mirror of
https://github.com/kernelkit/infix.git
synced 2026-08-02 22:03:01 +02:00
Compare commits
791
Commits
rngd
..
upload-image
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
cc0edaf59c | ||
|
|
60b3a97f0e | ||
|
|
e534c0bd2d | ||
|
|
692fa166d1 | ||
|
|
c5d9a7c8b3 | ||
|
|
45c588567d | ||
|
|
2a8580edcc | ||
|
|
ffd0c05f41 | ||
|
|
9271c2439f | ||
|
|
7295077f27 | ||
|
|
b3d76de8f3 | ||
|
|
56f14ff520 | ||
|
|
9845e3b0c7 | ||
|
|
08e6833266 | ||
|
|
df54982978 | ||
|
|
efd6cce842 | ||
|
|
1dc84af095 | ||
|
|
d6c0d4bea7 | ||
|
|
85c4b579d3 | ||
|
|
1f268a7b90 | ||
|
|
562fd253c4 | ||
|
|
be547ba9a8 | ||
|
|
40e94883c6 | ||
|
|
9f268606e4 | ||
|
|
de113503ea | ||
|
|
6f203b1c78 | ||
|
|
c31bbbefa9 | ||
|
|
0d03f874ee | ||
|
|
51176c7d26 | ||
|
|
88958a0b1f | ||
|
|
e3f87799b6 | ||
|
|
ebcb38be37 | ||
|
|
889fb3eb79 | ||
|
|
2a6e7e5208 | ||
|
|
9629e2eef4 | ||
|
|
a0c48e7b5f | ||
|
|
edd2e60dd5 | ||
|
|
ec82d68a9f | ||
|
|
20d5426935 | ||
|
|
9d6d0e2388 | ||
|
|
6167f2a6a4 | ||
|
|
4ad2664b78 | ||
|
|
fe031f1a10 | ||
|
|
0a3277caf2 | ||
|
|
cac357458c | ||
|
|
7b8bc43bca | ||
|
|
5c7fc3f570 | ||
|
|
bae70ec85a | ||
|
|
eeb10b0f07 | ||
|
|
b92c9daedd | ||
|
|
eabaaac7c2 | ||
|
|
de33df14e2 | ||
|
|
5eeed0e743 | ||
|
|
24852caad0 | ||
|
|
08f4207277 | ||
|
|
5fbb30fed5 | ||
|
|
f25f0ab050 | ||
|
|
b53c1612f0 | ||
|
|
57d5bf1577 | ||
|
|
0ad8fab5c7 | ||
|
|
ecabce86c7 | ||
|
|
a7e72a46d9 | ||
|
|
915bef2dd4 | ||
|
|
7f9a1df6f7 | ||
|
|
67a6fc18d5 | ||
|
|
8538888069 | ||
|
|
5a1cf7f9f8 | ||
|
|
6755011b25 | ||
|
|
e5a8514fa0 | ||
|
|
82c3eb1ee7 | ||
|
|
159135786a | ||
|
|
8a9415f0b4 | ||
|
|
93cffaedde | ||
|
|
991364b411 | ||
|
|
22cf97fdbd | ||
|
|
16c1b50349 | ||
|
|
d2e5c2cd29 | ||
|
|
8bca1bed9e | ||
|
|
b88841952a | ||
|
|
9c3e951286 | ||
|
|
c7c01e3616 | ||
|
|
a6889fa8c5 | ||
|
|
6cd92c25a8 | ||
|
|
ff4e20221c | ||
|
|
808edf0a29 | ||
|
|
3f68e297ef | ||
|
|
0158fe1adb | ||
|
|
4345ec1694 | ||
|
|
ebace5020b | ||
|
|
ae4424dafe | ||
|
|
50036e086d | ||
|
|
6d53d92346 | ||
|
|
e0696c453a | ||
|
|
8b9a452f0c | ||
|
|
8bc7858694 | ||
|
|
0065aeef47 | ||
|
|
dfc350a783 | ||
|
|
21a78c7639 | ||
|
|
d6d621af36 | ||
|
|
e6ea2991e1 | ||
|
|
00f69baace | ||
|
|
e5299fff1c | ||
|
|
d5e96a8232 | ||
|
|
aff385f37f | ||
|
|
e40fc33a55 | ||
|
|
71b4aed05d | ||
|
|
50a94e8175 | ||
|
|
2cbba5cf1f | ||
|
|
00f2a4cf33 | ||
|
|
ec7891c097 | ||
|
|
9c0a8e39ec | ||
|
|
4a4325baa3 | ||
|
|
cae5cfd3f0 | ||
|
|
fa7c3d0a51 | ||
|
|
874c0a54c4 | ||
|
|
6a2abd962f | ||
|
|
aa995e3321 | ||
|
|
0a74ba341f | ||
|
|
13de8be58d | ||
|
|
606aee68db | ||
|
|
e4578364b6 | ||
|
|
5cdaebf5e8 | ||
|
|
2848cd62bc | ||
|
|
2303fc08aa | ||
|
|
6277aaedcd | ||
|
|
f81b74458d | ||
|
|
8f61879966 | ||
|
|
5560266e19 | ||
|
|
d8cbdd7d92 | ||
|
|
7560da80a7 | ||
|
|
413cb61112 | ||
|
|
e3c6f749ad | ||
|
|
a990e559f7 | ||
|
|
a0b06b2593 | ||
|
|
354650c0a5 | ||
|
|
12e5b4c1b4 | ||
|
|
cfbdce1b90 | ||
|
|
0b29e9eee4 | ||
|
|
3f0a0e3df0 | ||
|
|
3b261b331d | ||
|
|
066ec71736 | ||
|
|
71295e0e37 | ||
|
|
ac89f94580 | ||
|
|
399984082f | ||
|
|
3375555911 | ||
|
|
794872ca0c | ||
|
|
b7f110dbdc | ||
|
|
af20325cc4 | ||
|
|
7a5c9d0324 | ||
|
|
a2533aa9c4 | ||
|
|
4d650bad7f | ||
|
|
ff5b71b825 | ||
|
|
2b5cf29bb9 | ||
|
|
513c03a764 | ||
|
|
5a982ab9ff | ||
|
|
4ea451362f | ||
|
|
44be4e57f0 | ||
|
|
dc0871a093 | ||
|
|
c6b44db18a | ||
|
|
a4def1379c | ||
|
|
028ab7c1f9 | ||
|
|
cc03a59725 | ||
|
|
092964a10b | ||
|
|
d0277de958 | ||
|
|
2df84e20af | ||
|
|
9de4633c13 | ||
|
|
50f955c242 | ||
|
|
f2f539b492 | ||
|
|
2b439298fb | ||
|
|
2ef759a9d8 | ||
|
|
6fe4db8431 | ||
|
|
b2525e29e1 | ||
|
|
7ef5223fca | ||
|
|
323bfc9d66 | ||
|
|
d6be23fa6b | ||
|
|
c7c2998e33 | ||
|
|
184ed470d7 | ||
|
|
75352a9f77 | ||
|
|
e3c601f2fd | ||
|
|
0ab9e2a36a | ||
|
|
7b20665cf9 | ||
|
|
3d86ecd2ee | ||
|
|
403b79d370 | ||
|
|
740ecbcc43 | ||
|
|
42af6eec30 | ||
|
|
c584af356b | ||
|
|
827dc098e4 | ||
|
|
bc5dd949d7 | ||
|
|
4a932dec11 | ||
|
|
d5c5e38604 | ||
|
|
02080bfb6c | ||
|
|
d3fa51e4fa | ||
|
|
6cfe5f8c58 | ||
|
|
b4f3e4eab8 | ||
|
|
b188e781ee | ||
|
|
8156179f1b | ||
|
|
55632eebaa | ||
|
|
71b11026bb | ||
|
|
2b28733fda | ||
|
|
8c115e17c4 | ||
|
|
10f62f679b | ||
|
|
fa4f7c6532 | ||
|
|
0647541988 | ||
|
|
2602ddc0b8 | ||
|
|
3886b284d3 | ||
|
|
22a9405d1e | ||
|
|
2902dccf11 | ||
|
|
644374bb29 | ||
|
|
a868307637 | ||
|
|
d213861e02 | ||
|
|
3d538d4eca | ||
|
|
06a6dd17f8 | ||
|
|
18659fd45a | ||
|
|
7253be7619 | ||
|
|
910749bab1 | ||
|
|
4f9b3146a1 | ||
|
|
b026abd0bc | ||
|
|
08658a37c4 | ||
|
|
6bbf2d02a8 | ||
|
|
538185c29e | ||
|
|
bd05715ba0 | ||
|
|
6960cd30eb | ||
|
|
c5c21dec83 | ||
|
|
73de6b6d42 | ||
|
|
f698d5f0ee | ||
|
|
7e59406436 | ||
|
|
b8a9dc9743 | ||
|
|
1b5aa16652 | ||
|
|
3f491ea785 | ||
|
|
9bdad9bc8b | ||
|
|
de711b0123 | ||
|
|
b52c462cfa | ||
|
|
f4e75dfecb | ||
|
|
c5fe10aada | ||
|
|
97623b989c | ||
|
|
ed2a776c55 | ||
|
|
ac4fcb61c6 | ||
|
|
41fa664a86 | ||
|
|
4f54cbe975 | ||
|
|
2291e9fd11 | ||
|
|
095c9c331e | ||
|
|
b8fc8b7f62 | ||
|
|
95931c8c0a | ||
|
|
dd788f5611 | ||
|
|
5d99c12089 | ||
|
|
03437fc936 | ||
|
|
56a086ef52 | ||
|
|
3f3fb4eeb4 | ||
|
|
4998e320c5 | ||
|
|
496d56e975 | ||
|
|
82df624ae9 | ||
|
|
5021a1da88 | ||
|
|
df1fc6f2d7 | ||
|
|
2ebcf26ede | ||
|
|
b1a77deadf | ||
|
|
bce1b34873 | ||
|
|
91f31c00c3 | ||
|
|
4b4ffdd14e | ||
|
|
50c83f1be7 | ||
|
|
ee86d12dc2 | ||
|
|
b388e080ad | ||
|
|
6e630018df | ||
|
|
9de5e5b802 | ||
|
|
399d3c365d | ||
|
|
3867abe4da | ||
|
|
90d2ae3868 | ||
|
|
581d1742e5 | ||
|
|
172d7607bb | ||
|
|
62a4b48679 | ||
|
|
3e07c9a960 | ||
|
|
05c197c457 | ||
|
|
77c321daa3 | ||
|
|
3d99af87d6 | ||
|
|
28c2a4a6cc | ||
|
|
1bbd62c021 | ||
|
|
ecc0b63da2 | ||
|
|
347e493542 | ||
|
|
77499790ba | ||
|
|
a960267c40 | ||
|
|
b9f3254ba7 | ||
|
|
266f18bbeb | ||
|
|
b70129f178 | ||
|
|
888f0c4207 | ||
|
|
88fa47c664 | ||
|
|
2ecc2c3602 | ||
|
|
02d8288863 | ||
|
|
d1dde5406e | ||
|
|
fd7b4bbe39 | ||
|
|
c28ea1db19 | ||
|
|
d68dacdc80 | ||
|
|
91f0094048 | ||
|
|
5660f6239d | ||
|
|
58cf5abf0b | ||
|
|
fc32d8a9db | ||
|
|
4b2f140140 | ||
|
|
67cb307f2d | ||
|
|
3811df9ab2 | ||
|
|
53d0995d0c | ||
|
|
7a692fd57d | ||
|
|
73e1c158f5 | ||
|
|
ab3b389f69 | ||
|
|
417d48f015 | ||
|
|
b6aa604cdd | ||
|
|
0dbf99cc82 | ||
|
|
7127caf6b5 | ||
|
|
638862d268 | ||
|
|
2d7dedf79c | ||
|
|
f690cd216c | ||
|
|
6a5bf66a42 | ||
|
|
5707711d84 | ||
|
|
5b3eb23aeb | ||
|
|
51987948ad | ||
|
|
e70559a68d | ||
|
|
83797ca19c | ||
|
|
d82b3e51ea | ||
|
|
e03bd37660 | ||
|
|
ee26cec88a | ||
|
|
88763034ed | ||
|
|
dad1c024aa | ||
|
|
f92d3846db | ||
|
|
ffab761274 | ||
|
|
b4c648229a | ||
|
|
1ca7acda14 | ||
|
|
8f30f88967 | ||
|
|
8eaaaa9d38 | ||
|
|
4e0ad1df1b | ||
|
|
dc3b78e678 | ||
|
|
4d7dde5366 | ||
|
|
3c0679991d | ||
|
|
fe741a92f3 | ||
|
|
f6879e24cc | ||
|
|
7e252ba941 | ||
|
|
46d5e750d7 | ||
|
|
5988249f84 | ||
|
|
7aee2600ba | ||
|
|
6f99a9c2dc | ||
|
|
eee1ce32fa | ||
|
|
d9f2f2c8f9 | ||
|
|
31d0f79a10 | ||
|
|
b290e44318 | ||
|
|
2d806de2cd | ||
|
|
c5db34b491 | ||
|
|
3d816d2525 | ||
|
|
fb394db981 | ||
|
|
da39855cec | ||
|
|
a6b79857db | ||
|
|
f1271f28b9 | ||
|
|
f62900699a | ||
|
|
cf16efe499 | ||
|
|
4260d24143 | ||
|
|
3ef1da1096 | ||
|
|
a90a39e8d8 | ||
|
|
dc5c7732d7 | ||
|
|
5bf9200880 | ||
|
|
f9b155b49f | ||
|
|
9782ac9afa | ||
|
|
773683bfd5 | ||
|
|
3dbb1759eb | ||
|
|
d7895d5c9c | ||
|
|
78499757b0 | ||
|
|
ec2e161649 | ||
|
|
18d8c439bd | ||
|
|
1ca11f1fe7 | ||
|
|
b70d0015a6 | ||
|
|
6a417f2f23 | ||
|
|
f212f0cc16 | ||
|
|
01d07b4942 | ||
|
|
039cb5db74 | ||
|
|
65bce0378e | ||
|
|
91cef6d57b | ||
|
|
f3da31b18c | ||
|
|
af1f173497 | ||
|
|
14fede3e56 | ||
|
|
d3bfbb57b6 | ||
|
|
3203ee925a | ||
|
|
fae1265587 | ||
|
|
97f3db8fdb | ||
|
|
a8b5120871 | ||
|
|
c22339c2cd | ||
|
|
b1830a36d4 | ||
|
|
05510c5001 | ||
|
|
343c465352 | ||
|
|
0cb2987de4 | ||
|
|
7d646c9494 | ||
|
|
395b21c693 | ||
|
|
6ef3ad9020 | ||
|
|
a608c4a36d | ||
|
|
e48da5bb21 | ||
|
|
f389a1f087 | ||
|
|
84521ea9b5 | ||
|
|
4ba43e2ddd | ||
|
|
3606bc05cf | ||
|
|
5e89d8ef3e | ||
|
|
028fc578b1 | ||
|
|
52e957d47f | ||
|
|
95cfcaa2fe | ||
|
|
340330b75b | ||
|
|
af8a90d651 | ||
|
|
ee44da6272 | ||
|
|
a5aba02ddd | ||
|
|
cb73ddf6bf | ||
|
|
e45fcfca41 | ||
|
|
27dae1edf0 | ||
|
|
d1e1c9ad33 | ||
|
|
d28fff67f2 | ||
|
|
62d539c424 | ||
|
|
3c1e9f3199 | ||
|
|
b196194e5f | ||
|
|
5ee78e28ad | ||
|
|
bcfd3d4a5b | ||
|
|
f86f184783 | ||
|
|
60f459687c | ||
|
|
455c384164 | ||
|
|
1fef35f77c | ||
|
|
8bc389987c | ||
|
|
ee56ebc205 | ||
|
|
9198383742 | ||
|
|
b010ad04bf | ||
|
|
4458e03cd2 | ||
|
|
4a37369750 | ||
|
|
7af75c0786 | ||
|
|
0fbe225b05 | ||
|
|
2405c002e4 | ||
|
|
1cc9e3c9c8 | ||
|
|
a64c9695cc | ||
|
|
d9be0b3a64 | ||
|
|
8b4682ac8b | ||
|
|
a975da2159 | ||
|
|
e483ddb487 | ||
|
|
267c8e0103 | ||
|
|
25f0d8ca2e | ||
|
|
be0edc00cc | ||
|
|
dc393946ce | ||
|
|
80a522ce08 | ||
|
|
b3ad9e5693 | ||
|
|
cc8c917de1 | ||
|
|
2a3fcbacd0 | ||
|
|
5c9cf276df | ||
|
|
76203b392a | ||
|
|
18913770fe | ||
|
|
2f23baf745 | ||
|
|
a7ce8c2ab4 | ||
|
|
d7ac84cf99 | ||
|
|
04b739b0bd | ||
|
|
131c0b1d4b | ||
|
|
f42c35d8ab | ||
|
|
0187d62246 | ||
|
|
01201708e3 | ||
|
|
986a28c891 | ||
|
|
0bbcd7ec43 | ||
|
|
f9dacaa0ff | ||
|
|
8f6a75806f | ||
|
|
05cb07c0ec | ||
|
|
d6ace7cc73 | ||
|
|
9ef6d2d038 | ||
|
|
c1e6f0c53b | ||
|
|
0e82c108bc | ||
|
|
9427b6a655 | ||
|
|
6a09e2c797 | ||
|
|
3b0b38360c | ||
|
|
3b3fe18f9d | ||
|
|
dedab8c2a2 | ||
|
|
3e0b816351 | ||
|
|
3f8fae2f16 | ||
|
|
70bcebc451 | ||
|
|
6a384bf48b | ||
|
|
10add98d90 | ||
|
|
a2257731ca | ||
|
|
6be990f1bb | ||
|
|
370920e931 | ||
|
|
ee441e172d | ||
|
|
5e90bde8b9 | ||
|
|
0b2f53e3b4 | ||
|
|
1fd55c484a | ||
|
|
1d13c5ea9e | ||
|
|
26303f5168 | ||
|
|
19c1f49fd3 | ||
|
|
5b8b1eec57 | ||
|
|
d83c333b2d | ||
|
|
4598585d4a | ||
|
|
c2959cf41e | ||
|
|
a640460baf | ||
|
|
5d6180a395 | ||
|
|
28c0cee4e3 | ||
|
|
27bba2c47c | ||
|
|
4753e35d7f | ||
|
|
28f67ff608 | ||
|
|
e1a033b97d | ||
|
|
2b7d2b4005 | ||
|
|
39de797b10 | ||
|
|
de9b1cdd2d | ||
|
|
f0c57da4ab | ||
|
|
b5218f7149 | ||
|
|
7cb311b5bc | ||
|
|
254c922254 | ||
|
|
4fb26b1119 | ||
|
|
ad262459b7 | ||
|
|
71b89d06d7 | ||
|
|
72b3058774 | ||
|
|
57c8d0cf1b | ||
|
|
f4c9a57bb5 | ||
|
|
9879e8b685 | ||
|
|
beecff2acf | ||
|
|
6f2face898 | ||
|
|
ddc8282dd7 | ||
|
|
c244042e55 | ||
|
|
78b7b34799 | ||
|
|
e397012394 | ||
|
|
5cc73ab97c | ||
|
|
be1b7cdf45 | ||
|
|
41f3fe15a6 | ||
|
|
df3a55d6a0 | ||
|
|
4e83520b0e | ||
|
|
94cd526772 | ||
|
|
4782cee201 | ||
|
|
907401f6f2 | ||
|
|
9a831217e4 | ||
|
|
1aab75d86a | ||
|
|
147cb713ed | ||
|
|
12b6146551 | ||
|
|
29031be4e9 | ||
|
|
b2db59f3bc | ||
|
|
cf129d1f9c | ||
|
|
41b96e8a01 | ||
|
|
805ddf6c92 | ||
|
|
547a9cd632 | ||
|
|
2ec226640e | ||
|
|
a0e4e813dd | ||
|
|
8812ae7052 | ||
|
|
28bf2d6c3c | ||
|
|
dadf0e2d16 | ||
|
|
c4a79766b7 | ||
|
|
385eab2016 | ||
|
|
bc33d8bc8a | ||
|
|
061fa5fc72 | ||
|
|
ac0acfe7c1 | ||
|
|
f3f313bb98 | ||
|
|
3ef40031dd | ||
|
|
44b60956a8 | ||
|
|
e4535aa856 | ||
|
|
343400c5fe | ||
|
|
bfeeade43b | ||
|
|
b425edffce | ||
|
|
f041d009b5 | ||
|
|
26d06bd13b | ||
|
|
9d51470ee2 | ||
|
|
49a003088b | ||
|
|
c099d887af | ||
|
|
08990556e2 | ||
|
|
cd5b076751 | ||
|
|
081f8e8412 | ||
|
|
465d8cbc82 | ||
|
|
323c77b702 | ||
|
|
780077e729 | ||
|
|
324bcb2533 | ||
|
|
e29a721571 | ||
|
|
389fc96794 | ||
|
|
da260fabf9 | ||
|
|
79bec6877c | ||
|
|
37b97d9e4c | ||
|
|
2e81e99224 | ||
|
|
bea18c2fa9 | ||
|
|
0233fdbf35 | ||
|
|
23ca94ea42 | ||
|
|
a8545e3369 | ||
|
|
1f2973d93f | ||
|
|
e00737ef78 | ||
|
|
a90294fe08 | ||
|
|
77215aeb87 | ||
|
|
7dfb1f131e | ||
|
|
7fecac2973 | ||
|
|
bb939ccdff | ||
|
|
8e38b34c55 | ||
|
|
ff8669e735 | ||
|
|
6a4c8f738e | ||
|
|
03cab6d1e4 | ||
|
|
96779c2620 | ||
|
|
e9a71ec3f7 | ||
|
|
b3da4c50fc | ||
|
|
eb9ae5e4dd | ||
|
|
9591093379 | ||
|
|
68d8c19b53 | ||
|
|
dc2ced8e09 | ||
|
|
02a8c3d78d | ||
|
|
a4ef38fbee | ||
|
|
5608e9457d | ||
|
|
34f0c5a462 | ||
|
|
5675f89d37 | ||
|
|
6d6f4e6dd9 | ||
|
|
f06a42987a | ||
|
|
76ab0fe07a | ||
|
|
734958b89d | ||
|
|
397568f1c8 | ||
|
|
a2c3919c0f | ||
|
|
e08576b008 | ||
|
|
83238aad7e | ||
|
|
1863297b5a | ||
|
|
9cd9440515 | ||
|
|
ec64c1585c | ||
|
|
429c4f1573 | ||
|
|
28ae8fca42 | ||
|
|
c076f0a770 | ||
|
|
219c61081d | ||
|
|
ad32129a13 | ||
|
|
1db039d6b4 | ||
|
|
f023304823 | ||
|
|
85603eb53d | ||
|
|
1f231c2b2a | ||
|
|
967388395f | ||
|
|
94cffd2c48 | ||
|
|
89c5b67a13 | ||
|
|
3436cd68ac | ||
|
|
d16ad7eedc | ||
|
|
e635e3e720 | ||
|
|
42b7cf9f94 | ||
|
|
7d9211a3ba | ||
|
|
1895e161d2 | ||
|
|
7804787201 | ||
|
|
3576450982 | ||
|
|
bb987cfe9e | ||
|
|
997310f9a2 | ||
|
|
bf23f53770 | ||
|
|
e8f9032339 | ||
|
|
80e4018b20 | ||
|
|
27b7d831d0 | ||
|
|
f0ae1aa835 | ||
|
|
88f7c6070a | ||
|
|
a3f85a3872 | ||
|
|
7467b2fcf4 | ||
|
|
3e387d74c2 | ||
|
|
f961bcfe86 | ||
|
|
ce05139452 | ||
|
|
a74eb58000 | ||
|
|
5cafd18b79 | ||
|
|
7334d0e54b | ||
|
|
fffe427497 | ||
|
|
168647ace9 | ||
|
|
0e14e05ae5 | ||
|
|
3ab7a7d531 | ||
|
|
fcef1ead3a | ||
|
|
784b391467 | ||
|
|
6d18ba4c39 | ||
|
|
fbe18a4ae0 | ||
|
|
020f0d0980 | ||
|
|
3fd4f2c72f | ||
|
|
fbabf0e857 | ||
|
|
a23dc89592 | ||
|
|
36d9056e8f | ||
|
|
ca0e54b50b | ||
|
|
bb1a656a05 | ||
|
|
7483a6f454 | ||
|
|
6072ec45b3 | ||
|
|
1ac07b5a7b | ||
|
|
ad9c432ff9 | ||
|
|
af0e24adf8 | ||
|
|
e39ef89150 | ||
|
|
877e3f3d81 | ||
|
|
ddfdcb40bb | ||
|
|
f4557ff8ab | ||
|
|
b6f9b6d967 | ||
|
|
6c2ab33028 | ||
|
|
63e1ff1fe9 | ||
|
|
0c88c464f1 | ||
|
|
70e8895478 | ||
|
|
371db579ea | ||
|
|
591397d3c7 | ||
|
|
88ab2a6f43 | ||
|
|
f6bd2094f0 | ||
|
|
b36e55e642 | ||
|
|
eabf79c7c4 | ||
|
|
963364d4e9 | ||
|
|
bc9c6a4871 | ||
|
|
d9eae887a0 | ||
|
|
e9efd224f7 | ||
|
|
e9fc62b365 | ||
|
|
03a2cf7b3b | ||
|
|
289534e0d5 | ||
|
|
d81b20ca0b | ||
|
|
68c86c8a89 | ||
|
|
de50179b3b | ||
|
|
66ae02363e | ||
|
|
866b9de779 | ||
|
|
77df9a327d | ||
|
|
1cfbf9bc11 | ||
|
|
81f80bd307 | ||
|
|
f381977e7b | ||
|
|
6d6a788749 | ||
|
|
7a642f9f8c | ||
|
|
c0ee09047b | ||
|
|
14dea0ca97 | ||
|
|
bbc9a55c1e | ||
|
|
82fd4bdb68 | ||
|
|
c7db71d095 | ||
|
|
5264a1c32b | ||
|
|
fabb28b5df | ||
|
|
de47caec38 | ||
|
|
d99b6fd557 | ||
|
|
a3af3f9be4 | ||
|
|
260d9615ec | ||
|
|
798194b64a | ||
|
|
0160fd539e | ||
|
|
df2689ca34 | ||
|
|
f9d21e5839 | ||
|
|
c8046bfbda | ||
|
|
74a12b3e31 | ||
|
|
efaad3c5b8 | ||
|
|
3d189d8ec6 | ||
|
|
06721a17b3 | ||
|
|
d7c7c33e72 | ||
|
|
47bb54254c | ||
|
|
30028f36a9 | ||
|
|
131d9e99b3 | ||
|
|
1ed8ad1233 | ||
|
|
8d32a525f3 | ||
|
|
3bbe9a9a9d | ||
|
|
ee0adce2a3 | ||
|
|
09077c6122 | ||
|
|
4c78613c4c | ||
|
|
7ec37a7efb | ||
|
|
904040098a | ||
|
|
8838efaf9d | ||
|
|
2d37e4be2c | ||
|
|
e480e26065 | ||
|
|
2aea461e7e | ||
|
|
7b389f6d0a | ||
|
|
43635c2727 | ||
|
|
c79e198615 | ||
|
|
021767c903 | ||
|
|
449fd46ea7 | ||
|
|
4a9d977682 | ||
|
|
5ace3afa5f | ||
|
|
1347080b4a | ||
|
|
db447712f7 | ||
|
|
2922b909af | ||
|
|
28c5f5e56f | ||
|
|
46dd0c7467 | ||
|
|
aa538820de | ||
|
|
7670f23805 | ||
|
|
c55b534005 | ||
|
|
cbcd39cdd6 | ||
|
|
032a51b9fc | ||
|
|
f4bf72de85 | ||
|
|
deee48d36a | ||
|
|
23e24635fe | ||
|
|
eb38d4538f | ||
|
|
2910d8b9bf | ||
|
|
6bdfdbe164 | ||
|
|
ceb78d66a2 | ||
|
|
9ac77be9eb | ||
|
|
d692a3d745 | ||
|
|
597da90b05 | ||
|
|
5d524006a3 | ||
|
|
4c1de659cb | ||
|
|
3b01f2d806 | ||
|
|
4e2458e18a | ||
|
|
dc741bb567 | ||
|
|
d5d487070f | ||
|
|
7052c54165 | ||
|
|
e25eb1966e | ||
|
|
fe1c47e107 | ||
|
|
57b66ec6d3 | ||
|
|
9103d31950 | ||
|
|
32ec9887b9 | ||
|
|
e0458ca079 | ||
|
|
e9aefc517f | ||
|
|
20295b08b5 | ||
|
|
7a9f1c1d7a | ||
|
|
7e08555013 | ||
|
|
82ff83c50d | ||
|
|
d277f5a860 | ||
|
|
f537e2fc13 | ||
|
|
73070f40c4 | ||
|
|
a0fb42e46d | ||
|
|
a820beebfa | ||
|
|
204672779b | ||
|
|
6a9f9fd3cc | ||
|
|
a78fd3da0a | ||
|
|
8721255554 | ||
|
|
5079691201 | ||
|
|
a23634dd7e | ||
|
|
3840ebc9fe | ||
|
|
56abfde8ec | ||
|
|
96d200fe70 | ||
|
|
7f2f3768db | ||
|
|
dc92db4e9f | ||
|
|
be828d46c9 | ||
|
|
a4a4a49eae | ||
|
|
2a6e4402f8 | ||
|
|
3031bba047 | ||
|
|
f9e430e41d | ||
|
|
17403afeb4 |
@@ -33,3 +33,4 @@ Releases
|
|||||||
- Easy to forget adaptations/hacks in customer repos -- may need Infix change/support
|
- Easy to forget adaptations/hacks in customer repos -- may need Infix change/support
|
||||||
- Ensure the markdown link for the release diff is updated
|
- Ensure the markdown link for the release diff is updated
|
||||||
- Ensure subrepos are tagged (can be automated, see kernelkit/infix#393)
|
- Ensure subrepos are tagged (can be automated, see kernelkit/infix#393)
|
||||||
|
- Sync tags for all repo. sync activities
|
||||||
|
|||||||
@@ -0,0 +1,26 @@
|
|||||||
|
# Security Policy
|
||||||
|
|
||||||
|
## Reporting a Vulnerability
|
||||||
|
|
||||||
|
If you discover a security vulnerability in Infix, please use GitHub's built-in
|
||||||
|
[Report a Vulnerability](https://github.com/kernelkit/infix/security/advisories/new)
|
||||||
|
feature for a private and secure disclosure.
|
||||||
|
|
||||||
|
When reporting, include:
|
||||||
|
|
||||||
|
- A clear description of the vulnerability.
|
||||||
|
- Steps to reproduce the issue.
|
||||||
|
- Potential impact of the vulnerability.
|
||||||
|
|
||||||
|
## Supported Versions
|
||||||
|
|
||||||
|
We provide security updates only for the main branch.
|
||||||
|
|
||||||
|
Individual support contracts are provided by _Wires_. See
|
||||||
|
[Support](https://github.com/kernelkit/infix/blob/main/.github/SUPPORT.md)
|
||||||
|
for more information.
|
||||||
|
|
||||||
|
## Acknowledgments
|
||||||
|
|
||||||
|
We appreciate the efforts of the security community to help improve the security
|
||||||
|
of Infix. Thank you for your responsible disclosure.
|
||||||
+3
-3
@@ -6,7 +6,7 @@ project on GitHub, and Discord, see <https://github.com/kernelkit>:
|
|||||||
|
|
||||||
Support contracts, development of new features, fast-tracking of reviews
|
Support contracts, development of new features, fast-tracking of reviews
|
||||||
and contributions, customer branding of Infix, and even customer specific
|
and contributions, customer branding of Infix, and even customer specific
|
||||||
features for dedicated products is provided by Addiva Elektronik.
|
features for dedicated products is provided by _Wires_.
