||||
</SWITCH>
|
||||
@@ -471,7 +471,7 @@ echo "Public: $pub"
|
||||
BRIEF_ARG="brief"
|
||||
fi
|
||||
# Pass subcommand, optional peer address, and brief flag
|
||||
show bfd ${KLISH_PARAM_subcommand:+"$KLISH_PARAM_subcommand"} ${KLISH_PARAM_peer_addr:+"$KLISH_PARAM_peer_addr"} ${BRIEF_ARG:+"$BRIEF_ARG"} |pager
|
||||
show bfd ${KLISH_PARAM_subcommand:+"$KLISH_PARAM_subcommand"} ${KLISH_PARAM_peer:+"$KLISH_PARAM_peer"} ${BRIEF_ARG:+"$BRIEF_ARG"} |pager
|
||||
</ACTION>
|
||||
</COMMAND>
|
||||
|
||||
|
||||
@@ -4832,7 +4832,7 @@ def show_ospf_interfaces(json_data):
|
||||
state = target_iface.get('state', 'down')
|
||||
cost = target_iface.get('cost', 0)
|
||||
priority = target_iface.get('priority', 1)
|
||||
iface_type = target_iface.get('interface-type', 'unknown')
|
||||
iface_type = target_iface.get('interface-type', '')
|
||||
hello_interval = target_iface.get('hello-interval', 10)
|
||||
dead_interval = target_iface.get('dead-interval', 40)
|
||||
retransmit_interval = target_iface.get('retransmit-interval', 5)
|
||||
@@ -4908,9 +4908,11 @@ def show_ospf_interfaces(json_data):
|
||||
network_type_map = {
|
||||
'point-to-point': 'POINTOPOINT',
|
||||
'broadcast': 'BROADCAST',
|
||||
'non-broadcast': 'NBMA'
|
||||
'non-broadcast': 'NBMA',
|
||||
'point-to-multipoint': 'POINTOMULTIPOINT',
|
||||
'hybrid': 'POINTOMULTIPOINT'
|
||||
}
|
||||
network_type = network_type_map.get(iface_type, iface_type.upper())
|
||||
network_type = network_type_map.get(iface_type, iface_type.upper() if iface_type else 'LOOPBACK')
|
||||
|
||||
print(f"{name} is up")
|
||||
if ip_address:
|
||||
@@ -4950,30 +4952,50 @@ def show_ospf_interfaces(json_data):
|
||||
return
|
||||
|
||||
# Display table view (no specific interface)
|
||||
hdr = f"{'INTERFACE':<12} {'AREA':<12} {'STATE':<10} {'COST':<6} {'PRI':<4} {'DR':<15} {'BDR':<15} {'NBRS':<5}"
|
||||
print(Decore.invert(hdr))
|
||||
type_display_map = {
|
||||
'point-to-point': 'P2P',
|
||||
'broadcast': 'Broadcast',
|
||||
'non-broadcast': 'NBMA',
|
||||
'point-to-multipoint': 'P2MP',
|
||||
'hybrid': 'Hybrid'
|
||||
}
|
||||
|
||||
def fmt_state(state):
|
||||
if state in ('dr', 'bdr'):
|
||||
return state.upper()
|
||||
if state == 'dr-other':
|
||||
return 'DROther'
|
||||
return state.capitalize()
|
||||
|
||||
table = SimpleTable([
|
||||
Column('INTERFACE'),
|
||||
Column('AREA'),
|
||||
Column('TYPE'),
|
||||
Column('STATE'),
|
||||
Column('COST', 'right'),
|
||||
Column('PRI', 'right'),
|
||||
Column('DR'),
|
||||
Column('BDR'),
|
||||
Column('NBRS', 'right')
|
||||
])
|
||||
|
||||
for iface in all_interfaces:
|
||||
name = iface.get('name', 'unknown')
|
||||
area_id = iface.get('_area_id', '0.0.0.0')
|
||||
state = iface.get('state', 'down')
|
||||
iface_type = iface.get('interface-type', '')
