Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8d57337fcf | ||
|
|
b29bbc56f9 | ||
|
|
05e34a5441 | ||
|
|
ec52472949 | ||
|
|
05fe5b5d46 | ||
|
|
17a1b80b83 | ||
|
|
461c092346 | ||
|
|
b2a7c0aac5 | ||
|
|
e3a0426154 | ||
|
|
2a51fc41d7 | ||
|
|
b0de6fc89c | ||
|
|
52ba6d2ecc | ||
|
|
ef9cfafdd9 | ||
|
|
dc0519043e | ||
|
|
4c6aa115a3 | ||
|
|
7291b812a6 | ||
|
|
56ea7faa7c | ||
|
|
ca1d40cf7a | ||
|
|
5b370745fd | ||
|
|
2a766d7886 | ||
|
|
1bb9f778ff | ||
|
|
d2abdf0f64 | ||
|
|
5df26b217a | ||
|
|
b3ae276a14 | ||
|
|
5bbb83a3e6 | ||
|
|
e233dbc6da | ||
|
|
d83c708cd1 | ||
|
|
d333c66f9c | ||
|
|
1b11bae8eb | ||
|
|
2744e6ee85 | ||
|
|
9b41139066 | ||
|
|
d0d95f4098 | ||
|
|
84dfaf7c03 | ||
|
|
afcc40589a | ||
|
|
208f7c9f08 | ||
|
|
f8c68a38af | ||
|
|
8994879e26 | ||
|
|
b5a0ea0b1b | ||
|
|
435406af68 | ||
|
|
79107d2548 | ||
|
|
7a9cece84f | ||
|
|
b8ba1a1042 | ||
|
|
60676e21be | ||
|
|
763750b6ed | ||
|
|
23c5f16a4f | ||
|
|
5d3fce35c8 | ||
|
|
6d6064f946 | ||
|
|
a4e5c27b9d | ||
|
|
ddc57ed6ae | ||
|
|
2ae1a70bac | ||
|
|
20350fa52c | ||
|
|
f866cf15b4 | ||
|
|
7030f85484 | ||
|
|
d194b52629 | ||
|
|
674fd6c396 | ||
|
|
0229057612 | ||
|
|
b3450d004d | ||
|
|
5c3a476cbc | ||
|
|
ba677bf5c1 | ||
|
|
a0c0a5e45c | ||
|
|
0fd8696860 | ||
|
|
ebc4ce1d90 | ||
|
|
25ff6f54f5 | ||
|
|
e28532d042 | ||
|
|
797c5c09f1 | ||
|
|
be6d287b19 | ||
|
|
67ea7a74c1 | ||
|
|
a365238854 | ||
|
|
d02f45d777 | ||
|
|
19c820fac2 | ||
|
|
a47e141dc4 | ||
|
|
93db076d72 | ||
|
|
322811d712 | ||
|
|
bbc01a5e54 | ||
|
|
584d6c57df | ||
|
|
4d398bbf57 | ||
|
|
a7d2e1b806 | ||
|
|
390e60cfcb | ||
|
|
f62d049aa9 | ||
|
|
4554b77105 | ||
|
|
0c6d96f8a9 | ||
|
|
473cda35bb | ||
|
|
227f1290fd | ||
|
|
12f1edb435 | ||
|
|
f5c549f669 | ||
|
|
7e19ee8777 | ||
|
|
7e0e6f244d | ||
|
|
d326939e10 | ||
|
|
a975f55284 | ||
|
|
89392c56be | ||
|
|
67ec3faa54 | ||
|
|
9272ae382d | ||
|
|
a78eeee651 | ||
|
|
1c3086be94 | ||
|
|
cd19b626a7 | ||
|
|
b5b310f3c8 | ||
|
|
f875056706 | ||
|
|
e412c28c37 | ||
|
|
3ccbdf2f0b | ||
|
|
8b3ba1f5c5 | ||
|
|
629f0aa74a | ||
|
|
dc2d429093 | ||
|
|
b1146cbb31 | ||
|
|
10ab88d93f | ||
|
|
d07c8a9b5e | ||
|
|
c40c1d0c10 | ||
|
|
beabc1fe5b | ||
|
|
d9611c48a9 | ||
|
|
d7120df65f | ||
|
|
423e78aba9 | ||
|
|
9f03e0a34b | ||
|
|
5570b13791 | ||
|
|
2c80c65962 | ||
|
|
bfb5b14ea0 | ||
|
|
f00511d235 | ||
|
|
f8432f59fb | ||
|
|
9720c7000f | ||
|
|
974ea7260f | ||
|
|
b0bd1dad11 | ||
|
|
ff96401ce2 | ||
|
|
9853e08145 | ||
|
|
04fbbc6fc8 | ||
|
|
6e30d4f590 | ||
|
|
f9733dc52d | ||
|
|
1a33604ed6 | ||
|
|
a80a731324 | ||
|
|
6e84a75550 | ||
|
|
2ef7490f69 | ||
|
|
8b10678dee | ||
|
|
7ac15796e3 | ||
|
|
e36aac736e | ||
|
|
fc328eb79b | ||
|
|
0ac5630be0 | ||
|
|
1dda8075cb | ||
|
|
613ec53fdf | ||
|
|
b2bf034a91 | ||
|
|
12482a5ab5 | ||
|
|
f2f52f8518 | ||
|
|
917eec3f25 | ||
|
|
6271e40ce0 | ||
|
|
bc535099ec | ||
|
|
a9c722fcd5 | ||
|
|
f8f73b89cb | ||
|
|
ad28fd9db5 | ||
|
|
9d5fd5db2f | ||
|
|
76c314a23a | ||
|
|
187c19639f | ||
|
|
68dfec210c | ||
|
|
50e678232d | ||
|
|
3b56b249b5 | ||
|
|
be3c76b7bf | ||
|
|
4fa933f4f5 | ||
|
|
a2f57bdd4d | ||
|
|
f4fd538a58 | ||
|
|
5cdabe555f | ||
|
|
60afb15488 | ||
|
|
ba010c0117 | ||
|
|
61b5c8954d | ||
|
|
40147a5265 | ||
|
|
be6cf4dcd5 | ||
|
|
bbea2bceae | ||
|
|
69fbf9e854 | ||
|
|
61d4325d2c | ||
|
|
44ade8b761 | ||
|
|
4e50c96567 | ||
|
|
c0225b7096 | ||
|
|
c31c80c154 | ||
|
|
91fc7466c2 | ||
|
|
5286c16480 | ||
|
|
fc7083dd86 | ||
|
|
8e5d49665b | ||
|
|
46fb3a061c | ||
|
|
74dcd5889f | ||
|
|
9a2f143d31 | ||
|
|
76cc1e8061 | ||
|
|
762915b703 | ||
|
|
5fd5d1254a | ||
|
|
1012759a41 | ||
|
|
925a43dead | ||
|
|
6958c9bb1a | ||
|
|
65eb4c072a | ||
|
|
c3d17586fd | ||
|
|
4c17a79de6 | ||
|
|
7fa141178f | ||
|
|
f7236fd59c | ||
|
|
aecb4546f8 | ||
|
|
9b0837100c | ||
|
|
b650d91895 | ||
|
|
68e4dc3e9b | ||
|
|
e8f14e1a06 | ||
|
|
230bd77623 | ||
|
|
0bc998c24a | ||
|
|
6618bcdf1e | ||
|
|
cf4de78d29 | ||
|
|
555de63fd6 | ||
|
|
9d4d521fa2 |
@@ -272,7 +272,7 @@ other contributions that are not aligned to this Code of Conduct."*
|
||||
[PEP-8]: https://peps.python.org/pep-0008/
|
||||
[RDD]: https://tom.preston-werner.com/2010/08/23/readme-driven-development
|
||||
[cbeams]: https://cbea.ms/git-commit/#seven-rules
|
||||
[conduct]: CODE-OF-CONDUCT.md
|
||||
[conduct]: CODE_OF_CONDUCT.md
|
||||
[DCO]: https://developercertificate.org/
|
||||
[closing]: https://docs.github.com/en/get-started/writing-on-github/working-with-advanced-formatting/using-keywords-in-issues-and-pull-requests
|
||||
[gpg-verify]: https://docs.github.com/en/authentication/managing-commit-signature-verification
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
version: 2
|
||||
updates:
|
||||
- package-ecosystem: gomod
|
||||
directory: /src/webui
|
||||
schedule:
|
||||
interval: weekly
|
||||
# goyang is pinned to our kernelkit fork via a replace directive and
|
||||
# stepped by hand when we add patches; leave it for Dependabot to ignore.
|
||||
ignore:
|
||||
- dependency-name: github.com/openconfig/goyang
|
||||
|
||||
- package-ecosystem: gomod
|
||||
directory: /src/netbrowse
|
||||
schedule:
|
||||
interval: weekly
|
||||
@@ -10,7 +10,7 @@ jobs:
|
||||
name: Add issue to project Infix&co
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/add-to-project@v1.0.2
|
||||
- uses: actions/add-to-project@v2
|
||||
with:
|
||||
project-url: https://github.com/orgs/kernelkit/projects/3
|
||||
github-token: ${{ secrets.ADD_TO_PROJECT }}
|
||||
|
||||
@@ -78,7 +78,7 @@ jobs:
|
||||
|
||||
- name: Configure ${{ matrix.defconfig }}_defconfig
|
||||
run: |
|
||||
make ${{ matrix.defconfig }}_defconfig
|
||||
make ${{ matrix.defconfig }}_defconfig apply-mirror
|
||||
|
||||
- name: Build ${{ matrix.defconfig }}_defconfig
|
||||
run: |
|
||||
@@ -108,17 +108,11 @@ jobs:
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- uses: actions/download-artifact@v7
|
||||
- uses: actions/download-artifact@v8
|
||||
with:
|
||||
pattern: "artifact-*"
|
||||
merge-multiple: true
|
||||
|
||||
- name: Create checksums ...
|
||||
run: |
|
||||
for file in *.tar.gz; do
|
||||
sha256sum $file > $file.sha256
|
||||
done
|
||||
|
||||
- uses: ncipollo/release-action@v1
|
||||
with:
|
||||
allowUpdates: true
|
||||
@@ -128,7 +122,7 @@ jobs:
|
||||
prerelease: true
|
||||
tag: "latest-boot"
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
artifacts: "*.tar.gz*"
|
||||
artifacts: "*.tar.gz"
|
||||
|
||||
- name: Summary
|
||||
run: |
|
||||
|
||||
@@ -173,7 +173,7 @@ jobs:
|
||||
export BUILD_DIR=$PWD/build
|
||||
export BR2_EXTERNAL_INFIX_PATH=$PWD
|
||||
export RELEASE=""
|
||||
export INFIX_ID="infix"
|
||||
export IX_ID="infix"
|
||||
|
||||
for target in $TARGETS; do
|
||||
export BINARIES_DIR=$PWD/output_${target}/images
|
||||
@@ -223,15 +223,6 @@ jobs:
|
||||
output/images/*-emmc.img*
|
||||
retention-days: 30
|
||||
|
||||
- name: Create checksums
|
||||
run: |
|
||||
cd output/images/
|
||||
for file in *-sdcard.img *-emmc.img; do
|
||||
if [ -f "$file" ]; then
|
||||
sha256sum "$file" > "$file.sha256"
|
||||
fi
|
||||
done
|
||||
|
||||
- name: Upload to release
|
||||
uses: ncipollo/release-action@v1
|
||||
with:
|
||||
@@ -242,7 +233,7 @@ jobs:
|
||||
prerelease: true
|
||||
tag: "latest-boot"
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
artifacts: "output/images/*-sdcard.img*,output/images/*-emmc.img*"
|
||||
artifacts: "output/images/*-sdcard.img,output/images/*-emmc.img"
|
||||
|
||||
- name: Generate summary
|
||||
run: |
|
||||
|
||||
@@ -45,13 +45,16 @@ jobs:
|
||||
target: ${{ matrix.target }}
|
||||
enabled: ${{ inputs.use_cache }}
|
||||
|
||||
# WebUI images bundle the mkdocs User's Guide via post-build.sh.
|
||||
- uses: kernelkit/actions/setup-mkdocs@v1.2
|
||||
|
||||
- name: Configure & Build
|
||||
env:
|
||||
INFIX_RELEASE: ${{ steps.vars.outputs.ver }}
|
||||
run: |
|
||||
target=${{ matrix.target }}_defconfig
|
||||
echo "Building $target ..."
|
||||
make $target
|
||||
make $target apply-mirror
|
||||
make
|
||||
|
||||
- name: Generate SBOM from Build
|
||||
@@ -67,6 +70,25 @@ jobs:
|
||||
run: |
|
||||
make test-spec
|
||||
|
||||
# rootfs.squashfs is still present here; it is stripped from the
|
||||
# tarball below. mkimage pulls the rpi64 bootloader from the
|
||||
# latest-boot release and uses the freshly built host genimage.
|
||||
- name: Build Raspberry Pi image
|
||||
if: matrix.target == 'aarch64'
|
||||
env:
|
||||
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
run: |
|
||||
./utils/mkimage.sh -d -r output raspberrypi-rpi64
|
||||
mkdir -p rpi-image
|
||||
mv output/images/*-rpi64-sdcard.img rpi-image/
|
||||
xz -T0 rpi-image/*-rpi64-sdcard.img
|
||||
|
||||
- uses: actions/upload-artifact@v7
|
||||
if: matrix.target == 'aarch64'
|
||||
with:
|
||||
name: artifact-rpi64-image
|
||||
path: rpi-image/*.img.xz
|
||||
|
||||
- name: Prepare Artifacts
|
||||
run: |
|
||||
cd output/
|
||||
@@ -95,3 +117,8 @@ jobs:
|
||||
with:
|
||||
name: artifact-disk-image-${{ matrix.target }}
|
||||
path: output/images/*.qcow2
|
||||
|
||||
- uses: actions/upload-artifact@v7
|
||||
with:
|
||||
name: artifact-pkg-${{ matrix.target }}
|
||||
path: output/images/*.pkg
|
||||
|
||||
@@ -124,9 +124,12 @@ jobs:
|
||||
with:
|
||||
target: ${{ env.TARGET }}
|
||||
|
||||
# WebUI images bundle the mkdocs User's Guide via post-build.sh.
|
||||
- uses: kernelkit/actions/setup-mkdocs@v1.2
|
||||
|
||||
- name: Configure ${{ env.TARGET }}
|
||||
run: |
|
||||
make ${{ env.TARGET }}_defconfig
|
||||
make ${{ env.TARGET }}_defconfig apply-mirror
|
||||
|
||||
- name: Cleanup stale containers and ports
|
||||
run: |
|
||||
|
||||
@@ -103,7 +103,7 @@ jobs:
|
||||
|
||||
- name: Create pull request
|
||||
if: steps.check.outputs.new_release == 'true'
|
||||
uses: actions/github-script@v8
|
||||
uses: actions/github-script@v9
|
||||
with:
|
||||
github-token: ${{ secrets.KERNEL_UPDATE_TOKEN }}
|
||||
script: |
|
||||
|
||||
@@ -0,0 +1,68 @@
|
||||
name: Go Vulnerability Scan
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- 'src/webui/**'
|
||||
- 'src/netbrowse/**'
|
||||
- '.github/workflows/govulncheck.yml'
|
||||
pull_request:
|
||||
paths:
|
||||
- 'src/webui/**'
|
||||
- 'src/netbrowse/**'
|
||||
- '.github/workflows/govulncheck.yml'
|
||||
schedule:
|
||||
- cron: '5 0 * * 6' # Saturday at 00:05 UTC, same as Coverity
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
govulncheck:
|
||||
if: ${{ github.repository_owner == 'kernelkit' }}
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
module:
|
||||
- src/webui
|
||||
- src/netbrowse
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- uses: actions/setup-go@v6
|
||||
with:
|
||||
go-version: stable
|
||||
|
||||
- name: Install govulncheck
|
||||
run: go install golang.org/x/vuln/cmd/govulncheck@latest
|
||||
|
||||
- name: Scan ${{ matrix.module }}
|
||||
working-directory: ${{ matrix.module }}
|
||||
run: |
|
||||
# Full report, for the run summary. govulncheck exits non-zero
|
||||
# whenever it finds anything, so don't let it fail the step here.
|
||||
{
|
||||
echo "## govulncheck: ${{ matrix.module }}"
|
||||
echo '```'
|
||||
govulncheck ./... || true
|
||||
echo '```'
|
||||
} | tee -a "$GITHUB_STEP_SUMMARY"
|
||||
|
||||
# Gate on vulnerabilities reachable from our code through a
|
||||
# dependency. govulncheck's call-graph analysis is transitive,
|
||||
# so indirect use counts too (we call a dep that calls the bad
|
||||
# symbol). trace[0] is the vulnerable symbol; we key on the
|
||||
# module it lives in. A chain that bottoms out in stdlib is
|
||||
# fixed by bumping the Buildroot host Go, not this module's
|
||||
# go.mod, so it's reported above but doesn't fail the build.
|
||||
# Keep the json scan and jq unguarded so a tool failure fails the
|
||||
# gate closed; only grep's no-match exit (all-clear) is tolerated.
|
||||
govulncheck -format json ./... > scan.json || true
|
||||
called=$(jq -r 'select(.finding.trace[0].function != null) |
|
||||
.finding.trace[0].module' scan.json | sort -u)
|
||||
vulns=$(printf '%s' "$called" | grep -vx stdlib || true)
|
||||
if [ -n "$vulns" ]; then
|
||||
echo "::error::Called vulnerabilities in dependencies: $(echo "$vulns" | paste -sd, -)"
|
||||
exit 1
|
||||
fi
|
||||
@@ -1,88 +0,0 @@
|
||||
name: Manny the Manager
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
checkout:
|
||||
required: true
|
||||
type: boolean
|
||||
cleanup:
|
||||
required: true
|
||||
type: boolean
|
||||
peek:
|
||||
required: true
|
||||
type: boolean
|
||||
|
||||
jobs:
|
||||
inventory:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Disk usage ...
|
||||
run: |
|
||||
cd
|
||||
du -hs .[^.]*
|
||||
- name: Disk inventory (1/2) ...
|
||||
run: |
|
||||
echo "df -h ========================================================================="
|
||||
df -h
|
||||
echo "mounts ========================================================================"
|
||||
mount
|
||||
- name: File inventory (1/2) ...
|
||||
run: |
|
||||
echo "Current directory: $(pwd)"
|
||||
echo "Files in $HOME ================================================================"
|
||||
ls $HOME
|
||||
echo "Find $HOME ===================================================================="
|
||||
find $HOME
|
||||
- name: Container inventory ...
|
||||
run: |
|
||||
echo "Available container images: ==================================================="
|
||||
docker images
|
||||
echo "Available containers: ========================================================="
|
||||
docker ps -a
|
||||
|
||||
checkout:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: kernelkit/actions/cache-restore@v1
|
||||
with:
|
||||
target: x86_64
|
||||
dl-prefix: dl-netconf
|
||||
- name: Disk inventory (2/2) ...
|
||||
run: |
|
||||
echo "df -h ========================================================================="
|
||||
df -h
|
||||
echo "mounts ========================================================================"
|
||||
mount
|
||||
- name: File inventory (2/2) ...
|
||||
run: |
|
||||
echo "Current directory: $(pwd)"
|
||||
echo "Files in $HOME ================================================================"
|
||||
ls $HOME
|
||||
echo "Find $HOME ===================================================================="
|
||||
find $HOME
|
||||
|
||||
peeky:
|
||||
if: ${{ inputs.peek }}
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Peek & Poke ...
|
||||
run: |
|
||||
whoami
|
||||
ls -l /mnt/
|
||||
cat /mnt/DATALOSS_WARNING_README.txt
|
||||
sudo mkdir /mnt/x-aarch64
|
||||
sudo chown $(id -un):$(id -gn) /mnt/x-aarch64
|
||||
ls -l /mnt/
|
||||
|
||||
cleanup:
|
||||
if: ${{ inputs.cleanup }}
|
||||
needs: [inventory, peeky]
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Cleaning up cruft ...
|
||||
run: |
|
||||
docker image prune -af
|
||||
docker volume prune -f
|
||||
docker container prune -f
|
||||
@@ -11,17 +11,11 @@ jobs:
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- uses: actions/download-artifact@v4
|
||||
- uses: actions/download-artifact@v8
|
||||
with:
|
||||
pattern: "artifact-*"
|
||||
merge-multiple: true
|
||||
|
||||
- name: Create checksums ...
|
||||
run: |
|
||||
for file in *.tar.gz; do
|
||||
sha256sum $file > $file.sha256
|
||||
done
|
||||
|
||||
- uses: ncipollo/release-action@v1
|
||||
with:
|
||||
allowUpdates: true
|
||||
@@ -32,7 +26,7 @@ jobs:
|
||||
prerelease: true
|
||||
tag: "latest"
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
artifacts: "*.tar.gz*"
|
||||
artifacts: "*.tar.gz"
|
||||
|
||||
- name: Summary
|
||||
run: |
|
||||
|
||||
@@ -78,22 +78,11 @@ jobs:
|
||||
echo "pre=${{ steps.rel.outputs.pre }}"
|
||||
echo "latest=${{ steps.rel.outputs.latest }}"
|
||||
|
||||
- uses: actions/download-artifact@v7
|
||||
- uses: actions/download-artifact@v8
|
||||
with:
|
||||
pattern: "artifact-*"
|
||||
merge-multiple: true
|
||||
|
||||
- name: Create checksums ...
|
||||
run: |
|
||||
for file in *.tar.gz; do
|
||||
sha256sum $file > $file.sha256
|
||||
done
|
||||
if ls *.qcow2 &>/dev/null; then
|
||||
for file in *.qcow2; do
|
||||
sha256sum "$file" > "$file.sha256"
|
||||
done
|
||||
fi
|
||||
|
||||
- name: Extract ChangeLog entry ...
