Compare commits

..
222 Commits
Author SHA1 Message Date
Tobias Waldekranz 769b7c2ba1 package/skeleton-init-finit: Run the getty in runlevel 9
Normally, no logins are actually possible, but this will have two
desirable effects effects:

- /etc/issue will be printed when hitting return over the console,
allowing the user to see the bootstrapping errors again, without
having to reboot the system.

- On devleoper builds, with CONFIG_TARGET_ENABLE_ROOT_LOGIN, we can
login as root and debug issues.
2023-11-30 11:39:42 +01:00
Tobias Waldekranz f4a604f63c Prevent non-essential services from running in runlevels > 6
In case failure-config fails to load, we park the system in runlevel
9. In this state, we only want the most essential services running.
2023-11-30 11:39:42 +01:00
Tobias Waldekranz 445fbf7873 confd: Notify user of all bootstrapping issues via login banners
Collect all bootstrapping issues in all banner-like files during boot,
so that they are presented to the user when logging in. This should
make it harder to miss overlook the fact that a system is running in a
degraded state.
2023-11-30 11:39:42 +01:00
Tobias Waldekranz af2b1f95a9 confd: Only move to runlevel 9 if failure-config fails to load
Before this change, the system would move to runlevel 9 as soon as
startup-config failed to load, in which no getty is allowed to run.

Instead, we want to reserve that runlevel for when failure-config
itself also fails to load, since the system will have no valid login
credentials at that point.
2023-11-30 11:39:42 +01:00
Joachim Wiberg f0c99b14dd src/confd: add support for routes set by ZeroConf agent
This fixes [ERR] from CLI `show routes`, and broken operational status
in setups with DHCP client enabled by default.

Feature (static routing) introduced in release cycle, no need to bring
up in release notes.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-30 11:03:16 +01:00
Joachim Wiberg 2428bf9a2c Update ChangeLog for v23.11.0-rc2
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-30 08:04:40 +01:00
Joachim Wiberg 14be582578 .github: ensure the leading 'v' in version is retained
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-30 08:02:39 +01:00
Tobias WaldekranzandJoachim Wiberg 10ece4378b confd: Don't cache libyang module references
As it turns out, references to module objects are not safe to keep
across callbacks. In particular: loading a new model into sysrepo at
runtime may cause it to move objects around in memory.

Therefore, fetch a valid reference to "infix-system" on every callback
instead.
2023-11-29 23:52:37 +01:00
Tobias WaldekranzandMattias Walström c5ba2971e6 test/docker: Add tshark
Needed by new sniffer implementation.
2023-11-29 16:57:48 +01:00
Tobias WaldekranzandMattias Walström 5f299ee151 test/infamy: Generalize wait functionality into "until" 2023-11-29 16:57:48 +01:00
Mattias Walström f7e9c44516 Fix problems when running test on real hardware not qemu
* sniffer did not work correctly
* links did not come upp as quick as in qemu
* must_reach in netns was to narrow, increase timeout
* add wait function to handle poll
2023-11-29 16:57:48 +01:00
Tobias WaldekranzandJoachim Wiberg bf5de743c6 test/docker: Add jq to docker
Needed by upcoming unit tests.
2023-11-29 11:28:14 +01:00
Joachim WibergandTobias Waldekranz 5ed5cca982 package/confd: install avahi _netconf-ssh._tcp service record
Currently we only advertise SSH+SFTP services over mDNS-SD, which are
the default services from the avahi package.  This patch adds support
for _netconf-ssh._tcp as well.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-29 07:34:05 +01:00
Joachim Wiberg 19977a9b32 cli-pretty: fix fallback version and datetime for show software
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-28 15:30:59 +01:00
Joachim Wiberg 18c698fe14 doc: spelling, ordering, and missing markdown link fixes
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-28 14:31:17 +01:00
Joachim Wiberg 481638a343 .github: check for true second level heading as release separator
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-28 14:16:49 +01:00
Joachim Wiberg 67a57ef52e doc: indent table, confuses release action
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-28 14:15:08 +01:00
Joachim Wiberg f61e8e4699 doc: update ChangeLog for v23.11.0-rc1
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-28 13:30:09 +01:00
Joachim Wiberg 0ff5b94ec6 klish-plugin-infix: rename command 'erase' -> 'remove' file
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-28 11:15:32 +01:00
Joachim Wiberg 09032dc4bb klish-plugin-infix: extend copy command with curl
Allow copy from/to with either datastore, file (in /cfg), or curl.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-28 11:15:32 +01:00
Joachim Wiberg 8f68a35b7b klish-plugin-infix: minor, rename type portar -> ifaces
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-28 11:15:32 +01:00
Joachim WibergandGitHub ada60bd705 src/klish-plugin-infix: fix 'show version' command 2023-11-28 09:43:10 +01:00
Tobias WaldekranzandJoachim Wiberg 985c2fd600 board/aarch64: alder: Disable EEE
Empirical studies shows that the surge protection on the alder board
is not compatible with Energy Efficient Ethernet.

Root cause has not yet been determined.
2023-11-27 16:54:46 +01:00
Henrik NordstromandJoachim Wiberg e26ff791eb Bump greenpak-programmer to v1.2
adds verification of programmed NVMEM / EEPROM
2023-11-27 14:11:06 +01:00
Joachim Wiberg f6c5685da8 doc: update changelog for v23.11-rc1
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-27 14:05:56 +01:00
Joachim Wiberg 64aa3b544c package/klish-plugin-sysrepo: fix regression in release cycle
Fix regression in line-drawing characters, introduced in c38c8a4.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-27 14:04:45 +01:00
Tobias Waldekranz e0144ef9a3 board/aarch64: alder: Swap LED colors on 1G ports
On the P2's the only reasonable way (in terms of hardware patching
effort) of driving the LEDs is to have the green LEDs at the top and
the yellow ones at the bottom.
2023-11-27 12:31:58 +01:00
Tobias Waldekranz cf31a2642d board/aarch64: alder: Wire up IRQ to power board GPIOs
Turns out that the gpio-charger doesn't have polled fallback if the
GPIO pin can't function as an interrupt controller.

Fortunately, we have access to the IRQ pin, so we can just use that
for now and leave the driver as-is.
2023-11-27 12:31:58 +01:00
Tobias Waldekranz 1281edbee6 board/aarch64: alder: Swap VIN1/2 to match hardware 2023-11-27 12:31:58 +01:00
Joachim Wiberg 9415c0fb64 src/confd: drop /interfaces/interface/eth:ethernet config deviation
Drop this deviation for v23.11 since it clashes with pyang + NETCONFc client.
We expect to support configuration of speed+duplex in v23.12.

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-27 10:03:03 +01:00
Joachim Wiberg f679ed7191 Update documentation, interfaces interface foo -> interface foo
With the latest bump of klish-plugin-sysrepo we no longer need the extra
container name in commands and paths.

Also, update the "show interfaces" example in the top-level README.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-27 10:03:03 +01:00
Joachim Wiberg e73e9d75e1 package/klish-plugin-sysrepo: bump for container-list collapse
This adds support for collapsing container-lists where applicable.
E.g., 'edit interfaces interface eth0' -> 'edit interface eth0'.

Great care has been taken to not mess up when container-lists are
critical, like ipv4/ipv6 routes.

Fix #187

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-27 10:03:03 +01:00
Joachim Wiberg 2365ab273a klish-plugin-infix: minor, help help text
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-27 10:03:03 +01:00
Mattias WalströmandJoachim Wiberg 35aa7a37e1 Documentation for routing support 2023-11-27 10:03:03 +01:00
Tobias WaldekranzandJoachim Wiberg e1db5bad78 rauc: Start after D-Bus
On occasion, rauc has problems registering with D-Bus. Ensure that the
D-Bus daemon is running before starting rauc.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg be728accbb rauc: Remove unsupported argument from finit service stanza
Fixes: 0f410eb ("rauc: add support for tftp:// for bundles and syslog for logging")
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg 2da2e7fd5e confd: Fix failure-config generation when password is missing
Setting admin's password to "!" is not accepted by the model, which
means we end up in RMA mode, even in cases when a valid startup
exists.

Not supplying a password will cause confd to generate a locked
account, which is what we want.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg e53fd91c7f common: probe: Support default passwords on devicetree based systems
In addition to QEMU, we can now source the factory default password
from real VPD EEPROMs, on systems that use a devicetree.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg 17d1a529e8 common: qemu: Run without VPD by default
Infix will fallback to admin/admin on a QEMU system.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg 0a746a9795 common: qemu: Only create VPD if it does not exist
This let's you create a custom one to test out different scenarios
without it being clobbered by qemu.sh.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg b7cc0935ac common: qemu: Simplify VPD generation
Also, remove the "VBD" terminology. We will only emulate a single VPD
anyway.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg b5ba1602ec common: onieprom: Don't read more data than needed when decoding TLV
There's little point in reading a 32kB EEPROM do decode a 100B
TLV. Instead figure out how much we need to read from the header.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg 7679c4137e board/aarch64: alder: Tag VPD memories with board information
This is needed to make informed decisions about which hardware is
available, and what trust level it has.
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg 42d4079c06 board/aarch64: alder: Remove old definition of DDR_TEN MPP
Fixes: b7aa560 ("board/aarch64: alder: Remap SFP9_RX_LOS and DDR_TEN MPPs")
2023-11-25 20:37:15 +01:00
Tobias WaldekranzandJoachim Wiberg cb0f8739ad kernel: Import latest kkit-linux-6.5.y
- Fixes the locking warnings when configuring LEDs on 6393X
- Correctly power up 3310X PHYs strapped to start powered down
- Fix kernel oops when reading from blank NVMEM configured with an
  ONIE layout
2023-11-25 20:37:15 +01:00
Joachim Wiberg 6c6ae844f3 board/netconf: allow default metric 0 for kernel + dhcp routes
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 14:29:56 +01:00
Joachim Wiberg 9655f98903 Fix #222: operational status b0rks on unknown route proto
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 14:29:16 +01:00
Joachim Wiberg 2be779718e Fix #221: set MFD_NOEXEC_SEAL flag on memfd
Silence kernel warning seems to be most secure option.  Also, set
MFD_CLOEXEC, because if we ever fork off a child it should never
get a copy of this fd.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 13:42:54 +01:00
Joachim Wiberg 748996dad8 Replace firmware with Linux OS, operating system, or software
We should avoid the use of the ambigous word 'firmware'.

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg b544778cfe doc: update CLI tutorial with a software upgrade section
Also, refresh the list of available commands.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg 56c3b4a880 doc: minor updates to the CLI online help text
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg 630a005bef cli: add 'show software' command
New command 'show software' to display software versions on each
partition, install date, and which one is currently booted.

admin@infix-00-00-00:/> show software
NAME      STATE     VERSION                DATE
primary   booted    v23.10.0-132           2023-11-23T22:24:33+00:00
secondary inactive  v23.10.0-132           2023-11-23T22:24:33+00:00

admin@infix-00-00-00:/> show software name primary
Name      : primary
State     : booted
Version   : v23.10.0-132-gfd6e8ea
Size      : 61992960
SHA-256   : ed6146aec462b77fb8631b14c48d281dd0f4fdb9c062f9482d863ee854081358
Installed : 2023-11-23T22:24:33+00:00

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg 23e4ca3f48 cli-pretty: whitespace fixup only
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg df76b4820f klish-plugin-infix: add 'upgrade' command to install software updates
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg 938c8aa8c5 klish-plugin-infix: update terse help text for basic commands
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim Wiberg 0f410eb3b2 rauc: add support for tftp:// for bundles and syslog for logging
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 12:35:46 +01:00
Joachim WibergandTobias Waldekranz c55d38df9a Use Kernelkit's IANA Enterprise Number
[skip ci]

Co-authored-by: Tobias Waldekranz <tobias@waldekranz.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg 9b1739283d confd: missing admin password, set error in /etc/issue & /etc/banner
The bootstrap script gets feedback from gen-admin-auth, on error we no
longer bail out but instead log the error and continue booting.  This
way a developer build with root login can diagnose the error.

When logging the error we also set /etc/issue, /etc/issue.net for local
and remote login services, as well as the dedicated /etc/banner used by
OpenSSH, to hold the error summary.  So when attaching to the console
port, or attempting to log in remotely with SSH, the error is printed
to indicate the device is not healthy.

Finally, since factory-config may be missing we need to bootstrap the
sysrepo db with something else, and fortunately we will always have a
failure-config to fall back on.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg f53f985dbc confd: do not fail if pwhash is missing in VPD, instead lock account
If pwhash is missing from system.json, lock account.  This allows for
more extensive diagnosis on developer builds with a root login.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg 8141cc13d1 confd: minor shellcheck fixes
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg fdaface79f probe: use fallback password hash also for qeneth (regression tests)
Break fallback hash to a separate function and allow gen_qemu_system_file()
to return the status.  We'd like to update the qeneth templates to include
the same VPD data as is used with qemu.sh, but for now this is sufficient.

The Qemu detection has been changed to the, slightly more, secure detection
of qemu_fw_cfg filesystem.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Joachim Wiberg ff12ba72b5 confd: exctract password also for failure-config
This patch adds generation of the 20-authentication.json snippet also
for failure-config.  The gen-admin-auth script is extended with shell
parameter, since the default shell differs from factory-config.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-24 08:55:57 +01:00
Richard AlpeandJoachim Wiberg 63a34d570d Use default pwd hash from VPD in QEMU
This commit does several things. Its end goal is to fetch the admin
password hash from VPD memory during factory bootstrap.

To accomplish this probe creates a new file /run/system.json with
information read from a fw_cfg QEMU partition. The data from
/run/system.json is then later used during config bootstrap to fill in
the factory administrator password.

The idea is to make QEMU behave the same way hardware does, i.e. a
default/factory password should be fetched and used from
"hardware memory". The hardware portion of this is yet to be done.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-24 08:55:57 +01:00
Richard AlpeandJoachim Wiberg 17093eba22 confd: disable admin login in failure config
Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-24 08:55:57 +01:00
Tobias Waldekranz 1e9cd310f8 board/common: Add self-provisioning scripts
This let's you netboot a system with a blank block device, and setup
all partitions, filesystems, images etc.
2023-11-23 12:18:28 +01:00
Tobias Waldekranz 252b894d55 rauc: Source service arguments from /etc/default, if available
This is need by upcoming provisioning scripts.
2023-11-23 12:18:28 +01:00
Tobias Waldekranz 98b9ca99cd defconfig: Build tools needed to self-provision Infix
Upcoming changes will add scripts to provision Infix to a blank block
device, which need these tools.
2023-11-23 12:18:28 +01:00
Tobias Waldekranz f258e030bd confd: Fix shellcheck warnings in gen-interfaces 2023-11-23 12:18:28 +01:00
Tobias Waldekranz 7f049db21f confd: Remove -6 option from gen-interfaces
With the behavior introduced in the referenced commit, port
interfaces (i.e. all ports on many systems) no longer get any SLAAC
address, leaving the user with no way of reaching the system.

Comment says this is by design, but that seems like an awkward
default.

Remove the option, and simplify gen_interfaces to either
- Enable SLAAC, if the port is not going to be part of any bridge, or
- Disabel SLAAC, if the port is going to be part of a bridge

If necessary, we can add an inverse option at a later date.

Fixes: d0f3960 ("confd: add -6 option to gen-interfaces for SLACC on port interfaces")
2023-11-23 12:18:28 +01:00
Tobias Waldekranz b7aa56071d board/aarch64: alder: Remap SFP9_RX_LOS and DDR_TEN MPPs
Layout changed from P1 to P2 becasue DDR_TEN must be connected to an
MPP with an internal pull-down, which MPP24 (old SFP9_RX_LOS) has.
2023-11-23 12:18:28 +01:00
Mattias Walström a0a80c8b77 Rename infix-routing to correct date
Should be 2023 not 2013.
2023-11-23 10:30:26 +01:00
Mattias Walström 37f7b5ba92 Add support for reading routing operational data for IPv4
In the CLI:
admin@infix-00-00-00:/> show routes
PREFIX                        DESTINATION                   PROTOCOL  METRIC
1.1.1.0/24                    e0                            kernel
192.168.100.0/24              1.1.1.1                       static    20
192.168.110.2/32              blackhole                     static    20
192.168.120.2/32              blackhole                     static    20
192.168.130.2/32              unreachable                   static    20
2023-11-23 10:30:26 +01:00
Jon-Olov VatnandJoachim Wiberg 6cfcf3ca10 Fixing and activating ieee802-ethernet yang deviations 2023-11-22 13:44:28 +01:00
Jon-Olov VatnandJoachim Wiberg 6669fee728 Draft infix deviations for ieee802-ethernet-interfaces
- Add deviations for non-supported statistics
- Limit config, currently we only have ro support
- Add deviations for non-supported configs and status leafs

[skip ci]
2023-11-22 13:44:28 +01:00
Joachim Wiberg 4bcac85e69 doc: helpful note to devs about re-enabling the root user for debug
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-22 12:04:05 +01:00
Joachim Wiberg 4c6d868627 Fix #215: impossible to enable NTP client
Regression introduced in ac0b0d5.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-21 19:24:05 +01:00
Joachim Wiberg c38c8a46ce package/klish: simplify, drop confusing comments
Also, change socket file path from /tmp to /run, as is customary.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-21 08:06:06 +01:00
Joachim Wiberg b6b03e4903 package/klish: simplify, maintain local version of klish.conf
Also, add -S option to less, which causes lines longer than the screen
width to be chopped (truncated) rather than wrapped.  With available
terminals supporting xterm a user can scroll right on really long lines.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-21 08:06:06 +01:00
Joachim Wiberg 69d0c16e30 src/klish-plugin-infix: show JSON of running-config
The default srp_show@sysrepo function creates the stripped down version
of running-config that, in the context of showing startup-config or the
factory-config, is very difficult to explain to users why they differ in
format.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-21 08:06:06 +01:00
Joachim Wiberg 30641cb243 package/klish: fix loss of Ctrl-C to abort current line edit
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-21 08:06:06 +01:00
Joachim Wiberg f32e2faf11 board/netconf: wrap klish in a fuzzy warm blanket
Having klish as the login shell means losing lots of neat features we've
gotten used to: help text in less pager, initial terminal probing on the
console, and more.

This commit replaces the clish -> klish symlnk with a fuzzy bash wrapper
that fixes all the above annoying little things.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-21 08:06:06 +01:00
Tobias WaldekranzandJoachim Wiberg 7e7d25d82e board/common: mnt: Remove old clixon remnants 2023-11-21 08:05:02 +01:00
Tobias WaldekranzandJoachim Wiberg 0a51b5e8e9 board/common: mnt: Be slightly less inconsistent with quoting 2023-11-21 08:05:02 +01:00
Tobias WaldekranzandJoachim Wiberg 2bfc524546 board/common: mnt: Correctly reset /var as part of a factory-reset
Before this change, the following would happen in /lib/infix/mnt if a
factory-reset was performed:

1. Copy the contents of /var from Squash into /mnt/var and bind mount
   /mnt/var over /var
2. Check for factory-reset
3. Clear /mnt/cfg/* and /mnt/var/*
4. Mount overlays

This ordering leaves the system with a completely empty /var on the
boot when a factory-reset is executed. Finit will fixup some of this
via its tmpfiles scripts, but we want the ability to ship files under
/var as part of the Squash and have these be available after the bind
mount, just like what happens at every other boot, when we don't
perform a factory-reset.

We solve this by delaying the bind mount (1) until after the reset has
been performed, together with all the overlays (4). While we're here,
make the fallback case, where no persistent /var is available, use a
bind mount as well. This should allow containers to be tested on such
setups, and it's one less flavor to test.

New order:

1. Check for factory-reset
2. Clear /mnt/cfg/* and /mnt/var/*
3. Mount overlays
4. Copy the contents of /var from Squash into /mnt/var and bind mount
   /mnt/var over /var

Now the only difference between a regular boot and a
"factory-reset-boot" is whether (2) executed or not.
2023-11-21 08:05:02 +01:00
Joachim Wiberg 5db84ddec6 Jack's hard-earned badges
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg ac63461bd8 confd: fix copy-paste error in dns-resolver
Found by Coverity Scan, CID 331048

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 123808d6bb confd: check return value of mktime()
Found by Coverity Scan, CID 331032

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg b2331dc8ce confd: minor, coding style
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 31bd1286a3 confd: minor, whitespace
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg da6b5a1950 confd: mark unchecked remove()/rename() as intentional
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 1b825d4ac6 confd: fix memory leak in handle_sr_shell_update()
Found by Coverity Scan, CID 331029

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 90af510092 confd: fix memory leak in handle_sr_passwd_update()
Found by Coverity Scan, CID 331033

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg c3045ecebb confd: fix obvious mistakes in checking return values
Found by Coverty Scan

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg f56baeb4fa confd: drop malplaced sr_free_values()
We haven't even called sr_get_items() yet.  Must've been a remnant
of an earlier refactor.

Fixes CID 331051

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Joachim Wiberg 2191202f2a statd: null terminate recv() buffer from netlink
Fixes CID 331053

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-20 13:34:19 +01:00
Tobias WaldekranzandJoachim Wiberg a4d02630c9 board/netconf: Define standard behavior for port LEDs
By default, assume that any LED with the function "tp", "sfp" or
"port" is attached to either an Ethernet PHY or MAC, with support for
offloading the "netdev" trigger.

Use green LEDs to indicate link/activity.

Disable any yellow LEDs for now, later on we can add alarm indications
etc. to these.
2023-11-19 08:50:19 +01:00
Tobias WaldekranzandJoachim Wiberg 6ce7f01d64 package/iito: Bump to 1.1.0
Needed to fix a memory leak, and to get access to the new "led-group"
driver.
2023-11-19 08:50:19 +01:00
Tobias WaldekranzandJoachim Wiberg 365ad5d565 board/aarch64: alder: Add LED setup for 1G ports 2023-11-19 08:50:19 +01:00
Tobias WaldekranzandJoachim Wiberg c4f8dadde0 board/aarch64: alder: Add LED setup for 10G ports 2023-11-19 08:50:19 +01:00
Tobias WaldekranzandJoachim Wiberg 405aa6510d kernel: Enable netdev LED trigger
This trigger can be offloaded into hardware by the PHY or MAC LED
attached to the netdev in question.
2023-11-19 08:50:19 +01:00
Tobias WaldekranzandJoachim Wiberg febb998702 kernel: Bump to 6.5.11 + kkit-linux-6.5.y
6.5.11: Pull latest fixes from stable tree

kkit-linux-6.5.y: LED support for 88X3310 PHY and 88E6393X switch.
2023-11-19 08:50:19 +01:00
Tobias WaldekranzandJoachim Wiberg 55afbb2a94 board/netconf: Only use iitod on netconf builds
None of the panic/failure/startup conditions make any sense on classic
builds where confd is not running.
2023-11-19 08:50:19 +01:00
Joachim Wiberg 072c3c6394 configs: enable our LED daemon iito in default builds
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-18 16:13:56 +01:00
Joachim Wiberg aceafb7555 package/iito: fix copy-paste error from confd.mk
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-18 16:13:27 +01:00
Joachim Wiberg 0810163528 configs: add missing iproute2 package, regression in 5031ff6
When dropping the net package in 5031ff6, a rebuild + test was not made
before pusing to main.  As a result Infix suddenly lost one of its most
important packages, iproute2.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-18 16:02:19 +01:00
Joachim Wiberg cc6232bf38 package/iito: relocate Finit conf and add tmpfiles.d for /run/led
Relocate Finit conf to package, like klish and confd.  Add condition to
ensure it is not started before mdev/udevd are up and kernel LED modules
have been loaded properly.

Also, add tmpfiles.conf to ensure /run/led is recreated at every boot.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-18 14:49:56 +01:00
Joachim Wiberg 2caf729ee8 github: enable building local src in host mode for analysis
Install libyang and sysrepo from source, too old packages in ubuntu-latest.

[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 18:04:18 +01:00
Joachim Wiberg 005eb58958 src: add support for host build check, for Coverity Scan
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 12:59:39 +01:00
Joachim Wiberg ff69fcfa69 libsrx: make autogen.sh executable
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 10:40:18 +01:00
Joachim Wiberg 41a14d3ca6 statd: refactor Makefile for host build
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 10:40:18 +01:00
Joachim Wiberg c529f06cf0 statd: fix gcc warning, "format not a string literal"
error: format not a string literal and no format arguments [-Werror=format-security]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 10:40:17 +01:00
Joachim Wiberg 04046437d7 confd: fix gcc warnings, "format not a string literal"
error: format not a string literal and no format arguments [-Werror=format-security]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 10:40:17 +01:00
Joachim Wiberg f7d1a72511 confd: tell automake about generated files for cleaning
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 10:40:17 +01:00
Joachim Wiberg 5031ff6224 net: drop unused 'net' package, replaced by dagger
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-17 09:49:32 +01:00
Mattias WalströmandJoachim Wiberg 1fd98758ba frr: add specific configuraion file
The new default behaviour is one gigantic file (frr.conf)
2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg 2bcc9dbb3a vlan_ping: add some negative test
Test that it works when removing interfaces.
2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg 171824c570 Add more memory to qemu devices
Since we now have FRR, there is not much memory left.
2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg ef740a8abc test: routing/static_routing: Sleep some to wait FRR startup
This should be replaced with reading the operational status.
2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg e6de267e29 Update qnenth submodule
Make the ports for the console at the qemu instances deterministic
2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg 10b4b761c5 Routing: Limit to one instance per routing protocol 2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg 85386382e3 Add FRR do defconfig 2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg 4ea1a682da Add test-case for a static routing 2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg a4cb66b642 infix-routing needs to be imported before infix-interfaces
Due to that infix-routing has a deviated node that depends on
a deviated node in infix-interfaces.
2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg 4768cae603 Expose ports 9000-9050 for console connections outside docker 2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg 0b1bd9e8a0 Implement IPv4 static routing in ietf-routing
Only config no operational state yet.

routing
  routing/control-plane-protocols
     control-plane-protocol static name default
        static-routes
          ipv4 route 192.168.200.0/24 next-hop special-next-hop blackhole
2023-11-17 07:19:28 +01:00
Mattias WalströmandJoachim Wiberg 03dbb409eb static-routing: Add model for ipv4/ipv6 routing 2023-11-17 07:19:28 +01:00
Henrik NordstromandJoachim Wiberg b36568bcb7 board/aarch64: alder: Watchdog support 2023-11-16 19:51:52 +01:00
Joachim Wiberg e7c6f255fd .clang-format: drop green goblin alignment
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-16 10:35:43 +01:00
Joachim Wiberg e26208afeb confd: reindent with new .clang-format (example)
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-16 10:35:43 +01:00
Joachim Wiberg 36175f599e Some use-package help for Emacs users
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-16 10:35:43 +01:00
Joachim Wiberg 715d17f475 statd: minor, cleanup, license headers
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-16 10:35:43 +01:00
Joachim Wiberg 485e4256a3 confd: minor, whitespace
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-16 10:35:43 +01:00
Joachim Wiberg 8af048462d src: proposed coding style for C, Linux++
The intention of this is to serve as a help/guidance for both devs and
reviewers of pull requests.

Baseline is taken from Linux v6.5.6, with some (possibly) controversial
additions (at the end of the file):

 - Do not enforce max line length
 - Alignment of variables, both when assigning and declaring
 - Use spaces to adjust when leading tabs are not enough (as Emacs)

I've also added a couple of exceptions for macros like TAILQ_FOREACH()
which are used as control statments (if, while, for), so the opening
brace should be on the same line -- otherwise clang-format thinkts we
are creating a recursive function ...

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-16 10:35:43 +01:00
Joachim Wiberg c867c8bd15 .github: initial workflow for Coverity Scan
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-16 10:06:23 +01:00
Joachim Wiberg 0de25f9c19 patches/netsnmp: add pid readiness signaling for Finit
This patch adds PID readiness notification to Net-SNMP.  This is
required for synchronizing processes like subagents.

PID readiness is similar to systemd READY=1 notification, which
Finit supports, but Net-SNMP only supports that at first startup
not after SIGHUP.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-15 15:09:14 +01:00
Richard AlpeandJoachim Wiberg d6928b933c statd: add speed to op data store and cli
Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-15 15:08:40 +01:00
Richard AlpeandJoachim Wiberg 9ccb6bfd2d statd: add duplex to op data store and cli
Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-15 15:08:40 +01:00
Richard AlpeandRichard Alpe 090a852644 statd: rewrite "backend" in python3
There should be no functional change in this patch.

In this patch we rewrite the data collection in python3. This is the
new script called "yanger". It runs various commands on the system,
such as "ip" and "ethtool". It then mangles the output data from these
commands into valid YANG data.

The yanger script is started from the sysrepo callback in the statd c
code. Its output is parsed using lyd_parse_data_fd().