|
||||
cost = iface.get('cost', 0)
|
||||
priority = iface.get('priority', 1)
|
||||
dr_id = iface.get('dr-router-id', '-')
|
||||
bdr_id = iface.get('bdr-router-id', '-')
|
||||
neighbors = iface.get('neighbors', {}).get('neighbor', [])
|
||||
nbr_count = len(neighbors)
|
||||
|
||||
# Capitalize state nicely
|
||||
state_display = state.upper() if state in ['dr', 'bdr'] else state.capitalize()
|
||||
if state == 'dr-other':
|
||||
state_display = 'DROther'
|
||||
table.row(name, area_id,
|
||||
type_display_map.get(iface_type, iface_type.capitalize() if iface_type else '-'),
|
||||
fmt_state(state),
|
||||
cost, priority, dr_id, bdr_id, len(neighbors))
|
||||
|
||||
# Shorten router IDs for display
|
||||
dr_display = dr_id if dr_id != '-' else '-'
|
||||
bdr_display = bdr_id if bdr_id != '-' else '-'
|
||||
|
||||
print(f"{name:<12} {area_id:<12} {state_display:<10} {cost:<6} {priority:<4} {dr_display:<15} {bdr_display:<15} {nbr_count:<5}")
|
||||
table.print()
|
||||
|
||||
|
||||
def show_ospf_neighbor(json_data):
|
||||
@@ -5527,7 +5549,8 @@ def main():
|
||||
global UNIT_TEST
|
||||
|
||||
try:
|
||||
json_data = json.load(sys.stdin)
|
||||
raw = sys.stdin.read()
|
||||
json_data = json.loads(raw) if raw.strip() else {}
|
||||
except json.JSONDecodeError:
|
||||
print("Error, invalid JSON input")
|
||||
sys.exit(1)
|
||||
|
||||
@@ -124,8 +124,15 @@ def add_areas(control_protocols):
|
||||
interface["enabled"] = iface["ospfEnabled"]
|
||||
if iface["networkType"] == "POINTOPOINT":
|
||||
interface["interface-type"] = "point-to-point"
|
||||
if iface["networkType"] == "BROADCAST":
|
||||
elif iface["networkType"] == "BROADCAST":
|
||||
interface["interface-type"] = "broadcast"
|
||||
elif iface["networkType"] == "POINTOMULTIPOINT":
|
||||
if iface.get("p2mpNonBroadcast", False):
|
||||
interface["interface-type"] = "point-to-multipoint"
|
||||
else:
|
||||
interface["interface-type"] = "hybrid"
|
||||
elif iface["networkType"] == "NBMA":
|
||||
interface["interface-type"] = "non-broadcast"
|
||||
|
||||
if iface.get("state"):
|
||||
# Wev've never seen "DependUpon", and has no entry in
|
||||
|
||||
@@ -8,7 +8,7 @@ Firewall configuration suitable for end devices on untrusted networks.
|
||||
|
||||
image::basic.svg[align=center, scaledwidth=50%]
|
||||
|
||||
- Single zone configuration, "public", with action=drop
|
||||
- Single zone configuration, "public-untrusted-net", with `action=drop`
|
||||
- Allowed services: SSH (port 22), DHCPv6-client, mySSH (custom, port 222)
|
||||
- All other ports (HTTP, HTTPS, Telnet, etc.) blocked
|
||||
- Check that unused interfaces are automatically assigned to default zone
|
||||
|
||||
@@ -5,7 +5,7 @@ Firewall configuration suitable for end devices on untrusted networks.