|
||||
run: |
|
||||
cat doc/ChangeLog.md | ./utils/extract-changelog.sh > release.md
|
||||
@@ -106,7 +95,7 @@ jobs:
|
||||
makeLatest: ${{ steps.rel.outputs.latest }}
|
||||
discussionCategory: ${{ steps.rel.outputs.cat }}
|
||||
bodyFile: release.md
|
||||
artifacts: "*.tar.gz*,*.qcow2*"
|
||||
artifacts: "*.tar.gz,*.qcow2,*.pkg,*.img.xz"
|
||||
|
||||
- name: Summary
|
||||
run: |
|
||||
|
||||
@@ -98,7 +98,7 @@ jobs:
|
||||
run: |
|
||||
make ${{ env.TARGET }}_defconfig
|
||||
|
||||
- uses: actions/download-artifact@v7
|
||||
- uses: actions/download-artifact@v8
|
||||
with:
|
||||
pattern: "artifact-*"
|
||||
merge-multiple: true
|
||||
@@ -143,3 +143,15 @@ jobs:
|
||||
with:
|
||||
name: test-report
|
||||
path: output/images/test-report.pdf
|
||||
|
||||
- name: Generate XPath Coverage Report for ${{ env.TARGET }}
|
||||
if: always()
|
||||
run: |
|
||||
make test-dir="$(pwd)/$TEST_PATH" xpath-coverage-report
|
||||
|
||||
- name: Upload XPath Coverage Report as Artifact
|
||||
if: always()
|
||||
uses: actions/upload-artifact@v7
|
||||
with:
|
||||
name: xpath-coverage-report
|
||||
path: output/images/xpath-coverage-report.pdf
|
||||
|
||||
@@ -22,22 +22,11 @@ jobs:
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- uses: actions/download-artifact@v6
|
||||
- uses: actions/download-artifact@v8
|
||||
with:
|
||||
pattern: "artifact-*"
|
||||
merge-multiple: true
|
||||
|
||||
- name: Create checksums
|
||||
run: |
|
||||
for file in *.tar.gz; do
|
||||
sha256sum $file > $file.sha256
|
||||
done
|
||||
if ls *.qcow2 &>/dev/null; then
|
||||
for file in *.qcow2; do
|
||||
sha256sum "$file" > "$file.sha256"
|
||||
done
|
||||
fi
|
||||
|
||||
- uses: ncipollo/release-action@v1
|
||||
with:
|
||||
tag: latest
|
||||
@@ -54,7 +43,7 @@ jobs:
|
||||
|
||||
**Commit:** ${{ github.sha }}
|
||||
**Built:** ${{ github.run_id }}
|
||||
artifacts: "*.tar.gz*,*.qcow2*"
|
||||
artifacts: "*.tar.gz,*.qcow2"
|
||||
|
||||
- name: Summary
|
||||
run: |
|
||||
|
||||
@@ -2,7 +2,7 @@ source "$BR2_EXTERNAL_INFIX_PATH/board/Config.in"
|
||||
|
||||
menu "Branding"
|
||||
|
||||
config INFIX_VENDOR
|
||||
config IX_VENDOR
|
||||
string "Vendor name"
|
||||
default "KernelKit"
|
||||
help
|
||||
@@ -15,7 +15,7 @@ config INFIX_VENDOR
|
||||
|
||||
Used for VENDOR_NAME in /etc/os-release and GNS3 appliance files.
|
||||
|
||||
config INFIX_VENDOR_HOME
|
||||
config IX_VENDOR_HOME
|
||||
string "Vendor URL"
|
||||
help
|
||||
The homepage of the OS vendor. The value should be in RFC3986
|
||||
@@ -24,14 +24,14 @@ config INFIX_VENDOR_HOME
|
||||
|
||||
Optional, used for VENDOR_HOME in /etc/os-release
|
||||
|
||||
config INFIX_NAME
|
||||
config IX_NAME
|
||||
string "Operating system name"
|
||||
default "Infix"
|
||||
help
|
||||
Mandatory. Used for identifying the OS as NAME in /etc/os-release
|
||||
and product_name in GNS3 appliance files.
|
||||
|
||||
config INFIX_ID
|
||||
config IX_ID
|
||||
string "Operating system identifier"
|
||||
default "infix"
|
||||
help
|
||||
@@ -43,9 +43,9 @@ config INFIX_ID
|
||||
Mandatory. Used for identifying the OS as ID in /etc/os-release and
|
||||
in the generated image name: ID-ARCH-VERSION.img
|
||||
|
||||
config INFIX_IMAGE_ID
|
||||
config IX_IMAGE_ID
|
||||
string "Operating system image name"
|
||||
default "${INFIX_ID}-${BR2_ARCH}"
|
||||
default "${IX_ID}-${BR2_ARCH}"
|
||||
help
|
||||
A lower-case string (no spaces or other characters outside of 0–9,
|
||||
a–z, ".", "_" and "-"), for naming critical image files, directories
|
||||
@@ -54,18 +54,18 @@ config INFIX_IMAGE_ID
|
||||
Mandatory. When INFIX_RELEASE is set, this string is appended to
|
||||
the IMAGE_ID with a '-' separator.
|
||||
|
||||
config INFIX_COMPATIBLE
|
||||
config IX_COMPATIBLE
|
||||
string "Operating system compatible string"
|
||||
default "${INFIX_IMAGE_ID}"
|
||||
default "${IX_IMAGE_ID}"
|
||||
help
|
||||
A lower-case string (no spaces or other characters outside of 0–9,
|
||||
a–z, ".", "_" and "-"), used for image identification at upgrade.
|
||||
E.g., the RAUC [system] compatible string.
|
||||
|
||||
Mandatory. Defaults to $INFIX_IMAGE_ID, which in turn is composed
|
||||
of $INFIX_ID-$BR2_ARCH.
|
||||
Mandatory. Defaults to $IX_IMAGE_ID, which in turn is composed
|
||||
of $IX_ID-$BR2_ARCH.
|
||||
|
||||
config INFIX_TAGLINE
|
||||
config IX_TAGLINE
|
||||
string "Operating system tagline"
|
||||
default "Infix OS — Immutable.Friendly.Secure"
|
||||
help
|
||||
@@ -74,25 +74,25 @@ config INFIX_TAGLINE
|
||||
|
||||
This is also show at boot when the system init process starts.
|
||||
|
||||
config INFIX_DESC
|
||||
config IX_DESC
|
||||
string "Operating system description"
|
||||
help
|
||||
Optional. Used for long description texts about the OS. E.g.,
|
||||
the GNS3 appliance file description field. Saved in the file
|
||||
/etc/os-release as INFIX_DESC.
|
||||
/etc/os-release as IX_DESC.
|
||||
|
||||
config INFIX_HOME
|
||||
config IX_HOME
|
||||
string "Operating system URL"
|
||||
help
|
||||
Used for identifying the OS, e.g. as HOME_URL in /etc/os-release
|
||||
|
||||
config INFIX_DOC
|
||||
config IX_DOC
|
||||
string "Operating system docs"
|
||||
help
|
||||
Optional. Main documentation URL, will be shown in /etc/os-release
|
||||
as DOCUMENTATION_URL.
|
||||
|
||||
config INFIX_SUPPORT
|
||||
config IX_SUPPORT
|
||||
string "Operating system support"
|
||||
help
|
||||
Main support page for the operating system, if there is any. This
|
||||
@@ -102,22 +102,23 @@ config INFIX_SUPPORT
|
||||
Optional. Shown, e.g., as SUPPORT_URL in /etc/os-release or
|
||||
maintainer_email in .gns3a.
|
||||
|
||||
config INFIX_OEM_PATH
|
||||
config IX_OEM_PATH
|
||||
string "Path to OEM br2-external"
|
||||
help
|
||||
A br2-external using Infix will likely want to version the branded
|
||||
OS using their own GIT tags. Set this variable to point to the base
|
||||
directory (absolute path) and the Infix post-build.sh will call `git
|
||||
describe -C $INFIX_OEM_PATH`.
|
||||
describe -C $IX_OEM_PATH`.
|
||||
|
||||
Note: for release builds the global variable INFIX_RELEASE overrides
|
||||
the version information derived from `git describe`. However, the
|
||||
GIT version is always saved as the BUILD_ID in /etc/os-releases.
|
||||
Note: the OS version (VERSION, VERSION_ID, BUILD_ID in
|
||||
/etc/os-release) is always derived from `git describe`. The global
|
||||
variable INFIX_RELEASE does not change it; it only labels the release
|
||||
channel (IMAGE_VERSION) and names the published artifacts.
|
||||
|
||||
endmenu
|
||||
|
||||
# For /etc/os-release, uses CondtionArchitechture= from systemd.unit(5)
|
||||
config INFIX_ARCH
|
||||
config IX_ARCH
|
||||
string
|
||||
default "arm" if BR2_arm
|
||||
default "arm64" if BR2_aarch64
|
||||
|
||||
@@ -1,63 +1,21 @@
|
||||
[![License Badge][]][License] [![Release Badge][]][Release] [![GitHub Status][]][GitHub] [![Coverity Status][]][Coverity Scan] [![Discord][discord-badge]][discord-url]
|
||||
[![License Badge][]][License] [![Release Badge][]][Release] [![GitHub Status][]][GitHub] [![Discord][discord-badge]][discord-url]
|
||||
|
||||
<img align="right" src="doc/logo.png" alt="Infix — Immutable.Friendly.Secure" width=480 padding=10>
|
||||
<img align="right" src="doc/logo.png" alt="Infix — Immutable.Friendly.Secure" width=380 padding=10>
|
||||
|
||||
Turn any ARM or x86 device into a powerful, manageable network appliance
|
||||
in minutes. From $35 Raspberry Pi boards to enterprise switches — deploy
|
||||
routers, IoT gateways, edge devices, or custom network solutions that
|
||||
just work.
|
||||
Infix turns an ARM or x86 device into a managed network appliance. The
|
||||
same OS runs on a $35 Raspberry Pi and on enterprise switching hardware,
|
||||
so you can build a router, an IoT gateway, or an edge device on whatever
|
||||
you have on hand.
|
||||
|
||||
## Our Values
|
||||
More in-depth material is available in our blog and User Guide:
|
||||
|
||||
**🔒 Immutable**
|
||||
Your system never breaks. Read-only filesystem with atomic upgrades
|
||||
means no configuration drift, no corrupted updates, and instant rollback
|
||||
if something goes wrong. Deploy once, trust forever.
|
||||
- <https://www.kernelkit.org/>
|
||||
- <https://www.kernelkit.org/infix/>
|
||||
|
||||
**🤝 Friendly**
|
||||
Actually easy to use. Auto-generated CLI from standard YANG models comes
|
||||
with built-in help for every command — just hit <kbd>?</kbd> or
|
||||
<kbd>TAB</kbd> for context-aware assistance.
|
||||
## See it in action
|
||||
|
||||
Familiar NETCONF & RESTCONF APIs and [comprehensive documentation][4]
|
||||
mean you're never stuck. Whether you're learning networking or managing
|
||||
enterprise infrastructure.
|
||||
|
||||
**🛡️ Secure**
|
||||
Built with security as a foundation, not an afterthought. Minimal
|
||||
attack surface, separation between system and data, and container
|
||||
isolation. Sleep better knowing your infrastructure is protected.
|
||||
|
||||
## Why Choose Infix
|
||||
|
||||
**Hardware Flexibility**: Start with a $35 Raspberry Pi, scale to
|
||||
enterprise switching hardware. Same OS, same tools, same reliability.
|
||||
|
||||
**Standards-Based**: Built around YANG models and IETF standards. Learn
|
||||
once, use everywhere - no vendor lock-in.
|
||||
|
||||
**Container Ready**: Run your applications alongside networking
|
||||
functions. GPIO access, dedicated Ethernet ports, custom protocols —
|
||||
your device, your rules.
|
||||
|
||||
## Use Cases
|
||||
|
||||
1. **Home Labs & Hobbyists**:
|
||||
Transform a Raspberry Pi into a full-featured router with WiFi
|
||||
1. **IoT & Edge Computing**:
|
||||
Bridge devices to the cloud with reliable, updatable gateways
|
||||
1. **Small Business Networks**:
|
||||
Enterprise-grade features without the complexity or cost
|
||||
1. **Developers & Makers**:
|
||||
Test networking concepts, prototype IoT solutions, or build custom
|
||||
appliances
|
||||
1. **Network Professionals**:
|
||||
Consistent tooling from development to production deployment.
|
||||
How about a digital twin using raw Qemu or [GNS3](https://gns3.com/infix)!
|
||||
|
||||
## Quick Example
|
||||
|
||||
Configure an interface in seconds - the CLI guides you with built-in help:
|
||||
The CLI is generated from the [YANG models][inside], so it guides you with
|
||||
built-in help. Here's setting an IP address on an interface:
|
||||
|
||||
<pre><code>admin@infix-12-34-56:/> <b>configure</b>
|
||||
admin@infix-12-34-56:/config/> <b>edit interface eth0</b>
|
||||
@@ -94,38 +52,94 @@ eth0 ethernet UP 52:54:00:12:34:56
|
||||
admin@infix-12-34-56:/> <b>copy running startup</b>
|
||||
</code></pre>
|
||||
|
||||
Notice how <kbd>TAB</kbd> completion shows available options, `show`
|
||||
displays current config, and `diff` shows exactly what changed before
|
||||
you commit your changes with the `leave` command.
|
||||
<kbd>TAB</kbd> completes available options and <kbd>?</kbd> shows online help
|
||||
for each option and argument. `show` displays the current config, and `diff`
|
||||
shows exactly what changed before you commit it with `leave`. See the [CLI
|
||||
documentation][3] for more.
|
||||
|
||||
For more information, see [CLI documentation][3].
|
||||
## Web interface
|
||||
|
||||
## Get Started
|
||||
If the CLI isn't your style, the same configuration is available through the
|
||||
web interface. Log in from a browser, keep an eye on your device from the
|
||||
Status dashboard and use the Configure > Interface setup wizard to create more
|
||||
advanced setups, or just fold out an interface to add an IP address.
|
||||
|
||||
Get [pre-built images][5] for your hardware. Use the CLI, web
|
||||
interface, or standard NETCONF/RESTCONF tools, e.g., `curl`. Add
|
||||
containers for any custom functionality you need.
|
||||
<p>
|
||||
<a href="doc/img/webui-login.png"><img src="doc/img/webui-login.png" alt="Login" align="top" width=220></a>
|
||||
<a href="doc/img/webui-dashboard.png"><img src="doc/img/webui-dashboard.png" alt="Dashboard" width=290></a>
|
||||
<a href="doc/img/webui-wizard.png"><img src="doc/img/webui-wizard.png" alt="Setup wizard" width=260></a>
|
||||
</p>
|
||||
|
||||
### Supported Platforms
|
||||
The web interface is built on the same concepts as the CLI, so operational
|
||||
status and state are kept separate from configuration and commands.
|
||||
|
||||
- **Raspberry Pi 2B/3B/4B/CM4** - Perfect for home labs, learning, and prototyping
|
||||
- **Banana Pi-R3** - Your next home router and gateway
|
||||
- **NanoPi R2S** - Compact dual-port router in a tiny package
|
||||
- **x86_64** - Run in VMs or on mini PCs for development and testing
|
||||
- **Marvell CN9130 CRB, EspressoBIN** - High-performance ARM64 platforms
|
||||
- **Microchip SparX-5i** - Enterprise switching capabilities
|
||||
- **Microchip SAMA7G54-EK** - ARM Cortex-A7
|
||||
- **NXP i.MX8MP EVK** - Highly capable ARM64 SoC
|
||||
- **StarFive VisionFive2** - RISC-V architecture support
|
||||
## Try it in 5 minutes
|
||||
|
||||
*Why start with Raspberry Pi?* It's affordable, widely available, has
|
||||
built-in WiFi + Ethernet, and runs the exact same Infix OS you'd deploy
|
||||
in production. Perfect for learning, prototyping, or even small-scale
|
||||
deployments.
|
||||
You don't need hardware to get started:
|
||||
|
||||
- **In a virtual lab** — run a full topology in [GNS3][gns3-post] and test
|
||||
networks entirely in software.
|
||||
- **From source** — [build it and `make run`][build-post] to boot Infix in
|
||||
QEMU, from `git clone` to pinging the internet.
|
||||
- **On real hardware** — grab a [pre-built image][5] for your board, or run
|
||||
the `x86_64` image in any VM.
|
||||
|
||||
Log in with `admin` / `admin` on the virtual and pre-built images. On
|
||||
shipped products the factory-reset credentials are customizable — we
|
||||
typically provision a unique per-device password stored in EEPROM/VPD.
|
||||
|
||||
## Supported hardware
|
||||
|
||||
- **Raspberry Pi 2B/3B/4B/CM4** - a good starting point; built-in WiFi and Ethernet
|
||||
- **Banana Pi-R64/R3/R3 Mini/R4** - multi-port routers and gateways
|
||||
- **NanoPi R2S** - compact dual-port router
|
||||
- **x86_64** - VMs and mini PCs, for development or production
|
||||
- **Marvell CN9130 CRB, EspressoBIN** - ARM64 development boards
|
||||
- **Microchip SparX-5i** - enterprise switching
|
||||
- **Microchip SAMA7G54-EK** - ARM Cortex-A7 evaluation kit
|
||||
- **NXP i.MX8MP EVK** - ARM64 SoC evaluation kit
|
||||
- **StarFive VisionFive2** - RISC-V board
|
||||
|
||||
*Why start with Raspberry Pi?* It's cheap, easy to get hold of, has
|
||||
built-in WiFi and Ethernet, and runs the same Infix you'd deploy in
|
||||
production — so what you learn on it carries straight over.
|
||||
|
||||
> [!TIP]
|
||||
> 📖 **[Complete documentation][4]** • 💬 **[Join our Discord][discord-url]**
|
||||
|
||||
## Technical Details
|
||||
## Why Infix
|
||||
|
||||
**🔒 Immutable**
|
||||
Read-only filesystem with atomic upgrades. An update either applies
|
||||
cleanly or rolls back, so a failed upgrade or a power cut midway through
|
||||
won't leave you with a half-broken system.
|
||||
|
||||
**🤝 Friendly**
|
||||
The CLI is generated from the YANG models, so every command carries its
|
||||
own help — hit <kbd>?</kbd> or <kbd>TAB</kbd> to see what's available.
|
||||
The same models are reachable over NETCONF and RESTCONF, with
|
||||
[documentation][4] for when you get stuck.
|
||||
|
||||
**🛡️ Secure**
|
||||
A small attack surface, separation between system and data, and
|
||||
container isolation. Since the system partition is read-only, a
|
||||
compromised service or container can't rewrite the OS underneath it.
|
||||
|
||||
## Use cases
|
||||
|
||||
1. **Home labs & hobbyists**:
|
||||
Turn a Raspberry Pi into a router with WiFi
|
||||
1. **IoT & edge**:
|
||||
Build gateways you can update in the field
|
||||
1. **Small business networks**:
|
||||
Routing, firewalling, and VLANs on affordable hardware
|
||||
1. **Developers & makers**:
|
||||
Prototype networking ideas, or build a custom appliance with containers
|
||||
1. **Network professionals**:
|
||||
The same tooling from lab to production — spin up a digital twin in raw
|
||||
Qemu or [GNS3](https://gns3.com/infix)
|
||||
|
||||
## Under the hood
|
||||
|
||||
<a href="https://bitsign.se">
|
||||
<picture>
|
||||
@@ -135,27 +149,29 @@ deployments.
|
||||
</picture>
|
||||
</a>
|
||||
|
||||
Built on proven open-source foundations: [Linux][0], [Buildroot][1], and
|
||||
[sysrepo][2] — for reliability you can trust:
|
||||
Built on [Linux][0], [Buildroot][1], and [sysrepo][2]:
|
||||
|
||||
- **Immutable OS**: Read-only filesystem, atomic updates, instant rollback
|
||||
- **YANG Configuration**: Industry-standard models with auto-generated tooling
|
||||
- **Hardware Acceleration**: Linux switchdev support for wire-speed packet processing
|
||||
- **Container Integration**: Docker support with flexible network and hardware access
|
||||
- **Memory Efficient**: Runs comfortably on devices with as little as 256 MB RAM
|
||||
- **Code Signing**: Releases are cryptographically signed for integrity verification
|
||||
- **Immutable OS**: read-only filesystem, atomic updates, rollback on failure
|
||||
- **YANG configuration**: standard models with an auto-generated CLI and APIs
|
||||
- **Hardware acceleration**: switchdev offload for wire-speed forwarding
|
||||
- **Container integration**: Docker, with access to host network and hardware
|
||||
- **Memory efficient**: runs on devices with as little as 256 MB RAM
|
||||
- **Code signing**: releases are cryptographically signed
|
||||
|
||||
Perfect for everything from resource-constrained edge devices to
|
||||
high-throughput network appliances.
|
||||
|
||||
With the entire system modeled in YANG, scalability is no longer an
|
||||
issue, be it in development, testing, or end users deploying and
|
||||
monitoring their devices. All knobs and dials are accessible from the
|
||||
CLI (console/SSH), or remotely using the native NETCONF or RESTCONF
|
||||
APIs.
|
||||
Because the whole system is modeled in YANG, every setting is reachable
|
||||
the same way: from the CLI over console or SSH, or remotely over the
|
||||
native NETCONF and RESTCONF APIs. The same models drive development,
|
||||
testing, and day-to-day monitoring.
|
||||
|
||||
> Check the *[Latest Build][]* for bleeding-edge features.
|
||||
|
||||
## Contributing
|
||||
|
||||
Bug reports, ideas, and pull requests are welcome. Start with
|
||||
[CONTRIBUTING][contributing] and the [code of conduct][coc]. Found a
|
||||
security issue? Follow the [security policy][security]. Need a hand?
|
||||
See [support options][support] or [join us on Discord][discord-url].
|
||||
|
||||
---
|
||||
|
||||
<div align="center">
|
||||
@@ -171,6 +187,13 @@ APIs.
|
||||
[3]: https://www.kernelkit.org/infix/latest/cli/introduction/
|
||||
[4]: https://www.kernelkit.org/infix/
|
||||
[5]: https://github.com/kernelkit/infix/releases/latest
|
||||
[inside]: https://www.kernelkit.org/posts/inside-infix/
|
||||
[gns3-post]: https://www.kernelkit.org/posts/infix-in-gns3/
|
||||
[build-post]: https://www.kernelkit.org/posts/building-infix-from-source/
|
||||
[contributing]: .github/CONTRIBUTING.md
|
||||
[coc]: .github/CODE_OF_CONDUCT.md
|
||||
[security]: .github/SECURITY.md
|
||||
[support]: .github/SUPPORT.md
|
||||
[Latest Build]: https://github.com/kernelkit/infix/releases/tag/latest "Latest build"
|
||||
[License]: https://en.wikipedia.org/wiki/GPL_license
|
||||
[License Badge]: https://img.shields.io/badge/License-GPL%20v2-blue.svg
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
Copyright (c) 2026 The KernelKit Authors
|
||||
|
||||
Permission to use, copy, modify, and/or distribute this software for any
|
||||
purpose with or without fee is hereby granted, provided that the above
|
||||
copyright notice and this permission notice appear in all copies.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
|
||||
WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
|
||||
MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
|
||||
ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
||||
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
|
||||
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
|
||||
OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
||||
@@ -0,0 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 d48246c717b505cc11df95171f2fd548b389e1a463f1af4c68d0b69fe0d1009b LICENSE
|
||||
@@ -22,7 +22,7 @@ image var.ext4 {
|
||||
}
|
||||
}
|
||||
|
||||
image #INFIX_ID##VERSION#-vero-w-#TARGET#.img {
|
||||
image #IX_ID##VERSION#-vero-w-#TARGET#.img {
|
||||
hdimage {
|
||||
partition-table-type = "gpt"
|
||||
gpt-no-backup = true
|
||||
|
||||
@@ -24,7 +24,7 @@ image var.ext4 {
|
||||
}
|
||||
}
|
||||
|
||||
image #INFIX_ID##VERSION#-bpi-r3-#TARGET#.img {
|
||||
image #IX_ID##VERSION#-bpi-r3-#TARGET#.img {
|
||||
hdimage {
|
||||
partition-table-type = "gpt"
|
||||
|
||||
|
||||
@@ -24,7 +24,7 @@ image var.ext4 {
|
||||
}
|
||||
}
|
||||
|
||||
image #INFIX_ID##VERSION#-bpi-r4-#TARGET#.img {
|
||||
image #IX_ID##VERSION#-bpi-r4-#TARGET#.img {
|
||||
hdimage {
|
||||
partition-table-type = "gpt"
|
||||
gpt-no-backup = true
|
||||
|
||||
@@ -24,7 +24,7 @@ image var.ext4 {
|
||||
}
|
||||
}
|
||||
|
||||
image #INFIX_ID##VERSION#-bpi-r64-#TARGET#.img {
|
||||
image #IX_ID##VERSION#-bpi-r64-#TARGET#.img {
|
||||
hdimage {
|
||||
partition-table-type = "hybrid"
|
||||
# MT7622 TF-A partition driver detects GPT by checking MBR[0]
|
||||
|
||||
@@ -26,7 +26,7 @@ image var.ext4 {
|
||||
}
|
||||
}
|
||||
|
||||
image #INFIX_ID##VERSION#-nanopi-r2s-sdcard.img {
|
||||
image #IX_ID##VERSION#-nanopi-r2s-sdcard.img {
|
||||
hdimage {
|
||||
partition-table-type = "gpt"
|
||||
}
|
||||
|
||||
@@ -24,7 +24,7 @@ image var.ext4 {
|
||||
}
|
||||
}
|
||||
|
||||
image #INFIX_ID##VERSION#-espressobin-#TARGET#.img {
|
||||
image #IX_ID##VERSION#-espressobin-#TARGET#.img {
|
||||
hdimage {
|
||||
partition-table-type = "gpt"
|
||||
}
|
||||
|
||||
@@ -36,7 +36,7 @@ image var.ext4 {
|
||||
}
|
||||
}
|
||||
|
||||
image #INFIX_ID##VERSION#-rpi64-sdcard.img {
|
||||
image #IX_ID##VERSION#-rpi64-sdcard.img {
|
||||
hdimage {
|
||||
partition-table-type = "hybrid"
|
||||
}
|
||||
|
||||
@@ -39,7 +39,7 @@ image var.ext4 {
|
||||
}
|
||||
}
|
||||
|
||||
image #INFIX_ID##VERSION#-sama7g54-ek-#TARGET#.img {
|
||||
image #IX_ID##VERSION#-sama7g54-ek-#TARGET#.img {
|
||||
hdimage {
|
||||
partition-table-type = "hybrid"
|
||||
}
|
||||
|
||||
@@ -36,7 +36,7 @@ image var.ext4 {
|
||||
}
|
||||
}
|
||||
|
||||
image #INFIX_ID##VERSION#-rpi2-sdcard.img {
|
||||
image #IX_ID##VERSION#-rpi2-sdcard.img {
|
||||
hdimage {
|
||||
partition-table-type = "hybrid"
|
||||
}
|
||||
|
||||
@@ -11,7 +11,7 @@ source "$BR2_EXTERNAL_INFIX_PATH/board/common/image/image-readme/Config.in"
|
||||
|
||||
endmenu
|
||||
|
||||
config QEMU_SCRIPTS
|
||||
config IX_QEMU_SCRIPTS
|
||||
bool "QEMU scripts"
|
||||
default y
|
||||
help
|
||||
@@ -19,20 +19,20 @@ config QEMU_SCRIPTS
|
||||
directory, which can be used to launch virtual Infix
|
||||
instances.