|
||||||
|
|
||||||
:globe_with_meridians: <https://www.addiva.se/electronics/>
|
:globe_with_meridians: <https://www.wires.se>
|
||||||
:e-mail: <mailto:ael@addiva.se>
|
:e-mail: <mailto:infix@wires.se>
|
||||||
|
|||||||
+85
-128
@@ -1,27 +1,54 @@
|
|||||||
name: Bob the Builder
|
name: Build
|
||||||
|
|
||||||
on:
|
on:
|
||||||
pull_request:
|
|
||||||
types: [opened, synchronize, reopened, labeled]
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- main
|
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
inputs:
|
inputs:
|
||||||
minimal:
|
flavor:
|
||||||
description: 'Build minimal defconfigs'
|
description: 'Optional build flavor (e.g. _minimal)'
|
||||||
|
required: false
|
||||||
|
default: ''
|
||||||
|
type: string
|
||||||
|
parallel:
|
||||||
|
description: 'Massive parallel build of each image'
|
||||||
required: false
|
required: false
|
||||||
default: true
|
default: true
|
||||||
type: boolean
|
type: boolean
|
||||||
|
infix_repo:
|
||||||
|
description: 'Repo to checkout (for spin overrides)'
|
||||||
|
required: false
|
||||||
|
default: kernelkit/infix
|
||||||
|
type: string
|
||||||
|
|
||||||
|
|
||||||
|
workflow_call:
|
||||||
|
inputs:
|
||||||
|
target:
|
||||||
|
required: true
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
required: true
|
||||||
|
type: string
|
||||||
|
flavor:
|
||||||
|
required: false
|
||||||
|
type: string
|
||||||
|
default: ''
|
||||||
|
infix_repo:
|
||||||
|
required: false
|
||||||
|
type: string
|
||||||
|
default: kernelkit/infix
|
||||||
|
|
||||||
|
env:
|
||||||
|
FLV: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.flavor || inputs.flavor }}
|
||||||
|
INFIX_REPO: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.infix_repo || inputs.infix_repo }}
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build Infix ${{ matrix.target }}
|
name: Build ${{ inputs.name }} ${{ inputs.target }}
|
||||||
runs-on: [ self-hosted, latest ]
|
runs-on: [ self-hosted, latest ]
|
||||||
strategy:
|
strategy:
|
||||||
matrix:
|
|
||||||
target: [aarch64, x86_64]
|
|
||||||
fail-fast: false
|
fail-fast: false
|
||||||
|
outputs:
|
||||||
|
build_id: ${{ steps.vars.outputs.INFIX_BUILD_ID }}
|
||||||
steps:
|
steps:
|
||||||
- name: Cleanup Build Folder
|
- name: Cleanup Build Folder
|
||||||
run: |
|
run: |
|
||||||
@@ -30,34 +57,36 @@ jobs:
|
|||||||
rm -rf ./.??* || true
|
rm -rf ./.??* || true
|
||||||
ls -la ./
|
ls -la ./
|
||||||
|
|
||||||
- uses: actions/checkout@v4
|
- name: Checkout infix repo
|
||||||
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
|
repository: ${{ env.INFIX_REPO }}
|
||||||
|
ref: ${{ github.ref }}
|
||||||
clean: true
|
clean: true
|
||||||
|
fetch-depth: 0
|
||||||
submodules: recursive
|
submodules: recursive
|
||||||
|
|
||||||
- name: Set Build Variables
|
- name: Set Build Variables
|
||||||
id: vars
|
id: vars
|
||||||
run: |
|
run: |
|
||||||
if [ "${{ github.event_name }}" == "workflow_dispatch" ]; then
|
if [ -n "${{ github.event.pull_request.head.sha }}" ]; then
|
||||||
if [ "${{ github.event.inputs.minimal }}" == "true" ]; then
|
# Since PRs are built from an internally generated merge
|
||||||
flavor="_minimal"
|
# commit, reverse lookups of PRs and/or commits from
|
||||||
fi
|
# image version information are cumbersome. Therefore:
|
||||||
else
|
# explicitly set a build id that references both the PR
|
||||||
# Ensure 'release' job get the proper image when building main
|
# and the commit.
|
||||||
if [ "$GITHUB_REF_NAME" != "main" ]; then
|
printf "INFIX_BUILD_ID=pr%d.%.7s\n" \
|
||||||
flavor="_minimal"
|
"${{ github.event.number }}" "${{ github.event.pull_request.head.sha }}" \
|
||||||
else
|
| tee -a $GITHUB_OUTPUT $GITHUB_ENV
|
||||||
flavor=""
|
|
||||||
fi
|
|
||||||
if ${{ contains(github.event.pull_request.labels.*.name, 'ci:main') }}; then
|
|
||||||
flavor=""
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
target=${{ matrix.target }}
|
|
||||||
echo "dir=infix-$target" >> $GITHUB_OUTPUT
|
target=${{ inputs.target }}
|
||||||
echo "tgz=infix-$target.tar.gz" >> $GITHUB_OUTPUT
|
name=${{ inputs.name }}
|
||||||
echo "flv=$flavor" >> $GITHUB_OUTPUT
|
echo "dir=${name}-${target}" >> $GITHUB_OUTPUT
|
||||||
echo "Building target ${target}${flavor}_defconfig"
|
echo "tgz=${name}-${target}.tar.gz" >> $GITHUB_OUTPUT
|
||||||
|
echo "flv=$FLV" >> $GITHUB_OUTPUT
|
||||||
|
echo "Building target ${target}${FLV}_defconfig"
|
||||||
|
|
||||||
- name: Restore Cache of dl/
|
- name: Restore Cache of dl/
|
||||||
uses: actions/cache@v4
|
uses: actions/cache@v4
|
||||||
with:
|
with:
|
||||||
@@ -70,23 +99,37 @@ jobs:
|
|||||||
uses: actions/cache@v4
|
uses: actions/cache@v4
|
||||||
with:
|
with:
|
||||||
path: .ccache/
|
path: .ccache/
|
||||||
key: ccache-${{ matrix.target }}-${{ hashFiles('.git/modules/buildroot/HEAD', 'package/*/*.hash') }}
|
key: ccache-${{ inputs.target }}-${{ hashFiles('.git/modules/buildroot/HEAD', 'package/*/*.hash') }}
|
||||||
restore-keys: |
|
restore-keys: |
|
||||||
ccache-${{ matrix.target }}-
|
ccache-${{ inputs.target }}-
|
||||||
ccache-
|
ccache-
|
||||||
|
|
||||||
- name: Configure ${{ matrix.target }}${{ steps.vars.outputs.flv }}
|
- name: Configure ${{ inputs.target }}${{ steps.vars.outputs.flv }}
|
||||||
run: |
|
run: |
|
||||||
make ${{ matrix.target }}${{ steps.vars.outputs.flv }}_defconfig
|
make ${{ inputs.target }}${{ steps.vars.outputs.flv }}_defconfig
|
||||||
|
|
||||||
- name: Unit Test ${{ matrix.target }}
|
- name: Unit Test ${{ inputs.target }}
|
||||||
run: |
|
run: |
|
||||||
make test-unit
|
make test-unit
|
||||||
|
|
||||||
- name: Build ${{ matrix.target }}${{ steps.vars.outputs.flv }}
|
- name: Prepare parallel build
|
||||||
|
id: parallel
|
||||||
run: |
|
run: |
|
||||||
echo "Building ${{ matrix.target }}${{ steps.vars.outputs.flv }}_defconfig ..."
|
|
||||||
make
|
if [ "${{ ((github.event.inputs.parallel == 'true' && github.event_name == 'workflow_dispatch') || (github.ref_name != 'main' && github.event_name != 'workflow_dispatch')) }}" == "true" ]; then
|
||||||
|
echo "BR2_PER_PACKAGE_DIRECTORIES=y" >> output/.config
|
||||||
|
MAKE="make -j$((`getconf _NPROCESSORS_ONLN` / 2 + 2))"
|
||||||
|
echo "Building in parallel with -j$((`getconf _NPROCESSORS_ONLN` / 2 + 2))"
|
||||||
|
else
|
||||||
|
echo "Disabling parallel build"
|
||||||
|
MAKE="make"
|
||||||
|
fi
|
||||||
|
echo "MAKE=$MAKE" >> $GITHUB_OUTPUT
|
||||||
|
|
||||||
|
- name: Build ${{ inputs.target }}${{ steps.vars.outputs.flv }}
|
||||||
|
run: |
|
||||||
|
echo "Building ${{ inputs.target }}${{ steps.vars.outputs.flv }}_defconfig ..."
|
||||||
|
eval "${{ steps.parallel.outputs.MAKE }}"
|
||||||
|
|
||||||
- name: Check SBOM from Build
|
- name: Check SBOM from Build
|
||||||
run: |
|
run: |
|
||||||
@@ -107,100 +150,14 @@ jobs:
|
|||||||
printf "Size of output/images/: "
|
printf "Size of output/images/: "
|
||||||
ls -l output/images/
|
ls -l output/images/
|
||||||
|
|
||||||
- name: Prepare ${{ matrix.target }} Artifact
|
- name: Prepare ${{ inputs.target }} Artifact
|
||||||
run: |
|
run: |
|
||||||
cd output/
|
cd output/
|
||||||
mv images ${{ steps.vars.outputs.dir }}
|
mv images ${{ steps.vars.outputs.dir }}
|
||||||
ln -s ${{ steps.vars.outputs.dir }} images
|
ln -s ${{ steps.vars.outputs.dir }} images
|
||||||
tar chfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
tar cfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||||
|
|
||||||
- uses: actions/upload-artifact@v4
|
- uses: actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
path: output/${{ steps.vars.outputs.tgz }}
|
path: output/${{ steps.vars.outputs.tgz }}
|
||||||
name: artifact-${{ matrix.target }}
|
name: artifact-${{ inputs.target }}
|
||||||
|
|
||||||
test:
|
|
||||||
name: Regression Test of Infix x86_64
|
|
||||||
needs: build
|
|
||||||
runs-on: [ self-hosted, regression ]
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
with:
|
|
||||||
clean: true
|
|
||||||
submodules: recursive
|
|
||||||
|
|
||||||
- name: Set Build Variables
|
|
||||||
id: vars
|
|
||||||
run: |
|
|
||||||
if [ "$GITHUB_REF_NAME" != "main" ]; then
|
|
||||||
flavor="_minimal"
|
|
||||||
else
|
|
||||||
flavor=""
|
|
||||||
fi
|
|
||||||
echo "flv=$flavor" >> $GITHUB_OUTPUT
|
|
||||||
|
|
||||||
- name: Configure x86_64${{ steps.vars.outputs.flv }}
|
|
||||||
run: |
|
|
||||||
make x86_64${{ steps.vars.outputs.flv }}_defconfig
|
|
||||||
|
|
||||||
- uses: actions/download-artifact@v4
|
|
||||||
with:
|
|
||||||
pattern: "artifact-*"
|
|
||||||
merge-multiple: true
|
|
||||||
|
|
||||||
- name: Restore x86-64${{ steps.vars.outputs.flv }} output/
|
|
||||||
run: |
|
|
||||||
ls -l
|
|
||||||
mkdir -p output
|
|
||||||
mv infix-x86_64.tar.gz output/
|
|
||||||
cd output/
|
|
||||||
tar xf infix-x86_64.tar.gz
|
|
||||||
ln -s infix-x86_64 images
|
|
||||||
|
|
||||||
- name: Regression Test x86_64${{ steps.vars.outputs.flv }}
|
|
||||||
run: |
|
|
||||||
make test
|
|
||||||
|
|
||||||
- name: Publish Test Result for x86_64${{ steps.vars.outputs.flv }}
|
|
||||||
# Ensure this runs even if Regression Test fails
|
|
||||||
if: always()
|
|
||||||
run: cat test/.log/last/result-gh.md >> $GITHUB_STEP_SUMMARY
|
|
||||||
|
|
||||||
release:
|
|
||||||
if: ${{github.repository_owner == 'kernelkit' && github.ref_name == 'main'}}
|
|
||||||
name: Upload Latest Build
|
|
||||||
needs: test
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
steps:
|
|
||||||
- uses: actions/download-artifact@v4
|
|
||||||
with:
|
|
||||||
pattern: "artifact-*"
|
|
||||||
merge-multiple: true
|
|
||||||
|
|
||||||
- name: Create checksums ...
|
|
||||||
run: |
|
|
||||||
for file in *.tar.gz; do
|
|
||||||
sha256sum $file > $file.sha256
|
|
||||||
done
|
|
||||||
|
|
||||||
- uses: ncipollo/release-action@v1
|
|
||||||
with:
|
|
||||||
allowUpdates: true
|
|
||||||
omitName: true
|
|
||||||
omitBody: true
|
|
||||||
omitBodyDuringUpdate: true
|
|
||||||
prerelease: true
|
|
||||||
tag: "latest"
|
|
||||||
token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
artifacts: "*.tar.gz*"
|
|
||||||
|
|
||||||
- name: Summary
|
|
||||||
run: |
|
|
||||||
cat <<EOF >> $GITHUB_STEP_SUMMARY
|
|
||||||
# Latest Build Complete! :rocket:
|
|
||||||
|
|
||||||
For the public download links of these build artifacts, please see:
|
|
||||||
<https://github.com/kernelkit/infix/releases/tag/latest>
|
|
||||||
EOF
|
|
||||||
|
|||||||
@@ -55,7 +55,7 @@ jobs:
|
|||||||
sudo apt-get -y update
|
sudo apt-get -y update
|
||||||
sudo apt-get -y install pkg-config libjansson-dev libev-dev \
|
sudo apt-get -y install pkg-config libjansson-dev libev-dev \
|
||||||
libcrypt-dev libglib2.0-dev libpcre2-dev \
|
libcrypt-dev libglib2.0-dev libpcre2-dev \
|
||||||
libuev-dev libite-dev
|
libuev-dev
|
||||||
|
|
||||||
- name: Build dependencies
|
- name: Build dependencies
|
||||||
run: |
|
run: |
|
||||||
@@ -65,6 +65,8 @@ jobs:
|
|||||||
git clone https://github.com/sysrepo/sysrepo.git
|
git clone https://github.com/sysrepo/sysrepo.git
|
||||||
mkdir sysrepo/build
|
mkdir sysrepo/build
|
||||||
(cd sysrepo/build && cmake .. && make all && sudo make install)
|
(cd sysrepo/build && cmake .. && make all && sudo make install)
|
||||||
|
git clone https://github.com/troglobit/libite.git
|
||||||
|
(cd libite && ./autogen.sh && ./configure && make && sudo make install)
|
||||||
make dep
|
make dep
|
||||||
|
|
||||||
- name: Check applications
|
- name: Check applications
|
||||||
|
|||||||
@@ -0,0 +1,43 @@
|
|||||||
|
name: Publish latest Infix
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
workflow_call:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
publish:
|
||||||
|
name: Upload Latest Build
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
steps:
|
||||||
|
- uses: actions/download-artifact@v4
|
||||||
|
with:
|
||||||
|
pattern: "artifact-*"
|
||||||
|
merge-multiple: true
|
||||||
|
|
||||||
|
- name: Create checksums ...
|
||||||
|
run: |
|
||||||
|
for file in *.tar.gz; do
|
||||||
|
sha256sum $file > $file.sha256
|
||||||
|
done
|
||||||
|
|
||||||
|
- uses: ncipollo/release-action@v1
|
||||||
|
with:
|
||||||
|
allowUpdates: true
|
||||||
|
omitName: true
|
||||||
|
omitBody: true
|
||||||
|
omitBodyDuringUpdate: true
|
||||||
|
prerelease: true
|
||||||
|
tag: "latest"
|
||||||
|
token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
artifacts: "*.tar.gz*"
|
||||||
|
|
||||||
|
- name: Summary
|
||||||
|
run: |
|
||||||
|
cat <<EOF >> $GITHUB_STEP_SUMMARY
|
||||||
|
# Latest Build Complete! :rocket:
|
||||||
|
|
||||||
|
For the public download links of these build artifacts, please see:
|
||||||
|
<https://github.com/kernelkit/infix/releases/tag/latest>
|
||||||
|
EOF
|
||||||
@@ -85,22 +85,28 @@ jobs:
|
|||||||
cd output/
|
cd output/
|
||||||
mv images ${{ steps.vars.outputs.dir }}
|
mv images ${{ steps.vars.outputs.dir }}
|
||||||
ln -s ${{ steps.vars.outputs.dir }} images
|
ln -s ${{ steps.vars.outputs.dir }} images
|
||||||
tar chfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
tar cfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||||
|
|
||||||
mv legal-info legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}
|
mv legal-info legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}
|
||||||
tar chfz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}.tar.gz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}
|
tar cfz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}.tar.gz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}
|
||||||
|
|
||||||
- uses: actions/upload-artifact@v4
|
- uses: actions/upload-artifact@v4
|
||||||
with:
|
with:
|
||||||
name: artifact-${{ matrix.target }}
|
name: artifact-${{ matrix.target }}
|
||||||
path: output/*.tar.gz
|
path: output/*.tar.gz
|
||||||
|
|
||||||
|
- uses: actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: artifact-disk-image-${{ matrix.target }}
|
||||||
|
path: output/images/*.qcow2
|
||||||
|
|
||||||
release:
|
release:
|
||||||
name: Release Infix ${{ github.ref_name }}
|
name: Release Infix ${{ github.ref_name }}
|
||||||
needs: build
|
needs: build
|
||||||
runs-on: [ self-hosted, release ]
|
runs-on: [ self-hosted, release ]
|
||||||
permissions:
|
permissions:
|
||||||
contents: write
|
contents: write
|
||||||
|
discussions: write
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
@@ -115,12 +121,14 @@ jobs:
|
|||||||
ver=${GITHUB_REF#refs/tags/}
|
ver=${GITHUB_REF#refs/tags/}
|
||||||
fi
|
fi
|
||||||
echo "ver=${ver}" >> $GITHUB_OUTPUT
|
echo "ver=${ver}" >> $GITHUB_OUTPUT
|
||||||
|
echo "cat=" >> $GITHUB_OUTPUT
|
||||||
if echo $ver | grep -qE 'v[0-9.]+(-alpha|-beta|-rc)[0-9]*'; then
|
if echo $ver | grep -qE 'v[0-9.]+(-alpha|-beta|-rc)[0-9]*'; then
|
||||||
echo "pre=true" >> $GITHUB_OUTPUT
|
echo "pre=true" >> $GITHUB_OUTPUT
|
||||||
echo "latest=false" >> $GITHUB_OUTPUT
|
echo "latest=false" >> $GITHUB_OUTPUT
|
||||||
elif echo $ver | grep -qE '^v[0-9.]+\.[0-9.]+(\.[0-9]+)?$'; then
|
elif echo $ver | grep -qE '^v[0-9.]+\.[0-9.]+(\.[0-9]+)?$'; then
|
||||||
echo "pre=false" >> $GITHUB_OUTPUT
|
echo "pre=false" >> $GITHUB_OUTPUT
|
||||||
echo "latest=true" >> $GITHUB_OUTPUT
|
echo "latest=true" >> $GITHUB_OUTPUT
|
||||||
|
echo "cat=Releases" >> $GITHUB_OUTPUT
|
||||||
else
|
else
|
||||||
echo "pre=false" >> $GITHUB_OUTPUT
|
echo "pre=false" >> $GITHUB_OUTPUT
|
||||||
echo "latest=false" >> $GITHUB_OUTPUT
|
echo "latest=false" >> $GITHUB_OUTPUT
|
||||||
@@ -138,6 +146,11 @@ jobs:
|
|||||||
for file in *.tar.gz; do
|
for file in *.tar.gz; do
|
||||||
sha256sum $file > $file.sha256
|
sha256sum $file > $file.sha256
|
||||||
done
|
done
|
||||||
|
if ls *.qcow2 &>/dev/null; then
|
||||||
|
for file in *.qcow2; do
|
||||||
|
sha256sum "$file" > "$file.sha256"
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
|
||||||
- name: Extract ChangeLog entry ...
|
- name: Extract ChangeLog entry ...
|
||||||
run: |
|
run: |
|
||||||
@@ -150,9 +163,9 @@ jobs:
|
|||||||
name: Infix ${{ github.ref_name }}
|
name: Infix ${{ github.ref_name }}
|
||||||
prerelease: ${{ steps.rel.outputs.pre }}
|
prerelease: ${{ steps.rel.outputs.pre }}
|
||||||
makeLatest: ${{ steps.rel.outputs.latest }}
|
makeLatest: ${{ steps.rel.outputs.latest }}
|
||||||
discussionCategory: Releases
|
discussionCategory: ${{ steps.rel.outputs.cat }}
|
||||||
bodyFile: release.md
|
bodyFile: release.md
|
||||||
artifacts: "*.tar.gz*"
|
artifacts: "*.tar.gz*,*.qcow2*"
|
||||||
|
|
||||||
- name: Summary
|
- name: Summary
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
@@ -0,0 +1,116 @@
|
|||||||
|
name: Test Infix
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
inputs:
|
||||||
|
infix_repo:
|
||||||
|
description: 'Repo to checkout (for spin overrides)'
|
||||||
|
required: false
|
||||||
|
default: kernelkit/infix
|
||||||
|
type: string
|
||||||
|
|
||||||
|
workflow_call:
|
||||||
|
inputs:
|
||||||
|
target:
|
||||||
|
required: true
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
required: true
|
||||||
|
type: string
|
||||||
|
flavor:
|
||||||
|
required: false
|
||||||
|
type: string
|
||||||
|
default: ''
|
||||||
|
infix_repo:
|
||||||
|
required: false
|
||||||
|
type: string
|
||||||
|
default: kernelkit/infix
|
||||||
|
ninepm-conf:
|
||||||
|
required: false
|
||||||
|
type: string
|
||||||
|
default: ''
|
||||||
|
test-path:
|
||||||
|
required: false
|
||||||
|
type: string
|
||||||
|
default: 'test'
|
||||||
|
|
||||||
|
env:
|
||||||
|
FLV: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.flavor || inputs.flavor }}
|
||||||
|
INFIX_REPO: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.infix_repo || inputs.infix_repo }}
|
||||||
|
NINEPM_CONF: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.ninepm-conf || inputs.ninepm-conf }}
|
||||||
|
TEST_PATH: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.test-path || inputs.test-path }}
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
test:
|
||||||
|
name: Regression Test ${{ inputs.name }} ${{ inputs.target }}
|
||||||
|
runs-on: [ self-hosted, regression ]
|
||||||
|
steps:
|
||||||
|
- name: Checkout infix repo
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
repository: ${{ env.INFIX_REPO }}
|
||||||
|
ref: ${{ github.ref }}
|
||||||
|
clean: true
|
||||||
|
fetch-depth: 0
|
||||||
|
submodules: recursive
|
||||||
|
|
||||||
|
- name: Set Build Variables
|
||||||
|
id: vars
|
||||||
|
run: |
|
||||||
|
if [ -n "${{ needs.build.outputs.build_id }}" ]; then
|
||||||
|
echo "INFIX_BUILD_ID=${{ needs.build.outputs.build_id }}" \
|
||||||
|
>>$GITHUB_ENV
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "flv=$FLV" >> $GITHUB_OUTPUT
|
||||||
|
|
||||||
|
- name: Configure ${{ inputs.target }}${{ steps.vars.outputs.flv }}
|
||||||
|
run: |
|
||||||
|
make ${{ inputs.target }}${{ steps.vars.outputs.flv }}_defconfig
|
||||||
|
|
||||||
|
- uses: actions/download-artifact@v4
|
||||||
|
with:
|
||||||
|
pattern: "artifact-*"
|
||||||
|
merge-multiple: true
|
||||||
|
|
||||||
|
- name: Restore x86-64${{ steps.vars.outputs.flv }} output/
|
||||||
|
run: |
|
||||||
|
target=${{ inputs.target }}
|
||||||
|
name=${{ inputs.name }}
|
||||||
|
|
||||||
|
ls -l
|
||||||
|
mkdir -p output
|
||||||
|
mv ${name}-${target}.tar.gz output/
|
||||||
|
cd output/
|
||||||
|
tar xf ${name}-${target}.tar.gz
|
||||||
|
ln -s ${name}-${target} images
|
||||||
|
|
||||||
|
- name: Regression Test x86_64${{ steps.vars.outputs.flv }}
|
||||||
|
run: |
|
||||||
|
if [ -n "$NINEPM_CONF" ]; then
|
||||||
|
export NINEPM_PROJ_CONFIG="${GITHUB_WORKSPACE}/$NINEPM_CONF"
|
||||||
|
echo "DEBUG: NINEPM_PROJ_CONFIG is '$NINEPM_PROJ_CONFIG'"
|
||||||
|
fi
|
||||||
|
make test
|
||||||
|
|
||||||
|
- name: Publish Test Result for x86_64${{ steps.vars.outputs.flv }}
|
||||||
|
# Ensure this runs even if Regression Test fails
|
||||||
|
if: always()
|
||||||
|
run: cat $TEST_PATH/.log/last/result-gh.md >> $GITHUB_STEP_SUMMARY
|
||||||
|
|
||||||
|
- name: Generate Test Report for x86_64${{ steps.vars.outputs.flv }}
|
||||||
|
# Ensure this runs even if Regression Test fails
|
||||||
|
if: always()
|
||||||
|
run: |
|
||||||
|
asciidoctor-pdf \
|
||||||
|
--theme $TEST_PATH/9pm/report/theme.yml \
|
||||||
|
-a pdf-fontsdir=$TEST_PATH/9pm/report/fonts \
|
||||||
|
$TEST_PATH/.log/last/report.adoc \
|
||||||
|
-o $TEST_PATH/.log/last/report.pdf
|
||||||
|
|
||||||
|
- name: Upload Test Report as Artifact
|
||||||
|
uses: actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: test-report
|
||||||
|
path: ${{ env.TEST_PATH }}/.log/last/report.pdf
|
||||||
|
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
name: Self Trigger
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
types: [opened, synchronize, reopened, labeled]
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- main
|
||||||
|
- ci-workflow-redesign
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
build-x86_64:
|
||||||
|
uses: ./.github/workflows/build.yml
|
||||||
|
with:
|
||||||
|
target: "x86_64"
|
||||||
|
name: "infix"
|
||||||
|
flavor: "_minimal"
|
||||||
|
|
||||||
|
build-aarch64:
|
||||||
|
uses: ./.github/workflows/build.yml
|
||||||
|
with:
|
||||||
|
target: "aarch64"
|
||||||
|
name: "infix"
|
||||||
|
flavor: "_minimal"
|
||||||
|
|
||||||
|
test-run-x86_64:
|
||||||
|
needs: build-x86_64
|
||||||
|
uses: ./.github/workflows/test.yml
|
||||||
|
with:
|
||||||
|
target: "x86_64"
|
||||||
|
name: "infix"
|
||||||
|
|
||||||
|
test-publish-x86_64:
|
||||||
|
needs: test-run-x86_64
|
||||||
|
uses: ./.github/workflows/publish.yml
|
||||||
|
|
||||||
@@ -8,3 +8,4 @@
|
|||||||
/test/.venv
|
/test/.venv
|
||||||
/test/.log
|
/test/.log
|
||||||
/local.mk
|
/local.mk
|
||||||
|
/test/spec/Readme.adoc
|
||||||
|
|||||||
@@ -65,7 +65,7 @@ config INFIX_COMPATIBLE
|
|||||||
|
|
||||||
config INFIX_TAGLINE
|
config INFIX_TAGLINE
|
||||||
string "Operating system tagline"
|
string "Operating system tagline"
|
||||||
default "Infix -- a Network Operating System"
|
default "Infix OS — Immutable.Friendly.Secure"
|
||||||
help
|
help
|
||||||
Mandatory. Used for identifying the OS, e.g. as PRETTY_NAME in
|
Mandatory. Used for identifying the OS, e.g. as PRETTY_NAME in
|
||||||
/etc/os-release and description in the GNS3 appliance.
|
/etc/os-release and description in the GNS3 appliance.
|
||||||
|
|||||||
@@ -2,11 +2,11 @@
|
|||||||
|
|
||||||
<img align="right" src="doc/logo.png" alt="Infix - Linux <3 NETCONF" width=480 border=10>
|
<img align="right" src="doc/logo.png" alt="Infix - Linux <3 NETCONF" width=480 border=10>
|
||||||
|
|
||||||
Infix is a free, Linux based, immutable Network Operating System (NOS)
|
Infix is a free, Linux-based, immutable operating system built around
|
||||||
built on [Buildroot][1], and [sysrepo][2]. A powerful mix that ease
|
[Buildroot][1] and [sysrepo][2]. A powerful mix that ease porting to
|
||||||
porting to different platforms, simplify long-term maintenance, and
|
different platforms, simplify long-term maintenance, and provide
|
||||||
provide made-easy management using NETCONF, RESTCONF[^2], or the
|
made-easy management using NETCONF, RESTCONF[^2], or the built-in
|
||||||
built-in command line interface (CLI) from a console or SSH login.
|
command line interface (CLI) from a console or SSH login.
|
||||||
|
|
||||||
> Click the **▶ Example CLI Session** foldout below for an example, or
|
> Click the **▶ Example CLI Session** foldout below for an example, or
|
||||||
> head on over to the [Infix Documentation](doc/README.md) for more
|
> head on over to the [Infix Documentation](doc/README.md) for more
|
||||||
@@ -27,13 +27,15 @@ it maintenance-free. Configuration and data, e.g, containers, is stored
|
|||||||
on separate partitions to ensure complete separation from system files
|
on separate partitions to ensure complete separation from system files
|
||||||
and allow for seamless backup, restore, and provisioning.
|
and allow for seamless backup, restore, and provisioning.
|
||||||
|
|
||||||
In itself Infix is perfectly suited for dedicated networking tasks and
|
In itself, Infix is perfectly suited for dedicated networking tasks,
|
||||||
native support for Docker containers provides a versatile platform that
|
such as routing, switching, and monitoring. This is how it started, as
|
||||||
can easily be adapted to any customer need. Be it legacy applications,
|
a network focused operating system. Now, with native support for Docker
|
||||||
network protocols, process monitoring, or edge data analysis, it can run
|
containers, it provides a versatile platform that can easily be adapted
|
||||||
close to end equipment. Either directly connected on dedicated Ethernet
|
to any customer need. Be it legacy applications, network protocols,
|
||||||
ports or indirectly using virtual network cables to exist on the same
|
process monitoring, or edge data analysis, it can run close to end
|
||||||
LAN as other connected equipment.
|
equipment. Either directly connected on dedicated Ethernet ports or
|
||||||
|
indirectly using virtual network cables to exist on the same LAN as
|
||||||
|
other connected equipment.
|
||||||
|
|
||||||
The simple design of Infix provides complete control over both system
|
The simple design of Infix provides complete control over both system
|
||||||
and data, minimal cognitive burden, and makes it incredibly easy to get
|
and data, minimal cognitive burden, and makes it incredibly easy to get
|
||||||
@@ -93,12 +95,14 @@ The [following boards](board/aarch64/README.md) are fully supported:
|
|||||||
- Marvell CN9130 CRB
|
- Marvell CN9130 CRB
|
||||||
- Marvell EspressoBIN
|
- Marvell EspressoBIN
|
||||||
- Microchip SparX-5i PCB135 (eMMC)
|
- Microchip SparX-5i PCB135 (eMMC)
|
||||||
- StarFive VisionFive2
|
- Raspberry Pi 4B
|
||||||
- NanoPi R2S
|
- NanoPi R2S
|
||||||
|
|
||||||
An x86_64 build is also available, primarily intended for development
|
Additionally, StarFive VisionFive2, a RISC-V based two-port router, and
|
||||||
and testing, but can also be used for evaluation and demo purposes. For
|
an x86_64 build is also available. The latter is primarily intended for
|
||||||
more information, see: [Infix in Virtual Environments](doc/virtual.md).
|
development and testing, but can also be used for evaluation and demo
|
||||||
|
purposes. For more information, see: [Infix in Virtual
|
||||||
|
Environments](doc/virtual.md).
|
||||||
|
|
||||||
> See the [GitHub Releases](https://github.com/kernelkit/infix/releases)
|
> See the [GitHub Releases](https://github.com/kernelkit/infix/releases)
|
||||||
> page for our pre-built images. The *[Latest Build][]* has bleeding
|
> page for our pre-built images. The *[Latest Build][]* has bleeding
|
||||||
@@ -106,6 +110,16 @@ more information, see: [Infix in Virtual Environments](doc/virtual.md).
|
|||||||
>
|
>
|
||||||
> For *customer specific builds* of Infix, see your product repository.
|
> For *customer specific builds* of Infix, see your product repository.
|
||||||
|
|
||||||
|
|
||||||
|
----
|
||||||
|
|
||||||
|
<div align="center">
|
||||||
|
<a href="https://github.com/wires-se"><img src="https://raw.githubusercontent.com/wires-se/.github/main/profile/logo.png" width=300></a>
|
||||||
|
<br />Infix development is sponsored by <a href="https://wires.se">Wires<a>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
----
|
||||||
|
|
||||||
[^1]: An immutable operating system is one with read-only file systems,
|
[^1]: An immutable operating system is one with read-only file systems,
|
||||||
atomic updates, rollbacks, declarative configuration, and workload
|
atomic updates, rollbacks, declarative configuration, and workload
|
||||||
isolation. All to improve reliability, scalability, and security.
|
isolation. All to improve reliability, scalability, and security.
|
||||||
|
|||||||
@@ -128,5 +128,9 @@ SD-card partition.
|
|||||||
> If possible, serve `infix-aarch64.pkg` over HTTP instead, as
|
> If possible, serve `infix-aarch64.pkg` over HTTP instead, as
|
||||||
> libcurl's TFTP implementation is quite slow.
|
> libcurl's TFTP implementation is quite slow.
|
||||||
|
|
||||||
|
## Console Port
|
||||||
|
|
||||||
|
The console port runs at 115200 baud, 8N1.