|
||||
|
||||
image::basic.svg[align=center, scaledwidth=50%]
|
||||
|
||||
- Single zone configuration, "public", with action=drop
|
||||
- Single zone configuration, "public-untrusted-net", with `action=drop`
|
||||
- Allowed services: SSH (port 22), DHCPv6-client, mySSH (custom, port 222)
|
||||
- All other ports (HTTP, HTTPS, Telnet, etc.) blocked
|
||||
- Check that unused interfaces are automatically assigned to default zone
|
||||
@@ -47,7 +47,7 @@ with infamy.Test() as test:
|
||||
|
||||
target.put_config_dict("infix-firewall", {
|
||||
"firewall": {
|
||||
"default": "public",
|
||||
"default": "public-untrusted-net",
|
||||
"logging": "all",
|
||||
"service": [{
|
||||
"name": "mySSH",
|
||||
@@ -69,7 +69,9 @@ with infamy.Test() as test:
|
||||
"interface": [mgmt_if],
|
||||
"service": ["ssh", "netconf", "restconf"]
|
||||
}, {
|
||||
"name": "public",
|
||||
# 20-char name, exceeds old iptables-derived 17-char limit
|
||||
# Verifies we allow long names with nftables, issue #1389
|
||||
"name": "public-untrusted-net",
|
||||
"description": "Public untrusted network",
|
||||
"action": "drop",
|
||||
"interface": [data_if],
|
||||
@@ -80,7 +82,7 @@ with infamy.Test() as test:
|
||||
|
||||
# Wait for configuration to be activated
|
||||
infamy.Firewall.wait_for_operational(target, {
|
||||
"public": {"action": "drop"},
|
||||
"public-untrusted-net": {"action": "drop"},
|
||||
"mgmt": {"action": "accept"}
|
||||
})
|
||||
|
||||
@@ -88,7 +90,7 @@ with infamy.Test() as test:
|
||||
data = target.get_data("/infix-firewall:firewall")
|
||||
fw = data["firewall"]
|
||||
|
||||
assert fw["default"] == "public"
|
||||
assert fw["default"] == "public-untrusted-net"
|
||||
|
||||
services = {svc["name"]: svc for svc in fw.get("service", [])}
|
||||
assert "mySSH" in services, "Custom service mySSH not found"
|
||||
@@ -106,8 +108,8 @@ with infamy.Test() as test:
|
||||
assert int(port_entry["lower"]) == 8080
|
||||
|
||||
zones = {zone["name"]: zone for zone in fw["zone"]}
|
||||
assert "public" in zones, "Public zone not found in configuration"
|
||||
public_zone = zones["public"]
|
||||
assert "public-untrusted-net" in zones, "public-untrusted-net zone not found in configuration"
|
||||
public_zone = zones["public-untrusted-net"]
|
||||
assert public_zone["action"] == "drop"
|
||||
assert data_if in public_zone["interface"]
|
||||
assert "ssh" in public_zone["service"]
|
||||
@@ -119,13 +121,13 @@ with infamy.Test() as test:
|
||||
data = target.get_data("/infix-firewall:firewall")
|
||||
fw = data["firewall"]
|
||||
|
||||
assert fw["default"] == "public", "Default zone should be 'public'"
|
||||
assert fw["default"] == "public-untrusted-net", "Default zone should be 'public-untrusted-net'"
|
||||
|
||||
zones = {zone["name"]: zone for zone in fw["zone"]}
|
||||
public_zone = zones["public"]
|
||||
public_zone = zones["public-untrusted-net"]
|
||||
|
||||
assert unused_if in public_zone["interface"], \
|
||||
f"Unused interface {unused_if} should be in default zone 'public', got interfaces: {public_zone['interface']}"
|
||||
f"Unused interface {unused_if} should be in default zone 'public-untrusted-net', got interfaces: {public_zone['interface']}"
|
||||
|
||||
with infamy.IsolatedMacVlan(host_data) as ns:
|
||||
ns.addip(HOST_IP)
|
||||
|
||||
@@ -10,6 +10,8 @@ Tests verifying standard routing protocols and configuration:
|
||||
- OSPF with BFD (Bidirectional Forwarding Detection)
|
||||
- OSPF default route advertisement and propagation
|
||||
- OSPF debug logging configuration and verification
|
||||
- OSPF point-to-multipoint hybrid (broadcast) interface type
|
||||
- OSPF point-to-multipoint (non-broadcast) interface type with static neighbors
|
||||
- RIP basic neighbor discovery and route exchange
|
||||
- RIP passive interface configuration
|
||||
- RIP route redistribution (connected, static, and OSPF)
|
||||
@@ -46,6 +48,14 @@ include::ospf_debug/Readme.adoc[]
|
||||
|
||||
<<<
|
||||
|
||||
include::ospf_point_to_multipoint_hybrid/Readme.adoc[]
|
||||
|
||||
<<<
|
||||
|
||||
include::ospf_point_to_multipoint/Readme.adoc[]
|
||||
|
||||
<<<
|
||||
|
||||
include::rip_basic/Readme.adoc[]
|
||||
|
||||
<<<
|
||||
|
||||
@@ -29,6 +29,12 @@
|
||||
- name: OSPF Debug Logging
|
||||
case: ospf_debug/test.py
|
||||
|
||||
- name: OSPF Point-to-Multipoint Hybrid
|
||||
case: ospf_point_to_multipoint_hybrid/test.py
|
||||
|
||||
- name: OSPF Point-to-Multipoint
|
||||
case: ospf_point_to_multipoint/test.py
|
||||
|
||||
- name: RIP Basic
|
||||
case: rip_basic/test.py
|
||||
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
test.adoc
|
||||
@@ -0,0 +1,49 @@
|
||||
=== OSPF Point-to-Multipoint
|
||||
|
||||
ifdef::topdoc[:imagesdir: {topdoc}../../test/case/routing/ospf_point_to_multipoint]
|
||||
|
||||
==== Description
|
||||
|
||||
Verify OSPF point-to-multipoint (non-broadcast) interface type by
|
||||
configuring three routers on a shared multi-access network with the
|
||||
ietf-ospf 'point-to-multipoint' interface type and static neighbors.
|
||||
This maps to FRR's 'point-to-multipoint non-broadcast' network type,
|
||||
which requires manual neighbor configuration since there is no
|
||||
multicast neighbor discovery.
|
||||
|
||||
R2 acts as the hub, bridging two physical links (link1, link2) into a
|
||||
single broadcast domain (br0). R1 and R3 each connect to one of R2's
|
||||
ports. The test verifies that all routers form OSPF adjacencies via
|
||||
unicast, exchange routes, and that the interface type is correctly
|
||||
reported as point-to-multipoint.
|
||||
|
||||
....
|
||||
+------------------+ +------------------+
|
||||
| R1 | | R3 |
|
||||
| 10.0.1.1/32 | | 10.0.3.1/32 |
|
||||
| (lo) | | (lo) |
|
||||
+--------+---------+ +--------+---------+
|
||||
| .1 | .3
|
||||
| +------------------+ |
|
||||
+----link1------+ R2 +------link2--------+
|
||||
| 10.0.2.1/32 |
|
||||
| (lo) |
|
||||
| br0: 10.0.123.2 |
|
||||
+------------------+
|
||||
10.0.123.0/24
|
||||
(P2MP non-broadcast / shared segment)
|
||||
....
|
||||
|
||||
==== Topology
|
||||
|
||||
image::topology.svg[OSPF Point-to-Multipoint topology, align=center, scaledwidth=75%]
|
||||
|
||||
==== Sequence
|
||||
|
||||
. Set up topology and attach to target DUTs
|
||||
. Configure targets
|
||||
. Wait for OSPF routes
|
||||
. Verify interface type is point-to-multipoint
|
||||
. Verify connectivity between all DUTs
|
||||
|
||||
|
||||
+341
@@ -0,0 +1,341 @@
|
||||
#!/usr/bin/env python3
|
||||
"""OSPF Point-to-Multipoint
|
||||
|
||||
Verify OSPF point-to-multipoint (non-broadcast) interface type by
|
||||
configuring three routers on a shared multi-access network with the
|
||||
ietf-ospf 'point-to-multipoint' interface type and static neighbors.