|
||||
|
||||
menuconfig TRUSTED_KEYS
|
||||
menuconfig IX_TRUSTED_KEYS
|
||||
bool "Trusted keys for image"
|
||||
help
|
||||
Keys that will be accepted for this image
|
||||
|
||||
config TRUSTED_KEYS_DEVELOPMENT
|
||||
config IX_TRUSTED_KEYS_DEVELOPMENT
|
||||
bool "Development key"
|
||||
depends on TRUSTED_KEYS
|
||||
depends on IX_TRUSTED_KEYS
|
||||
|
||||
config TRUSTED_KEYS_DEVELOPMENT_PATH
|
||||
config IX_TRUSTED_KEYS_DEVELOPMENT_PATH
|
||||
string
|
||||
depends on TRUSTED_KEYS_DEVELOPMENT
|
||||
depends on IX_TRUSTED_KEYS_DEVELOPMENT
|
||||
default "${BR2_EXTERNAL_INFIX_PATH}/board/common/signing-keys/development/infix.crt"
|
||||
|
||||
config TRUSTED_KEYS_EXTRA_PATH
|
||||
config IX_TRUSTED_KEYS_EXTRA_PATH
|
||||
string "Path to extra keys to include in image"
|
||||
depends on TRUSTED_KEYS
|
||||
depends on IX_TRUSTED_KEYS
|
||||
|
||||
@@ -1,14 +1,14 @@
|
||||
include $(BR2_EXTERNAL_INFIX_PATH)/board/common/image/image.mk
|
||||
include $(BR2_EXTERNAL_INFIX_PATH)/board/common/qemu/qemu.mk
|
||||
|
||||
ifeq ($(TRUSTED_KEYS),y)
|
||||
ifeq ($(IX_TRUSTED_KEYS),y)
|
||||
include $(BR2_EXTERNAL_INFIX_PATH)/board/common/uboot/uboot.mk
|
||||
|
||||
TRUSTED_KEYS=$(TRUSTED_KEYS_DEVELOPMENT_PATH) $(TRUSTED_KEYS_EXTRA_PATH)
|
||||
IX_TRUSTED_KEYS=$(IX_TRUSTED_KEYS_DEVELOPMENT_PATH) $(IX_TRUSTED_KEYS_EXTRA_PATH)
|
||||
define RAUC_POST_BUILD_INSTALL_CERT
|
||||
@$(call IXMSG,"Installing signing cert for RAUC")
|
||||
mkdir -p $(TARGET_DIR)/etc/rauc/keys
|
||||
$(foreach crt,$(shell ls $(TRUSTED_KEYS)), \
|
||||
$(foreach crt,$(shell ls $(IX_TRUSTED_KEYS)), \
|
||||
cp $(crt) $(TARGET_DIR)/etc/rauc/keys/$(shell openssl x509 -hash -noout <$(crt)).0;)
|
||||
|
||||
endef
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
config IMAGE_EXT4_RAUC
|
||||
config IX_IMAGE_EXT4_RAUC
|
||||
bool "RAUC upgrade bundle (ext4)"
|
||||
depends on BR2_TARGET_ROOTFS_EXT2
|
||||
select BR2_PACKAGE_HOST_RAUC
|
||||
@@ -7,17 +7,17 @@ config IMAGE_EXT4_RAUC
|
||||
image. Intended for development boards whose bootloader does
|
||||
not support squashfs.
|
||||
|
||||
config IMAGE_EXT4_RAUC_KEY
|
||||
config IX_IMAGE_EXT4_RAUC_KEY
|
||||
string "signing key"
|
||||
depends on IMAGE_EXT4_RAUC
|
||||
depends on IX_IMAGE_EXT4_RAUC
|
||||
default "${BR2_EXTERNAL_INFIX_PATH}/board/common/signing-keys/development/infix.key"
|
||||
help
|
||||
Path to the private key, in PKCS#8 format, used to sign
|
||||
the RAUC bundle; or a PKCS#11 URI.
|
||||
|
||||
config IMAGE_EXT4_RAUC_CERT
|
||||
config IX_IMAGE_EXT4_RAUC_CERT
|
||||
string "signing certificate"
|
||||
depends on IMAGE_EXT4_RAUC
|
||||
depends on IX_IMAGE_EXT4_RAUC
|
||||
default "${BR2_EXTERNAL_INFIX_PATH}/board/common/signing-keys/development/infix.crt"
|
||||
help
|
||||
Path to the X509 certificate which will be associated with
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
config IMAGE_ITB_AUX
|
||||
config IX_IMAGE_ITB_AUX
|
||||
bool "aux partition"
|
||||
depends on IMAGE_ITB_ROOTFS
|
||||
depends on IX_IMAGE_ITB_ROOTFS
|
||||
select BR2_PACKAGE_HOST_UBOOT_TOOLS
|
||||
select BR2_PACKAGE_HOST_GENIMAGE
|
||||
help
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
menuconfig IMAGE_ITB_DL_RELEASE
|
||||
menuconfig IX_IMAGE_ITB_DL_RELEASE
|
||||
bool "Download existing release"
|
||||
depends on !BR2_TARGET_ROOTFS_SQUASHFS
|
||||
help
|
||||
@@ -7,9 +7,9 @@ menuconfig IMAGE_ITB_DL_RELEASE
|
||||
Infix image, to create a full disk image that can be
|
||||
provisioned to an SD-card or eMMC.
|
||||
|
||||
config IMAGE_ITB_DL_RELEASE_URL
|
||||
config IX_IMAGE_ITB_DL_RELEASE_URL
|
||||
string "URL"
|
||||
depends on IMAGE_ITB_DL_RELEASE
|
||||
depends on IX_IMAGE_ITB_DL_RELEASE
|
||||
default "https://github.com/kernelkit/infix/releases/download/latest/infix-${BR2_ARCH}.tar.gz"
|
||||
help
|
||||
URL to release tarball.
|
||||
|
||||
@@ -1,23 +1,23 @@
|
||||
menuconfig IMAGE_ITB_GNS3A
|
||||
menuconfig IX_IMAGE_ITB_GNS3A
|
||||
bool "GNS3 Appliance (ITB)"
|
||||
depends on BR2_x86_64
|
||||
select IMAGE_ITB_QCOW
|
||||
select IX_IMAGE_ITB_QCOW
|
||||
help
|
||||
Create a GNS3 appliance description that, together with the
|
||||
disk image, can be imported into GNS3.
|
||||
|
||||
config IMAGE_ITB_GNS3A_RAM
|
||||
config IX_IMAGE_ITB_GNS3A_RAM
|
||||
int "Reserved RAM (MiB)"
|
||||
depends on IMAGE_ITB_GNS3A
|
||||
depends on IX_IMAGE_ITB_GNS3A
|
||||
default "192"
|
||||
help
|
||||
Amount of host RAM reserved for an appliance instance.
|
||||
|
||||
Minimum supported size is 192M.
|
||||
|
||||
config IMAGE_ITB_GNS3A_IFNUM
|
||||
config IX_IMAGE_ITB_GNS3A_IFNUM
|
||||
int "Number of interfaces"
|
||||
depends on IMAGE_ITB_GNS3A
|
||||
depends on IX_IMAGE_ITB_GNS3A
|
||||
default "1"
|
||||
help
|
||||
Number of Ethernet interfaces to create for an appliance instance.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
menuconfig IMAGE_ITB_QCOW
|
||||
menuconfig IX_IMAGE_ITB_QCOW
|
||||
bool "QEMU disk image (ITB)"
|
||||
depends on (IMAGE_ITB_ROOTFS && IMAGE_ITB_AUX) || IMAGE_ITB_DL_RELEASE
|
||||
depends on (IX_IMAGE_ITB_ROOTFS && IX_IMAGE_ITB_AUX) || IX_IMAGE_ITB_DL_RELEASE
|
||||
select BR2_PACKAGE_HOST_GENIMAGE
|
||||
help
|
||||
Compose a full disk image with redundant Linux OS partitions,
|
||||
@@ -11,9 +11,9 @@ menuconfig IMAGE_ITB_QCOW
|
||||
- Creating a GNS3 appliance
|
||||
- Developing/debugging issues in the boot process in QEMU
|
||||
|
||||
menuconfig IMAGE_ITB_QCOW_SIZE
|
||||
menuconfig IX_IMAGE_ITB_QCOW_SIZE
|
||||
string "Image size"
|
||||
depends on IMAGE_ITB_QCOW
|
||||
depends on IX_IMAGE_ITB_QCOW
|
||||
default "512M"
|
||||
help
|
||||
Create a disk image of this size. A K/M/G suffix may be used
|
||||
@@ -26,22 +26,22 @@ menuconfig IMAGE_ITB_QCOW_SIZE
|
||||
|
||||
choice
|
||||
prompt "Bootloader"
|
||||
depends on IMAGE_ITB_QCOW
|
||||
default IMAGE_ITB_QCOW_BOOT_EFI if BR2_x86_64
|
||||
default IMAGE_ITB_QCOW_BOOT_NONE
|
||||
depends on IX_IMAGE_ITB_QCOW
|
||||
default IX_IMAGE_ITB_QCOW_BOOT_EFI if BR2_x86_64
|
||||
default IX_IMAGE_ITB_QCOW_BOOT_NONE
|
||||
|
||||
config IMAGE_ITB_QCOW_BOOT_NONE
|
||||
config IX_IMAGE_ITB_QCOW_BOOT_NONE
|
||||
bool "None"
|
||||
help
|
||||
Do not create any bootloader partition in the disk image.
|
||||
|
||||
config IMAGE_ITB_QCOW_BOOT_EFI
|
||||
config IX_IMAGE_ITB_QCOW_BOOT_EFI
|
||||
bool "EFI"
|
||||
help
|
||||
Create a boot partition from a directory containing an EFI
|
||||
boot application, e.g. GRUB.
|
||||
|
||||
config IMAGE_ITB_QCOW_BOOT_BIN
|
||||
config IX_IMAGE_ITB_QCOW_BOOT_BIN
|
||||
bool "Binary"
|
||||
help
|
||||
Create a boot partition from a raw image containing the boot
|
||||
@@ -49,18 +49,18 @@ config IMAGE_ITB_QCOW_BOOT_BIN
|
||||
|
||||
endchoice
|
||||
|
||||
config IMAGE_ITB_QCOW_BOOT_DATA
|
||||
config IX_IMAGE_ITB_QCOW_BOOT_DATA
|
||||
string "Bootloader data"
|
||||
depends on IMAGE_ITB_QCOW
|
||||
depends on IMAGE_ITB_QCOW_BOOT_EFI || IMAGE_ITB_QCOW_BOOT_BIN
|
||||
depends on IX_IMAGE_ITB_QCOW
|
||||
depends on IX_IMAGE_ITB_QCOW_BOOT_EFI || IX_IMAGE_ITB_QCOW_BOOT_BIN
|
||||
default "${BINARIES_DIR}/efi-part/EFI" if BR2_x86_64
|
||||
help
|
||||
Path to the directory or file holding the bootloader data.
|
||||
|
||||
config IMAGE_ITB_QCOW_BOOT_OFFSET
|
||||
config IX_IMAGE_ITB_QCOW_BOOT_OFFSET
|
||||
hex "Bootloader offset"
|
||||
depends on IMAGE_ITB_QCOW
|
||||
depends on IMAGE_ITB_QCOW_BOOT_EFI || IMAGE_ITB_QCOW_BOOT_BIN
|
||||
depends on IX_IMAGE_ITB_QCOW
|
||||
depends on IX_IMAGE_ITB_QCOW_BOOT_EFI || IX_IMAGE_ITB_QCOW_BOOT_BIN
|
||||
default 0x8000
|
||||
help
|
||||
Offset at which the bootloader partition is placed. Remember
|
||||
|
||||
@@ -6,8 +6,8 @@
|
||||
|
||||
# We can source the rootfs+aux from a local build, or from a
|
||||
# downloaded release; so adjust our dependencies accordingly.
|
||||
IMAGE_ITB_QCOW_SRC-$(IMAGE_ITB_ROOTFS) := image-itb-rootfs image-itb-aux
|
||||
IMAGE_ITB_QCOW_SRC-$(IMAGE_ITB_DL_RELEASE) := image-itb-dl-release
|
||||
IMAGE_ITB_QCOW_SRC-$(IX_IMAGE_ITB_ROOTFS) := image-itb-rootfs image-itb-aux
|
||||
IMAGE_ITB_QCOW_SRC-$(IX_IMAGE_ITB_DL_RELEASE) := image-itb-dl-release
|
||||
|
||||
IMAGE_ITB_QCOW_DEPENDENCIES := host-genimage $(IMAGE_ITB_QCOW_SRC-y)
|
||||
IMAGE_ITB_QCOW_CONFIG_VARS := BOOT_DATA BOOT_OFFSET SIZE
|
||||
|
||||
@@ -1,23 +1,23 @@
|
||||
menuconfig IMAGE_ITB_RAUC
|
||||
menuconfig IX_IMAGE_ITB_RAUC
|
||||
bool "RAUC upgrade bundle (ITB)"
|
||||
select IMAGE_ITB_ROOTFS
|
||||
select IX_IMAGE_ITB_ROOTFS
|
||||
select BR2_PACKAGE_HOST_RAUC
|
||||
help
|
||||
Create RAUC upgrade bundle, for targets using ITB images,
|
||||
that can be used to upgrade a running system to this version
|
||||
of Infix.
|
||||
|
||||
config IMAGE_ITB_RAUC_KEY
|
||||
config IX_IMAGE_ITB_RAUC_KEY
|
||||
string "signing key"
|
||||
depends on IMAGE_ITB_RAUC
|
||||
depends on IX_IMAGE_ITB_RAUC
|
||||
default "${BR2_EXTERNAL_INFIX_PATH}/board/common/signing-keys/development/infix.key"
|
||||
help
|
||||
Path to the private key, in PKCS#8 format, used to sign
|
||||
the RAUC bundle; or a PKCS#11 URI.
|
||||
|
||||
config IMAGE_ITB_RAUC_CERT
|
||||
config IX_IMAGE_ITB_RAUC_CERT
|
||||
string "signing certificate"
|
||||
depends on IMAGE_ITB_RAUC
|
||||
depends on IX_IMAGE_ITB_RAUC
|
||||
default "${BR2_EXTERNAL_INFIX_PATH}/board/common/signing-keys/development/infix.crt"
|
||||
help
|
||||
Path to the X509 certificate which will be associated with
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
menuconfig IMAGE_ITB_ROOTFS
|
||||
menuconfig IX_IMAGE_ITB_ROOTFS
|
||||
bool "rootfs.itb+.itbh"
|
||||
select BR2_TARGET_ROOTFS_SQUASHFS
|
||||
select BR2_PACKAGE_HOST_UBOOT_TOOLS
|
||||
@@ -7,9 +7,9 @@ menuconfig IMAGE_ITB_ROOTFS
|
||||
and extract detached header (.itbh) for U-Boot based
|
||||
targets.
|
||||
|
||||
config IMAGE_ITB_ROOTFS_KEY
|
||||
config IX_IMAGE_ITB_ROOTFS_KEY
|
||||
string "signing key"
|
||||
depends on IMAGE_ITB_ROOTFS
|
||||
depends on IX_IMAGE_ITB_ROOTFS
|
||||
default "${BR2_EXTERNAL_INFIX_PATH}/board/common/signing-keys/development/infix.key"
|
||||
help
|
||||
Path to the private RSA key, in PKCS#8 format, used to sign
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
config IMAGE_README
|
||||
config IX_IMAGE_README
|
||||
bool "Install README.md in images"
|
||||
help
|
||||
Install a README.md with useful information about getting
|
||||
|
||||
@@ -13,6 +13,6 @@ $(BINARIES_DIR)/README.md: $(IMAGE_README_DIR)/README.md
|
||||
@mkdir -p $(BINARIES_DIR)
|
||||
@cp $< $@
|
||||
|
||||
ifeq ($(IMAGE_README),y)
|
||||
ifeq ($(IX_IMAGE_README),y)
|
||||
TARGETS_ROOTFS += image-readme
|
||||
endif
|
||||
|
||||
@@ -12,15 +12,17 @@ $(1): $$($(2)_DEPENDENCIES)
|
||||
BINARIES_DIR=$$(BINARIES_DIR) \
|
||||
BR2_EXTERNAL_INFIX_PATH=$$(BR2_EXTERNAL_INFIX_PATH) \
|
||||
ARTIFACT=$$(INFIX_ARTIFACT) \
|
||||
COMPATIBLE=$$(INFIX_COMPATIBLE) \
|
||||
COMPATIBLE=$$(IX_COMPATIBLE) \
|
||||
VERSION=$$(INFIX_VERSION) \
|
||||
$$(foreach var,$$($(2)_CONFIG_VARS),$$(var)=$$($(2)_$$(var)) ) \
|
||||
$$(foreach var,$$($(2)_CONFIG_VARS),$$(var)=$$($(3)_$$(var)) ) \
|
||||
$$($(2)_DIR)/generate.sh $$($(2)_OPTS)
|
||||
|
||||
ifeq ($$($(2)),y)
|
||||
ifeq ($$($(3)),y)
|
||||
TARGETS_ROOTFS += $(1)
|
||||
endif
|
||||
|
||||
endef
|
||||
|
||||
ix-image = $(call inner-ix-image,$(pkgname),$(call UPPERCASE,$(pkgname)))
|
||||
# $(2) is the package-local make-var prefix (UPPERCASE pkgname); $(3) is
|
||||
# the IX_ prefixed Kconfig symbol name, see issue #1305.
|
||||
ix-image = $(call inner-ix-image,$(pkgname),$(call UPPERCASE,$(pkgname)),IX_$(call UPPERCASE,$(pkgname)))
|
||||
|
||||
@@ -16,7 +16,7 @@ die()
|
||||
# DISK_IMAGE_SIZE="512"
|
||||
# etc.
|
||||
#
|
||||
# Nested variables, like INFIX_COMPATIBLE="${INFIX_IMAGE_ID}"
|
||||
# Nested variables, like IX_COMPATIBLE="${IX_IMAGE_ID}"
|
||||
# are handled by sourcing the file in a subshell.
|
||||
#
|
||||
# shellcheck disable=SC1090
|
||||
|
||||
@@ -37,7 +37,7 @@ EOF
|
||||
}
|
||||
|
||||
if [ -f "$TARGET_DIR/etc/rauc/system.conf" ]; then
|
||||
sed -i "s/compatible=.*/compatible=$INFIX_COMPATIBLE/" "$TARGET_DIR/etc/rauc/system.conf"
|
||||
sed -i "s/compatible=.*/compatible=$IX_COMPATIBLE/" "$TARGET_DIR/etc/rauc/system.conf"
|
||||
fi
|
||||
|
||||
if [ -n "${ID_LIKE}" ]; then
|
||||
@@ -53,40 +53,40 @@ cp "$TARGET_DIR/etc/hostname" "$TARGET_DIR/etc/hostname.d/10-default"
|
||||
ixmsg "Creating /etc/os-release"
|
||||
rm -f "$TARGET_DIR/etc/os-release"
|
||||
{
|
||||
echo "NAME=\"$INFIX_NAME\""
|
||||
echo "ID=$INFIX_ID"
|
||||
echo "PRETTY_NAME=\"$INFIX_TAGLINE $INFIX_VERSION\""
|
||||
echo "NAME=\"$IX_NAME\""
|
||||
echo "ID=$IX_ID"
|
||||
echo "PRETTY_NAME=\"$IX_TAGLINE $INFIX_VERSION\""
|
||||
echo "ID_LIKE=\"${ID}\""
|
||||
echo "DEFAULT_HOSTNAME=$BR2_TARGET_GENERIC_HOSTNAME"
|
||||
echo "VERSION=\"${INFIX_VERSION}\""
|
||||
echo "VERSION_ID=${INFIX_VERSION}"
|
||||
echo "BUILD_ID=\"${INFIX_BUILD_ID}\""
|
||||
if [ -n "$INFIX_IMAGE_ID" ]; then
|
||||
echo "IMAGE_ID=\"$INFIX_IMAGE_ID\""
|
||||
if [ -n "$IX_IMAGE_ID" ]; then
|
||||
echo "IMAGE_ID=\"$IX_IMAGE_ID\""
|
||||
fi
|
||||
if [ -n "$INFIX_RELEASE" ]; then
|
||||
echo "IMAGE_VERSION=\"$INFIX_RELEASE\""
|
||||
fi
|
||||
echo "ARCHITECTURE=\"${INFIX_ARCH}\""
|
||||
echo "HOME_URL=$INFIX_HOME"
|
||||
if [ -n "$INFIX_VENDOR" ]; then
|
||||
echo "VENDOR_NAME=\"$INFIX_VENDOR\""
|
||||
echo "ARCHITECTURE=\"${IX_ARCH}\""
|
||||
echo "HOME_URL=$IX_HOME"
|
||||
if [ -n "$IX_VENDOR" ]; then
|
||||
echo "VENDOR_NAME=\"$IX_VENDOR\""
|
||||
fi
|
||||
if [ -n "$INFIX_VENDOR_HOME" ]; then
|
||||
echo "VENDOR_HOME=\"$INFIX_VENDOR_HOME\""
|
||||
if [ -n "$IX_VENDOR_HOME" ]; then
|
||||
echo "VENDOR_HOME=\"$IX_VENDOR_HOME\""
|
||||
fi
|
||||
if [ -n "$INFIX_DOC" ]; then
|
||||
echo "DOCUMENTATION_URL=\"$INFIX_DOC\""
|
||||
if [ -n "$IX_DOC" ]; then
|
||||
echo "DOCUMENTATION_URL=\"$IX_DOC\""
|
||||
fi
|
||||
if [ -n "$INFIX_SUPPORT" ]; then
|
||||
echo "SUPPORT_URL=\"$INFIX_SUPPORT\""
|
||||
if [ -n "$IX_SUPPORT" ]; then
|
||||
echo "SUPPORT_URL=\"$IX_SUPPORT\""
|
||||
fi
|
||||
if [ -n "$INFIX_DESC" ]; then
|
||||
echo "INFIX_DESC=\"$INFIX_DESC\""
|
||||
if [ -n "$IX_DESC" ]; then
|
||||
echo "INFIX_DESC=\"$IX_DESC\""
|
||||
fi
|
||||
} > "$TARGET_DIR/etc/os-release"
|
||||
|
||||
echo "$INFIX_TAGLINE $INFIX_VERSION -- $(date +"%b %e %H:%M %Z %Y")" > "$TARGET_DIR/etc/version"
|
||||
echo "$IX_TAGLINE $INFIX_VERSION -- $(date +"%b %e %H:%M %Z %Y")" > "$TARGET_DIR/etc/version"
|
||||
ixmsg "Creating /etc/version: $(cat "$TARGET_DIR/etc/version")"
|
||||
|
||||
# In case of ambguities, this is what the image was built from
|
||||
@@ -120,3 +120,29 @@ grep -qsE '^/bin/clish$$' "$TARGET_DIR/etc/shells" \
|
||||
if [ "$BR2_PACKAGE_HOST_PYTHON_YANGDOC" = "y" ]; then
|
||||
mkyangdoc "$BINARIES_DIR/yangdoc.html"