|
||||||
|
|
||||||
[release]: https://github.com/kernelkit/infix/releases
|
[release]: https://github.com/kernelkit/infix/releases
|
||||||
[mvebu64boot]: https://github.com/addiva-elektronik/mvebu64boot
|
[mvebu64boot]: https://github.com/addiva-elektronik/mvebu64boot
|
||||||
|
|||||||
@@ -34,6 +34,10 @@ CONFIG_PROFILING=y
|
|||||||
CONFIG_ARCH_SPARX5=y
|
CONFIG_ARCH_SPARX5=y
|
||||||
CONFIG_ARCH_MVEBU=y
|
CONFIG_ARCH_MVEBU=y
|
||||||
CONFIG_ARCH_VEXPRESS=y
|
CONFIG_ARCH_VEXPRESS=y
|
||||||
|
CONFIG_ARM64_ERRATUM_2441007=y
|
||||||
|
CONFIG_ARM64_ERRATUM_1286807=y
|
||||||
|
CONFIG_ARM64_ERRATUM_1542419=y
|
||||||
|
CONFIG_ARM64_ERRATUM_2441009=y
|
||||||
CONFIG_ARM64_VA_BITS_48=y
|
CONFIG_ARM64_VA_BITS_48=y
|
||||||
CONFIG_SCHED_MC=y
|
CONFIG_SCHED_MC=y
|
||||||
CONFIG_NR_CPUS=64
|
CONFIG_NR_CPUS=64
|
||||||
@@ -57,6 +61,7 @@ CONFIG_MODULE_UNLOAD=y
|
|||||||
CONFIG_KSM=y
|
CONFIG_KSM=y
|
||||||
CONFIG_TRANSPARENT_HUGEPAGE=y
|
CONFIG_TRANSPARENT_HUGEPAGE=y
|
||||||
CONFIG_CMA=y
|
CONFIG_CMA=y
|
||||||
|
CONFIG_CMA_AREAS=7
|
||||||
CONFIG_NET=y
|
CONFIG_NET=y
|
||||||
CONFIG_PACKET=y
|
CONFIG_PACKET=y
|
||||||
CONFIG_XDP_SOCKETS=y
|
CONFIG_XDP_SOCKETS=y
|
||||||
@@ -165,7 +170,6 @@ CONFIG_BRIDGE_EBT_REDIRECT=m
|
|||||||
CONFIG_BRIDGE_EBT_SNAT=m
|
CONFIG_BRIDGE_EBT_SNAT=m
|
||||||
CONFIG_BRIDGE_EBT_LOG=m
|
CONFIG_BRIDGE_EBT_LOG=m
|
||||||
CONFIG_BRIDGE_EBT_NFLOG=m
|
CONFIG_BRIDGE_EBT_NFLOG=m
|
||||||
CONFIG_BPFILTER=y
|
|
||||||
CONFIG_BRIDGE=y
|
CONFIG_BRIDGE=y
|
||||||
CONFIG_BRIDGE_VLAN_FILTERING=y
|
CONFIG_BRIDGE_VLAN_FILTERING=y
|
||||||
CONFIG_BRIDGE_MRP=y
|
CONFIG_BRIDGE_MRP=y
|
||||||
@@ -227,6 +231,7 @@ CONFIG_SCSI_SAS_ATA=y
|
|||||||
CONFIG_SCSI_VIRTIO=y
|
CONFIG_SCSI_VIRTIO=y
|
||||||
CONFIG_ATA=y
|
CONFIG_ATA=y
|
||||||
CONFIG_SATA_AHCI=y
|
CONFIG_SATA_AHCI=y
|
||||||
|
CONFIG_SATA_MOBILE_LPM_POLICY=0
|
||||||
CONFIG_SATA_AHCI_PLATFORM=y
|
CONFIG_SATA_AHCI_PLATFORM=y
|
||||||
CONFIG_AHCI_MVEBU=y
|
CONFIG_AHCI_MVEBU=y
|
||||||
CONFIG_PATA_OF_PLATFORM=y
|
CONFIG_PATA_OF_PLATFORM=y
|
||||||
@@ -282,6 +287,7 @@ CONFIG_NET_DSA_MV88E6XXX_PTP=y
|
|||||||
CONFIG_MVNETA=m
|
CONFIG_MVNETA=m
|
||||||
CONFIG_MVPP2=m
|
CONFIG_MVPP2=m
|
||||||
# CONFIG_NET_VENDOR_MELLANOX is not set
|
# CONFIG_NET_VENDOR_MELLANOX is not set
|
||||||
|
# CONFIG_NET_VENDOR_META is not set
|
||||||
# CONFIG_NET_VENDOR_MICREL is not set
|
# CONFIG_NET_VENDOR_MICREL is not set
|
||||||
CONFIG_SPARX5_SWITCH=y
|
CONFIG_SPARX5_SWITCH=y
|
||||||
# CONFIG_NET_VENDOR_MICROSEMI is not set
|
# CONFIG_NET_VENDOR_MICROSEMI is not set
|
||||||
@@ -353,13 +359,14 @@ CONFIG_SERIAL_XILINX_PS_UART=y
|
|||||||
CONFIG_SERIAL_XILINX_PS_UART_CONSOLE=y
|
CONFIG_SERIAL_XILINX_PS_UART_CONSOLE=y
|
||||||
CONFIG_SERIAL_MVEBU_UART=y
|
CONFIG_SERIAL_MVEBU_UART=y
|
||||||
CONFIG_VIRTIO_CONSOLE=y
|
CONFIG_VIRTIO_CONSOLE=y
|
||||||
|
CONFIG_HW_RANDOM_CN10K=m
|
||||||
CONFIG_I2C=y
|
CONFIG_I2C=y
|
||||||
CONFIG_I2C_CHARDEV=y
|
CONFIG_I2C_CHARDEV=y
|
||||||
CONFIG_I2C_MUX=y
|
CONFIG_I2C_MUX=y
|
||||||
CONFIG_I2C_MUX_GPIO=y
|
CONFIG_I2C_MUX_GPIO=y
|
||||||
CONFIG_I2C_MUX_PCA954x=y
|
CONFIG_I2C_MUX_PCA954x=y
|
||||||
CONFIG_I2C_MUX_PINCTRL=y
|
CONFIG_I2C_MUX_PINCTRL=y
|
||||||
CONFIG_I2C_DESIGNWARE_PLATFORM=y
|
CONFIG_I2C_DESIGNWARE_CORE=y
|
||||||
CONFIG_I2C_MV64XXX=y
|
CONFIG_I2C_MV64XXX=y
|
||||||
CONFIG_I2C_SLAVE=y
|
CONFIG_I2C_SLAVE=y
|
||||||
CONFIG_SPI=y
|
CONFIG_SPI=y
|
||||||
@@ -495,6 +502,7 @@ CONFIG_EXTCON_USB_GPIO=y
|
|||||||
CONFIG_IIO=y
|
CONFIG_IIO=y
|
||||||
CONFIG_TI_ADC081C=y
|
CONFIG_TI_ADC081C=y
|
||||||
CONFIG_PWM=y
|
CONFIG_PWM=y
|
||||||
|
CONFIG_RESET_GPIO=y
|
||||||
CONFIG_PHY_MVEBU_CP110_COMPHY=y
|
CONFIG_PHY_MVEBU_CP110_COMPHY=y
|
||||||
CONFIG_PHY_MVEBU_CP110_UTMI=y
|
CONFIG_PHY_MVEBU_CP110_UTMI=y
|
||||||
CONFIG_PHY_SAMSUNG_USB2=y
|
CONFIG_PHY_SAMSUNG_USB2=y
|
||||||
@@ -523,13 +531,13 @@ CONFIG_9P_FS=y
|
|||||||
CONFIG_NLS_CODEPAGE_437=y
|
CONFIG_NLS_CODEPAGE_437=y
|
||||||
CONFIG_NLS_ISO8859_1=y
|
CONFIG_NLS_ISO8859_1=y
|
||||||
CONFIG_SECURITY=y
|
CONFIG_SECURITY=y
|
||||||
|
CONFIG_LSM="landlock,lockdown,yama,loadpin,safesetid,bpf"
|
||||||
CONFIG_CRYPTO_CCM=m
|
CONFIG_CRYPTO_CCM=m
|
||||||
CONFIG_CRYPTO_ECHAINIV=y
|
CONFIG_CRYPTO_ECHAINIV=y
|
||||||
CONFIG_CRYPTO_ANSI_CPRNG=y
|
CONFIG_CRYPTO_ANSI_CPRNG=y
|
||||||
CONFIG_CRYPTO_GHASH_ARM64_CE=y
|
CONFIG_CRYPTO_GHASH_ARM64_CE=y
|
||||||
CONFIG_CRYPTO_SHA1_ARM64_CE=y
|
CONFIG_CRYPTO_SHA1_ARM64_CE=y
|
||||||
CONFIG_CRYPTO_SHA2_ARM64_CE=y
|
CONFIG_CRYPTO_SHA2_ARM64_CE=y
|
||||||
CONFIG_CRYPTO_AES_ARM64_CE_BLK=y
|
|
||||||
CONFIG_CRYPTO_AES_ARM64_CE_CCM=y
|
CONFIG_CRYPTO_AES_ARM64_CE_CCM=y
|
||||||
CONFIG_DMA_CMA=y
|
CONFIG_DMA_CMA=y
|
||||||
CONFIG_CMA_SIZE_MBYTES=0
|
CONFIG_CMA_SIZE_MBYTES=0
|
||||||
|
|||||||
@@ -101,6 +101,13 @@ Worth noting, unlike many other boards, the Rockchip family of chipsets
|
|||||||
runs the UART at 1500000 bps (1.5 Mbps) 8N1.
|
runs the UART at 1500000 bps (1.5 Mbps) 8N1.
|
||||||
|
|
||||||
|
|
||||||
|
Console Port
|
||||||
|
------------
|
||||||
|
|
||||||
|
Unlike many other boards, the NanoPi R2S console, and in fact all
|
||||||
|
Rockchip family chipsets, runs at 1500000 bps (1.5 Mbps) 8N1.
|
||||||
|
|
||||||
|
|
||||||
Secure Boot
|
Secure Boot
|
||||||
-----------
|
-----------
|
||||||
|
|
||||||
|
|||||||
@@ -230,7 +230,6 @@ CONFIG_MAC80211_LEDS=y
|
|||||||
CONFIG_RFKILL=y
|
CONFIG_RFKILL=y
|
||||||
CONFIG_NET_9P=y
|
CONFIG_NET_9P=y
|
||||||
CONFIG_NET_9P_VIRTIO=y
|
CONFIG_NET_9P_VIRTIO=y
|
||||||
# CONFIG_ETHTOOL_NETLINK is not set
|
|
||||||
CONFIG_PCI=y
|
CONFIG_PCI=y
|
||||||
CONFIG_PCIEPORTBUS=y
|
CONFIG_PCIEPORTBUS=y
|
||||||
CONFIG_PCI_IOV=y
|
CONFIG_PCI_IOV=y
|
||||||
@@ -481,7 +480,6 @@ CONFIG_I2C=y
|
|||||||
CONFIG_I2C_CHARDEV=y
|
CONFIG_I2C_CHARDEV=y
|
||||||
CONFIG_I2C_MUX=y
|
CONFIG_I2C_MUX=y
|
||||||
CONFIG_I2C_MUX_PCA954x=y
|
CONFIG_I2C_MUX_PCA954x=y
|
||||||
CONFIG_I2C_DESIGNWARE_PLATFORM=y
|
|
||||||
CONFIG_I2C_GPIO=m
|
CONFIG_I2C_GPIO=m
|
||||||
CONFIG_I2C_RK3X=y
|
CONFIG_I2C_RK3X=y
|
||||||
CONFIG_I2C_SLAVE=y
|
CONFIG_I2C_SLAVE=y
|
||||||
|
|||||||
@@ -0,0 +1,14 @@
|
|||||||
|
--- a/arch/arm/boot/dts/broadcom/bcm2711-rpi-4-b.dts 2025-04-28 00:13:06.880003668 +0200
|
||||||
|
+++ b/arch/arm/boot/dts/broadcom/bcm2711-rpi-4-b.dts 2025-04-28 00:14:17.708941263 +0200
|
||||||
|
@@ -14,6 +14,11 @@
|
||||||
|
chosen {
|
||||||
|
/* 8250 auxiliary UART instead of pl011 */
|
||||||
|
stdout-path = "serial1:115200n8";
|
||||||
|
+
|
||||||
|
+ infix {
|
||||||
|
+ /* Default admin user password: 'admin' */
|
||||||
|
+ factory-password-hash = "$5$mI/zpOAqZYKLC2WU$i7iPzZiIjOjrBF3NyftS9CCq8dfYwHwrmUK097Jca9A";
|
||||||
|
+ };
|
||||||
|
};
|
||||||
|
|
||||||
|
cam1_reg: regulator-cam1 {
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1 @@
|
|||||||
|
root=/dev/mmcblk0p2 rootwait console=tty1 console=ttyAMA0,115200
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
# Please note that this is only a sample, we recommend you to change it to fit
|
||||||
|
# your needs.
|
||||||
|
# You should override this file using BR2_PACKAGE_RPI_FIRMWARE_CONFIG_FILE.
|
||||||
|
# See http://buildroot.org/manual.html#rootfs-custom
|
||||||
|
# and http://elinux.org/RPiconfig for a description of config.txt syntax
|
||||||
|
|
||||||
|
start_file=start4.elf
|
||||||
|
fixup_file=fixup4.dat
|
||||||
|
|
||||||
|
kernel=u-boot.bin
|
||||||
|
|
||||||
|
device_tree=bcm2711-rpi-4-b.dtb
|
||||||
|
dtoverlay=rpi-env
|
||||||
|
dtoverlay=infix-key
|
||||||
|
|
||||||
|
# To use an external initramfs file
|
||||||
|
#initramfs rootfs.cpio.gz
|
||||||
|
|
||||||
|
# Disable overscan assuming the display supports displaying the full resolution
|
||||||
|
# If the text shown on the screen disappears off the edge, comment this out
|
||||||
|
disable_overscan=1
|
||||||
|
|
||||||
|
# How much memory in MB to assign to the GPU on Pi models having
|
||||||
|
# 256, 512 or 1024 MB total memory
|
||||||
|
gpu_mem_256=100
|
||||||
|
gpu_mem_512=100
|
||||||
|
gpu_mem_1024=100
|
||||||
|
|
||||||
|
# Enable UART0 for serial console on ttyAMA0
|
||||||
|
enable_uart=1
|
||||||
|
force_turbo=1
|
||||||
|
#dtoverlay=miniuart-bt
|
||||||
|
|
||||||
|
# Run as fast as firmware / board allows
|
||||||
|
arm_boost=1
|
||||||
|
|
||||||
|
# enable 64bits support
|
||||||
|
arm_64bit=1
|
||||||
|
|
||||||
|
# Enable early debugging info
|
||||||
|
uart_2ndstage=1
|
||||||
@@ -0,0 +1,71 @@
|
|||||||
|
image boot.vfat {
|
||||||
|
vfat {
|
||||||
|
files = {
|
||||||
|
#BOOT_FILES#
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
size = 32M
|
||||||
|
}
|
||||||
|
|
||||||
|
image cfg.ext4 {
|
||||||
|
empty = true
|
||||||
|
temporary = true
|
||||||
|
size = 16M
|
||||||
|
|
||||||
|
ext4 {
|
||||||
|
label = "cfg"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
image var.ext4 {
|
||||||
|
empty = true
|
||||||
|
temporary = true
|
||||||
|
size = 512M
|
||||||
|
|
||||||
|
ext4 {
|
||||||
|
label = "var"
|
||||||
|
use-mke2fs = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
image sdcard.img {
|
||||||
|
hdimage {
|
||||||
|
partition-table-type = "gpt"
|
||||||
|
}
|
||||||
|
|
||||||
|
partition boot {
|
||||||
|
partition-type-uuid = EBD0A0A2-B9E5-4433-87C0-68B6B72699C7
|
||||||
|
bootable = "true"
|
||||||
|
image = "boot.vfat"
|
||||||
|
}
|
||||||
|
|
||||||
|
partition aux {
|
||||||
|
partition-uuid = D4EF35A0-0652-45A1-B3DE-D63339C82035
|
||||||
|
image = "aux.ext4"
|
||||||
|
}
|
||||||
|
|
||||||
|
partition primary {
|
||||||
|
partition-type-uuid = 0FC63DAF-8483-4772-8E79-3D69D8477DE4
|
||||||
|
bootable = true
|
||||||
|
size = 200M
|
||||||
|
image = "rootfs.squashfs"
|
||||||
|
}
|
||||||
|
|
||||||
|
partition secondary {
|
||||||
|
partition-type-uuid = 0FC63DAF-8483-4772-8E79-3D69D8477DE4
|
||||||
|
bootable = true
|
||||||
|
size = 200M
|
||||||
|
image = "rootfs.squashfs"
|
||||||
|
}
|
||||||
|
|
||||||
|
partition cfg {
|
||||||
|
partition-uuid = 7aa497f0-73b5-47e5-b2ab-8752d8a48105
|
||||||
|
image = "cfg.ext4"
|
||||||
|
}
|
||||||
|
|
||||||
|
partition var {
|
||||||
|
partition-uuid = 8046A06A-E45A-4A14-A6AD-6684704A393F
|
||||||
|
image = "var.ext4"
|
||||||
|
}
|
||||||
|
}
|
||||||
Executable
+7
@@ -0,0 +1,7 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
|
||||||
|
# Armbian firmware installs to /lib/firmware but driver wants the
|
||||||
|
# file(s) in /lib/firmware/brcm/
|
||||||
|
if [ -f "${TARGET_DIR}/lib/firmware/BCM4345C0.hcd" ]; then
|
||||||
|
mv "${TARGET_DIR}/lib/firmware/BCM4345C0.hcd" "${TARGET_DIR}/lib/firmware/brcm/"
|
||||||
|
fi
|
||||||
Executable
+43
@@ -0,0 +1,43 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
set -e
|
||||||
|
|
||||||
|
BOARD_DIR=$(dirname "$0")
|
||||||
|
GENIMAGE_CFG="${BUILD_DIR}/genimage.cfg"
|
||||||
|
GENIMAGE_TMP="${BUILD_DIR}/genimage.tmp"
|
||||||
|
|
||||||
|
# Device trees are installed for distro boot (syslinux.conf), but on RPi
|
||||||
|
# we need them for the SPL, which feeds the TPL (U-Boot) for use instead
|
||||||
|
# of the (built-in) control DT other platforms use.
|
||||||
|
find "${TARGET_DIR}/boot" -type f -name '*.dtb' -exec cp '{}' "${BINARIES_DIR}/" \;
|
||||||
|
|
||||||
|
# We've asked U-Boot previously to build overlays for us: Infix signing
|
||||||
|
# key and our ixboot scripts. Make sure here they are installed in the
|
||||||
|
# proper directory so genimage can create the DOS partition the SPL
|
||||||
|
# reads config.txt from.
|
||||||
|
find "${BINARIES_DIR}" -type f -name '*.dtbo' -exec mv '{}' "${BINARIES_DIR}/rpi-firmware/overlays/" \;
|
||||||
|
|
||||||
|
# Create FILES array for the genimage.cfg generation
|
||||||
|
FILES=""
|
||||||
|
for f in "${BINARIES_DIR}"/*.dtb "${BINARIES_DIR}"/rpi-firmware/*; do
|
||||||
|
case "$f" in
|
||||||
|
*~|*.bak) continue ;;
|
||||||
|
esac
|
||||||
|
FILES="${FILES}\t\t\t\"${f#"${BINARIES_DIR}/"}\",\n"
|
||||||
|
done
|
||||||
|
|
||||||
|
KERNEL=$(sed -n 's/^kernel=//p' "${BINARIES_DIR}/rpi-firmware/config.txt")
|
||||||
|
FILES="${FILES}\t\t\t\"${KERNEL}\""
|
||||||
|
|
||||||
|
sed "s|#BOOT_FILES#|${FILES}|" "${BOARD_DIR}/genimage.cfg.in" > "${GENIMAGE_CFG}"
|
||||||
|
|
||||||
|
ROOTPATH_TMP=$(mktemp -d)
|
||||||
|
trap 'rm -rf \"$ROOTPATH_TMP\"' EXIT
|
||||||
|
|
||||||
|
rm -rf "${GENIMAGE_TMP}"
|
||||||
|
|
||||||
|
genimage \
|
||||||
|
--rootpath "${ROOTPATH_TMP}" \
|
||||||
|
--tmppath "${GENIMAGE_TMP}" \
|
||||||
|
--inputpath "${BINARIES_DIR}" \
|
||||||
|
--outputpath "${BINARIES_DIR}" \
|
||||||
|
--config "${GENIMAGE_CFG}"
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
default rpi4b
|
||||||
|
menu title Boot Menu
|
||||||
|
prompt 1
|
||||||
|
timeout 30
|
||||||
|
|
||||||
|
label rpi4b
|
||||||
|
menu label Infix on Raspberry Pi 4B
|
||||||
|
kernel /boot/Image
|
||||||
|
devicetree /boot/broadcom/bcm2711-rpi-4-b.dtb
|
||||||
|
append ${bootargs_root} 8250.nr_uarts=1 console=ttyS0,115200 ${bootargs_log} -- ${bootargs_user}
|
||||||
|
|
||||||
|
label rpi400
|
||||||
|
menu label Infix on Raspberry Pi 400
|
||||||
|
kernel /boot/Image
|
||||||
|
devicetree /boot/broadcom/bcm2711-rpi-400.dtb
|
||||||
|
append ${bootargs_root} 8250.nr_uarts=1 console=ttyS0,115200 ${bootargs_log} -- ${bootargs_user}
|
||||||
@@ -0,0 +1,193 @@
|
|||||||
|
{
|
||||||
|
"ieee802-dot1ab-lldp:lldp": {
|
||||||
|
"infix-lldp:enabled": true
|
||||||
|
},
|
||||||
|
"ietf-interfaces:interfaces": {
|
||||||
|
"interface": [
|
||||||
|
{
|
||||||
|
"name": "lo",
|
||||||
|
"type": "infix-if-type:loopback",
|
||||||
|
"ietf-ip:ipv4": {
|
||||||
|
"address": [
|
||||||
|
{
|
||||||
|
"ip": "127.0.0.1",
|
||||||
|
"prefix-length": 8
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"ietf-ip:ipv6": {
|
||||||
|
"address": [
|
||||||
|
{
|
||||||
|
"ip": "::1",
|
||||||
|
"prefix-length": 128
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "eth0",
|
||||||
|
"type": "infix-if-type:ethernet"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"ietf-keystore:keystore": {
|
||||||
|
"asymmetric-keys": {
|
||||||
|
"asymmetric-key": [
|
||||||
|
{
|
||||||
|
"name": "genkey",
|
||||||
|
"public-key-format": "ietf-crypto-types:ssh-public-key-format",
|
||||||
|
"public-key": "",
|
||||||
|
"private-key-format": "ietf-crypto-types:rsa-private-key-format",
|
||||||
|
"cleartext-private-key": "",
|
||||||
|
"certificates": {}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"ietf-netconf-acm:nacm": {
|
||||||
|
"enable-nacm": true,
|
||||||
|
"groups": {
|
||||||
|
"group": [
|
||||||
|
{
|
||||||
|
"name": "admin",
|
||||||
|
"user-name": [
|
||||||
|
"admin"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"rule-list": [
|
||||||
|
{
|
||||||
|
"name": "admin-acl",
|
||||||
|
"group": [
|
||||||
|
"admin"
|
||||||
|
],
|
||||||
|
"rule": [
|
||||||
|
{
|
||||||
|
"name": "permit-all",
|
||||||
|
"module-name": "*",
|
||||||
|
"access-operations": "*",
|
||||||
|
"action": "permit",
|
||||||
|
"comment": "Allow 'admin' group complete access to all operations and data."
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "default-deny-all",
|
||||||
|
"group": [
|
||||||
|
"*"
|
||||||
|
],
|
||||||
|
"rule": [
|
||||||
|
{
|
||||||
|
"name": "deny-password-read",
|
||||||
|
"module-name": "ietf-system",
|
||||||
|
"path": "/ietf-system:system/authentication/user/password",
|
||||||
|
"access-operations": "*",
|
||||||
|
"action": "deny"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"ietf-netconf-server:netconf-server": {
|
||||||
|
"listen": {
|
||||||
|
"endpoints": {
|
||||||
|
"endpoint": [
|
||||||
|
{
|
||||||
|
"name": "default-ssh",
|
||||||
|
"ssh": {
|
||||||
|
"tcp-server-parameters": {
|
||||||
|
"local-address": "::"
|
||||||
|
},
|
||||||
|
"ssh-server-parameters": {
|
||||||
|
"server-identity": {
|
||||||
|
"host-key": [
|
||||||
|
{
|
||||||
|
"name": "default-key",
|
||||||
|
"public-key": {
|
||||||
|
"central-keystore-reference": "genkey"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"ietf-system:system": {
|
||||||
|
"hostname": "rpi4",
|
||||||
|
"ntp": {
|
||||||
|
"enabled": true,
|
||||||
|
"server": [
|
||||||
|
{
|
||||||
|
"name": "ntp.org",
|
||||||
|
"udp": {
|
||||||
|
"address": "pool.ntp.org"
|
||||||
|
},
|
||||||
|
"iburst": true
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"authentication": {
|
||||||
|
"user": [
|
||||||
|
{
|
||||||
|
"name": "admin",
|
||||||
|
"password": "$factory$",
|
||||||
|
"infix-system:shell": "bash"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"infix-system:motd-banner": "Li0tLS0tLS0uCnwgIC4gLiAgfCBJbmZpeCAtLSBhIE5ldHdvcmsgT3BlcmF0aW5nIFN5c3RlbQp8LS4gdiAuLXwgaHR0cHM6Ly9rZXJuZWxraXQuZ2l0aHViLmlvCictJy0tLSctJwo="
|
||||||
|
},
|
||||||
|
"infix-dhcp-client:dhcp-client": {
|
||||||
|
"client-if": [
|
||||||
|
{
|
||||||
|
"if-name": "eth0",
|
||||||
|
"option": [
|
||||||
|
{
|
||||||
|
"id": "netmask"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "broadcast"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "router"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "domain"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "hostname"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "dns-server"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "ntp-server"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"infix-meta:meta": {
|
||||||
|
"infix-meta:version": "1.2"
|
||||||
|
},
|
||||||
|
"infix-services:mdns": {
|
||||||
|
"enabled": true
|
||||||
|
},
|
||||||
|
"infix-services:web": {
|
||||||
|
"enabled": true,
|
||||||
|
"console": {
|
||||||
|
"enabled": true
|
||||||
|
},
|
||||||
|
"netbrowse": {
|
||||||
|
"enabled": true
|
||||||
|
},
|
||||||
|
"restconf": {
|
||||||
|
"enabled": true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
{
|
||||||
|
"eth0": {
|
||||||
|
"phy-detached-when-down": true
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
# Broadcom BCM2835 Watchdog timer
|
||||||
|
device /dev/watchdog0 {
|
||||||
|
timeout = 60
|
||||||
|
interval = 5
|
||||||
|
safe-exit = true
|
||||||
|
}
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
# CONFIG_MMC_PCI is not set
|
||||||
|
CONFIG_OF_OVERLAY_LIST="rpi-env infix-key"
|
||||||
|
# CONFIG_ENV_IS_IN_FAT is not set
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
/dts-v1/;
|
||||||
|
/plugin/;
|
||||||
|
|
||||||
|
&{/} {
|
||||||
|
config {
|
||||||
|
environment {
|
||||||
|
vendor = "infix";
|
||||||
|
preboot = "run ixpreboot";
|
||||||
|
ixbootdelay = "0.5";
|
||||||
|
bootdelay = "-2";
|
||||||
|
bootmenu_delay = "10";
|
||||||
|
boot_targets = "mmc1";
|
||||||
|
ethprime = "eth0";
|
||||||
|
bootcmd = "run ixboot";
|
||||||
|
|
||||||
|
ixpreboot = /incbin/("scripts/ixpreboot.sh");
|
||||||
|
ixbtn-devmode = "setenv dev_mode yes; echo Enabled";
|
||||||
|
ixbtn-factory = "echo \"No button available, use bootmenu\"";
|
||||||
|
ixfactory = /incbin/("scripts/ixfactory.sh");
|
||||||
|
|
||||||
|
ixboot = /incbin/("scripts/ixboot.sh");
|
||||||
|
ixbootslot = /incbin/("scripts/ixbootslot.sh");
|
||||||
|
ixprepblk = /incbin/("scripts/ixprepblk.sh");
|
||||||
|
ixprepdhcp = /incbin/("scripts/ixprepdhcp.sh");
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -45,11 +45,11 @@ The default credentials for the demo builds is
|
|||||||
login: admin
|
login: admin
|
||||||
password: admin
|
password: admin
|
||||||
|
|
||||||
Infix -- a Network Operating System v24.09.0-rc1 (hvc0)
|
Infix OS — Immutable.Friendly.Secure v24.09.0-rc1 (hvc0)
|
||||||
infix-00-00-00 login: admin
|
infix-00-00-00 login: admin
|
||||||
Password:
|
Password:
|
||||||
.-------.
|
.-------.
|
||||||
| . . | Infix -- a Network Operating System
|
| . . | Infix OS — Immutable.Friendly.Secure
|
||||||
|-. v .-| https://kernelkit.org
|
|-. v .-| https://kernelkit.org
|
||||||
'-'---'-'
|
'-'---'-'
|
||||||
|
|
||||||
@@ -122,9 +122,9 @@ There's a lot of tutorials and guides online, start here:
|
|||||||
About
|
About
|
||||||
-----
|
-----
|
||||||
|
|
||||||
Infix is a free, Linux based, immutable Network Operating System (NOS)
|
Infix is a free, Linux-based, immutable operating system built around
|
||||||
built on Buildroot, and sysrepo. A powerful mix that ease porting to
|
Buildroot, and sysrepo. A powerful mix that ease porting to different
|
||||||
different platforms, simplify long-term maintenance, and provide easy
|
platforms, simplify long-term maintenance, and provide easy management
|
||||||
management using NETCONF, RESTCONF, or the built-in command line
|
using NETCONF, RESTCONF, or the built-in command line interface (CLI)
|
||||||
interface (CLI) from a console or SSH login.
|
from a console or SSH login.