This means that the daemon part of statd is still written in c and the
new python code is only used when getting a query callback from
sysrepo. The c code still handles the interface netlink messages from
the kernel which controls what interfaces statd should do sysrepo
subscribe/unsubscribe to.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-15 14:35:17 +01:00
Richard AlpeandRichard Alpe 9f4e12f8f5 libsrx: expose fsystemv()
Expose fsystemv() in header and remove static. This function can be
useful for others that needs to be in control of any output stream.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-15 14:35:17 +01:00
Richard AlpeandRichard Alpe f2919a2e44 cli: handle missing type and phys-address gracefully
Avoid crashing if they are missing from the input data.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-15 14:35:17 +01:00
Tobias WaldekranzandJoachim Wiberg de5b0061a8 common: Define standard LED behavior
Provide a set of standard rules for commonly available LEDs.
2023-11-14 16:41:03 +01:00
Tobias WaldekranzandJoachim Wiberg 2b7119b332 iito: Add package
Used to control LEDs based on system state.
2023-11-14 16:41:03 +01:00
Tobias WaldekranzandJoachim Wiberg 6d655d3f5e board/aarch64: alder: Add power supply status support
Add a gpio-charger for each input and wire up the alert LEDs to
trigger when their respective supply goes offline.
2023-11-14 16:41:03 +01:00
Tobias WaldekranzandJoachim Wiberg 2a9e87ea75 board/aarch64: alder: Update LED mapping
Also, blink the red boot LED during the kernel boot phase.
2023-11-14 16:41:03 +01:00
Tobias WaldekranzandJoachim Wiberg e454c4a8b6 board/aarch64: alder: Add power board related drivers
- I2C GPIO expanders, mainly used for LED control and power-good
  inputs

- LED blink support
2023-11-14 16:41:03 +01:00
Tobias WaldekranzandJoachim Wiberg 436f597aba board/aarch64: alder: Explicitly set USB role
This silences warnings from the kernel about implicitly selecting host
mode.
2023-11-14 16:41:03 +01:00
Tobias WaldekranzandJoachim Wiberg 9feed50d08 common: onieprom: Encode/decode ONIE EEPROMs from/to JSON 2023-11-14 16:41:03 +01:00
Joachim Wiberg c1fd4506e6 test: validate defconfigs, ensure root login is disabled
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-14 10:20:00 +01:00
Joachim Wiberg b4eb4508e4 configs: disable root login in NETCONF builds
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-14 10:20:00 +01:00
Ahmed KaricandJoachim Wiberg b43e4ce008 doc: added instructions for package override using local.mk 2023-11-14 10:11:09 +01:00
Joachim WibergandMattias Walström 9f792d56d6 package/skeleton-init-finit: hardening, no login services in RMA
When Infix Fail Secure Mode ends up in RMA state, runlevel 9, we should
not allow Finit to "time out" and give us a login prompt.  Instead we
disable all login services in runlevels 7-9, reserving these extra
levels for future failure modes.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-13 10:28:47 +01:00
Joachim WibergandMattias Walström 54ae8aaf8b src/klish-plugin-infix: change shell from /bin/sh to /bin/bash
Most defconfigs have Bash enabled, those that do not will have the
BusyBox symlink to ash.

This fixes the completion isses we've seen with initctl.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-13 10:28:47 +01:00
Joachim WibergandMattias Walström ab799c0622 src/klish-plugin-infix: minor, add missing keyword in help text
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-13 10:28:47 +01:00
Joachim WibergandMattias Walström 608f82afd6 Mark known services as 'notify:none', no readiness notification
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-13 10:28:47 +01:00
Joachim WibergandMattias Walström 2e1e99bbb0 package/finit: bump to v4.6
Mostly a Bug fix release.  Only major change is support for service
`notify:pid` and `readiness none` global option to change how Finit
expects readiness notification.

Fixes:

- Dbus and runparts regression in Finit v4.5.  The configure script must
  expand `FINIT_RUNPATH_` before defining it in `config.h`

- Service environment variables drop everything but the first argument,
  e.g., `VAR="foo bar qux"` drops everything but `foo`

- Internal conditions, e.g., `<int/bootstrap>` turn into flux when
  leaving bootstrap, causing depending services to stop

- Global environment variables declared with `set VAR=NAME` do not drop
  leading `set `, causing `'set VAR'='NAME'` in env.

- Sanity check environment variables, for services and globally.  Ensure
  the variable name (key) does not contain spaces, or a leading `set `

https://github.com/troglobit/finit/releases/tag/4.6

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-13 10:28:47 +01:00
Joachim WibergandGitHub 4930fa78a8 board/common/rootfs/etc/nginx: drop, unused
[skip ci]
2023-11-13 10:16:17 +01:00
Joachim Wiberg 3807d0bcbc doc: How to Customize Services in Hybrid Mode
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-08 17:21:00 +01:00
Joachim WibergandTobias Waldekranz 32c2319311 Fix #198: no defult PVID for a VLAN filtering bridge
- drop bridge pvid setting in YANG model, we require bridge ports to
   have explicit VLAN assignment (security)
 - refactor bridge_vlan_settings(), do not enable vlan_filtering if
   there are no VLANs configured on the bridge

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-08 16:03:28 +01:00
Mattias Walström 4889d402ec Use proper mkfs.ext4 when creating /var and /cfg partitions
Without this it used an genimage internal one, which did not set
the filetype feature on the filesystem. This caused
podman to refuse to start
2023-11-08 14:16:57 +01:00
Jon-Olov VatnandJoachim Wiberg 8e152d8db3 Fixing typos 2023-11-08 11:18:23 +01:00
Jon-Olov VatnandJoachim Wiberg 349011dc2d Extending VLAN Filtering Bridge documentation (PVID etc)
Adding missing information
- that PVID should (typically) be set for ports associated untagged
- that the bridge should associated with VLAN to terminate the VLAN
  in the bridge
2023-11-08 11:18:23 +01:00
Jon-Olov VatnandJoachim Wiberg 6a9a6780fa Extending the VLAN inteface documentation (picture and example)
Providing an additional config example (VLAN atop brigde)
Adding picture for this and the existing example (VLAN atop Eth)
Adding info on name conventions (eth.20 vs vlan10)
[skip ci]
2023-11-08 11:18:23 +01:00
Joachim Wiberg abb3952fb7 klish-plugin-infix: sync interactive command changes with upstream
Upstream has replaced interactive="true" with:

 - in="tty"
 - out="tty"
 - interrupt="true"

Also, disable Oneliners option since it's too confusing for users
compared to the regular JSON output for startup and factory-config

We can [skip ci] since we do not have any CLI tests yet.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-08 11:17:41 +01:00
Joachim Wiberg 7cbaebc435 klish: fix line drawing characters
For some reasone upstream changed the Pager (less) from -r to -R, to
explictly only allow ANSI color sequences.  This caused the 'show
interfaces' command to output <EF><33><13> style replacement chars
instead of UTF8 line drawing characters.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-08 11:17:41 +01:00
Joachim Wiberg 42ad40f905 rootfs: minor adjustments to /bin/yorn output formatting
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-08 11:17:41 +01:00
Joachim Wiberg 829b4061f6 confd: drop developer debug message
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-07 23:36:51 +01:00
Joachim Wiberg 1f618a5193 Fix #111: upgrade Klish & C:o to fix inference callbacks
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-07 23:36:51 +01:00
Joachim Wiberg 500ae3f8dd Fix #125: improve feedback on invalid configure input
This is an attempt at improving the error reporting from klish-plugin-infix,
or more specifically commit@infix.  Previously none of the sysrepo errors were
shown, now all the latest errors, as well as a few new ones specific to
interfaces have been added.

Example (eth0 does not exist):

    admin@infix-00-00-00:/config/> edit interfaces interface eth0
    admin@infix-00-00-00:/config/interfaces/interface/eth0/> leave
    Error: Mandatory node "type" instance does not exist. (Data location "/ietf-interfaces:interfaces/interface[name='eth0']".)
    Failed committing candidate to running: Validation failed
    admin@infix-00-00-00:/config/interfaces/interface/eth0/> set type ethernet
    admin@infix-00-00-00:/config/interfaces/interface/eth0/> leave
    Error: Cannot create fixed Ethernet interface eth0, wrong type or name.
           Please check your changes, try 'diff' and 'do show interfaces'.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-07 23:36:51 +01:00
Richard AlpeandJoachim Wiberg ff7b8ec9bf cli: speedup detailed interface view
This affects CLI command such as:
> show interface name p1

Prior to this patch, this took roughly ~1200ms on hardware and with
the path it takes roughly 50ms.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-06 20:12:16 +01:00
Richard AlpeandJoachim Wiberg 5b58c60919 test: cli: use random ipv4 addresses in bloated.json
Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-06 20:10:43 +01:00
Richard AlpeandJoachim Wiberg e1080a5412 test: cli: use random ipv6 addresses in bloated.json
Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-06 20:10:43 +01:00
Richard AlpeandJoachim Wiberg 8d2c3f862a test: cli: use random mac addresses in bloated.json 2023-11-06 20:10:43 +01:00
Richard AlpeandJoachim Wiberg 429e1463af cli: add support for printing veth pair
They have link set in there json data from ip link show.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-06 20:10:43 +01:00
Richard AlpeandJoachim Wiberg c0a1c7f259 cli: print iface auto-negotiation in detailed view
Print autoneg status as "on" or "off" if the data exists in the
operational datastore.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-06 11:28:53 +01:00
Richard AlpeandJoachim Wiberg 13092757a1 statd: add auto-negotiation status to op datastore
Add a python3 script "ethtool-to-json" which runs ethtool locally and
converts output which we are interested in into json. The script
simply json encodes the output from ethtool, i.e. it does not print it
in YANG format. This might be a good idea to change in the future if
the C code has to do a lot of ethtool to YANG translations.

The json output of the ethtool-to-json script is then parsed in C
using libjansson, translated to YANG and added to the operational
datastore.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-11-06 11:28:53 +01:00
Joachim Wiberg 40ac1595e5 .github: revert b4d7609, does not work as intended
The idea was to change regression tests to opt-in, but it does not work
as intended for our core devs, so revert.

If you do *not* want the workflow(s) to run on your fork, you can
disable them with the [...] button on the right-hand side, beside the
"Filter workflow runs" text entry, in the Actions view of your fork.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-06 10:04:03 +01:00
Mattias WalströmandJoachim Wiberg 69652280d8 Update documentation for VLAN configuration 2023-11-06 09:22:48 +01:00
Joachim Wiberg fd58eaba4c package/finit: backport critical runpath fix from upstream
Both the dbus plugin and runparts were slightly broken in Finit v4.5.
For details, see https://github.com/troglobit/finit/issues/383

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-05 23:57:48 +01:00
Joachim Wiberg c927578731 doc: fix nested HERE document for easy copy-paste to terminal
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-05 23:57:26 +01:00
Joachim WibergandTobias Waldekranz 62401377b0 Check for factory-reset condition from bootloader
Refactor factory-reset check slightly to check for a Finit condition
from the bootloader, as well as a custom check for br2-externals.

Note, the chgrp call has been extended to ensure admin users have
permission to create any file or directory in any overlay.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-03 12:55:44 +01:00
Joachim WibergandTobias Waldekranz d0f3960d71 confd: add -6 option to gen-interfaces for SLACC on port interfaces
This change updates the documentation for the script, hopefully it is
more readable now than the previous wall of text.

Also, a new -6 option to toggle IPv6 SLACC option for port interfaces.
This, in combination with omitting the -b option, allows for enabling
SLACC on interfaces that would otherwise not get an address.

No functional change, tested manually [skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-03 12:55:44 +01:00
Joachim Wiberg 64222bdac3 ChangeLog: corrections and minor cleanup of 23.10 release
When released the YANG status section claimed IPv4/IPv6 MTU was
not-supported, which was very confusing since the following Changes
section clearly states added support for it.

The YANG Status section was wrong.  It has also been cleaned up a bit.
E.g., no need to mention which native model provides an augment or a
deviation, to an end-user the only thing that matters is what is added
to or removed from the standard models.

[skip ci] becuase none of this warrants a rebuild.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-03 08:20:44 +01:00
Joachim Wiberg a591eeebce confd: fix description whitespace in native model
No logical change, keeping modification date and revision.  We may be
stricted in the future with this.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-03 08:16:04 +01:00
Joachim Wiberg 72b0f9f3eb board/common: add missing $VERSION to /etc/os-release PRETTY_NAME
Per spec[1], the PRETTY_NAME "May or may not contain a release code name
or OS version of some kind, as suitable." and seeing as this is not only
a common practice, Finit use this string in the heading when booting.

We've had this already in Infix a while back so it must have been lost
in one of many refactoring rounds.

[1]: https://www.freedesktop.org/software/systemd/man/latest/os-release.html

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-02 07:00:49 +01:00
Joachim WibergandTobias Waldekranz b7a0c7cf1f doc: add section Factory Defaults to branding document
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-01 21:50:47 +01:00
Joachim WibergandTobias Waldekranz 202b08d34d confd: allow overriding confdrc settings in a confdrc.local
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-01 21:50:47 +01:00
Joachim WibergandTobias Waldekranz 2c69be68e1 confd: minor, move placement of conditions to first row
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-01 21:50:47 +01:00
Joachim WibergandTobias Waldekranz d05de543e4 klish: update system path to factory-config
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-01 21:50:47 +01:00
Joachim WibergandTobias Waldekranz 87378b4fe3 confd: fix and simplify .json snippet collation to factory-config
First, fix collation of .json snippets to ensure they are sorted by
number, regardless of which directory they originate from.

Second, and with an unexpected twist, use /etc as the target directory
for factory-config.cfg and failure-config.cfg.  At first just to avoid
having the resulting .gen and .cfg files in /run/confd/, but it also
unintentionally gives us a way to provide a static /etc/factory-confg
in the image.  As the TODO says, not perfect but better than before.

Third, update load script to use the same base path as bootstrap by
sourcing the system /etc/confdrc.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-11-01 21:50:47 +01:00
Joachim Wiberg 69a3663a82 board/common: expose settings for Qemu machine and its RAM size
A customer specific build required more RAM to boot (bigger image and
more features), but there was no way to modify this as an end user.

This patch opens this up and should give our users a more smooth ride!

We can [skip ci] on this, no functional changes to the OS itself.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-31 18:21:09 +01:00
Richard AlpeandJoachim Wiberg 3bd104a46c cli: use pwgen secure and increase password length
Adhere to our recommendations and avoid pseudorandom passwords which
are "easy to remember". Also increase password length to 13 chars.

Side notes:
Knowing that a password contains at least one char, one number and so
on, lowers the number of possible passwords to test when brute forcing.

The entropy for the pwgen "easy to remember" passwords isn't good
(naturally).

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-31 13:16:37 +01:00
Joachim Wiberg 85a1bfc999 .github: add support for manually starting a release build
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-31 11:29:36 +01:00
Joachim Wiberg 5ebd473972 Update ChangeLog for Infix v23.10 [skip ci]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-31 10:09:01 +01:00
Richard AlpeandJoachim Wiberg 12462d5b17 statd: add more ethtool counters to op datastore
Add counters from Ethtool groups to the operational datastore. The
mapping from Linux / Ethtool to YANG is described in the included
document eth-counters.md.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-31 10:01:55 +01:00
Joachim WibergandTobias Waldekranz afbf92c07e configs: drop x86_64_minimal_defconfig
Replaced with full build in GitHub Actions.  No other use-cases for it,
and too much of a hassle to maintain, so remove.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-31 09:28:28 +01:00
Joachim WibergandTobias Waldekranz 552550495a configs: reenable lost bash for netconf builds
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-31 09:28:28 +01:00
Joachim WibergandTobias Waldekranz 6503face19 package/finit: bump to v4.5
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-31 09:28:28 +01:00
Mattias Walström 90d94fe255 Remove ietf-if-vlan-encapsulation, it is replaced by infix-if-vlan
This is a followup for 941fc3158
2023-10-31 09:16:58 +01:00
Joachim WibergandTobias Waldekranz fc5310b3fd confd: adjust path to failure-config
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-30 12:48:14 +01:00
Joachim WibergandTobias Waldekranz 120e87ac99 confd: sort interfaces according to length and name
A list of interfaces: x10 x9 x8 x7 x6 x5 x4 x1 x2 x3 should be sorted in
order with x10 last.  Using the common 'sort -n' would generate: x1 x10
x2 ... so we use version sort.  This way we can ensure that the order of
bridge ports is natural and what end users expect.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-30 12:48:14 +01:00
Joachim WibergandTobias Waldekranz 7fd7a2e430 confd: regenerate failure-config and factory-config on each boot
Operational experience shows that the current Infix Fail Secure mode,
introduced in ca9daef, does not work in practice.

The factory datastore in sysrepo is created at boot with the YANG models
and the factory-config file.  When the factory-config file is generated
from older versions of these models, the resulting datastore may fail to
pass the validation and system will end up in an unrecoverable state.

Instead, both the factory-config and failure-config must be created at
every boot to match the YANG models in the active Linux image.  This
ensures loading the YANG models will always work and the system can
proceed to attempt to load startup-config to the running datastore.

If loading startup-config fails we can fall back to failure-config,
which like factory-config, will then provide a way to log in an dianose
the system.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-30 12:48:14 +01:00
Tobias WaldekranzandJoachim Wiberg c385e2e9c2 uboot: Import latest patches from u-boot-2023.07.y-kkit
Adds enough support for 6393X switchcore to enable netbooting from a
single port.
2023-10-30 11:24:18 +01:00
Tobias WaldekranzandJoachim Wiberg 97747a95ea common/uboot: Use factory-reset and dev-mode buttons, if available
If the bootloader knows about a factory-reset or dev-mode button, use
them to allow stopping the boot process, and to signal the
factory-reset condition to infix.
2023-10-30 11:24:18 +01:00
Tobias WaldekranzandJoachim Wiberg 01e43896df common/uboot: Explicitly separate kernel/user arguments
This way, we avoid arguments intended for userspace to be accidentally
parsed by the kernel.
2023-10-30 11:24:18 +01:00
Tobias WaldekranzandJoachim Wiberg 60c777fb41 common/uboot: If no valid boot media exists, fall back to netboot
This means that a device with a valid bootloader, but a completely
empty eMMC is still salvageable.
2023-10-30 11:24:18 +01:00
Tobias WaldekranzandJoachim Wiberg 194aa5de8a common/uboot: Use correct name of netboot in default order 2023-10-30 11:24:18 +01:00
Tobias WaldekranzandJoachim Wiberg 47fe0529f4 arm-trusted-firmware: Default to 16-bit DDR4 on CN9130 boards 2023-10-30 11:24:18 +01:00
Mattias WalströmandJoachim Wiberg 941fc31581 infix-vlan: Create a custom vlan model
This implements the new model infix-if-vlan.
The new CLI is:

root@infix-00-00-00:/config/interfaces/interface/vlan10/> set vlan id 10 lower-layer-if eth0

with an possible extra option for tag-type, default tag-type is c-vlan.
2023-10-27 10:53:55 +02:00
Joachim Wiberg be8bad9885 doc: add Versioning section to branding document
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-24 13:51:27 +02:00
Joachim Wiberg e03ab9c81b board/common: add help text for Qemu interface model
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-24 13:37:28 +02:00
Mattias WalströmandJoachim Wiberg f224d0d03d ietf-factory-default: Implement factory reset
fixes #157, fixes #156
2023-10-24 12:25:38 +02:00
Mattias WalströmandJoachim Wiberg d66740250c confd: Add support for timezone-utc-offset
Some deviations has been done the yang model to comply with tzdata
on linux.

This fixes #106
2023-10-20 12:55:02 +02:00
Mattias WalströmandJoachim Wiberg 0db65846c3 Add tzset() before localtime
Without it, the offset generated will always be zero.
But over netconf it will still be correct, most likely
because due to how libyang handles the date-and-time type.
2023-10-20 12:55:02 +02:00
Richard AlpeandJoachim Wiberg 4471c45d3c .github: use defconfig instead of minimal_defconfig
The issues seen in the regression tests looks related to files
missing from minimal defconfig.

Fixes #127.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-17 18:18:19 +02:00
Richard AlpeandJoachim Wiberg 5639e5bdd4 statd: ignore interfaces with group = internal
Don't add any info about interfaces which has "group" = "internal" to
the operational datastore.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-17 18:17:59 +02:00
Richard AlpeandJoachim Wiberg 1654773bc6 statd: ignore parent interface for kind dsa
DSA ports such as pX has "link" (parent) set to dsaY. We don't see it
that way from an networking perspective. In this commit we avoid
adding parent to the statd data structure if the linkinfo -> info_kind
is dsa. This means the ports shows up as regular interfaces, which is
what we want.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-17 18:17:59 +02:00
Richard AlpeandJoachim Wiberg 4a84ab95d0 statd: dsa ifaces has type infix-if-type:ethernet
Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-17 18:17:59 +02:00
Richard AlpeandJoachim Wiberg f643b4f9dc statd: break out parent interface code (cosmetic)
A non functional change to prepare for upcoming patches.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-17 18:17:59 +02:00
Richard AlpeandJoachim Wiberg d6152ce6ea cli: add graceful error for missing json in cli-pretty
Print a graceful error message if the json data is missing of invalid.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-17 18:17:59 +02:00
Richard AlpeandJoachim Wiberg 1a3105c06d cli: pretty print existing Ethernet frame stats
Pretty print all Ethernet frame statistics from the operational
datastore. Only in the detailed interface view.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-17 18:17:59 +02:00
Richard AlpeandJoachim Wiberg 14dc3cf8a0 statd: add ethtool frame counters to op datastore
This patch adds the framework for reading ethtool statistics and
inserting it into the operational datastore.

The ethtool data we rely on is "group data" such as "eth-mac" or
"rmon".

This data can be displayed using:
ethtool --json -S e0 --all-groups

The "group data" is still missing for most common drivers, so testing
this will require a firmware which has support for it.