|
||||
fi
|
||||
|
||||
# Bundle the mkdocs User's Guide into the rootfs, served by the WebUI's
|
||||
# nginx at /guide/. Only when the WebUI is present (nothing serves it
|
||||
# otherwise, and it keeps minimal images small) and mkdocs is on the build
|
||||
# host. Best-effort: a failed build warns but does not abort the image
|
||||
# build, and the WebUI hides its User Guide entry when the docs are absent.
|
||||
mkuserguide()
|
||||
{
|
||||
local cfg dst
|
||||
cfg="$(readlink -f "$common/../..")/mkdocs.yml"
|
||||
dst="$TARGET_DIR/var/www/guide"
|
||||
|
||||
if ! command -v mkdocs >/dev/null 2>&1; then
|
||||
ixmsg "mkdocs not found, skipping User's Guide bundling"
|
||||
return
|
||||
fi
|
||||
ixmsg "Building User's Guide into $dst"
|
||||
if ! mkdocs build -f "$cfg" -d "$dst" --clean --quiet; then
|
||||
ixmsg "WARNING: mkdocs build failed, shipping without on-device User's Guide"
|
||||
rm -rf "$dst"
|
||||
fi
|
||||
}
|
||||
|
||||
if [ "$BR2_PACKAGE_WEBUI" = "y" ]; then
|
||||
mkuserguide
|
||||
fi
|
||||
|
||||
@@ -1,85 +1,85 @@
|
||||
mainmenu "QEMU Virtualization"
|
||||
|
||||
config QEMU_ARCH_IS_32
|
||||
config IX_QEMU_ARCH_IS_32
|
||||
bool
|
||||
|
||||
config QEMU_ARCH_IS_64
|
||||
config IX_QEMU_ARCH_IS_64
|
||||
bool
|
||||
|
||||
choice
|
||||
prompt "Target Architecture"
|
||||
default @ARCH@
|
||||
|
||||
config QEMU_riscv64
|
||||
bool "risv64"
|
||||
select QEMU_ARCH_IS_64
|
||||
config IX_QEMU_riscv64
|
||||
bool "riscv64"
|
||||
select IX_QEMU_ARCH_IS_64
|
||||
|
||||
config QEMU_x86_64
|
||||
config IX_QEMU_x86_64
|
||||
bool "x86_64"
|
||||
select QEMU_ARCH_IS_64
|
||||
select IX_QEMU_ARCH_IS_64
|
||||
|
||||
config QEMU_arm
|
||||
config IX_QEMU_arm
|
||||
bool "AArch32 (little endian)"
|
||||
select QEMU_ARCH_IS_32
|
||||
select IX_QEMU_ARCH_IS_32
|
||||
|
||||
config QEMU_aarch64
|
||||
config IX_QEMU_aarch64
|
||||
bool "AArch64 (little endian)"
|
||||
select QEMU_ARCH_IS_64
|
||||
select IX_QEMU_ARCH_IS_64
|
||||
|
||||
endchoice
|
||||
|
||||
choice
|
||||
prompt "Loader"
|
||||
default QEMU_LOADER_KERNEL
|
||||
default IX_QEMU_LOADER_KERNEL
|
||||
|
||||
config QEMU_LOADER_KERNEL
|
||||
config IX_QEMU_LOADER_KERNEL
|
||||
bool "Kernel"
|
||||
|
||||
config QEMU_LOADER_UBOOT
|
||||
config IX_QEMU_LOADER_UBOOT
|
||||
bool "U-Boot"
|
||||
depends on QEMU_aarch64
|
||||
depends on IX_QEMU_aarch64
|
||||
|
||||
config QEMU_LOADER_OVMF
|
||||
config IX_QEMU_LOADER_OVMF
|
||||
bool "OVMF (UEFI)"
|
||||
depends on QEMU_x86_64
|
||||
depends on IX_QEMU_x86_64
|
||||
|
||||
endchoice
|
||||
|
||||
choice
|
||||
prompt "Rootfs type"
|
||||
default QEMU_ROOTFS_INITRD
|
||||
default IX_QEMU_ROOTFS_INITRD
|
||||
|
||||
config QEMU_ROOTFS_MMC
|
||||
config IX_QEMU_ROOTFS_MMC
|
||||
bool "MMC"
|
||||
depends on QEMU_aarch64
|
||||
depends on IX_QEMU_aarch64
|
||||
|
||||
config QEMU_ROOTFS_INITRD
|
||||
config IX_QEMU_ROOTFS_INITRD
|
||||
bool "Initrd"
|
||||
depends on QEMU_LOADER_KERNEL
|
||||
depends on IX_QEMU_LOADER_KERNEL
|
||||
|
||||
config QEMU_ROOTFS_VSCSI
|
||||
config IX_QEMU_ROOTFS_VSCSI
|
||||
bool "Virtio SCSI"
|
||||
|
||||
endchoice
|
||||
|
||||
choice
|
||||
prompt "Console"
|
||||
default QEMU_CONSOLE_SERIAL if QEMU_arm
|
||||
default QEMU_CONSOLE_VIRTIO
|
||||
default IX_QEMU_CONSOLE_SERIAL if IX_QEMU_arm
|
||||
default IX_QEMU_CONSOLE_VIRTIO
|
||||
|
||||
config QEMU_CONSOLE_VIRTIO
|
||||
config IX_QEMU_CONSOLE_VIRTIO
|
||||
bool "Virtio (hvc0)"
|
||||
|
||||
config QEMU_CONSOLE_SERIAL
|
||||
config IX_QEMU_CONSOLE_SERIAL
|
||||
bool "Serial (ttyS0/ttyAMA0)"
|
||||
depends on !QEMU_LOADER_OVMF
|
||||
depends on !IX_QEMU_LOADER_OVMF
|
||||
endchoice
|
||||
|
||||
config QEMU_MACHINE
|
||||
config IX_QEMU_MACHINE
|
||||
string "Select emulated machine"
|
||||
default "qemu-system-arm -M virt,accel=kvm:tcg -cpu max" if QEMU_arm
|
||||
default "qemu-system-aarch64 -M virt,accel=kvm:tcg -cpu cortex-a53" if QEMU_aarch64
|
||||
default "qemu-system-x86_64 -M pc,accel=kvm:tcg -cpu max" if QEMU_x86_64
|
||||
default "qemu-system-arm -M virt,accel=kvm:tcg -cpu max" if IX_QEMU_arm
|
||||
default "qemu-system-aarch64 -M virt,accel=kvm:tcg -cpu cortex-a53" if IX_QEMU_aarch64
|
||||
default "qemu-system-x86_64 -M pc,accel=kvm:tcg -cpu max" if IX_QEMU_x86_64
|
||||
help
|
||||
You should not have to change this setting, although you may
|
||||
want to tweak it, or change the acceleration.
|
||||
@@ -88,7 +88,7 @@ config QEMU_MACHINE
|
||||
the defconfig you started with. Currently Infix supports
|
||||
arm (AArch32), aarch64 (ARM64), and x86_64 (AMD64).
|
||||
|
||||
config QEMU_MACHINE_RAM
|
||||
config IX_QEMU_MACHINE_RAM
|
||||
string "RAM size (k/M/G)"
|
||||
default "448M"
|
||||
help
|
||||
@@ -96,62 +96,62 @@ config QEMU_MACHINE_RAM
|
||||
if you get kernel panic with: "System is deadlocked on memory",
|
||||
try increasing this one.
|
||||
|
||||
config QEMU_KERNEL
|
||||
config IX_QEMU_KERNEL
|
||||
string
|
||||
depends on QEMU_LOADER_KERNEL
|
||||
default "../zImage" if QEMU_arm
|
||||
default "../Image" if QEMU_aarch64
|
||||
default "../bzImage" if QEMU_x86_64
|
||||
depends on IX_QEMU_LOADER_KERNEL
|
||||
default "../zImage" if IX_QEMU_arm
|
||||
default "../Image" if IX_QEMU_aarch64
|
||||
default "../bzImage" if IX_QEMU_x86_64
|
||||
|
||||
config QEMU_BIOS
|
||||
config IX_QEMU_BIOS
|
||||
string
|
||||
depends on !QEMU_LOADER_KERNEL
|
||||
default "../u-boot.bin" if QEMU_LOADER_UBOOT
|
||||
default "../OVMF.fd" if QEMU_LOADER_OVMF
|
||||
depends on !IX_QEMU_LOADER_KERNEL
|
||||
default "../u-boot.bin" if IX_QEMU_LOADER_UBOOT
|
||||
default "../OVMF.fd" if IX_QEMU_LOADER_OVMF
|
||||
|
||||
config QEMU_ROOTFS
|
||||
config IX_QEMU_ROOTFS
|
||||
string
|
||||
default "@DISK_IMG@" if !QEMU_ROOTFS_INITRD
|
||||
default "../rootfs.squashfs" if QEMU_ROOTFS_INITRD
|
||||
default "@DISK_IMG@" if !IX_QEMU_ROOTFS_INITRD
|
||||
default "../rootfs.squashfs" if IX_QEMU_ROOTFS_INITRD
|
||||
|
||||
config QEMU_DTB_EXTEND
|
||||
config IX_QEMU_DTB_EXTEND
|
||||
bool
|
||||
depends on QEMU_LOADER_UBOOT
|
||||
default y if QEMU_aarch64
|
||||
depends on IX_QEMU_LOADER_UBOOT
|
||||
default y if IX_QEMU_aarch64
|
||||
|
||||
if QEMU_ROOTFS_INITRD
|
||||
if IX_QEMU_ROOTFS_INITRD
|
||||
|
||||
config QEMU_RW
|
||||
config IX_QEMU_RW
|
||||
string "Writable /cfg layer"
|
||||
depends on QEMU_ROOTFS_INITRD
|
||||
depends on IX_QEMU_ROOTFS_INITRD
|
||||
default "cfg.ext4"
|
||||
|
||||
config QEMU_RW_VAR_OPT
|
||||
config IX_QEMU_RW_VAR_OPT
|
||||
bool "Separate writable /var"
|
||||
|
||||
if QEMU_RW_VAR_OPT
|
||||
config QEMU_RW_VAR_SIZE
|
||||
if IX_QEMU_RW_VAR_OPT
|
||||
config IX_QEMU_RW_VAR_SIZE
|
||||
string "Size of /var"
|
||||
default "256M"
|
||||
config QEMU_RW_VAR
|
||||
config IX_QEMU_RW_VAR
|
||||
string "Writable /var layer"
|
||||
default "var.ext4"
|
||||
endif
|
||||
|
||||
endif
|
||||
|
||||
config QEMU_VPD
|
||||
config IX_QEMU_VPD
|
||||
bool "Emulate a Vital Product Data (VPD) Memory"
|
||||
|
||||
config QEMU_HOST
|
||||
config IX_QEMU_HOST
|
||||
string "Export host filesystem path"
|
||||
default "/tmp"
|
||||
|
||||
config QEMU_APPEND
|
||||
config IX_QEMU_APPEND
|
||||
string "Extra kernel options"
|
||||
depends on !QEMU_ROOTFS_MMC
|
||||
depends on !IX_QEMU_ROOTFS_MMC
|
||||
|
||||
config QEMU_EXTRA
|
||||
config IX_QEMU_EXTRA
|
||||
string "Extra QEMU options"
|
||||
|
||||
|
||||
@@ -159,72 +159,72 @@ comment "RTC"
|
||||
|
||||
choice
|
||||
prompt "Mode"
|
||||
default QEMU_RTC_UTC
|
||||
default IX_QEMU_RTC_UTC
|
||||
|
||||
config QEMU_RTC_UTC
|
||||
config IX_QEMU_RTC_UTC
|
||||
bool "UTC"
|
||||
|
||||
config QEMU_RTC_LOCAL
|
||||
config IX_QEMU_RTC_LOCAL
|
||||
bool "Local time"
|
||||
|
||||
config QEMU_RTC_RANDOM
|
||||
config IX_QEMU_RTC_RANDOM
|
||||
bool "Random"
|
||||
|
||||
endchoice
|
||||
|
||||
choice
|
||||
prompt "Clock"
|
||||
default QEMU_CLOCK_HOST
|
||||
default IX_QEMU_CLOCK_HOST
|
||||
|
||||
config QEMU_CLOCK_HOST
|
||||
config IX_QEMU_CLOCK_HOST
|
||||
bool "Host clock"
|
||||
|
||||
config QEMU_CLOCK_RT
|
||||
config IX_QEMU_CLOCK_RT
|
||||
bool "Independent (monotonic)"
|
||||
|
||||
config QEMU_CLOCK_VM
|
||||
config IX_QEMU_CLOCK_VM
|
||||
bool "Virtual"
|
||||
|
||||
endchoice
|
||||
|
||||
config QEMU_RTC
|
||||
config IX_QEMU_RTC
|
||||
string
|
||||
default "utc" if QEMU_RTC_UTC
|
||||
default "localtime" if QEMU_RTC_LOCAL
|
||||
default "random" if QEMU_RTC_RANDOM
|
||||
default "utc" if IX_QEMU_RTC_UTC
|
||||
default "localtime" if IX_QEMU_RTC_LOCAL
|
||||
default "random" if IX_QEMU_RTC_RANDOM
|
||||
|
||||
config QEMU_CLOCK
|
||||
config IX_QEMU_CLOCK
|
||||
string
|
||||
default "host" if QEMU_CLOCK_HOST
|
||||
default "rt" if QEMU_CLOCK_RT
|
||||
default "vm" if QEMU_CLOCK_VM
|
||||
default "host" if IX_QEMU_CLOCK_HOST
|
||||
default "rt" if IX_QEMU_CLOCK_RT
|
||||
default "vm" if IX_QEMU_CLOCK_VM
|
||||
|
||||
comment "Networking"
|
||||
|
||||
choice
|
||||
prompt "Network Mode"
|
||||
default QEMU_NET_USER
|
||||
default IX_QEMU_NET_USER
|
||||
|
||||
config QEMU_NET_NONE
|
||||
config IX_QEMU_NET_NONE
|
||||
bool "None"
|
||||
|
||||
config QEMU_NET_BRIDGE
|
||||
config IX_QEMU_NET_BRIDGE
|
||||
bool "Bridged"
|
||||
|
||||
config QEMU_NET_USER
|
||||
config IX_QEMU_NET_USER
|
||||
bool "User"
|
||||
|
||||
config QEMU_NET_TAP
|
||||
config IX_QEMU_NET_TAP
|
||||
bool "TAP"
|
||||
|
||||
config QEMU_NET_ROCKER
|
||||
config IX_QEMU_NET_ROCKER
|
||||
bool "Rocker"
|
||||
|
||||
endchoice
|
||||
|
||||
config QEMU_NET_MODEL
|
||||
config IX_QEMU_NET_MODEL
|
||||
string "Interface model"
|
||||
default "virtio-net-device" if QEMU_arm
|
||||
default "virtio-net-device" if IX_QEMU_arm
|
||||
default "virtio-net-pci"
|
||||
help
|
||||
The default, virtio-net-pci, NIC works for most use-cases, but
|
||||
@@ -233,23 +233,23 @@ config QEMU_NET_MODEL
|
||||
|
||||
Note: ARM 32-bit uses virtio-net-device (MMIO) by default.
|
||||
|
||||
config QEMU_NET_BRIDGE_DEV
|
||||
config IX_QEMU_NET_BRIDGE_DEV
|
||||
string "Bridge device"
|
||||
depends on QEMU_NET_BRIDGE
|
||||
depends on IX_QEMU_NET_BRIDGE
|
||||
default "virbr0"
|
||||
|
||||
config QEMU_NET_USER_OPTS
|
||||
config IX_QEMU_NET_USER_OPTS
|
||||
string "User mode options"
|
||||
depends on QEMU_NET_USER
|
||||
depends on IX_QEMU_NET_USER
|
||||
help
|
||||
Extra -nic user,<OPTIONS>
|
||||
|
||||
config QEMU_NET_TAP_N
|
||||
config IX_QEMU_NET_TAP_N
|
||||
int "Number of TAPs"
|
||||
depends on QEMU_NET_TAP
|
||||
depends on IX_QEMU_NET_TAP
|
||||
default 1
|
||||
|
||||
config QEMU_NET_PORTS
|
||||
config IX_QEMU_NET_PORTS
|
||||
int "Number of Rocker switch ports"
|
||||
depends on QEMU_NET_ROCKER
|
||||
depends on IX_QEMU_NET_ROCKER
|
||||
default 10
|
||||
|
||||
@@ -10,7 +10,7 @@ qemu-kconfig = \
|
||||
BR2_CONFIG="$(BINARIES_DIR)/qemu/.config" \
|
||||
$(BUILD_DIR)/buildroot-config/$(1) $(2) "$(BINARIES_DIR)/qemu/Config.in"
|
||||
|
||||
ifeq ($(QEMU_SCRIPTS),y)
|
||||
ifeq ($(IX_QEMU_SCRIPTS),y)
|
||||
|
||||
.PHONY: run
|
||||
run:
|
||||
@@ -33,7 +33,7 @@ $(BINARIES_DIR)/qemu/run.sh: $(QEMU_SCRIPTS_DIR)/run.sh
|
||||
$(BINARIES_DIR)/qemu/Config.in: $(QEMU_SCRIPTS_DIR)/Config.in.in
|
||||
@mkdir -p $(dir $@)
|
||||
@sed \
|
||||
-e "s:@ARCH@:QEMU_$(BR2_ARCH):" \
|
||||
-e "s:@ARCH@:IX_QEMU_$(BR2_ARCH):" \
|
||||
-e "s:@DISK_IMG@:../$(INFIX_ARTIFACT).qcow2:" \
|
||||
< $< >$@
|
||||
|
||||
|
||||
@@ -40,7 +40,7 @@ usage()
|
||||
echo " ARGS1 Args before the '--' separator are for kernel space"
|
||||
echo " -- Separator"
|
||||
echo " ARGS2 Args after the '--' separator are for the init process"
|
||||
echo " Also, qemu.cfg has QEMU_APPEND which can affect this."
|
||||
echo " Also, qemu.cfg has IX_QEMU_APPEND which can affect this."