|
||||||
|
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
#
|
#
|
||||||
# Automatically generated make config: don't edit
|
# Automatically generated make config: don't edit
|
||||||
# Busybox version: 1.36.1
|
# Busybox version: 1.36.1
|
||||||
# Tue Oct 22 13:12:02 2024
|
# Sun Feb 9 12:25:37 2025
|
||||||
#
|
#
|
||||||
CONFIG_HAVE_DOT_CONFIG=y
|
CONFIG_HAVE_DOT_CONFIG=y
|
||||||
|
|
||||||
@@ -17,7 +17,7 @@ CONFIG_SHOW_USAGE=y
|
|||||||
CONFIG_FEATURE_VERBOSE_USAGE=y
|
CONFIG_FEATURE_VERBOSE_USAGE=y
|
||||||
# CONFIG_FEATURE_COMPRESS_USAGE is not set
|
# CONFIG_FEATURE_COMPRESS_USAGE is not set
|
||||||
CONFIG_LFS=y
|
CONFIG_LFS=y
|
||||||
# CONFIG_PAM is not set
|
CONFIG_PAM=y
|
||||||
CONFIG_FEATURE_DEVPTS=y
|
CONFIG_FEATURE_DEVPTS=y
|
||||||
CONFIG_FEATURE_UTMP=y
|
CONFIG_FEATURE_UTMP=y
|
||||||
CONFIG_FEATURE_WTMP=y
|
CONFIG_FEATURE_WTMP=y
|
||||||
@@ -325,7 +325,7 @@ CONFIG_FEATURE_STAT_FILESYSTEM=y
|
|||||||
CONFIG_STTY=y
|
CONFIG_STTY=y
|
||||||
CONFIG_SUM=y
|
CONFIG_SUM=y
|
||||||
CONFIG_SYNC=y
|
CONFIG_SYNC=y
|
||||||
# CONFIG_FEATURE_SYNC_FANCY is not set
|
CONFIG_FEATURE_SYNC_FANCY=y
|
||||||
CONFIG_FSYNC=y
|
CONFIG_FSYNC=y
|
||||||
# CONFIG_TAC is not set
|
# CONFIG_TAC is not set
|
||||||
CONFIG_TAIL=y
|
CONFIG_TAIL=y
|
||||||
@@ -336,7 +336,7 @@ CONFIG_TEST=y
|
|||||||
CONFIG_TEST1=y
|
CONFIG_TEST1=y
|
||||||
CONFIG_TEST2=y
|
CONFIG_TEST2=y
|
||||||
CONFIG_FEATURE_TEST_64=y
|
CONFIG_FEATURE_TEST_64=y
|
||||||
# CONFIG_TIMEOUT is not set
|
CONFIG_TIMEOUT=y
|
||||||
CONFIG_TOUCH=y
|
CONFIG_TOUCH=y
|
||||||
CONFIG_FEATURE_TOUCH_SUSV3=y
|
CONFIG_FEATURE_TOUCH_SUSV3=y
|
||||||
CONFIG_TR=y
|
CONFIG_TR=y
|
||||||
@@ -357,7 +357,7 @@ CONFIG_BASE32=y
|
|||||||
CONFIG_BASE64=y
|
CONFIG_BASE64=y
|
||||||
CONFIG_UUENCODE=y
|
CONFIG_UUENCODE=y
|
||||||
CONFIG_WC=y
|
CONFIG_WC=y
|
||||||
# CONFIG_FEATURE_WC_LARGE is not set
|
CONFIG_FEATURE_WC_LARGE=y
|
||||||
CONFIG_WHO=y
|
CONFIG_WHO=y
|
||||||
CONFIG_W=y
|
CONFIG_W=y
|
||||||
CONFIG_USERS=y
|
CONFIG_USERS=y
|
||||||
|
|||||||
@@ -127,7 +127,7 @@ bootdata=
|
|||||||
diskimg=disk.img
|
diskimg=disk.img
|
||||||
bootimg=
|
bootimg=
|
||||||
bootpart=
|
bootpart=
|
||||||
|
tmpimage=$(mktemp)
|
||||||
while getopts "a:b:B:n:s:" opt; do
|
while getopts "a:b:B:n:s:" opt; do
|
||||||
case ${opt} in
|
case ${opt} in
|
||||||
a)
|
a)
|
||||||
@@ -166,7 +166,7 @@ awk \
|
|||||||
-vimgsize=$imgsize \
|
-vimgsize=$imgsize \
|
||||||
-vcfgsize=$cfgsize \
|
-vcfgsize=$cfgsize \
|
||||||
-vvarsize=$varsize \
|
-vvarsize=$varsize \
|
||||||
-vdiskimg=$diskimg \
|
-vdiskimg=$tmpimage \
|
||||||
-vbootimg="$bootimg" -vbootpart="$bootpart" \
|
-vbootimg="$bootimg" -vbootpart="$bootpart" \
|
||||||
'{
|
'{
|
||||||
sub(/@TOTALSIZE@/, total);
|
sub(/@TOTALSIZE@/, total);
|
||||||
@@ -211,5 +211,7 @@ genimage \
|
|||||||
--rootpath "$root" \
|
--rootpath "$root" \
|
||||||
--tmppath "$tmp" \
|
--tmppath "$tmp" \
|
||||||
--inputpath "$BINARIES_DIR" \
|
--inputpath "$BINARIES_DIR" \
|
||||||
--outputpath "$BINARIES_DIR" \
|
|
||||||
--config "$root/genimage.cfg"
|
--config "$root/genimage.cfg"
|
||||||
|
|
||||||
|
qemu-img convert -c -O qcow2 "$tmpimage" "$BINARIES_DIR/$diskimg"
|
||||||
|
rm "$tmpimage"
|
||||||
|
|||||||
@@ -2,8 +2,6 @@
|
|||||||
|
|
||||||
set -e
|
set -e
|
||||||
|
|
||||||
GIT_VERSION=$(git -C "$BR2_EXTERNAL_INFIX_PATH" describe --always --dirty --tags)
|
|
||||||
|
|
||||||
name=$1
|
name=$1
|
||||||
compat=$2
|
compat=$2
|
||||||
sign=$3
|
sign=$3
|
||||||
@@ -26,7 +24,7 @@ cp -f "$BINARIES_DIR/rootfs.itbh" "$work/rootfs.itbh"
|
|||||||
cat >"$work/manifest.raucm" <<EOF
|
cat >"$work/manifest.raucm" <<EOF
|
||||||
[update]
|
[update]
|
||||||
compatible=${compat}
|
compatible=${compat}
|
||||||
version=${GIT_VERSION}
|
version=${INFIX_VERSION}
|
||||||
|
|
||||||
[bundle]
|
[bundle]
|
||||||
format=verity
|
format=verity
|
||||||
|
|||||||
@@ -39,22 +39,6 @@ if [ -n "${ID_LIKE}" ]; then
|
|||||||
ID="${ID} ${ID_LIKE}"
|
ID="${ID} ${ID_LIKE}"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [ -z "$GIT_VERSION" ]; then
|
|
||||||
infix_path="$BR2_EXTERNAL_INFIX_PATH"
|
|
||||||
if [ -n "$INFIX_OEM_PATH" ]; then
|
|
||||||
# Use version from br2-external OEM:ing Infix
|
|
||||||
infix_path="$INFIX_OEM_PATH"
|
|
||||||
fi
|
|
||||||
GIT_VERSION=$(git -C "$infix_path" describe --always --dirty --tags)
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Override VERSION in /etc/os-release and filenames for release builds
|
|
||||||
if [ -n "$INFIX_RELEASE" ]; then
|
|
||||||
VERSION="$INFIX_RELEASE"
|
|
||||||
else
|
|
||||||
VERSION=$GIT_VERSION
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -n "$INFIX_IMAGE_ID" ]; then
|
if [ -n "$INFIX_IMAGE_ID" ]; then
|
||||||
NAME="$INFIX_IMAGE_ID"
|
NAME="$INFIX_IMAGE_ID"
|
||||||
else
|
else
|
||||||
@@ -71,12 +55,12 @@ rm -f "$TARGET_DIR/etc/os-release"
|
|||||||
{
|
{
|
||||||
echo "NAME=\"$INFIX_NAME\""
|
echo "NAME=\"$INFIX_NAME\""
|
||||||
echo "ID=$INFIX_ID"
|
echo "ID=$INFIX_ID"
|
||||||
echo "PRETTY_NAME=\"$INFIX_TAGLINE $VERSION\""
|
echo "PRETTY_NAME=\"$INFIX_TAGLINE $INFIX_VERSION\""
|
||||||
echo "ID_LIKE=\"${ID}\""
|
echo "ID_LIKE=\"${ID}\""
|
||||||
echo "DEFAULT_HOSTNAME=$BR2_TARGET_GENERIC_HOSTNAME"
|
echo "DEFAULT_HOSTNAME=$BR2_TARGET_GENERIC_HOSTNAME"
|
||||||
echo "VERSION=\"${VERSION}\""
|
echo "VERSION=\"${INFIX_VERSION}\""
|
||||||
echo "VERSION_ID=${VERSION}"
|
echo "VERSION_ID=${INFIX_VERSION}"
|
||||||
echo "BUILD_ID=\"${GIT_VERSION}\""
|
echo "BUILD_ID=\"${INFIX_BUILD_ID}\""
|
||||||
if [ -n "$INFIX_IMAGE_ID" ]; then
|
if [ -n "$INFIX_IMAGE_ID" ]; then
|
||||||
echo "IMAGE_ID=\"$INFIX_IMAGE_ID\""
|
echo "IMAGE_ID=\"$INFIX_IMAGE_ID\""
|
||||||
fi
|
fi
|
||||||
@@ -102,7 +86,7 @@ rm -f "$TARGET_DIR/etc/os-release"
|
|||||||
fi
|
fi
|
||||||
} > "$TARGET_DIR/etc/os-release"
|
} > "$TARGET_DIR/etc/os-release"
|
||||||
|
|
||||||
echo "$INFIX_TAGLINE $VERSION -- $(date +"%b %e %H:%M %Z %Y")" > "$TARGET_DIR/etc/version"
|
echo "$INFIX_TAGLINE $INFIX_VERSION -- $(date +"%b %e %H:%M %Z %Y")" > "$TARGET_DIR/etc/version"
|
||||||
|
|
||||||
# In case of ambguities, this is what the image was built from
|
# In case of ambguities, this is what the image was built from
|
||||||
cp "$BR2_CONFIG" "$TARGET_DIR/usr/share/infix/config"
|
cp "$BR2_CONFIG" "$TARGET_DIR/usr/share/infix/config"
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ if [ -n "$IMAGE_ID" ]; then
|
|||||||
else
|
else
|
||||||
NAME="$INFIX_ID"-$(echo "$BR2_ARCH" | tr _ - | sed 's/x86-64/x86_64/')
|
NAME="$INFIX_ID"-$(echo "$BR2_ARCH" | tr _ - | sed 's/x86-64/x86_64/')
|
||||||
fi
|
fi
|
||||||
diskimg=disk.img
|
diskimg=disk.qcow2
|
||||||
|
|
||||||
ver()
|
ver()
|
||||||
{
|
{
|
||||||
@@ -48,7 +48,7 @@ fi
|
|||||||
load_cfg DISK_IMAGE
|
load_cfg DISK_IMAGE
|
||||||
if [ "$DISK_IMAGE" = "y" ]; then
|
if [ "$DISK_IMAGE" = "y" ]; then
|
||||||
ixmsg "Creating Disk Image"
|
ixmsg "Creating Disk Image"
|
||||||
diskimg="${NAME}-disk$(ver).img"
|
diskimg="${NAME}-disk$(ver).qcow2"
|
||||||
bootcfg=
|
bootcfg=
|
||||||
if [ "$DISK_IMAGE_BOOT_DATA" ]; then
|
if [ "$DISK_IMAGE_BOOT_DATA" ]; then
|
||||||
bootcfg="-b $DISK_IMAGE_BOOT_DATA -B $DISK_IMAGE_BOOT_OFFSET"
|
bootcfg="-b $DISK_IMAGE_BOOT_DATA -B $DISK_IMAGE_BOOT_OFFSET"
|
||||||
@@ -90,7 +90,7 @@ if [ "$BR2_TARGET_ROOTFS_SQUASHFS" = "y" ]; then
|
|||||||
rel=$(ver)
|
rel=$(ver)
|
||||||
ln -sf rootfs.squashfs "$BINARIES_DIR/${NAME}${rel}.img"
|
ln -sf rootfs.squashfs "$BINARIES_DIR/${NAME}${rel}.img"
|
||||||
if [ -n "$rel" ]; then
|
if [ -n "$rel" ]; then
|
||||||
ln -sf "$BINARIES_DIR/${NAME}${rel}.img" "$BINARIES_DIR/${NAME}.img"
|
ln -sf "${NAME}${rel}.img" "$BINARIES_DIR/${NAME}.img"
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|||||||
@@ -66,7 +66,7 @@ endchoice
|
|||||||
|
|
||||||
config QEMU_MACHINE
|
config QEMU_MACHINE
|
||||||
string "Select emulated machine"
|
string "Select emulated machine"
|
||||||
default "qemu-system-aarch64 -M virt,accel=kvm:tcg -cpu max" if QEMU_aarch64
|
default "qemu-system-aarch64 -M virt,accel=kvm:tcg -cpu max,pauth-impdef=on" if QEMU_aarch64
|
||||||
default "qemu-system-x86_64 -M pc,accel=kvm:tcg -cpu max" if QEMU_x86_64
|
default "qemu-system-x86_64 -M pc,accel=kvm:tcg -cpu max" if QEMU_x86_64
|
||||||
help
|
help
|
||||||
You should not have to change this setting, although you may
|
You should not have to change this setting, although you may
|
||||||
@@ -78,7 +78,7 @@ config QEMU_MACHINE
|
|||||||
|
|
||||||
config QEMU_MACHINE_RAM
|
config QEMU_MACHINE_RAM
|
||||||
string "RAM size (k/M/G)"
|
string "RAM size (k/M/G)"
|
||||||
default "384M"
|
default "448M"
|
||||||
help
|
help
|
||||||
The default, 384 MiB, works for most configurations. However,
|
The default, 384 MiB, works for most configurations. However,
|
||||||
if you get kernel panic with: "System is deadlocked on memory",
|
if you get kernel panic with: "System is deadlocked on memory",
|
||||||
@@ -189,7 +189,7 @@ config QEMU_CLOCK
|
|||||||
comment "Networking"
|
comment "Networking"
|
||||||
|
|
||||||
choice
|
choice
|
||||||
prompt "Mode"
|
prompt "Network Mode"
|
||||||
default QEMU_NET_USER
|
default QEMU_NET_USER
|
||||||
|
|
||||||
config QEMU_NET_NONE
|
config QEMU_NET_NONE
|
||||||
@@ -204,6 +204,9 @@ config QEMU_NET_USER
|
|||||||
config QEMU_NET_TAP
|
config QEMU_NET_TAP
|
||||||
bool "TAP"
|
bool "TAP"
|
||||||
|
|
||||||
|
config QEMU_NET_ROCKER
|
||||||
|
bool "Rocker"
|
||||||
|
|
||||||
endchoice
|
endchoice
|
||||||
|
|
||||||
config QEMU_NET_MODEL
|
config QEMU_NET_MODEL
|
||||||
@@ -229,3 +232,8 @@ config QEMU_NET_TAP_N
|
|||||||
int "Number of TAPs"
|
int "Number of TAPs"
|
||||||
depends on QEMU_NET_TAP
|
depends on QEMU_NET_TAP
|
||||||
default 1
|
default 1
|
||||||
|
|
||||||
|
config QEMU_NET_PORTS
|
||||||
|
int "Number of Rocker switch ports"
|
||||||
|
depends on QEMU_NET_ROCKER
|
||||||
|
default 10
|
||||||
|
|||||||
+68
-30
@@ -17,9 +17,10 @@
|
|||||||
#
|
#
|
||||||
# ./qemu.sh -h
|
# ./qemu.sh -h
|
||||||
#
|
#
|
||||||
|
# shellcheck disable=SC3037
|
||||||
|
|
||||||
# Local variables
|
# Local variables
|
||||||
imgdir=$(readlink -f $(dirname "$0"))
|
imgdir=$(readlink -f "$(dirname "$0")")
|
||||||
prognm=$(basename "$0")
|
prognm=$(basename "$0")
|
||||||
|
|
||||||
usage()
|
usage()
|
||||||
@@ -30,6 +31,7 @@ usage()
|
|||||||
echo "Options:"
|
echo "Options:"
|
||||||
echo " -c Run menuconfig to change Qemu settings"
|
echo " -c Run menuconfig to change Qemu settings"
|
||||||
echo " -h This help text"
|
echo " -h This help text"
|
||||||
|
echo " -k Keep generated qemu.run script (name shown at end)"
|
||||||
echo
|
echo
|
||||||
echo "Arguments:"
|
echo "Arguments:"
|
||||||
echo " ARGS1 Args before the '--' separator are for kernel space"
|
echo " ARGS1 Args before the '--' separator are for kernel space"
|
||||||
@@ -54,19 +56,20 @@ die()
|
|||||||
|
|
||||||
load_qemucfg()
|
load_qemucfg()
|
||||||
{
|
{
|
||||||
local tmp=$(mktemp -p /tmp)
|
tmp=$(mktemp -p /tmp)
|
||||||
|
|
||||||
grep ^CONFIG_QEMU_ $1 >$tmp
|
grep ^CONFIG_QEMU_ "$1" >"$tmp"
|
||||||
. $tmp
|
# shellcheck disable=SC1090
|
||||||
rm $tmp
|
. "$tmp"
|
||||||
|
rm "$tmp"
|
||||||
|
|
||||||
[ "$CONFIG_QEMU_MACHINE" ] || die "Missing QEMU_MACHINE"
|
[ "$CONFIG_QEMU_MACHINE" ] || die "Missing QEMU_MACHINE"
|
||||||
[ "$CONFIG_QEMU_ROOTFS" ] || die "Missing QEMU_ROOTFS"
|
[ "$CONFIG_QEMU_ROOTFS" ] || die "Missing QEMU_ROOTFS"
|
||||||
|
|
||||||
[ "$CONFIG_QEMU_KERNEL" -a "$CONFIG_QEMU_BIOS" ] \
|
[ -n "$CONFIG_QEMU_KERNEL" ] && [ -n "$CONFIG_QEMU_BIOS" ] \
|
||||||
&& die "QEMU_KERNEL conflicts with QEMU_BIOS"
|
&& die "QEMU_KERNEL conflicts with QEMU_BIOS"
|
||||||
|
|
||||||
[ ! "$CONFIG_QEMU_KERNEL" -a ! "$CONFIG_QEMU_BIOS" ] \
|
[ -z "$CONFIG_QEMU_KERNEL" ] && [ -z "$CONFIG_QEMU_BIOS" ] \
|
||||||
&& die "QEMU_KERNEL or QEMU_BIOS must be set"
|
&& die "QEMU_KERNEL or QEMU_BIOS must be set"
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -93,7 +96,7 @@ append_args()
|
|||||||
|
|
||||||
if [ "$CONFIG_QEMU_ROOTFS_INITRD" = "y" ]; then
|
if [ "$CONFIG_QEMU_ROOTFS_INITRD" = "y" ]; then
|
||||||
# Size of initrd, rounded up to nearest kb
|
# Size of initrd, rounded up to nearest kb
|
||||||
local size=$((($(stat -c %s $CONFIG_QEMU_ROOTFS) + 1023) >> 10))
|
size=$((($(stat -c %s "$CONFIG_QEMU_ROOTFS") + 1023) >> 10))
|
||||||
echo -n "root=/dev/ram0 ramdisk_size=${size} "
|
echo -n "root=/dev/ram0 ramdisk_size=${size} "
|
||||||
elif [ "$CONFIG_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
elif [ "$CONFIG_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
||||||
echo -n "root=PARTLABEL=primary "
|
echo -n "root=PARTLABEL=primary "
|
||||||
@@ -117,7 +120,7 @@ rootfs_args()
|
|||||||
echo -n "-device sd-card,drive=mmc "
|
echo -n "-device sd-card,drive=mmc "
|
||||||
echo -n "-drive id=mmc,file=$CONFIG_QEMU_ROOTFS,if=none,format=raw "
|
echo -n "-drive id=mmc,file=$CONFIG_QEMU_ROOTFS,if=none,format=raw "
|
||||||
elif [ "$CONFIG_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
elif [ "$CONFIG_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
||||||
echo -n "-drive file=$CONFIG_QEMU_ROOTFS.qcow2,if=virtio,format=qcow2,bus=0,unit=0 "
|
echo -n "-drive file=qemu.qcow2,if=virtio,format=qcow2,bus=0,unit=0 "
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -198,13 +201,24 @@ host_args()
|
|||||||
|
|
||||||
net_dev_args()
|
net_dev_args()
|
||||||
{
|
{
|
||||||
local name="e$1"
|
name="e$1"
|
||||||
local mac=$(printf "02:00:00:00:00:%02x" $1)
|
mac=$(printf "02:00:00:00:00:%02x" "$1")
|
||||||
|
|
||||||
echo -n "-device $CONFIG_QEMU_NET_MODEL,netdev=$name,mac=$mac "
|
echo -n "-device $CONFIG_QEMU_NET_MODEL,netdev=$name,mac=$mac "
|
||||||
echo "$name $mac" >>"$mactab"
|
echo "$name $mac" >>"$mactab"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
rocker_port_args()
|
||||||
|
{
|
||||||
|
sw=$1
|
||||||
|
port=$2
|
||||||
|
name="sw${sw}p${port}"
|
||||||
|
mac=$(printf "02:00:00:00:%02x:%02x" "$sw" "$port")
|
||||||
|
|
||||||
|
echo -n "-netdev tap,id=$name,ifname=$name,script=no,downscript=no "
|
||||||
|
echo "$name $mac" >> "$mactab"
|
||||||
|
}
|
||||||
|
|
||||||
net_args()
|
net_args()
|
||||||
{
|
{
|
||||||
# Infix will pick up this file via fwcfg and install it to /etc
|
# Infix will pick up this file via fwcfg and install it to /etc
|
||||||
@@ -216,14 +230,25 @@ net_args()
|
|||||||
echo -n "-netdev bridge,id=e1,br=$CONFIG_QEMU_NET_BRIDGE_DEV "
|
echo -n "-netdev bridge,id=e1,br=$CONFIG_QEMU_NET_BRIDGE_DEV "
|
||||||
net_dev_args 1
|
net_dev_args 1
|
||||||
elif [ "$CONFIG_QEMU_NET_TAP" = "y" ]; then
|
elif [ "$CONFIG_QEMU_NET_TAP" = "y" ]; then
|
||||||
for i in $(seq 1 $(($CONFIG_QEMU_NET_TAP_N))); do
|
for i in $(seq 1 "$CONFIG_QEMU_NET_TAP_N"); do
|
||||||
echo -n "-netdev tap,id=e$i,ifname=qtap$i "
|
echo -n "-netdev tap,id=e$i,ifname=qtap$i "
|
||||||
net_dev_args $i
|
net_dev_args "$i"
|
||||||
|
done
|
||||||
|
elif [ "$CONFIG_QEMU_NET_ROCKER" = "y" ]; then
|
||||||
|
sw=sw0 # Only single switch support atm.
|
||||||
|
echo -n "-device '{\"driver\":\"rocker\", \"name\":\"${sw}\", "
|
||||||
|
echo -n "\"fp_start_macaddr\":\"02:00:00:00:00:01\", "
|
||||||
|
echo -n "\"ports\":["
|
||||||
|
for i in $(seq 1 "$CONFIG_QEMU_NET_PORTS"); do
|
||||||
|
[ "$i" -gt 1 ] && echo -n ", "
|
||||||
|
echo -n "\"${sw}p${i}\""
|
||||||
|
done
|
||||||
|
echo -n "]}' "
|
||||||
|
for i in $(seq 1 "$CONFIG_QEMU_NET_PORTS"); do
|
||||||
|
rocker_port_args 0 "$i"
|
||||||
done
|
done
|
||||||
elif [ "$CONFIG_QEMU_NET_USER" = "y" ]; then
|
elif [ "$CONFIG_QEMU_NET_USER" = "y" ]; then
|
||||||
local useropts=
|
|
||||||
[ "$CONFIG_QEMU_NET_USER_OPTS" ] && useropts=",$CONFIG_QEMU_NET_USER_OPTS"
|
[ "$CONFIG_QEMU_NET_USER_OPTS" ] && useropts=",$CONFIG_QEMU_NET_USER_OPTS"
|
||||||
|
|
||||||
echo -n "-netdev user,id=e1${useropts} "
|
echo -n "-netdev user,id=e1${useropts} "
|
||||||
net_dev_args 1
|
net_dev_args 1
|
||||||
else
|
else
|
||||||
@@ -291,18 +316,17 @@ gdb_args()
|
|||||||
run_qemu()
|
run_qemu()
|
||||||
{
|
{
|
||||||
if [ "$CONFIG_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
if [ "$CONFIG_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
||||||
if ! qemu-img check "${CONFIG_QEMU_ROOTFS}.qcow2"; then
|
if ! qemu-img check "qemu.qcow2"; then
|
||||||
rm -f "${CONFIG_QEMU_ROOTFS}.qcow2"
|
rm -f "qemu.qcow2"
|
||||||
fi
|
fi
|
||||||
if [ ! -f "${CONFIG_QEMU_ROOTFS}.qcow2" ]; then
|
if [ ! -f "qemu.qcow2" ]; then
|
||||||
echo "Creating qcow2 disk image for Qemu ..."
|
echo "Creating qcow2 disk image for Qemu ..."
|
||||||
qemu-img create -f qcow2 -o backing_file="$CONFIG_QEMU_ROOTFS" \
|
qemu-img create -f qcow2 -o backing_file="$CONFIG_QEMU_ROOTFS" \
|
||||||
-F raw "${CONFIG_QEMU_ROOTFS}.qcow2" > /dev/null
|
-F qcow2 "qemu.qcow2" > /dev/null
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
local qemu
|
read -r qemu <<EOF
|
||||||
read qemu <<EOF
|
|
||||||
$CONFIG_QEMU_MACHINE -nodefaults -m $CONFIG_QEMU_MACHINE_RAM \
|
$CONFIG_QEMU_MACHINE -nodefaults -m $CONFIG_QEMU_MACHINE_RAM \
|
||||||
$(loader_args) \
|
$(loader_args) \
|
||||||
$(rootfs_args) \
|
$(rootfs_args) \
|
||||||
@@ -317,18 +341,28 @@ run_qemu()
|
|||||||
$(gdb_args) \
|
$(gdb_args) \
|
||||||
$CONFIG_QEMU_EXTRA
|
$CONFIG_QEMU_EXTRA
|
||||||
EOF
|
EOF
|
||||||
|
# Save resulting command to a script, because I cannot for the life
|
||||||
|
# of me figure out how to embed the JSON snippet for Rocker and run
|
||||||
|
# it here without issues, spent way too much time on it -- Joachim
|
||||||
|
run=$(mktemp -t run.qemu.XXX)
|
||||||
|
echo "#!/bin/sh" > "$run"
|
||||||
|
if [ "$CONFIG_QEMU_KERNEL" ]; then
|
||||||
|
echo "$qemu -append \"$(append_args)\" $*" >> "$run"
|
||||||
|
else
|
||||||
|
echo "$qemu $*" >> "$run"
|
||||||
|
fi
|
||||||
|
chmod +x "$run"
|
||||||
|
|
||||||
echo "Starting Qemu :: Ctrl-a x -- exit | Ctrl-a c -- toggle console/monitor"
|
echo "Starting Qemu :: Ctrl-a x -- exit | Ctrl-a c -- toggle console/monitor"
|
||||||
line=$(stty -g)
|
line=$(stty -g)
|
||||||
stty raw
|
stty raw
|
||||||
|
$run
|
||||||
if [ "$CONFIG_QEMU_KERNEL" ]; then
|
|
||||||
$qemu -append "$(append_args)" "$@"
|
|
||||||
else
|
|
||||||
$qemu "$@"
|
|
||||||
fi
|
|
||||||
|
|
||||||
stty "$line"
|
stty "$line"
|
||||||
|
if [ -n "$keep" ]; then
|
||||||
|
echo "Keeping generated qemu.run script: $run"
|
||||||
|
else
|
||||||
|
rm "$run"
|
||||||
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
dtb_args()
|
dtb_args()
|
||||||
@@ -364,7 +398,7 @@ generate_dot()
|
|||||||
hostports="<qtap1> qtap1"
|
hostports="<qtap1> qtap1"
|
||||||
targetports="<e1> e1"
|
targetports="<e1> e1"
|
||||||
edges="host:qtap1 -- target:e1 [kind=mgmt];"
|
edges="host:qtap1 -- target:e1 [kind=mgmt];"
|
||||||
for tap in $(seq 2 $(($CONFIG_QEMU_NET_TAP_N - 1))); do
|
for tap in $(seq 2 $((CONFIG_QEMU_NET_TAP_N - 1))); do
|
||||||
hostports="$hostports | <qtap$tap> qtap$tap "
|
hostports="$hostports | <qtap$tap> qtap$tap "
|
||||||
targetports="$targetports | <e$tap> e$tap "
|
targetports="$targetports | <e$tap> e$tap "
|
||||||
edges="$edges host:qtap$tap -- target:e$tap;"
|
edges="$edges host:qtap$tap -- target:e$tap;"
|
||||||
@@ -404,7 +438,8 @@ menuconfig()
|
|||||||
exec kconfig-mconf Config.in
|
exec kconfig-mconf Config.in
|
||||||
}
|
}
|
||||||
|
|
||||||
cd $(dirname $(readlink -f "$0"))
|
scriptdir=$(dirname "$(readlink -f "$0")")
|
||||||
|
cd "$scriptdir" || (echo "Failed cd to $scriptdir"; exit 1)
|
||||||
|
|
||||||
while [ "$1" != "" ]; do
|
while [ "$1" != "" ]; do
|
||||||
case $1 in
|
case $1 in
|
||||||
@@ -414,6 +449,9 @@ while [ "$1" != "" ]; do
|
|||||||
-h)
|
-h)
|
||||||
usage
|
usage
|
||||||
;;
|
;;
|
||||||
|
-k)
|
||||||
|
keep=true
|
||||||
|
;;
|
||||||
*)
|
*)
|
||||||
break
|
break
|
||||||
esac
|
esac
|
||||||
|
|||||||
@@ -9,46 +9,20 @@
|
|||||||
# $3 IP adddress
|
# $3 IP adddress
|
||||||
|
|
||||||
PATH="$PATH:/usr/bin:/usr/sbin:/bin:/sbin"
|
PATH="$PATH:/usr/bin:/usr/sbin:/bin:/sbin"
|
||||||
NAME="/etc/frr/static.d/$2-zeroconf.conf"
|
|
||||||
NEXT="${NAME}+"
|
|
||||||
|
|
||||||
log()
|
log()
|
||||||
{
|
{
|
||||||
logger -I $$ -t zeroconf -p user.notice "$*"
|
logger -I $$ -t zeroconf -p user.notice "$*"
|
||||||
}
|
}
|
||||||
|
|
||||||
# Reduce changes needed by comparing with previous route(s)
|
|
||||||
act()
|
|
||||||
{
|
|
||||||
case $1 in
|
|
||||||
add)
|
|
||||||
echo "! Generated by avahi-autoipd" > "$NEXT"
|
|
||||||
echo "ip route 0.0.0.0/0 $2 254" >> "$NEXT"
|
|
||||||
cmp -s "$NAME" "$NEXT" && return
|
|
||||||
mv "$NEXT" "$NAME"
|
|
||||||
;;
|
|
||||||
del)
|
|
||||||
[ -f "$NAME" ] || return
|
|
||||||
rm "$NAME"
|
|
||||||
;;
|
|
||||||
*)
|
|
||||||
return
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
initctl -nbq restart staticd
|
|
||||||
}
|
|
||||||
|
|
||||||
case "$1" in
|
case "$1" in
|
||||||
BIND)
|
BIND)
|
||||||
ip addr flush dev "$2" proto random
|
ip addr flush dev "$2" proto random
|
||||||
ip addr add "$3"/16 brd 169.254.255.255 scope link dev "$2" proto random
|
ip addr add "$3"/16 brd 169.254.255.255 scope link dev "$2" proto random
|
||||||
act add "$2"
|
|
||||||
log "set ipv4ll $3 on iface $2"
|
log "set ipv4ll $3 on iface $2"
|
||||||
;;
|
;;
|
||||||
|
|
||||||
CONFLICT|UNBIND|STOP)
|
CONFLICT|UNBIND|STOP)
|
||||||
act del "$2"
|
|
||||||
ip addr flush dev "$2" proto random
|
ip addr flush dev "$2" proto random
|
||||||
log "clr ipv4ll on iface $2"
|
log "clr ipv4ll on iface $2"
|
||||||
;;
|
;;
|
||||||
|
|||||||
@@ -0,0 +1,2 @@
|
|||||||
|
# --log-level debug
|
||||||
|
OSPFD_ARGS="-A 127.0.0.1 -u frr -g frr -f /etc/frr/ospfd.conf --log syslog"
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
RAUC_ARGS="-s"
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
# --log-level debug
|
||||||
|
ZEBRA_ARGS="-A 127.0.0.1 -u frr -g frr --log syslog "
|
||||||
@@ -3,16 +3,19 @@
|
|||||||
# and similar events feed servers and configuration to dnsmasq.
|
# and similar events feed servers and configuration to dnsmasq.
|
||||||
domain-needed
|
domain-needed
|
||||||
|
|
||||||
# Only listen to loopback (local system)
|
# Allow configuration and cache clear over D-Bus
|
||||||
interface=lo
|
|
||||||
bind-dynamic
|
|
||||||
#listen-address=127.0.0.1,::1
|
|
||||||
|
|
||||||
enable-dbus
|
enable-dbus
|
||||||
|
|
||||||
|
# Disable the following dnsmasq default DHCP options
|
||||||
|
#dhcp-option=option:netmask
|
||||||
|
#dhcp-option=28 # option:broadcast
|
||||||
|
#dhcp-option=option:domain-name
|
||||||
|
dhcp-option=option:router
|
||||||
|
dhcp-option=option:dns-server
|
||||||
|
dhcp-option=12 # option:hostname
|
||||||
|
|
||||||
# Generated by openresolv
|
# Generated by openresolv
|
||||||
resolv-file=/var/lib/misc/resolv.conf
|
resolv-file=/var/lib/misc/resolv.conf
|
||||||
|
|
||||||
# Include all files in a directory which end in .conf
|
# Include all files in a directory which end in .conf
|
||||||
conf-dir=/etc/dnsmasq.d/,*.conf
|
conf-dir=/etc/dnsmasq.d/,*.conf
|
||||||
|
|
||||||
|
|||||||
@@ -1,4 +1,7 @@
|
|||||||
service :%i pid:!/run/k8s-logger-%i.pid <usr/container:%i> \
|
# Start a container instance (%i) and redirect logs to /log/container
|
||||||
[2345] k8s-logger -cni %i -f local1 /run/containers/%i.fifo -- Logger for container %i
|
# Give podman enough time to properly shut down the container. Every
|
||||||
sysv :%i pid:!/run/container:%i.pid <pid/k8s-logger:%i> log kill:10 \
|
# time we start a container we run the setup stage, disable the Finit
|
||||||
[2345] container -n %i -- container %i
|
# timeout to allow the setup stage to run to completion.
|
||||||
|
sysv log:prio:local1,tag:%i kill:10 pid:!/run/container:%i.pid \
|
||||||
|
pre:0,/usr/sbin/container cleanup:0,/usr/sbin/container \
|
||||||
|
[2345] <!> :%i container -n %i -- container %i
|
||||||
|
|||||||
@@ -0,0 +1,9 @@
|
|||||||
|
# A single mstpd instance can manage multiple bridges, which are
|
||||||
|
# dynamically added/removed by the kernel via the /sbin/bridge-stp
|
||||||
|
# usermode helper. We use a manual service so that confd can
|
||||||
|
# enable/disable it without an initctl barrier, since it needs to
|
||||||
|
# already be running when a bridge interface with spanning tree
|
||||||
|
# enabled is created.
|
||||||
|
|
||||||
|
service env:-/etc/default/mstpd manual:yes \
|
||||||
|
[S0123456789] mstpd $MSTPD_ARGS -- Spanning Tree daemon
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
# Use <pid/syslogd> as barrier for other system tasks and service that
|
||||||
|
# rely on modules, firmware, and device nodes to be ready.
|
||||||
|
service if:udevd nowarn env:-/etc/default/sysklogd <run/udevadm:post/success> \
|
||||||
|
[S0123456789] syslogd -F $SYSLOGD_ARGS -- System log daemon
|
||||||
@@ -1 +1 @@
|
|||||||
service [2345] <!> ttyd -i lo -p 8001 login -- Web terminal daemon (ttyd)
|
service [2345] <!> ttyd -i lo -W -p 8001 login -- Web terminal daemon (ttyd)
|
||||||
|
|||||||
@@ -0,0 +1,5 @@
|
|||||||
|
service name:wpa_supplicant :%i \
|
||||||
|
[2345] wpa_supplicant -s -i %i -c /etc/wpa_supplicant-%i.conf -P/var/run/wpa_supplicant-%i.pid \
|
||||||
|
-- WPA supplicant @%i
|
||||||
|
|
||||||
|
task name:wifi-scanner :%i [2345] <pid/wpa_supplicant:%i> /usr/libexec/infix/wifi-scanner %i -- Start scanning for SSID @ %i
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
../available/mstpd.conf
|
||||||
+1
@@ -0,0 +1 @@
|
|||||||
|
/var/lib/dbus/machine-id
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
.-------.
|
.-------.