Signed-off-by: Richard Alpe <richard@bit42.se>
2023-10-17 18:17:54 +02:00
Joachim Wiberg 9292231674 .github: switch to ncipollo/release-action for latest build
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-17 18:08:07 +02:00
244 changed files with 12437 additions and 4655 deletions
+10 -11
View File
@@ -1,9 +1,3 @@
# To enable this workflow of your Infix fork, set the repoistory or
# organisation variable (not secret):
#
# LATEST_BUILD = true
#
# https://docs.github.com/en/actions/learn-github-actions/variables#creating-configuration-variables-for-a-repository
name: Bob the Builder
on:
@@ -14,7 +8,6 @@ on:
jobs:
build:
if: ${{ vars.LATEST_BUILD == 'true' }}
name: Build ${{ matrix.platform }} ${{ matrix.variant }}
runs-on: ubuntu-latest
strategy:
@@ -80,14 +73,20 @@ jobs:
name: Upload Latest Build
needs: build
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/download-artifact@v3
- uses: pyTooling/Actions/releaser@main
- uses: ncipollo/release-action@v1
with:
tag: latest
rm: false
allowUpdates: true
omitName: true
omitBody: true
omitBodyDuringUpdate: true
prerelease: true
tag: "latest"
token: ${{ secrets.GITHUB_TOKEN }}
files: artifact/*
artifacts: "artifact/*"
- name: Summary
run: |
cat <<EOF >> $GITHUB_STEP_SUMMARY
+81
View File
@@ -0,0 +1,81 @@
name: Coverity Scan
on:
workflow_dispatch:
env:
PROJECT_NAME: Infix
CONTACT_EMAIL: troglobit@gmail.com
jobs:
coverity:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Fetch latest Coverity Scan MD5
id: var
env:
TOKEN: ${{ secrets.COVERITY_SCAN_TOKEN }}
run: |
wget -q https://scan.coverity.com/download/cxx/linux64 \
--post-data "token=$TOKEN&project=${PROJECT_NAME}&md5=1" \
-O coverity-latest.tar.gz.md5
echo "md5=$(cat coverity-latest.tar.gz.md5)" | tee -a $GITHUB_OUTPUT
- uses: actions/cache@v3
id: cache
with:
path: coverity-latest.tar.gz
key: ${{ runner.os }}-coverity-${{ steps.var.outputs.md5 }}
restore-keys: |
${{ runner.os }}-coverity-${{ steps.var.outputs.md5 }}
${{ runner.os }}-coverity-
${{ runner.os }}-coverity
- name: Download Coverity Scan
env:
TOKEN: ${{ secrets.COVERITY_SCAN_TOKEN }}
run: |
if [ ! -f coverity-latest.tar.gz ]; then
wget -q https://scan.coverity.com/download/cxx/linux64 \
--post-data "token=$TOKEN&project=${PROJECT_NAME}" \
-O coverity-latest.tar.gz
else
echo "Latest Coverity Scan available from cache :-)"
md5sum coverity-latest.tar.gz
fi
mkdir coverity
tar xzf coverity-latest.tar.gz --strip 1 -C coverity
- name: Install dependencies
run: |
sudo apt-get -y update
sudo apt-get -y install pkg-config libjansson-dev libev-dev libite-dev \
libaugeas-dev libglib2.0-dev libpcre2-dev
- name: Build dependencies
run: |
git clone https://github.com/CESNET/libyang.git
mkdir libyang/build
(cd libyang/build && cmake .. && make all && sudo make install)
git clone https://github.com/sysrepo/sysrepo.git
mkdir sysrepo/build
(cd sysrepo/build && cmake .. && make all && sudo make install)
make dep
- name: Check applications
run: |
export PATH=`pwd`/coverity/bin:$PATH
cov-build --dir cov-int make check
- name: Submit results to Coverity Scan
env:
TOKEN: ${{ secrets.COVERITY_SCAN_TOKEN }}
run: |
tar czvf ${PROJECT_NAME}.tgz cov-int
curl \
--form token=$TOKEN \
--form email=${CONTACT_EMAIL} \
--form file=@${PROJECT_NAME}.tgz \
--form version=$(git rev-parse HEAD) \
--form description="${PROJECT_NAME} $(git rev-parse HEAD)" \
https://scan.coverity.com/builds?project=${PROJECT_NAME}
- name: Upload build.log
uses: actions/upload-artifact@v3
with:
name: coverity-build.log
path: cov-int/build-log.txt
+3 -10
View File
@@ -1,9 +1,3 @@
# To enable this workflow of your Infix fork, set the repoistory or
# organisation variable (not secret):
#
# REGRESSION_TEST = true
#
# https://docs.github.com/en/actions/learn-github-actions/variables#creating-configuration-variables-for-a-repository
name: Reggie Regression
on:
@@ -21,7 +15,6 @@ concurrency:
jobs:
build:
if: ${{ vars.REGRESSION_TEST == 'true' }}
name: Regression Testing
runs-on: ubuntu-latest
steps:
@@ -31,7 +24,7 @@ jobs:
- name: Set Build Variables
id: vars
run: |
target=x86_64-minimal
target=x86_64
echo "dir=infix-$target" >> $GITHUB_OUTPUT
echo "tgz=infix-$target.tar.gz" >> $GITHUB_OUTPUT
- name: Restore Cache of dl/
@@ -52,9 +45,9 @@ jobs:
ccache-x86_64-netconf-
ccache-x86_64-
ccache-
- name: Configure Minimal NETCONF
- name: Configure NETCONF
run: |
make x86_64_minimal_defconfig
make x86_64_defconfig
- name: Build
run: |
make
+22 -5
View File
@@ -1,9 +1,21 @@
# This job can be started by a git tag or using the workflow dispatch.
#
# The version string *must* be of the format: vYY.MM(-alphaN|-betaN|-rcN)
#
# In /etc/os-release this string is used for VERSION, VERSION_ID, and
# IMAGE_VERSION, with the 'v' prefix. In release artifact filenames,
# and zip file directory names, the 'v' is dropped per convention.
name: Release General
on:
push:
tags:
- 'v[0-9]*.*'
workflow_dispatch:
inputs:
version:
required: false
type: string
jobs:
build:
@@ -20,17 +32,22 @@ jobs:
- name: Set Release Variables
id: build
run: |
ver=${GITHUB_REF#refs/tags/v}
if [ -n "${{ inputs.version }}" ]; then
ver=${{ inputs.version }}
else
ver=${GITHUB_REF#refs/tags/}
fi
echo "ver=${ver}" >> $GITHUB_OUTPUT
if echo $ver | grep -qE '[0-9.]+(-alpha|-beta|-rc)[0-9]*'; then
if echo $ver | grep -qE 'v[0-9\.]+(-alpha|-beta|-rc)[0-9]*'; then
echo "pre=true" >> $GITHUB_OUTPUT
else
echo "pre=false" >> $GITHUB_OUTPUT
fi
fver=${ver#v}
if [ "${{ matrix.variant }}" = "netconf" ]; then
target=${{ matrix.platform }}-${ver}
target=${{ matrix.platform }}-${fver}
else
target=${{ matrix.platform }}-${{ matrix.variant }}-${ver}
target=${{ matrix.platform }}-${{ matrix.variant }}-${fver}
fi
echo "dir=infix-$target" >> $GITHUB_OUTPUT
echo "tgz=infix-$target.tar.gz" >> $GITHUB_OUTPUT
@@ -82,7 +99,7 @@ jobs:
- uses: actions/download-artifact@v3
- name: Extract ChangeLog entry ...
run: |
awk '/-----*/{if (x == 1) exit; x=1;next}x' doc/ChangeLog.md \
awk '/^-----*$/{if (x == 1) exit; x=1;next}x' doc/ChangeLog.md \
|head -n -1 > release.md
cat release.md
- uses: ncipollo/release-action@v1
+6 -1
View File
@@ -11,6 +11,10 @@ bmake = $(MAKE) -C buildroot O=$(O) $1
all: $(config) buildroot/Makefile
@+$(call bmake,$@)
check dep:
@echo "Starting local check, stage $@ ..."
@make -C src $@
$(config):
@+$(call bmake,list-defconfigs)
@echo "\e[7mERROR: No configuration selected.\e[0m"
@@ -25,4 +29,5 @@ $(config):
buildroot/Makefile:
@git submodule update --init
.PHONY: all
.PHONY: all check
+29 -17
View File
@@ -1,4 +1,5 @@
<img align="right" src="doc/logo.png" alt="Infix - Linux <3 NETCONF" width=480>
[![License Badge][]][License] [![Coverity Status][]][Coverity Scan]
<img align="right" src="doc/logo.png" alt="Infix - Linux <3 NETCONF" width=480 border=10>
<details><summary><b>Documentation</b></summary>
- **Infix In-Depth**
@@ -19,7 +20,8 @@
Infix is a Linux Network Operating System (NOS) based on [Buildroot][1],
and [sysrepo][2]. A powerful mix that ease porting to different
platforms, simplify long-term maintenance, and provide made-easy
management using NETCONF[^1] (remote) or the built-in [CLI][3].
management using NETCONF[^1] (remote) or the built-in [command
line interface (CLI)][3] (click the foldout for an example).
<details><summary><b>Example CLI Session</b></summary>
@@ -29,16 +31,20 @@ is brief example of how to set the IP address of an interface:
```
admin@infix-12-34-56:/> configure
admin@infix-12-34-56:/config/> edit interfaces interface eth0
admin@infix-12-34-56:/config/interfaces/interface/eth0/> set ipv4 <TAB>
admin@infix-12-34-56:/config/> edit interface eth0
admin@infix-12-34-56:/config/interface/eth0/> set ipv4 <TAB>
address autoconf bind-ni-name enabled
forwarding mtu neighbor
admin@infix-12-34-56:/config/interfaces/interface/eth0/> set ipv4 address 192.168.2.200 prefix-length 24
admin@infix-12-34-56:/config/interfaces/interface/eth0/> show
type ethernetCsmacd;
ipv4 address 192.168.2.200 prefix-length 24;
ipv6 enabled true;
admin@infix-12-34-56:/config/interfaces/interface/eth0/> diff
admin@infix-12-34-56:/config/interface/eth0/> set ipv4 address 192.168.2.200 prefix-length 24
admin@infix-12-34-56:/config/interface/eth0/> show
type ethernet;
ipv4 {
address 192.168.2.200 {
prefix-length 24;
}
}
ipv6
admin@infix-12-34-56:/config/interface/eth0/> diff
interfaces {
interface eth0 {
+ ipv4 {
@@ -48,13 +54,15 @@ interfaces {
+ }
}
}
admin@infix-12-34-56:/config/interfaces/interface/eth0/> leave
admin@infix-12-34-56:/> show interfaces brief
lo UNKNOWN 00:00:00:00:00:00 <LOOPBACK,UP,LOWER_UP>
eth0 UP 52:54:00:12:34:56 <BROADCAST,MULTICAST,UP,LOWER_UP>
admin@infix-12-34-56:/> show ip brief
lo UNKNOWN 127.0.0.1/8 ::1/128
eth0 UP 192.168.2.200/24 fe80::5054:ff:fe12:3456/64
admin@infix-12-34-56:/config/interface/eth0/> leave
admin@infix-12-34-56:/> show interfaces
INTERFACE PROTOCOL STATE DATA
eth0 ethernet UP 52:54:00:12:34:56
ipv4 192.168.2.200/24 (static)
ipv6 fe80::5054:ff:fe12:3456/64 (link-layer)
lo ethernet UP 00:00:00:00:00:00
ipv4 127.0.0.1/8 (static)
ipv6 ::1/128 (static)
admin@infix-12-34-56:/> copy running-config startup-config
```
@@ -86,3 +94,7 @@ more information, see: [Infix in Virtual Environments](doc/virtual.md).
[1]: https://buildroot.org/
[2]: https://www.sysrepo.org/
[3]: doc/cli/introduction.md
[License]: https://en.wikipedia.org/wiki/GPL_license
[License Badge]: https://img.shields.io/badge/License-GPL%20v2-blue.svg
[Coverity Scan]: https://scan.coverity.com/projects/29393
[Coverity Status]: https://scan.coverity.com/projects/29393/badge.svg
+4 -4
View File
@@ -25,7 +25,7 @@
/* mpp21: Unused */
/* mpp22: Unused */
/* mpp23: Unused */
#define SFP9_RX_LOS(X) X("mpp24", cp0_gpio1, 24, GPIO_ACTIVE_HIGH)
#define DDR_TEN(X) X("mpp24", cp0_gpio1, 24, GPIO_ACTIVE_HIGH)
#define ETH9_RESETn(X) X("mpp25", cp0_gpio1, 25, GPIO_ACTIVE_LOW)
#define SW_INTn(X) X("mpp26", cp0_gpio1, 26, IRQ_TYPE_LEVEL_LOW)
#define SFP9_RS1(X) X("mpp27", cp0_gpio1, 27, GPIO_ACTIVE_HIGH)
@@ -34,7 +34,7 @@
#define CP_UA0_TXD(X) X("mpp30", none, 0, 0)
#define SFP10_TX_DISABLE(X) X("mpp31", cp0_gpio1, 31, GPIO_ACTIVE_HIGH)
#define SFP10_MOD_ABS(X) X("mpp32", cp0_gpio2, 0, GPIO_ACTIVE_LOW)
#define I2C_IRQ(X) X("mpp33", cp0_gpio2, 1, GPIO_ACTIVE_HIGH)
#define I2C_IRQ(X) X("mpp33", cp0_gpio2, 1, IRQ_TYPE_LEVEL_LOW)
#define SFP10_RS0(X) X("mpp34", cp0_gpio2, 2, GPIO_ACTIVE_HIGH)
#define CP_I2C1_SDA(X) X("mpp35", none, 0, 0)
#define CP_I2C1_SCK(X) X("mpp36", none, 0, 0)
@@ -54,7 +54,7 @@
#define USB1_VBUS_ENABLE(X) X("mpp50", cp0_gpio2, 18, GPIO_ACTIVE_HIGH)
#define USB1_VBUS_ERROR_OC(X) X("mpp51", cp0_gpio2, 19, GPIO_ACTIVE_HIGH)
/* mpp52: Unused */
/* mpp53: Unused */
#define SFP9_RX_LOS(X) X("mpp53", cp0_gpio2, 21, GPIO_ACTIVE_HIGH)
/* mpp54: Unused */
#define CP_SD_LED(X) X("mpp55", none, 0, 0)
#define CP_SD_CLK(X) X("mpp56", none, 0, 0)
@@ -63,7 +63,7 @@
#define CP_SD_D1(X) X("mpp59", none, 0, 0)
#define CP_SD_D2(X) X("mpp60", none, 0, 0)
#define CP_SD_D3(X) X("mpp61", none, 0, 0)
#define DDR_TEN(X) X("mpp62", cp0_gpio2, 30 GPIO_ACTIVE_HIGH)
/* mpp62: Unused */
/* Macros to extract MPP info in different formats */
#define MPP_ID(_mpp, _chip, _no, _flags) _mpp
+187 -46
View File
@@ -21,6 +21,10 @@
chosen {
stdout-path = "serial0:115200n8";
infix {
vpds = <&vpd_cpu &vpd_product &vpd_power>;
};
};
memory@0 {
@@ -71,10 +75,13 @@
pinctrl-names = "default";
pinctrl-0 = <&cp0_i2c0_pins>;
eeprom@50 {
vpd_cpu: eeprom@50 {
// AT24C256C-MAHL-T
compatible = "atmel,24c256";
reg = <0x50>;
infix,board = "cpu";
infix,trusted;
};
};
@@ -159,11 +166,12 @@
/* System Management */
&i2c_sysmgmt {
eeprom@b {
vpd_product: eeprom@b {
label = "vpd";
reg = <0x0b>;
compatible = "atmel,24c02";
read-only;
infix,board = "product";
nvmem-layout {
compatible = "onie,tlv-layout";
@@ -302,6 +310,7 @@
&cp0_utmi1 {
status = "okay";
dr_mode = "host";
};
&cp0_usb3_1 {
@@ -377,42 +386,80 @@
};
};
#define SWP(_n, _label, _mac_offs, _phymode, _phy) \
port@_n { \
#define SWP_COMMON(_n, _label, _mac_offs, _phymode, _phy) \
reg = <0x ## _n>; \
label = _label; \
phy-mode = _phymode; \
phy-handle = <&_phy>; \
\
nvmem-cells = <&base_mac _mac_offs>; \
nvmem-cell-names = "mac-address"; \
nvmem-cell-names = "mac-address"
#define XSWP(_n, _label, _mac_offs, _phy) \
port@_n { \
SWP_COMMON(_n, _label, _mac_offs, "usxgmii", _phy); \
}
SWP(9, "x1", 1, "usxgmii", xphy9);
SWP(a, "x2", 2, "usxgmii", xphya);
#define GSWP(_n, _label, _mac_offs, _phy) \
port@_n { \
SWP_COMMON(_n, _label, _mac_offs, "gmii", _phy); \
\
leds { \
#address-cells = <1>; \
#size-cells = <0>; \
\
led@0 { \
reg = <0>; \
function = "tp"; \
color = <LED_COLOR_ID_GREEN>; \
default-state = "keep"; \
}; \
led@1 { \
reg = <1>; \
function = "tp"; \
color = <LED_COLOR_ID_YELLOW>; \
default-state = "off"; \
}; \
}; \
}
SWP(8, "x3", 3, "gmii", swphy8);
SWP(7, "x4", 4, "gmii", swphy7);
SWP(6, "x5", 5, "gmii", swphy6);
SWP(5, "x6", 6, "gmii", swphy5);
SWP(4, "x7", 7, "gmii", swphy4);
SWP(3, "x8", 8, "gmii", swphy3);
SWP(2, "x9", 9, "gmii", swphy2);
SWP(1, "x10", 10, "gmii", swphy1);
#undef SWP
XSWP(9, "x1", 1, xphy9);
XSWP(a, "x2", 2, xphya);
GSWP(8, "x3", 3, swphy8);
GSWP(7, "x4", 4, swphy7);
GSWP(6, "x5", 5, swphy6);
GSWP(5, "x6", 6, swphy5);
GSWP(4, "x7", 7, swphy4);
GSWP(3, "x8", 8, swphy3);
GSWP(2, "x9", 9, swphy2);
GSWP(1, "x10", 10, swphy1);
#undef GSWP
#undef XSWP
#undef SWP_COMMON
};
mdio {
#address-cells = <1>;
#size-cells = <0>;
swphy1: ethernet-phy@1 { reg = <0x1>; };
swphy2: ethernet-phy@2 { reg = <0x2>; };
swphy3: ethernet-phy@3 { reg = <0x3>; };
swphy4: ethernet-phy@4 { reg = <0x4>; };
swphy5: ethernet-phy@5 { reg = <0x5>; };
swphy6: ethernet-phy@6 { reg = <0x6>; };
swphy7: ethernet-phy@7 { reg = <0x7>; };
swphy8: ethernet-phy@8 { reg = <0x8>; };
#define SWPHY(_n) \
ethernet-phy@_n { \
compatible = "ethernet-phy-ieee802.3-c22"; \
reg = <_n>; \
eee-broken-100tx; \
eee-broken-1000t; \
}
swphy1: SWPHY(1);
swphy2: SWPHY(2);
swphy3: SWPHY(3);
swphy4: SWPHY(4);
swphy5: SWPHY(5);
swphy6: SWPHY(6);
swphy7: SWPHY(7);
swphy8: SWPHY(8);
#undef SWPHY
};
};
};
@@ -453,17 +500,59 @@
/* 88X3310 specifices 35ns minimum MDC period (28.57 MHz). */
clock-frequency = <28571428>;
xphy9: ethernet-phy@4 {
compatible = "ethernet-phy-ieee802.3-c45";
reg = <4>;
sfp = <&sfp9>;
};
#define XPHY(_n, _sfp) \
ethernet-phy@_n { \
compatible = "ethernet-phy-ieee802.3-c45"; \
reg = <_n>; \
sfp = <&_sfp>; \
\
leds { \
#address-cells = <1>; \
#size-cells = <0>; \
\
led@0 { \
reg = <0>; \
function = "tp"; \
color = <LED_COLOR_ID_YELLOW>; \
default-state = "off"; \
\
marvell,media = "copper"; \
marvell,polarity = "active-high"; \
}; \
led@1 { \
reg = <1>; \
function = "tp"; \
color = <LED_COLOR_ID_GREEN>; \
default-state = "keep"; \
\
marvell,media = "copper"; \
marvell,polarity = "active-high"; \
}; \
\
led@2 { \
reg = <2>; \
function = "sfp"; \
color = <LED_COLOR_ID_YELLOW>; \
default-state = "off"; \
\
marvell,media = "fiber"; \
marvell,polarity = "active-high"; \
}; \
led@3 { \
reg = <3>; \
function = "sfp"; \
color = <LED_COLOR_ID_GREEN>; \
default-state = "keep"; \
\
marvell,media = "fiber"; \
marvell,polarity = "active-high"; \
}; \
}; \
}
xphya: ethernet-phy@5 {
compatible = "ethernet-phy-ieee802.3-c45";
reg = <5>;
sfp = <&sfpa>;
};
xphy9: XPHY(4, sfp9);
xphya: XPHY(5, sfpa);
#undef XPHY
};
/ {
@@ -495,23 +584,35 @@
/* Power Board */
&cp0_pinctrl {
cp0_pwr_gpio_pins: cp0-pwr-gpio-0 {
marvell,pins = I2C_IRQ(MPP_ID);
marvell,function = "gpio";
};
};
&i2c_pwr {
// Shared IRQ on I2C_IRQ
pinctrl-names = "default";
pinctrl-0 = <&cp0_pwr_gpio_pins>;
// 0x26 U13 PCF8574 GPIO I/O
gpio_pwr1: gpio@26 {
compatible = "nxp,pcf8574a";
#gpio-cells = <2>;
gpio-controller;
#interrupt-cells = <2>;
interrupt-controller;
interrupts-extended = I2C_IRQ(MPP_IRQ_REF);
reg = <0x26>;
#define GPIO_PWR1_UNUSED0 gpio_pwr1 0 GPIO_ACTIVE_HIGH
#define GPIO_PWR1_UNUSED1 gpio_pwr1 1 GPIO_ACTIVE_HIGH
#define GPIO_POE_PGOOD gpio_pwr1 2 GPIO_ACTIVE_HIGH
#define GPIO_RESET_BUTTON gpio_pwr1 3 GPIO_ACTIVE_LOW
#define GPIO_VIN1_PGOOD gpio_pwr1 4 GPIO_ACTIVE_LOW
#define GPIO_LED_VIN1_ALERT gpio_pwr1 5 GPIO_ACTIVE_LOW
#define GPIO_LED_VIN2_ALERT gpio_pwr1 5 GPIO_ACTIVE_LOW
#define GPIO_VIN2_PGOOD gpio_pwr1 6 GPIO_ACTIVE_LOW
#define GPIO_LED_VIN2_ALERT gpio_pwr1 7 GPIO_ACTIVE_LOW
#define GPIO_LED_VIN1_ALERT gpio_pwr1 7 GPIO_ACTIVE_LOW
};
//0x27 U3 PCF8574 GPIO LED
@@ -519,6 +620,9 @@
compatible = "nxp,pcf8574a";
#gpio-cells = <2>;
gpio-controller;
#interrupt-cells = <2>;
interrupt-controller;
interrupts-extended = I2C_IRQ(MPP_IRQ_REF);
reg = <0x27>;
#define GPIO_LED2G gpio_pwr2 0 GPIO_ACTIVE_LOW
#define GPIO_LED2R gpio_pwr2 1 GPIO_ACTIVE_LOW
@@ -534,10 +638,12 @@
//0x30 U5 TPS23861PWR PoE Controller broadcast
//0x50 U15 AT24C256C EEPROM
eeprom@50 {
vpd_power: eeprom@50 {
// AT24C256C-MAHL-T
compatible = "atmel,24c256";
reg = <0x50>;
infix,board = "power";
};
};
@@ -545,6 +651,18 @@
/* System LEDs */
/ {
power-a {
compatible = "gpio-charger";
charger-type = "mains";
gpios = <&GPIO_VIN1_PGOOD>;
};
power-b {
compatible = "gpio-charger";
charger-type = "mains";
gpios = <&GPIO_VIN2_PGOOD>;
};
leds: leds {
compatible = "gpio-leds";
@@ -584,28 +702,51 @@
gpios = <&GPIO_LED3R>;
};
led-dbgg {
function = LED_FUNCTION_DEBUG;
led-bootg {
function = LED_FUNCTION_BOOT;
color = <LED_COLOR_ID_GREEN>;
gpios = <&GPIO_LED4G>;
};
led-dbgr {
function = LED_FUNCTION_DEBUG;
led-bootr {
function = LED_FUNCTION_BOOT;
color = <LED_COLOR_ID_RED>;
gpios = <&GPIO_LED4R>;
default-state = "on";
linux,default-trigger = "timer";
};
led-vin1_alert {
function = "power-1";
led-vin1-alert {
function = "power-a";
color = <LED_COLOR_ID_RED>;
gpios = <&GPIO_LED_VIN1_ALERT>;
};
led-vin2_alert {
function = "power-2";
led-vin2-alert {
function = "power-b";
color = <LED_COLOR_ID_RED>;
gpios = <&GPIO_LED_VIN2_ALERT>;
};
};
};
/* Watchdog */
&cp0_pinctrl {
watchdog_pins: watchdog-pins {
marvell,pins = WDT_TICKLE(MPP_ID);
marvell,function = "gpio";
};
};
/ {
sysmgmt-watchdog {
pinctrl-names = "default";
pinctrl-0 = <&watchdog_pins>;
compatible = "linux,wdt-gpio";
gpios = WDT_TICKLE(MPP_GPIO_REF);
always-running;
hw_algo = "toggle";
hw_margin_ms = <20000>; /* toggle period must be below 1 minute */
};
};
+4
View File
@@ -384,6 +384,7 @@ CONFIG_GPIO_PL061=y
CONFIG_GPIO_XGENE=y
CONFIG_GPIO_PCA953X=y
CONFIG_GPIO_PCA953X_IRQ=y
CONFIG_GPIO_PCF857X=y
CONFIG_GPIO_MAX77620=y
CONFIG_POWER_RESET_GPIO_RESTART=y
CONFIG_POWER_RESET_XGENE=y
@@ -400,6 +401,7 @@ CONFIG_ARMADA_THERMAL=y
CONFIG_WATCHDOG=y
CONFIG_WATCHDOG_SYSFS=y
CONFIG_SOFT_WATCHDOG=y
CONFIG_GPIO_WATCHDOG=y
CONFIG_ARMADA_37XX_WATCHDOG=y
CONFIG_I6300ESB_WDT=y
CONFIG_MFD_MAX77620=y
@@ -469,8 +471,10 @@ CONFIG_LEDS_CLASS=y
CONFIG_LEDS_GPIO=y
CONFIG_LEDS_SYSCON=y
CONFIG_LEDS_TRIGGERS=y
CONFIG_LEDS_TRIGGER_TIMER=y
CONFIG_LEDS_TRIGGER_HEARTBEAT=y
CONFIG_LEDS_TRIGGER_CPU=y
CONFIG_LEDS_TRIGGER_NETDEV=y
CONFIG_RTC_CLASS=y
CONFIG_RTC_DRV_MAX77686=y
CONFIG_RTC_DRV_PCF8523=y
@@ -1,4 +1,4 @@
label Infix (aarch64)
kernel /boot/Image
fdtdir /boot
append ${bootargs_root} ${bootargs_rauc} ${bootargs_log}
append ${bootargs_root} ${bootargs_log} -- ${bootargs_user}
+1 -1
View File
@@ -23,7 +23,7 @@ config SIGN_KEY
menuconfig DISK_IMAGE
bool "Disk image"
help
Compose a full disk image with redundant firmware partitions,
Compose a full disk image with redundant Linux OS partitions,
configuration partition, etc.
This is useful when:
-65
View File
@@ -1,65 +0,0 @@
image aux.ext4 {
mountpoint = "/aux"
temporary = true
size = 2M
ext4 {
label = "aux"
}
}
image cfg.ext4 {
empty = true
temporary = true
size = 16M
ext4 {
label = "cfg"
}
}
image var.ext4 {
empty = true
temporary = true
# 44M - 24k (GPT backup)
size = 45032k
ext4 {
label = "var"
}
}
image mmc.img {
size = 512M
hdimage {
partition-table-type = "gpt"
}
partition aux {
offset = 2M
image = "aux.ext4"
}
partition primary {
image = "rootfs.squashfs"
size = 224M
}
partition secondary {
bootable = true
image = "rootfs.squashfs"
size = 224M
}
partition cfg {
image = "cfg.ext4"
}
partition var {
image = "var.ext4"
}
}
# Silence genimage warnings
config {}
+3
View File
@@ -7,6 +7,7 @@ image aux.ext4 {
ext4 {
label = "aux"
use-mke2fs = true
}
}
@@ -17,6 +18,7 @@ image cfg.ext4 {
ext4 {
label = "cfg"
use-mke2fs = true
}
}
@@ -27,6 +29,7 @@ image var.ext4 {
ext4 {
label = "var"
use-mke2fs = true
}
}
+1 -1
View File
@@ -29,7 +29,7 @@ rm -f "$TARGET_DIR/etc/os-release"
{
echo "NAME=\"$INFIX_NAME\""
echo "ID=$INFIX_ID"
echo "PRETTY_NAME=\"$INFIX_TAGLINE\""
echo "PRETTY_NAME=\"$INFIX_TAGLINE $VERSION\""
echo "ID_LIKE=\"${ID}\""
echo "VERSION=\"${VERSION}\""
echo "VERSION_ID=${VERSION}"
+1 -4
View File
@@ -73,10 +73,6 @@ if [ "$FIT_IMAGE" = "y" ]; then
fi
if [ "$BR2_TARGET_ROOTFS_SQUASHFS" = "y" ]; then
if [ -z "${NAME##*minimal*}" ]; then
NAME=$(echo "$NAME" | sed 's/-minimal//')
fi
rel=$(ver)
ln -sf rootfs.squashfs "$BINARIES_DIR/${NAME}${rel}.img"
if [ -n "$rel" ]; then
@@ -85,6 +81,7 @@ if [ "$BR2_TARGET_ROOTFS_SQUASHFS" = "y" ]; then
fi
# Menuconfig support for modifying Qemu args in release tarballs
cp "$BR2_EXTERNAL_INFIX_PATH/board/common/rootfs/bin/onieprom" "$BINARIES_DIR/"
cp "$BR2_EXTERNAL_INFIX_PATH/board/common/qemu/qemu.sh" "$BINARIES_DIR/"
sed -e "s/@ARCH@/QEMU_$BR2_ARCH/" \
-e "s/@DISK_IMG@/$diskimg/" \
+25 -3
View File
@@ -62,9 +62,24 @@ config QEMU_CONSOLE_SERIAL
endchoice
config QEMU_MACHINE
string
default "qemu-system-aarch64 -M virt -cpu cortex-a72 -m 256M" if QEMU_aarch64
default "qemu-system-x86_64 -M q35,accel=kvm -cpu host -m 256M" if QEMU_x86_64
string "Select emulated machine"
default "qemu-system-aarch64 -M virt -cpu cortex-a72" if QEMU_aarch64
default "qemu-system-x86_64 -M q35,accel=kvm -cpu host" if QEMU_x86_64
help
You should not have to change this setting, although you may
want to tweak it, or change the acceleration.
The default is based on the Buildroot architecture, selected by
the defconfig you started with. Currently Infix supports only
aarch64 (ARM64) and x86_64 (AMD64).
config QEMU_MACHINE_RAM
string "RAM size (k/M/G)"
default "256M"
help
The default, 255 MiB, works for most configurations, even less for
the Infix Classic builds. However, if you get kernel panic with:
"System is deadlocked on memory", try increasing this one.
config QEMU_KERNEL
string
@@ -103,6 +118,9 @@ config QEMU_RW_VAR
default "var.ext4"
endif
config QEMU_VPD
bool "Emulate a Vital Product Data (VPD) Memory"
config QEMU_HOST
string "Export host filesystem path"
default "/tmp"
@@ -137,6 +155,10 @@ endchoice
config QEMU_NET_MODEL
string "Interface model"
default "virtio-net-pci"
help
The default, virtio-net-pci, NIC works for most use-cases, but
if you want to play with low-level stuff like ethtool, you
might want to test the Intel 82545EM driver, e1000.
config QEMU_NET_BRIDGE_DEV
string "Bridge device"
+32 -2
View File
@@ -19,6 +19,7 @@
#
# Local variables
imgdir=$(readlink -f $(dirname "$0"))
prognm=$(basename "$0")
usage()
@@ -169,7 +170,7 @@ net_dev_args()
net_args()
{
# Infix will pick up this file via fwcfg and install it to /etc
mactab=$(dirname "$CONFIG_QEMU_ROOTFS")/mactab
mactab=${imgdir}/mactab
:> "$mactab"
echo -n "-fw_cfg name=opt/mactab,file=$mactab "
@@ -192,6 +193,34 @@ net_args()
fi
}
# Vital Product data
vpd_args()
{
[ "$CONFIG_QEMU_VPD" = "y" ] || return
vpd_file="${imgdir}/vpd"
if ! [ -f "$vpd_file" ]; then
onieprom="${imgdir}/onieprom"
# This is you QEMU factory/default password:
pwhash=$(echo -n "admin" | mkpasswd -s -m sha256crypt)
cat <<EOF | "$onieprom" -e >"$vpd_file"
{
"manufacture-date": "$(date +"%d/%m/%Y %H:%M:%S")",
"vendor-extension": [
[
61046,
"{\"pwhash\":\"$pwhash\"}"
]
]
}
EOF
fi
echo -n "-fw_cfg name=opt/vpd,file=$vpd_file"
}
wdt_args()
{
echo -n "-device i6300esb -rtc clock=host"
@@ -201,7 +230,7 @@ run_qemu()
{
local qemu
read qemu <<EOF
$CONFIG_QEMU_MACHINE \
$CONFIG_QEMU_MACHINE -m $CONFIG_QEMU_MACHINE_RAM \
$(loader_args) \
$(rootfs_args) \
$(serial_args) \
@@ -209,6 +238,7 @@ run_qemu()
$(host_args) \
$(net_args) \
$(wdt_args) \
$(vpd_args) \
$CONFIG_QEMU_EXTRA
EOF
+218
View File
@@ -0,0 +1,218 @@
#!/usr/bin/env python3
import binascii
import struct
HDRMGC = b"TlvInfo"
HDRVER = 1
HDRFMT = ">7sxBH"
HDRLEN = struct.calcsize(HDRFMT)
CRCFMT = ">BBL"
CRCLEN = struct.calcsize(CRCFMT)
def pack_varstr(s, maxlen=0xff):
b = bytes(s, "ascii")
assert(len(b) <= maxlen)
return b
def unpack_varstr(b):
return b.decode("ascii")
def pack_u8(num):
return struct.pack("B", num)
def unpack_u8(b):
return struct.unpack("B", b)[0]
def pack_u16(num):
return struct.pack(">H", num)
def unpack_u16(b):
return struct.unpack(">H", b)[0]
def pack_u32(num):
return struct.pack(">L", num)
def unpack_u32(b):
return struct.unpack(">L", b)[0]
def pack_date(datestr):
assert(len(datestr) == 19)
return pack_varstr(datestr, 19)
def pack_country(cstr):