|
||||
echo
|
||||
echo "Example:"
|
||||
echo " $prognm -- finit.debug"
|
||||
@@ -62,45 +62,45 @@ load_qemucfg()
|
||||
# shellcheck disable=SC1090
|
||||
. "./.config"
|
||||
|
||||
[ "$CONFIG_QEMU_MACHINE" ] || die "Missing QEMU_MACHINE"
|
||||
[ "$CONFIG_QEMU_ROOTFS" ] || die "Missing QEMU_ROOTFS"
|
||||
[ "$CONFIG_IX_QEMU_MACHINE" ] || die "Missing IX_QEMU_MACHINE"
|
||||
[ "$CONFIG_IX_QEMU_ROOTFS" ] || die "Missing IX_QEMU_ROOTFS"
|
||||
|
||||
[ -n "$CONFIG_QEMU_KERNEL" ] && [ -n "$CONFIG_QEMU_BIOS" ] \
|
||||
&& die "QEMU_KERNEL conflicts with QEMU_BIOS"
|
||||
[ -n "$CONFIG_IX_QEMU_KERNEL" ] && [ -n "$CONFIG_IX_QEMU_BIOS" ] \
|
||||
&& die "IX_QEMU_KERNEL conflicts with IX_QEMU_BIOS"
|
||||
|
||||
[ -z "$CONFIG_QEMU_KERNEL" ] && [ -z "$CONFIG_QEMU_BIOS" ] \
|
||||
&& die "QEMU_KERNEL or QEMU_BIOS must be set"
|
||||
[ -z "$CONFIG_IX_QEMU_KERNEL" ] && [ -z "$CONFIG_IX_QEMU_BIOS" ] \
|
||||
&& die "IX_QEMU_KERNEL or IX_QEMU_BIOS must be set"
|
||||
}
|
||||
|
||||
loader_args()
|
||||
{
|
||||
if [ "$CONFIG_QEMU_BIOS" ]; then
|
||||
echo -n "-bios $CONFIG_QEMU_BIOS "
|
||||
elif [ "$CONFIG_QEMU_KERNEL" ]; then
|
||||
echo -n "-kernel $CONFIG_QEMU_KERNEL "
|
||||
if [ "$CONFIG_IX_QEMU_BIOS" ]; then
|
||||
echo -n "-bios $CONFIG_IX_QEMU_BIOS "
|
||||
elif [ "$CONFIG_IX_QEMU_KERNEL" ]; then
|
||||
echo -n "-kernel $CONFIG_IX_QEMU_KERNEL "
|
||||
fi
|
||||
}
|
||||
|
||||
append_args()
|
||||
{
|
||||
# ARM 32-bit doesn't support virtio console properly, always use serial
|
||||
if [ "$CONFIG_QEMU_arm" ]; then
|
||||
if [ "$CONFIG_IX_QEMU_arm" ]; then
|
||||
echo -n "console=ttyAMA0 "
|
||||
elif [ "$CONFIG_QEMU_CONSOLE_VIRTIO" ]; then
|
||||
elif [ "$CONFIG_IX_QEMU_CONSOLE_VIRTIO" ]; then
|
||||
echo -n "console=hvc0 "
|
||||
elif [ "$CONFIG_QEMU_x86_64" ]; then
|
||||
elif [ "$CONFIG_IX_QEMU_x86_64" ]; then
|
||||
echo -n "console=ttyS0 "
|
||||
elif [ "$CONFIG_QEMU_aarch64" ]; then
|
||||
elif [ "$CONFIG_IX_QEMU_aarch64" ]; then
|
||||
echo -n "console=ttyAMA0 "
|
||||
else
|
||||
die "Unknown console"
|
||||
fi
|
||||
|
||||
if [ "$CONFIG_QEMU_ROOTFS_INITRD" = "y" ]; then
|
||||
if [ "$CONFIG_IX_QEMU_ROOTFS_INITRD" = "y" ]; then
|
||||
# Size of initrd, rounded up to nearest kb
|
||||
size=$((($(stat -c %s "$CONFIG_QEMU_ROOTFS") + 1023) >> 10))
|
||||
size=$((($(stat -c %s "$CONFIG_IX_QEMU_ROOTFS") + 1023) >> 10))
|
||||
echo -n "root=/dev/ram0 ramdisk_size=${size} "
|
||||
elif [ "$CONFIG_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
||||
elif [ "$CONFIG_IX_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
||||
echo -n "root=PARTLABEL=primary "
|
||||
fi
|
||||
|
||||
@@ -110,20 +110,20 @@ append_args()
|
||||
echo -n "debug "
|
||||
fi
|
||||
|
||||
echo -n "${QEMU_APPEND} ${QEMU_EXTRA_APPEND} "
|
||||
echo -n "${IX_QEMU_APPEND} ${QEMU_EXTRA_APPEND} "
|
||||
}
|
||||
|
||||
rootfs_args()
|
||||
{
|
||||
if [ "$CONFIG_QEMU_ROOTFS_INITRD" = "y" ]; then
|
||||
echo -n "-initrd $CONFIG_QEMU_ROOTFS "
|
||||
elif [ "$CONFIG_QEMU_ROOTFS_MMC" = "y" ]; then
|
||||
if [ "$CONFIG_IX_QEMU_ROOTFS_INITRD" = "y" ]; then
|
||||
echo -n "-initrd $CONFIG_IX_QEMU_ROOTFS "
|
||||
elif [ "$CONFIG_IX_QEMU_ROOTFS_MMC" = "y" ]; then
|
||||
echo -n "-device sdhci-pci "
|
||||
echo -n "-device sd-card,drive=mmc "
|
||||
echo -n "-drive id=mmc,file=$CONFIG_QEMU_ROOTFS,if=none,format=raw "
|
||||
elif [ "$CONFIG_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
||||
echo -n "-drive id=mmc,file=$CONFIG_IX_QEMU_ROOTFS,if=none,format=raw "
|
||||
elif [ "$CONFIG_IX_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
||||
# ARM 32-bit virt machine uses MMIO virtio devices, not PCI
|
||||
if [ "$CONFIG_QEMU_arm" ]; then
|
||||
if [ "$CONFIG_IX_QEMU_arm" ]; then
|
||||
echo -n "-drive file=qemu.qcow2,if=none,format=qcow2,id=rootfs "
|
||||
echo -n "-device virtio-blk-device,drive=rootfs "
|
||||
else
|
||||
@@ -140,9 +140,9 @@ serial_args()
|
||||
echo -n "-chardev stdio,id=console0,mux=on "
|
||||
echo -n "-mon chardev=console0 "
|
||||
|
||||
if [ "$CONFIG_QEMU_CONSOLE_VIRTIO" ]; then
|
||||
if [ "$CONFIG_IX_QEMU_CONSOLE_VIRTIO" ]; then
|
||||
echo -n "-device virtconsole,nr=0,name=console,chardev=console0 "
|
||||
elif [ "$CONFIG_QEMU_CONSOLE_SERIAL" ]; then
|
||||
elif [ "$CONFIG_IX_QEMU_CONSOLE_SERIAL" ]; then
|
||||
echo -n "-serial chardev:console0 "
|
||||
else
|
||||
die "Unknown console"
|
||||
@@ -175,7 +175,7 @@ usb_args()
|
||||
|
||||
rw_args()
|
||||
{
|
||||
[ "$CONFIG_QEMU_RW" ] || return
|
||||
[ "$CONFIG_IX_QEMU_RW" ] || return
|
||||
|
||||
command -v mkfs.ext4 >/dev/null || die "$prognm: cannot find mkfs.ext4"
|
||||
|
||||
@@ -184,45 +184,45 @@ rw_args()
|
||||
mkfs.ext4 -L aux "aux.ext4" >/dev/null 2>&1
|
||||
fi
|
||||
|
||||
if ! [ -f "$CONFIG_QEMU_RW" ]; then
|
||||
dd if=/dev/zero of="$CONFIG_QEMU_RW" bs=16M count=1 >/dev/null 2>&1
|
||||
mkfs.ext4 -L cfg "$CONFIG_QEMU_RW" >/dev/null 2>&1
|
||||
if ! [ -f "$CONFIG_IX_QEMU_RW" ]; then
|
||||
dd if=/dev/zero of="$CONFIG_IX_QEMU_RW" bs=16M count=1 >/dev/null 2>&1
|
||||
mkfs.ext4 -L cfg "$CONFIG_IX_QEMU_RW" >/dev/null 2>&1
|
||||
fi
|
||||
|
||||
# ARM 32-bit virt machine uses MMIO virtio devices, not PCI
|
||||
if [ "$CONFIG_QEMU_arm" ]; then
|
||||
if [ "$CONFIG_IX_QEMU_arm" ]; then
|
||||
echo -n "-drive file=aux.ext4,if=none,format=raw,id=aux "
|
||||
echo -n "-device virtio-blk-device,drive=aux "
|
||||
echo -n "-drive file=$CONFIG_QEMU_RW,if=none,format=raw,id=cfg "
|
||||
echo -n "-drive file=$CONFIG_IX_QEMU_RW,if=none,format=raw,id=cfg "
|
||||
echo -n "-device virtio-blk-device,drive=cfg "
|
||||
|
||||
if [ "$CONFIG_QEMU_RW_VAR_OPT" ]; then
|
||||
if ! [ -f "$CONFIG_QEMU_RW_VAR" ]; then
|
||||
dd if=/dev/zero of="$CONFIG_QEMU_RW_VAR" bs=$CONFIG_QEMU_RW_VAR_SIZE count=1 >/dev/null 2>&1
|
||||
mkfs.ext4 -L var "$CONFIG_QEMU_RW_VAR" >/dev/null 2>&1
|
||||
if [ "$CONFIG_IX_QEMU_RW_VAR_OPT" ]; then
|
||||
if ! [ -f "$CONFIG_IX_QEMU_RW_VAR" ]; then
|
||||
dd if=/dev/zero of="$CONFIG_IX_QEMU_RW_VAR" bs=$CONFIG_IX_QEMU_RW_VAR_SIZE count=1 >/dev/null 2>&1
|
||||
mkfs.ext4 -L var "$CONFIG_IX_QEMU_RW_VAR" >/dev/null 2>&1
|
||||
fi
|
||||
echo -n "-drive file=$CONFIG_QEMU_RW_VAR,if=none,format=raw,id=var "
|
||||
echo -n "-drive file=$CONFIG_IX_QEMU_RW_VAR,if=none,format=raw,id=var "
|
||||
echo -n "-device virtio-blk-device,drive=var "
|
||||
fi
|
||||
else
|
||||
echo -n "-drive file=aux.ext4,if=virtio,format=raw,bus=0,unit=3 "
|
||||
echo -n "-drive file=$CONFIG_QEMU_RW,if=virtio,format=raw,bus=0,unit=1 "
|
||||
echo -n "-drive file=$CONFIG_IX_QEMU_RW,if=virtio,format=raw,bus=0,unit=1 "
|
||||
|
||||
if [ "$CONFIG_QEMU_RW_VAR_OPT" ]; then
|
||||
if ! [ -f "$CONFIG_QEMU_RW_VAR" ]; then
|
||||
dd if=/dev/zero of="$CONFIG_QEMU_RW_VAR" bs=$CONFIG_QEMU_RW_VAR_SIZE count=1 >/dev/null 2>&1
|
||||
mkfs.ext4 -L var "$CONFIG_QEMU_RW_VAR" >/dev/null 2>&1
|
||||
if [ "$CONFIG_IX_QEMU_RW_VAR_OPT" ]; then
|
||||
if ! [ -f "$CONFIG_IX_QEMU_RW_VAR" ]; then
|
||||
dd if=/dev/zero of="$CONFIG_IX_QEMU_RW_VAR" bs=$CONFIG_IX_QEMU_RW_VAR_SIZE count=1 >/dev/null 2>&1
|
||||
mkfs.ext4 -L var "$CONFIG_IX_QEMU_RW_VAR" >/dev/null 2>&1
|
||||
fi
|
||||
echo -n "-drive file=$CONFIG_QEMU_RW_VAR,if=virtio,format=raw,bus=0,unit=2 "
|
||||
echo -n "-drive file=$CONFIG_IX_QEMU_RW_VAR,if=virtio,format=raw,bus=0,unit=2 "
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
host_args()
|
||||
{
|
||||
[ "$CONFIG_QEMU_HOST" ] || return
|
||||
[ "$CONFIG_IX_QEMU_HOST" ] || return
|
||||
|
||||
echo -n "-virtfs local,path=$CONFIG_QEMU_HOST,security_model=none,writeout=immediate,mount_tag=hostfs "
|
||||
echo -n "-virtfs local,path=$CONFIG_IX_QEMU_HOST,security_model=none,writeout=immediate,mount_tag=hostfs "
|
||||
}
|
||||
|
||||
net_dev_args()
|
||||
@@ -230,7 +230,7 @@ net_dev_args()
|
||||
name="e$1"
|
||||
mac=$(printf "02:00:00:00:00:%02x" "$1")
|
||||
|
||||
echo -n "-device $CONFIG_QEMU_NET_MODEL,netdev=$name,mac=$mac "
|
||||
echo -n "-device $CONFIG_IX_QEMU_NET_MODEL,netdev=$name,mac=$mac "
|
||||
echo "$name $mac" >>"$mactab"
|
||||
}
|
||||
|
||||
@@ -252,29 +252,29 @@ net_args()
|
||||
:> "$mactab"
|
||||
echo -n "-fw_cfg name=opt/mactab,file=$mactab "
|
||||
|
||||
if [ "$CONFIG_QEMU_NET_BRIDGE" = "y" ]; then
|
||||
echo -n "-netdev bridge,id=e1,br=$CONFIG_QEMU_NET_BRIDGE_DEV "
|
||||
if [ "$CONFIG_IX_QEMU_NET_BRIDGE" = "y" ]; then
|
||||
echo -n "-netdev bridge,id=e1,br=$CONFIG_IX_QEMU_NET_BRIDGE_DEV "
|
||||
net_dev_args 1
|
||||
elif [ "$CONFIG_QEMU_NET_TAP" = "y" ]; then
|
||||
for i in $(seq 1 "$CONFIG_QEMU_NET_TAP_N"); do
|
||||
elif [ "$CONFIG_IX_QEMU_NET_TAP" = "y" ]; then
|
||||
for i in $(seq 1 "$CONFIG_IX_QEMU_NET_TAP_N"); do
|
||||
echo -n "-netdev tap,id=e$i,ifname=qtap$i "
|
||||
net_dev_args "$i"
|
||||
done
|
||||
elif [ "$CONFIG_QEMU_NET_ROCKER" = "y" ]; then
|
||||
elif [ "$CONFIG_IX_QEMU_NET_ROCKER" = "y" ]; then
|
||||
sw=sw0 # Only single switch support atm.
|
||||
echo -n "-device '{\"driver\":\"rocker\", \"name\":\"${sw}\", "
|
||||
echo -n "\"fp_start_macaddr\":\"02:00:00:00:00:01\", "
|
||||
echo -n "\"ports\":["
|
||||
for i in $(seq 1 "$CONFIG_QEMU_NET_PORTS"); do
|
||||
for i in $(seq 1 "$CONFIG_IX_QEMU_NET_PORTS"); do
|
||||
[ "$i" -gt 1 ] && echo -n ", "
|
||||
echo -n "\"${sw}p${i}\""
|
||||
done
|
||||
echo -n "]}' "
|
||||
for i in $(seq 1 "$CONFIG_QEMU_NET_PORTS"); do
|
||||
for i in $(seq 1 "$CONFIG_IX_QEMU_NET_PORTS"); do
|
||||
rocker_port_args 0 "$i"
|
||||
done
|
||||
elif [ "$CONFIG_QEMU_NET_USER" = "y" ]; then
|
||||
[ "$CONFIG_QEMU_NET_USER_OPTS" ] && useropts=",$CONFIG_QEMU_NET_USER_OPTS"
|
||||
elif [ "$CONFIG_IX_QEMU_NET_USER" = "y" ]; then
|
||||
[ "$CONFIG_IX_QEMU_NET_USER_OPTS" ] && useropts=",$CONFIG_IX_QEMU_NET_USER_OPTS"
|
||||
echo -n "-netdev user,id=e1${useropts} "
|
||||
net_dev_args 1
|
||||
else
|
||||
@@ -285,7 +285,7 @@ net_args()
|
||||
# Vital Product data
|
||||
vpd_args()
|
||||
{
|
||||
[ "$CONFIG_QEMU_VPD" = "y" ] || return
|
||||
[ "$CONFIG_IX_QEMU_VPD" = "y" ] || return
|
||||
|
||||
vpd_file="${qdir}/vpd"
|
||||
|
||||
@@ -324,8 +324,8 @@ random_date()
|
||||
|
||||
rtc_args()
|
||||
{
|
||||
rtc="${CONFIG_QEMU_RTC:-utc}"
|
||||
clock="${CONFIG_QEMU_CLOCK:-host}"
|
||||
rtc="${CONFIG_IX_QEMU_RTC:-utc}"
|
||||
clock="${CONFIG_IX_QEMU_CLOCK:-host}"
|
||||
if [ "$rtc" = "random" ]; then
|
||||
rtc=$(random_date)
|
||||
fi
|
||||
@@ -358,28 +358,28 @@ extract_squashfs()
|
||||
run_qemu()
|
||||
{
|
||||
# Auto-extract rootfs.squashfs from rootfs.itb if needed for initrd mode
|
||||
if [ "$CONFIG_QEMU_ROOTFS_INITRD" = "y" ] && [ ! -f "$CONFIG_QEMU_ROOTFS" ]; then
|
||||
itb="${CONFIG_QEMU_ROOTFS%.squashfs}.itb"
|
||||
if [ "$CONFIG_IX_QEMU_ROOTFS_INITRD" = "y" ] && [ ! -f "$CONFIG_IX_QEMU_ROOTFS" ]; then
|
||||
itb="${CONFIG_IX_QEMU_ROOTFS%.squashfs}.itb"
|
||||
if [ -f "$itb" ]; then
|
||||
extract_squashfs "$itb" "$CONFIG_QEMU_ROOTFS"
|
||||
extract_squashfs "$itb" "$CONFIG_IX_QEMU_ROOTFS"
|
||||
else
|
||||
die "Missing $CONFIG_QEMU_ROOTFS and cannot find $itb to extract it from"
|
||||
die "Missing $CONFIG_IX_QEMU_ROOTFS and cannot find $itb to extract it from"
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ "$CONFIG_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
||||
if [ "$CONFIG_IX_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
||||
if ! qemu-img check "qemu.qcow2"; then
|
||||
rm -f "qemu.qcow2"
|
||||
fi
|
||||
if [ ! -f "qemu.qcow2" ]; then
|
||||
echo "Creating qcow2 disk image for Qemu ..."
|
||||
qemu-img create -f qcow2 -o backing_file="$CONFIG_QEMU_ROOTFS" \
|
||||
qemu-img create -f qcow2 -o backing_file="$CONFIG_IX_QEMU_ROOTFS" \
|
||||
-F qcow2 "qemu.qcow2" > /dev/null
|
||||
fi
|
||||
fi
|
||||
|
||||
read -r qemu <<EOF
|
||||
$CONFIG_QEMU_MACHINE -nodefaults -m $CONFIG_QEMU_MACHINE_RAM \
|
||||
$CONFIG_IX_QEMU_MACHINE -nodefaults -m $CONFIG_IX_QEMU_MACHINE_RAM \
|
||||
$(loader_args) \
|
||||
$(rootfs_args) \
|
||||
$(serial_args) \
|
||||
@@ -391,14 +391,14 @@ run_qemu()
|
||||
$(rtc_args) \
|
||||
$(vpd_args) \
|
||||
$(gdb_args) \
|
||||
$CONFIG_QEMU_EXTRA
|
||||
$CONFIG_IX_QEMU_EXTRA
|
||||
EOF
|
||||
# Save resulting command to a script, because I cannot for the life
|
||||
# of me figure out how to embed the JSON snippet for Rocker and run
|
||||
# it here without issues, spent way too much time on it -- Joachim
|
||||
run=$(mktemp -t run.qemu.XXX)
|
||||
echo "#!/bin/sh" > "$run"
|
||||
if [ "$CONFIG_QEMU_KERNEL" ]; then
|
||||
if [ "$CONFIG_IX_QEMU_KERNEL" ]; then
|
||||
echo "$qemu -append \"$(append_args)\" $*" >> "$run"
|
||||
else
|
||||
echo "$qemu $*" >> "$run"
|
||||
@@ -419,9 +419,9 @@ EOF
|
||||
|
||||
dtb_args()
|
||||
{
|
||||
[ "$CONFIG_QEMU_LOADER_UBOOT" ] || return
|
||||
[ "$CONFIG_IX_QEMU_LOADER_UBOOT" ] || return
|
||||
|
||||
if [ "$CONFIG_QEMU_DTB_EXTEND" ]; then
|
||||
if [ "$CONFIG_IX_QEMU_DTB_EXTEND" ]; then
|
||||
# On the current architecture, QEMU will generate an internal
|
||||
# DT based on the system configuration.
|
||||
|
||||
@@ -445,12 +445,12 @@ dtb_args()
|
||||
|
||||
generate_dot()
|
||||
{
|
||||
[ "$CONFIG_QEMU_NET_TAP" = "y" ] || return
|
||||
[ "$CONFIG_IX_QEMU_NET_TAP" = "y" ] || return
|
||||
|
||||
hostports="<qtap1> qtap1"
|
||||
targetports="<e1> e1"
|
||||
edges="host:qtap1 -- target:e1 [kind=mgmt];"
|
||||
for tap in $(seq 2 $((CONFIG_QEMU_NET_TAP_N - 1))); do
|
||||
for tap in $(seq 2 $((CONFIG_IX_QEMU_NET_TAP_N - 1))); do
|
||||
hostports="$hostports | <qtap$tap> qtap$tap "
|
||||
targetports="$targetports | <e$tap> e$tap "
|
||||
edges="$edges host:qtap$tap -- target:e$tap;"
|
||||
@@ -485,7 +485,7 @@ EOF
|
||||
|
||||
menuconfig()
|
||||
{
|
||||
grep -q QEMU_MACHINE Config.in || die "$prognm: must be run from the $$O/images/qemu directory"
|
||||
grep -q IX_QEMU_MACHINE Config.in || die "$prognm: must be run from the $$O/images/qemu directory"
|
||||
command -v kconfig-mconf >/dev/null || die "$prognm: cannot find kconfig-mconf for menuconfig"
|
||||
exec kconfig-mconf Config.in
|
||||
}
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
RESTCONF_URL=https://127.0.0.1/restconf
|
||||
INSECURE_TLS=1
|
||||
# Spool firmware uploads (and any other temp files) to persistent storage
|
||||
# instead of the RAM-backed /tmp to enable push-upgrades on low-memory systems.
|
||||
TMPDIR=/var/tmp
|
||||
@@ -1,3 +0,0 @@
|
||||
service <!> name:hostapd :%i \
|
||||
[2345] hostapd -P/var/run/hostapd-%i.pid /etc/hostapd-%i.conf \
|
||||
-- Wi-Fi Access Point @%i
|
||||
@@ -0,0 +1,3 @@
|
||||
service name:wpa_supplicant :%i \
|
||||
[2345] wpa_supplicant -s -i %i -c /etc/wpa_supplicant-%i.conf -P/var/run/wpa_supplicant-%i.pid \
|
||||
-- Wi-Fi Mesh @%i
|
||||
@@ -0,0 +1 @@
|
||||
../restconf.app
|
||||
@@ -0,0 +1,3 @@
|
||||
allow 127.0.0.1;
|
||||
allow ::1;
|
||||
deny all;
|
||||
@@ -0,0 +1 @@
|
||||
restconf-access-local.conf
|
||||
@@ -1,5 +1,6 @@
|
||||
# /telemetry/optics is for streaming (not used atm)
|
||||
location ~ ^/(restconf|yang|.well-known)/ {
|
||||
include /etc/nginx/restconf-access.conf;
|
||||
grpc_pass grpc://[::1]:10080;
|
||||
grpc_set_header Host $host;
|
||||
grpc_set_header X-Real-IP $remote_addr;
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
if [ -s /run/os-update ]; then
|
||||
printf '\n\033[1;33m *** %s ***\033[0m\n\n' "$(cat /run/os-update)"
|
||||
fi
|
||||
@@ -24,6 +24,10 @@ net.ipv4.conf.all.arp_ignore=1
|
||||
net.ipv4.ip_forward=1
|
||||
net.ipv4.ip_forward_update_priority=0
|
||||
|
||||
# Allow binding to non-local addresses, e.g. floating VIPs not yet
|
||||
# configured on an interface, see issue #1022
|
||||
net.ipv4.ip_nonlocal_bind=1
|
||||
|
||||
net.ipv4.conf.all.forwarding=0
|
||||
net.ipv4.conf.default.forwarding=0
|
||||
|
||||
|
||||
@@ -7,6 +7,10 @@ net.ipv6.conf.all.ignore_routes_with_linkdown=1
|
||||
net.ipv6.conf.all.forwarding=0
|
||||
net.ipv6.conf.default.forwarding=0
|
||||
|
||||
# Allow binding to non-local addresses, e.g. floating VIPs not yet
|
||||
# configured on an interface, see issue #1022
|
||||
net.ipv6.ip_nonlocal_bind=1
|
||||
|
||||
# Accept router advertisements even when forwarding is enabled
|
||||
net.ipv6.conf.all.accept_ra=2
|
||||
net.ipv6.conf.default.accept_ra=2
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
f /run/os-update 0666 admin admin
|
||||
@@ -257,15 +257,15 @@ def parse_interface_info(ifname):
|
||||
for line in output.splitlines():
|
||||
stripped = line.strip()
|
||||
|
||||
# Interface type
|
||||
# Interface type (can be multi-word, e.g. "mesh point")
|
||||
if stripped.startswith('type '):
|
||||
result['iftype'] = stripped.split()[1]
|
||||
result['iftype'] = ' '.join(stripped.split()[1:])
|
||||
|
||||
# MAC address
|
||||
elif stripped.startswith('addr '):
|
||||
result['mac'] = stripped.split()[1]
|
||||
|
||||
# SSID
|
||||
# SSID (AP mode) or mesh-id (mesh point mode) — kernel uses same attr
|
||||
elif stripped.startswith('ssid '):
|
||||
result['ssid'] = decode_iw_ssid(' '.join(stripped.split()[1:]))
|
||||
|
||||
@@ -538,6 +538,43 @@ def parse_link(ifname):
|
||||
return result
|
||||
|
||||
|
||||
def parse_phy_caps(phy_name):
|
||||
"""
|
||||
Parse 'iw phy <name> info' for HT and VHT capability bitmasks.