|
||||||
| . . | Infix -- a Network Operating System
|
| . . | Infix OS — Immutable.Friendly.Secure
|
||||||
|-. v .-| https://kernelkit.org
|
|-. v .-| https://kernelkit.org
|
||||||
'-'---'-'
|
'-'---'-'
|
||||||
|
|||||||
@@ -1,5 +1,11 @@
|
|||||||
# /telemetry/optics is for streaming (not used atm)
|
# /telemetry/optics is for streaming (not used atm)
|
||||||
|
# Proxy buffer settings for large files
|
||||||
|
proxy_buffering off; # Disable buffering for streaming
|
||||||
|
proxy_request_buffering off; # Stream request body immediately
|
||||||
|
proxy_max_temp_file_size 0; # No temp files
|
||||||
location ~ ^/(restconf|yang|.well-known)/ {
|
location ~ ^/(restconf|yang|.well-known)/ {
|
||||||
|
client_max_body_size 200M;
|
||||||
|
client_body_buffer_size 1M;
|
||||||
grpc_pass grpc://[::1]:10080;
|
grpc_pass grpc://[::1]:10080;
|
||||||
grpc_set_header Host $host;
|
grpc_set_header Host $host;
|
||||||
grpc_set_header X-Real-IP $remote_addr;
|
grpc_set_header X-Real-IP $remote_addr;
|
||||||
|
|||||||
@@ -1,2 +1 @@
|
|||||||
alias cli='clish'
|
alias cli='clish'
|
||||||
alias cfg='sysrepocfg -f json'
|
|
||||||
|
|||||||
@@ -1,3 +0,0 @@
|
|||||||
HostKey /var/lib/ssh/ssh_host_rsa_key
|
|
||||||
HostKey /var/lib/ssh/ssh_host_ecdsa_key
|
|
||||||
HostKey /var/lib/ssh/ssh_host_ed25519_key
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
net.ipv4.ip_forward=1
|
|
||||||
net.ipv4.ip_forward_update_priority=0
|
|
||||||
net.ipv6.conf.all.forwarding=1
|
|
||||||
@@ -1 +1,32 @@
|
|||||||
|
# Router defaults
|
||||||
|
net.ipv4.conf.default.rp_filter=0
|
||||||
|
net.ipv4.conf.all.rp_filter=0
|
||||||
|
|
||||||
|
net.ipv4.conf.lo.rp_filter=0
|
||||||
|
|
||||||
|
net.ipv4.icmp_errors_use_inbound_ifaddr=1
|
||||||
|
net.ipv4.conf.all.ignore_routes_with_linkdown=1
|
||||||
|
|
||||||
|
# Use neigh information on selection of nexthop for multipath hops
|
||||||
|
net.ipv4.fib_multipath_use_neigh=1
|
||||||
|
|
||||||
|
# Sane ARP defaults for a switch/router
|
||||||
|
net.ipv4.conf.default.arp_announce=2
|
||||||
|
net.ipv4.conf.all.arp_announce=2
|
||||||
|
|
||||||
|
net.ipv4.conf.default.arp_notify=1
|
||||||
|
net.ipv4.conf.all.arp_notify=1
|
||||||
|
|
||||||
|
net.ipv4.conf.default.arp_ignore=1
|
||||||
|
net.ipv4.conf.all.arp_ignore=1
|
||||||
|
|
||||||
|
# IP Routing
|
||||||
|
net.ipv4.ip_forward=1
|
||||||
|
net.ipv4.ip_forward_update_priority=0
|
||||||
|
|
||||||
net.ipv4.conf.all.forwarding=0
|
net.ipv4.conf.all.forwarding=0
|
||||||
|
net.ipv4.conf.default.forwarding=0
|
||||||
|
|
||||||
|
# Multicast group subscriptions
|
||||||
|
net.ipv4.igmp_max_memberships=1000
|
||||||
|
net.ipv4.neigh.default.mcast_solicit=10
|
||||||
|
|||||||
@@ -1,5 +1,23 @@
|
|||||||
net.ipv6.conf.all.forwarding=1
|
# Router defaults
|
||||||
|
net.ipv6.route.max_size=131072
|
||||||
|
net.ipv6.conf.all.ignore_routes_with_linkdown=1
|
||||||
|
|
||||||
|
# IP Routing is disabled by default, enabled globally, and per
|
||||||
|
# interface, for each interface in confd. See also accept_ra.
|
||||||
|
net.ipv6.conf.all.forwarding=0
|
||||||
net.ipv6.conf.default.forwarding=0
|
net.ipv6.conf.default.forwarding=0
|
||||||
|
|
||||||
|
# Accept router advertisements even when forwarding is enabled
|
||||||
|
net.ipv6.conf.all.accept_ra=2
|
||||||
|
net.ipv6.conf.default.accept_ra=2
|
||||||
|
|
||||||
|
# IPv6 SLAAC
|
||||||
net.ipv6.conf.all.autoconf=0
|
net.ipv6.conf.all.autoconf=0
|
||||||
net.ipv6.conf.default.autoconf=0
|
net.ipv6.conf.default.autoconf=0
|
||||||
|
|
||||||
|
# Keep permanent addresses on an admin down
|
||||||
|
net.ipv6.conf.all.keep_addr_on_down=1
|
||||||
net.ipv6.conf.default.keep_addr_on_down=1
|
net.ipv6.conf.default.keep_addr_on_down=1
|
||||||
|
|
||||||
|
# Multicast group subscriptions
|
||||||
|
net.ipv6.mld_max_msf=512
|
||||||
|
|||||||
@@ -0,0 +1,145 @@
|
|||||||
|
Many of the defaults here are are taken from the Frr recommendations [1].
|
||||||
|
Below are relevant excerpts from the kernel documentation.
|
||||||
|
|
||||||
|
|
||||||
|
accept_ra, accept Router Advertisements; autoconfigure using them, also
|
||||||
|
determines whether or not to transmit Router Solicitations.
|
||||||
|
If and only if the functional setting is to accept Router
|
||||||
|
Advertisements, Router Solicitations will be transmitted.
|
||||||
|
|
||||||
|
0 - Do not accept Router Advertisements.
|
||||||
|
|
||||||
|
1 - Accept Router Advertisements if forwarding is disabled.
|
||||||
|
|
||||||
|
2 - Overrule forwarding behaviour. Accept Router Advertisements even
|
||||||
|
if forwarding is enabled.
|
||||||
|
|
||||||
|
Default:
|
||||||
|
- enabled if local forwarding is disabled
|
||||||
|
- disabled if local forwarding is enabled
|
||||||
|
|
||||||
|
|
||||||
|
accept_ra_pinfo, learn Prefix Information in Router Advertisement.
|
||||||
|
|
||||||
|
Default:
|
||||||
|
- enabled if accept_ra is enabled
|
||||||
|
- disabled if accept_ra is disabled
|
||||||
|
|
||||||
|
|
||||||
|
autoconf, autoconfigure IPv6 addresses using Prefix Information in
|
||||||
|
Router Advertisements.
|
||||||
|
|
||||||
|
Default:
|
||||||
|
- enabled if accept_ra_pinfo is enabled
|
||||||
|
- disabled if accept_ra_pinfo is disabled
|
||||||
|
|
||||||
|
|
||||||
|
arp_announce, define restriction level for announcing the local source
|
||||||
|
address from IP packets in ARP requests sent on interface:
|
||||||
|
|
||||||
|
0 - (default) Use any local address, configured on any interface
|
||||||
|
|
||||||
|
1 - Try to avoid local addresses that are not in the target’s subnet
|
||||||
|
for this interface. Useful when target hosts reachable via this
|
||||||
|
interface require the source IP address in ARP requests to be part
|
||||||
|
of their logical network configured on the receiving interface.
|
||||||
|
When we generate the request we will check all our subnets that
|
||||||
|
include the target IP and will preserve the source address if it
|
||||||
|
is from such subnet. If there is no such subnet we select source
|
||||||
|
address according to the rules for level 2.
|
||||||
|
|
||||||
|
2 - Always use the best local address for this target. In this mode we
|
||||||
|
ignore the source address in the IP packet and try to select local
|
||||||
|
address that we prefer for talks with the target host. Such local
|
||||||
|
address is selected by looking for primary IP addresses on all our
|
||||||
|
subnets on the outgoing interface that include the target address.
|
||||||
|
If no suitable local address is found we select the first local
|
||||||
|
address we have on the outgoing interface or on all other
|
||||||
|
interfaces, with the hope we will receive reply for our request
|
||||||
|
and even sometimes no matter the source IP address we announce.
|
||||||
|
|
||||||
|
|
||||||
|
arp_notify, define mode for notification of address and device changes.
|
||||||
|
|
||||||
|
0 - (default): do nothing
|
||||||
|
1 - generate gratuitous arp requests when device is brought up or
|
||||||
|
hardware address changes.
|
||||||
|
|
||||||
|
|
||||||
|
arp_ignore, define different modes for sending replies in response to
|
||||||
|
received ARP requests that resolve local target addresses:
|
||||||
|
|
||||||
|
0 - (default): reply for any local target IP address, configured on
|
||||||
|
any interface
|
||||||
|
|
||||||
|
1 - reply only if the target IP address is a local address configured
|
||||||
|
on the incoming interface
|
||||||
|
|
||||||
|
2 - reply only if the target IP address is local address configured on
|
||||||
|
the incoming interface and both with the sender’s IP address are part
|
||||||
|
from same subnet on this interface
|
||||||
|
|
||||||
|
3 - do not reply for local addresses configured with scope host, only
|
||||||
|
resolutions for global and link addresses are replied
|
||||||
|
|
||||||
|
4-7 - reserved
|
||||||
|
|
||||||
|
8 - do not reply for all local addresses
|
||||||
|
|
||||||
|
|
||||||
|
arp_accept, define behavior for accepting gratuitous ARP (garp) frames
|
||||||
|
from devices that are not already present in the ARP table:
|
||||||
|
|
||||||
|
0 - don’t create new entries in the ARP table
|
||||||
|
|
||||||
|
1 - create new entries in the ARP table
|
||||||
|
|
||||||
|
2 - create new entries only if the source IP address is in the same
|
||||||
|
subnet as an address configured on the interface that received
|
||||||
|
the garp message.
|
||||||
|
|
||||||
|
Both replies and requests type gratuitous arp will trigger the ARP
|
||||||
|
table to be updated, if this setting is on. If the ARP table already
|
||||||
|
contains the IP address of the gratuitous arp frame, the arp table
|
||||||
|
will be updated regardless if this setting is on or off.
|
||||||
|
|
||||||
|
|
||||||
|
icmp_errors_use_inbound_ifaddr
|
||||||
|
|
||||||
|
0 - (default): icmp error messages are sent with the primary address
|
||||||
|
of the exiting interface.
|
||||||
|
|
||||||
|
1 - the message will be sent with the primary address of the interface
|
||||||
|
that received the packet that caused the icmp error. This is the
|
||||||
|
behaviour many network administrators will expect from a router.
|
||||||
|
And it can make debugging complicated network layouts much easier.
|
||||||
|
|
||||||
|
Note, if no primary address exists for the interface selected, then
|
||||||
|
the primary address of the first non-loopback interface that has one
|
||||||
|
will be used regardless of this setting.
|
||||||
|
|
||||||
|
|
||||||
|
rp_filter, reverse path source filtering:
|
||||||
|
|
||||||
|
0 - (default): no source validation.
|
||||||
|
|
||||||
|
1 - Strict mode as defined in RFC3704, 'Strict Reverse Path'. Each
|
||||||
|
incoming packet is tested against the FIB and if the interface is
|
||||||
|
not the best reverse path the packet check will fail. By default
|
||||||
|
failed packets are discarded.
|
||||||
|
|
||||||
|
2 - Loose mode as defined in RFC3704, 'Loose Reverse Path'. Each
|
||||||
|
incoming packet’s source address is also tested against the FIB
|
||||||
|
and if the source address is not reachable via any interface the
|
||||||
|
packet check will fail.
|
||||||
|
|
||||||
|
Current recommended practice in RFC3704 is to enable strict mode to
|
||||||
|
prevent IP spoofing from DDos attacks. If using asymmetric routing or
|
||||||
|
other complicated routing, then loose mode is recommended.
|
||||||
|
|
||||||
|
The max value from conf/{all,interface}/rp_filter is used when doing
|
||||||
|
source validation on the {interface}.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
[1]: https://github.com/FRRouting/frr/blob/master/doc/user/Useful_Sysctl_Settings.md
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
SUBSYSTEM=="net", ACTION=="add", TEST=="/sys/class/net/$name/wireless", NAME="wifi%n"
|
||||||
Executable
+58
@@ -0,0 +1,58 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# User-friendly wrapper for sysrepocfg
|
||||||
|
# TODO: add import/export, copy, ...
|
||||||
|
|
||||||
|
# Edit YANG binary types using sysrepo, base64, and duct tape.
|
||||||
|
edit()
|
||||||
|
{
|
||||||
|
xpath=$1
|
||||||
|
if [ -z "$xpath" ]; then
|
||||||
|
echo "Usage: cfg edit \"/full/xpath/to/binary/leaf\""
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if tmp=$(sysrepocfg -G "$xpath"); then
|
||||||
|
file=$(mktemp)
|
||||||
|
|
||||||
|
echo "$tmp" | base64 -d > "$file"
|
||||||
|
if /usr/bin/editor "$file"; then
|
||||||
|
tmp=$(base64 -w0 < "$file")
|
||||||
|
sysrepocfg -S "$xpath" -u "$tmp"
|
||||||
|
fi
|
||||||
|
|
||||||
|
rm -f "$file"
|
||||||
|
else
|
||||||
|
echo "Failed to retrieve value for $xpath"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
usage()
|
||||||
|
{
|
||||||
|
echo "Usage:"
|
||||||
|
echo " cfg CMD [ARG]"
|
||||||
|
echo
|
||||||
|
echo "Command:"
|
||||||
|
echo " edit XPATH Edit YANG binary type"
|
||||||
|
echo " help This help text"
|
||||||
|
echo
|
||||||
|
echo "As a backwards compatible fallback, this script forwards"
|
||||||
|
echo "all other commands as options to sysrepocfg."
|
||||||
|
echo
|
||||||
|
|
||||||
|
exit 0
|
||||||
|
}
|
||||||
|
|
||||||
|
cmd=$1; shift
|
||||||
|
case $cmd in
|
||||||
|
edit)
|
||||||
|
edit "$1"
|
||||||
|
;;
|
||||||
|
help)
|
||||||
|
usage
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
set -- "$cmd" "$@"
|
||||||
|
exec sysrepocfg -f json "$@"
|
||||||
|
;;
|
||||||
|
esac
|
||||||
@@ -21,7 +21,11 @@ dir()
|
|||||||
if [ -d "$1" ]; then
|
if [ -d "$1" ]; then
|
||||||
dir "$1"
|
dir "$1"
|
||||||
else
|
else
|
||||||
dir "$HOME"
|
if [ "$USER" = "root" ]; then
|
||||||
|
dir "$HOME"
|
||||||
|
else
|
||||||
|
dir "/home/$USER"
|
||||||
|
fi
|
||||||
dir "/cfg"
|
dir "/cfg"
|
||||||
dir "/log"
|
dir "/log"
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -1 +0,0 @@
|
|||||||
less
|
|
||||||
Executable
+14
@@ -0,0 +1,14 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# -d ;; suppress error message "the terminal is dumb"
|
||||||
|
# -F :: exit if the entire file can be displayed on the first screen
|
||||||
|
# -I :: Ignore case, even for patterns
|
||||||
|
# -K :: exit immediately when an interrupt character (usually ^C) is typed
|
||||||
|
# -R :: Almost raw control charachters, only ANSI color escape sequences and
|
||||||
|
# OSC 8 hyperlink sequences are output. Allows veritcal scrolling
|
||||||
|
# -X :: No termcap initialization and deinitialization set to the terminal.
|
||||||
|
# This is what leaves the contents of the output on screen.
|
||||||
|
|
||||||
|
export LESS="-P %f (press h for help or q to quit)"
|
||||||
|
export LANG=en_US.UTF-8
|
||||||
|
|
||||||
|
less -RIKd -FX "$@"
|
||||||
Executable → Regular
+49
@@ -70,12 +70,14 @@ options:
|
|||||||
-p Show plain output, no bells or whistles
|
-p Show plain output, no bells or whistles
|
||||||
|
|
||||||
commands:
|
commands:
|
||||||
|
dhcp Show DHCP server
|
||||||
port PORT Show port configuration and link information
|
port PORT Show port configuration and link information
|
||||||
ports Show ports available for bridging
|
ports Show ports available for bridging
|
||||||
vlans Show port groups in bridge
|
vlans Show port groups in bridge
|
||||||
ifaces Show interfaces and their addresses
|
ifaces Show interfaces and their addresses
|
||||||
fdb Show forwarding database (unicast)
|
fdb Show forwarding database (unicast)
|
||||||
mdb Show multicast forwarding database
|
mdb Show multicast forwarding database
|
||||||
|
stp Show spanning tree status
|
||||||
ip addr Show IPv4 addresses
|
ip addr Show IPv4 addresses
|
||||||
route Show routing table
|
route Show routing table
|
||||||
ipv6 addr Show IPv6 addresses
|
ipv6 addr Show IPv6 addresses
|
||||||
@@ -87,6 +89,41 @@ commands:
|
|||||||
EOF
|
EOF
|
||||||
}
|
}
|
||||||
|
|
||||||
|
is_dhcp_running()
|
||||||
|
{
|
||||||
|
sysrepocfg -X -f json -m infix-dhcp-server | jq -r '
|
||||||
|
."infix-dhcp-server:dhcp-server".enabled as $global |
|
||||||
|
if ."infix-dhcp-server:dhcp-server".subnet? then
|
||||||
|
(."infix-dhcp-server:dhcp-server".subnet[] |
|
||||||
|
select(.enabled != false)) |
|
||||||
|
if $global != false and . then "true" else "false" end
|
||||||
|
else "false" end
|
||||||
|
' 2>/dev/null | grep -q true
|
||||||
|
}
|
||||||
|
|
||||||
|
dhcp()
|
||||||
|
{
|
||||||
|
if ! is_dhcp_running; then
|
||||||
|
echo "DHCP server not enabled."
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
case $1 in
|
||||||
|
detail)
|
||||||
|
sysrepocfg -f json -X -d operational -m infix-dhcp-server | \
|
||||||
|
jq -C .
|
||||||
|
;;
|
||||||
|
stat*)
|
||||||
|
sysrepocfg -f json -X -d operational -m infix-dhcp-server | \
|
||||||
|
/usr/libexec/statd/cli-pretty "show-dhcp-server" -s
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
sysrepocfg -f json -X -d operational -m infix-dhcp-server | \
|
||||||
|
/usr/libexec/statd/cli-pretty "show-dhcp-server"
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
}
|
||||||
|
|
||||||
# Usage 1: show port eth0
|
# Usage 1: show port eth0
|
||||||
# Usage 2: show port
|
# Usage 2: show port
|
||||||
# Usage 3: show ports
|
# Usage 3: show ports
|
||||||
@@ -188,6 +225,12 @@ rstp()
|
|||||||
mstpctl showport br0
|
mstpctl showport br0
|
||||||
}
|
}
|
||||||
|
|
||||||
|
stp()
|
||||||
|
{
|
||||||
|
sysrepocfg -f json -X -d operational -m ietf-interfaces | \
|
||||||
|
/usr/libexec/statd/cli-pretty "show-bridge-stp"
|
||||||
|
}
|
||||||
|
|
||||||
fdb()
|
fdb()
|
||||||
{
|
{
|
||||||
bridge $bopt fdb show
|
bridge $bopt fdb show
|
||||||
@@ -288,6 +331,9 @@ case $cmd in
|
|||||||
help)
|
help)
|
||||||
usage
|
usage
|
||||||
;;
|
;;
|
||||||
|
dhcp | dhcp-server)
|
||||||
|
dhcp $*
|
||||||
|
;;
|
||||||
port*)
|
port*)
|
||||||
ports $*
|
ports $*
|
||||||
;;
|
;;
|
||||||
@@ -353,6 +399,9 @@ case $cmd in
|
|||||||
span*)
|
span*)
|
||||||
rstp
|
rstp
|
||||||
;;
|
;;
|
||||||
|
stp*)
|
||||||
|
stp
|
||||||
|
;;
|
||||||
sys*)
|
sys*)
|
||||||
system
|
system
|
||||||
;;
|
;;
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
# Extend finit's default udevadm settle synchronization for situations
|
||||||
|
# where device are very slow to probe (see #685)
|
||||||
|
run nowarn if:udevd cgroup.init <service/udevd/ready> log \
|
||||||
|
[S] /usr/libexec/infix/hw-wait -- Probing hardware
|
||||||
|
|
||||||
|
# Now that everything should be probed, do a final pass over the
|
||||||
|
# uevent queue before starting syslogd and everything else
|
||||||
|
run nowarn if:udevd cgroup.init :post <service/udevd/ready> log \
|
||||||
|
[S] udevadm settle -t 30 --
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
d /run/containers/args 0700 - -
|
||||||
|
d /run/containers/files 0700 - -
|
||||||
|
d /var/lib/containers 0700 - -
|
||||||
|
d /var/lib/containers/oci 0700 - -
|
||||||
|
d /run/cni 0755 - -
|
||||||
|
L+ /var/lib/cni - - - - /run/cni
|
||||||
@@ -1 +1,2 @@
|
|||||||
d /var/run/frr 0755 frr frr -
|
d /var/run/frr 0755 frr frr -
|
||||||
|
R /var/tmp/frr - - - -
|
||||||
|
|||||||
+12
@@ -0,0 +1,12 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
if [ $# -lt 2 ]; then
|
||||||
|
echo "usage: $0 <quirk-name> <ifname>"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
quirk=$1
|
||||||
|
ifname=$2
|
||||||
|
if [ -f "/etc/product/interface-quirks.json" ]; then
|
||||||
|
echo "$(jq -r --arg iface "$ifname" --arg quirk "$quirk" '.[$iface][$quirk] // "false"' /etc/product/interface-quirks.json)"
|
||||||
|
else
|
||||||
|
echo "false"
|
||||||
|
fi
|
||||||
+41
@@ -0,0 +1,41 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# (Ab)use the kernel's device link subsystem to detect consumer side
|
||||||
|
# devices that may be very slow to probe (looking at you, mv88e6xxx!).
|
||||||
|
|
||||||
|
ident=$(basename "$0")
|
||||||
|
|
||||||
|
report()
|
||||||
|
{
|
||||||
|
if [ -r "/tmp/$ident" ]; then
|
||||||
|
logger -k -p "user.$1" -t "$ident" "Waited for slow devices:"
|
||||||
|
sort "/tmp/$ident" | uniq -c | logger -k -p "user.$1" -t "$ident"
|
||||||
|
fi
|
||||||
|
|
||||||
|
rm -f "/tmp/$ident"
|
||||||
|
}
|
||||||
|
|
||||||
|
for _ in $(seq 50); do
|
||||||
|
again=
|
||||||
|
|
||||||
|
for dl in /sys/class/devlink/*; do
|
||||||
|
[ -r "$dl/status" ] || continue
|
||||||
|
|
||||||
|
status=$(cat "$dl/status")
|
||||||
|
if [ "$status" = "consumer probing" ]; then
|
||||||
|
basename "$(readlink "$dl/consumer")" >>"/tmp/$ident"
|
||||||
|
again=yes
|
||||||
|
fi
|
||||||
|
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ -z "$again" ]; then
|
||||||
|
report notice
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
sleep .2
|
||||||
|
done
|
||||||
|
|
||||||
|
logger -k -p user.error -t "$ident" "Timeout waiting for devices to come online"
|
||||||
|
report error
|
||||||
|
exit 1
|
||||||
@@ -8,10 +8,11 @@ import struct
|
|||||||
import subprocess
|
import subprocess
|
||||||
import sys
|
import sys
|
||||||
|
|
||||||
onieprom = importlib.machinery.SourceFileLoader("onieprom","/bin/onieprom").load_module()
|
onieprom = importlib.machinery.SourceFileLoader("onieprom", "/bin/onieprom").load_module()
|
||||||
SYSTEM_JSON = "/run/system.json"
|
SYSTEM_JSON = "/run/system.json"
|
||||||
KKIT_IANA_PEM = 61046
|
KKIT_IANA_PEM = 61046
|
||||||
|
|
||||||
|
|
||||||
class DTSystem:
|
class DTSystem:
|
||||||
BASE = "/sys/firmware/devicetree/base"
|
BASE = "/sys/firmware/devicetree/base"
|
||||||
INFIX = BASE + "/chosen/infix"
|
INFIX = BASE + "/chosen/infix"
|
||||||
@@ -28,7 +29,9 @@ class DTSystem:
|
|||||||
if not os.path.exists(phandle):
|
if not os.path.exists(phandle):
|
||||||
continue
|
continue
|
||||||
|
|
||||||
ph, = struct.unpack(">L", open(phandle, "rb").read())
|
with open(phandle, "rb") as f:
|
||||||
|
data = f.read()
|
||||||
|
ph, = struct.unpack(">L", data)
|
||||||
dt[ph] = root
|
dt[ph] = root
|
||||||
|
|
||||||
sys = {}
|
sys = {}
|
||||||
@@ -40,14 +43,18 @@ class DTSystem:
|
|||||||
if not os.path.exists(phandle):
|
if not os.path.exists(phandle):
|
||||||
continue
|
continue
|
||||||
|
|
||||||
ph, = struct.unpack(">L", open(phandle, "rb").read())
|
with open(phandle, "rb") as f:
|
||||||
|
data = f.read()
|
||||||
|
ph, = struct.unpack(">L", data)
|
||||||
if ph not in sys:
|
if ph not in sys:
|
||||||
sys[ph] = []
|
sys[ph] = []
|
||||||
sys[ph].append(root)
|
sys[ph].append(root)
|
||||||
|
|
||||||
phs = set(list(dt.keys()) + list(sys.keys()))
|
phs = set(list(dt.keys()) + list(sys.keys()))
|
||||||
|
|
||||||
self.devs = { ph: [Device(ph, dt.get(ph), s if s is not None else "") for s in (sys.get(ph) or []) if ph is not None] for ph in phs }
|
self.devs = {ph: [Device(ph, dt.get(ph), s if s is not None else "")
|
||||||
|
for s in (sys.get(ph) or []) if ph is not None]
|
||||||
|
for ph in phs}
|
||||||
self.base = Device(0, None, DTSystem.BASE)
|
self.base = Device(0, None, DTSystem.BASE)
|
||||||
self.infix = Device(0, None, DTSystem.INFIX)
|
self.infix = Device(0, None, DTSystem.INFIX)
|
||||||
|
|
||||||
@@ -56,7 +63,8 @@ class DTSystem:
|
|||||||
if not os.path.exists(path):
|
if not os.path.exists(path):
|
||||||
return ()
|
return ()
|
||||||
|
|
||||||
data = open(path, "rb").read()
|
with open(path, "rb") as f:
|
||||||
|
data = f.read()
|
||||||
elems = len(data) // struct.calcsize(">L")
|
elems = len(data) // struct.calcsize(">L")
|
||||||
return struct.unpack(">" + elems * "L", data)
|
return struct.unpack(">" + elems * "L", data)
|
||||||
|
|
||||||
@@ -69,7 +77,8 @@ class DTSystem:
|
|||||||
return {}
|
return {}
|
||||||
|
|
||||||
try:
|
try:
|
||||||
data = onieprom.from_tlv(open(dev.attrpath("nvmem"), "rb", 0))
|
with open(dev.attrpath("nvmem"), "rb", 0) as f:
|
||||||
|
data = onieprom.from_tlv(f)
|
||||||
except:
|
except:
|
||||||
data = {}
|
data = {}
|
||||||
|
|
||||||
@@ -84,14 +93,18 @@ class DTSystem:
|
|||||||
}
|
}
|
||||||
|
|
||||||
def infix_usb_devices(self, out):
|
def infix_usb_devices(self, out):
|
||||||
names=self.infix.str_array("usb-port-names", ())
|
names = self.infix.str_array("usb-port-names", ())
|
||||||
phs=self.__get_phandle_array("usb-ports")
|
phs = self.__get_phandle_array("usb-ports")
|
||||||
data=dict(zip(names,phs))
|
data = dict(zip(names, phs))
|
||||||
if data != {}:
|
if data != {}:
|
||||||
out["usb-ports"] = []
|
out["usb-ports"] = []
|
||||||
for name,ph in data.items():
|
for name, ph in data.items():
|
||||||
[out["usb-ports"].extend([{"name": name, "path": dev.attrpath("authorized")}, {"name": name, "path": dev.attrpath("authorized_default")}]) for dev in self.devices_from_ph(ph)]
|
[out["usb-ports"].extend([{
|
||||||
|
"name": name,
|
||||||
|
"path": dev.attrpath("authorized")}, {
|
||||||
|
"name": name,
|
||||||
|
"path": dev.attrpath("authorized_default")
|
||||||
|
}]) for dev in self.devices_from_ph(ph)]
|
||||||
|
|
||||||
def infix_devices(self, kind):
|
def infix_devices(self, kind):
|
||||||
phs = self.__get_phandle_array(kind)
|
phs = self.__get_phandle_array(kind)
|
||||||
@@ -101,6 +114,7 @@ class DTSystem:
|
|||||||
flat_devices = [device for sublist in self.infix_devices("vpds") for device in sublist]
|
flat_devices = [device for sublist in self.infix_devices("vpds") for device in sublist]
|
||||||
return [self.into_vpd(device) for device in flat_devices]
|
return [self.into_vpd(device) for device in flat_devices]
|
||||||
|
|
||||||
|
|
||||||
class QEMUSystem:
|
class QEMUSystem:
|
||||||
BASE = "/sys/firmware/qemu_fw_cfg"
|
BASE = "/sys/firmware/qemu_fw_cfg"
|
||||||
REV = BASE + "/rev"
|
REV = BASE + "/rev"
|
||||||
@@ -110,7 +124,8 @@ class QEMUSystem:
|
|||||||
data = {}
|
data = {}
|
||||||
if os.path.exists(QEMUSystem.VPD):
|
if os.path.exists(QEMUSystem.VPD):
|
||||||
try:
|
try:
|
||||||
data = onieprom.from_tlv(open(QEMUSystem.VPD, "rb", 0))
|
with open(QEMUSystem.VPD, "rb", 0) as f:
|
||||||
|
data = onieprom.from_tlv(f)
|
||||||
except:
|
except:
|
||||||
pass
|
pass
|
||||||
|
|
||||||
@@ -127,31 +142,27 @@ class QEMUSystem:
|
|||||||
def usb_ports(self):
|
def usb_ports(self):
|
||||||
ports = [
|
ports = [
|
||||||
{
|
{
|
||||||
"name": "USB",
|
"name": "USB",
|
||||||
"path": "/sys/bus/usb/devices/usb1/authorized"
|
"path": "/sys/bus/usb/devices/usb1/authorized"
|
||||||
|
}, {
|
||||||
},
|
"name": "USB",
|
||||||
{
|
"path": "/sys/bus/usb/devices/usb1/authorized_default"
|
||||||
"name": "USB",
|
}, {
|
||||||
"path": "/sys/bus/usb/devices/usb1/authorized_default"
|
"name": "USB2",
|
||||||
|
"path": "/sys/bus/usb/devices/usb2/authorized"
|
||||||
},
|
}, {
|
||||||
{
|
"name": "USB2",
|
||||||
"name": "USB2",
|
"path": "/sys/bus/usb/devices/usb2/authorized_default"
|
||||||
"path": "/sys/bus/usb/devices/usb2/authorized"
|
}]
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "USB2",
|
|
||||||
"path": "/sys/bus/usb/devices/usb2/authorized_default"
|
|
||||||
|
|
||||||
}]
|
|
||||||
return ports
|
return ports
|
||||||
|
|
||||||
|
|
||||||
class Device:
|
class Device:
|
||||||
def __init__(self, ph, dtpath, syspath):
|
def __init__(self, ph, dtpath, syspath):
|
||||||
self.ph, self.dtpath, self.syspath = ph, dtpath, syspath
|
self.ph, self.dtpath, self.syspath = ph, dtpath, syspath
|
||||||
|
|
||||||
def available(self):
|
def available(self):
|
||||||
return self.syspath != None
|
return self.syspath is not None
|
||||||
|
|
||||||
def __getitem__(self, attr):
|
def __getitem__(self, attr):
|
||||||
return self.attr(attr).decode("utf-8").strip("\0")
|
return self.attr(attr).decode("utf-8").strip("\0")
|
||||||
@@ -159,7 +170,6 @@ class Device:
|
|||||||
def __setitem__(self, attr, value):
|
def __setitem__(self, attr, value):
|
||||||
return self.attr(attr, val=value.encode("utf-8"))
|
return self.attr(attr, val=value.encode("utf-8"))
|
||||||
|
|
||||||
|
|
||||||
def attrpath(self, attr):
|
def attrpath(self, attr):
|
||||||
return os.path.join(self.syspath, attr)
|
return os.path.join(self.syspath, attr)
|
||||||
|
|
||||||
@@ -168,13 +178,16 @@ class Device:
|
|||||||
|
|
||||||
def attr(self, attr, default=None, val=None):
|
def attr(self, attr, default=None, val=None):
|
||||||
if not self.hasattr(attr):
|
if not self.hasattr(attr):
|
||||||
return default if val == None else False
|
return default if val is None else False
|
||||||
|
|
||||||
if val:
|
if val:
|
||||||
open(self.attrpath(attr), "wb").write(value)
|
with open(self.attrpath(attr), "wb") as f:
|
||||||
|
f.write(val)
|
||||||
return True
|
return True
|
||||||
|
|
||||||
return open(self.attrpath(attr), "rb").read()
|
with open(self.attrpath(attr), "rb") as f:
|
||||||
|
data = f.read()
|
||||||
|
return data
|
||||||
|
|
||||||
def str(self, attr, default=None):
|
def str(self, attr, default=None):
|
||||||
val = self.attr(attr)
|
val = self.attr(attr)
|
||||||
@@ -194,7 +207,9 @@ class Device:
|
|||||||
if not self.hasdtattr(attr):
|
if not self.hasdtattr(attr):
|
||||||
return default
|
return default
|
||||||
|
|
||||||
return open(self.dtattrpath(attr), "rb").read()
|
with open(self.dtattrpath(attr), "rb") as f:
|
||||||
|
data = f.read()
|
||||||
|
return data
|
||||||
|
|
||||||
def dtstr(self, attr, default=None):
|
def dtstr(self, attr, default=None):
|
||||||
val = self.dtattr(attr)
|
val = self.dtattr(attr)
|
||||||
@@ -212,6 +227,7 @@ def vpd_get_json_ve(vpd, pem):
|
|||||||
|
|
||||||
return out
|
return out
|
||||||
|
|
||||||
|
|
||||||
def vpd_get_pwhash(vpd):
|
def vpd_get_pwhash(vpd):
|
||||||
if not vpd.get("trusted"):
|
if not vpd.get("trusted"):
|
||||||
return None
|
return None
|
||||||
@@ -219,8 +235,9 @@ def vpd_get_pwhash(vpd):
|
|||||||
kkit = vpd_get_json_ve(vpd, KKIT_IANA_PEM)
|
kkit = vpd_get_json_ve(vpd, KKIT_IANA_PEM)
|
||||||
return kkit.get("pwhash")
|
return kkit.get("pwhash")
|
||||||
|
|
||||||
|
|
||||||
def vpd_inject(out, vpds):
|
def vpd_inject(out, vpds):
|
||||||
out["vpd"] = { vpd["board"]: vpd for vpd in vpds }
|
out["vpd"] = {vpd["board"]: vpd for vpd in vpds}
|
||||||
|
|
||||||
product = out["vpd"].get("product", {}).get("data", {})
|
product = out["vpd"].get("product", {}).get("data", {})
|
||||||
hoistattrs = ("vendor", "product-name", "part-number", "serial-number", "mac-address")
|
hoistattrs = ("vendor", "product-name", "part-number", "serial-number", "mac-address")
|
||||||
@@ -234,6 +251,7 @@ def vpd_inject(out, vpds):
|
|||||||
out["factory-password-hash"] = pwhash
|
out["factory-password-hash"] = pwhash
|
||||||
break
|
break
|
||||||
|
|
||||||
|
|
||||||
def qemu_base_mac():
|
def qemu_base_mac():
|
||||||
"""Find MAC address of first non-loopback interface, subtract with 1"""
|
"""Find MAC address of first non-loopback interface, subtract with 1"""
|
||||||
base_path = '/sys/class/net'
|
base_path = '/sys/class/net'
|
||||||
@@ -244,7 +262,8 @@ def qemu_base_mac():
|
|||||||
continue
|
continue
|
||||||
try:
|
try:
|
||||||
# pylint: disable=invalid-name
|
# pylint: disable=invalid-name
|
||||||
with open(os.path.join(base_path, iface, 'address'), 'r', encoding='ascii') as f:
|
fn = os.path.join(base_path, iface, 'address')
|
||||||
|
with open(fn, 'r', encoding='ascii') as f:
|
||||||
mac = f.read().strip()
|
mac = f.read().strip()
|
||||||
interfaces.append((mac, iface))
|
interfaces.append((mac, iface))
|
||||||
except FileNotFoundError:
|
except FileNotFoundError:
|
||||||
@@ -261,6 +280,7 @@ def qemu_base_mac():
|
|||||||
|
|
||||||
return None
|
return None
|
||||||
|
|
||||||
|
|
||||||
def probe_qemusystem(out):
|
def probe_qemusystem(out):
|
||||||
"""Probe Qemu based test systems and 'make run'"""
|
"""Probe Qemu based test systems and 'make run'"""
|
||||||
admin_hash = "$5$mI/zpOAqZYKLC2WU$i7iPzZiIjOjrBF3NyftS9CCq8dfYwHwrmUK097Jca9A"
|
admin_hash = "$5$mI/zpOAqZYKLC2WU$i7iPzZiIjOjrBF3NyftS9CCq8dfYwHwrmUK097Jca9A"
|
||||||
@@ -288,6 +308,7 @@ def probe_qemusystem(out):
|
|||||||
subprocess.run("initctl -nbq cond set qemu".split(), check=False)
|
subprocess.run("initctl -nbq cond set qemu".split(), check=False)
|
||||||
return 0
|
return 0
|
||||||
|
|
||||||
|
|
||||||
def probe_dtsystem(out):
|
def probe_dtsystem(out):
|
||||||
"""Probe DTS based system, expects a VPD in ONIE PROM format."""