assert(len(cstr) == 2)
return pack_varstr(cstr, 2)
def pack_mac(macstr):
return struct.pack("6B", *[int(o, 16) for o in macstr.split(":")])
def unpack_mac(b):
o = struct.unpack("6B", b)
return f"{o[0]:02x}:{o[1]:02x}:{o[2]:02x}:{o[3]:02x}:{o[4]:02x}:{o[5]:02x}"
OPS = {
"varstr": (pack_varstr, unpack_varstr),
"u8": (pack_u8, unpack_u8),
"u16": (pack_u16, unpack_u16),
"u32": (pack_u32, unpack_u32),
"date": (pack_date, unpack_varstr),
"country": (pack_country, unpack_varstr),
"mac": (pack_mac, unpack_mac),
}
TLV = (
{ "type": 0x21, "name": "product-name", "ops": "varstr" },
{ "type": 0x22, "name": "part-number", "ops": "varstr" },
{ "type": 0x23, "name": "serial-number", "ops": "varstr" },
{ "type": 0x24, "name": "mac-address", "ops": "mac" },
{ "type": 0x25, "name": "manufacture-date", "ops": "date" },
{ "type": 0x26, "name": "device-version", "ops": "u8" },
{ "type": 0x27, "name": "label-revision", "ops": "varstr" },
{ "type": 0x28, "name": "platform-name", "ops": "varstr" },
{ "type": 0x29, "name": "onie-version", "ops": "varstr" },
{ "type": 0x2a, "name": "num-macs", "ops": "u16" },
{ "type": 0x2b, "name": "manufacturer", "ops": "varstr" },
{ "type": 0x2c, "name": "country-code", "ops": "country" },
{ "type": 0x2d, "name": "vendor", "ops": "varstr" },
{ "type": 0x2e, "name": "diag-version", "ops": "varstr" },
{ "type": 0x2f, "name": "service-tag", "ops": "varstr" },
)
TLV_VENDOR_EXTENSION = 0xfd
TLV_CRC32 = 0xfe
def _tlv_by_lambda(fn):
info = next(filter(fn, TLV))
if "ops" in info:
return info, OPS[info["ops"]]
else:
return info
def tlv_by_name(name):
try:
return _tlv_by_lambda(lambda info: info["name"] == name)
except StopIteration:
raise ValueError(f"Unknown type name \"{name}\"")
def tlv_by_type(t):
try:
return _tlv_by_lambda(lambda info: info["type"] == t)
except StopIteration:
raise ValueError(f"Unknown type id {t}")
def into_tlv(d):
def pack_vendor(exts):
out = b""
for (iana_pen, val) in exts:
b = bytes(val, "utf-8")
l = len(b) + struct.calcsize(">L")
assert(l <= 0xff)
out += struct.pack(">BBL", TLV_VENDOR_EXTENSION, l, iana_pen) + b
return out
out = b""
# Generate all optional data
for (k, v) in sorted(d.items()):
if k == "vendor-extension":
out += pack_vendor(v)
else:
info, (pack, _) = tlv_by_name(k)
val = pack(v)
out += struct.pack("BB", info["type"], len(val)) + val
# Prepend the header now that we know the total length of the
# optional fields - make sure sure to include the CRC TLV length,
# which is appended in the last step
out = struct.pack(HDRFMT, HDRMGC, HDRVER, len(out) + CRCLEN) + out
out += struct.pack("BB", TLV_CRC32, struct.calcsize(">L"))
out += struct.pack(">L", binascii.crc32(out))
return out
def from_tlv(f):
d = {}
def unpack_vendor(ext):
head, tail = ext[:4], ext[4:]
iana_pen = struct.unpack(">L", head)[0]
val = tail.decode("utf-8")
if "vendor-extension" not in d:
d["vendor-extension"] = []
d["vendor-extension"].append([iana_pen, val])
head = f.read(HDRLEN)
magic, ver, l = struct.unpack(HDRFMT, head)
assert(magic == HDRMGC)
assert(ver == 1)
tail = f.read(l)
b = head + tail
assert(len(b) >= HDRLEN + l)
crcoffs = HDRLEN + l - CRCLEN
t, l, v = struct.unpack(CRCFMT, b[crcoffs:crcoffs+CRCLEN])
assert(t == TLV_CRC32)
assert(v == binascii.crc32(b[:crcoffs + struct.calcsize("BB")]))
while len(tail) >= 2:
t, l = struct.unpack("BB", tail[:2])
v = tail[2:l+2]
tail = tail[l+2:]
if t == TLV_VENDOR_EXTENSION:
unpack_vendor(v)
continue
elif t == TLV_CRC32:
break
info, (_, unpack) = tlv_by_type(t)
d[info["name"]] = unpack(v)
return d
if __name__ == "__main__":
import argparse
import json
import os
import sys
parser = argparse.ArgumentParser(prog='onieprom')
parser.add_argument("infile", nargs="?", default=sys.stdin, type=argparse.FileType("rb", 0))
parser.add_argument("outfile", nargs="?", default=sys.stdout, type=argparse.FileType("wb"))
parser.add_argument("-e", "--encode", default=False, action="store_true",
help="Encode JSON input to binary output")
parser.add_argument("-d", "--decode", default=False, action="store_true",
help="Decode binary input to JSON output")
args = parser.parse_args()
if (not args.encode) and (not args.decode):
c = args.infile.read(1)
args.infile.seek(0, 0)
if c == b"{":
args.encode = True
elif c == b"T":
args.decode = True
else:
sys.stderr.write("Neither encode nor decode specified, and could not infer operation from input")
sys.exit(1)
if args.encode:
args.outfile.buffer.write(into_tlv(json.load(args.infile)))
else:
args.outfile.write(json.dumps(from_tlv(args.infile)))
+13
View File
@@ -0,0 +1,13 @@
#!/bin/sh
Q=$@
/bin/echo -n "$Q, are you sure (y/N)? "
read -n1 yorn
echo
if [ x$yorn != "xy" ] && [ x$yorn != "xY" ]; then
echo "OK, aborting."
exit 1
fi
exit 0
@@ -1,141 +0,0 @@
_cond()
{
initctl -pt cond dump | awk '{print $4}' | sed 's/<\(.*\)>/\1/'
}
_ident()
{
if [ -n "$1" ]; then
initctl ident | grep -q $1
else
initctl ident
fi
}
_svc()
{
initctl ls -pt | grep $1 | sed "s/.*\/\(.*\)/\1/g" | sort -u
}
_enabled()
{
echo "$(_svc enabled)"
}
_available()
{
all=$(mktemp)
ena=$(mktemp)
echo "$(_svc available)" >$all
echo "$(_svc enabled)" >$ena
grep -v -f $ena $all
rm $all $ena
}
# Determine first non-option word. Usually the command
_firstword() {
local firstword i
firstword=
for ((i = 1; i < ${#COMP_WORDS[@]}; ++i)); do
if [[ ${COMP_WORDS[i]} != -* ]]; then
firstword=${COMP_WORDS[i]}
break
fi
done
echo $firstword
}
# Determine last non-option word. Uusally a sub-command
_lastword() {
local lastword i
lastword=
for ((i = 1; i < ${#COMP_WORDS[@]}; ++i)); do
if [[ ${COMP_WORDS[i]} != -* ]] && [[ -n ${COMP_WORDS[i]} ]] && [[ ${COMP_WORDS[i]} != $cur ]]; then
lastword=${COMP_WORDS[i]}
fi
done
echo $lastword
}
_initctl()
{
local cur command
cur=${COMP_WORDS[COMP_CWORD]}
prev="${COMP_WORDS[COMP_CWORD-1]}"
firstword=$(_firstword)
lastword=$(_lastword)
commands="status cond debug help kill ls log version list enable \
disable touch show cat edit create delete reload start \
stop restart signal cgroup ps top plugins runlevel reboot \
halt poweroff suspend utmp"
cond_cmds="set get clear status dump"
cond_types="hook net pid service task usr"
signals="int term hup stop tstp cont usr1 usr2 pwr"
options="-b --batch \
-c --create \
-d --debug \
-f --force \
-h --help \
-j --json \
-n --noerr \
-1 --once \
-p --plain \
-q --quiet \
-t --no-heading \
-v --verbose \
-V --version"
case "${firstword}" in
enable)
COMPREPLY=($(compgen -W "$(_available)" -- $cur))
;;
disable|touch)
COMPREPLY=($(compgen -W "$(_enabled)" -- $cur))
;;
show|cat|edit|delete)
COMPREPLY=($(compgen -W "$(_svc .)" -- $cur))
;;
start|stop|restart|log|status)
COMPREPLY=($(compgen -W "$(_ident)" -- $cur))
;;
signal|kill)
if $(_ident "${prev}"); then
COMPREPLY=($(compgen -W "$signals" -- $cur))
else
COMPREPLY=($(compgen -W "$(_ident)" -- $cur))
fi
;;
cond)
case "${lastword}" in
set|clear)
compopt -o nospace
COMPREPLY=($(compgen -W "usr/" -- $cur))
;;
get)
COMPREPLY=($(compgen -W "$(_cond)" -- $cur))
;;
dump)
COMPREPLY=($(compgen -W "$cond_types" -- $cur))
;;
*)
COMPREPLY=($(compgen -W "$cond_cmds" -- $cur))
;;
esac
;;
*)
COMPREPLY=($(compgen -W "$commands" -- $cur))
;;
esac
if [[ $cur == -* ]]; then
COMPREPLY=($(compgen -W "$options" -- $cur))
fi
}
complete -F _initctl initctl
@@ -1,3 +1,3 @@
run [S] /lib/infix/probe -- Probing system information
run [S] log:console /lib/infix/probe -- Probing system information
run [S] <pid/syslogd> /lib/infix/sysctl-sync-ip-conf --
run [S] <pid/syslogd> /lib/infix/nameif -- Probing network interfaces
@@ -1 +1,5 @@
service [2345789] log:prio:user.notice rauc service -- Software update service
set G_MESSAGES_DEBUG=nocolor
service [2345] <service/dbus/running> \
env:-/etc/default/rauc log:prio:user.notice \
rauc service $RAUC_ARGS -- Software update service
+2 -2
View File
@@ -1,5 +1,5 @@
# Override Finit plugin
service cgroup.system name:dbus pid:!/run/messagebus.pid <pid/syslogd> \
[S123456789] /usr/bin/dbus-daemon --nofork --system --syslog-only \
service cgroup.system name:dbus notify:none pid:!/run/messagebus.pid \
[S123456789] <pid/syslogd> /usr/bin/dbus-daemon --nofork --system --syslog-only \
-- D-Bus message bus daemon
-122
View File
@@ -1,122 +0,0 @@
#user nobody;
worker_processes 1;
#error_log logs/error.log;
#error_log logs/error.log notice;
#error_log logs/error.log info;
#pid logs/nginx.pid;
events {
worker_connections 1024;
}
http {
include mime.types;
default_type application/octet-stream;
#log_format main '$remote_addr - $remote_user [$time_local] "$request" '
# '$status $body_bytes_sent "$http_referer" '
# '"$http_user_agent" "$http_x_forwarded_for"';
#access_log logs/access.log main;
sendfile on;
#tcp_nopush on;
#keepalive_timeout 0;
keepalive_timeout 65;
#gzip on;
server {
listen 80;
server_name localhost;
#charset koi8-r;
#access_log logs/host.access.log main;
location / {
root html;
index index.html index.htm;
}
location /restconf/ {
fastcgi_pass unix:/var/run/clixon/restconf.sock;
include fastcgi_params;
}
#error_page 404 /404.html;
# redirect server error pages to the static page /50x.html
#
error_page 500 502 503 504 /50x.html;
location = /50x.html {
root html;
}
# proxy the PHP scripts to Apache listening on 127.0.0.1:80
#
#location ~ \.php$ {
# proxy_pass http://127.0.0.1;
#}
# pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000
#
#location ~ \.php$ {
# root html;
# fastcgi_pass 127.0.0.1:9000;
# fastcgi_index index.php;
# fastcgi_param SCRIPT_FILENAME /scripts$fastcgi_script_name;
# include fastcgi_params;
#}
# deny access to .htaccess files, if Apache's document root
# concurs with nginx's one
#
#location ~ /\.ht {
# deny all;
#}
}
# another virtual host using mix of IP-, name-, and port-based configuration
#
#server {
# listen 8000;
# listen somename:8080;
# server_name somename alias another.alias;
# location / {
# root html;
# index index.html index.htm;
# }
#}
# HTTPS server
#
#server {
# listen 443 ssl;
# server_name localhost;
# ssl_certificate cert.pem;
# ssl_certificate_key cert.key;
# ssl_session_cache shared:SSL:1m;
# ssl_session_timeout 5m;
# ssl_ciphers HIGH:!aNULL:!MD5;
# ssl_prefer_server_ciphers on;
# location / {
# root html;
# index index.html index.htm;
# }
#}
}
@@ -0,0 +1 @@
Banner /etc/banner
@@ -0,0 +1 @@
local0.* -/var/log/upgrade.log
+43 -28
View File
@@ -17,10 +17,37 @@
set -e
nm=$(basename $0)
nm=$(basename "$0")
err=0
opt="-k"
# External button or bootloader changed kernel command line
check_factory()
{
if [ -f /mnt/cfg/infix/.reset ]; then
return 0;
fi
if grep -q 'finit.cond=factory-reset' /proc/cmdline; then
return 0;
fi
# Add to your br2-external to extend factory-reset check
if [ ! -x /lib/infix/check-factory ]; then
return 1;
fi
/lib/infix/check-factory
}
factory_reset()
{
# XXX: flash LEDs to confirm factory-reset in progress
logger $opt -p user.crit -t "$nm" "Resetting to factory defaults."
rm -rf /mnt/cfg/* /mnt/var/*
sync
}
mount_rw()
{
# If something is already setup, leave it be.
@@ -60,6 +87,10 @@ mount_overlay()
mkdir -p -m 0755 "$u"
mkdir -p -m 0755 "$w"
# Ensure that all users in wheel can create the .reset file
# on /cfg and upload docker images to /var
chgrp wheel "$(dirname "$u")"
mount -t overlay "$tag-overlay" "$dst" \
-o lowerdir="$dst",upperdir="$u",workdir="$w"
}
@@ -78,12 +109,8 @@ varsrc=/mnt/var
if ! mount_rw var >/dev/null 2>&1; then
logger $opt -p user.warn -t "$nm" \
"No persistent storage found for /var, only /var/lib is persisted."
varsrc=/mnt/tmp
varsrc=/mnt/tmp/infix/var
vlibsrc=/mnt/cfg/vlib
else
mount_bind "$varsrc" /var
varsrc=
vlibsrc=
fi
cfgsrc=/mnt/cfg
@@ -100,35 +127,23 @@ if ! mount_rw cfg >/dev/null 2>&1; then
# there's no point in overlaying one ramdisk on top of another.
vlibsrc=
else
# Check for factory reset
if [ -f /mnt/cfg/infix/.reset ]; then
logger $opt -p user.crit -t "$nm" "Resetting to factory defaults."
rm -rf /mnt/cfg/infix /mnt/var/infix
sync
fi
# Check build: NETCONF or Classic
# Classic Infix has read-write /etc across boots
if [ "$VARIANT_ID" != "netconf" ]; then
etcsrc=/mnt/cfg
fi
# Ensure that all users in wheel can create the .reset file
mkdir -p /mnt/cfg/infix
chgrp wheel /mnt/cfg/infix
fi
mount_overlay cfg $cfgsrc /cfg
mount_overlay etc $etcsrc /etc
mount_overlay home $cfgsrc /home
mount_overlay root $cfgsrc /root
if check_factory; then
factory_reset
fi
[ "$varsrc" ] && mount_overlay var "$varsrc" /var
[ "$vlibsrc" ] && mount_bind "$vlibsrc" /var/lib
mount_overlay cfg "$cfgsrc" /cfg
mount_overlay etc "$etcsrc" /etc
mount_overlay home "$cfgsrc" /home
mount_overlay root "$cfgsrc" /root
mount_bind "$varsrc" /var
# Keep transient configs in a ramdisk and symlink out to /cfg for
# startup.
mkdir -p /mnt/tmp/infix/db
ln -s /cfg/startup_db /mnt/tmp/infix/db/startup_db
[ "$vlibsrc" ] && mount_bind "$vlibsrc" /var/lib
for tag in $(ls /sys/bus/virtio/devices/*/mount_tag 2>/dev/null); do
if [ "$(cat $tag | tr -d '\0')" = hostfs ]; then
+266 -5
View File
@@ -1,6 +1,267 @@
#!/bin/sh
# Probe for various types of harware features
#!/usr/bin/env python3
if dmesg |grep -q QEMU || test -d /sys/module/qemu_fw_cfg; then
initctl cond set qemu
fi
import importlib.machinery
import json
import os
import struct
import subprocess
import sys
onieprom = importlib.machinery.SourceFileLoader("onieprom","/bin/onieprom").load_module()
KKIT_IANA_PEM = 61046
class DTSystem:
BASE = "/sys/firmware/devicetree/base"
INFIX = BASE + "/chosen/infix"
def __init__(self):
self.vpdseq = 0
dt = {}
for root, _, files in os.walk(DTSystem.BASE):
if "phandle" not in files:
continue
phandle = os.path.join(root, "phandle")
if not os.path.exists(phandle):
continue
ph, = struct.unpack(">L", open(phandle, "rb").read())
dt[ph] = root
sys = {}
for root, dirs, _ in os.walk("/sys/devices"):
if "of_node" not in dirs:
continue
phandle = os.path.join(root, "of_node", "phandle")
if not os.path.exists(phandle):
continue
ph, = struct.unpack(">L", open(phandle, "rb").read())
sys[ph] = root
phs = set(list(dt.keys()) + list(sys.keys()))
self.devs = { ph: Device(ph, dt.get(ph), sys.get(ph)) for ph in phs }
self.base = Device(0, None, DTSystem.BASE)
self.infix = Device(0, None, DTSystem.INFIX)
def __get_phandle_array(self, name):
path = os.path.join(DTSystem.INFIX, name)
if not os.path.exists(path):
return ()
data = open(path, "rb").read()
elems = len(data) // struct.calcsize(">L")
return struct.unpack(">" + elems * "L", data)
def device_from_ph(self, ph):
return self.devs.get(ph)
def into_vpd(self, dev):
def parse():
if not dev.available():
return {}
try:
data = onieprom.from_tlv(open(dev.attrpath("nvmem"), "rb", 0))
except:
data = {}
return data
self.vpdseq += 1
return {
"board": dev.dtstr("infix,board", f"UNKNOWN{self.vpdseq}"),
"available": dev.available(),
"trusted": dev.hasdtattr("infix,trusted"),
"data": parse(),
}
def infix_devices(self, kind):
phs = self.__get_phandle_array(kind)
return [self.device_from_ph(ph) for ph in phs]
def infix_vpds(self):
return [self.into_vpd(dev) for dev in self.infix_devices("vpds")]
class QEMUSystem:
BASE = "/sys/firmware/qemu_fw_cfg"
REV = BASE + "/rev"
VPD = BASE + "/by_name/opt/vpd/raw"
def product_vpd(self):
data = {}
if os.path.exists(QEMUSystem.VPD):
try:
data = onieprom.from_tlv(open(QEMUSystem.VPD, "rb", 0))
except:
pass
return {
"board": "product",
"available": os.path.exists(QEMUSystem.VPD),
"trusted": True,
"data": data,
}
def vpds(self):
return [self.product_vpd()]
class Device:
def __init__(self, ph, dtpath, syspath):
self.ph, self.dtpath, self.syspath = ph, dtpath, syspath
def available(self):
return self.syspath != None
def __getitem__(self, attr):
return self.attr(attr).decode("utf-8").strip("\0")
def __setitem__(self, attr, value):
return self.attr(attr, val=value.encode("utf-8"))
def attrpath(self, attr):
return os.path.join(self.syspath, attr)
def hasattr(self, attr):
return os.path.exists(self.attrpath(attr))
def attr(self, attr, default=None, val=None):
if not self.hasattr(attr):
return default if val == None else False
if val:
open(self.attrpath(attr), "wb").write(value)
return True
return open(self.attrpath(attr), "rb").read()
def str(self, attr, default=None):
val = self.attr(attr)
return val.decode("utf-8").strip("\0") if val else default
def dtattrpath(self, attr):
return os.path.join(self.dtpath, attr)
def hasdtattr(self, attr):
return os.path.exists(self.dtattrpath(attr))
def dtattr(self, attr, default=None):
if not self.hasdtattr(attr):
return default
return open(self.dtattrpath(attr), "rb").read()
def dtstr(self, attr, default=None):
val = self.dtattr(attr)
return val.decode("utf-8").strip("\0") if val else default
def vpd_get_json_ve(vpd, pem):
ves = vpd["data"].get("vendor-extension")
if not ves:
return {}
out = {}
for ve in filter(lambda ve: ve[0] == pem, ves):
out.update(json.loads(ve[1]))
return out
def vpd_get_pwhash(vpd):
if not vpd.get("trusted"):
return None
kkit = vpd_get_json_ve(vpd, KKIT_IANA_PEM)
return kkit.get("pwhash")
def vpd_inject(out, vpds):
out["vpd"] = { vpd["board"]: vpd for vpd in vpds }
product = out["vpd"].get("product", {}).get("data", {})
hoistattrs = ("vendor", "product-name", "part-number", "serial-number", "mac-address")
for attr in hoistattrs:
if attr in product:
out[attr] = product[attr]
for vpd in vpds:
pwhash = vpd_get_pwhash(vpd)
if pwhash:
out["factory-password-hash"] = pwhash
break
def probe_qemusystem(out):
ADMINHASH = "$5$mI/zpOAqZYKLC2WU$i7iPzZiIjOjrBF3NyftS9CCq8dfYwHwrmUK097Jca9A"
qsys = QEMUSystem()
vpds = qsys.vpds()
vpd_inject(out, vpds)
for (attr, default) in (
("vendor", "QEMU"),
("product-name", "VM"),
):
if not out[attr]:
out[attr] = default
if not out["factory-password-hash"] and \
not out["vpd"]["product"]["available"]:
# Virtual instance without VPD emulation, fallback to
# admin/admin
out["factory-password-hash"] = ADMINHASH
# Let others react to the fact that we are running in QEMU
subprocess.run("initctl -nbq cond set qemu".split())
return 0
def probe_dtsystem(out):
dtsys = DTSystem()
vpds = dtsys.infix_vpds()
model = dtsys.base.str("model")
if model:
out["product-name"] = model
staticpw = dtsys.infix.str("factory-password-hash")
if not out["factory-password-hash"]:
out["factory-password-hash"] = staticpw
vpd_inject(out, vpds)
return 0
def main():
out = {
"vendor": None,
"product-name": None,
"part-number": None,
"serial-number": None,
"mac-address": None,
"factory-password-hash": None,
"vpd": {}
}
vpds = []
if os.path.exists(QEMUSystem.REV):
err = probe_qemusystem(out)
elif os.path.exists(DTSystem.BASE):
err = probe_dtsystem(out)
else:
return 1
if err:
return err
if not out["factory-password-hash"]:
sys.stdout.write("\n\n\033[31mCRITICAL BOOTSTRAP ERROR\nNO FACTORY PASSWORD FOUND\033[0m\n\n")
err = 1
json.dump(out, open("/run/system.json", "w"))
os.chmod("/run/system.json", 0o444)
return err
if __name__ == "__main__":
sys.exit(main())
+38
View File
@@ -0,0 +1,38 @@
#!/bin/sh
set -e
disk=$1
bootoffs=$2
bootsize=8M
auxsize=8M
total=$(awk -vdisk="$(basename $disk)" '$4 == disk { print($3 / 1024); }' /proc/partitions)
if [ "$total" -ge 4096 ]; then
imgsize=1024M
cfgsize=512M
elif [ "$total" -ge 2048 ]; then
imgsize=512M
cfgsize=256M
elif [ "$total" -ge 1024 ]; then
imgsize=256M
cfgsize=64M
elif [ "$total" -ge 512 ]; then
imgsize=192M
cfgsize=16M
else
echo "$disk is only ${total}M, at least 512M is required" >2
exit 1
fi
sgdisk \
-o \
-n1:${bootoffs}:+${bootsize} -t1:8301 -c1:boot \
-n2::+${auxsize} -t2:8301 -c2:aux \
-n3::+${imgsize} -t3:8300 -c3:primary \
-n4::+${imgsize} -t4:8300 -c4:secondary \
-n5::+${cfgsize} -t5:8302 -c5:cfg \
-n6:: -t6:8310 -c6:var \
-p \
$disk
+115
View File
@@ -0,0 +1,115 @@
#!/bin/sh
set -e
progname="$0"
usage()
{
cat <<EOF
Usage: ${progname} <url-to-pkg> <block-dev>
Provision Infix to a system (typically netbooted) with a blank block
device
- Downloads an Infix install bundle, using curl(1)
- Creates an Infix compatible partition table on the block device
- Initializes auxiliary and configuration filesystems and metadata
- Installs Infix to both primary and secondary partitions
EOF
}
step()
{
current="$*"
printf "\e[37;44m>>> %-60s\e[0m\n" "${current} ..." >&2
}
ok()
{
printf "\e[37;42m<<< %-56s OK\e[0m\n\n" "${current}" >&2
}
err()
{
printf "\e[37;41m!!! %-56s ERR\e[0m\n\n" "${current}" >&2
exit 1
}
while getopts "h" opt; do
case ${opt} in
h)
usage && exit 0
;;
esac
done
shift $((OPTIND - 1))
if [ $# -lt 2 ]; then
usage && exit 1
fi
url=$1
blk=$2
pkg=/tmp/pkg
step "Downloading $url"
curl -o $pkg $url || err
rauc info $pkg || err
ok
step "Formatting $blk"
[ -b $blk ] || { echo "$blk is not a block device" >&2; err; }
/lib/infix/prod/fdisk $blk || err
sleep 1
ok
for part in aux cfg var; do
step "Creating $part filesystem"
mkfs.ext4 -F -L $part /dev/disk/by-partlabel/$part || err
mount /mnt/$part || err
ok
done
step "Bootstrapping aux partition"
if [ -f /etc/fw_env.config ]; then
size_n_file=$(awk '{ print("-s", $3, "-o", $1); }' /etc/fw_env.config)
mkenvimage $size_n_file - <<EOF
BOOT_ORDER=primary secondary net
BOOT_primary_LEFT=1
BOOT_secondary_LEFT=1
BOOT_net_LEFT=1
EOF
fi
ok
step "Preparing installation"
rm -f /tmp/rauc
[ -f /etc/default/rauc ] && cp /etc/default/rauc /tmp/rauc
ok
step "Installing to primary partition"
echo "RAUC_ARGS=--override-boot-slot=secondary" >/etc/default/rauc
initctl -b restart rauc || err
rauc install $pkg || err
ok
step "Installing to secondary partition"
echo "RAUC_ARGS=--override-boot-slot=primary" >/etc/default/rauc
initctl -b restart rauc || err
rauc install $pkg || err
ok
step "Finishing installation"
rm /etc/default/rauc
[ -f /tmp/rauc ] && cp /tmp/rauc /etc/default/rauc
initctl -b restart rauc || err
rauc status mark-active rootfs.0
rauc status --detailed
ok
@@ -87,7 +87,7 @@ case "$ACTION" in
# format: dest1/mask gw1 ... destn/mask gwn
set -- $staticroutes
while [ -n "$1" -a -n "$2" ]; do
route add -net "$1" gw "$2" dev "$interface"
ip route add -net "$1" via "$2" dev "$interface" proto 16
shift 2
done
elif [ -n "$router" ] ; then
@@ -97,7 +97,7 @@ case "$ACTION" in
done
for i in $router ; do
route add default gw $i dev $interface
ip route add default via $i dev $interface proto 16
done
fi
+5 -1
View File
@@ -8,9 +8,13 @@
&env {
vendor = "infix";
bootdelay = "-2";
bootcmd = "run ixboot";
bootcmd = "run ixbtn";
boot_targets = "virtio mmc";
ixbtn = /incbin/("scripts/ixbtn.sh");
ixdevmode = /incbin/("scripts/ixdevmode.sh");
ixfactory = /incbin/("scripts/ixfactory.sh");
ixbtn = /incbin/("scripts/ixbtn.sh");
ixboot = /incbin/("scripts/ixboot.sh");
ixbootmedia = /incbin/("scripts/ixbootmedia.sh");
ixbootslot = /incbin/("scripts/ixbootslot.sh");
+11 -1
View File
@@ -1,3 +1,5 @@
setenv valid_media no
for tgt in "${boot_targets}"; do
if test "${tgt}" = "mmc0"; then
setenv devtype "mmc"
@@ -17,7 +19,7 @@ for tgt in "${boot_targets}"; do
env import -b ${loadaddr} ${filesize} BOOT_ORDER DEBUG
fi
test -n "${BOOT_ORDER}" || setenv BOOT_ORDER "primary secondary dhcp"
test -n "${BOOT_ORDER}" || setenv BOOT_ORDER "primary secondary net"
if test -n "${DEBUG}"; then
setenv bootargs_log "debug"
@@ -25,8 +27,16 @@ for tgt in "${boot_targets}"; do
setenv bootargs_log "loglevel=4"
fi
setenv valid_media yes
run ixbootmedia
fi
done
if test "${valid_media}" = "no"; then
echo "NO BOOTABLE MEDIA FOUND, falling back to netboot"
setenv BOOT_ORDER "net"
setenv bootargs_log "debug"
run ixbootmedia
fi
reset
+7 -1
View File
@@ -14,7 +14,13 @@ if test "${prepared}" = "ok"; then
if iminfo ${ramdisk_addr_r}; then
echo "${slot}: Booting..."
setenv bootargs_rauc "rauc.slot=${slot}"
setenv bootargs_user "rauc.slot=${slot}"
if test "${factory_reset}" = "yes"; then
setenv bootargs_user "${bootargs_user} finit.cond=factory-reset"
fi
if test "${dev_mode}" = "yes"; then
setenv bootargs_user "${bootargs_user} finit.cond=dev-mode"
fi
blkmap create boot
blkmap get boot dev blkmapnum
+13
View File
@@ -0,0 +1,13 @@
setenv dev_mode no
setenv factory_reset no
echo -n "dev-mode: "
run ixdevmode
echo -n "factory-reset: "
run ixfactory
if test "${dev_mode}" = "yes"; then
sleep 1 && run ixboot
else
run ixboot
fi
+3
View File
@@ -0,0 +1,3 @@
if button dev-mode; then
setenv dev_mode yes
fi
+7
View File
@@ -0,0 +1,7 @@
if button factory-reset; then
echo "Keep button pressed for 10 seconds to engage reset"
if sleep 10 && button factory-reset; then
setenv factory_reset yes
echo "FACTORY RESET ENGAGED"
fi
fi
-1
View File
@@ -1 +0,0 @@
../usr/bin/klish
+3
View File
@@ -0,0 +1,3 @@
#!/bin/bash -li
# Source settings, aliases, and probe terminal size, then hand over to klish
exec /usr/bin/klish
+88
View File
@@ -0,0 +1,88 @@
#!/bin/sh