|
||||
This maps to FRR's 'point-to-multipoint non-broadcast' network type,
|
||||
which requires manual neighbor configuration since there is no
|
||||
multicast neighbor discovery.
|
||||
|
||||
R2 acts as the hub, bridging two physical links (link1, link2) into a
|
||||
single broadcast domain (br0). R1 and R3 each connect to one of R2's
|
||||
ports. The test verifies that all routers form OSPF adjacencies via
|
||||
unicast, exchange routes, and that the interface type is correctly
|
||||
reported as point-to-multipoint.
|
||||
|
||||
....
|
||||
+------------------+ +------------------+
|
||||
| R1 | | R3 |
|
||||
| 10.0.1.1/32 | | 10.0.3.1/32 |
|
||||
| (lo) | | (lo) |
|
||||
+--------+---------+ +--------+---------+
|
||||
| .1 | .3
|
||||
| +------------------+ |
|
||||
+----link1------+ R2 +------link2--------+
|
||||
| 10.0.2.1/32 |
|
||||
| (lo) |
|
||||
| br0: 10.0.123.2 |
|
||||
+------------------+
|
||||
10.0.123.0/24
|
||||
(P2MP non-broadcast / shared segment)
|
||||
....
|
||||
"""
|
||||
|
||||
import infamy
|
||||
import infamy.route as route
|
||||
from infamy.util import until, parallel
|
||||
|
||||
|
||||
def config_target1(target, link, data):
|
||||
target.put_config_dicts({
|
||||
"ietf-interfaces": {
|
||||
"interfaces": {
|
||||
"interface": [
|
||||
{
|
||||
"name": link,
|
||||
"enabled": True,
|
||||
"ipv4": {
|
||||
"forwarding": True,
|
||||
"address": [{
|
||||
"ip": "10.0.123.1",
|
||||
"prefix-length": 24
|
||||
}]
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": data,
|
||||
"enabled": True,
|
||||
"ipv4": {
|
||||
"forwarding": True,
|
||||
"address": [{
|
||||
"ip": "10.0.10.1",
|
||||
"prefix-length": 24
|
||||
}]
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": "lo",
|
||||
"enabled": True,
|
||||
"ipv4": {
|
||||
"address": [{
|
||||
"ip": "10.0.1.1",
|
||||
"prefix-length": 32
|
||||
}]
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
"ietf-routing": {
|
||||
"routing": {
|
||||
"control-plane-protocols": {
|
||||
"control-plane-protocol": [{
|
||||
"type": "infix-routing:ospfv2",
|
||||
"name": "default",
|
||||
"ospf": {
|
||||
"redistribute": {
|
||||
"redistribute": [{
|
||||
"protocol": "connected"
|
||||
}]
|
||||
},
|
||||
"areas": {
|
||||
"area": [{
|
||||
"area-id": "0.0.0.0",
|
||||
"interfaces": {
|
||||
"interface": [{
|
||||
"name": link,
|
||||
"enabled": True,
|
||||
"hello-interval": 1,
|
||||
"dead-interval": 3,
|
||||
"interface-type": "point-to-multipoint",
|
||||
"static-neighbors": {
|
||||
"neighbor": [
|
||||
{"identifier": "10.0.123.2"},
|
||||
{"identifier": "10.0.123.3"}
|
||||
]
|
||||
}
|
||||
}, {
|
||||
"name": "lo",
|
||||
"enabled": True
|
||||
}]
|
||||
}
|
||||
}]
|
||||
}
|
||||
}
|
||||
}]
|
||||
}
|
||||
}
|
||||
}
|
||||
})
|
||||
|
||||
|
||||
def config_target2(target, link1, link2):
|
||||
target.put_config_dicts({
|
||||
"ietf-interfaces": {
|
||||