|
"""Probe DTS based system, expects a VPD in ONIE PROM format."""
|
||||||
dtsys = DTSystem()
|
dtsys = DTSystem()
|
||||||
@@ -297,6 +318,8 @@ def probe_dtsystem(out):
|
|||||||
if model:
|
if model:
|
||||||
out["product-name"] = model
|
out["product-name"] = model
|
||||||
|
|
||||||
|
out["compatible"] = dtsys.base.str_array("compatible")
|
||||||
|
|
||||||
staticpw = dtsys.infix.str("factory-password-hash")
|
staticpw = dtsys.infix.str("factory-password-hash")
|
||||||
if not out["factory-password-hash"]:
|
if not out["factory-password-hash"]:
|
||||||
out["factory-password-hash"] = staticpw
|
out["factory-password-hash"] = staticpw
|
||||||
@@ -304,6 +327,7 @@ def probe_dtsystem(out):
|
|||||||
vpd_inject(out, vpds)
|
vpd_inject(out, vpds)
|
||||||
return 0
|
return 0
|
||||||
|
|
||||||
|
|
||||||
def main():
|
def main():
|
||||||
out = {
|
out = {
|
||||||
"vendor": None,
|
"vendor": None,
|
||||||
@@ -338,5 +362,6 @@ def main():
|
|||||||
shutil.chown(SYSTEM_JSON, user="root", group="wheel")
|
shutil.chown(SYSTEM_JSON, user="root", group="wheel")
|
||||||
return err
|
return err
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
if __name__ == "__main__":
|
||||||
sys.exit(main())
|
sys.exit(main())
|
||||||
|
|||||||
@@ -1,22 +1,50 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# Find and install any product specific files in /etc before bootstrap
|
# Find, install, and run product specific files and script in /etc
|
||||||
|
# before resuming bootstrap.
|
||||||
|
#
|
||||||
|
# Use /etc/product/init.d/S01-myscript for scripts, may be a symlink, it
|
||||||
|
# will be called with `start` as its only argument.
|
||||||
|
#
|
||||||
|
# The compatible array is listed in the same order as the device tree,
|
||||||
|
# most significant to least. Hence the reverse.[], to ensure overrides
|
||||||
|
# are applied in order of significance.
|
||||||
ident=$(basename "$0")
|
ident=$(basename "$0")
|
||||||
|
|
||||||
|
PRODUCT_INIT=/etc/product/init.d
|
||||||
PREFIXD=/usr/share/product
|
PREFIXD=/usr/share/product
|
||||||
PRODUCT=$(jq -r '."product-name" | ascii_downcase' /run/system.json)
|
COMPATIBLES=$(jq -r '.compatible | reverse.[] | ascii_downcase' /run/system.json)
|
||||||
|
|
||||||
note()
|
note()
|
||||||
{
|
{
|
||||||
logger -I $$ -k -p user.notice -t "$ident" "$1"
|
logger -I $$ -k -p user.notice -t "$ident" "$1"
|
||||||
}
|
}
|
||||||
|
|
||||||
DIR="$PREFIXD/$PRODUCT"
|
found=false
|
||||||
if [ -z "$PRODUCT" ] || [ ! -d "$DIR" ]; then
|
for PRODUCT in $COMPATIBLES; do
|
||||||
note "No vendor/product specific directory found, using built-in defaults."
|
DIR="$PREFIXD/$PRODUCT"
|
||||||
exit 0
|
if [ -d "$DIR" ]; then
|
||||||
|
note "Using vendor/product-specific defaults for $PRODUCT."
|
||||||
|
for dir in "$DIR"/*; do
|
||||||
|
[ -d "$dir" ] && cp -a "$dir" /
|
||||||
|
done
|
||||||
|
found=true
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ "$found" = false ]; then
|
||||||
|
note "No vendor/product-specific directory found, using built-in defaults."
|
||||||
fi
|
fi
|
||||||
|
|
||||||
note "Using vendor/product specific defaults."
|
# Conditions for bootstrap services, this enables product specific
|
||||||
for dir in "$DIR"/*; do
|
# init scripts to prevent select services from starting.
|
||||||
[ -d "$dir" ] && cp -a "$dir" /
|
initctl -nbq cond set led
|
||||||
done
|
|
||||||
|
if [ -d "$PRODUCT_INIT" ]; then
|
||||||
|
note "Calling runparts $PRODUCT_INIT/S[0-9]+.* start"
|
||||||
|
/usr/libexec/finit/runparts -bsp "$PRODUCT_INIT"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Product specific init done.
|
||||||
|
initctl -nbq cond set product
|
||||||
|
|
||||||
|
exit 0
|
||||||
|
|||||||
@@ -14,24 +14,6 @@ for file in /sys/firmware/qemu_fw_cfg/by_name/opt/mactab/raw /etc/mactab; do
|
|||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
|
|
||||||
# Sometimes the sysfs is not populated when the switch driver is loaded, with the result
|
|
||||||
# that the DSA interface was not found (no /dsa/tagging entry in sysfs. See issue #685.
|
|
||||||
#
|
|
||||||
# This mitigates that problem by waiting for sysfs to come up if a DSA switch is found
|
|
||||||
if [ -n "$(devlink -j dev info | jq -r '.info.[].driver' | grep -q mv88e6085)" ]; then
|
|
||||||
timeout=50
|
|
||||||
while [ -z "$(ls /sys/class/net/*/dsa/tagging)" ]; do
|
|
||||||
timeout=$((timeout-1))
|
|
||||||
if [ $timeout -eq 0 ]; then
|
|
||||||
logger -k -p user.emerg -t "$ident" "Failed to find DSA interface"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
sleep 0.1
|
|
||||||
done
|
|
||||||
|
|
||||||
logger -k -p user.notice -t "$ident" "Found DSA interface in $timeout seconds"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Find CPU interfaces used for connecting to a switch managed by DSA
|
# Find CPU interfaces used for connecting to a switch managed by DSA
|
||||||
for netif in /sys/class/net/*; do
|
for netif in /sys/class/net/*; do
|
||||||
iface=$(basename "$netif")
|
iface=$(basename "$netif")
|
||||||
|
|||||||
@@ -43,10 +43,15 @@ while [ "$1" ]; do
|
|||||||
txqs="$2"
|
txqs="$2"
|
||||||
shift 2
|
shift 2
|
||||||
|
|
||||||
|
[ $(/usr/libexec/infix/has-quirk "broken-mqprio" "$iface") = "true" ] && echo "Skipping $iface, does not support mqprio" && continue
|
||||||
[ $txqs -lt 2 ] && continue
|
[ $txqs -lt 2 ] && continue
|
||||||
[ $txqs -gt 8 ] && txqs=8
|
[ $txqs -gt 8 ] && txqs=8
|
||||||
|
|
||||||
tc qdisc add dev $iface root mqprio hw 1 \
|
output=$(tc qdisc add dev $iface root mqprio hw 1 \
|
||||||
num_tc $txqs $(map $txqs) $(queues $txqs) || true
|
num_tc $txqs $(map $txqs) $(queues $txqs) 2>&1) || true
|
||||||
|
if echo "$output" | grep -q "does not support hardware offload"; then
|
||||||
|
echo "Skipping $iface, hardware offload not supported."
|
||||||
|
elif [ -n "$output" ]; then
|
||||||
|
echo "$output"
|
||||||
|
fi
|
||||||
done
|
done
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# Initialize speed/duplex of virtio interfaces
|
||||||
|
# For virtual test systems (lacp tests)
|
||||||
|
|
||||||
|
ifaces=$(ip -d -json link show | jq -r '.[] | select(.parentbus == "virtio") | .ifname')
|
||||||
|
for iface in $ifaces; do
|
||||||
|
ethtool -s "$iface" speed 1000 duplex full
|
||||||
|
done
|
||||||
@@ -4,10 +4,14 @@
|
|||||||
# the migrate tool inserts old version in name before .cfg extension.
|
# the migrate tool inserts old version in name before .cfg extension.
|
||||||
CONFIG_FILE="/cfg/startup-config.cfg"
|
CONFIG_FILE="/cfg/startup-config.cfg"
|
||||||
BACKUP_FILE="/cfg/backup/startup-config.cfg"
|
BACKUP_FILE="/cfg/backup/startup-config.cfg"
|
||||||
mkdir -p "$(dirname "$BACKUP_FILE")"
|
BACKUP_DIR="$(dirname "$BACKUP_FILE")"
|
||||||
|
|
||||||
|
mkdir -p "$BACKUP_DIR"
|
||||||
|
chown root:wheel "$BACKUP_DIR"
|
||||||
|
chmod 0770 "$BACKUP_DIR"
|
||||||
|
|
||||||
if [ ! -f "$CONFIG_FILE" ]; then
|
if [ ! -f "$CONFIG_FILE" ]; then
|
||||||
note "No $(basename "$CONFIG_FILE" .cfg) yet, likely factory reset."
|
logger -I $$ -k -p user.notice -t $(basename "$0") "No $(basename "$CONFIG_FILE" .cfg) yet, likely factory reset."
|
||||||
exit 0
|
exit 0
|
||||||
elif migrate -cq "$CONFIG_FILE"; then
|
elif migrate -cq "$CONFIG_FILE"; then
|
||||||
exit 0
|
exit 0
|
||||||
|
|||||||
@@ -1,2 +1,2 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
exec initctl -bq cond set ixinit-done
|
exec initctl -bq cond set ixinit
|
||||||
|
|||||||
+24
@@ -0,0 +1,24 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
# Store and convert RSA PUBLIC/PRIVATE KEYs to be able to use them in
|
||||||
|
# OpenSSHd.
|
||||||
|
set -e
|
||||||
|
|
||||||
|
NAME="$1"
|
||||||
|
DIR="$2"
|
||||||
|
PUBLIC="$3"
|
||||||
|
PRIVATE="$4"
|
||||||
|
TMP="$(mktemp)"
|
||||||
|
|
||||||
|
echo -e '-----BEGIN RSA PRIVATE KEY-----' > "$DIR/$NAME"
|
||||||
|
echo "$PRIVATE" >> "$DIR/$NAME"
|
||||||
|
echo -e '-----END RSA PRIVATE KEY-----' >> "$DIR/$NAME"
|
||||||
|
|
||||||
|
echo -e "-----BEGIN RSA PUBLIC KEY-----" > "$TMP"
|
||||||
|
echo -e "$PUBLIC" >> "$TMP"
|
||||||
|
echo -e "-----END RSA PUBLIC KEY-----" >> "$TMP"
|
||||||
|
|
||||||
|
ssh-keygen -i -m PKCS8 -f "$TMP" > "$DIR/$NAME.pub"
|
||||||
|
chmod 0600 "$DIR/$NAME.pub"
|
||||||
|
chmod 0600 "$DIR/$NAME"
|
||||||
|
chown sshd:sshd "$DIR/$NAME.pub"
|
||||||
|
chown sshd:sshd "$DIR/$NAME"
|
||||||
@@ -45,11 +45,6 @@ factory_reset()
|
|||||||
find /sys/class/leds/ -type l -exec sh -c 'echo 100 > $0/brightness' {} \;
|
find /sys/class/leds/ -type l -exec sh -c 'echo 100 > $0/brightness' {} \;
|
||||||
logger $opt -p user.crit -t "$nm" "Resetting to factory defaults."
|
logger $opt -p user.crit -t "$nm" "Resetting to factory defaults."
|
||||||
|
|
||||||
# Shred all files to prevent restoring contents
|
|
||||||
find /mnt/cfg -type f -exec shred -zu {} \;
|
|
||||||
find /mnt/var -type f -exec shred -zu {} \;
|
|
||||||
|
|
||||||
# Remove any lingering directories and symlinks as well
|
|
||||||
rm -rf /mnt/cfg/* /mnt/var/*
|
rm -rf /mnt/cfg/* /mnt/var/*
|
||||||
|
|
||||||
logger $opt -p user.crit -t "$nm" "Factory reset complete."
|
logger $opt -p user.crit -t "$nm" "Factory reset complete."
|
||||||
|
|||||||
+16
@@ -0,0 +1,16 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
|
||||||
|
if [ $# -ne 1 ]; then
|
||||||
|
echo "usage: $0 <ifname>"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
ifname=$1
|
||||||
|
|
||||||
|
TIMEOUT=300
|
||||||
|
status=$(wpa_cli -i $ifname scan)
|
||||||
|
while [ "$status" != "OK" ]; do
|
||||||
|
status=$(wpa_cli -i $ifname scan)
|
||||||
|
TIMEOUT=$((TIMEOUT-1))
|
||||||
|
[ $TIMEOUT -eq 0 ] && logger -t wifi-scanner "Failed to start scanning $ifname" && exit 1
|
||||||
|
sleep 0.5
|
||||||
|
done
|
||||||
@@ -1,5 +1,19 @@
|
|||||||
#!/bin/sh
|
#!/bin/bash
|
||||||
|
# This script can be used to start, stop, create, and delete containers.
|
||||||
|
# It is what confd use, with the Finit container@.conf template, to set
|
||||||
|
# up, run, and delete containers.
|
||||||
|
#
|
||||||
|
# NOTE: when creating/deleting containers, remember 'initctl reload' to
|
||||||
|
# activate the changes! In confd this is already handled.
|
||||||
|
#
|
||||||
|
DOWNLOADS=/var/lib/containers/oci
|
||||||
|
BUILTIN=/lib/oci
|
||||||
|
TMPDIR=/var/tmp
|
||||||
|
container=$0
|
||||||
|
checksum=""
|
||||||
|
extracted=
|
||||||
|
timeout=30
|
||||||
|
dir=""
|
||||||
all=""
|
all=""
|
||||||
env=""
|
env=""
|
||||||
port=""
|
port=""
|
||||||
@@ -10,80 +24,192 @@ log()
|
|||||||
logger -I $PPID -t container -p local1.notice -- "$*"
|
logger -I $PPID -t container -p local1.notice -- "$*"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
err()
|
||||||
|
{
|
||||||
|
rc=$1; shift
|
||||||
|
logger -I $PPID -t container -p local1.err -- "Error: $*"
|
||||||
|
|
||||||
|
if [ -n "$extracted" ]; then
|
||||||
|
if [ -d "$TMPDIR/$dir" ]; then
|
||||||
|
log "Cleaning up extracted $dir"
|
||||||
|
rm -rf "$dir"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
[ "$rc" -eq 0 ] || exit "$rc"
|
||||||
|
}
|
||||||
|
|
||||||
|
pidfn()
|
||||||
|
{
|
||||||
|
echo "/run/containers/${1}.pid"
|
||||||
|
}
|
||||||
|
|
||||||
|
check()
|
||||||
|
{
|
||||||
|
file=$1
|
||||||
|
|
||||||
|
if [ -z "$checksum" ]; then
|
||||||
|
log "no checksum to verify $file against, continuing."
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
if echo "${checksum} ${file}" | "$cmdsum" -c -s; then
|
||||||
|
log "$file checksum verified OK."
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
got=$("$cmdsum" "${file}" | awk '{print $1}')
|
||||||
|
log "$file checksum mismatch, got $got, expected $checksum, removing file."
|
||||||
|
rm -f "$file"
|
||||||
|
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# Fetch an OCI image over ftp/http/https. Use wget for FTP, which curl
|
||||||
|
# empirically does not work well with. Log progress+ & error to syslog.
|
||||||
|
fetch()
|
||||||
|
{
|
||||||
|
url=$1
|
||||||
|
file=$(basename "$url")
|
||||||
|
dst="$DOWNLOADS/$file"
|
||||||
|
|
||||||
|
cd "$DOWNLOADS" || return
|
||||||
|
if [ -e "$file" ]; then
|
||||||
|
log "$file already available."
|
||||||
|
if check "$file"; then
|
||||||
|
echo "$dst"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
log "Fetching $url"
|
||||||
|
|
||||||
|
if echo "$url" | grep -qE "^ftp://"; then
|
||||||
|
cmd="wget -q $url"
|
||||||
|
elif echo "$url" | grep -qE "^https?://"; then
|
||||||
|
cmd="curl $creds -sSL --fail -o \"$file\" $url"
|
||||||
|
else
|
||||||
|
log "Unsupported URL scheme: $url"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if out=$(eval "$cmd" 2>&1); then
|
||||||
|
log "$file downloaded successfully."
|
||||||
|
if check "$file"; then
|
||||||
|
echo "$dst"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
# log error message from backend
|
||||||
|
while IFS= read -r line; do
|
||||||
|
log "$line"
|
||||||
|
done <<EOF
|
||||||
|
$out
|
||||||
|
EOF
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
# Unpacks a given oci-archive.tar[.gz] in the current directory. Sanity
|
# Unpacks a given oci-archive.tar[.gz] in the current directory. Sanity
|
||||||
# checks, at least one index.json in the top-level dir of the archive.
|
# checks, at least one index.json in the top-level dir of the archive.
|
||||||
# If there are more index files, this function does not handle them.
|
# If there are more index files, this function does not handle them.
|
||||||
unpack_archive()
|
unpack_archive()
|
||||||
{
|
{
|
||||||
image=$1
|
uri=$1
|
||||||
name=$2
|
tag=$2
|
||||||
|
img=$(basename "$uri")
|
||||||
|
|
||||||
# Supported transports for load and create
|
# Supported transports for load and create
|
||||||
case "$image" in
|
case "$uri" in
|
||||||
oci:*) # Unpacked OCI image
|
oci:*) # Unpacked OCI image
|
||||||
file=${image#oci:}
|
file=${uri#oci:}
|
||||||
;;
|
;;
|
||||||
oci-archive:*) # Packed OCI image, .tar or .tar.gz format
|
oci-archive:*) # Packed OCI image, .tar or .tar.gz format
|
||||||
file=${image#oci-archive:}
|
file=${uri#oci-archive:}
|
||||||
;;
|
;;
|
||||||
|
ftp://* | http://* | https://*)
|
||||||
|
if ! file=$(fetch "$uri"); then
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
;;
|
||||||
*) # docker://*, docker-archive:*, or URL
|
*) # docker://*, docker-archive:*, or URL
|
||||||
echo "$image"
|
if podman image exists "$img"; then
|
||||||
|
echo "$img"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
# XXX: use --retry=0 with Podman 5.0 or later.
|
||||||
|
if ! id=$(podman pull --quiet "$uri"); then
|
||||||
|
log "Failed pulling $uri"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
# Echo image tag to caller
|
||||||
|
podman images --filter id="$id" --format "{{.Repository}}:{{.Tag}}"
|
||||||
return 0
|
return 0
|
||||||
;;
|
;;
|
||||||
esac
|
esac
|
||||||
|
|
||||||
if [ ! -e "$file" ]; then
|
if [ ! -e "$file" ]; then
|
||||||
if [ -e "/var/lib/containers/oci/$file" ]; then
|
if [ -e "$DOWNLOADS/$file" ]; then
|
||||||
file="/var/lib/containers/oci/$file"
|
file="$DOWNLOADS/$file"
|
||||||
elif [ -e "/lib/oci/$file" ]; then
|
elif [ -e "$BUILTIN/$file" ]; then
|
||||||
file="/lib/oci/$file"
|
file="$BUILTIN/$file"
|
||||||
else
|
else
|
||||||
log "Error: cannot find OCI archive $file in search path."
|
err 1 "cannot find OCI archive $file in URI $uri"
|
||||||
exit 1
|
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [ -d "$file" ]; then
|
if [ -d "$file" ]; then
|
||||||
index=$(find "$file" -name index.json)
|
index=$(find "$file" -name index.json)
|
||||||
if [ -z "$index" ]; then
|
if [ -z "$index" ]; then
|
||||||
log "Error: cannot find index.json in OCI image $file"
|
err 1 "cannot find index.json in OCI image $file"
|
||||||
exit 1
|
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
|
cd "$TMPDIR" || err 0 "failed cd $TMPDIR, wiill use $(pwd) for OCI archive extraction."
|
||||||
|
|
||||||
index=$(tar tf "$file" |grep index.json)
|
index=$(tar tf "$file" |grep index.json)
|
||||||
if [ -z "$index" ]; then
|
if [ -z "$index" ]; then
|
||||||
log "Error: invalid OCI archive, cannot find index.json in $file"
|
err 1 "invalid OCI archive, cannot find index.json in $file"
|
||||||
exit 1
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
[ -n "$quiet" ] || log "Extracting OCI archive $file ..."
|
[ -n "$quiet" ] || log "Extracting OCI archive $file ..."
|
||||||
tar xf "$file" || (log "Error: failed unpacking $file in $(pwd)"; exit 1)
|
tar xf "$file" || err 1 "failed unpacking $file in $(pwd)"
|
||||||
remove=true
|
extracted=true
|
||||||
fi
|
fi
|
||||||
|
|
||||||
dir=$(dirname "$index")
|
dir=$(dirname "$index")
|
||||||
|
if echo "$dir" | grep -q ":"; then
|
||||||
|
if [ -z "$tag" ]; then
|
||||||
|
tag="$dir"
|
||||||
|
fi
|
||||||
|
sanitized_dir=$(echo "$dir" | cut -d':' -f1)
|
||||||
|
mv "$dir" "$sanitized_dir" || err 1 "failed renaming $dir to $sanitized_dir"
|
||||||
|
dir="$sanitized_dir"
|
||||||
|
fi
|
||||||
|
|
||||||
[ -n "$quiet" ] || log "Loading OCI image $dir ..."
|
[ -n "$quiet" ] || log "Loading OCI image $dir ..."
|
||||||
podman load -qi "$dir" >/dev/null
|
podman load -qi "$dir" >/dev/null
|
||||||
|
|
||||||
# Rename image from podman default $dir:latest
|
# Clean up after ourselves
|
||||||
if [ -n "$name" ]; then
|
if [ -n "$extracted" ]; then
|
||||||
podman tag "$dir" "$name" >/dev/null
|
log "Cleaning up extracted $dir"
|
||||||
podman rmi "$dir" >/dev/null
|
rm -rf "$dir"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Retag image from podman default $dir:latest
|
||||||
|
if [ -n "$tag" ]; then
|
||||||
|
podman tag "$dir" "$tag" >/dev/null
|
||||||
|
podman rmi "$dir" >/dev/null
|
||||||
else
|
else
|
||||||
name=$dir
|
tag=$dir
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [ "$remove" = "true" ]; then
|
echo "$tag"
|
||||||
rm -rf "$file"
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "$name"
|
|
||||||
}
|
}
|
||||||
|
|
||||||
running()
|
running()
|
||||||
{
|
{
|
||||||
run=$(podman inspect "$1" 2>/dev/null |jq .[].State.Running)
|
status=$(podman inspect -f '{{.State.Status}}' "$1" 2>/dev/null)
|
||||||
[ "$run" = "true" ] && return 0
|
[ "$status" = "running" ] && return 0
|
||||||
return 1
|
return 1
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -102,16 +228,19 @@ create()
|
|||||||
|
|
||||||
# Unpack and load docker-archive/oci/oci-archive, returning image
|
# Unpack and load docker-archive/oci/oci-archive, returning image
|
||||||
# name, or return docker:// URL for download.
|
# name, or return docker:// URL for download.
|
||||||
image=$(unpack_archive "$image")
|
if ! image=$(unpack_archive "$image"); then
|
||||||
|
exit 1
|
||||||
if [ -z "$logging" ]; then
|
|
||||||
logging="--log-driver k8s-file --log-opt path=/run/containers/$name.fifo"
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
args="$args --replace --quiet --cgroup-parent=containers $caps"
|
if [ -z "$logging" ]; then
|
||||||
|
logging="--log-driver syslog"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# When we get here we've already fetched, or pulled, the image
|
||||||
|
args="$args --read-only --replace --quiet --cgroup-parent=containers $caps"
|
||||||
args="$args --restart=$restart --systemd=false --tz=local $privileged"
|
args="$args --restart=$restart --systemd=false --tz=local $privileged"
|
||||||
args="$args $ro $vol $mount $hostname $entrypoint $env $port $logging"
|
args="$args $vol $mount $hostname $entrypoint $env $port $logging"
|
||||||
pidfn=/run/container:${name}.pid
|
pidfile=/run/container:${name}.pid
|
||||||
|
|
||||||
[ -n "$quiet" ] || log "---------------------------------------"
|
[ -n "$quiet" ] || log "---------------------------------------"
|
||||||
[ -n "$quiet" ] || log "Got name: $name image: $image"
|
[ -n "$quiet" ] || log "Got name: $name image: $image"
|
||||||
@@ -134,22 +263,22 @@ create()
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
# shellcheck disable=SC2048
|
# shellcheck disable=SC2048
|
||||||
log "Calling podman create --name $name --conmon-pidfile=$pidfn $args $image $*"
|
log "podman create --name $name --conmon-pidfile=$pidfile $args $image $*"
|
||||||
if podman create --name "$name" --conmon-pidfile="$pidfn" $args "$image" $*; then
|
if podman create --name "$name" --conmon-pidfile="$pidfile" $args "$image" $*; then
|
||||||
[ -n "$quiet" ] || log "Successfully created container $name from $image"
|
[ -n "$quiet" ] || log "Successfully created container $name from $image"
|
||||||
rm -f "/run/containers/env/${name}.env"
|
|
||||||
[ -n "$manual" ] || start "$name"
|
[ -n "$manual" ] || start "$name"
|
||||||
|
|
||||||
|
# Should already be enabled by confd (this is for manual use)
|
||||||
|
initctl -bnq enable "container@${name}.conf"
|
||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
|
|
||||||
log "Error: failed creating container $name, please check the configuration."
|
err 1 "failed creating container $name, please check the configuration."
|
||||||
exit 1
|
|
||||||
}
|
}
|
||||||
|
|
||||||
delete()
|
delete()
|
||||||
{
|
{
|
||||||
name=$1
|
name=$1
|
||||||
image=$2
|
|
||||||
|
|
||||||
if [ -z "$name" ]; then
|
if [ -z "$name" ]; then
|
||||||
echo "Usage:"
|
echo "Usage:"
|
||||||
@@ -157,18 +286,30 @@ delete()
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# Should already be stopped, but if not ...
|
||||||
|
log "$name: should already be stopped, double checking ..."
|
||||||
|
container stop "$name" >/dev/null
|
||||||
|
|
||||||
|
while running "$name"; do
|
||||||
|
log "$name: still running, waiting for it to stop ..."
|
||||||
|
_=$((timeout -= 1))
|
||||||
|
if [ $timeout -le 0 ]; then
|
||||||
|
err 1 "timed out waiting for container $1 to stop before deleting it."
|
||||||
|
fi
|
||||||
|
sleep 1
|
||||||
|
done
|
||||||
|
|
||||||
|
log "$name: calling podman rm -vif ..."
|
||||||
podman rm -vif "$name" >/dev/null 2>&1
|
podman rm -vif "$name" >/dev/null 2>&1
|
||||||
[ -n "$quiet" ] || log "Container $name has been removed."
|
[ -n "$quiet" ] || log "Container $name has been removed."
|
||||||
}
|
}
|
||||||
|
|
||||||
waitfor()
|
waitfor()
|
||||||
{
|
{
|
||||||
timeout=$2
|
|
||||||
while [ ! -f "$1" ]; do
|
while [ ! -f "$1" ]; do
|
||||||
_=$((timeout -= 1))
|
_=$((timeout -= 1))
|
||||||
if [ $timeout -le 0 ]; then
|
if [ $timeout -le 0 ]; then
|
||||||
log "Timeout waiting for $1, aborting!"
|
err 1 "timed out waiting for $1, aborting!"
|
||||||
exit 1
|
|
||||||
fi
|
fi
|
||||||
sleep 1;
|
sleep 1;
|
||||||
done
|
done
|
||||||
@@ -183,7 +324,7 @@ start()
|
|||||||
return
|
return
|
||||||
fi
|
fi
|
||||||
|
|
||||||
initctl -bq cond set "container:$name"
|
initctl start container:$name
|
||||||
# Real work is done by wrap() courtesy of finit sysv emulation
|
# Real work is done by wrap() courtesy of finit sysv emulation
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -196,7 +337,7 @@ stop()
|
|||||||
return
|
return
|
||||||
fi
|
fi
|
||||||
|
|
||||||
initctl -bq cond clr "container:$name"
|
initctl stop container:$name
|
||||||
# Real work is done by wrap() courtesy of finit sysv emulation
|
# Real work is done by wrap() courtesy of finit sysv emulation
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -204,8 +345,27 @@ wrap()
|
|||||||
{
|
{
|
||||||
name=$1
|
name=$1
|
||||||
cmd=$2
|
cmd=$2
|
||||||
|
pidfile=$(pidfn "$name")
|
||||||
|
|
||||||
podman "$cmd" "$name"
|
# Containers have three phases: setup, running, and teardown.
|
||||||
|
|
||||||
|
# The setup phase may run forever in the background trying to fetch
|
||||||
|
# the image. It saves its PID in /run/containers/${name}.pid
|
||||||
|
if [ "$cmd" = "stop" ] && [ -f "$pidfile" ]; then
|
||||||
|
pid=$(cat "$pidfile")
|
||||||
|
|
||||||
|
# Check if setup is still running ...
|
||||||
|
if kill -0 "$pid" 2>/dev/null; then
|
||||||
|
kill "$pid"
|
||||||
|
wait "$pid" 2>/dev/null
|
||||||
|
fi
|
||||||
|
|
||||||
|
rm -f "$pidfile"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Skip "echo $name" from podman start in log
|
||||||
|
podman "$cmd" "$name" >/dev/null
|
||||||
}
|
}
|
||||||
|
|
||||||
# Removes network $1 from all containers
|
# Removes network $1 from all containers
|
||||||
@@ -236,6 +396,19 @@ netrestart()
|
|||||||
done
|
done
|
||||||
}
|
}
|
||||||
|
|
||||||
|
cleanup()
|
||||||
|
{
|
||||||
|
pidfile=$(pidfn "$name")
|
||||||
|
|
||||||
|
log "Received signal, exiting."