# This file is part of avahi.
#
# avahi is free software; you can redistribute it and/or modify it
# under the terms of the GNU Lesser General Public License as
# published by the Free Software Foundation; either version 2 of the
# License, or (at your option) any later version.
#
# avahi is distributed in the hope that it will be useful, but WITHOUT
# ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
# or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public
# License for more details.
#
# You should have received a copy of the GNU Lesser General Public
# License along with avahi; if not, write to the Free Software
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307
# USA.
set -e
# Command line arguments:
# $1 event that happened:
# BIND: Successfully claimed address
# CONFLICT: An IP address conflict happened
# UNBIND: The IP address is no longer needed
# STOP: The daemon is terminating
# $2 interface name
# $3 IP adddress
PATH="$PATH:/usr/bin:/usr/sbin:/bin:/sbin"
# Use a different metric for each interface, so that we can set
# identical routes to multiple interfaces.
METRIC=$((1000 + `cat "/sys/class/net/$2/ifindex" 2>/dev/null || echo 0`))
if [ -x /bin/ip -o -x /sbin/ip ] ; then
# We have the Linux ip tool from the iproute package
case "$1" in
BIND)
ip addr flush dev "$2" label "$2:avahi"
ip addr add "$3"/16 brd 169.254.255.255 label "$2:avahi" scope link dev "$2" proto 6
ip route add default dev "$2" metric "$METRIC" scope link proto 17 ||:
;;
CONFLICT|UNBIND|STOP)
ip route del default dev "$2" metric "$METRIC" scope link ||:
ip addr del "$3"/16 brd 169.254.255.255 label "$2:avahi" scope link dev "$2"
;;
*)
echo "Unknown event $1" >&2
exit 1
;;
esac
elif [ -x /bin/ifconfig -o -x /sbin/ifconfig ] ; then
# We have the old ifconfig tool
case "$1" in
BIND)
ifconfig "$2:avahi" inet "$3" netmask 255.255.0.0 broadcast 169.254.255.255 up
route add default dev "$2:avahi" metric "$METRIC" ||:
;;
CONFLICT|STOP|UNBIND)
route del default dev "$2:avahi" metric "$METRIC" ||:
ifconfig "$2:avahi" down
;;
*)
echo "Unknown event $1" >&2
exit 1
;;
esac
else
echo "No network configuration tool found." >&2
exit 1
fi
exit 0
+143
View File
@@ -0,0 +1,143 @@
{
"input": {
"path": {
"locate": { "path": "/run/led/locate" },
"status-prime": { "path": "/run/led/status-prime" },
"status-ok": { "path": "/run/led/status-ok" },
"status-err": { "path": "/run/led/status-err" },
"status-crit": { "path": "/run/led/status-crit" },
"fault-prime": { "path": "/run/led/fault-prime" },
"fault-ok": { "path": "/run/led/fault-ok" },
"fault-err": { "path": "/run/led/fault-err" },
"fault-crit": { "path": "/run/led/fault-crit" },
"lan-prime": { "path": "/run/led/lan-prime" },
"lan-ok": { "path": "/run/led/lan-ok" },
"lan-err": { "path": "/run/led/lan-err" },
"lan-crit": { "path": "/run/led/lan-crit" },
"startup": { "path": "/run/finit/cond/run/startup/success" },
"fail-safe": { "path": "/run/finit/cond/run/failure/success" },
"panic": { "path": "/run/finit/cond/run/failure/failure" }
},
"udev": {
"power-a": { "subsystem": "power_supply" },
"power-b": { "subsystem": "power_supply" }
}
},
"output": {
"led-group": {
"port-link-act": {
"match": ["*:green:tp", "*:green:sfp", "*:green:port" ],
"rules": [
{ "if": "true", "then": { "trigger": "netdev", "link": 1, "rx": 1, "tx": 1 } }
]
},
"port-alarm": {
"match": ["*:yellow:tp", "*:yellow:sfp", "*:yellow:port" ],
"rules": [
]
}
},
"led": {
"red:status": {
"rules": [
{ "if": "locate", "then": "@off" },
{ "if": "panic", "then": "@blink-5hz" },
{ "if": "status-crit", "then": "@blink-1hz" },
{ "if": "status-err", "then": "@on" }
]
},
"green:status": {
"rules": [
{ "if": "locate", "then": "@blink-1hz" },
{ "if": "status-prime", "then": "@blink-1hz" },
{ "if": "status-ok", "then": "@on" }
]
},
"red:fault": {
"rules": [
{ "if": "locate", "then": "@off" },
{ "if": "panic", "then": "@blink-5hz" },
{ "if": "fault-crit", "then": "@blink-1hz" },
{ "if": "fault-err", "then": "@on" }
]
},
"green:fault": {
"rules": [
{ "if": "locate", "then": "@blink-1hz" },
{ "if": "fault-prime", "then": "@blink-1hz" },
{ "if": "fault-ok", "then": "@on" }
]
},
"red:lan": {
"rules": [
{ "if": "locate", "then": "@off" },
{ "if": "panic", "then": "@blink-5hz" },
{ "if": "lan-crit", "then": "@blink-1hz" },
{ "if": "lan-err", "then": "@on" }
]
},
"green:lan": {
"rules": [
{ "if": "locate", "then": "@blink-1hz" },
{ "if": "lan-prime", "then": "@blink-1hz" },
{ "if": "lan-ok", "then": "@on" }
]
},
"red:boot": {
"rules": [
{ "if": "locate", "then": "@off" },
{ "if": "panic", "then": "@blink-5hz" },
{ "if": "fail-safe", "then": "@blink-5hz" }
]
},
"green:boot": {
"rules": [
{ "if": "locate", "then": "@blink-1hz" },
{ "if": "panic", "then": "@off" },
{ "if": "startup", "then": "@on" },
{ "if": "true", "then": "@blink-1hz" }
]
},
"red:power-a": {
"rules": [
{ "if": "panic", "then": "@blink-5hz" },
{ "if": "!power-a:online", "then": "@blink-1hz" }
]
},
"red:power-b": {
"rules": [
{ "if": "panic", "then": "@blink-5hz" },
{ "if": "!power-b:online", "then": "@blink-1hz" }
]
}
}
},
"aliases": {
"on": {
"brightness": true
},
"off": {
"brightness": false
},
"blink-1hz": {
"trigger": "timer",
"delay_on": 500,
"delay_off": 500
},
"blink-5hz": {
"trigger": "timer",
"delay_on": 100,
"delay_off": 100
}
}
}
@@ -0,0 +1 @@
17 zeroconf
+219 -23
View File
@@ -14,6 +14,19 @@ class Pad:
state = 12
data = 41
class PadRoute:
prefix = 30
protocol = 10
next_hop = 30
metric = 10
class PadSoftware:
name = 10
date = 25
hash = 64
state = 10
version = 23
class Decore():
@staticmethod
def decorate(sgr, txt, restore="0"):
@@ -31,12 +44,86 @@ class Decore():
def green(txt):
return Decore.decorate("32", txt, "39")
def get_json_data(default, indata, *args):
data = indata
for arg in args:
if arg in data:
data = data.get(arg)
else:
return default
return data
class Route:
def __init__(self,data):
self.data = data
self.prefix = data.get('ietf-ipv4-unicast-routing:destination-prefix', '')
self.protocol = data.get('source-protocol','')[14:]
self.metric = data.get('route-preference','')
interface = get_json_data(None, self.data, 'next-hop', 'outgoing-interface')
address = get_json_data(None, self.data, 'next-hop', 'ietf-ipv4-unicast-routing:next-hop-address')
special = get_json_data(None, self.data, 'next-hop', 'special-next-hop')
if interface:
self.next_hop = interface
elif address:
self.next_hop = address
elif special:
self.next_hop = special
else:
self.next_hop = "unspecified"
def print(self):
row = f"{self.prefix:<{PadRoute.prefix}}"
row += f"{self.next_hop:<{PadRoute.next_hop}}"
row += f"{self.metric:<{PadRoute.metric}}"
row += f"{self.protocol:<{PadRoute.protocol}}"
print(row)
class Software:
"""Software bundle class """
def __init__(self, data):
self.data = data
self.name = data.get('bootname', '')
self.size = data.get('size', '')
self.type = data.get('class', '')
self.hash = data.get('sha256', '')
self.state = data.get('state', '')
self.version = get_json_data('', self.data, 'bundle', 'version')
self.date = get_json_data('', self.data, 'installed', 'datetime')
def is_rootfs(self):
"""True if bundle type is 'rootfs'"""
return self.type == "rootfs"
def print(self):
"""Brief information about one bundle"""
row = f"{self.name:<{PadSoftware.name}}"
row += f"{self.state:<{PadSoftware.state}}"
row += f"{self.version:<{PadSoftware.version}}"
row += f"{self.date:<{PadSoftware.date}}"
print(row)
def detail(self):
"""Detailed information about one bundle"""
print(f"Name : {self.name}")
print(f"State : {self.state}")
print(f"Version : {self.version}")
print(f"Size : {self.size}")
print(f"SHA-256 : {self.hash}")
print(f"Installed : {self.date}")
class Iface:
def __init__(self, data):
self.data = data
self.name = data.get('name', '')
self.type = data.get('type', '')
self.index = data.get('if-index', '')
self.oper_status = data.get('oper-status', '')
self.autoneg = get_json_data('unknown', self.data, 'ieee802-ethernet-interface:ethernet',
'auto-negotiation', 'enable')
self.duplex = get_json_data('', self.data,'ieee802-ethernet-interface:ethernet','duplex')
self.speed = get_json_data('', self.data, 'ieee802-ethernet-interface:ethernet', 'speed')
self.phys_address = data.get('phys-address', '')
if data.get('statistics'):
@@ -46,8 +133,6 @@ class Iface:
self.in_octets = ''
self.out_octets = ''
self.parent = data.get('ietf-if-extensions:parent-interface', None)
if self.data.get('ietf-ip:ipv4'):
self.mtu = self.data.get('ietf-ip:ipv4').get('mtu', '')
self.ipv4_addr = self.data.get('ietf-ip:ipv4').get('address', '')
@@ -65,11 +150,19 @@ class Iface:
else:
self.bridge = ''
if self.data.get('infix-interfaces:vlan'):
self.lower_if = self.data.get('infix-interfaces:vlan', None).get('lower-layer-if',None)
else:
self.lower_if = ''
def is_vlan(self):
return self.data['type'] == "infix-if-type:vlan"
return self.type == "infix-if-type:vlan"
def is_bridge(self):
return self.data['type'] == "infix-if-type:bridge"
return self.type == "infix-if-type:bridge"
def is_veth(self):
return self.data['type'] == "infix-if-type:veth"
def pr_name(self, pipe=""):
print(f"{pipe}{self.name:<{Pad.iface - len(pipe)}}", end="")
@@ -97,7 +190,7 @@ class Iface:
row = f"{'ethernet':<{Pad.proto}}"
dec = Decore.green if self.oper_status == "up" else Decore.red
row += dec(f"{self.oper_status.upper():<{Pad.state}}")
row += f"{self.data['phys-address']:<{Pad.data}}"
row += f"{self.phys_address:<{Pad.data}}"
print(row)
def pr_bridge(self, _ifaces):
@@ -122,11 +215,25 @@ class Iface:
lower.pr_name(pipe)
lower.pr_proto_eth()
def pr_veth(self, _ifaces):
self.pr_name(pipe="")
self.pr_proto_eth()
if self.lower_if:
row = f"{'':<{Pad.iface}}"
row += f"{'veth':<{Pad.proto}}"
row += f"{'':<{Pad.state}}"
row += f"peer:{self.lower_if}"
print(row)
self.pr_proto_ipv4()
self.pr_proto_ipv6()
def pr_vlan(self, _ifaces):
self.pr_name(pipe="")
self.pr_proto_eth()
if self.parent:
if self.lower_if:
self.pr_proto_ipv4(pipe='│')
self.pr_proto_ipv6(pipe='│')
else:
@@ -134,7 +241,7 @@ class Iface:
self.pr_proto_ipv6()
return
parent = find_iface(_ifaces, self.parent)
parent = find_iface(_ifaces, self.lower_if)
if not parent:
print(f"Error, didn't find parent interface for vlan {self.name}")
sys.exit(1)
@@ -148,6 +255,21 @@ class Iface:
print(f"{'mtu':<{20}}: {self.mtu}")
if self.oper_status:
print(f"{'operational status':<{20}}: {self.oper_status}")
if self.lower_if:
print(f"{'lower-layer-if':<{20}}: {self.lower_if}")
if self.autoneg != 'unknown':
val = "on" if self.autoneg else "off"
print(f"{'auto-negotiation':<{20}}: {val}")
if self.duplex:
print(f"{'duplex':<{20}}: {self.duplex}")
if self.speed:
mbs = float(self.speed) * 1000
print(f"{'speed':<{20}}: {int(mbs)}")
if self.phys_address:
print(f"{'physical address':<{20}}: {self.phys_address}")
@@ -181,6 +303,13 @@ class Iface:
print(f"{'in-octets':<{20}}: {self.in_octets}")
print(f"{'out-octets':<{20}}: {self.out_octets}")
frame = get_json_data([], self.data,'ieee802-ethernet-interface:ethernet',
'statistics', 'frame')
if frame:
print(f"")
for key, val in frame.items():
print(f"eth-{key:<{25}}: {val}")
def find_iface(_ifaces, name):
for _iface in [Iface(data) for data in _ifaces]:
@@ -205,12 +334,16 @@ def pr_interface_list(json):
iface.pr_bridge(ifaces)
continue
if iface.is_veth():
iface.pr_veth(ifaces)
continue
if iface.is_vlan():
iface.pr_vlan(ifaces)
continue
# These interfaces are printed by there parent, such as bridge
if iface.parent:
if iface.lower_if:
continue
if iface.bridge:
continue
@@ -221,24 +354,87 @@ def pr_interface_list(json):
iface.pr_proto_ipv6()
def ietf_interfaces(json, name):
if not json or not json.get("ietf-interfaces:interfaces"):
print(f"Error, top level \"ietf-interfaces:interfaces\" missing")
if name:
if not json.get("ietf-interfaces:interfaces"):
print(f"No interface data found for \"{name}\"")
sys.exit(1)
iface = find_iface(json["ietf-interfaces:interfaces"]["interface"], name)
if not iface:
print(f"Interface \"{name}\" not found")
sys.exit(1)
iface.pr_iface()
else:
if not json.get("ietf-interfaces:interfaces"):
print(f"Error, top level \"ietf-interfaces:interfaces\" missing")
sys.exit(1)
pr_interface_list(json)
def ietf_routing(json, protocol="ipv4"):
if not json.get("ietf-routing:routing"):
print(f"Error, top level \"ietf-routing:routing\" missing")
sys.exit(1)
routes = get_json_data({}, json, 'ietf-routing:routing','ribs', 'rib')[0]
routes = get_json_data(None, routes, "routes", "route")
hdr = (f"{'PREFIX':<{PadRoute.prefix}}"
f"{'NEXT-HOP':<{PadRoute.next_hop}}"
f"{'METRIC':<{PadRoute.metric}}"
f"{'PROTOCOL':<{PadRoute.protocol}}")
print(Decore.invert(hdr))
if routes:
for r in routes:
route = Route(r)
route.print()
def find_slot(_slots, name):
for _slot in [Software(data) for data in _slots]:
if _slot.name == name:
return _slot
return False
def infix_system(json, name):
if not json.get("ietf-system:system-state", "infix-system:software"):
print("Error, cannot find infix-system:software")
sys.exit(1)
if not name:
return pr_interface_list(json)
slots = get_json_data({}, json, 'ietf-system:system-state', 'infix-system:software', 'slot')
if name:
slot = find_slot(slots, name)
if slot:
slot.detail()
else:
hdr = (f"{'NAME':<{PadSoftware.name}}"
f"{'STATE':<{PadSoftware.state}}"
f"{'VERSION':<{PadSoftware.version}}"
f"{'DATE':<{PadSoftware.date}}")
print(Decore.invert(hdr))
for _s in slots:
slot = Software(_s)
if slot.is_rootfs():
slot.print()
iface = find_iface(json["ietf-interfaces:interfaces"]["interface"], name)
if not iface:
print(f"Interface {name} not found")
def main():
try:
json_data = json.load(sys.stdin)
except json.JSONDecodeError:
print("Error, invalid JSON input")
sys.exit(1)
except Exception as e:
print("Error, unexpected error parsing JSON")
sys.exit(1)
return iface.pr_iface()
if args.module == "ietf-interfaces":
sys.exit(ietf_interfaces(json_data, args.name))
if args.module == "ietf-routing":
sys.exit(ietf_routing(json_data, args.name))
if args.module == "infix-system":
sys.exit(infix_system(json_data, args.name))
else:
print(f"Error, unknown module {args.module}")
sys.exit(1)
json = json.load(sys.stdin)
if args.module == "ietf-interfaces":
sys.exit(ietf_interfaces(json, args.name))
else:
print(f"Error, unknown module {args.module}")
sys.exit(1)
if __name__ == "__main__":
main()
+36
View File
@@ -0,0 +1,36 @@
#!/usr/bin/env python3
import subprocess
import sys
import json
def get_ethtool_output(interface):
try:
output = subprocess.check_output(['ethtool', interface], stderr=subprocess.DEVNULL, text=True)
return output.splitlines()
except subprocess.CalledProcessError:
print("Error: Failed to run ethtool on interface", interface)
sys.exit(1)
def parse_ethtool_output(lines, keys):
result = {}
for line in lines:
line = line.strip()
key = line.split(':', 1)[0].strip()
if key in keys:
key, value = line.split(':', 1)
result[key.strip()] = value.strip()
return result
if __name__ == "__main__":
if len(sys.argv) != 2:
print(f"Usage: {sys.argv[0]} INTERFACE")
sys.exit(1)
interface = sys.argv[1]
keys = ["Duplex", "Auto-negotiation"]
lines = get_ethtool_output(interface)
parsed_data = parse_ethtool_output(lines, keys)
print(json.dumps(parsed_data, indent=4))
+405
View File
@@ -0,0 +1,405 @@
#!/usr/bin/env python3
import subprocess
import json
import sys # (built-in module)
def json_get_yang_type(iface_in):
if iface_in['link_type'] == "loopback":
return "infix-if-type:loopback"
if iface_in['link_type'] != "ether":
return "infix-if-type:other";
if not 'linkinfo' in iface_in:
return "infix-if-type:ethernet"
if not 'info_kind' in iface_in['linkinfo']:
return "infix-if-type:ethernet";
if iface_in['linkinfo']['info_kind'] == "veth":
return "infix-if-type:veth";
if iface_in['linkinfo']['info_kind'] == "vlan":
return "infix-if-type:vlan";
if iface_in['linkinfo']['info_kind'] == "bridge":
return "infix-if-type:bridge";
if iface_in['linkinfo']['info_kind'] == "dsa":
return "infix-if-type:ethernet";
# Fallback
return "infix-if-type:ethernet";
def json_get_yang_origin(addr):
map = {
"kernel_ll": "link-layer",
"kernel_ra": "link-layer",
"static": "static",
"dhcp": "dhcp",
"random": "random",
}
proto = addr['protocol']
if proto == "kernel_ll" or proto == "kernel_ra":
if "stable-privacy" in addr:
return "random"
return map.get(proto, "other")
def get_proc_value(procfile):
try:
with open(procfile, 'r') as file:
data = file.read().strip()
return data
except FileNotFoundError:
# This is considered OK
return None
except IOError:
print(f"Error: reading from {procfile}", file=sys.stderr)
# This function returns a value from a nested json dict
def lookup(json, *keys):
curr = json
for key in keys:
if isinstance(curr, dict) and key in curr:
curr = curr[key]
else:
return None
return curr
# This function inserts a value into a nested json dict
def insert(json, *path_and_value):
if len(path_and_value) < 2:
raise ValueError("Error: insert() takes at least two args")
*path, value = path_and_value
curr = json
for key in path[:-1]:
if key not in curr or not isinstance(curr[key], dict):
curr[key] = {}
curr = curr[key]
curr[path[-1]] = value
def run_cmd(cmd):
try:
output = subprocess.check_output(cmd, stderr=subprocess.DEVNULL, text=True)
return output.splitlines()
except subprocess.CalledProcessError:
print(f"Error: command returned error", file=sys.stderr)
sys.exit(1)
def run_json_cmd(cmd):
try:
result = subprocess.run(cmd, check=True, stdout=subprocess.PIPE,
stderr=subprocess.PIPE, text=True)
output = result.stdout
data = json.loads(output)
except subprocess.CalledProcessError as e:
print(f"Error: unable to get data:", file=sys.stderr)
print(f"{e.stderr}", file=sys.stderr)
sys.exit(1)
except json.JSONDecodeError as e:
print(f"Error: parsing JSON output: {e.msg}", file=sys.stderr)
sys.exit(1)
return data
def iface_is_dsa(iface_in):
if not "linkinfo" in iface_in:
return False
if not "info_kind" in iface_in['linkinfo']:
return False
if iface_in['linkinfo']['info_kind'] != "dsa":
return False
return True
def add_ipv4_route(routes):
cmd = ['ip', '-4', '-s', '-d', '-j', 'route']
data = run_json_cmd(cmd)
out={}
out["route"] = []
for d in data:
new = {}
next_hop = {}
if(d['dst'] == "default"):
d['dst'] = "0.0.0.0/0"
if(d['dst'].find('/') == -1):
d['dst'] = d['dst']+"/32"
new['ietf-ipv4-unicast-routing:destination-prefix'] = d['dst']
new['source-protocol'] = "infix-routing:"+d['protocol']
if d.get("metric"):
new['route-preference'] = d['metric']
else:
new['route-preference'] = 0
if d['type'] == "blackhole":
next_hop['special-next-hop'] = "blackhole"
if d['type'] == "unreachable":
next_hop['special-next-hop'] = "unreachable"
if d['type'] == "unicast":
if(d.get("gateway")):
next_hop['ietf-ipv4-unicast-routing:next-hop-address'] = d['gateway']
elif(d.get("dev")):
next_hop['outgoing-interface'] = d['dev']
new['next-hop'] = next_hop
out['route'].append(new)
insert(routes, 'routes', out)
def add_ip_link(ifname, iface_out):
cmd = ['ip', '-s', '-d', '-j', 'link', 'show', 'dev', ifname]
data = run_json_cmd(cmd)
if len(data) != 1:
print(f"Error: expected ip link output to be array with length 1", file=sys.stderr)
sys,exit(1)
iface_in = data[0]
if 'ifname' in iface_in:
iface_out['name'] = iface_in['ifname']
if 'ifindex' in iface_in:
iface_out['if-index'] = iface_in['ifindex']
if 'address' in iface_in:
iface_out['phys-address'] = iface_in['address']
if 'master' in iface_in:
insert(iface_out, "infix-interfaces:bridge-port", "bridge", iface_in['master'])
if 'link' in iface_in and not iface_is_dsa(iface_in):
insert(iface_out, "infix-interfaces:vlan", "lower-layer-if", iface_in['link'])
if 'operstate' in iface_in:
map = {
"DOWN": "down",
"UP": "up",
"DORMANT": "dormant",
"TESTING": "testing",
"LOWERLAYERDOWN": "lower-layer-down",
"NOTPRESENT": "not-present"
}
val = map.get(iface_in['operstate'], "unknown")
iface_out['oper-status'] = val
if 'link_type' in iface_in:
val = json_get_yang_type(iface_in)
iface_out['type'] = val
val = lookup(iface_in, "stats64", "rx", "bytes")
if val is not None:
insert(iface_out, "statistics", "out-octets", str(val))
val = lookup(iface_in, "stats64", "tx", "bytes")
if val is not None:
insert(iface_out, "statistics", "in-octets", str(val))
def add_ip_addr(ifname, iface_out):
cmd = ['ip', '-j', 'addr', 'show', 'dev', ifname]
data = run_json_cmd(cmd)
if len(data) != 1:
print(f"Error: expected ip addr output to be array with length 1", file=sys.stderr)
sys,exit(1)
iface_in = data[0]
if 'mtu' in iface_in and ifname != "lo":
insert(iface_out, "ietf-ip:ipv4", "mtu", iface_in['mtu'])
# We avoid importing os to check if the file exists (for performance)
val = get_proc_value(f"/proc/sys/net/ipv6/conf/{ifname}/mtu")
if val is not None:
insert(iface_out, "ietf-ip:ipv6", "mtu", int(val))
if 'addr_info' in iface_in:
inet = []
inet6 = []
for addr in iface_in['addr_info']:
new = {}
if not 'family' in addr:
print(f"Error: 'family' missing from 'addr_info'", file=sys.stderr)
continue
if 'local' in addr:
new['ip'] = addr['local']
if 'prefixlen' in addr:
new['prefix-length'] = addr['prefixlen']
if 'protocol' in addr:
new['origin'] = json_get_yang_origin(addr)
if addr['family'] == "inet":
inet.append(new)
elif addr['family'] == "inet6":
inet6.append(new)
else:
print(f"Error: invalid 'family' in 'addr_info'", file=sys.stderr)
sys.exit(1)
insert(iface_out, "ietf-ip:ipv4", "address", inet)
insert(iface_out, "ietf-ip:ipv6", "address", inet6)
def add_ethtool_groups(ifname, iface_out):
cmd = ['ethtool', '--json', '-S', ifname, '--all-groups']
data = run_json_cmd(cmd)
if len(data) != 1:
print(f"Error: expected ethtool groups output to be array with length 1", file=sys.stderr)
sys,exit(1)
iface_in = data[0]
# TODO: room for improvement here, the "frame" creation could be more dynamic.
if "eth-mac" in iface_in or "rmon" in iface_in:
insert(iface_out, "ieee802-ethernet-interface:ethernet", "statistics", "frame", {})
frame = iface_out['ieee802-ethernet-interface:ethernet']['statistics']['frame']
if "eth-mac" in iface_in:
mac_in = iface_in['eth-mac']
if "FramesTransmittedOK" in mac_in:
frame['out-frames'] = str(mac_in['FramesTransmittedOK'])
if "MulticastFramesXmittedOK" in mac_in:
frame['out-multicast-frames'] = str(mac_in['MulticastFramesXmittedOK'])
if "BroadcastFramesXmittedOK" in mac_in:
frame['out-broadcast-frames'] = str(mac_in['BroadcastFramesXmittedOK'])
if "FramesReceivedOK" in mac_in:
frame['in-frames'] = str(mac_in['FramesReceivedOK'])
if "MulticastFramesReceivedOK" in mac_in:
frame['in-multicast-frames'] = str(mac_in['MulticastFramesReceivedOK'])
if "BroadcastFramesReceivedOK" in mac_in:
frame['in-broadcast-frames'] = str(mac_in['BroadcastFramesReceivedOK'])
if "FrameCheckSequenceErrors" in mac_in:
frame['in-error-fcs-frames'] = str(mac_in['FrameCheckSequenceErrors'])
if "FramesLostDueToIntMACRcvError" in mac_in:
frame['in-error-mac-internal-frames'] = str(mac_in['FramesLostDueToIntMACRcvError'])
tot = 0
found = False
if "FramesReceivedOK" in mac_in:
tot += mac_in['FramesReceivedOK']
found = True
if "FrameCheckSequenceErrors" in mac_in:
tot += mac_in['FrameCheckSequenceErrors']
found = True
if "FramesLostDueToIntMACRcvError" in mac_in:
tot += mac_in['FramesLostDueToIntMACRcvError']
found = True
if "AlignmentErrors" in mac_in:
tot += mac_in['AlignmentErrors']
found = True
if "etherStatsOversizePkts" in mac_in:
tot += mac_in['etherStatsOversizePkts']
found = True
if "etherStatsJabbers" in mac_in:
tot += mac_in['etherStatsJabbers']
found = True
if found:
frame['in-total-frames'] = str(tot)
if "rmon" in iface_in:
rmon_in = iface_in['rmon']
if "undersize_pkts" in rmon_in:
frame['in-error-undersize-frames'] = str(rmon_in['undersize_pkts'])
tot = 0
found = False
if "etherStatsJabbers" in rmon_in:
tot += rmon_in['etherStatsJabbers']
found = True
if "etherStatsOversizePkts" in rmon_in:
tot += rmon_in['etherStatsOversizePkts']
found = True
if found:
frame['in-error-oversize-frames'] = str(tot)
def add_ethtool_std(ifname, iface_out):
cmd = ['ethtool', ifname]
keys = ['Speed', 'Duplex', 'Auto-negotiation']
result = {}
lines = run_cmd(cmd)
for line in lines:
line = line.strip()
key = line.split(':', 1)[0].strip()
if key in keys:
key, value = line.split(':', 1)
result[key.strip()] = value.strip()
if "Auto-negotiation" in result:
if result['Auto-negotiation'] == "on":
insert(iface_out, "ieee802-ethernet-interface:ethernet", "auto-negotiation", "enable", True)
else:
insert(iface_out, "ieee802-ethernet-interface:ethernet", "auto-negotiation", "enable", False)
if "Duplex" in result:
if result['Duplex'] == "Half":
insert(iface_out, "ieee802-ethernet-interface:ethernet", "duplex", "half")
elif result['Duplex'] == "Full":
insert(iface_out, "ieee802-ethernet-interface:ethernet", "duplex", "full")
else:
insert(iface_out, "ieee802-ethernet-interface:ethernet", "duplex", "unknown")
if "Speed" in result and result['Speed'] != "Unknown!":
# Avoid importing re (performance)
num = ''.join(filter(str.isdigit, result['Speed']))
if num:
num = round((int(num) / 1000), 3)