|
||||
Returns: {ht_cap: int, vht_cap: int}
|
||||
|
||||
iw phy info output format:
|
||||
Capabilities: 0x1ef
|
||||
...
|
||||
VHT Capabilities (0x339071b2):
|
||||
...
|
||||
"""
|
||||
actual_phy = normalize_phy_name(phy_name)
|
||||
output = run_iw('phy', actual_phy, 'info')
|
||||
if not output:
|
||||
output = run_iw(actual_phy, 'info')
|
||||
if not output:
|
||||
return {'ht_cap': 0, 'vht_cap': 0}
|
||||
|
||||
ht_cap = 0
|
||||
vht_cap = 0
|
||||
|
||||
for line in output.splitlines():
|
||||
stripped = line.strip()
|
||||
|
||||
# HT Capabilities: "Capabilities: 0x1ef"
|
||||
ht_match = re.match(r'Capabilities:\s+(0x[0-9a-fA-F]+)', stripped)
|
||||
if ht_match:
|
||||
ht_cap = int(ht_match.group(1), 16)
|
||||
|
||||
# VHT Capabilities: "VHT Capabilities (0x339071b2):"
|
||||
vht_match = re.match(r'VHT Capabilities\s+\((0x[0-9a-fA-F]+)\)', stripped)
|
||||
if vht_match:
|
||||
vht_cap = int(vht_match.group(1), 16)
|
||||
|
||||
return {'ht_cap': ht_cap, 'vht_cap': vht_cap}
|
||||
|
||||
|
||||
def main():
|
||||
if len(sys.argv) < 2:
|
||||
print(json.dumps({
|
||||
@@ -548,7 +585,8 @@ def main():
|
||||
'info': 'Get PHY or interface information (requires device)',
|
||||
'survey': 'Get channel survey data (requires interface)',
|
||||
'station': 'Get connected stations in AP mode (requires interface)',
|
||||
'link': 'Get link info in station mode (requires interface)'
|
||||
'link': 'Get link info in station mode (requires interface)',
|
||||
'caps': 'Get HT/VHT capability bitmasks (requires PHY/radio)'
|
||||
},
|
||||
'examples': [
|
||||
'iw.py list',
|
||||
@@ -557,7 +595,8 @@ def main():
|
||||
'iw.py info wlan0',
|
||||
'iw.py station wifi0',
|
||||
'iw.py link wlan0',
|
||||
'iw.py survey wlan0'
|
||||
'iw.py survey wlan0',
|
||||
'iw.py caps radio0'
|
||||
]
|
||||
}, indent=2))
|
||||
sys.exit(1)
|
||||
@@ -594,6 +633,11 @@ def main():
|
||||
data = {'error': 'survey command requires interface argument'}
|
||||
else:
|
||||
data = parse_survey(sys.argv[2])
|
||||
elif command == 'caps':
|
||||
if len(sys.argv) < 3:
|
||||
data = {'error': 'caps command requires PHY/radio argument'}
|
||||
else:
|
||||
data = parse_phy_caps(sys.argv[2])
|
||||
else:
|
||||
data = {'error': f'Unknown command: {command}'}
|
||||
|
||||
|
||||
@@ -0,0 +1,55 @@
|
||||
#!/bin/sh
|
||||
# Check for available software updates and notify on login if one exists.
|
||||
# Called by the scheduler.
|
||||
|
||||
NOTIFY_FILE=/run/os-update
|
||||
TAG=os-update
|
||||
|
||||
# Source os-release for VERSION and IMAGE_ID
|
||||
if [ ! -f /etc/os-release ]; then
|
||||
logger -t "$TAG" "ERROR: /etc/os-release not found"
|
||||
exit 1
|
||||
fi
|
||||
. /etc/os-release
|
||||
|
||||
# Dev/dirty builds have no comparable semver — always show the latest release
|
||||
IS_RELEASE=true
|
||||
if ! echo "$VERSION" | grep -qE '^[0-9]+\.[0-9]+\.[0-9]+'; then
|
||||
IS_RELEASE=false
|
||||
fi
|
||||
|
||||
# Read configured update-url from running config, fall back to upstream
|
||||
UPDATE_URL=$(copy running-config \
|
||||
-x '/ietf-system:system/infix-system:software/check-update/update-url' \
|
||||
2>/dev/null \
|
||||
| jq -r '.. | objects | ."update-url"? // empty')
|
||||
UPDATE_URL=${UPDATE_URL:-"https://github.com/kernelkit/infix"}
|
||||
|
||||
# Derive API URL from the configured update URL.
|
||||
# Default (github.com): https://github.com/org/repo → https://api.github.com/repos/org/repo
|
||||
REPO=$(echo "$UPDATE_URL" | sed 's|https://github.com/||; s|/*$||')
|
||||
API_URL="https://api.github.com/repos/${REPO}/releases/latest"
|
||||
|
||||
LATEST_TAG=$(curl -sSL --max-time 10 "$API_URL" 2>/dev/null \
|
||||
| jq -r '.tag_name // empty')
|
||||
if [ -z "$LATEST_TAG" ]; then
|
||||
logger -p daemon.info -t "$TAG" "Update check skipped: could not reach ${API_URL}"
|
||||
exit 0
|
||||
fi
|
||||
LATEST=${LATEST_TAG#v}
|
||||
|
||||
# Compare: is $1 strictly newer than $2?
|
||||
newer() {
|
||||
[ "$1" = "$2" ] && return 1
|
||||
[ "$(printf '%s\n%s' "$1" "$2" | sort -V | tail -1)" = "$1" ]
|
||||
}
|
||||
|
||||
if [ "$IS_RELEASE" = false ] || newer "$LATEST" "$VERSION"; then
|
||||
RELEASE_URL="${UPDATE_URL}/releases/${LATEST_TAG}"
|
||||
MSG="Software update available: ${LATEST_TAG}, running ${VERSION} (see ${RELEASE_URL})"
|
||||
logger -t "$TAG" "$MSG"
|
||||
printf '%s\n' "$MSG" > "$NOTIFY_FILE"
|
||||
else
|
||||
logger -p daemon.debug -t "$TAG" "No update available (current: $VERSION, latest: $LATEST)"
|
||||
printf '' > "$NOTIFY_FILE"
|
||||
fi
|
||||
@@ -25,7 +25,7 @@ define UBOOT_PRE_BUILD_INSTALL_KEY
|
||||
$(HOST_DIR)/bin/dtc -a 1024 <(echo '/dts-v1/; / { signature {}; };') \
|
||||
>$(@D)/infix-key.dtb
|
||||
$(foreach key, \
|
||||
$(call qstrip,$(TRUSTED_KEYS_DEVELOPMENT_PATH)) $(call qstrip,$(TRUSTED_KEYS_EXTRA_PATH)),\
|
||||
$(call qstrip,$(IX_TRUSTED_KEYS_DEVELOPMENT_PATH)) $(call qstrip,$(IX_TRUSTED_KEYS_EXTRA_PATH)),\
|
||||
$(call uboot-add-pubkey,$(key),$(@D)/infix-key.dtb))
|
||||
$(HOST_DIR)/bin/dtc -I dtb -O dts \
|
||||
<$(@D)/infix-key.dtb \
|
||||
@@ -46,3 +46,12 @@ define UBOOT_PRE_BUILD_INSTALL_ENV
|
||||
$(@D)/arch/$(UBOOT_ARCH)/dts/
|
||||
endef
|
||||
UBOOT_PRE_BUILD_HOOKS += UBOOT_PRE_BUILD_INSTALL_ENV
|
||||
|
||||
# Stamp non-release builds so they cannot be mistaken for a release,
|
||||
# U-Boot's setlocalversion picks up .scmversion, see issue #919.
|
||||
define UBOOT_PRE_BUILD_DEVEL_VERSION
|
||||
echo "-DEVEL" >$(@D)/.scmversion
|
||||
endef
|
||||
ifeq ($(INFIX_RELEASE),)
|
||||
UBOOT_PRE_BUILD_HOOKS += UBOOT_PRE_BUILD_DEVEL_VERSION
|
||||
endif
|
||||
|
||||
@@ -27,7 +27,7 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.32"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.39"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -143,11 +143,11 @@ BR2_PACKAGE_MARVELL_CN9130_CRB=y
|
||||
BR2_PACKAGE_MARVELL_ESPRESSOBIN=y
|
||||
BR2_PACKAGE_RASPBERRYPI_RPI64=y
|
||||
BR2_PACKAGE_STYX_DCP_SC_28P=y
|
||||
INFIX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
INFIX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://www.kernelkit.org/infix/"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
IX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
IX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
IX_HOME="https://github.com/kernelkit/infix/"
|
||||
IX_DOC="https://www.kernelkit.org/infix/"
|
||||
IX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_FEATURE_GPS=y
|
||||
BR2_PACKAGE_FEATURE_WIFI=y
|
||||
BR2_PACKAGE_FEATURE_WIFI_MEDIATEK=y
|
||||
@@ -175,7 +175,6 @@ BR2_PACKAGE_FIREWALL=y
|
||||
BR2_PACKAGE_IITO=y
|
||||
BR2_PACKAGE_KEYACK=y
|
||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||
BR2_PACKAGE_LANDING=y
|
||||
BR2_PACKAGE_LOWDOWN=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_MDNS_ALIAS=y
|
||||
@@ -187,12 +186,14 @@ BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
# BR2_PACKAGE_LANDING is not set
|
||||
BR2_PACKAGE_WEBUI=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
BR2_PACKAGE_PCIUTILS=y
|
||||
IMAGE_ITB_AUX=y
|
||||
IMAGE_ITB_QCOW=y
|
||||
IMAGE_ITB_RAUC=y
|
||||
IMAGE_README=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_IMAGE_ITB_AUX=y
|
||||
IX_IMAGE_ITB_QCOW=y
|
||||
IX_IMAGE_ITB_RAUC=y
|
||||
IX_IMAGE_README=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -27,7 +27,7 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.32"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.39"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -121,11 +121,11 @@ BR2_PACKAGE_MARVELL_CN9130_CRB=y
|
||||
BR2_PACKAGE_MARVELL_ESPRESSOBIN=y
|
||||
BR2_PACKAGE_RASPBERRYPI_RPI64=y
|
||||
BR2_PACKAGE_STYX_DCP_SC_28P=y
|
||||
INFIX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
INFIX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://www.kernelkit.org/infix/"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
IX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
IX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
IX_HOME="https://github.com/kernelkit/infix/"
|
||||
IX_DOC="https://www.kernelkit.org/infix/"
|
||||
IX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_CONFD=y
|
||||
BR2_PACKAGE_NETD=y
|
||||
BR2_PACKAGE_CONFD_TEST_MODE=y
|
||||
@@ -144,15 +144,16 @@ BR2_PACKAGE_FIREWALL=y
|
||||
BR2_PACKAGE_IITO=y
|
||||
BR2_PACKAGE_KEYACK=y
|
||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||
BR2_PACKAGE_LANDING=y
|
||||
BR2_PACKAGE_LOWDOWN=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_MDNS_ALIAS=y
|
||||
BR2_PACKAGE_ONIEPROM=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
IMAGE_ITB_AUX=y
|
||||
IMAGE_ITB_QCOW=y
|
||||
IMAGE_ITB_RAUC=y
|
||||
IMAGE_README=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_IMAGE_ITB_AUX=y
|
||||
IX_IMAGE_ITB_QCOW=y
|
||||
IX_IMAGE_ITB_RAUC=y
|
||||
IX_IMAGE_README=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -25,5 +25,5 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -28,7 +28,7 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.32"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.39"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/arm/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -129,6 +129,7 @@ BR2_PACKAGE_HOST_DOSFSTOOLS=y
|
||||
BR2_PACKAGE_HOST_E2FSPROGS=y
|
||||
BR2_PACKAGE_HOST_ENVIRONMENT_SETUP=y
|
||||
BR2_PACKAGE_HOST_GENEXT2FS=y
|
||||
BR2_PACKAGE_HOST_GO_BIN=y
|
||||
BR2_PACKAGE_HOST_KMOD_XZ=y
|
||||
BR2_PACKAGE_HOST_MTOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
@@ -136,11 +137,11 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
BR2_PACKAGE_MICROCHIP_SAMA7G54_EK=y
|
||||
BR2_PACKAGE_RASPBERRYPI_RPI2=y
|
||||
INFIX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
INFIX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://www.kernelkit.org/infix/"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
IX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
IX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
IX_HOME="https://github.com/kernelkit/infix/"
|
||||
IX_DOC="https://www.kernelkit.org/infix/"
|
||||
IX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_FEATURE_GPS=y
|
||||
BR2_PACKAGE_FEATURE_WIFI_MEDIATEK=y
|
||||
BR2_PACKAGE_FEATURE_WIFI_REALTEK=y
|
||||
@@ -162,7 +163,6 @@ BR2_PACKAGE_FIREWALL=y
|
||||
BR2_PACKAGE_IITO=y
|
||||
BR2_PACKAGE_KEYACK=y
|
||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||
BR2_PACKAGE_LANDING=y
|
||||
BR2_PACKAGE_LOWDOWN=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_MDNS_ALIAS=y
|
||||
@@ -170,11 +170,13 @@ BR2_PACKAGE_NETBROWSE=y
|
||||
BR2_PACKAGE_ONIEPROM=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
# BR2_PACKAGE_LANDING is not set
|
||||
BR2_PACKAGE_WEBUI=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
IMAGE_ITB_AUX=y
|
||||
IMAGE_ITB_QCOW=y
|
||||
IMAGE_ITB_RAUC=y
|
||||
IMAGE_README=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_IMAGE_ITB_AUX=y
|
||||
IX_IMAGE_ITB_QCOW=y
|
||||
IX_IMAGE_ITB_RAUC=y
|
||||
IX_IMAGE_README=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -28,7 +28,7 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.32"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.39"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/arm/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -119,11 +119,11 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
BR2_PACKAGE_MICROCHIP_SAMA7G54_EK=y
|
||||
BR2_PACKAGE_RASPBERRYPI_RPI2=y
|
||||
INFIX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
INFIX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://www.kernelkit.org/infix/"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
IX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
IX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
IX_HOME="https://github.com/kernelkit/infix/"
|
||||
IX_DOC="https://www.kernelkit.org/infix/"
|
||||
IX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_CONFD=y
|
||||
BR2_PACKAGE_NETD=y
|
||||
BR2_PACKAGE_CONFD_TEST_MODE=y
|
||||
@@ -142,15 +142,16 @@ BR2_PACKAGE_FIREWALL=y
|
||||
BR2_PACKAGE_IITO=y
|
||||
BR2_PACKAGE_KEYACK=y
|
||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||
BR2_PACKAGE_LANDING=y
|
||||
BR2_PACKAGE_LOWDOWN=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_MDNS_ALIAS=y
|
||||
BR2_PACKAGE_ONIEPROM=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
IMAGE_ITB_AUX=y
|
||||
IMAGE_ITB_QCOW=y
|
||||
IMAGE_ITB_RAUC=y
|
||||
IMAGE_README=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_IMAGE_ITB_AUX=y
|
||||
IX_IMAGE_ITB_QCOW=y
|
||||
IX_IMAGE_ITB_RAUC=y
|
||||
IX_IMAGE_README=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -40,5 +40,5 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -38,5 +38,5 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -38,5 +38,5 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -38,5 +38,5 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -38,5 +38,5 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -38,5 +38,5 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -38,5 +38,5 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -45,5 +45,5 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
BR2_PACKAGE_BOOTLOADER_SPLASHSCREEN=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -164,14 +164,15 @@ BR2_TARGET_UBOOT_SPL=y
|
||||
BR2_TARGET_UBOOT_SPL_NAME="spl/u-boot-spl.bin.normal.out"
|
||||
BR2_TARGET_UBOOT_CUSTOM_DTS_PATH="$(BR2_EXTERNAL_INFIX_PATH)/board/riscv64/visionfive2/uboot/visionfive2-env.dtsi"
|
||||
BR2_PACKAGE_HOST_BMAP_TOOLS=y
|
||||
BR2_PACKAGE_HOST_GO_BIN=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
INFIX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
INFIX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://www.kernelkit.org/infix/"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
IX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
IX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
IX_HOME="https://github.com/kernelkit/infix/"
|
||||
IX_DOC="https://www.kernelkit.org/infix/"
|
||||
IX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_FEATURE_GPS=y
|
||||
BR2_PACKAGE_FEATURE_WIFI=y
|
||||
BR2_PACKAGE_FEATURE_WIFI_MEDIATEK=y
|
||||
@@ -194,7 +195,6 @@ BR2_PACKAGE_FIREWALL=y
|
||||
BR2_PACKAGE_IITO=y
|
||||
BR2_PACKAGE_KEYACK=y
|
||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||
BR2_PACKAGE_LANDING=y
|
||||
BR2_PACKAGE_LOWDOWN=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_MDNS_ALIAS=y
|
||||
@@ -206,12 +206,14 @@ BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
# BR2_PACKAGE_LANDING is not set
|
||||
BR2_PACKAGE_WEBUI=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
BR2_PACKAGE_PCIUTILS=y
|
||||
IMAGE_ITB_AUX=y
|
||||
IMAGE_ITB_QCOW=y
|
||||
IMAGE_ITB_RAUC=y
|
||||
IMAGE_README=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_IMAGE_ITB_AUX=y
|
||||
IX_IMAGE_ITB_QCOW=y
|
||||
IX_IMAGE_ITB_RAUC=y
|
||||
IX_IMAGE_README=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -40,5 +40,5 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
BR2_PACKAGE_BOOTLOADER_SPLASHSCREEN=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -34,5 +34,5 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -34,5 +34,5 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
BR2_TARGET_ROOTFS_EXT2=y
|
||||
BR2_TARGET_ROOTFS_EXT2_4=y
|
||||
BR2_TARGET_ROOTFS_EXT2_SIZE="512M"
|
||||
IMAGE_EXT4_RAUC=y
|
||||
IX_IMAGE_EXT4_RAUC=y
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
# Prefer internal download mirror over official upstream sites. If
|
||||
# the mirror is unreachable, e.g., off-site without VPN, Buildroot
|
||||
# falls back to the upstream URL and then sources.buildroot.net
|
||||
# Set up a local mirror and add IP to /etc/hosts to override
|
||||
BR2_PRIMARY_SITE="http://mirror.internal/pub"
|
||||
@@ -26,7 +26,7 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.32"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.39"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -139,11 +139,11 @@ BR2_PACKAGE_HOST_MTOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
INFIX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
INFIX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://www.kernelkit.org/infix/"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
IX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
IX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
IX_HOME="https://github.com/kernelkit/infix/"
|
||||
IX_DOC="https://www.kernelkit.org/infix/"
|
||||
IX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_FEATURE_GPS=y
|
||||
BR2_PACKAGE_FEATURE_WIFI=y
|
||||
BR2_PACKAGE_FEATURE_WIFI_MEDIATEK=y
|
||||
@@ -169,7 +169,6 @@ BR2_PACKAGE_FIREWALL=y
|
||||
BR2_PACKAGE_IITO=y
|
||||
BR2_PACKAGE_KEYACK=y
|
||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||
BR2_PACKAGE_LANDING=y
|
||||
BR2_PACKAGE_LOWDOWN=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_MDNS_ALIAS=y
|
||||
@@ -181,12 +180,14 @@ BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
# BR2_PACKAGE_LANDING is not set
|
||||
BR2_PACKAGE_WEBUI=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
BR2_PACKAGE_PCIUTILS=y
|
||||
IMAGE_ITB_AUX=y
|
||||
IMAGE_ITB_QCOW=y
|
||||
IMAGE_ITB_RAUC=y
|
||||
IMAGE_README=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_IMAGE_ITB_AUX=y
|
||||
IX_IMAGE_ITB_QCOW=y
|
||||
IX_IMAGE_ITB_RAUC=y
|
||||
IX_IMAGE_README=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -26,7 +26,7 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.32"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.18.39"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -118,11 +118,11 @@ BR2_PACKAGE_HOST_MTOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FDT_ADD_PUBKEY=y
|
||||
INFIX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
INFIX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://www.kernelkit.org/infix/"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
IX_VENDOR_HOME="https://www.kernelkit.org"
|
||||
IX_DESC="Infix is an immutable, friendly, and secure operating system that turns any ARM or x86 device into a powerful, manageable network appliance. Deploy on anything from $35 Raspberry Pi boards to enterprise switches as routers, IoT gateways, or edge devices. Infix models Linux networking features using YANG so you can manage your devices using NETCONF/RESTCONF APIs and focus on your business logic running in isolated containers."
|
||||
IX_HOME="https://github.com/kernelkit/infix/"
|
||||
IX_DOC="https://www.kernelkit.org/infix/"
|
||||
IX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_CONFD=y
|
||||
BR2_PACKAGE_NETD=y
|
||||
BR2_PACKAGE_CONFD_TEST_MODE=y
|
||||
@@ -141,15 +141,16 @@ BR2_PACKAGE_FIREWALL=y
|
||||
BR2_PACKAGE_IITO=y
|
||||
BR2_PACKAGE_KEYACK=y
|
||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||
BR2_PACKAGE_LANDING=y
|
||||
BR2_PACKAGE_LOWDOWN=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_MDNS_ALIAS=y
|
||||
BR2_PACKAGE_ONIEPROM=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
IMAGE_ITB_AUX=y
|
||||
IMAGE_ITB_QCOW=y
|
||||
IMAGE_ITB_RAUC=y
|
||||
IMAGE_README=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
IX_IMAGE_ITB_AUX=y
|
||||
IX_IMAGE_ITB_QCOW=y
|
||||
IX_IMAGE_ITB_RAUC=y
|
||||
IX_IMAGE_README=y
|
||||
IX_TRUSTED_KEYS=y
|
||||
IX_TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -3,29 +3,153 @@ Change Log
|
||||
|
||||
All notable changes to the project are documented in this file.
|
||||
|
||||
[v26.05.0][UNRELEASED]
|
||||
[v26.08.0][UNRELEASED]
|
||||
-------------------------
|
||||
|
||||
### Changes
|
||||
|
||||
- Upgrade Linux kernel to 6.18.32 (LTS)
|
||||
- Upgrade FRR to 10.5.4
|
||||
- Add support for [Acer Connect Vero W6m][AcerConnectVero], a COTS home router,
|
||||
based upon the same hardware as [Banana Pi BPI-R3][BPI-R3], but
|
||||
with a Wi-Fi 6E (6 GHz band) chip.
|
||||
- Add configurable channel-width in Wi-Fi configuration.
|
||||
- Upgrade Linux kernel to 6.18.39 (LTS)
|
||||
- Upgrade Buildroot to 2025.02.15 (LTS)
|
||||
- Add support for firewall address-set (ipset): named sets of IP addresses and
|
||||
networks, usable as zone sources for per-IP access control, issue #1189
|
||||
- Build RPi64 SD card images in release builds
|
||||
- Include .pkg files in release builds
|
||||
|
||||
### Fixes
|
||||
|
||||
- Fix #1493: container with a physical interface not properly removed
|
||||
when switching to a configuration without containers
|
||||
- Handle unclean daemon exits better, e.g., `dbus-daemon` crashing and
|
||||
leaving a stale pidfile behind, causing it to refuse to be restarted
|
||||
- Fix annoying "cannot deselect all services" or reset to YANG default in the
|
||||
web interface's firewall configuration page
|
||||
|
||||
[v26.06.0][] - 2026-07-01
|
||||
-------------------------
|
||||
|
||||
> [!NOTE]
|
||||
> Noteworthy changes and additions in this release:
|
||||
>
|
||||
> **🌐 Web Interface:** Infix gets its first-ever web interface! Browse live
|
||||
> status and a full operational tree, handle common tasks from curated
|
||||
> configuration pages, and drop into a YANG tree editor for everything else.