|
||||||
|
if [ -n "$name" ] && [ -f "$pidfile" ]; then
|
||||||
|
log "$name: in setup phase, removing $pidfile ..."
|
||||||
|
rm -f "$pidfile"
|
||||||
|
fi
|
||||||
|
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
|
||||||
usage()
|
usage()
|
||||||
{
|
{
|
||||||
cat <<EOF
|
cat <<EOF
|
||||||
@@ -248,6 +421,7 @@ options:
|
|||||||
--dns-search LIST Set host lookup search list when creating container
|
--dns-search LIST Set host lookup search list when creating container
|
||||||
--cap-add CAP Add capability to unprivileged container
|
--cap-add CAP Add capability to unprivileged container
|
||||||
--cap-drop CAP Drop capability, for privileged containter
|
--cap-drop CAP Drop capability, for privileged containter
|
||||||
|
--checksum TYPE:SUM Use md5/sha256/sha512 to verify ftp/http/https archives
|
||||||
-c, --creds USR[:PWD] Credentials to pass to curl -u for remote ops
|
-c, --creds USR[:PWD] Credentials to pass to curl -u for remote ops
|
||||||
-d, --detach Detach a container started with 'run IMG [CMD]'
|
-d, --detach Detach a container started with 'run IMG [CMD]'
|
||||||
-e, --env FILE Environment variables when creating container
|
-e, --env FILE Environment variables when creating container
|
||||||
@@ -267,14 +441,15 @@ options:
|
|||||||
Syntax: [[ip:][hostPort]:]containerPort[/protocol]
|
Syntax: [[ip:][hostPort]:]containerPort[/protocol]
|
||||||
-q, --quiet Quiet operation, called from confd
|
-q, --quiet Quiet operation, called from confd
|
||||||
-r, --restart POLICY One of "no", "always", or "on-failure:NUM"
|
-r, --restart POLICY One of "no", "always", or "on-failure:NUM"
|
||||||
--read-only Do not create a writable layer
|
|
||||||
-s, --simple Show output in simplified format
|
-s, --simple Show output in simplified format
|
||||||
|
-t, --timeout SEC Set timeout for delete/restart commands, default: 20
|
||||||
-v, --volume NAME:PATH Create named volume mounted inside container on PATH
|
-v, --volume NAME:PATH Create named volume mounted inside container on PATH
|
||||||
|
|
||||||
commands:
|
commands:
|
||||||
create NAME IMAGE NET Create container NAME using IMAGE with networks NET
|
create NAME IMAGE NET Create container NAME using IMAGE with networks NET
|
||||||
delete [network] NAME Remove container NAME or network NAME from all containers
|
delete [network] NAME Remove container NAME or network NAME from all containers
|
||||||
exec NAME CMD Run a command inside a container
|
exec NAME CMD Run a command inside a container
|
||||||
|
flush Clean up lingering containers and associated anonymous volumes
|
||||||
find [ifname PID] Find PID of container where '--net IFNAME' currently lives
|
find [ifname PID] Find PID of container where '--net IFNAME' currently lives
|
||||||
or, find the name of our IFNAME inside the container @PID
|
or, find the name of our IFNAME inside the container @PID
|
||||||
help Show this help text
|
help Show this help text
|
||||||
@@ -285,11 +460,13 @@ commands:
|
|||||||
restart [network] NAME Restart a (crashed) container or container(s) using network
|
restart [network] NAME Restart a (crashed) container or container(s) using network
|
||||||
run NAME [CMD] Run a container interactively, with an optional command
|
run NAME [CMD] Run a container interactively, with an optional command
|
||||||
save IMAGE FILE Save a container image to an OCI tarball FILE[.tar.gz]
|
save IMAGE FILE Save a container image to an OCI tarball FILE[.tar.gz]
|
||||||
shell Start a shell inside a container
|
setup NAME Create and set up container as a Finit task
|
||||||
|
shell [CMD] Start a shell, or run CMD, inside a container
|
||||||
show [image | volume] Show containers, images, or volumes
|
show [image | volume] Show containers, images, or volumes
|
||||||
stat Show continuous stats about containers (Ctrl-C aborts)
|
stat Show continuous stats about containers (Ctrl-C aborts)
|
||||||
start [NAME] Start a container, see -n
|
start [NAME] Start a container, see -n
|
||||||
stop [NAME] Stop a container, see -n
|
stop [NAME] Stop a container, see -n
|
||||||
|
upgrade NAME Upgrade a running container (stop, pull, restart)
|
||||||
volume [prune] Prune unused volumes
|
volume [prune] Prune unused volumes
|
||||||
EOF
|
EOF
|
||||||
}
|
}
|
||||||
@@ -307,6 +484,25 @@ while [ "$1" != "" ]; do
|
|||||||
shift
|
shift
|
||||||
caps="$caps --cap-drop=$1"
|
caps="$caps --cap-drop=$1"
|
||||||
;;
|
;;
|
||||||
|
--checksum)
|
||||||
|
shift
|
||||||
|
type="${1%%:*}"
|
||||||
|
checksum="${1#*:}"
|
||||||
|
case "$type" in
|
||||||
|
md5)
|
||||||
|
cmdsum=md5sum
|
||||||
|
;;
|
||||||
|
sha256)
|
||||||
|
cmdsum=sha256sum
|
||||||
|
;;
|
||||||
|
sha512)
|
||||||
|
cmdsum=sha512sum
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
err 1 "Unsupported checksum type: $type"
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
;;
|
||||||
-c | --creds)
|
-c | --creds)
|
||||||
shift
|
shift
|
||||||
creds="-u $1"
|
creds="-u $1"
|
||||||
@@ -351,11 +547,10 @@ while [ "$1" != "" ]; do
|
|||||||
--log-path)
|
--log-path)
|
||||||
shift
|
shift
|
||||||
logging="$logging --log-opt path=$1"
|
logging="$logging --log-opt path=$1"
|
||||||
log_path="$1"
|
|
||||||
;;
|
;;
|
||||||
-m | --mount)
|
-m | --mount)
|
||||||
shift
|
shift
|
||||||
mount="--mount=$1"
|
mount="$mount --mount=$1"
|
||||||
;;
|
;;
|
||||||
--manual)
|
--manual)
|
||||||
manual=true
|
manual=true
|
||||||
@@ -386,12 +581,13 @@ while [ "$1" != "" ]; do
|
|||||||
shift
|
shift
|
||||||
restart=$1
|
restart=$1
|
||||||
;;
|
;;
|
||||||
--read-only)
|
|
||||||
ro="--read-only=true"
|
|
||||||
;;
|
|
||||||
-s | --simple)
|
-s | --simple)
|
||||||
simple=true
|
simple=true
|
||||||
;;
|
;;
|
||||||
|
-t | --timeout)
|
||||||
|
shift
|
||||||
|
timeout=$1
|
||||||
|
;;
|
||||||
-v | --volume)
|
-v | --volume)
|
||||||
shift
|
shift
|
||||||
vol="$vol -v $1"
|
vol="$vol -v $1"
|
||||||
@@ -408,6 +604,8 @@ if [ -n "$cmd" ]; then
|
|||||||
shift
|
shift
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
trap cleanup INT HUP TERM
|
||||||
|
|
||||||
case $cmd in
|
case $cmd in
|
||||||
# Does not work atm., cannot attach to TTY because
|
# Does not work atm., cannot attach to TTY because
|
||||||
# we monitor 'podman start -ai foo' with Finit.
|
# we monitor 'podman start -ai foo' with Finit.
|
||||||
@@ -420,15 +618,24 @@ case $cmd in
|
|||||||
;;
|
;;
|
||||||
delete)
|
delete)
|
||||||
cmd=$1
|
cmd=$1
|
||||||
name=$2
|
[ -n "$name" ] || name=$2
|
||||||
if [ "$cmd" = "network" ] && [ -n "$name" ]; then
|
if [ "$cmd" = "network" ] && [ -n "$name" ]; then
|
||||||
netwrm "$name"
|
netwrm "$name"
|
||||||
else
|
else
|
||||||
delete "$@"
|
[ -n "$name" ] || name=$1
|
||||||
|
delete "$name"
|
||||||
fi
|
fi
|
||||||
;;
|
;;
|
||||||
exec)
|
exec)
|
||||||
podman exec -it "$@"
|
if [ -z "$name" ]; then
|
||||||
|
name="$1"
|
||||||
|
shift
|
||||||
|
fi
|
||||||
|
podman exec -i "$name" "$@"
|
||||||
|
;;
|
||||||
|
flush)
|
||||||
|
echo "Cleaning up any lingering containers";
|
||||||
|
podman rm -av $force
|
||||||
;;
|
;;
|
||||||
find)
|
find)
|
||||||
cmd=$1
|
cmd=$1
|
||||||
@@ -455,25 +662,12 @@ case $cmd in
|
|||||||
usage
|
usage
|
||||||
;;
|
;;
|
||||||
load)
|
load)
|
||||||
url=$1
|
|
||||||
name=$2
|
|
||||||
# shellcheck disable=SC2086
|
# shellcheck disable=SC2086
|
||||||
if echo "$url" | grep -q "://"; then
|
name=$(unpack_archive "$1" $2)
|
||||||
file=$(basename "$url")
|
[ -n "$name" ] || exit 1
|
||||||
curl -k $creds -Lo "$file" "$url"
|
|
||||||
else
|
|
||||||
file="$url"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# shellcheck disable=SC2086
|
|
||||||
name=$(unpack_archive "$file" $name)
|
|
||||||
|
|
||||||
# Show resulting image(s) matching $name
|
# Show resulting image(s) matching $name
|
||||||
if [ -n "$name" ]; then
|
podman images -n "$name"
|
||||||
podman images -n "$name"
|
|
||||||
else
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
;;
|
;;
|
||||||
locate) # Find where the host's ifname lives
|
locate) # Find where the host's ifname lives
|
||||||
if [ -z "$network" ]; then
|
if [ -z "$network" ]; then
|
||||||
@@ -500,9 +694,9 @@ case $cmd in
|
|||||||
podman images $all --format "{{.Repository}}:{{.Tag}}"
|
podman images $all --format "{{.Repository}}:{{.Tag}}"
|
||||||
;;
|
;;
|
||||||
oci)
|
oci)
|
||||||
find /lib/oci /var/lib/containers/oci -type f 2>/dev/null
|
find $BUILTIN $DOWNLOADS -type f 2>/dev/null
|
||||||
;;
|
;;
|
||||||
*)
|
*)
|
||||||
podman ps $all --format "{{.Names}}"
|
podman ps $all --format "{{.Names}}"
|
||||||
;;
|
;;
|
||||||
esac
|
esac
|
||||||
@@ -542,8 +736,38 @@ case $cmd in
|
|||||||
gzip "$file"
|
gzip "$file"
|
||||||
fi
|
fi
|
||||||
;;
|
;;
|
||||||
|
setup)
|
||||||
|
[ -n "$name" ] || err 1 "setup: missing container name."
|
||||||
|
script=/run/containers/${name}.sh
|
||||||
|
[ -x "$script" ] || err 1 "setup: $script does not exist or is not executable."
|
||||||
|
|
||||||
|
# Save our PID in case we get stuck here and someone wants to
|
||||||
|
# stop us, e.g., due to reconfiguration or reboot.
|
||||||
|
pidfile=$(pidfn "${name}")
|
||||||
|
echo $$ > "$pidfile"
|
||||||
|
|
||||||
|
while ! "$script"; do
|
||||||
|
log "${name}: setup failed, waiting for network changes ..."
|
||||||
|
read -t 60 _ < <(ip monitor address route)
|
||||||
|
|
||||||
|
# On IP address/route changes, wait a few seconds more to ensure
|
||||||
|
# the system has ample time to react and set things up for us.
|
||||||
|
log "${name}: retrying ..."
|
||||||
|
sleep 2
|
||||||
|
done
|
||||||
|
|
||||||
|
rm -f "$pidfile"
|
||||||
|
;;
|
||||||
shell)
|
shell)
|
||||||
podman exec -it "$1" sh -l
|
if [ -z "$name" ]; then
|
||||||
|
name="$1"
|
||||||
|
shift
|
||||||
|
fi
|
||||||
|
if [ $# -gt 0 ]; then
|
||||||
|
podman exec -i "$name" sh -c "$*"
|
||||||
|
else
|
||||||
|
podman exec -it "$name" sh -l
|
||||||
|
fi
|
||||||
;;
|
;;
|
||||||
show)
|
show)
|
||||||
cmd=$1
|
cmd=$1
|
||||||
@@ -596,12 +820,10 @@ case $cmd in
|
|||||||
else
|
else
|
||||||
name=$1
|
name=$1
|
||||||
stop "$name"
|
stop "$name"
|
||||||
timeout=20
|
|
||||||
while running "$name"; do
|
while running "$name"; do
|
||||||
_=$((timeout -= 1))
|
_=$((timeout -= 1))
|
||||||
if [ $timeout -le 0 ]; then
|
if [ $timeout -le 0 ]; then
|
||||||
log "Timeout waiting for container $1 to stop before restarting it."
|
err 1 "timed out waiting for container $1 to stop before restarting it."
|
||||||
exit 1
|
|
||||||
fi
|
fi
|
||||||
sleep 1
|
sleep 1
|
||||||
done
|
done
|
||||||
@@ -627,7 +849,7 @@ case $cmd in
|
|||||||
;;
|
;;
|
||||||
upgrade)
|
upgrade)
|
||||||
# Start script used to initially create container
|
# Start script used to initially create container
|
||||||
script=/var/lib/containers/active/S01-${1}.sh
|
script=/run/containers/${1}.sh
|
||||||
|
|
||||||
# Find container image
|
# Find container image
|
||||||
img=$(podman inspect "$1" | jq -r .[].ImageName)
|
img=$(podman inspect "$1" | jq -r .[].ImageName)
|
||||||
@@ -638,15 +860,15 @@ case $cmd in
|
|||||||
|
|
||||||
# Likely an OCI archive, or local directory, assume user has updated image.
|
# Likely an OCI archive, or local directory, assume user has updated image.
|
||||||
if echo "$img" | grep -Eq '^localhost/'; then
|
if echo "$img" | grep -Eq '^localhost/'; then
|
||||||
file=$(awk '{s=$NF} END{print s}' "$script")
|
file=$(awk '/^# meta-image:/ {print $3}' "$script")
|
||||||
echo "Upgrading container ${1} with local archive: $file ..."
|
echo ">> Upgrading container $1 using $file ..."
|
||||||
else
|
else
|
||||||
printf ">> Stopping ... "
|
printf ">> Stopping ... "
|
||||||
podman stop "$1"
|
podman stop "$1"
|
||||||
printf ">> "
|
printf ">> "
|
||||||
podman pull "$img" || (echo "Failed fetching $img, check your network (settings)."; exit 1)
|
podman pull "$img" || (echo "Failed fetching $img, check your network (settings)."; exit 1)
|
||||||
|
echo ">> Starting $1 ..."
|
||||||
fi
|
fi
|
||||||
echo ">> Starting $1 ..."
|
|
||||||
if ! "$script"; then
|
if ! "$script"; then
|
||||||
echo ">> Failed recreating container $1"
|
echo ">> Failed recreating container $1"
|
||||||
exit 1
|
exit 1
|
||||||
@@ -658,7 +880,7 @@ case $cmd in
|
|||||||
[ -n "$cmd" ] && shift
|
[ -n "$cmd" ] && shift
|
||||||
case $cmd in
|
case $cmd in
|
||||||
prune)
|
prune)
|
||||||
podman volume $force prune
|
podman volume prune $force
|
||||||
;;
|
;;
|
||||||
*)
|
*)
|
||||||
false
|
false
|
||||||
@@ -666,6 +888,22 @@ case $cmd in
|
|||||||
esac
|
esac
|
||||||
;;
|
;;
|
||||||
*)
|
*)
|
||||||
|
if [ -n "$SERVICE_SCRIPT_TYPE" ] && [ -n "$SERVICE_ID" ]; then
|
||||||
|
case "$SERVICE_SCRIPT_TYPE" in
|
||||||
|
pre)
|
||||||
|
# Called as pre-script from Finit service
|
||||||
|
exec $container -q -n "$SERVICE_ID" setup
|
||||||
|
;;
|
||||||
|
cleanup)
|
||||||
|
# Called as cleanup-script from Finit service
|
||||||
|
log "Calling $container -n $SERVICE_ID delete"
|
||||||
|
exec $container -q -n "$SERVICE_ID" delete
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
false
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
fi
|
||||||
usage
|
usage
|
||||||
exit 1
|
exit 1
|
||||||
;;
|
;;
|
||||||
|
|||||||
@@ -50,7 +50,7 @@ set_dhcp_routes()
|
|||||||
# format: dest1/mask gw1 ... destn/mask gwn
|
# format: dest1/mask gw1 ... destn/mask gwn
|
||||||
set -- $staticroutes
|
set -- $staticroutes
|
||||||
while [ -n "$1" -a -n "$2" ]; do
|
while [ -n "$1" -a -n "$2" ]; do
|
||||||
log "adding route $1 via $2 dev $interface proto dhcp"
|
log "adding route $1 via $2 metric $metric tag 100"
|
||||||
echo "ip route $1 $2 $metric tag 100" >> "$NEXT"
|
echo "ip route $1 $2 $metric tag 100" >> "$NEXT"
|
||||||
shift 2
|
shift 2
|
||||||
done
|
done
|
||||||
@@ -115,7 +115,7 @@ case "$ACTION" in
|
|||||||
/usr/sbin/avahi-autoipd -c $interface && /usr/sbin/avahi-autoipd -k $interface
|
/usr/sbin/avahi-autoipd -c $interface && /usr/sbin/avahi-autoipd -k $interface
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if /bin/ip addr add dev $interface $ip/$subnet $BROADCAST proto 5; then
|
if /bin/ip addr add dev $interface $ip/$subnet $BROADCAST proto dhcp; then
|
||||||
echo "$ip" > "$IP_CACHE"
|
echo "$ip" > "$IP_CACHE"
|
||||||
fi
|
fi
|
||||||
if [ -n "$ipv6" ] ; then
|
if [ -n "$ipv6" ] ; then
|
||||||
|
|||||||
@@ -17,14 +17,23 @@ endef
|
|||||||
# U-Boot build tree. This will then be built in to the final U-Boot
|
# U-Boot build tree. This will then be built in to the final U-Boot
|
||||||
# image's control DT via the CONFIG_DEVICE_TREE_INCLUDES option (see
|
# image's control DT via the CONFIG_DEVICE_TREE_INCLUDES option (see
|
||||||
# extras.config).
|
# extras.config).
|
||||||
|
#
|
||||||
|
# Some platforms, most notably Raspberry Pi, load the device tree
|
||||||
|
# from the SPL, effectively overriding the built-in control DT.
|
||||||
|
# For that we bundle an overlay that can be included instead.
|
||||||
define UBOOT_PRE_BUILD_INSTALL_KEY
|
define UBOOT_PRE_BUILD_INSTALL_KEY
|
||||||
$(HOST_DIR)/bin/dtc <(echo '/dts-v1/; / { signature {}; };') >$(@D)/infix-key.dtb
|
$(HOST_DIR)/bin/dtc -a 1024 <(echo '/dts-v1/; / { signature {}; };') \
|
||||||
|
>$(@D)/infix-key.dtb
|
||||||
$(foreach key, \
|
$(foreach key, \
|
||||||
$(call qstrip,$(TRUSTED_KEYS_DEVELOPMENT_PATH)) $(call qstrip,$(TRUSTED_KEYS_EXTRA_PATH)),\
|
$(call qstrip,$(TRUSTED_KEYS_DEVELOPMENT_PATH)) $(call qstrip,$(TRUSTED_KEYS_EXTRA_PATH)),\
|
||||||
$(call uboot-add-pubkey,$(key),$(@D)/infix-key.dtb))
|
$(call uboot-add-pubkey,$(key),$(@D)/infix-key.dtb))
|
||||||
$(HOST_DIR)/bin/dtc -I dtb -O dts \
|
$(HOST_DIR)/bin/dtc -I dtb -O dts \
|
||||||
<$(@D)/infix-key.dtb \
|
<$(@D)/infix-key.dtb \
|
||||||
| sed -e 's:/dts-v[0-9]\+/;::' >$(@D)/arch/$(UBOOT_ARCH)/dts/infix-key.dtsi
|
| sed -e 's:/dts-v[0-9]\+/;::' \
|
||||||
|
| tee $(@D)/arch/$(UBOOT_ARCH)/dts/infix-key.dtsi \
|
||||||
|
| sed -e '1i\/dts-v1/;\n/plugin/;\n' -e '/^$$/d' -e 's:/ {:\&{/} {:' \
|
||||||
|
>$(@D)/arch/$(UBOOT_ARCH)/dts/infix-key.dtso
|
||||||
|
|
||||||
rm $(@D)/infix-key.dtb
|
rm $(@D)/infix-key.dtb
|
||||||
endef
|
endef
|
||||||
UBOOT_PRE_BUILD_HOOKS += UBOOT_PRE_BUILD_INSTALL_KEY
|
UBOOT_PRE_BUILD_HOOKS += UBOOT_PRE_BUILD_INSTALL_KEY
|
||||||
|
|||||||
@@ -33,6 +33,7 @@ CONFIG_KALLSYMS_ALL=y
|
|||||||
CONFIG_PROFILING=y
|
CONFIG_PROFILING=y
|
||||||
CONFIG_SMP=y
|
CONFIG_SMP=y
|
||||||
CONFIG_EFI=y
|
CONFIG_EFI=y
|
||||||
|
CONFIG_KPROBES=y
|
||||||
# CONFIG_GCC_PLUGINS is not set
|
# CONFIG_GCC_PLUGINS is not set
|
||||||
CONFIG_MODULES=y
|
CONFIG_MODULES=y
|
||||||
CONFIG_MODULE_UNLOAD=y
|
CONFIG_MODULE_UNLOAD=y
|
||||||
@@ -144,7 +145,6 @@ CONFIG_BRIDGE_EBT_REDIRECT=m
|
|||||||
CONFIG_BRIDGE_EBT_SNAT=m
|
CONFIG_BRIDGE_EBT_SNAT=m
|
||||||
CONFIG_BRIDGE_EBT_LOG=m
|
CONFIG_BRIDGE_EBT_LOG=m
|
||||||
CONFIG_BRIDGE_EBT_NFLOG=m
|
CONFIG_BRIDGE_EBT_NFLOG=m
|
||||||
CONFIG_BPFILTER=y
|
|
||||||
CONFIG_BRIDGE=y
|
CONFIG_BRIDGE=y
|
||||||
CONFIG_BRIDGE_VLAN_FILTERING=y
|
CONFIG_BRIDGE_VLAN_FILTERING=y
|
||||||
CONFIG_BRIDGE_MRP=y
|
CONFIG_BRIDGE_MRP=y
|
||||||
@@ -161,12 +161,14 @@ CONFIG_MPLS=y
|
|||||||
CONFIG_NET_MPLS_GSO=y
|
CONFIG_NET_MPLS_GSO=y
|
||||||
CONFIG_MPLS_ROUTING=m
|
CONFIG_MPLS_ROUTING=m
|
||||||
CONFIG_MPLS_IPTUNNEL=m
|
CONFIG_MPLS_IPTUNNEL=m
|
||||||
|
CONFIG_NET_SWITCHDEV=y
|
||||||
CONFIG_NET_PKTGEN=y
|
CONFIG_NET_PKTGEN=y
|
||||||
# CONFIG_WIRELESS is not set
|
# CONFIG_WIRELESS is not set
|
||||||
CONFIG_NET_9P=y
|
CONFIG_NET_9P=y
|
||||||
CONFIG_NET_9P_VIRTIO=y
|
CONFIG_NET_9P_VIRTIO=y
|
||||||
CONFIG_LWTUNNEL=y
|
CONFIG_LWTUNNEL=y
|
||||||
CONFIG_PCI=y
|
CONFIG_PCI=y
|
||||||
|
CONFIG_PCI_MSI=y
|
||||||
CONFIG_UEVENT_HELPER=y
|
CONFIG_UEVENT_HELPER=y
|
||||||
CONFIG_UEVENT_HELPER_PATH="/sbin/hotplug"
|
CONFIG_UEVENT_HELPER_PATH="/sbin/hotplug"
|
||||||
CONFIG_DEVTMPFS=y
|
CONFIG_DEVTMPFS=y
|
||||||
@@ -208,6 +210,7 @@ CONFIG_NET_VRF=y
|
|||||||
CONFIG_E1000=y
|
CONFIG_E1000=y
|
||||||
CONFIG_NE2K_PCI=y
|
CONFIG_NE2K_PCI=y
|
||||||
CONFIG_8139CP=y
|
CONFIG_8139CP=y
|
||||||
|
CONFIG_ROCKER=y
|
||||||
# CONFIG_WLAN is not set
|
# CONFIG_WLAN is not set
|
||||||
CONFIG_INPUT_EVDEV=y
|
CONFIG_INPUT_EVDEV=y
|
||||||
CONFIG_SERIAL_8250=y
|
CONFIG_SERIAL_8250=y
|
||||||
@@ -264,5 +267,5 @@ CONFIG_PANIC_ON_OOPS=y
|
|||||||
CONFIG_PANIC_TIMEOUT=20
|
CONFIG_PANIC_TIMEOUT=20
|
||||||
CONFIG_DETECT_HUNG_TASK=y
|
CONFIG_DETECT_HUNG_TASK=y
|
||||||
CONFIG_BOOTPARAM_HUNG_TASK_PANIC=y
|
CONFIG_BOOTPARAM_HUNG_TASK_PANIC=y
|
||||||
# CONFIG_FTRACE is not set
|
CONFIG_FUNCTION_TRACER=y
|
||||||
CONFIG_UNWINDER_FRAME_POINTER=y
|
CONFIG_UNWINDER_FRAME_POINTER=y
|
||||||
|
|||||||
+1
-1
Submodule buildroot updated: 475ea17ffe...f57cf505fa
+19
-12
@@ -13,8 +13,8 @@ BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
|||||||
BR2_INIT_FINIT=y
|
BR2_INIT_FINIT=y
|
||||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
|
||||||
BR2_ROOTFS_MERGED_USR=y
|
BR2_ROOTFS_MERGED_USR=y
|
||||||
|
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||||
BR2_SYSTEM_BIN_SH_BASH=y
|
BR2_SYSTEM_BIN_SH_BASH=y
|
||||||
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
||||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||||
@@ -27,17 +27,14 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build
|
|||||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||||
BR2_LINUX_KERNEL=y
|
BR2_LINUX_KERNEL=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.52"
|
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.35"
|
||||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||||
BR2_LINUX_KERNEL_DTS_SUPPORT=y
|
|
||||||
BR2_LINUX_KERNEL_INTREE_DTS_NAME="alder/alder styx/dcp-sc-28p-a styx/dcp-sc-28p-b marvell/armada-3720-espressobin marvell/armada-3720-espressobin-emmc marvell/armada-3720-espressobin-v7 marvell/armada-3720-espressobin-v7-emmc marvell/armada-3720-espressobin-ultra marvell/cn9130-crb-A marvell/cn9130-crb-B microchip/sparx5_pcb135_emmc_no_psci"
|
|
||||||
BR2_LINUX_KERNEL_CUSTOM_DTS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/dts"
|
|
||||||
BR2_LINUX_KERNEL_DTB_KEEP_DIRNAME=y
|
|
||||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||||
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
||||||
BR2_PACKAGE_STRACE=y
|
BR2_PACKAGE_STRACE=y
|
||||||
BR2_PACKAGE_STRESS_NG=y
|
BR2_PACKAGE_STRESS_NG=y
|
||||||
|
BR2_PACKAGE_SYSREPO_GROUP="sys-cli"
|
||||||
BR2_PACKAGE_JQ=y
|
BR2_PACKAGE_JQ=y
|
||||||
BR2_PACKAGE_E2FSPROGS=y
|
BR2_PACKAGE_E2FSPROGS=y
|
||||||
BR2_PACKAGE_DBUS_CXX=y
|
BR2_PACKAGE_DBUS_CXX=y
|
||||||
@@ -59,8 +56,8 @@ BR2_PACKAGE_PYTHON_GUNICORN=y
|
|||||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||||
BR2_PACKAGE_LIBSSH2=y
|
BR2_PACKAGE_LIBSSH2=y
|
||||||
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
||||||
BR2_PACKAGE_LIBXCRYPT=y
|
|
||||||
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
||||||
|
BR2_PACKAGE_LIBINPUT=y
|
||||||
BR2_PACKAGE_LIBCURL_CURL=y
|
BR2_PACKAGE_LIBCURL_CURL=y
|
||||||
BR2_PACKAGE_NETOPEER2_CLI=y
|
BR2_PACKAGE_NETOPEER2_CLI=y
|
||||||
BR2_PACKAGE_NSS_MDNS=y
|
BR2_PACKAGE_NSS_MDNS=y
|
||||||
@@ -80,6 +77,7 @@ BR2_PACKAGE_IPROUTE2=y
|
|||||||
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
||||||
BR2_PACKAGE_IPUTILS=y
|
BR2_PACKAGE_IPUTILS=y
|
||||||
BR2_PACKAGE_LLDPD=y
|
BR2_PACKAGE_LLDPD=y
|
||||||
|
BR2_PACKAGE_MSTPD=y
|
||||||
BR2_PACKAGE_NETCALC=y
|
BR2_PACKAGE_NETCALC=y
|
||||||
BR2_PACKAGE_NETCAT_OPENBSD=y
|
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||||
BR2_PACKAGE_NETSNMP=y
|
BR2_PACKAGE_NETSNMP=y
|
||||||
@@ -109,6 +107,7 @@ BR2_PACKAGE_RAUC=y
|
|||||||
BR2_PACKAGE_RAUC_DBUS=y
|
BR2_PACKAGE_RAUC_DBUS=y
|
||||||
BR2_PACKAGE_RAUC_GPT=y
|
BR2_PACKAGE_RAUC_GPT=y
|
||||||
BR2_PACKAGE_RAUC_NETWORK=y
|
BR2_PACKAGE_RAUC_NETWORK=y
|
||||||
|
BR2_PACKAGE_RAUC_JSON=y
|
||||||
BR2_PACKAGE_SYSKLOGD=y
|
BR2_PACKAGE_SYSKLOGD=y
|
||||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||||
BR2_PACKAGE_WATCHDOGD=y
|
BR2_PACKAGE_WATCHDOGD=y
|
||||||
@@ -121,22 +120,27 @@ BR2_PACKAGE_HOST_E2FSPROGS=y
|
|||||||
BR2_PACKAGE_HOST_ENVIRONMENT_SETUP=y
|
BR2_PACKAGE_HOST_ENVIRONMENT_SETUP=y
|
||||||
BR2_PACKAGE_HOST_GENEXT2FS=y
|
BR2_PACKAGE_HOST_GENEXT2FS=y
|
||||||
BR2_PACKAGE_HOST_GENIMAGE=y
|
BR2_PACKAGE_HOST_GENIMAGE=y
|
||||||
|
BR2_PACKAGE_HOST_GO_BIN=y
|
||||||
BR2_PACKAGE_HOST_RAUC=y
|
BR2_PACKAGE_HOST_RAUC=y
|
||||||
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||||
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||||
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
|
INFIX_DESC="Infix is an operating system based on Linux and modeled with YANG. It can be set up both as a switch, with offloading using switchdev, a router with firewalling, or a secure end device. All while supporting advanced networking scenarios and running Docker containers."