insert(iface_out, "ieee802-ethernet-interface:ethernet", "speed", str(num))
if __name__ == "__main__":
if len(sys.argv) < 2:
print(f"usage: yanger <model> [params]", file=sys.stderr)
sys.exit(1)
model = sys.argv[1]
if(model == 'ietf-interfaces'):
# For now, we handle each interface separately, as this is how it's
# currently implemented in sysrepo. I.e sysrepo will subscribe to
# each individual interface and query it for YANG data.
if len(sys.argv) != 3:
print(f"usage: yanger ietf-interfaces IFNAME", file=sys.stderr)
sys.exit(1)
yang_data = {
"ietf-interfaces:interfaces": {
"interface": [{}]
}
}
ifname = sys.argv[2]
iface_out = yang_data['ietf-interfaces:interfaces']['interface'][0]
add_ip_link(ifname, iface_out)
add_ip_addr(ifname, iface_out)
add_ethtool_groups(ifname, iface_out)
add_ethtool_std(ifname, iface_out)
elif(model == 'ietf-routing'):
yang_data = {
"ietf-routing:routing": {
"ribs": {
"rib": [{
"name": "ipv4",
"address-family": "ipv4",
}]
}
}
}
ipv4routes = yang_data['ietf-routing:routing']['ribs']['rib'][0]
add_ipv4_route(ipv4routes);
else:
print(f"Unsupported model {model}", file=sys.stderr)
sys.exit(1)
print(json.dumps(yang_data, indent=2))
+2 -1
View File
@@ -1,5 +1,6 @@
test-dir := $(BR2_EXTERNAL_INFIX_PATH)/test
INFIX_TESTS ?= $(test-dir)/case/all-unit.yaml $(test-dir)/case/all.yaml
INFIX_TESTS ?= $(test-dir)/case/all-repo.yaml $(test-dir)/case/all-unit.yaml \
$(test-dir)/case/all.yaml
test-env = $(test-dir)/env \
-f $(BINARIES_DIR)/infix-x86_64.img \
+7
View File
@@ -229,6 +229,13 @@ CONFIG_USB_XHCI_HCD=y
CONFIG_USB_EHCI_HCD=y
CONFIG_USB_UHCI_HCD=y
CONFIG_USB_STORAGE=y
CONFIG_NEW_LEDS=y
CONFIG_LEDS_CLASS=y
CONFIG_LEDS_TRIGGERS=y
CONFIG_LEDS_TRIGGER_TIMER=y
CONFIG_LEDS_TRIGGER_HEARTBEAT=y
CONFIG_LEDS_TRIGGER_ACTIVITY=y
CONFIG_LEDS_TRIGGER_NETDEV=y
CONFIG_RTC_CLASS=y
CONFIG_SYNC_FILE=y
CONFIG_VIRTIO_PCI=y
+1 -1
View File
@@ -22,7 +22,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.5.6"
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.5.11"
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
BR2_LINUX_KERNEL_DTS_SUPPORT=y
+11 -3
View File
@@ -13,6 +13,7 @@ BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
BR2_INIT_FINIT=y
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/xattrs"
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
BR2_SYSTEM_DHCP="eth0"
BR2_ENABLE_LOCALE_WHITELIST="C en_US en_CA"
@@ -23,7 +24,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.5.6"
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.5.11"
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
BR2_LINUX_KERNEL_DTS_SUPPORT=y
@@ -36,17 +37,21 @@ BR2_PACKAGE_BUSYBOX_SHOW_OTHERS=y
BR2_PACKAGE_STRACE=y
BR2_PACKAGE_STRESS_NG=y
BR2_PACKAGE_JQ=y
BR2_PACKAGE_E2FSPROGS=y
BR2_PACKAGE_DBUS_CXX=y
BR2_PACKAGE_DBUS_GLIB=y
BR2_PACKAGE_DBUS_TRIGGERD=y
BR2_PACKAGE_EUDEV_RULES_GEN=y
# BR2_PACKAGE_EUDEV_ENABLE_HWDB is not set
BR2_PACKAGE_GPTFDISK=y
BR2_PACKAGE_GPTFDISK_SGDISK=y
BR2_PACKAGE_MDIO_TOOLS=y
BR2_PACKAGE_RNG_TOOLS=y
BR2_PACKAGE_UBOOT_TOOLS=y
BR2_PACKAGE_UBOOT_TOOLS_FIT_SUPPORT=y
BR2_PACKAGE_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
BR2_PACKAGE_UBOOT_TOOLS_FIT_CHECK_SIGN=y
BR2_PACKAGE_UBOOT_TOOLS_MKENVIMAGE=y
BR2_PACKAGE_PYTHON3=y
BR2_PACKAGE_CA_CERTIFICATES=y
BR2_PACKAGE_LIBOPENSSL_BIN=y
@@ -62,7 +67,9 @@ BR2_PACKAGE_CONNTRACK_TOOLS=y
BR2_PACKAGE_DNSMASQ=y
BR2_PACKAGE_ETHTOOL=y
BR2_PACKAGE_FPING=y
BR2_PACKAGE_FRR=y
# BR2_PACKAGE_IFUPDOWN_SCRIPTS is not set
BR2_PACKAGE_IPROUTE2=y
BR2_PACKAGE_IPTABLES=y
BR2_PACKAGE_IPTABLES_NFTABLES=y
BR2_PACKAGE_IPUTILS=y
@@ -81,6 +88,7 @@ BR2_PACKAGE_SOCAT=y
BR2_PACKAGE_TCPDUMP=y
BR2_PACKAGE_TRACEROUTE=y
BR2_PACKAGE_ULOGD=y
BR2_PACKAGE_BASH=y
BR2_PACKAGE_BASH_COMPLETION=y
BR2_PACKAGE_IRQBALANCE=y
BR2_PACKAGE_KMOD_TOOLS=y
@@ -107,7 +115,7 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
INFIX_VENDOR_HOME="https://github.com/kernelkit"
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
INFIX_HOME="https://github.com/kernelkit/infix"
INFIX_HOME="https://github.com/kernelkit/infix/"
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
BR2_PACKAGE_CONFD=y
@@ -119,9 +127,9 @@ BR2_PACKAGE_FINIT_PLUGIN_MODULES_LOAD=y
BR2_PACKAGE_FINIT_PLUGIN_RTC=y
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
BR2_PACKAGE_IITO=y
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
BR2_PACKAGE_LOWDOWN=y
BR2_PACKAGE_NET=y
BR2_PACKAGE_TETRIS=y
BR2_PACKAGE_QUERIERD=y
DISK_IMAGE_BOOT_BIN=y
+1 -1
View File
@@ -21,7 +21,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INF
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.5.6"
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.5.11"
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
BR2_LINUX_KERNEL_INSTALL_TARGET=y
+9 -2
View File
@@ -12,6 +12,7 @@ BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
BR2_INIT_FINIT=y
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/xattrs"
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
BR2_SYSTEM_DHCP="eth0"
BR2_ENABLE_LOCALE_WHITELIST="C en_US en_CA"
@@ -22,7 +23,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INF
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.5.6"
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.5.11"
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
BR2_LINUX_KERNEL_INSTALL_TARGET=y
@@ -38,11 +39,14 @@ BR2_PACKAGE_DBUS_GLIB=y
BR2_PACKAGE_DBUS_TRIGGERD=y
BR2_PACKAGE_EUDEV_RULES_GEN=y
# BR2_PACKAGE_EUDEV_ENABLE_HWDB is not set
BR2_PACKAGE_GPTFDISK=y
BR2_PACKAGE_GPTFDISK_SGDISK=y
BR2_PACKAGE_RNG_TOOLS=y
BR2_PACKAGE_UBOOT_TOOLS=y
BR2_PACKAGE_UBOOT_TOOLS_FIT_SUPPORT=y
BR2_PACKAGE_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
BR2_PACKAGE_UBOOT_TOOLS_FIT_CHECK_SIGN=y
BR2_PACKAGE_UBOOT_TOOLS_MKENVIMAGE=y
BR2_PACKAGE_PYTHON3=y
BR2_PACKAGE_CA_CERTIFICATES=y
BR2_PACKAGE_LIBOPENSSL_BIN=y
@@ -58,7 +62,9 @@ BR2_PACKAGE_CONNTRACK_TOOLS=y
BR2_PACKAGE_DNSMASQ=y
BR2_PACKAGE_ETHTOOL=y
BR2_PACKAGE_FPING=y
BR2_PACKAGE_FRR=y
# BR2_PACKAGE_IFUPDOWN_SCRIPTS is not set
BR2_PACKAGE_IPROUTE2=y
BR2_PACKAGE_IPTABLES=y
BR2_PACKAGE_IPTABLES_NFTABLES=y
BR2_PACKAGE_IPUTILS=y
@@ -77,6 +83,7 @@ BR2_PACKAGE_SOCAT=y
BR2_PACKAGE_TCPDUMP=y
BR2_PACKAGE_TRACEROUTE=y
BR2_PACKAGE_ULOGD=y
BR2_PACKAGE_BASH=y
BR2_PACKAGE_BASH_COMPLETION=y
BR2_PACKAGE_IRQBALANCE=y
BR2_PACKAGE_KMOD_TOOLS=y
@@ -123,9 +130,9 @@ BR2_PACKAGE_FINIT_PLUGIN_MODULES_LOAD=y
BR2_PACKAGE_FINIT_PLUGIN_RTC=y
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
BR2_PACKAGE_IITO=y
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
BR2_PACKAGE_LOWDOWN=y
BR2_PACKAGE_NET=y
BR2_PACKAGE_TETRIS=y
BR2_PACKAGE_QUERIERD=y
GNS3_APPLIANCE_RAM=512
-77
View File
@@ -1,77 +0,0 @@
BR2_x86_64=y
BR2_x86_corei7=y
BR2_TOOLCHAIN_EXTERNAL=y
BR2_TOOLCHAIN_EXTERNAL_GDB_SERVER_COPY=y
BR2_DL_DIR="${BR2_EXTERNAL_INFIX_PATH}/dl"
BR2_CCACHE=y
BR2_CCACHE_DIR="${BR2_EXTERNAL_INFIX_PATH}/.ccache"
BR2_ENABLE_DEBUG=y
BR2_GLOBAL_PATCH_DIR="${BR2_EXTERNAL_INFIX_PATH}/patches"
BR2_TARGET_GENERIC_HOSTNAME="infix"
BR2_TARGET_GENERIC_ISSUE="Minfix by KernelKit"
BR2_INIT_FINIT=y
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/xattrs"
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
BR2_SYSTEM_DHCP="eth0"
BR2_ENABLE_LOCALE_WHITELIST="C en_US en_CA"
BR2_GENERATE_LOCALE="en_US en_CA"
BR2_TARGET_TZ_INFO=y
BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/rootfs ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/rootfs"
BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/post-build.sh"
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.5.6"
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
BR2_LINUX_KERNEL_INSTALL_TARGET=y
BR2_LINUX_KERNEL_NEEDS_HOST_LIBELF=y
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
BR2_PACKAGE_BUSYBOX_SHOW_OTHERS=y
BR2_PACKAGE_JQ=y
BR2_PACKAGE_DBUS_CXX=y
BR2_PACKAGE_DBUS_GLIB=y
BR2_PACKAGE_DBUS_TRIGGERD=y
BR2_PACKAGE_EUDEV_RULES_GEN=y
# BR2_PACKAGE_EUDEV_ENABLE_HWDB is not set
BR2_PACKAGE_RNG_TOOLS=y
BR2_PACKAGE_LIBOPENSSL_BIN=y
BR2_PACKAGE_NETOPEER2_CLI=y
BR2_PACKAGE_NSS_MDNS=y
BR2_PACKAGE_ONIGURUMA=y
BR2_PACKAGE_AVAHI=y
BR2_PACKAGE_AVAHI_DAEMON=y
BR2_PACKAGE_AVAHI_DEFAULT_SERVICES=y
BR2_PACKAGE_CHRONY=y
BR2_PACKAGE_DNSMASQ=y
BR2_PACKAGE_ETHTOOL=y
# BR2_PACKAGE_IFUPDOWN_SCRIPTS is not set
BR2_PACKAGE_LLDPD=y
BR2_PACKAGE_OPENRESOLV=y
BR2_PACKAGE_OPENSSH=y
BR2_PACKAGE_TCPDUMP=y
BR2_PACKAGE_KMOD_TOOLS=y
BR2_PACKAGE_BASH_COMPLETION=y
BR2_PACKAGE_PWGEN=y
BR2_PACKAGE_SYSKLOGD=y
BR2_PACKAGE_SYSKLOGD_LOGGER=y
BR2_PACKAGE_LESS=y
BR2_TARGET_ROOTFS_SQUASHFS=y
# BR2_TARGET_ROOTFS_TAR is not set
BR2_PACKAGE_CONFD=y
BR2_PACKAGE_STATD=y
BR2_PACKAGE_FACTORY=y
BR2_PACKAGE_FINIT_SULOGIN=y
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
BR2_PACKAGE_FINIT_PLUGIN_MODULES_LOAD=y
BR2_PACKAGE_FINIT_PLUGIN_RTC=y
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
BR2_PACKAGE_NET=y
BR2_PACKAGE_PYTHON3=y
BR2_PACKAGE_PYTHON3_PYC_ONLY=y
# SIGN_ENABLED is not set
# GNS3_APPLIANCE is not set
+264 -1
View File
@@ -4,6 +4,268 @@ Change Log
All notable changes to the project are documented in this file.
[v23.11.0][] - 2023-11-30
-------------------------
> **Note:** this is the first release where the `root` account is disabled in
> default builds. Only the `admin` user, generated from `factory-config`, can
> log in to the system. This can be changed only in developer builds: `make
> menuconfig` -> System configuration -> `[*]Enable root login with password`
### YANG Status
- [ieee802-ethernet-interface][]: Currently supported (read-only) features:
- Status of auto-negotiation, and if enabled.
- Current speed and duplex
- Frame counters:
| **YANG** | **Linux / Ethtool** |
|-----------------------------|-----------------------------------|
| `out-frames` | `FramesTransmittedOK` |
| `out-multicast-frames` | `MulticastFramesXmittedOK` |
| `out-broadcast-frames` | `BroadcastFramesXmittedOK` |
| `in-total-octets` | `FramesReceivedOK` |
| | + `FrameCheckSequenceErrors` |
| | + `FramesLostDueToIntMACRcvError` |
| | + `AlignmentErrors` |
| | + `etherStatsOversizePkts` |
| | + `etherStatsJabbers` |
| `in-frames` | `FramesReceivedOK` |
| `in-multicast-frames` | `MulticastFramesReceivedOK` |
| `in-broadcast-frames` | `BroadcastFramesReceivedOK` |
| `in-error-undersize-frames` | `undersize_pkts` |
| `in-error-fcs-frames` | `FrameCheckSequenceErrors` |
- [ietf-system][]:
- **augments:**
- MotD (Message of the Day)
- User login shell, default: `/bin/false` (no SSH or console login)
- State information for remotely querying firmware version information
- **deviations:**
- timezone-name, using IANA timezones instead of plain string
- UTC offset, only support per-hour offsets with [tzdata][]
- Usernames, clarifying Linux restrictions
- Unsupported features marked as deviations, e.g. RADIUS
- [infix-system-software][]: firmware upgrade with `install-bundle` RPC
- [ietf-interfaces][]:
- deviation to allow read-write `if:phys-address` for custom MAC address
- [ietf-ip][]: augments
- IPv4LL similar to standardized IPv6LL
- [ietf-ip][]: deviations (`not-supported`) added for IPv4 and IPv6:
- `/if:interfaces/if:interface/ip:ipv4/ip:address/ip:subnet/ip:netmask`
- `/if:interfaces/if:interface/ip:ipv6/ip:address/ip:status`
- `/if:interfaces/if:interface/ip:ipv4/ip:neighbor`
- `/if:interfaces/if:interface/ip:ipv6/ip:neighbor`
- [ietf-routing][]: Base model for routing
- [ietf-ipv4-unicast-routing][]: Static unicast routing, incl. operational
data, i.e., setting static IPv4 routes and reading IPv4 routing table
- [infix-ethernet-interface][]: deviations for ieee802-ethernet-interface
- [infix-routing][]: Limit ietf-routing to one instance `default` per
routing protocol, also details unsupported features (deviations)
- [infix-if-bridge][]: Linux bridge interfaces with native VLAN support
- [infix-if-type][]: deviation for interface types, limiting number
to supported types only. New identities are derived from default
IANA interface types, ensuring compatibility with other standard
models, e.g., `ieee802-ethernet-interface.yang`
- [infix-if-veth][]: Linux VETH pairs
- [infix-if-vlan][]: Linux VLAN interfaces, e.g. `eth0.10`
- **Configurable services:**
- [ieee802-dot1ab-lldp][]: stripped down to an `enabled` setting
- [infix-services][]: support for enabling mDNS service/device discovery
[tzdata]: https://www.iana.org/time-zones
[ietf-system]: https://www.rfc-editor.org/rfc/rfc7317.html
[ietf-interfaces]: https://www.rfc-editor.org/rfc/rfc7223.html
[ietf-ip]: https://www.rfc-editor.org/rfc/rfc8344.html
[ietf-if-vlan-encapsulation]: https://www.ietf.org/id/draft-ietf-netmod-sub-intf-vlan-model-08.html
[ietf-routing]: https://www.rfc-editor.org/rfc/rfc8349
[ietf-ipv4-unicast-routing]: https://www.rfc-editor.org/rfc/rfc8349#page-29
[ieee802-dot1ab-lldp]: https://github.com/kernelkit/infix/blob/985c2fd/src/confd/yang/ieee802-dot1ab-lldp%402022-03-15.yang
[ieee802-ethernet-interface]: https://github.com/kernelkit/infix/blob/985c2fd/src/confd/yang/ieee802-ethernet-interface%402019-06-21.yang
[infix-ethernet-interface]: https://github.com/kernelkit/infix/blob/985c2fd/src/confd/yang/infix-ethernet-interface%402023-11-22.yang
[infix-if-bridge]: https://github.com/kernelkit/infix/blob/985c2fd/src/confd/yang/infix-if-bridge%402023-11-08.yang
[infix-if-type]: https://github.com/kernelkit/infix/blob/985c2fd/src/confd/yang/infix-if-type%402023-08-21.yang
[infix-if-veth]: https://github.com/kernelkit/infix/blob/985c2fd/src/confd/yang/infix-if-veth%402023-06-05.yang
[infix-if-vlan]: https://github.com/kernelkit/infix/blob/985c2fd/src/confd/yang/infix-if-vlan%402023-10-25.yang
[infix-ip]: https://github.com/kernelkit/infix/tree/985c2fd/src/confd/yang/infix-ip%402023-09-14.yang
[infix-routing]: https://github.com/kernelkit/infix/blob/985c2fd/src/confd/yang/infix-routing%402023-11-23.yang
[infix-services]: https://github.com/kernelkit/infix/blob/985c2fd/src/confd/yang/infix-services%402023-10-16.yang
[infix-system-software]: https://github.com/kernelkit/infix/tree/985c2fd/src/confd/yang/infix-system-software%402023-06-27.yang
### Changes
- The CLI built-in command `password generate` has been changed to use the
secure mode of the `pwgen` tool, and 13 chars for increased entropy
- The `qemu.sh -c` command, available in developer builds and the release zip,
can now be used to modify the RAM size and enable VPD emulation
- Add support for overriding generated factory defaults in derivatives
using a `/etc/confdrc.lcocal` file -- incl. updated branding docs.
- Add support for detecting factory reset condition from a bootloader
- Ensure `/var` is also cleared (properly) during factory reset
- Add support for port auto-negotiation status in operational datastore
- Add CLI support for showing veth pairs in `show interfaces`
- Speedups to CLI detailed view of a single interface
- Updated documentation of VLAN interfaces and VLAN filtering bridge
- Updated documentation for how to customize services in *Hybrid Mode*
- In RMA mode (runlevel 9), the system no longer has any login services
- Disable `root` login in all NETCONF builds, only `admin` available
- Add support for VPD data in ONIE EEPROM format
- Add `iito`, the intelligent input/output daemon for LED control
- Add port autoneg and speed/duplex status to operational data
- Upgrade Linux to v6.5.11, with kkit extensions
- Add support for static IPv4 routing using `ietf-routing@2018-03-13.yang` and
`ietf-ipv4-unicast-routing@2018-03-13.yang`, one `default` instance only
- Add support for partitioning and self-provisioning of new devices
- Add support for reading `admin` user's default password from VPD. Devices
that do not have a VPD can set a password hash in the device tree
- Add support for upgrading software bundles (images) from the CLI.
Supported remote servers: ftp, tftp, and http/https.
- Traversing the CLI configure context has been simplified by collapsing all
YANG containers that only contain a single list element. Example:
`edit interfaces interface eth0` becomes `edit interface eth0`
- Add CLI support for creating configuration backups and transferring files
to/from remote servers: tftp, ftp, http/https (download only). Issue #155
- Add `_netconf-ssh._tcp` record to mDNS-SD
### Fixes
- Fix #111: fix auto-inference of dynamic interface types (bridge, veth)
- Fix #125: improved feedback on invalid input in configure context
- Fix #198: drop bridge default PVID setting, for VLAN filtering bridge.
All bridge ports must have explicit VLAN assignment (security)
- Fix #215: impossible to enable NTP client, regression from v23.06.0
- Fix regression in CLI `show factory-config` command
- Fix missing version in `/etc/os-release` variable `PRETTY_NAME`
- Fix failure to start `podman` in GNS3 (missing Ext4 filesystem feature)
- Fix initial terminal size probing in CLI when logging in from console port
- Fix CLI `show running-config`, use proper JSON format like other files
- Fix caching of libyang module references in confd. Loading other plugins to
sysrepo-plugind modifies these references, which may can cause corruption
- Fix missing `v` in `VERSION`, `VERSION_ID`, and `IMAGE_VERSION` in
`/etc/os-release` and other generated files for release builds.
[v23.10.0][] - 2023-10-31
-------------------------
> **Note:** upcoming releases will lock the `root` user for system-only
> services. Instead an `admin` user will be the only default user with
> the CLI as its login shell. This user is already available, so please
> consider updating any guidelines or documentation you may have.
### YANG Status
- [ietf-system][]:
- **augments:**
- MotD (Message of the Day)
- User login shell, default: `/bin/false`
- State information for remotely querying firmware version information
- **deviations:**
- timezone-name, using IANA timezones instead of plain string
- UTC offset, only support per-hour offsets with [tzdata][]
- Usernames, clarifying Linux restrictions
- Unsupported features marked as deviations, e.g. RADIUS
- [infix-system-software][]: firmware upgrade with `install-bundle` RPC
- [ietf-interfaces][]:
- deviation to allow read-write `if:phys-address` for custom MAC address
- [ietf-ip][]: augments
- IPv4LL similar to standardized IPv6LL
- [ietf-ip][]: deviations (`not-supported`) added for IPv4 and IPv6:
- `/if:interfaces/if:interface/ip:ipv4/ip:address/ip:subnet/ip:netmask`
- `/if:interfaces/if:interface/ip:ipv6/ip:address/ip:status`
- `/if:interfaces/if:interface/ip:ipv4/ip:neighbor`
- `/if:interfaces/if:interface/ip:ipv6/ip:neighbor`
- ~~[ietf-if-vlan-encapsulation][]:~~ Removed in favor of a native model.
- [infix-if-bridge][]: Linux bridge interfaces with native VLAN support
- [infix-if-type][]: deviation for interface types, limiting number
to supported types only. New identities are derived from default
IANA interface types, ensuring compatibility with other standard
models, e.g., `ieee802-ethernet-interface.yang`
- [infix-if-veth][]: Linux VETH pairs
- [infix-if-vlan][]: Linux VLAN interfaces, e.g. `eth0.10` (New model!)
- **Configurable services:**
- [ieee802-dot1ab-lldp][]: stripped down to an `enabled` setting
- [infix-services][]: support for enabling mDNS service/device discovery
[tzdata]: https://www.iana.org/time-zones
[ieee802-dot1ab-lldp]: https://github.com/kernelkit/infix/tree/50a550b/src/confd/yang/ieee802-dot1ab-lldp%402022-03-15.yang
[ietf-system]: https://www.rfc-editor.org/rfc/rfc7317.html
[ietf-interfaces]: https://www.rfc-editor.org/rfc/rfc7223.html
[ietf-ip]: https://www.rfc-editor.org/rfc/rfc8344.html
[ietf-if-vlan-encapsulation]: https://www.ietf.org/id/draft-ietf-netmod-sub-intf-vlan-model-08.html
[infix-if-bridge]: https://github.com/kernelkit/infix/blob/fc5310b/src/confd/yang/infix-if-bridge%402023-08-21.yang
[infix-if-type]: https://github.com/kernelkit/infix/tree/fc5310b/src/confd/yang/infix-if-type%402023-08-21.yang
[infix-if-veth]: https://github.com/kernelkit/infix/tree/fc5310b/src/confd/yang/infix-if-veth%402023-06-05.yang
[infix-if-vlan]: https://github.com/kernelkit/infix/blob/fc5310b/src/confd/yang/infix-if-vlan%402023-10-25.yang
[infix-ip]: https://github.com/kernelkit/infix/tree/fc5310b/src/confd/yang/infix-ip%402023-09-14.yang
[infix-services]: https://github.com/kernelkit/infix/blob/fc5310b/src/confd/yang/infix-services%402023-10-16.yang
[infix-system-software]: https://github.com/kernelkit/infix/tree/fc5310b/src/confd/yang/infix-system-software%402023-06-27.yang
### Changes
- Add support for setting/querying IPv4/IPv6 MTU, see #152 for details.
- Add support for *Fail Secure Mode*: if loading `startup-config` fails,
e.g. YANG model validation failure after upgrade, the system now falls back
to load `failure-config` instead of just crashing. This config, along with
`factory-config`, is generated on every boot to match the active image's
YANG models. In case neither config can be loaded, or even bootstrapping
YANG models fail, the system will go into an RMA state -- Return to
Manufacturer, clearly signaled on the console and, on devices that support
it, angry LED signaling. See #154 for more.
- Add support for generating GNS3 appliance file for NETCONF Aarch64.
- Add support for UTC offset (+/- HH:00) in `ietf-system`, PR #174
- Add support for `ietf-factory-default` RPC, PR #175
- Add support for performing factory reset (using #175 RPC) from CLI
- Replace `ietf-if-vlan-encapsulation` YANG model with the native
`infix-if-vlan` model. This fits better with Linux VLAN interfaces and
simplifies the syntax greatly. For details, see PR #179
admin@example:/config/interfaces/interface/eth0.10/> set vlan id 10 lower-layer-if eth0
- The following new NETCONF interface operational counters have been added:
| **YANG** | **Linux / Ethtool** |
|-----------------------------|-----------------------------------|
| `out-frames` | `FramesTransmittedOK` |
| `out-multicast-frames` | `MulticastFramesXmittedOK` |
| `out-broadcast-frames` | `BroadcastFramesXmittedOK` |
| `in-total-frames` | `FramesReceivedOK` |
| | + `FrameCheckSequenceErrors` |
| | + `FramesLostDueToIntMACRcvError` |
| | + `AlignmentErrors` |
| | + `etherStatsOversizePkts` |
| | + `etherStatsJabbers` |
| `in-frames` | `FramesReceivedOK` |
| `in-multicast-frames` | `MulticastFramesReceivedOK` |
| `in-broadcast-frames` | `BroadcastFramesReceivedOK` |
| `in-error-undersize-frames` | `undersize_pkts` |
| `in-error-fcs-frames` | `FrameCheckSequenceErrors` |
- Greatly improved branding support using `make menuconfig`. All the
identifying strings, including firmware image, is in `/etc/os-release`, will
be used in CLI `show system-information`, the WebUI About dialog, and any
prominent areas when booting up (on console), logging in to CLI and WebUI.
- IGMP/MLD snooping is now disabled by default on new bridges. Support
for multicast filtering bridges expected no later than v24.01.
- The SSDP responder, device discovery in Windows, has been removed in favor
of Windows 10 (build 1709) native support for mDNS-SD. Details in #166
- A GreenPAK programmer has been added, not enabled by default. This is a
popular programmable little chip from Renesas. Worth a look!
- The `confd` script `gen-interfaces` can now generate bridges and stand-alone
interfaces with IPv6 (SLAAC) for `factory-config` et al.
- Drop `x86_64_minimal_defconfig`, previously used for regression tests only
- Documentation updates of how IPv4/IPv6 addresses are shown in NETCONF
operational data, as well as the built-in CLI, see #163 for details.
### Fixes
- Fix #106: confd: drop deviation `ietf-system:timezone-utc-offset`
- Fix #151: Operational status broken in v23.09
- Fix #159: Hacky generation of `/etc/resolv.conf` at boot
- Fix #162: VLAN interface without encapsulation is accepted by YANG model
[v23.09.0][] - 2023-10-02
-------------------------
@@ -216,7 +478,8 @@ Supported YANG models in addition to those used by sysrepo and netopeer:
- N/A
[buildroot]: https://buildroot.org/
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v23.08.0...HEAD
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v23.10.0...HEAD
[v23.10.0]: https://github.com/kernelkit/infix/compare/v23.09.0...v23.10.0
[v23.09.0]: https://github.com/kernelkit/infix/compare/v23.08.0...v23.09.0
[v23.08.0]: https://github.com/kernelkit/infix/compare/v23.06.0...v23.08.0
[v23.06.0]: https://github.com/kernelkit/infix/compare/BASE...v23.06.0
+4 -4
View File
@@ -62,7 +62,7 @@ To mitigate the risk of a malicious user being able to circumvent the
bootloader's validation procedure, user configuration is kept to a
minimum. Two settings are available:
- **Boot order**: Since Infix maintains two copies of its firmware,
- **Boot order**: Since Infix maintains two copies of its software image,
and as some bootloaders support netbooting, the order in which boot