|
||||
> A maintenance section covers firmware upgrade, backup & restore, and more.
|
||||
>
|
||||
> **📶 Wi-Fi Roaming & Mesh:** Access points sharing an SSID can hand clients
|
||||
> off seamlessly with 802.11k/v/r, form a cable-free 802.11s mesh backhaul,
|
||||
> and steer dual-band clients onto the faster 5/6 GHz band.
|
||||
>
|
||||
> **🗓️ System Scheduling:** Reusable time schedules based on ietf-schedule
|
||||
> (RFC 9922) let features like scheduled reboot and software update checks
|
||||
> run on a recurring, cron-style calendar.
|
||||
|
||||
### Changes
|
||||
|
||||
- Upgrade Linux kernel to 6.18.37 (LTS)
|
||||
- Upgrade Buildroot to 2025.02.15 (LTS)
|
||||
- Add basic web interface: static status pages and a tree view of operational
|
||||
status. Curated configuration pages for some common tasks and a YANG tree
|
||||
editor for the rest. Also includes a maintenance section for firmware
|
||||
upgrade, backup & restore, and more
|
||||
- Add Wi-Fi roaming for fast, seamless handoff between access points that
|
||||
share an SSID: 802.11k, 802.11v and 802.11r (over-the-air FT). See the
|
||||
[Wi-Fi][wifi] guide for details
|
||||
- Add Wi-Fi 802.11s mesh support, letting access points form a wireless
|
||||
backhaul between each other without cabling
|
||||
- Add band steering for dual-band access points, nudging dual-band
|
||||
clients onto the faster 5/6 GHz band
|
||||
- Add `legacy-rates` option to re-enable 802.11b rates on 2.4 GHz for
|
||||
old IoT devices (disabled by default)
|
||||
- Add system scheduling based on ietf-schedule (RFC 9922), using the
|
||||
iCalendar recurrence grouping pruned to cron-expressible rules. Schedules
|
||||
are reusable time-specs; features (`scheduled-reboot`,
|
||||
`software/check-update`) trigger off them via a schedule reference
|
||||
- Configuring multiple BSS (more than one SSID) on a single Wi-Fi radio now
|
||||
requires an explicitly configured MAC address per BSS
|
||||
- New operational `advertised-pmd-types` leaf-list on each Ethernet interface,
|
||||
exposing the link modes currently advertised, to compare against the
|
||||
`supported-pmd-types` introduced in v26.05.0
|
||||
- Release assets no longer ship separate `.sha256` checksum files; the
|
||||
download page now publishes a SHA-256 checksum for each asset directly
|
||||
|
||||
### Fixes
|
||||
|
||||
- Fix #941: a VETH pair can now connect two containers directly, with both
|
||||
ends assigned to containers.
|
||||
- Enabling IP masquerading in the firewall no longer enables IP forwarding on
|
||||
all interfaces. This has been an issue ever since the firewall support was
|
||||
introduced in v25.10.0
|
||||
- Fix file permission regression in `/cfg/startup-config.cfg`, causing the
|
||||
default `admin` user no permission to read or write the file from shell
|
||||
- Fix admin url shown for HTTP/HTTPS links in <https://network.local> browser,
|
||||
used pre-conflict resolution hostname.local, instead of hostname-2.local
|
||||
- Fix unreadable per-port temperature sensor names in `show hardware` on
|
||||
Marvell based switches: each sensor is now named after the front-panel port
|
||||
it serves (e.g. `e1`, `e2`) instead of a raw device-tree path. `show
|
||||
system` also reports a representative SoC temperature on CN913x platforms
|
||||
- Fix missing `contact` and `location` settings in operational status; the
|
||||
values were configurable but never returned on RESTCONF/NETCONF reads
|
||||
- Fix spurious YANG validation warnings, for NTP and WireGuard configuration,
|
||||
emitted on every NETCONF session and schema load
|
||||
|
||||
[wifi]: https://www.kernelkit.org/infix/latest/wifi/
|
||||
|
||||
[v26.05.0][] - 2026-05-29
|
||||
-------------------------
|
||||
|
||||
### Changes
|
||||
|
||||
- Upgrade Linux kernel to 6.18.33 (LTS)
|
||||
- Upgrade Buildroot to 2025.02.14 (LTS)
|
||||
- Upgrade FRR to 10.5.4
|
||||
- Add support for [Acer Connect Vero W6m][AcerConnectVero], a low-cost COTS
|
||||
home router, based on the same hardware as [Banana Pi BPI-R3][BPI-R3], but
|
||||
with a Wi-Fi 6E (6 GHz band) chip.
|
||||
- Add configurable channel-width in Wi-Fi configuration.
|
||||
- Upgrade `ieee802-ethernet-interface` YANG model to revision 2025-09-10 (IEEE
|
||||
Std 802.3.2-2025), adding the standard `phy-type` and `pmd-type` operational
|
||||
leaves. Speed is now exposed via `ietf-interfaces:speed` (bps, RFC 8343);
|
||||
the now obsolete `eth:speed` is no longer returned
|
||||
- Rework `show interface` summary output as layered protocol rows. When a
|
||||
port has link, a physical-medium row (e.g. `1000baseT`, `10GbaseLR`) appears
|
||||
above the `ethernet` row. VLAN, GRE, VXLAN and WiFi interfaces likewise get
|
||||
one row per protocol layer, with type-specific data on each (`vid:`,
|
||||
`remote:`, `vni:`, `station ssid:`, etc.), issue #530
|
||||
- Add support for configurable auto-negotiation for Ethernet ports. A new
|
||||
`advertised-pmd-types` leaf-list replaces the fixed speed idiom for pinned
|
||||
link modes, issue #805. See the [Ethernet Interfaces][ethernet] section in
|
||||
the User Guide for details. Existing configurations using fixed speed are
|
||||
migrated automatically on upgrade
|
||||
- Add support for configurable MDI/MDI-X pinout on Ethernet ports. Needed on
|
||||
some PHYs where Auto-MDIX stops working once auto-negotiation is disabled
|
||||
- New operational `supported-pmd-types` leaf-list on each Ethernet interface,
|
||||
exposing the set of PMD types currently supported
|
||||
- New CLI command `show operational`, and optional XPath filtering for this
|
||||
and any of the other datastores, using `[path /path/to/subtree]`
|
||||
- CLI `show` commands now surface human-friendly error messages instead of a
|
||||
raw Python exceptions, e.g., `Interface "w" not found`
|
||||
|
||||
### Fixes
|
||||
|
||||
- Fix #1493: container with a physical interface not properly removed when
|
||||
switching to a configuration without containers
|
||||
- Fix #1506: add documentation on how to configure VLAN interfaces, including
|
||||
stacked (Q-in-Q) VLAN interfaces, in a dedicated `vlan.md`
|
||||
- Handle unclean daemon exits better, e.g., `dbus-daemon` crashing and leaving
|
||||
a stale pidfile behind, causing it to refuse to be restarted
|
||||
- Fix occasional blank or garbled `[ OK ]` lines at startup
|
||||
- Disallow multicast MAC addresses in custom MAC address configuration
|
||||
- Fix broken Wi-Fi 6 GHz band configuration.
|
||||
- Fix operational read of `/containers` failing and thereby aborting all
|
||||
operational get-data, including RESTCONF/NETCONF reads — for containers
|
||||
whose command contains shell metacharacters, e.g. `sh -c "... && ..."`
|
||||
- WireGuard interfaces are now regenerated when a referenced keystore key
|
||||
changes: the asymmetric `private-key`, and the symmetric `preshared-key` at
|
||||
both peer-group and per-peer level
|
||||
- Fix crash in operational data when a bridge has VLAN ranges configured: the
|
||||
kernel may report ranges (e.g. `vlan 1 vlanEnd 3`) from `bridge vlan global
|
||||
show`, which were not expanded, so `show interface` and other operational
|
||||
reads failed. Ranges are now expanded and listed correctly
|
||||
|
||||
[AcerConnectVero]: ../board/aarch64/acer-connect-vero-w6m/
|
||||
[ethernet]: https://www.kernelkit.org/infix/latest/ethernet/#restricting-advertised-link-modes
|
||||
[BPI-R3]: https://docs.banana-pi.org/en/BPI-R3/BananaPi_BPI-R3
|
||||
[AcerConnectVero]: https://github.com/kernelkit/infix/tree/main/board/aarch64/acer-connect-vero-w6m
|
||||
|
||||
[v26.04.0][] - 2026-04-30
|
||||
-------------------------
|
||||
@@ -72,7 +196,6 @@ All notable changes to the project are documented in this file.
|
||||
- Fix [BPI-R3][] PCIe devices failing to initialize on boot due to a missing
|
||||
clock definition in the device tree
|
||||
|
||||
[BPI-R3]: https://wiki.banana-pi.org/Banana_Pi_BPI-R3
|
||||
[BPI-R4]: https://docs.banana-pi.org/en/BPI-R4/BananaPi_BPI-R4
|
||||
[ESPRESSObin]: https://espressobin.net/
|
||||
[SAMA7G54]: https://www.microchip.com/en-us/development-tool/ev21h18a
|
||||
@@ -176,7 +299,7 @@ All notable changes to the project are documented in this file.
|
||||
|
||||
- Fix CLI `copy` command problem to copy to scp/sftp destinations
|
||||
|
||||
[BPI-R3-MINI]: https://wiki.banana-pi.org/Banana_Pi_BPI-R3_Mini
|
||||
[BPI-R3-MINI]: https://docs.banana-pi.org/en/BPI-R3_Mini/BananaPi_BPI-R3_Mini
|
||||
[SAMA7G54-EK]: https://www.microchip.com/en-us/development-tool/ev21h18a
|
||||
|
||||
[v26.01.0][] - 2026-02-03
|
||||
@@ -2099,7 +2222,11 @@ Supported YANG models in addition to those used by sysrepo and netopeer:
|
||||
- N/A
|
||||
|
||||
[buildroot]: https://buildroot.org/
|
||||
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v26.03.0...HEAD
|
||||
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v26.06.0...HEAD
|
||||
[v26.08.0]: https://github.com/kernelkit/infix/compare/v26.06.0...v26.08.0
|
||||
[v26.06.0]: https://github.com/kernelkit/infix/compare/v26.05.0...v26.06.0
|
||||
[v26.05.0]: https://github.com/kernelkit/infix/compare/v26.04.0...v26.05.0
|
||||
[v26.04.0]: https://github.com/kernelkit/infix/compare/v26.03.0...v26.04.0
|
||||
[v26.03.0]: https://github.com/kernelkit/infix/compare/v26.02.0...v26.03.0
|
||||
[v26.02.0]: https://github.com/kernelkit/infix/compare/v26.01.0...v26.02.0
|
||||
[v26.01.0]: https://github.com/kernelkit/infix/compare/v25.11.0...v26.01.0
|
||||
|
||||
@@ -21,6 +21,7 @@ regression test system solely relies on NETCONF and RESTCONF.
|
||||
- [Introduction](introduction.md)
|
||||
- [System Configuration](system.md)
|
||||
- [Network Configuration](networking.md)
|
||||
- [Wi-Fi](wifi.md)
|
||||
- [DHCP Server](dhcp.md)
|
||||
- [Syslog Support](syslog.md)
|
||||
- **Infix In-Depth**
|
||||
|
||||
@@ -28,7 +28,7 @@ Verify the result after a build by inspecting:
|
||||
|
||||
> [!IMPORTANT]
|
||||
> To get a proper GIT revision (hash) from your OS spin, remember to set
|
||||
> in menuconfig `INFIX_OEM_PATH`. When unset, the Infix `post-build.sh`
|
||||
> in menuconfig `IX_OEM_PATH`. When unset, the Infix `post-build.sh`
|
||||
> script defaults to the Infix base path. The revision is stored in the
|
||||
> file `/etc/os-release` as `BUILD_ID`, also in the file `/etc/version`.
|
||||
> See below for more info.
|
||||
@@ -427,7 +427,7 @@ Used for `BUILD_ID` in `/etc/os-release`.
|
||||
**Default:** `$(git describe --always --dirty --tags)`, from the _top
|
||||
directory_. By default, the top directory refers to the root of the
|
||||
Infix source tree, but this can be changed by setting the branding
|
||||
variable `INFIX_OEM_PATH`, e.g. in a `defconfig` file or via `make
|
||||
variable `IX_OEM_PATH`, e.g. in a `defconfig` file or via `make
|
||||
menuconfig`, to the path of an enclosing br2-external.
|
||||
|
||||
#### `INFIX_RELEASE`
|
||||
|
||||
@@ -73,8 +73,8 @@ admin@example:/config/interface/br0/> <b>set bridge vlans vlan 20 tagged br0</b>
|
||||
</code></pre>
|
||||
|
||||
To route or to manage via a VLAN, a VLAN interface needs to be created
|
||||
on top of the bridge, see section [VLAN Interfaces](ethernet.md#vlan-interfaces)
|
||||
for more on this topic.
|
||||
on top of the bridge, see section [VLAN Interfaces](vlan.md) for more
|
||||
on this topic.
|
||||
|
||||
> [!NOTE]
|
||||
> In some use-cases only a single management VLAN on the bridge is used.
|
||||
|
||||
@@ -164,7 +164,7 @@ interfaces {
|
||||
}
|
||||
}
|
||||
admin@host-12-34-56:/config/interface/eth0/> leave
|
||||
admin@host-12-34-56:/> show interfaces
|
||||
admin@host-12-34-56:/> show interface
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
lo loopback UNKNOWN 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
|
||||
@@ -668,11 +668,9 @@ set:
|
||||
|
||||
For an example of both, see the next section.
|
||||
|
||||
> [!IMPORTANT]
|
||||
> **VETH Pair Limitation:** When using VETH pairs with containers, at least
|
||||
> one side of the pair must remain in the host namespace. It is currently
|
||||
> not possible to create VETH pairs where both ends are assigned to different
|
||||
> containers. One end must always be accessible from the host.
|
||||
> [!TIP]
|
||||
> Both ends of a VETH pair may be assigned to containers, connecting two
|
||||
> containers directly without involving the host namespace.
|
||||
|
||||
[^3]: Something which the container bridge network type does behind the
|
||||
scenes with one end of an automatically created VETH pair.
|
||||
|
||||
@@ -122,13 +122,21 @@ recommend using `pipx` to install the necessary tooling:
|
||||
```bash
|
||||
$ sudo apt install pipx
|
||||
$ pipx install mkdocs
|
||||
$ pipx inject mkdocs mkdocs-material pymdown-extensions mkdocs-callouts mike mkdocs-to-pdf
|
||||
$ pipx inject mkdocs mkdocs-material pymdown-extensions mkdocs-callouts mike mkdocs-to-pdf mkdocs-glightbox
|
||||
```
|
||||
|
||||
The last two packages, `mike` and `mkdocs-to-pdf`, are used for online
|
||||
versioning and PDF generation by GitHub Actions, but since they are in
|
||||
the `mkdocs.yml` file, everyone who wants to preview the documentation
|
||||
have to install all the tooling.
|
||||
The `mike` and `mkdocs-to-pdf` packages are used for online versioning
|
||||
and PDF generation by GitHub Actions, but since every plugin is listed
|
||||
in `mkdocs.yml`, anyone who wants to preview the documentation has to
|
||||
install all the tooling.
|
||||
|
||||
> [!IMPORTANT]
|
||||
> MkDocs is also required to **build a WebUI image**. The build bundles
|
||||
> the User's Guide into the image (served on-device at `/guide/`), so
|
||||
> `make` runs `mkdocs build` from `post-build.sh` when the `webui`
|
||||
> package is selected. If MkDocs is missing the build still succeeds,
|
||||
> but the image ships without the on-device guide. Minimal images and
|
||||
> any build without the `webui` package skip this step entirely.
|
||||
|
||||
Preview with:
|
||||
|
||||
@@ -182,6 +190,9 @@ To apply a single snippet to the current output directory:
|
||||
make apply-ext4 # build an ext4 rootfs (needed for boards
|
||||
# whose bootloader lacks squashfs support,
|
||||
# e.g. Marvell ESPRESSObin)
|
||||
make apply-mirror # prefer an internal download mirror
|
||||
# (BR2_PRIMARY_SITE) over upstream sites,
|
||||
# see utils/mirror-sync.sh for populating it
|
||||
|
||||
The `apply-*` targets require an existing `.config` (i.e. you must have
|
||||
already run a `make <board>_defconfig`). The snippet is merged using
|
||||
|
||||
@@ -109,11 +109,11 @@ When configuring, e.g., `dns-server`, or `router` options with the value
|
||||
`auto`, the system uses the IP address from the interface matching the
|
||||
subnet. For example:
|
||||
|
||||
<pre class="cli"><code>admin@example:/> <b>show interfaces</b>
|
||||
<span class="header">INTERFACE PROTOCOL STATE DATA </span>
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
<pre class="cli"><code>admin@example:/> <b>show interface</b>
|
||||
<span class="header">INTERFACE PROTOCOL STATE DATA </span>
|
||||
eth0 ethernet UP 02:00:00:00:00:00
|
||||
ipv4 192.168.1.1/24 (static)
|
||||
eth1 ethernet UP 02:00:00:00:00:01
|
||||
eth1 ethernet UP 02:00:00:00:00:01
|
||||
ipv4 192.168.2.1/24 (static)
|
||||
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/> <b>edit option dns-server</b>
|
||||
|
||||
@@ -1,52 +1,8 @@
|
||||
# Ethernet Interfaces
|
||||
|
||||
This document covers VLAN interfaces, physical Ethernet interfaces,
|
||||
and virtual Ethernet (VETH) pairs.
|
||||
|
||||
|
||||
## VLAN Interfaces
|
||||
|
||||
Creating a VLAN can be done in many ways. This section assumes VLAN
|
||||
interfaces created atop another Linux interface. E.g., the VLAN
|
||||
interfaces created on top of the Ethernet interface or bridge in the
|
||||
picture below.
|
||||
|
||||

|
||||
|
||||
A VLAN interface is basically a filtering abstraction. When you run
|
||||
`tcpdump` on a VLAN interface you will only see the frames matching the
|
||||
VLAN ID of the interface, compared to *all* the VLAN IDs if you run
|
||||
`tcpdump` on the lower-layer interface.
|
||||
|
||||
<pre class="cli"><code>admin@example:/> <b>configure</b>
|
||||
admin@example:/config/> <b>edit interface eth0.20</b>
|
||||
admin@example:/config/interface/eth0.20/> <b>show</b>
|
||||
type vlan;
|
||||
vlan {
|
||||
tag-type c-vlan;
|
||||
id 20;
|
||||
lower-layer-if eth0;
|
||||
}
|
||||
admin@example:/config/interface/eth0.20/> <b>leave</b>
|
||||
</code></pre>
|
||||
|
||||
The example below assumes bridge br0 is already created, see [VLAN
|
||||
Filtering Bridge](bridging.md#vlan-filtering-bridge).
|
||||
|
||||
<pre class="cli"><code>admin@example:/> <b>configure</b>
|
||||
admin@example:/config/> <b>edit interface vlan10</b>
|
||||
admin@example:/config/interface/vlan10/> <b>set vlan id 10</b>
|
||||
admin@example:/config/interface/vlan10/> <b>set vlan lower-layer-if br0</b>
|
||||
admin@example:/config/interface/vlan10/> <b>leave</b>
|
||||
</code></pre>
|
||||
|
||||
As conventions, a VLAN interface for VID 20 on top of an Ethernet
|
||||
interface *eth0* is named *eth0.20*, and a VLAN interface for VID 10 on
|
||||
top of a bridge interface *br0* is named *vlan10*.
|
||||
|
||||
> [!NOTE]
|
||||
> If you name your VLAN interface `foo0.N` or `vlanN`, where `N` is a
|
||||
> number, the CLI infers the interface type automatically.
|
||||
This document covers physical Ethernet interfaces and virtual Ethernet
|
||||
(VETH) pairs. For VLAN interfaces stacked on top of an Ethernet port
|
||||
or bridge, see [VLAN Interfaces](vlan.md).
|
||||
|
||||
|
||||
## Physical Ethernet Interfaces
|
||||
@@ -56,111 +12,219 @@ top of a bridge interface *br0* is named *vlan10*.
|
||||
Physical Ethernet interfaces provide low-level settings for speed/duplex as
|
||||
well as packet status and [statistics](#ethernet-statistics).
|
||||
|
||||
By default, Ethernet interfaces defaults to auto-negotiating
|
||||
speed/duplex modes, advertising all speed and duplex modes available.
|
||||
In the example below, the switch would by default auto-negotiate speed
|
||||
1 Gbit/s on port eth1 and 100 Mbit/s on port eth4, as those are the
|
||||
highest speeds supported by H1 and H2 respectively.
|
||||
By default, Ethernet interfaces defaults to auto-negotiating speed/duplex
|
||||
modes, advertising all speed and duplex modes available. In the example
|
||||
below, the switch would by default auto-negotiate speed 1 Gbps on port eth1
|
||||
and 100 Mbps on port eth4, as those are the highest speeds supported by H1 and
|
||||
H2 respectively.
|
||||
|
||||

|
||||
|
||||
The speed and duplex status for the links can be listed as shown
|
||||
below, assuming the link operational status is 'up'.
|
||||
A quick at-a-glance view of the physical link is available in the summary
|
||||
listing. When a port is up, a physical-layer row appears above the ethernet
|
||||
row, naming the IEEE PMD type (e.g. `1000baseT`, `10GbaseLR`) in the PROTOCOL
|
||||
column and the negotiated duplex in DATA. When the link is down the row is
|
||||
omitted and the interface name falls onto the ethernet row.
|
||||
|
||||
<pre class="cli"><code>admin@example:/> <b>show interface</b>
|
||||
<span class="header">INTERFACE PROTOCOL STATE DATA </span>
|
||||
eth1 1000baseT UP duplex: full
|
||||
ethernet 00:53:00:06:11:01
|
||||
eth2 1000baseT UP duplex: full
|
||||
ethernet 00:53:00:06:11:02
|
||||
eth3 ethernet DOWN 00:53:00:06:11:03
|
||||
eth4 100baseTX UP duplex: full
|
||||
ethernet 00:53:00:06:11:04
|
||||
...
|
||||
</code></pre>
|
||||
|
||||
The detail view spells everything out, including auto-negotiation
|
||||
state and the speed in Mbit/s.
|
||||
|
||||
<pre class="cli"><code>admin@example:/> <b>show interface eth1</b>
|
||||
name : eth1
|
||||
index : 2
|
||||
mtu : 1500
|
||||
operational status : up
|
||||
auto-negotiation : on
|
||||
duplex : full
|
||||
speed : 1000
|
||||
physical address : 00:53:00:06:11:01
|
||||
ipv4 addresses :
|
||||
ipv6 addresses :
|
||||
in-octets : 75581
|
||||
out-octets : 43130
|
||||
name : eth1
|
||||
index : 2
|
||||
mtu : 1500
|
||||
operational status : up
|
||||
link mode : 1000baseT
|
||||
auto-negotiation : on
|
||||
duplex : full
|
||||
speed : 1000
|
||||
physical address : 00:53:00:06:11:01
|
||||
ipv4 addresses :
|
||||
ipv6 addresses :
|
||||
in-octets : 75581
|
||||
out-octets : 43130
|
||||
...