"interfaces": {
|
||||
"interface": [
|
||||
{
|
||||
"name": "br0",
|
||||
"type": "infix-if-type:bridge",
|
||||
"enabled": True,
|
||||
"ipv4": {
|
||||
"forwarding": True,
|
||||
"address": [{
|
||||
"ip": "10.0.123.2",
|
||||
"prefix-length": 24
|
||||
}]
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": link1,
|
||||
"enabled": True,
|
||||
"infix-interfaces:bridge-port": {
|
||||
"bridge": "br0"
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": link2,
|
||||
"enabled": True,
|
||||
"infix-interfaces:bridge-port": {
|
||||
"bridge": "br0"
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": "lo",
|
||||
"enabled": True,
|
||||
"ipv4": {
|
||||
"address": [{
|
||||
"ip": "10.0.2.1",
|
||||
"prefix-length": 32
|
||||
}]
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
"ietf-routing": {
|
||||
"routing": {
|
||||
"control-plane-protocols": {
|
||||
"control-plane-protocol": [{
|
||||
"type": "infix-routing:ospfv2",
|
||||
"name": "default",
|
||||
"ospf": {
|
||||
"redistribute": {
|
||||
"redistribute": [{
|
||||
"protocol": "connected"
|
||||
}]
|
||||
},
|
||||
"areas": {
|
||||
"area": [{
|
||||
"area-id": "0.0.0.0",
|
||||
"interfaces": {
|
||||
"interface": [{
|
||||
"name": "br0",
|
||||
"enabled": True,
|
||||
"hello-interval": 1,
|
||||
"dead-interval": 3,
|
||||
"interface-type": "point-to-multipoint",
|
||||
"static-neighbors": {
|
||||
"neighbor": [
|
||||
{"identifier": "10.0.123.1"},
|
||||
{"identifier": "10.0.123.3"}
|
||||
]
|
||||
}
|
||||
}, {
|
||||
"name": "lo",
|
||||
"enabled": True
|
||||
}]
|
||||
}
|
||||
}]
|
||||
}
|
||||
}
|
||||
}]
|
||||
}
|
||||
}
|
||||
}
|
||||
})
|
||||
|
||||
|
||||
def config_target3(target, link, data):
|
||||
target.put_config_dicts({
|
||||
"ietf-interfaces": {
|
||||
"interfaces": {
|
||||
"interface": [
|
||||
{
|
||||
"name": link,
|
||||
"enabled": True,
|
||||
"ipv4": {
|
||||
"forwarding": True,
|
||||
"address": [{
|
||||
"ip": "10.0.123.3",
|
||||
"prefix-length": 24
|
||||
}]
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": data,
|
||||
"enabled": True,
|
||||
"ipv4": {
|
||||
"forwarding": True,
|
||||
"address": [{
|
||||
"ip": "10.0.30.1",
|
||||
"prefix-length": 24
|
||||
}]
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": "lo",
|
||||
"enabled": True,
|
||||
"ipv4": {
|
||||
"address": [{
|
||||
"ip": "10.0.3.1",
|
||||
"prefix-length": 32
|
||||
}]
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
"ietf-routing": {
|
||||
"routing": {
|
||||
"control-plane-protocols": {
|
||||
"control-plane-protocol": [{
|
||||
"type": "infix-routing:ospfv2",
|
||||
"name": "default",
|
||||
"ospf": {
|
||||
"redistribute": {
|
||||
"redistribute": [{
|
||||
"protocol": "connected"
|
||||
}]
|
||||
},
|
||||
"areas": {
|
||||
"area": [{
|
||||
"area-id": "0.0.0.0",
|
||||
"interfaces": {
|
||||
"interface": [{
|
||||
"name": link,
|
||||
"enabled": True,
|