sources are considered can be configured. To select the active
source, use [RAUC][]:
@@ -106,7 +106,7 @@ boot Infix over the network. DHCP is used to configure the network
and TFTP to transfer the image to the system's RAM.
Access to U-Boot's shell is disabled to prevent side-loading of
malicious firmware. To configure the active boot partition, refer to
malicious software. To configure the active boot partition, refer to
the [Bootloader Interface](#bootloader-interface) section.
@@ -128,11 +128,11 @@ Interface](#bootloader-interface).
System Upgrade
==============
Much of the minutiae of firmware upgrades is delegated to [RAUC][],
Much of the minutiae of software upgrades is delegated to [RAUC][],
which offers lots of benefits out-of-the-box:
- Upgrade Bundles are always signed, such that their authenticity can
be verified by the running firmware, before the new one is
be verified by the running operating system, before the new one is
installed.
- The bureaucracy of interfacing with different bootloaders, manage
+82 -1
View File
@@ -41,6 +41,62 @@ Verify the result after a build by inspecting:
printed on a label on the device.
Factory Defaults
----------------
The Infix default configuration, factory-config, is part static files
and part per-device generated files, e.g., SSH hostkey and hostname.
The latter is constructed from the file `/etc/hostname`, appended with
the last three octets of the system's base MAC address. To override the
base hostname, set `BR2_TARGET_GENERIC_HOSTNAME` in your defconfig.
The static files are installed by Infix `confd` in `/usr/share/confd/`
at build time. It contains two subdirectories:
/usr/share/confd/
|- factory.d/
| |- 10-foo.json
| |- 10-bar.json
| `- 10-qux.json
`- failure.d/
|- 10-xyzzy.json
`- 10-garply.json
To override, or extend, these files in you br2-external, set up a rootfs
overlay and add it last in `BR2_ROOTFS_OVERLAY`. Your overlay can look
something like this:
./board/common/rootfs/
|- etc/
| |- confdrc # See below
| `- confdrc.local
`- usr/
`- share/
`- confd/
|- 10-foo.json # Override Infix foo
|- 30-bar.json # Extend, probably 10-bar.json
`- 30-fred.json # Extend, your own defaults
Using the same filename in your overlay, here `10-foo.json`, completely
replaces the contents of the same file provided by Infix. If you just
want to extend, or replace parts of an Infix default, use `30-....json`.
Here the file `30-bar.json` is just a helpful hit to maintainers of your
br2-external that it probably extends Infix' `10-bar.json`.
The reason for the jump in numbers is that 20 is reserved for files
generated by Infix' `gen-function` scripts. Your br2-external can
provide a few custom ones that the `bootstrap` knows about, e.g.,
`gen-ifs-custom` that overrides `20-interfaces.json`. See the
bootstrap script for more help, and up-to-date information.
> **Note:** you may not need to provide your own `/etc/confdrc`. The
> one installed by `confd` is usually enough. However, if you want to
> adjust the behavior of `bootstrap` you may want to override it. There
> is also `confdrc.local`, which usually is enough to change arguments
> to scripts like `gen-interfaces`, e.g., to create a bridge by default,
> you may want to look into `GEN_IFACE_OPTS`.
Integration
-----------
@@ -103,7 +159,31 @@ Releases
--------
A release build requires the global variable `INFIX_RELEASE` to be set.
It can be derived from GIT, if the source tree is kept in GIT VCS.
It can be derived from GIT, if the source tree is kept in GIT VCS. First,
let us talk about versioning in general.
### Versioning
Two popular scheme for versioning a product derived from Infix:
1. Track Infix major.minor, e.g. *Foobar v23.08.z*, where `z` is
your patch level. I.e., Foobar v23.08.0 could be based on Infix
v23.08.0, or v23.08.12, it is up to you. Maybe you based it on
v23.08.12 and then back ported changes from v23.10.0, but it was
the first release you made to your customer(s).
2. Start from v1.0.0 and step the major number every time you sync
with a new Infix release, or every time Infix bumps to the next
Buildroot LTS.
The important thing is to be consistent, not only for your own sake,
but also for your end customers. The *major.minor.patch* style is
the most common and often recommended style, which usually maps well
to other systems, e.g. PROFINET GSDML files require this (*VX.Y.Z*).
But you can of course use only two numbers, *major.minor*, as well.
> What could be confusing, however, is if you use the name *Infix*
> with your own versioning scheme.
### `INFIX_RELEASE`
@@ -122,3 +202,4 @@ Infix tree and can be changed by setting the menuconfig branding
variable `INFIX_OEM_PATH` to that of the br2-external. It is also
possible to set the `GIT_VERSION` variable in your `post-build.sh`
script to change how the VCS version is extracted.
+12 -12
View File
@@ -35,7 +35,7 @@ The system has several datastores (or files):
To save configuration changes made to the `running-config` so the system
will use them consecutive reboots, use the `copy` command:
admin@infix-12-34-56:/> copy running-config startup-config
admin@host-12-34-56:/> copy running-config startup-config
In *configure context* the following commands are available:
@@ -64,17 +64,17 @@ We inspect the system status to ensure the change took effect. Then we
save the changes for the next reboot.
```
admin@infix-12-34-56:/> configure
admin@infix-12-34-56:/config/> edit interfaces interface eth0
admin@infix-12-34-56:/config/interfaces/interface/eth0/> set ipv4 <TAB>
admin@host-12-34-56:/> configure
admin@host-12-34-56:/config/> edit interface eth0
admin@host-12-34-56:/config/interface/eth0/> set ipv4 <TAB>
address autoconf bind-ni-name enabled
forwarding mtu neighbor
admin@infix-12-34-56:/config/interfaces/interface/eth0/> set ipv4 address 192.168.2.200 prefix-length 24
admin@infix-12-34-56:/config/interfaces/interface/eth0/> show
admin@host-12-34-56:/config/interface/eth0/> set ipv4 address 192.168.2.200 prefix-length 24
admin@host-12-34-56:/config/interface/eth0/> show
type ethernetCsmacd;
ipv4 address 192.168.2.200 prefix-length 24;
ipv6 enabled true;
admin@infix-12-34-56:/config/interfaces/interface/eth0/> diff
admin@host-12-34-56:/config/interface/eth0/> diff
interfaces {
interface eth0 {
+ ipv4 {
@@ -84,14 +84,14 @@ interfaces {
+ }
}
}
admin@infix-12-34-56:/config/interfaces/interface/eth0/> leave
admin@infix-12-34-56:/> show interfaces brief
admin@host-12-34-56:/config/interface/eth0/> leave
admin@host-12-34-56:/> show interfaces brief
lo UNKNOWN 00:00:00:00:00:00 <LOOPBACK,UP,LOWER_UP>
eth0 UP 52:54:00:12:34:56 <BROADCAST,MULTICAST,UP,LOWER_UP>
admin@infix-12-34-56:/> show ip brief
admin@host-12-34-56:/> show ip brief
lo UNKNOWN 127.0.0.1/8 ::1/128
eth0 UP 192.168.2.200/24 fe80::5054:ff:fe12:3456/64
admin@infix-12-34-56:/> copy running-config startup-config
admin@host-12-34-56:/> copy running-config startup-config
```
One of the ideas behind a separate running and startup configuration is
@@ -99,7 +99,7 @@ to be able to verify a configuration change. In case of an inadvertent
change that, e.g., breaks networking, it is trivial to revert back by:
```
admin@infix-12-34-56:/> copy startup-config running-config
admin@host-12-34-56:/> copy startup-config running-config
```
Or restarting the device.
+95 -35
View File
@@ -1,9 +1,9 @@
User Guide
==========
The command line interface (CLI, see-el-i) is built on the open source
component [klish][1], which implements a CISCO like, or Juniper Networks
JunOS-like CLI on a UNIX system.
The command line interface (CLI, see-ell-aye) is built on the open source
component [klish][1], which implements a CISCO-like, or Juniper Networks
JunOS-like, CLI for UNIX systems.
New users always get the CLI as the default "shell" when logging in, but
the default `admin` user logs in to the Bash. To access the CLI, type:
@@ -18,11 +18,11 @@ Key commands available in any context are:
For each command it also possible to press the `?` key and `TAB` to get
more help and suggestions for completion.
> **Note:** for the sake of brevity, the hostname in the following
> examples has been shortened to `host`. The default name is composed
> from a product specific string followed by the last three octets of
> the system base MAC address, e.g., `infix-12-34-56`. An example of
> how to change the hostname is included below.
> **Note:** for the sake of brevity, the hostname in the following examples
> has been shortened to `host`. The default name is composed from a product
> specific string followed by the last three octets of the system base MAC
> address, e.g., `switch-12-34-56`. An example of how to change the hostname
> is included below.
Admin Exec
@@ -36,14 +36,74 @@ Available commands can be seen by pressing `?` at the prompt:
```
admin@host:/>
configure Create new candidate-config based on running-config
copy Copy
exit Exit
logout Alias for exit
shell Enter system shell
show Show
configure Create new candidate-config based on running-config
copy Copy configuration, e.g., copy running-config startup-config
exit Exit from CLI (log out)
factory-reset Restore the system to factory default state
follow Monitor a log file, use Ctrl-C to abort
help Help system (also try '?' key)
logout Alias to exit
netcalc IP subnet calculator
password Password tools
ping Ping a network host or multicast group
poweroff Poweroff system (system policy may yield reboot)
reboot Reboot system
set Set operations, e.g., current date/time
shell Enter system shell
show Show system status and configuration files
tcpdump Capture network traffic
upgrade Install a software update bundle
```
To get more help for a given command, type the command, a space, and
then tap `?` again. You can also tap the `Tab` key to see available
argument completions.
### Upgrading the Software
The admin-exec command `upgrade` can be used to install software images, or
bundles. A bundle is a signed and self-contained package that carries all the
information necessary to determine if it holds a bootloader, a Linux image, or
even both.
To install a new software image to the currently *inactive* partition[^1], we
use the `upgrade` command and a URI to a ftp/tftp/sftp or http/https server
that hosts the file:
```
admin@host:/> upgrade tftp://192.168.122.1/firmware-x86_64-v23.11.pkg
installing
0% Installing
0% Determining slot states
20% Determining slot states done.
20% Checking bundle
20% Verifying signature
40% Verifying signature done.
40% Checking bundle done.
40% Checking manifest contents
60% Checking manifest contents done.
60% Determining target install group
80% Determining target install group done.
80% Updating slots
80% Checking slot rootfs.1
90% Checking slot rootfs.1 done.
90% Copying image to rootfs.1
99% Copying image to rootfs.1 done.
99% Updating slots done.
100% Installing done.
Installing `tftp://192.168.122.1/firmware-x86_64-v23.11.pkg` succeeded
admin@host:/>
```
The secondary partition (`rootfs.1`) has now been upgraded and will be used as
the *active* partition on the next boot. Leaving the primary partition, with
the version we are currently running, intact in case of trouble.
[^1]: It is not possible to upgrade the partition we booted from. Thankfully
the underlying "rauc" subsystem keeps track of this. Hence, to upgrade
both partitions you must reboot to the new version (to verify it works)
and then repeat the same command.
Configure Context
-----------------
@@ -73,15 +133,15 @@ admin@host:/config/>
The `edit` command lets you change to a sub-configure context, e.g.:
```
admin@host:/config/> edit interfaces interface eth0
admin@host:/config/interfaces/interface/eth0/>
admin@host:/config/> edit interface eth0
admin@host:/config/interface/eth0/>
```
Use `up` to go up one level.
```
admin@host:/config/interfaces/interface/eth0/> up
admin@host:/config/interfaces/>
admin@host:/config/interface/eth0/> up
admin@host:/config/>
```
> **Note:** the tree structure in the configure context is automatically
@@ -94,16 +154,16 @@ admin@host:/config/interfaces/>
### Set IP Address on an Interface
```
admin@host:/config/> edit interfaces interface eth0
admin@host:/config/interfaces/interface/eth0/>
admin@host:/config/interfaces/interface/eth0/> set ipv4 address 192.168.2.200 prefix-length 24
admin@host:/config/> edit interface eth0
admin@host:/config/interface/eth0/>
admin@host:/config/interface/eth0/> set ipv4 address 192.168.2.200 prefix-length 24
```
From anywhere in configure context you can see the changes you have
made by typing `diff`:
```
admin@host:/config/interfaces/interface/eth0/> diff
admin@host:/config/interface/eth0/> diff
interfaces {
interface eth0 {
+ ipv4 {
@@ -121,7 +181,7 @@ interfaces {
Apply the changes (from candidate to `running-config`):
```
admin@host:/config/interfaces/> leave
admin@host:/config/interface/eth0/> leave
admin@host:/> show running-config
...
interfaces {
@@ -199,11 +259,11 @@ pair which is useful for connecting, e.g., a container to the physical
world. Here we also add an IPv4 address to one end of the pair.
```
admin@host:/config/> edit interfaces interface veth0a
admin@host:/config/interfaces/interface/veth0a/> set veth peer veth0b
admin@host:/config/interfaces/interface/veth0a/> set ipv4 address 192.168.0.1 prefix-length 24
admin@host:/config/interfaces/interface/veth0a/> up
admin@host:/config/interfaces/> diff
admin@host:/config/> edit interface veth0a
admin@host:/config/interface/veth0a/> set veth peer veth0b
admin@host:/config/interface/veth0a/> set ipv4 address 192.168.0.1 prefix-length 24
admin@host:/config/interface/veth0a/> up
admin@host:/config/> diff
interfaces {
+ interface veth0a {
+ type veth;
@@ -223,7 +283,7 @@ interfaces {
+ }
+ }
}
admin@host:/config/interfaces/> leave
admin@host:/config/> leave
```
See the bridging example below for more.
@@ -241,12 +301,12 @@ between both its bridge ports: `eth0` and `vet0b`.
```
admin@host:/> configure
admin@host:/config/> edit interfaces interface br0
admin@host:/config/interfaces/interface/br0/> set bridge ieee-group-forward lldp
admin@host:/config/interfaces/interface/br0/> up
admin@host:/config/interfaces/> set interface eth0 bridge-port bridge br0
admin@host:/config/interfaces/> set interface veth0b bridge-port bridge br0
admin@host:/config/interfaces/> diff
admin@host:/config/> edit interface br0
admin@host:/config/interface/br0/> set bridge ieee-group-forward lldp
admin@host:/config/interface/br0/> up
admin@host:/config/> set interface eth0 bridge-port bridge br0
admin@host:/config/> set interface veth0b bridge-port bridge br0
admin@host:/config/> diff
interfaces {
+ interface br0 {
+ type bridge;
+7 -6
View File
@@ -5,7 +5,7 @@ Containers in Infix
* [Docker Containers with Podman](#docker-containers-with-podman)
* [Multiple Networks](#multiple-networks)
* [Hybrid Mode](#hybrid-mode)
* [Enabling Containers](#enabling-containers)
* [Enabling Container Support](#enabling-container-support)
* [Debugging Containers](#debugging-containers)
@@ -57,10 +57,10 @@ inside the container will always be: `eth0`, `eth1`, etc.
A common setup is to use a VETH pair, with one end in the container and
the other end routed, or bridged, to the rest of the world. The Infix
[CLI Guide](cli/introduction.md) provides examples of both. In either case you need
to create a matching CNI profile for one end of the VETH pair before
starting the container, here we use two network profiles, the default
podman bridge and the VETH profile:
[CLI Guide](cli/introduction.md) provides examples of both. In either
case you need to create a matching CNI profile for one end of the VETH
pair before starting the container, here we use two network profiles,
the default podman bridge and the VETH profile:
cni create host net1 veth0a 192.168.0.42/24
podman run -d --rm --net=podman,net1 --entrypoint "/linuxrc" \
@@ -160,7 +160,7 @@ downloaded with `podman pull docker://troglobit/buildroot:latest` and
a container created (above):
```
root@infix:/cfg/start.d$ cat <<EOF >20-enable-container.sh
root@infix:/cfg/start.d$ cat <<HERE >20-enable-container.sh
#!/bin/sh
# Remember to create the veth0a <--> vet0b pair in the CLI first!
cni create host net1 veth0a 192.168.0.42/24
@@ -169,6 +169,7 @@ service name:pod :system pid:!/run/pod:system.pid podman --syslog start system -
EOF
initctl enable pod:system
exit 0
HERE
root@infix:/cfg/start.d$ chmod +x 20-enable-container.sh
```
+15 -1
View File
@@ -1,6 +1,20 @@
Developer's Guide
=================
Please note, by default the `root` account is disabled in Infix NETCONF
builds. Meaning, the only way to access the system is with the `admin`
account, which is created based on credentials found in the VPD area --
for Qemu devices this is emulated using `qemu_fw_cfg`.
For developers this can be quite frustrating to be blocked from logging
in to debug the system. So we recommend enabling the `root` account in
the Buildroot `make menuconfig` system.
make menuconfig
-> System configuration
-> [*]Enable root login with password
Cloning
-------
@@ -75,7 +89,7 @@ To see available defconfigs for supported targets, use:
Development
-----------
When changing a package, locally kept sources, or when using `local.mk`,
When changing a package, locally kept sources, or when using [`local.mk`](override-package.md),
you only want to rebuild the parts you have modified:
make foo-rebuild
+31
View File
@@ -0,0 +1,31 @@
# YANG to Ethtool Mapping
This column contains the mapping between YANG and Linux / Ethtool counters.
```
┌─────────────────────────────────┬──────────────────────────────────┐
│ YANG │ Linux / Ethtool │
├─────────────────────────────────┼──────────────────────────────────┤
│ out-frames │ FramesTransmittedOK │
├─────────────────────────────────┼──────────────────────────────────┤
│ out-multicast-frames │ MulticastFramesXmittedOK │
├─────────────────────────────────┼──────────────────────────────────┤
│ out-broadcast-frames │ BroadcastFramesXmittedOK │
├─────────────────────────────────┼──────────────────────────────────┤
│ in-total-frames │ FramesReceivedOK, │
│ │ FrameCheckSequenceErrors │
│ │ FramesLostDueToIntMACRcvError │
│ │ AlignmentErrors │
│ │ etherStatsOversizePkts │
│ │ etherStatsJabbers │
├─────────────────────────────────┼──────────────────────────────────┤
│ in-frames │ FramesReceivedOK │
├─────────────────────────────────┼──────────────────────────────────┤
│ in-multicast-frames │ MulticastFramesReceivedOK │
├─────────────────────────────────┼──────────────────────────────────┤
│ in-broadcast-frames │ BroadcastFramesReceivedOK │
├─────────────────────────────────┼──────────────────────────────────┤
│ in-error-undersize-frames │ undersize_pkts │
├─────────────────────────────────┼──────────────────────────────────┤
│ in-error-fcs-frames │ FrameCheckSequenceErrors │
└─────────────────────────────────┴──────────────────────────────────┘
```
File diff suppressed because it is too large Load Diff

After

Width:  |  Height:  |  Size: 61 KiB

+112 -46
View File
@@ -8,7 +8,7 @@
| -------- | ----------------- | ------------------------------------------------------------- |
| bridge | infix-if-bridge | SW implementation of an IEEE 802.1Q bridge |
| ip | ietf-ip, infix-ip | IP address to the subordinate interface |
| vlan | ietf-vlan-encap | Capture all traffic belonging to a specific 802.1Q VID |
| vlan | infix-if-vlan | Capture all traffic belonging to a specific 802.1Q VID |
| lag[^1] | infix-if-lag | Bonds multiple interfaces into one, creating a link aggregate |
| lo | ietf-interfaces | Software loopback interface |
| eth | ietf-interfaces | Physical Ethernet device/port |
@@ -34,11 +34,11 @@ In Infix ports are by default not switch ports, unless the customer specific fac
```
admin@example:/> configure
admin@example:/config/> edit interfaces interface br0
admin@example:/config/interfaces/interface/br0/> up
admin@example:/config/interfaces/> set interface eth0 bridge-port bridge br0
admin@example:/config/interfaces/> set interface eth1 bridge-port bridge br0
admin@example:/config/interfaces/> leave
admin@example:/config/> edit interface br0
admin@example:/config/interface/br0/> up
admin@example:/config/> set interface eth0 bridge-port bridge br0
admin@example:/config/> set interface eth1 bridge-port bridge br0
admin@example:/config/> leave
```
Here we add two ports to bridge `br0`: `eth0` and `eth1`.
@@ -47,37 +47,62 @@ Here we add two ports to bridge `br0`: `eth0` and `eth1`.
#### VLAN Filtering Bridge
By default bridges in Linux do not filter based on VLAN tags. It can be enabled in Infix when creating a bridge by adding a port to a VLAN as a tagged or untagged member:
By default bridges in Linux do not filter based on VLAN tags. It can be enabled in Infix when creating a bridge by adding a port to a VLAN as a tagged or untagged member.
Use the port default VID (PVID) setting to control VLAN association for traffic ingressing a port untagged (default PVID: 1).
```
admin@example:/config/> edit interfaces interface br0
admin@example:/config/interfaces/interface/br0/> up
admin@example:/config/interfaces/> set interface eth0 bridge-port bridge br0
admin@example:/config/interfaces/> set interface eth1 bridge-port bridge br0
admin@example:/config/interfaces/> edit interface br0
admin@example:/config/interfaces/interface/br0/> set bridge vlans vlan 10 untagged eth0
admin@example:/config/interfaces/interface/br0/> set bridge vlans vlan 20 untagged eth1
admin@example:/config/> edit interface br0
admin@example:/config/interface/br0/> up
admin@example:/config/> set interface eth0 bridge-port bridge br0
admin@example:/config/> set interface eth0 bridge-port pvid 10
admin@example:/config interface eth1 bridge-port bridge br0
admin@example:/config/> set interface eth1 bridge-port pvid 20
admin@example:/config/> edit interface br0
admin@example:/config/interface/br0/> set bridge vlans vlan 10 untagged eth0
admin@example:/config/interface/br0/> set bridge vlans vlan 20 untagged eth1
```
This sets `eth0` as an untagged member of VLAN 10 and `eth1` as an
untagged member of VLAN 20. Switching between these ports is thus
prohibited.
To terminate a VLAN in the switch itself, either for switch management or for routing, the bridge must become a (tagged) member of the VLAN.
```
admin@example:/config/interface/br0/> set bridge vlans vlan 10 tagged br0
admin@example:/config/interface/br0/> set bridge vlans vlan 20 tagged br0
```
> To route or to manage via a VLAN, a VLAN interface also needs to be created on top of the bridge, see section [VLAN Interfaces](#vlan-interfaces) below.
### VLAN Interfaces
Creating a VLAN can be done in many ways. This section assumes VLAN interfaces created atop another Linux interface. E.g., the VLAN interfaces created on top of the bridge in the picture above.
Creating a VLAN can be done in many ways. This section assumes VLAN interfaces created atop another Linux interface. E.g., the VLAN interfaces created on top of the Ethernet interface or bridge in the picture below.
A VLAN interface is basically a filtering abstraction. When you run `tcpdump` on a VLAN interface you will only see the frames matching the VLAN ID of the interface, compared to *all* the VLAN IDs if you run `tcpdump` on the parent interface.
![VLAN interface on top of Ethernet or Bridge interfaces](img/interface-vlan-variants.svg)
A VLAN interface is basically a filtering abstraction. When you run `tcpdump` on a VLAN interface you will only see the frames matching the VLAN ID of the interface, compared to *all* the VLAN IDs if you run `tcpdump` on the lower-layer interface.
```
admin@example:/> configure
admin@example:/config/> edit interfaces interface eth0.20
admin@example:/config/interfaces/interface/eth0.20/> set encapsulation dot1q-vlan outer-tag tag-type c-vlan vlan-id 20
admin@example:/config/interfaces/interface/eth0.20/> set parent-interface eth0
admin@example:/config/interfaces/interface/eth0.20/> leave
admin@example:/config/> edit interface eth0.20
admin@example:/config/interface/eth0.20/> set vlan id 20
admin@example:/config/interface/eth0.20/> set vlan lower-layer-if eth0
admin@example:/config/interface/eth0.20/> leave
```
> **Note:** If you name your VLAN interface `foo0.N`, where `N` is a number, Infix will set the interface type automatically for you.
The example below assumes bridge br0 is already created, see [VLAN Filtering Bridge](#vlan-filtering-bridge).
```
admin@example:/> configure
admin@example:/config/> edit interface vlan10
admin@example:/config/interface/vlan10/> set vlan id 10
admin@example:/config/interface/vlan10/> set vlan lower-layer-if br0
admin@example:/config/interface/vlan10/> leave
```