|
||||
admin@example:/> <b>show interface eth4</b>
|
||||
name : eth4
|
||||
index : 5
|
||||
mtu : 1500
|
||||
operational status : up
|
||||
auto-negotiation : on
|
||||
duplex : full
|
||||
speed : 100
|
||||
physical address : 00:53:00:06:11:04
|
||||
ipv4 addresses :
|
||||
ipv6 addresses :
|
||||
in-octets : 75439
|
||||
out-octets : 550704
|
||||
name : eth4
|
||||
index : 5
|
||||
mtu : 1500
|
||||
operational status : up
|
||||
link mode : 100baseTX
|
||||
auto-negotiation : on
|
||||
duplex : full
|
||||
speed : 100
|
||||
physical address : 00:53:00:06:11:04
|
||||
ipv4 addresses :
|
||||
ipv6 addresses :
|
||||
in-octets : 75439
|
||||
out-octets : 550704
|
||||
...
|
||||
admin@example:/>
|
||||
</code></pre>
|
||||
|
||||
### Configuring fixed speed and duplex
|
||||
### Restricting advertised link modes
|
||||
|
||||
Auto-negotiation of speed/duplex mode is desired in almost all
|
||||
use-cases, but it is possible to disable auto-negotiation and specify
|
||||
a fixed speed and duplex mode.
|
||||
Auto-negotiation is the right default for almost all links, but sometimes a
|
||||
port has to come up at a fixed speed, usually when talking to old hardware
|
||||
that won't auto-negotiate or does it badly. IEEE Std 802.3.2-2025 dropped
|
||||
the old "turn off auto-negotiation, then set a fixed speed and duplex"
|
||||
approach. Instead you restrict the set of PMD types the port may advertise:
|
||||
list a single PMD and the link pins to that mode against any peer that
|
||||
supports it.
|
||||
|
||||
> [!IMPORTANT]
|
||||
> When setting a fixed speed and duplex mode, ensure both sides of the
|
||||
> link have matching configuration. If speed does not match, the link
|
||||
> will not come up. If duplex mode does not match, the result is
|
||||
> reported collisions and/or bad throughput.
|
||||
> [!NOTE]
|
||||
> Earlier Infix releases needed `enable false` plus explicit `speed` and
|
||||
> `duplex` leaves. IEEE Std 802.3.2-2025 retired the `eth:speed` leaf, so
|
||||
> the speed now comes from the `advertised-pmd-types` entry instead.
|
||||
> Existing `startup-config.cfg` files are migrated automatically on upgrade.
|
||||
|
||||
The example below configures port eth3 to fixed speed 100 Mbit/s
|
||||
half-duplex mode.
|
||||
Each entry in `auto-negotiation/advertised-pmd-types` is an IEEE PMD-type
|
||||
identity (`ieee802-ethernet-phy-type:pmd-type-*`). The separate `duplex`
|
||||
leaf controls half vs full duplex.
|
||||
|
||||
The example below pins port `eth3` to 100 Mbit/s half-duplex.
|
||||
|
||||
<pre class="cli"><code>admin@example:/> <b>configure</b>
|
||||
admin@example:/config/> <b>edit interface eth3 ethernet</b>
|
||||
admin@example:/config/interface/eth3/ethernet/> <b>set speed 0.1</b>
|
||||
admin@example:/config/interface/eth3/ethernet/> <b>set auto-negotiation advertised-pmd-types pmd-type-100BASE-TX</b>
|
||||
admin@example:/config/interface/eth3/ethernet/> <b>set duplex half</b>
|
||||
admin@example:/config/interface/eth3/ethernet/> <b>set auto-negotiation enable false</b>
|
||||
admin@example:/config/interface/eth3/ethernet/> <b>show</b>
|
||||
auto-negotiation {
|
||||
enable false;
|
||||
advertised-pmd-types [ ieee802-ethernet-phy-type:pmd-type-100BASE-TX ];
|
||||
}
|
||||
duplex half;
|
||||
speed 0.1;
|
||||
admin@example:/config/interface/eth3/ethernet/> <b>leave</b>
|
||||
admin@example:/>
|
||||
</code></pre>
|
||||
|
||||
Speed metric is in Gbit/s. Auto-negotiation needs to be disabled in
|
||||
order for fixed speed/duplex to apply. Only speeds `0.1`(100 Mbit/s)
|
||||
and `0.01` (10 Mbit/s) can be specified. 1 Gbit/s and higher speeds
|
||||
require auto-negotiation to be enabled.
|
||||
List several PMDs to advertise all of them; auto-negotiation then settles
|
||||
on the highest mode both ends support.
|
||||
|
||||
> [!IMPORTANT]
|
||||
> When pinning a link mode, make sure both ends share at least one common
|
||||
> (PMD, duplex) combination, otherwise the link will not come up.
|
||||
|
||||
#### Duplex and advertised modes
|
||||
|
||||
A PMD type like `10BASE-T` or `100BASE-TX` says nothing about duplex on its
|
||||
own, but the kernel tracks half and full duplex as separate link modes.
|
||||
Infix advertises both variants of every PMD you list, then narrows to one
|
||||
duplex when the `duplex` leaf is set:
|
||||
|
||||
| `advertised-pmd-types` | `duplex` | Resulting advertised modes |
|
||||
|----------------------------|----------|------------------------------------------|
|
||||
| `[10BASE-T]` | _unset_ | `10baseT/Half` + `10baseT/Full` |
|
||||
| `[10BASE-T]` | `full` | `10baseT/Full` |
|
||||
| `[10BASE-T]` | `half` | `10baseT/Half` |
|
||||
| `[10BASE-T, 100BASE-TX]` | _unset_ | all four half/full combinations |
|
||||
| `[10BASE-T, 100BASE-TX]` | `full` | `10baseT/Full` + `100baseT/Full` |
|
||||
| _unset_ | _unset_ | every mode the PHY supports (default) |
|
||||
|
||||
So `duplex` filters the PMDs you listed. PMDs with no half-duplex variant
|
||||
(everything above 1 Gbps) only ever advertise full.
|
||||
|
||||
#### Disabling auto-negotiation
|
||||
|
||||
The method above keeps auto-negotiation on and only limits what it
|
||||
advertises, so the peer still negotiates as usual. That doesn't help with
|
||||
gear that won't negotiate at all, like some old switches or a back-to-back
|
||||
copper link. For those, set `auto-negotiation/enable false` together with a
|
||||
single `advertised-pmd-types` entry to force a fixed speed and duplex with
|
||||
negotiation off:
|
||||
|
||||
<pre class="cli"><code>admin@example:/config/interface/eth3/ethernet/> <b>set auto-negotiation enable false</b>
|
||||
admin@example:/config/interface/eth3/ethernet/> <b>set auto-negotiation advertised-pmd-types pmd-type-100BASE-TX</b>
|
||||
admin@example:/config/interface/eth3/ethernet/> <b>set duplex full</b>
|
||||
</code></pre>
|
||||
|
||||
With `enable false` you must list exactly one PMD: it sets the speed, and
|
||||
the `duplex` leaf sets half or full. Leave `duplex` out and Infix uses
|
||||
whatever the PMD supports, normally full.
|
||||
|
||||
Auto-MDIX usually rides along with auto-negotiation, so turning negotiation
|
||||
off can leave both ends picking the same MDI/MDI-X pinout. The link then
|
||||
comes up electrically but carries no traffic. When that happens, force
|
||||
opposite pinouts with the `mdi-x` leaf — set one end true (MDI-X) and the
|
||||
other false (MDI):
|
||||
|
||||
<pre class="cli"><code>admin@example:/config/interface/eth3/ethernet/> <b>set mdi-x false</b>
|
||||
</code></pre>
|
||||
|
||||
Leaving `mdi-x` unset keeps Auto-MDIX in charge, which is correct whenever
|
||||
auto-negotiation is on.
|
||||
|
||||
> [!NOTE]
|
||||
> Whether `enable false` reaches the external PHY depends on the driver.
|
||||
> Direct-attach NICs handle it directly. Switch user ports go through the
|
||||
> switch driver, and some accept the request at the MAC but leave the PHY
|
||||
> auto-negotiating: the kernel reports the configured speed while the wire
|
||||
> runs at whatever was negotiated, and traffic stalls. If that happens,
|
||||
> read the PHY's BMCR register (e.g. with `mdio` from `mdiotools`) to see
|
||||
> what the PHY is actually doing.
|
||||
|
||||
The detail view exposes a `supported` block (operational state,
|
||||
backed by the `supported-pmd-types` leaf-list) listing the PMD types
|
||||
the kernel currently believes the interface can operate at. For
|
||||
SFP/SFP+ cages this set reflects the inserted module: plug in a 10G
|
||||
LR optic and `supported` will narrow to `10GbaseLR` only. Combined
|
||||
with the operational `link mode` row above it, this makes it trivial
|
||||
to confirm what an unknown transceiver actually is — no `ethtool -m`
|
||||
round-trip needed.
|
||||
|
||||
<pre class="cli"><code>admin@example:/> <b>show interface eth13</b>
|
||||
name : eth13
|
||||
type : ethernet
|
||||
operational status : up
|
||||
link mode : 10GbaseLR
|
||||
auto-negotiation : off
|
||||
supported : 10GbaseLR
|
||||
duplex : full
|
||||
speed : 10000
|
||||
...
|
||||
</code></pre>
|
||||
|
||||
### Ethernet statistics
|
||||
|
||||
Ethernet packet statistics[^1] can be listed as shown below.
|
||||
|
||||
<pre class="cli"><code>admin@example:/> <b>show interface eth1</b>
|
||||
name : eth1
|
||||
index : 2
|
||||
mtu : 1500
|
||||
operational status : up
|
||||
auto-negotiation : on
|
||||
duplex : full
|
||||
speed : 1000
|
||||
physical address : 00:53:00:06:11:0a
|
||||
ipv4 addresses :
|
||||
ipv6 addresses :
|
||||
in-octets : 75581
|
||||
out-octets : 43130
|
||||
|
||||
eth-in-frames : 434
|
||||
eth-in-multicast-frames : 296
|
||||
eth-in-broadcast-frames : 138
|
||||
eth-in-error-fcs-frames : 0
|
||||
eth-in-error-oversize-frames : 0
|
||||
eth-out-frames : 310
|
||||
eth-out-multicast-frames : 310
|
||||
eth-out-broadcast-frames : 0
|
||||
eth-out-good-octets : 76821
|
||||
eth-in-good-octets : 60598
|
||||
name : eth1
|
||||
index : 2
|
||||
mtu : 1500
|
||||
operational status : up
|
||||
link mode : 1000baseT
|
||||
auto-negotiation : on
|
||||
duplex : full
|
||||
speed : 1000
|
||||
physical address : 00:53:00:06:11:0a
|
||||
ipv4 addresses :
|
||||
ipv6 addresses :
|
||||
in-octets : 75581
|
||||
out-octets : 43130
|
||||
───────────────────
|
||||
<b>Ethernet Statistics</b>
|
||||
in-frames : 434
|
||||
in-multicast-frames : 296
|
||||
in-broadcast-frames : 138
|
||||
in-error-fcs-frames : 0
|
||||
in-error-oversize-frames : 0
|
||||
out-frames : 310
|
||||
out-multicast-frames : 310
|
||||
out-broadcast-frames : 0
|
||||
out-good-octets : 76821
|
||||
in-good-octets : 60598
|
||||
admin@example:/>
|
||||
</code></pre>
|
||||
|
||||
|
||||
@@ -1,3 +1,90 @@
|
||||
/* Chirpy-style typography (must precede all other rules).
|
||||
* Source Sans Pro was renamed "Source Sans 3" on Google Fonts; it is the
|
||||
* same typeface. Lato is used for headings, matching www.kernelkit.org. */
|
||||
@import url('https://fonts.googleapis.com/css2?family=Lato:wght@400;700;900&family=Source+Sans+3:ital,wght@0,400;0,600;0,700;1,400&display=swap');
|
||||
|
||||
/* ---- Fonts ---------------------------------------------------------------
|
||||
* theme.font is disabled in mkdocs.yml, so we set Material's font vars here.
|
||||
* Body: Source Sans 3, code: system monospace (same stack Chirpy uses). */
|
||||
:root {
|
||||
--md-text-font: "Source Sans 3";
|
||||
--md-code-font: SFMono-Regular, Menlo, Monaco, Consolas, "Liberation Mono", "Courier New";
|
||||
}
|
||||
|
||||
body {
|
||||
-webkit-font-smoothing: antialiased;
|
||||
-moz-osx-font-smoothing: grayscale;
|
||||
}
|
||||
|
||||
/* Lato for all headings and the masthead site title. */
|
||||
.md-typeset h1,
|
||||
.md-typeset h2,
|
||||
.md-typeset h3,
|
||||
.md-typeset h4,
|
||||
.md-typeset h5,
|
||||
.md-typeset h6,
|
||||
.md-header__title,
|
||||
.md-nav__title {
|
||||
font-family: "Lato", "Microsoft Yahei", sans-serif;
|
||||
}
|
||||
|
||||
/* ---- Light mode (Chirpy "default" palette) ------------------------------- */
|
||||
[data-md-color-scheme="default"] {
|
||||
--md-typeset-color: #34343c;
|
||||
--md-typeset-a-color: #0056b2; /* Chirpy blue links */
|
||||
--md-accent-fg-color: #0056b2; /* link hover / active TOC */
|
||||
--md-code-bg-color: #f6f8fa;
|
||||
--md-code-fg-color: #3a3a3a;
|
||||
}
|
||||
|
||||
[data-md-color-scheme="default"] .md-typeset h1,
|
||||
[data-md-color-scheme="default"] .md-typeset h2,
|
||||
[data-md-color-scheme="default"] .md-typeset h3,
|
||||
[data-md-color-scheme="default"] .md-typeset h4,
|
||||
[data-md-color-scheme="default"] .md-typeset h5,
|
||||
[data-md-color-scheme="default"] .md-typeset h6 {
|
||||
color: #2a2a2a;
|
||||
}
|
||||
|
||||
/* Subtle tinted sidebars (left nav + right TOC), as on the blog. */
|
||||
[data-md-color-scheme="default"] .md-sidebar {
|
||||
background-color: #f6f8fa;
|
||||
}
|
||||
|
||||
/* ---- Dark mode (Chirpy "dark" palette over Material's slate) ------------- */
|
||||
[data-md-color-scheme="slate"] {
|
||||
--md-default-bg-color: rgb(27 27 30); /* neutral near-black */
|
||||
--md-default-fg-color: rgb(207 208 209); /* UI text */
|
||||
--md-default-fg-color--light: rgb(175 176 177);
|
||||
--md-default-fg-color--lighter: rgb(175 176 177 / 45%);
|
||||
--md-default-fg-color--lightest: rgb(175 176 177 / 18%);
|
||||
--md-typeset-color: rgb(175 176 177); /* body text */
|
||||
--md-code-bg-color: #151515;
|
||||
--md-code-fg-color: #b0b0b0;
|
||||
--md-typeset-a-color: rgb(138 180 248); /* Chirpy blue links */
|
||||
--md-accent-fg-color: rgb(168 199 250); /* brighter blue on hover */
|
||||
}
|
||||
|
||||
[data-md-color-scheme="slate"] .md-typeset h1,
|
||||
[data-md-color-scheme="slate"] .md-typeset h2,
|
||||
[data-md-color-scheme="slate"] .md-typeset h3,
|
||||
[data-md-color-scheme="slate"] .md-typeset h4,
|
||||
[data-md-color-scheme="slate"] .md-typeset h5,
|
||||
[data-md-color-scheme="slate"] .md-typeset h6 {
|
||||
color: #cccccc;
|
||||
}
|
||||
|
||||
/* Sidebars slightly lighter than the main background, as on the blog. */
|
||||
[data-md-color-scheme="slate"] .md-sidebar {
|
||||
background-color: #1e1e1e;
|
||||
}
|
||||
|
||||
/* Inline code reads as a faint highlight rather than a dark block. */
|
||||
[data-md-color-scheme="slate"] .md-typeset :not(pre) > code {
|
||||
background-color: rgb(255 255 255 / 6%);
|
||||
}
|
||||
|
||||
/* ---- Existing project styling -------------------------------------------- */
|
||||
.md-header__title {
|
||||
font-size: 1.1rem;
|
||||
line-height: 2.6rem;
|
||||
|
||||
@@ -223,6 +223,96 @@ The firewall includes over 100 pre-defined services, such as:
|
||||
> See the YANG model for the full list, or tap the ++question++ key
|
||||
> when setting up an allowed host service in a zone `set service`
|
||||
|
||||
## Address Sets
|
||||
|
||||
Address sets are named collections of IP addresses and networks that can be
|
||||
used as zone *sources*, alongside the `network` setting. Traffic from a
|
||||
member of the set is classified into that zone regardless of which interface
|
||||
it arrives on. Since source matching takes precedence over interface
|
||||
matching, an address set in a trusted zone can selectively lift devices out
|
||||
of a restrictive interface zone.
|
||||
|
||||
This enables per-IP access control: block everything by default and grant
|
||||
individual end devices access at runtime.
|
||||
|
||||
> [!IMPORTANT]
|
||||
> Assigning an address set to a zone only decides which zone the source IP
|
||||
> belongs to. It does **not** by itself grant access to the device. Access
|
||||
> to HOST services is still controlled by the zone's `action` and `service`
|
||||
> settings. A common pattern is to keep the interface or default zone
|
||||
> restrictive (`reject`/`drop`) and attach the address set to a separate
|
||||
> trusted zone with `action accept`, as shown below.
|
||||
|
||||
<pre class="cli"><code>admin@example:/> <b>configure</b>
|
||||
admin@example:/config/> <b>edit firewall address-set allowed</b>
|
||||
admin@example:/config/firewall/…/allowed/> <b>set description "End devices granted access"</b>
|
||||
admin@example:/config/firewall/…/allowed/> <b>set entry 192.168.1.40</b>
|
||||
admin@example:/config/firewall/…/allowed/> <b>end</b>
|
||||
admin@example:/config/firewall/> <b>edit zone trusted</b>
|
||||
admin@example:/config/firewall/…/trusted/> <b>set action accept</b>
|
||||
admin@example:/config/firewall/…/trusted/> <b>set address-set allowed</b>
|
||||
admin@example:/config/firewall/…/trusted/> <b>leave</b>
|
||||
</code></pre>
|
||||
|
||||
### Static and Dynamic Entries
|
||||
|
||||
Entries come in two kinds:
|
||||
|
||||
- **Static** entries are set in the configuration, like `192.168.1.40`
|
||||
above, and are restored at boot
|
||||
- **Dynamic** entries are added and removed at runtime using the `add`,
|
||||
`remove`, and `flush` actions. They take effect immediately and survive
|
||||
firewall configuration changes, but are *not* saved to the configuration,
|
||||
so a reboot starts from a clean slate
|
||||
|
||||
From admin-exec context in the CLI:
|
||||
|
||||
<pre class="cli"><code>admin@example:/> <b>firewall address-set allowed add 192.168.1.42</b>
|
||||
admin@example:/> <b>show firewall address-set allowed</b>
|
||||
name : allowed
|
||||
family : ipv4
|
||||
timeout : none
|
||||
|
||||
ENTRY TYPE EXPIRES
|
||||
192.168.1.40 static
|
||||
192.168.1.42 dynamic
|
||||
admin@example:/> <b>firewall address-set allowed remove 192.168.1.42</b>
|
||||
</code></pre>
|
||||
|
||||
The same actions are available over NETCONF and RESTCONF, e.g., allowing a
|
||||
device from a network management system:
|
||||
|
||||
```json
|
||||
~$ curl -kX POST -u admin:admin -H "Content-Type: application/yang-data+json" \
|
||||
-d '{"infix-firewall:input": {"entry": "192.168.1.42"}}' \
|
||||
https://example.local/restconf/data/infix-firewall:firewall/address-set=allowed/add
|
||||
```
|
||||
|
||||
Static entries can only be removed by changing the configuration, the
|
||||
`remove` action manages dynamic entries only. The `flush` action removes
|
||||
all dynamic entries at once, leaving static entries in place.
|
||||
|
||||
### Expiring Entries
|
||||
|
||||
An address set can be created with a `timeout`, giving every dynamic entry a
|
||||
limited lifetime. Such sets are dynamic-only: static entries cannot be
|
||||
configured, and entries cannot be removed manually, they expire on their
|
||||
own. This suits time-limited access grants and automated ban lists.
|
||||
|
||||
<pre class="cli"><code>admin@example:/config/firewall/> <b>edit address-set banned</b>
|
||||
admin@example:/config/firewall/…/banned/> <b>set timeout 3600</b>
|
||||
admin@example:/config/firewall/…/banned/> <b>leave</b>
|
||||
admin@example:/> <b>firewall address-set banned add 203.0.113.99</b>
|
||||
</code></pre>
|
||||
|
||||
The remaining lifetime of each entry is shown in the `EXPIRES` column of
|
||||
<kbd>show firewall address-set</kbd>.
|
||||
|
||||
> [!NOTE]
|
||||
> Entries in timeout sets do not survive firewall configuration changes,
|
||||
> the set is flushed when the firewall configuration is rebuilt. Regular
|
||||
> (non-timeout) sets keep their dynamic entries over configuration changes.
|
||||
|
||||
## Examples
|
||||
|
||||
### End Device Protection
|
||||
|
||||
@@ -61,13 +61,19 @@ admin@example:/config/interface/eth0/> <b>leave</b>
|
||||
The operational status can be inspected to see both administrative and
|
||||
actual link state:
|
||||
|
||||
<pre class="cli"><code>admin@example:/> <b>show interfaces</b>
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
eth0 ethernet <b>DISABLED</b> 02:00:00:00:00:00
|
||||
eth1 ethernet UP 02:00:00:00:00:01
|
||||
<pre class="cli"><code>admin@example:/> <b>show interface</b>
|
||||
<span class="header">INTERFACE PROTOCOL STATE DATA </span>
|
||||
eth0 ethernet <b>DISABLED</b> 02:00:00:00:00:00
|
||||
eth1 1000baseT UP duplex: full
|
||||
ethernet 02:00:00:00:00:01
|
||||
...
|
||||
</code></pre>
|
||||
|
||||
The rows are layered bottom-up by protocol: a physical-medium row (only
|
||||
emitted when the link is up) on top, then the ethernet row carrying the
|
||||
bare MAC, then any ipv4/ipv6 sub-rows. See [Ethernet](ethernet.md) for the
|
||||
full set of summary fields.
|
||||
|
||||
|
||||
## Description
|
||||
|
||||
@@ -84,9 +90,9 @@ The description is visible in the operational datastore and in `show`
|
||||
commands:
|
||||
|
||||
<pre class="cli"><code>admin@example:/> <b>show interface eth0</b>
|
||||
name : eth0
|
||||
description : Uplink to core switch
|
||||
index : 2
|
||||
name : eth0
|
||||
description : Uplink to core switch
|
||||
index : 2
|
||||
...
|
||||
</code></pre>
|
||||
|
||||
|
||||
|
Before Width: | Height: | Size: 4.6 KiB After Width: | Height: | Size: 4.6 KiB |
|
Before Width: | Height: | Size: 11 KiB After Width: | Height: | Size: 11 KiB |
|
After Width: | Height: | Size: 107 KiB |
|
After Width: | Height: | Size: 12 KiB |
|
After Width: | Height: | Size: 71 KiB |
|
After Width: | Height: | Size: 15 KiB |