||||
"hello-interval": 1,
|
||||
"dead-interval": 3,
|
||||
"interface-type": "point-to-multipoint",
|
||||
"static-neighbors": {
|
||||
"neighbor": [
|
||||
{"identifier": "10.0.123.1"},
|
||||
{"identifier": "10.0.123.2"}
|
||||
]
|
||||
}
|
||||
}, {
|
||||
"name": "lo",
|
||||
"enabled": True
|
||||
}]
|
||||
}
|
||||
}]
|
||||
}
|
||||
}
|
||||
}]
|
||||
}
|
||||
}
|
||||
}
|
||||
})
|
||||
|
||||
|
||||
with infamy.Test() as test:
|
||||
with test.step("Set up topology and attach to target DUTs"):
|
||||
env = infamy.Env()
|
||||
R1 = env.attach("R1", "mgmt")
|
||||
R2 = env.attach("R2", "mgmt")
|
||||
R3 = env.attach("R3", "mgmt")
|
||||
|
||||
|
||||
with test.step("Configure targets"):
|
||||
_, R1link = env.ltop.xlate("R1", "link")
|
||||
_, R1data = env.ltop.xlate("R1", "data")
|
||||
_, R2link1 = env.ltop.xlate("R2", "link1")
|
||||
_, R2link2 = env.ltop.xlate("R2", "link2")
|
||||
_, R3link = env.ltop.xlate("R3", "link")
|
||||
_, R3data = env.ltop.xlate("R3", "data")
|
||||
|
||||
parallel(config_target1(R1, R1link, R1data),
|
||||
config_target2(R2, R2link1, R2link2),
|
||||
config_target3(R3, R3link, R3data))
|
||||
|
||||
with test.step("Wait for OSPF routes"):
|
||||
print("Waiting for OSPF routes from all routers")
|
||||
until(lambda: route.ipv4_route_exist(R1, "10.0.2.1/32", proto="ietf-ospf:ospfv2"), attempts=200)
|
||||
until(lambda: route.ipv4_route_exist(R1, "10.0.3.1/32", proto="ietf-ospf:ospfv2"), attempts=200)
|
||||
until(lambda: route.ipv4_route_exist(R2, "10.0.1.1/32", proto="ietf-ospf:ospfv2"), attempts=200)
|
||||
until(lambda: route.ipv4_route_exist(R2, "10.0.3.1/32", proto="ietf-ospf:ospfv2"), attempts=200)
|
||||
until(lambda: route.ipv4_route_exist(R3, "10.0.1.1/32", proto="ietf-ospf:ospfv2"), attempts=200)
|
||||
until(lambda: route.ipv4_route_exist(R3, "10.0.2.1/32", proto="ietf-ospf:ospfv2"), attempts=200)
|
||||
|
||||
with test.step("Verify interface type is point-to-multipoint"):
|
||||
print("Checking OSPF interface type on all routers")
|
||||
assert route.ospf_get_interface_type(R1, "0.0.0.0", R1link) == "point-to-multipoint"
|
||||
assert route.ospf_get_interface_type(R2, "0.0.0.0", "br0") == "point-to-multipoint"
|
||||
assert route.ospf_get_interface_type(R3, "0.0.0.0", R3link) == "point-to-multipoint"
|
||||
|
||||
with test.step("Verify connectivity between all DUTs"):
|
||||
_, hport1 = env.ltop.xlate("PC", "data1")
|
||||
_, hport2 = env.ltop.xlate("PC", "data2")
|
||||
with infamy.IsolatedMacVlan(hport1) as ns1, \
|
||||
infamy.IsolatedMacVlan(hport2) as ns2:
|
||||
ns1.addip("10.0.10.2")
|
||||
ns2.addip("10.0.30.2")
|
||||
ns1.addroute("10.0.3.1/32", "10.0.10.1")
|
||||
ns2.addroute("10.0.1.1/32", "10.0.30.1")
|
||||
parallel(
|
||||
lambda: ns1.must_reach("10.0.3.1"),
|
||||
lambda: ns2.must_reach("10.0.1.1"),
|
||||
)
|
||||
test.succeed()
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user