As conventions, a VLAN interface for VID 20 on top of an Ethernet interface *eth0* is named *eth0.20*, and a VLAN interface for VID 10 on top of a bridge interface *br0* is named *vlan10*.
> **Note:** If you name your VLAN interface `foo0.N` or `vlanN`, where `N` is a number, Infix will set the interface type automatically for you.
## Management Plane
@@ -138,10 +163,10 @@ default.
![Setting static IPv4 (and link-local IPv4)](img/ip-address-example-ipv4-static.svg)
admin@example:/> configure
admin@example:/config/> edit interfaces interface eth0 ipv4
admin@example:/config/interfaces/interface/eth0/ipv4/> set address 10.0.1.1 prefix-length 24
admin@example:/config/interfaces/interface/eth0/ipv4/> set autoconf enabled true
admin@example:/config/interfaces/interface/eth0/ipv4/> diff
admin@example:/config/> edit interface eth0 ipv4
admin@example:/config/interface/eth0/ipv4/> set address 10.0.1.1 prefix-length 24
admin@example:/config/interface/eth0/ipv4/> set autoconf enabled true
admin@example:/config/interface/eth0/ipv4/> diff
+interfaces {
+ interface eth0 {
+ ipv4 {
@@ -154,7 +179,7 @@ default.
+ }
+ }
+}
admin@example:/config/interfaces/interface/eth0/ipv4/> leave
admin@example:/config/interface/eth0/ipv4/> leave
admin@example:/> show interfaces
INTERFACE PROTOCOL STATE DATA
eth0 ethernet UP 02:00:00:00:00:00
@@ -177,7 +202,7 @@ enabled true`. The resulting address (169.254.1.3/16) is of type
admin@example:/> configure
admin@example:/config/> edit dhcp-client
admin@example:/config/dhcp-client/> set client-if eth0
admin@example:/config/dhcp-client/> set enabled true
admin@example:/config/dhcp-client/> set enabled true
admin@example:/config/dhcp-client/> leave
admin@example:/> show interfaces
INTERFACE PROTOCOL STATE DATA
@@ -197,11 +222,11 @@ The resulting address (10.1.2.100/24) is of type *dhcp*.
The (only) way to disable IPv6 link-local addresses is by disabling IPv6 on the interface.
```(disabling
admin@example:/> configure
admin@example:/config/> edit interfaces interface eth0 ipv6
admin@example:/config/interfaces/interface/eth0/ipv6/> set enabled false
admin@example:/config/interfaces/interface/eth0/ipv6/> leave
admin@example:/> show interfaces
admin@example:/> configure
admin@example:/config/> edit interface eth0 ipv6
admin@example:/config/interface/eth0/ipv6/> set enabled false
admin@example:/config/interface/eth0/ipv6/> leave
admin@example:/> show interfaces
INTERFACE PROTOCOL STATE DATA
eth0 ethernet UP 02:00:00:00:00:00
lo ethernet UP 00:00:00:00:00:00
@@ -214,10 +239,10 @@ admin@example:/>
![Setting static IPv6](img/ip-address-example-ipv6-static.svg)
admin@example:/> configure
admin@example:/config/> edit interfaces interface eth0 ipv6
admin@example:/config/interfaces/interface/eth0/ipv6/> set address 2001:db8::1 prefix-length 64
admin@example:/config/interfaces/interface/eth0/ipv6/> leave
admin@example:/> configure
admin@example:/config/> edit interface eth0 ipv6
admin@example:/config/interface/eth0/ipv6/> set address 2001:db8::1 prefix-length 64
admin@example:/config/interface/eth0/ipv6/> leave
admin@example:/> show interfaces
INTERFACE PROTOCOL STATE DATA
eth0 ethernet UP 02:00:00:00:00:00
@@ -239,7 +264,7 @@ identifier. The resulting address is of type *link-layer*, as it
is formed based on the interface identifier ([IETF
ip-yang][ietf-ip-yang]).
admin@example:/> show interfaces
admin@example:/> show interfaces
INTERFACE PROTOCOL STATE DATA
eth0 ethernet UP 02:00:00:00:00:00
ipv6 2001:db8:0:1:0:ff:fe00:0/64 (link-layer)
@@ -253,9 +278,9 @@ Disabling auto-configuration of global IPv6 addresses can be done as shown
below.
admin@example:/> configure
admin@example:/config/> edit interfaces interface eth0 ipv6
admin@example:/config/interfaces/interface/eth0/ipv6/> set autoconf create-global-addresses false
admin@example:/config/interfaces/interface/eth0/ipv6/> leave
admin@example:/config/> edit interface eth0 ipv6
admin@example:/config/interface/eth0/ipv6/> set autoconf create-global-addresses false
admin@example:/config/interface/eth0/ipv6/> leave
admin@example:/> show interfaces
INTERFACE PROTOCOL STATE DATA
eth0 ethernet UP 02:00:00:00:00:00
@@ -272,7 +297,7 @@ below.
By default, the auto-configured link-local and global IPv6 addresses
are formed from a link-identifier based on the MAC address.
admin@example:/> show interfaces
admin@example:/> show interfaces
INTERFACE PROTOCOL STATE DATA
eth0 ethernet UP 02:00:00:00:00:00
ipv6 2001:db8:0:1:0:ff:fe00:0/64 (link-layer)
@@ -285,10 +310,10 @@ are formed from a link-identifier based on the MAC address.
To avoid revealing identity information in the IPv6 address, it is
possible to specify use of a random identifier ([ietf-ip][ietf-ip-yang] YANG and [RFC8981][ietf-ipv6-privacy]).
admin@example:/> configure
admin@example:/config/> edit interfaces interface eth0 ipv6
admin@example:/config/interfaces/interface/eth0/ipv6/> set autoconf create-temporary-addresses true
admin@example:/config/interfaces/interface/eth0/ipv6/> leave
admin@example:/> configure
admin@example:/config/> edit interface eth0 ipv6
admin@example:/config/interface/eth0/ipv6/> set autoconf create-temporary-addresses true
admin@example:/config/interface/eth0/ipv6/> leave
admin@example:/> show interfaces
INTERFACE PROTOCOL STATE DATA
eth0 ethernet UP 02:00:00:00:00:00
@@ -302,10 +327,51 @@ possible to specify use of a random identifier ([ietf-ip][ietf-ip-yang] YANG and
Both the link-local address (fe80::) and the global address (2001:)
have changed type to *random*.
## Routing support
| **Yang Model** | **Description** |
|:--------------------------|:----------------------------------------------------------|
| ietf-routing | Base routing model, required for all other routing models |
| ietf-ipv4-unicast-routing | Static IPv4 unicast routing |
### Static routes
admin@example:/> configure
admin@example:/config/> edit routing control-plane-protocol static name default
admin@example:/config/routing/control-plane-protocol/static/name/default/> set ipv4 route 192.168.200.0/24 next-hop next-hop-address 192.168.1.1
admin@example:/config/routing/control-plane-protocol/static/name/default/> leave
admin@example:/>
> **Note:** The only name allowed for a control-plane-protocol is currently
> *default*. Meaning, you can only have one instance per routing protocol.
### View IPv4 routing table
The routing table can be viewed from the operational datastore over
NETCONF or using the CLI:
admin@example:/> show routes
PREFIX NEXT-HOP METRIC PROTOCOL
192.168.1.0/24 e0 kernel
192.168.200.0/24 192.168.1.1 20 static
The source protocol describes the origin of the route.
| **Protocol** | **Description** |
|:-------------|:---------------------------------------------------------------------|
| kernel | Added when setting a subnet address on an interface |
| static | User created static routes |
| dhcp | Routes retrieved from DHCP |
The YANG model *ietf-routing* support multiple ribs but only two are
currently supported, namely `ipv4` and `ipv6`.
[ietf-ip-yang]: https://www.rfc-editor.org/rfc/rfc8344.html
[ietf-ipv6-privacy]: https://www.rfc-editor.org/rfc/rfc8981.html
[^1]: Please note, link aggregates are not yet supported in Infix.
[^2]: Link-local IPv6 addresses are implicitly enabled when enabling IPv6. IPv6 can be enabled/disabled per interface in [ietf-ip][ietf-ip-yang] YANG model.
[^2]: Link-local IPv6 addresses are implicitly enabled when enabling IPv6.
IPv6 can be enabled/disabled per interface in the [ietf-ip][ietf-ip-yang]
YANG model.
+50
View File
@@ -0,0 +1,50 @@
Package override
================
This guide demonstrates how the `local.mk` file is utilized to override
a Linux Buildroot package. The example of `tcpdump` serves to illustrate
this process.
In an instance such as `Infix` using tcpdump, the `local.mk` file is modified
as shown below:
```
TCPDUMP_OVERRIDE_SRCDIR = /path/to/tcpdump/repo
```
and stored in the `output/` folder, alongside the `.config` file:
```
user@PC:~/infix$ll output/ | grep -e 'local.mk' -e '.config'
-rw-r--r-- 1 group user 119936 Nov 10 18:04 .config
-rw-r--r-- 1 group user 43 Nov 10 18:25 local.mk
```
The execution of `make tcpdump-rebuild all` triggers a process where
Buildroot synchronizes the tcpdump source code from the specified override directory
to `output/build/tcpdump-custom`, followed by the rebuilding of the entire project.
```
user@PC:~/infix$ make tcpdump-rebuild all
```
```
user@PC:~/infix$ ll /output/build/ | grep tcpdump
drwxr-xr-x 7 group user 20480 Nov 10 18:26 tcpdump-4.99.4/
drwxr-xr-x 7 group user 12288 Nov 10 18:28 tcpdump-custom/
```
Buildroot follows a process of downloading and processing tarballs
(extraction, configuration, compilation, and installation).
The source code is stored in a temporary directory:
`output/build/<package>-<version>` (i.e. `tcpdump-4.99.4/`),
which is removed and recreated with each `make` command. That is why
the direct modifications in the `output/build` directory are generally
**not recommended**.
To manage the development changes more effectively, where the package source code
remains untouched, Buildroot incorporates the `<pkg>_OVERRIDE_SRCDIR` feature.
For a comprehensive understanding of utilizing Buildroot during development,
including detailed elaboration on the `<pkg>_OVERRIDE_SRCDIR` feature,
refer to section 8.13.6 in [Using Buildroot during development](https://nightly.buildroot.org/).
+24
View File
@@ -123,6 +123,30 @@ For more information, see [Containers in Infix](container.md).
> of course also enable it yourself in Infix by using `make menuconfig`
> followed by rebuilding the image.
### Customizing Services
When running containers a common question is: "what if we want an outside
SSH connection on port 22 to be forwarded to the container instead of the
Infix system?" There are two possible answers that currently require a
Hybrid Mode fix since it is not yet possible to configure the SSH daemon:
1. Disable SSH daemon
2. Run SSH daemon on another port
The first one is simple, use what you have learned above about start.d
scripts and add one that does `initctl disable sshd`.
The second is a little bit more involved:
```
root@infix:/cfg/start.d$ cat <<EOF >10-custom-sshd-port.sh
#!/bin/sh
echo SSHD_OPTS=\"-p222\" > /etc/default/sshd
EOF
root@infix:/cfg/start.d$ chmod +x 10-custom-sshd-port.sh
```
[1]: https://www.sysrepo.org/
[2]: https://github.com/CESNET/netopeer
+7
View File
@@ -17,3 +17,10 @@ run:
run-menuconfig: $(BUILD_DIR)/buildroot-config/mconf
CONFIG_="CONFIG_" BR2_CONFIG="$(BINARIES_DIR)/.config" \
$(BUILD_DIR)/buildroot-config/mconf $(BINARIES_DIR)/Config.in
define FRR_POST_BUILD_HOOK
mkdir -p $(TARGET_DIR)/etc/iproute2/
cp -r $(@D)/tools/etc/iproute2/rt_protos.d/ $(TARGET_DIR)/etc/iproute2/
endef
FRR_POST_BUILD_HOOKS += FRR_POST_BUILD_HOOK
+1 -1
View File
@@ -5,13 +5,13 @@ source "$BR2_EXTERNAL_INFIX_PATH/package/factory/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/faux/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/finit/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/ifupdown-ng/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/iito/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/klish-plugin-infix/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/klish/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/klish-plugin-sysrepo/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/libsrx/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/lowdown/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/mdnsd/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/net/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/podman/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/skeleton-init-finit/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/tetris/Config.in"
+9
View File
@@ -0,0 +1,9 @@
<?xml version="1.0" standalone='no'?>
<!DOCTYPE service-group SYSTEM "avahi-service.dtd">
<service-group>
<name replace-wildcards="yes">%h</name>
<service>
<type>_netconf-ssh._tcp</type>
<port>830</port>
</service>
</service-group>
+9 -9
View File
@@ -8,25 +8,25 @@ run name:error :1 log:console norestart if:<run/bootstrap/failure> \
[S] /usr/libexec/confd/error --
service name:confd log <run/bootstrap/success> \
[S12345789] sysrepo-plugind -f -p /run/confd.pid -n -v3 -- Configuration daemon
[S12345] sysrepo-plugind -f -p /run/confd.pid -n -v3 -- Configuration daemon
# Bootstrap system with startup-config
run name:startup log:prio:user.notice norestart \
[S] <pid/confd> /usr/libexec/confd/load -b startup-config \
run name:startup log:prio:user.notice norestart <pid/confd> \
[S] /usr/libexec/confd/load startup-config \
-- Loading startup-config
# Run if loading startup-config fails for some reason
run name:failure log:prio:user.critical norestart if:<run/startup/failure> \
[S] <pid/confd> /usr/libexec/confd/load failure-config \
run name:failure log:prio:user.critical norestart <pid/confd> if:<run/startup/failure> \
[S] /usr/libexec/confd/load failure-config \
-- Loading failure-config
run name:error :2 log:console norestart if:<run/failure/failure> \
[S] /usr/libexec/confd/error --
service name:netopeer log \
[12345789] <pid/confd> netopeer2-server -F -t 60 \
service name:netopeer notify:none log <pid/confd> \
[12345] netopeer2-server -F -t 60 \
-- NETCONF server
# Create initial /etc/resolv.conf after successful bootstrap
task name:resolv :conf norestart if:<run/startup/success> \
[S] <pid/dnsmasq> resolvconf -u -- Update DNS configuration
task name:resolv :conf norestart <pid/dnsmasq> if:<run/startup/success> \
[S] resolvconf -u -- Update DNS configuration
+2
View File
@@ -17,6 +17,8 @@ define CONFD_INSTALL_EXTRA
cp $(CONFD_PKGDIR)/confd.conf $(FINIT_D)/available/
ln -sf ../available/confd.conf $(FINIT_D)/enabled/confd.conf
cp $(CONFD_PKGDIR)/tmpfiles.conf $(TARGET_DIR)/etc/tmpfiles.d/confd.conf
mkdir -p $(TARGET_DIR)/etc/avahi/services
cp $(CONFD_PKGDIR)/avahi.service $(TARGET_DIR)/etc/avahi/services/netconf.service
endef
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_EXTRA
+2 -1
View File
@@ -1,2 +1,3 @@
d /run/confd/factory.d - - -
d /run/confd/failure.d - - -
d /run/resolvconf/interfaces - - -
+1 -1
View File
@@ -1,3 +1,3 @@
# Locally calculated
sha256 9d9d33b873917ca5d0bdcc47a36d2fd385971ab0c045d1472fcadf95ee5bcf5b LICENCE
sha256 f665a98cf5026f25a21b86d9cba55a8e6ee82f4f257a1b538bb4ebb7341c2179 faux-99c9cf7b95d8e2955519e2bec5ddb021eeda2d55-br1.tar.gz
sha256 f8725f39b9d9d45c8ad6fd2cfc3c1c834a80c32b4217a3d07dd8ed7fe4b6e352 faux-df1d569287bc45d8fd880287c00e3874c5627c19-br1.tar.gz
+1 -1
View File
@@ -4,7 +4,7 @@
#
################################################################################
FAUX_VERSION = 99c9cf7b95d8e2955519e2bec5ddb021eeda2d55
FAUX_VERSION = df1d569287bc45d8fd880287c00e3874c5627c19
FAUX_SITE = https://github.com/kernelkit/faux.git
#FAUX_VERSION = tags/2.1.0
#FAUX_SITE = https://src.libcode.org/pkun/faux.git
+1 -1
View File
@@ -1,5 +1,5 @@
# From https://github.com/troglobit/finit/releases/
sha256 904af0b0d7b22bcbe7772ea5851a0496445bfb3cff5c9a65935fd74745dcba75 finit-4.5-rc5.tar.gz
sha256 84ce1623ee935dc5d2d615ca14ed087f4bb3c47207fda97f26b1346e4983a6b2 finit-4.6.tar.gz
# Locally calculated
sha256 3a2b964c1772d03ab17b73a389ecce9151e0b190a9247817a2c009b16d356422 LICENSE
+7 -1
View File
@@ -4,7 +4,7 @@
#
################################################################################
FINIT_VERSION = 4.5-rc5
FINIT_VERSION = 4.6
FINIT_SITE = https://github.com/troglobit/finit/releases/download/$(FINIT_VERSION)
FINIT_LICENSE = MIT
FINIT_LICENSE_FILES = LICENSE
@@ -119,6 +119,12 @@ else
FINIT_CONF_OPTS += --disable-alsa-utils-plugin
endif
ifeq ($(BR2_PACKAGE_BASH_COMPLETION),y)
FINIT_CONF_OPTS += --with-bash-completiond-dir
else
FINIT_CONF_OPTS += --without-bash-completiond-dir
endif
ifeq ($(BR2_PACKAGE_DBUS),y)
FINIT_CONF_OPTS += --enable-dbus-plugin
else
@@ -1,5 +1,5 @@
# From https://github.com/addiva-elektronik/greenpak-programmer/releases/download/v1.1/greenpak-programmer-1.1.tar.gz.sha256
sha256 960521714312e3b519a238b6c527826c3aacf6af93252f9ceb2fa2a22e341449 greenpak-programmer-1.1.tar.gz
# From https://github.com/addiva-elektronik/greenpak-programmer/releases/download/v1.2/greenpak-programmer-1.2.tar.gz.sha256
sha256 6beec4e668f3f88c4a55c9784e4d34d1ec070a2f2cd33063c9cae0e02fc97cd9 greenpak-programmer-1.2.tar.gz
# Locally generated
sha256 c1673b6eecedfe5f461ee719291ff81b57d31f64f36cad3d00fb97b14dffc025 LICENSE.txt
@@ -4,7 +4,7 @@
#
################################################################################
GREENPAK_PROGRAMMER_VERSION = 1.1
GREENPAK_PROGRAMMER_VERSION = 1.2
GREENPAK_PROGRAMMER_SITE = https://github.com/addiva-elektronik/greenpak-programmer/releases/download/v$(GREENPAK_PROGRAMMER_VERSION)
GREENPAK_PROGRAMMER_LICENSE = MIT
GREENPAK_PROGRAMMER_LICENSE_FILES = LICENSE.txt
+11
View File
@@ -0,0 +1,11 @@
config BR2_PACKAGE_IITO
bool "iito"
depends on BR2_PACKAGE_HAS_UDEV
select BR2_PACKAGE_JANSSON
select BR2_PACKAGE_LIBEV
help
If Input, Then Output
Monitor input sources, and reflect their state on output sinks.
https://github.com/kernelkit/iito
+3
View File
@@ -0,0 +1,3 @@
# Locally calculated
sha256 7db4077b7c132170e9c358397cc2a30ae810ce24b8a5b66eb6b31c7c203156c1 iito-1.1.0.tar.gz
sha256 8177f97513213526df2cf6184d8ff986c675afb514d4e68a404010521b880643 COPYING
+22
View File
@@ -0,0 +1,22 @@
################################################################################
#
# iito
#
################################################################################
IITO_VERSION = 1.1.0
IITO_SITE = https://github.com/kernelkit/iito/releases/download/v$(IITO_VERSION)
IITO_LICENSE = GPL-2.0
IITO_LICENSE_FILES = COPYING
IITO_DEPENDENCIES = jansson libev udev
define IITO_INSTALL_HOOK
$(INSTALL) -D -m 0644 $(IITO_PKGDIR)/iitod.svc $(FINIT_D)/available/iitod.conf
$(INSTALL) -d -m 0755 $(FINIT_D)/enabled
ln -sf ../available/iitod.conf $(FINIT_D)/enabled/iitod.conf
cp $(IITO_PKGDIR)/tmpfiles.conf $(TARGET_DIR)/etc/tmpfiles.d/iitod.conf
endef
IITO_POST_INSTALL_TARGET_HOOKS += IITO_INSTALL_HOOK
$(eval $(autotools-package))
+1
View File
@@ -0,0 +1 @@
service [S0123456789] <!pid/syslogd> iitod -- LED daemon
+1
View File
@@ -0,0 +1 @@
d /run/led - - -
@@ -1,3 +1,3 @@
# Locally calculated
sha256 9d9d33b873917ca5d0bdcc47a36d2fd385971ab0c045d1472fcadf95ee5bcf5b LICENCE
sha256 5b20f20d0054d2df61d301bd5cc84d7a4a31d06b5faf268fc17950d6f521fc73 klish-plugin-sysrepo-b345ab9da2684623dec801aa935e99595c218a7b-br1.tar.gz
sha256 468b9a4da872257795964e2fff17fbfc5a592070a98a0a51e5f54464171ee73f klish-plugin-sysrepo-fa1228a7ff2b3500b8c1bc6f6f0d28bddd2d0a91-br1.tar.gz
@@ -4,7 +4,7 @@
#
################################################################################
KLISH_PLUGIN_SYSREPO_VERSION = b345ab9da2684623dec801aa935e99595c218a7b
KLISH_PLUGIN_SYSREPO_VERSION = fa1228a7ff2b3500b8c1bc6f6f0d28bddd2d0a91
KLISH_PLUGIN_SYSREPO_SITE = https://github.com/kernelkit/klish-plugin-sysrepo.git
#KLISH_PLUGIN_SYSREPO_VERSION = cdd3eb51a7f7ee0ed5bd925fa636061d3b1b85fb
#KLISH_PLUGIN_SYSREPO_SITE = https://src.libcode.org/pkun/klish-plugin-sysrepo.git
@@ -17,8 +17,7 @@ KLISH_PLUGIN_SYSREPO_AUTORECONF = YES
ifeq ($(BR2_PACKAGE_KLISH_PLUGIN_SYSREPO_XML),y)
define KLISH_PLUGIN_SYSREPO_INSTALL_XML
$(INSTALL) -t $(TARGET_DIR)/etc/klish -D -m 0644 \
$(@D)/xml/sysrepo.xml
$(INSTALL) -t $(TARGET_DIR)/etc/klish -D -m 0644 $(@D)/xml/sysrepo.xml
endef
KLISH_PLUGIN_SYSREPO_POST_INSTALL_TARGET_HOOKS += \
KLISH_PLUGIN_SYSREPO_INSTALL_XML
+14
View File
@@ -0,0 +1,14 @@
# Overrides for config file /etc/klish/klish.conf
UnixSocketPath=/run/klishd.sock
# Klish can use an external pager for all output
Pager="/usr/bin/less -I -F -e -X -K -d -r -S"
UsePager=y
# Set max size of history. By default 100 lines are saved, for every new
# line after that, the oldest line is dropped. Set to 0 for unlimited.
#HistorySize=100
# Save history after each (unique/non-repeated) command.
HistorySaveAlways=n
+1 -1
View File
@@ -1,3 +1,3 @@
# Locally calculated
sha256 9d9d33b873917ca5d0bdcc47a36d2fd385971ab0c045d1472fcadf95ee5bcf5b LICENCE
sha256 fa1b616d478a627158823994da4768e8ab166c9d5c8689b0c7a3f15f289e5d8e klish-8022195e6ed8122bbf2de6d31aba85bef85f072c-br1.tar.gz
sha256 0ef97fe42377e32be96a69096fc149e547568e6567d641cc50252356eb64e934 klish-ce81f52b50bcc3c37ce1ce2bec5a7965e2d698d2-br1.tar.gz
+4 -6
View File
@@ -4,7 +4,7 @@
#
################################################################################
KLISH_VERSION = 8022195e6ed8122bbf2de6d31aba85bef85f072c
KLISH_VERSION = ce81f52b50bcc3c37ce1ce2bec5a7965e2d698d2
KLISH_SITE = https://github.com/kernelkit/klish.git
#KLISH_VERSION = tags/3.0.0
#KLISH_SITE = https://src.libcode.org/pkun/klish.git
@@ -20,16 +20,14 @@ KLISH_CONF_OPTS += --with-libxml2
define KLISH_INSTALL_CONFIG
$(INSTALL) -t $(TARGET_DIR)/etc/klish -D -m 0644 \
$(@D)/plugins/klish/xml/ptypes.xml
$(INSTALL) -t $(TARGET_DIR)/etc/klish -D -m 0644 \
$(@D)/klish.conf $(@D)/klishd.conf
sed -i 's/#HistorySaveAlways=n/HistorySaveAlways=y/' $(TARGET_DIR)/etc/klish/klish.conf
$(INSTALL) -t $(TARGET_DIR)/etc/klish -m 0644 $(KLISH_PKGDIR)/klish.conf
$(INSTALL) -t $(TARGET_DIR)/etc/klish -m 0644 $(KLISH_PKGDIR)/klishd.conf
endef
KLISH_POST_INSTALL_TARGET_HOOKS += KLISH_INSTALL_CONFIG
ifeq ($(BR2_PACKAGE_KLISH_DEFAULT_XML),y)
define KLISH_INSTALL_XML
$(INSTALL) -t $(TARGET_DIR)/etc/klish -D -m 0644 \
$(BR2_EXTERNAL_INFIX_PATH)/package/klish/default.xml
$(INSTALL) -t $(TARGET_DIR)/etc/klish -m 0644 $(KLISH_PKGDIR)/default.xml
endef
KLISH_POST_INSTALL_TARGET_HOOKS += KLISH_INSTALL_XML
endif
+1 -1
View File
@@ -1 +1 @@
service <!> log [2345789] /usr/bin/klishd -d -- CLI backend daemon
service <!> log [2345] /usr/bin/klishd -d -- CLI backend daemon
+5
View File
@@ -0,0 +1,5 @@
# Overrides for config file /etc/klish/klishd.conf
UnixSocketPath=/run/klishd.sock
DBs=libxml2
-6
View File
@@ -1,6 +0,0 @@
config BR2_PACKAGE_NET
bool "net"
select BR2_PACKAGE_IPROUTE2
select BR2_PACKAGE_LIBITE
help
Handles transitions between network states.
-21
View File
@@ -1,21 +0,0 @@
################################################################################
#
# net
#
################################################################################
NET_VERSION = 1.0
NET_LICENSE = MIT
NET_LICENSE_FILES = LICENSE
NET_SITE_METHOD = local
NET_SITE = $(BR2_EXTERNAL_INFIX_PATH)/src/net
NET_REDISTRIBUTE = NO
NET_DEPENDENCIES = libite
NET_AUTORECONF = YES
define NET_INSTALL_EXTRA
chmod +x $(TARGET_DIR)/usr/share/net/*.sh
endef
NET_POST_INSTALL_TARGET_HOOKS += NET_INSTALL_EXTRA
$(eval $(autotools-package))
@@ -1 +1 @@
service [2345789] avahi-dnsconfd -s -- Avahi unicast DNS configuration daemon
service [2345] avahi-dnsconfd -s -- Avahi unicast DNS configuration daemon
@@ -1 +1 @@
service [2345789] name:mdns avahi-daemon -s -- Avahi mDNS-SD daemon
service [2345] name:mdns avahi-daemon -s -- Avahi mDNS-SD daemon
@@ -1,2 +1,2 @@
# Requires /etc/chrony.conf to start, see https://chrony.tuxfamily.org/doc/3.4/chrony.conf.html
service [2345789] <!> env:-/etc/default/chronyd chronyd -n $CHRONY_ARGS -- Chrony NTP v3/v4 daemon
service [2345] <!> env:-/etc/default/chronyd chronyd -n $CHRONY_ARGS -- Chrony NTP v3/v4 daemon
@@ -1 +1 @@
service [2345789] env:-/etc/default/conntrackd conntrackd $CONNTRACKD_ARGS -- Connection tracking daemon
service [2345] env:-/etc/default/conntrackd conntrackd $CONNTRACKD_ARGS -- Connection tracking daemon
@@ -1 +1 @@
service [S12345789] <pid/syslogd> dnsmasq -k -u root -- DHCP/DNS proxy
service [S12345] <pid/syslogd> dnsmasq -k -u root -- DHCP/DNS proxy
@@ -1,4 +1,4 @@
# <!>: dropbear does not honor SIGHUP.
# -R: Create hostkeys if needed.
# -F: Run in foreground.
service [2345789] <!> env:-/etc/default/dropbear dropbear -F -R $DROPBEAR_ARGS -- Dropbear SSH daemon
service [2345] <!> env:-/etc/default/dropbear dropbear -F -R $DROPBEAR_ARGS -- Dropbear SSH daemon
@@ -1 +1 @@
service [2345789] log:null <!pid/zebra> babled -A 127.0.0.1 -u frr -g frr -- Babel routing daemon
service [2345] log:null <!pid/zebra> babled -A 127.0.0.1 -u frr -g frr -- Babel routing daemon
@@ -1 +1 @@
service [2345789] log:null <!pid/zebra> bfdd -A 127.0.0.1 -u frr -g frr -- BFD daemon
service [2345] log:null <!pid/zebra> bfdd -A 127.0.0.1 -u frr -g frr -- BFD daemon
@@ -1 +1 @@
service [2345789] log:null <!pid/zebra> bgpd -A 127.0.0.1 -u frr -g frr -- BGP daemon
service [2345] log:null <!pid/zebra> bgpd -A 127.0.0.1 -u frr -g frr -- BGP daemon
@@ -1 +1 @@
service [2345789] log:null <!pid/zebra> eigrpd -A 127.0.0.1 -u frr -g frr -- EIGRP daemon
service [2345] log:null <!pid/zebra> eigrpd -A 127.0.0.1 -u frr -g frr -- EIGRP daemon

Some files were not shown because too many files have changed in this diff Show More