|
||||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||||
|
BR2_PACKAGE_ALDER_ALDER=y
|
||||||
|
BR2_PACKAGE_MARVELL_CN9130_CRB=y
|
||||||
|
BR2_PACKAGE_MARVELL_ESPRESSOBIN=y
|
||||||
|
BR2_PACKAGE_STYX_DCP_SC_28P=y
|
||||||
BR2_PACKAGE_CONFD=y
|
BR2_PACKAGE_CONFD=y
|
||||||
BR2_PACKAGE_CONFD_TEST_MODE=y
|
BR2_PACKAGE_CONFD_TEST_MODE=y
|
||||||
BR2_PACKAGE_CURIOS_HTTPD=y
|
BR2_PACKAGE_CURIOS_HTTPD=y
|
||||||
BR2_PACKAGE_CURIOS_NFTABLES=y
|
BR2_PACKAGE_CURIOS_NFTABLES=y
|
||||||
BR2_PACKAGE_EXECD=y
|
|
||||||
BR2_PACKAGE_GENCERT=y
|
BR2_PACKAGE_GENCERT=y
|
||||||
BR2_PACKAGE_STATD=y
|
BR2_PACKAGE_STATD=y
|
||||||
|
BR2_PACKAGE_SHOW=y
|
||||||
BR2_PACKAGE_FACTORY=y
|
BR2_PACKAGE_FACTORY=y
|
||||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||||
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
||||||
@@ -147,7 +151,6 @@ BR2_PACKAGE_FINIT_RTC_FILE="/var/lib/misc/rtc"
|
|||||||
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
|
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
|
||||||
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
|
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
|
||||||
BR2_PACKAGE_IITO=y
|
BR2_PACKAGE_IITO=y
|
||||||
BR2_PACKAGE_K8S_LOGGER=y
|
|
||||||
BR2_PACKAGE_KEYACK=y
|
BR2_PACKAGE_KEYACK=y
|
||||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||||
BR2_PACKAGE_LANDING=y
|
BR2_PACKAGE_LANDING=y
|
||||||
@@ -161,10 +164,14 @@ BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
|||||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||||
BR2_PACKAGE_TETRIS=y
|
BR2_PACKAGE_TETRIS=y
|
||||||
BR2_PACKAGE_ROUSETTE=y
|
BR2_PACKAGE_ROUSETTE=y
|
||||||
BR2_PACKAGE_LIBINPUT=y
|
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||||
|
BR2_PACKAGE_FEATURE_WIFI=y
|
||||||
|
BR2_PACKAGE_FEATURE_WIFI_DONGLE_REALTEK=y
|
||||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||||
DISK_IMAGE_BOOT_BIN=y
|
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
||||||
|
BR2_PACKAGE_GETENT=y
|
||||||
TRUSTED_KEYS=y
|
TRUSTED_KEYS=y
|
||||||
TRUSTED_KEYS_DEVELOPMENT=y
|
TRUSTED_KEYS_DEVELOPMENT=y
|
||||||
|
DISK_IMAGE_BOOT_BIN=y
|
||||||
GNS3_APPLIANCE_RAM=512
|
GNS3_APPLIANCE_RAM=512
|
||||||
GNS3_APPLIANCE_IFNUM=10
|
GNS3_APPLIANCE_IFNUM=10
|
||||||
|
|||||||
@@ -27,17 +27,14 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build
|
|||||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||||
BR2_LINUX_KERNEL=y
|
BR2_LINUX_KERNEL=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.52"
|
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.35"
|
||||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||||
BR2_LINUX_KERNEL_DTS_SUPPORT=y
|
|
||||||
BR2_LINUX_KERNEL_INTREE_DTS_NAME="alder/alder styx/dcp-sc-28p-a styx/dcp-sc-28p-b marvell/armada-3720-espressobin marvell/armada-3720-espressobin-emmc marvell/armada-3720-espressobin-v7 marvell/armada-3720-espressobin-v7-emmc marvell/armada-3720-espressobin-ultra marvell/cn9130-crb-A marvell/cn9130-crb-B microchip/sparx5_pcb135_emmc_no_psci"
|
|
||||||
BR2_LINUX_KERNEL_CUSTOM_DTS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/dts"
|
|
||||||
BR2_LINUX_KERNEL_DTB_KEEP_DIRNAME=y
|
|
||||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||||
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
||||||
BR2_PACKAGE_STRACE=y
|
BR2_PACKAGE_STRACE=y
|
||||||
BR2_PACKAGE_STRESS_NG=y
|
BR2_PACKAGE_STRESS_NG=y
|
||||||
|
BR2_PACKAGE_SYSREPO_GROUP="sys-cli"
|
||||||
BR2_PACKAGE_JQ=y
|
BR2_PACKAGE_JQ=y
|
||||||
BR2_PACKAGE_E2FSPROGS=y
|
BR2_PACKAGE_E2FSPROGS=y
|
||||||
BR2_PACKAGE_DBUS_CXX=y
|
BR2_PACKAGE_DBUS_CXX=y
|
||||||
@@ -75,6 +72,7 @@ BR2_PACKAGE_FRR=y
|
|||||||
BR2_PACKAGE_IPROUTE2=y
|
BR2_PACKAGE_IPROUTE2=y
|
||||||
BR2_PACKAGE_IPUTILS=y
|
BR2_PACKAGE_IPUTILS=y
|
||||||
BR2_PACKAGE_LLDPD=y
|
BR2_PACKAGE_LLDPD=y
|
||||||
|
BR2_PACKAGE_MSTPD=y
|
||||||
BR2_PACKAGE_NETCALC=y
|
BR2_PACKAGE_NETCALC=y
|
||||||
BR2_PACKAGE_NGINX=y
|
BR2_PACKAGE_NGINX=y
|
||||||
BR2_PACKAGE_NGINX_HTTP_SSL_MODULE=y
|
BR2_PACKAGE_NGINX_HTTP_SSL_MODULE=y
|
||||||
@@ -92,6 +90,7 @@ BR2_PACKAGE_RAUC=y
|
|||||||
BR2_PACKAGE_RAUC_DBUS=y
|
BR2_PACKAGE_RAUC_DBUS=y
|
||||||
BR2_PACKAGE_RAUC_GPT=y
|
BR2_PACKAGE_RAUC_GPT=y
|
||||||
BR2_PACKAGE_RAUC_NETWORK=y
|
BR2_PACKAGE_RAUC_NETWORK=y
|
||||||
|
BR2_PACKAGE_RAUC_JSON=y
|
||||||
BR2_PACKAGE_SYSKLOGD=y
|
BR2_PACKAGE_SYSKLOGD=y
|
||||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||||
BR2_PACKAGE_WATCHDOGD=y
|
BR2_PACKAGE_WATCHDOGD=y
|
||||||
@@ -109,14 +108,19 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
|||||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||||
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||||
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
|
INFIX_DESC="Infix is an operating system based on Linux and modeled with YANG. It can be set up both as a switch, with offloading using switchdev, a router with firewalling, or a secure end device. All while supporting advanced networking scenarios and running Docker containers."
|
||||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||||
|
BR2_PACKAGE_ALDER_ALDER=y
|
||||||
|
BR2_PACKAGE_MARVELL_CN9130_CRB=y
|
||||||
|
BR2_PACKAGE_MARVELL_ESPRESSOBIN=y
|
||||||
|
BR2_PACKAGE_STYX_DCP_SC_28P=y
|
||||||
BR2_PACKAGE_CONFD=y
|
BR2_PACKAGE_CONFD=y
|
||||||
BR2_PACKAGE_CONFD_TEST_MODE=y
|
BR2_PACKAGE_CONFD_TEST_MODE=y
|
||||||
BR2_PACKAGE_GENCERT=y
|
BR2_PACKAGE_GENCERT=y
|
||||||
BR2_PACKAGE_STATD=y
|
BR2_PACKAGE_STATD=y
|
||||||
|
BR2_PACKAGE_SHOW=y
|
||||||
BR2_PACKAGE_FACTORY=y
|
BR2_PACKAGE_FACTORY=y
|
||||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||||
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
||||||
@@ -134,6 +138,9 @@ BR2_PACKAGE_MCD=y
|
|||||||
BR2_PACKAGE_MDNS_ALIAS=y
|
BR2_PACKAGE_MDNS_ALIAS=y
|
||||||
BR2_PACKAGE_LIBINPUT=y
|
BR2_PACKAGE_LIBINPUT=y
|
||||||
BR2_PACKAGE_ROUSETTE=y
|
BR2_PACKAGE_ROUSETTE=y
|
||||||
|
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||||
|
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
||||||
|
BR2_PACKAGE_GETENT=y
|
||||||
DISK_IMAGE_BOOT_BIN=y
|
DISK_IMAGE_BOOT_BIN=y
|
||||||
TRUSTED_KEYS=y
|
TRUSTED_KEYS=y
|
||||||
TRUSTED_KEYS_DEVELOPMENT=y
|
TRUSTED_KEYS_DEVELOPMENT=y
|
||||||
|
|||||||
@@ -8,7 +8,6 @@ BR2_CCACHE=y
|
|||||||
BR2_CCACHE_DIR="${BR2_EXTERNAL_INFIX_PATH}/.ccache"
|
BR2_CCACHE_DIR="${BR2_EXTERNAL_INFIX_PATH}/.ccache"
|
||||||
BR2_ENABLE_DEBUG=y
|
BR2_ENABLE_DEBUG=y
|
||||||
BR2_GLOBAL_PATCH_DIR="${BR2_EXTERNAL_INFIX_PATH}/patches"
|
BR2_GLOBAL_PATCH_DIR="${BR2_EXTERNAL_INFIX_PATH}/patches"
|
||||||
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
|
||||||
BR2_TARGET_GENERIC_HOSTNAME="infix"
|
BR2_TARGET_GENERIC_HOSTNAME="infix"
|
||||||
BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||||
BR2_INIT_FINIT=y
|
BR2_INIT_FINIT=y
|
||||||
@@ -30,7 +29,7 @@ BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image
|
|||||||
BR2_ROOTFS_POST_SCRIPT_ARGS="-c $(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/r2s/genimage.cfg"
|
BR2_ROOTFS_POST_SCRIPT_ARGS="-c $(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/r2s/genimage.cfg"
|
||||||
BR2_LINUX_KERNEL=y
|
BR2_LINUX_KERNEL=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.10.3"
|
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.35"
|
||||||
BR2_LINUX_KERNEL_PATCH="$(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/r2s/rk3328-nanopi-r2s-dts.patch"
|
BR2_LINUX_KERNEL_PATCH="$(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/r2s/rk3328-nanopi-r2s-dts.patch"
|
||||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/r2s/linux_defconfig"
|
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/r2s/linux_defconfig"
|
||||||
@@ -42,6 +41,7 @@ BR2_LINUX_KERNEL_NEEDS_HOST_OPENSSL=y
|
|||||||
BR2_PACKAGE_BUSYBOX_CONFIG="$(BR2_EXTERNAL_INFIX_PATH)/board/common/busybox_defconfig"
|
BR2_PACKAGE_BUSYBOX_CONFIG="$(BR2_EXTERNAL_INFIX_PATH)/board/common/busybox_defconfig"
|
||||||
BR2_PACKAGE_STRACE=y
|
BR2_PACKAGE_STRACE=y
|
||||||
BR2_PACKAGE_STRESS_NG=y
|
BR2_PACKAGE_STRESS_NG=y
|
||||||
|
BR2_PACKAGE_SYSREPO_GROUP="sys-cli"
|
||||||
BR2_PACKAGE_JQ=y
|
BR2_PACKAGE_JQ=y
|
||||||
BR2_PACKAGE_E2FSPROGS=y
|
BR2_PACKAGE_E2FSPROGS=y
|
||||||
BR2_PACKAGE_LINUX_FIRMWARE=y
|
BR2_PACKAGE_LINUX_FIRMWARE=y
|
||||||
@@ -74,7 +74,6 @@ BR2_PACKAGE_PYTHON_GUNICORN=y
|
|||||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||||
BR2_PACKAGE_LIBSSH2=y
|
BR2_PACKAGE_LIBSSH2=y
|
||||||
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
||||||
BR2_PACKAGE_LIBXCRYPT=y
|
|
||||||
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
||||||
BR2_PACKAGE_LIBINPUT=y
|
BR2_PACKAGE_LIBINPUT=y
|
||||||
BR2_PACKAGE_LIBCURL_CURL=y
|
BR2_PACKAGE_LIBCURL_CURL=y
|
||||||
@@ -128,6 +127,7 @@ BR2_PACKAGE_RAUC=y
|
|||||||
BR2_PACKAGE_RAUC_DBUS=y
|
BR2_PACKAGE_RAUC_DBUS=y
|
||||||
BR2_PACKAGE_RAUC_GPT=y
|
BR2_PACKAGE_RAUC_GPT=y
|
||||||
BR2_PACKAGE_RAUC_NETWORK=y
|
BR2_PACKAGE_RAUC_NETWORK=y
|
||||||
|
BR2_PACKAGE_RAUC_JSON=y
|
||||||
BR2_PACKAGE_SYSKLOGD=y
|
BR2_PACKAGE_SYSKLOGD=y
|
||||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||||
BR2_PACKAGE_WATCHDOGD=y
|
BR2_PACKAGE_WATCHDOGD=y
|
||||||
@@ -170,14 +170,14 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
|||||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||||
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||||
INFIX_IMAGE_ID="${INFIX_ID}-r2s"
|
INFIX_IMAGE_ID="${INFIX_ID}-r2s"
|
||||||
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
|
INFIX_DESC="Infix is an operating system based on Linux and modeled with YANG. It can be set up both as a switch, with offloading using switchdev, a router with firewalling, or a secure end device. All while supporting advanced networking scenarios and running Docker containers."
|
||||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||||
BR2_PACKAGE_CONFD=y
|
BR2_PACKAGE_CONFD=y
|
||||||
BR2_PACKAGE_EXECD=y
|
|
||||||
BR2_PACKAGE_GENCERT=y
|
BR2_PACKAGE_GENCERT=y
|
||||||
BR2_PACKAGE_STATD=y
|
BR2_PACKAGE_STATD=y
|
||||||
|
BR2_PACKAGE_SHOW=y
|
||||||
BR2_PACKAGE_FACTORY=y
|
BR2_PACKAGE_FACTORY=y
|
||||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||||
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
||||||
@@ -188,7 +188,6 @@ BR2_PACKAGE_FINIT_RTC_FILE="/var/lib/misc/rtc"
|
|||||||
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
|
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
|
||||||
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
|
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
|
||||||
BR2_PACKAGE_IITO=y
|
BR2_PACKAGE_IITO=y
|
||||||
BR2_PACKAGE_K8S_LOGGER=y
|
|
||||||
BR2_PACKAGE_KEYACK=y
|
BR2_PACKAGE_KEYACK=y
|
||||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||||
BR2_PACKAGE_LANDING=y
|
BR2_PACKAGE_LANDING=y
|
||||||
@@ -202,7 +201,10 @@ BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
|||||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||||
BR2_PACKAGE_TETRIS=y
|
BR2_PACKAGE_TETRIS=y
|
||||||
BR2_PACKAGE_ROUSETTE=y
|
BR2_PACKAGE_ROUSETTE=y
|
||||||
|
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||||
|
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
||||||
|
BR2_PACKAGE_GETENT=y
|
||||||
TRUSTED_KEYS=y
|
TRUSTED_KEYS=y
|
||||||
TRUSTED_KEYS_DEVELOPMENT=y
|
TRUSTED_KEYS_DEVELOPMENT=y
|
||||||
# GNS3_APPLIANCE is not set
|
# GNS3_APPLIANCE is not set
|
||||||
|
|||||||
@@ -39,6 +39,7 @@ BR2_LINUX_KERNEL_NEEDS_HOST_OPENSSL=y
|
|||||||
BR2_PACKAGE_BUSYBOX_CONFIG="$(BR2_EXTERNAL_INFIX_PATH)/board/common/busybox_defconfig"
|
BR2_PACKAGE_BUSYBOX_CONFIG="$(BR2_EXTERNAL_INFIX_PATH)/board/common/busybox_defconfig"
|
||||||
BR2_PACKAGE_STRACE=y
|
BR2_PACKAGE_STRACE=y
|
||||||
BR2_PACKAGE_STRESS_NG=y
|
BR2_PACKAGE_STRESS_NG=y
|
||||||
|
BR2_PACKAGE_SYSREPO_GROUP="sys-cli"
|
||||||
BR2_PACKAGE_JQ=y
|
BR2_PACKAGE_JQ=y
|
||||||
BR2_PACKAGE_E2FSPROGS=y
|
BR2_PACKAGE_E2FSPROGS=y
|
||||||
BR2_PACKAGE_LINUX_FIRMWARE=y
|
BR2_PACKAGE_LINUX_FIRMWARE=y
|
||||||
@@ -88,6 +89,7 @@ BR2_PACKAGE_IPROUTE2=y
|
|||||||
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
||||||
BR2_PACKAGE_IPUTILS=y
|
BR2_PACKAGE_IPUTILS=y
|
||||||
BR2_PACKAGE_LLDPD=y
|
BR2_PACKAGE_LLDPD=y
|
||||||
|
BR2_PACKAGE_MSTPD=y
|
||||||
BR2_PACKAGE_NETCALC=y
|
BR2_PACKAGE_NETCALC=y
|
||||||
BR2_PACKAGE_NETCAT_OPENBSD=y
|
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||||
BR2_PACKAGE_NETSNMP=y
|
BR2_PACKAGE_NETSNMP=y
|
||||||
@@ -117,6 +119,7 @@ BR2_PACKAGE_RAUC=y
|
|||||||
BR2_PACKAGE_RAUC_DBUS=y
|
BR2_PACKAGE_RAUC_DBUS=y
|
||||||
BR2_PACKAGE_RAUC_GPT=y
|
BR2_PACKAGE_RAUC_GPT=y
|
||||||
BR2_PACKAGE_RAUC_NETWORK=y
|
BR2_PACKAGE_RAUC_NETWORK=y
|
||||||
|
BR2_PACKAGE_RAUC_JSON=y
|
||||||
BR2_PACKAGE_SYSKLOGD=y
|
BR2_PACKAGE_SYSKLOGD=y
|
||||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||||
BR2_PACKAGE_WATCHDOGD=y
|
BR2_PACKAGE_WATCHDOGD=y
|
||||||
@@ -159,15 +162,15 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
|||||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||||
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||||
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
|
INFIX_DESC="Infix is an operating system based on Linux and modeled with YANG. It can be set up both as a switch, with offloading using switchdev, a router with firewalling, or a secure end device. All while supporting advanced networking scenarios and running Docker containers."
|
||||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||||
BR2_PACKAGE_CONFD=y
|
BR2_PACKAGE_CONFD=y
|
||||||
# BR2_PACKAGE_CONFD_TEST_MODE is not set
|
# BR2_PACKAGE_CONFD_TEST_MODE is not set
|
||||||
BR2_PACKAGE_EXECD=y
|
|
||||||
BR2_PACKAGE_GENCERT=y
|
BR2_PACKAGE_GENCERT=y
|
||||||
BR2_PACKAGE_STATD=y
|
BR2_PACKAGE_STATD=y
|
||||||
|
BR2_PACKAGE_SHOW=y
|
||||||
BR2_PACKAGE_FACTORY=y
|
BR2_PACKAGE_FACTORY=y
|
||||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||||
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
||||||
@@ -178,7 +181,6 @@ BR2_PACKAGE_FINIT_RTC_FILE="/var/lib/misc/rtc"
|
|||||||
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
|
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
|
||||||
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
|
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
|
||||||
BR2_PACKAGE_IITO=y
|
BR2_PACKAGE_IITO=y
|
||||||
BR2_PACKAGE_K8S_LOGGER=y
|
|
||||||
BR2_PACKAGE_KEYACK=y
|
BR2_PACKAGE_KEYACK=y
|
||||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||||
BR2_PACKAGE_LANDING=y
|
BR2_PACKAGE_LANDING=y
|
||||||
@@ -193,6 +195,9 @@ BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
|||||||
BR2_PACKAGE_TETRIS=y
|
BR2_PACKAGE_TETRIS=y
|
||||||
BR2_PACKAGE_ROUSETTE=y
|
BR2_PACKAGE_ROUSETTE=y
|
||||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||||
|
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||||
|
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
||||||
|
BR2_PACKAGE_GETENT=y
|
||||||
TRUSTED_KEYS=y
|
TRUSTED_KEYS=y
|
||||||
TRUSTED_KEYS_DEVELOPMENT=y
|
TRUSTED_KEYS_DEVELOPMENT=y
|
||||||
# GNS3_APPLIANCE is not set
|
# GNS3_APPLIANCE is not set
|
||||||
|
|||||||
@@ -0,0 +1,201 @@
|
|||||||
|
BR2_aarch64=y
|
||||||
|
BR2_cortex_a72=y
|
||||||
|
BR2_ARM_FPU_VFPV4=y
|
||||||
|
BR2_TOOLCHAIN_EXTERNAL=y
|
||||||
|
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
|
||||||
|
BR2_TOOLCHAIN_EXTERNAL_GDB_SERVER_COPY=y
|
||||||
|
BR2_DL_DIR="${BR2_EXTERNAL_INFIX_PATH}/dl"
|
||||||
|
BR2_CCACHE=y
|
||||||
|
BR2_CCACHE_DIR="${BR2_EXTERNAL_INFIX_PATH}/.ccache"
|
||||||
|
BR2_GLOBAL_PATCH_DIR="board/raspberrypi/patches ${BR2_EXTERNAL_INFIX_PATH}/patches"
|
||||||
|
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
||||||
|
BR2_TARGET_GENERIC_HOSTNAME="infix"
|
||||||
|
BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||||
|
BR2_INIT_FINIT=y
|
||||||
|
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||||
|
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||||
|
BR2_ROOTFS_MERGED_USR=y
|
||||||
|
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||||
|
BR2_SYSTEM_BIN_SH_BASH=y
|
||||||
|
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
||||||
|
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||||
|
BR2_SYSTEM_DHCP="eth0"
|
||||||
|
BR2_SYSTEM_DEFAULT_PATH="/bin:/sbin:/usr/bin:/usr/sbin"
|
||||||
|
BR2_ENABLE_LOCALE_WHITELIST="C en_US en_CA C.UTF-8"
|
||||||
|
BR2_GENERATE_LOCALE="en_US en_CA C.UTF-8"
|
||||||
|
BR2_TARGET_TZ_INFO=y
|
||||||
|
BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/rootfs ${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/rpi/rootfs"
|
||||||
|
BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/rpi/post-build.sh"
|
||||||
|
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh ${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/rpi/post-image.sh"
|
||||||
|
BR2_LINUX_KERNEL=y
|
||||||
|
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||||
|
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.35"
|
||||||
|
BR2_LINUX_KERNEL_PATCH="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/rpi/bcm2711-rpi-4-b-dts.patch"
|
||||||
|
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||||
|
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/rpi/bcm2711_defconfig"
|
||||||
|
BR2_LINUX_KERNEL_DTS_SUPPORT=y
|
||||||
|
BR2_LINUX_KERNEL_INTREE_DTS_NAME="broadcom/bcm2711-rpi-4-b broadcom/bcm2711-rpi-400"
|
||||||
|
BR2_LINUX_KERNEL_DTB_KEEP_DIRNAME=y
|
||||||
|
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||||
|
BR2_LINUX_KERNEL_NEEDS_HOST_OPENSSL=y
|
||||||
|
BR2_PACKAGE_BUSYBOX_CONFIG="$(BR2_EXTERNAL_INFIX_PATH)/board/common/busybox_defconfig"
|
||||||
|
BR2_PACKAGE_XZ=y
|
||||||
|
BR2_PACKAGE_STRACE=y
|
||||||
|
BR2_PACKAGE_STRESS_NG=y
|
||||||
|
BR2_PACKAGE_JQ=y
|
||||||
|
BR2_PACKAGE_E2FSPROGS=y
|
||||||
|
BR2_PACKAGE_ARMBIAN_FIRMWARE=y
|
||||||
|
BR2_PACKAGE_ARMBIAN_FIRMWARE_AP6255=y
|
||||||
|
BR2_PACKAGE_BRCMFMAC_SDIO_FIRMWARE_RPI=y
|
||||||
|
BR2_PACKAGE_LINUX_FIRMWARE=y
|
||||||
|
BR2_PACKAGE_LINUX_FIRMWARE_BRCM_BCM43XX=y
|
||||||
|
BR2_PACKAGE_LINUX_FIRMWARE_BRCM_BCM43XXX=y
|
||||||
|
BR2_PACKAGE_LINUX_FIRMWARE_BRCM_BCM4366B1=y
|
||||||
|
BR2_PACKAGE_LINUX_FIRMWARE_BRCM_BCM4366C0=y
|
||||||
|
BR2_PACKAGE_RPI_FIRMWARE=y
|
||||||
|
BR2_PACKAGE_RPI_FIRMWARE_VARIANT_PI4=y
|
||||||
|
BR2_PACKAGE_RPI_FIRMWARE_VARIANT_PI4_X=y
|
||||||
|
BR2_PACKAGE_RPI_FIRMWARE_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/rpi/config.txt"
|
||||||
|
BR2_PACKAGE_RPI_FIRMWARE_CMDLINE_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/rpi/cmdline.txt"
|
||||||
|
BR2_PACKAGE_DBUS_CXX=y
|
||||||
|
BR2_PACKAGE_DBUS_GLIB=y
|
||||||
|
BR2_PACKAGE_DBUS_TRIGGERD=y
|
||||||
|
BR2_PACKAGE_EUDEV_RULES_GEN=y
|
||||||
|
# BR2_PACKAGE_EUDEV_ENABLE_HWDB is not set
|
||||||
|
BR2_PACKAGE_EVEMU=y
|
||||||
|
BR2_PACKAGE_EVTEST=y
|
||||||
|
BR2_PACKAGE_GPTFDISK=y
|
||||||
|
BR2_PACKAGE_GPTFDISK_SGDISK=y
|
||||||
|
BR2_PACKAGE_INPUT_EVENT_DAEMON=y
|
||||||
|
BR2_PACKAGE_MDIO_TOOLS=y
|
||||||
|
BR2_PACKAGE_RNG_TOOLS=y
|
||||||
|
BR2_PACKAGE_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||||
|
BR2_PACKAGE_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||||
|
BR2_PACKAGE_UBOOT_TOOLS_FIT_CHECK_SIGN=y
|
||||||
|
BR2_PACKAGE_UBOOT_TOOLS_MKENVIMAGE=y
|
||||||
|
BR2_PACKAGE_PYTHON3=y
|
||||||
|
BR2_PACKAGE_PYTHON_GUNICORN=y
|
||||||
|
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||||
|
BR2_PACKAGE_LIBSSH2=y
|
||||||
|
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
||||||
|
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
||||||
|
BR2_PACKAGE_LIBINPUT=y
|
||||||
|
BR2_PACKAGE_LIBCURL_CURL=y
|
||||||
|
BR2_PACKAGE_NETOPEER2_CLI=y
|
||||||
|
BR2_PACKAGE_NSS_MDNS=y
|
||||||
|
BR2_PACKAGE_LINUX_PAM=y
|
||||||
|
BR2_PACKAGE_LIBPAM_RADIUS_AUTH=y
|
||||||
|
BR2_PACKAGE_ONIGURUMA=y
|
||||||
|
BR2_PACKAGE_AVAHI_DAEMON=y
|
||||||
|
BR2_PACKAGE_AVAHI_DEFAULT_SERVICES=y
|
||||||
|
BR2_PACKAGE_CHRONY=y
|
||||||
|
BR2_PACKAGE_CONNTRACK_TOOLS=y
|
||||||
|
BR2_PACKAGE_DNSMASQ=y
|
||||||
|
BR2_PACKAGE_ETHTOOL=y
|
||||||
|
BR2_PACKAGE_FPING=y
|
||||||
|
BR2_PACKAGE_FRR=y
|
||||||
|
BR2_PACKAGE_HOSTAPD=y
|
||||||
|
# BR2_PACKAGE_IFUPDOWN_SCRIPTS is not set
|
||||||
|
BR2_PACKAGE_IPROUTE2=y
|
||||||
|
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
||||||
|
BR2_PACKAGE_IPUTILS=y
|
||||||
|
BR2_PACKAGE_IW=y
|
||||||
|
BR2_PACKAGE_LLDPD=y
|
||||||
|
BR2_PACKAGE_MSTPD=y
|
||||||
|
BR2_PACKAGE_NETCALC=y
|
||||||
|
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||||
|
BR2_PACKAGE_NETSNMP=y
|
||||||
|
BR2_PACKAGE_NFTABLES=y
|
||||||
|
BR2_PACKAGE_NGINX=y
|
||||||
|
BR2_PACKAGE_NGINX_HTTP_SSL_MODULE=y
|
||||||
|
BR2_PACKAGE_NGINX_HTTP_V2_MODULE=y
|
||||||
|
BR2_PACKAGE_NMAP=y
|
||||||
|
BR2_PACKAGE_NMAP_NCAT=y
|
||||||
|
BR2_PACKAGE_NMAP_NMAP=y
|
||||||
|
BR2_PACKAGE_NMAP_NPING=y
|
||||||
|
BR2_PACKAGE_OPENRESOLV=y
|
||||||
|
BR2_PACKAGE_OPENSSH=y
|
||||||
|
BR2_PACKAGE_SOCAT=y
|
||||||
|
BR2_PACKAGE_TCPDUMP=y
|
||||||
|
BR2_PACKAGE_TRACEROUTE=y
|
||||||
|
BR2_PACKAGE_ULOGD=y
|
||||||
|
BR2_PACKAGE_WHOIS=y
|
||||||
|
BR2_PACKAGE_WIRELESS_REGDB=y
|
||||||
|
BR2_PACKAGE_WIRELESS_TOOLS=y
|
||||||
|
BR2_PACKAGE_WPA_SUPPLICANT=y
|
||||||
|
BR2_PACKAGE_BASH_COMPLETION=y
|
||||||
|
BR2_PACKAGE_SUDO=y
|
||||||
|
BR2_PACKAGE_TTYD=y
|
||||||
|
BR2_PACKAGE_GETENT=y
|
||||||
|
BR2_PACKAGE_HTOP=y
|
||||||
|
BR2_PACKAGE_IRQBALANCE=y
|
||||||
|
BR2_PACKAGE_KMOD_TOOLS=y
|
||||||
|
BR2_PACKAGE_PWGEN=y
|
||||||
|
BR2_PACKAGE_RAUC=y
|
||||||
|
BR2_PACKAGE_RAUC_DBUS=y
|
||||||
|
BR2_PACKAGE_RAUC_GPT=y
|
||||||
|
BR2_PACKAGE_RAUC_NETWORK=y
|
||||||
|
BR2_PACKAGE_RAUC_JSON=y
|
||||||
|
BR2_PACKAGE_SYSKLOGD=y
|
||||||
|
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||||
|
BR2_PACKAGE_WATCHDOGD=y
|
||||||
|
BR2_PACKAGE_LESS=y
|
||||||
|
BR2_PACKAGE_MG=y
|
||||||
|
BR2_PACKAGE_NANO=y
|
||||||
|
BR2_TARGET_ROOTFS_SQUASHFS=y
|
||||||
|
# BR2_TARGET_ROOTFS_TAR is not set
|
||||||
|
BR2_TARGET_UBOOT=y
|
||||||
|
BR2_TARGET_UBOOT_BOARD_DEFCONFIG="rpi_arm64"
|
||||||
|
BR2_TARGET_UBOOT_CONFIG_FRAGMENT_FILES="$(BR2_EXTERNAL_INFIX_PATH)/board/common/uboot/extras.config $(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/rpi/uboot/extras.config"
|
||||||
|
BR2_TARGET_UBOOT_FORMAT_CUSTOM=y
|
||||||
|
BR2_TARGET_UBOOT_FORMAT_CUSTOM_NAME="arch/arm/dts/infix-key.dtbo arch/arm/dts/rpi-env.dtbo"
|
||||||
|
BR2_TARGET_UBOOT_CUSTOM_DTS_PATH="$(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/rpi/uboot/rpi-env.dtso"
|
||||||
|
BR2_PACKAGE_HOST_DOSFSTOOLS=y
|
||||||
|
BR2_PACKAGE_HOST_E2FSPROGS=y
|
||||||
|
BR2_PACKAGE_HOST_ENVIRONMENT_SETUP=y
|
||||||
|
BR2_PACKAGE_HOST_GENEXT2FS=y
|
||||||
|
BR2_PACKAGE_HOST_GENIMAGE=y
|
||||||
|
BR2_PACKAGE_HOST_KMOD_XZ=y
|
||||||
|
BR2_PACKAGE_HOST_MTOOLS=y
|
||||||
|
BR2_PACKAGE_HOST_RAUC=y
|
||||||
|
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||||
|
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||||
|
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||||
|
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||||
|
INFIX_IMAGE_ID="${INFIX_ID}-rpi4"
|
||||||
|
INFIX_DESC="Infix is an operating system based on Linux and modeled with YANG. It can be set up both as a switch, with offloading using switchdev, a router with firewalling, or a secure end device. All while supporting advanced networking scenarios and running Docker containers."
|
||||||
|
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||||
|
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||||
|
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||||
|
BR2_PACKAGE_CONFD=y
|
||||||
|
BR2_PACKAGE_GENCERT=y
|
||||||
|
BR2_PACKAGE_STATD=y
|
||||||
|
BR2_PACKAGE_FACTORY=y
|
||||||
|
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||||
|
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
||||||
|
BR2_PACKAGE_FINIT_PLUGIN_MODULES_LOAD=y
|
||||||
|
BR2_PACKAGE_FINIT_PLUGIN_RTC=y
|
||||||
|
BR2_PACKAGE_FINIT_RTC_DATE="2024-11-04 10:54:00"
|
||||||
|
BR2_PACKAGE_FINIT_RTC_FILE="/var/lib/misc/rtc"
|
||||||
|
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
|
||||||
|
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
|
||||||
|
BR2_PACKAGE_IITO=y
|
||||||
|
BR2_PACKAGE_KEYACK=y
|
||||||
|
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||||
|
BR2_PACKAGE_LANDING=y
|
||||||
|
BR2_PACKAGE_LOWDOWN=y
|
||||||
|
BR2_PACKAGE_MCD=y
|
||||||
|
BR2_PACKAGE_MDNS_ALIAS=y
|
||||||
|
BR2_PACKAGE_NETBROWSE=y
|
||||||
|
BR2_PACKAGE_PODMAN=y
|
||||||
|
BR2_PACKAGE_PODMAN_DRIVER_BTRFS=y
|
||||||
|
BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
||||||
|
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||||
|
BR2_PACKAGE_SHOW=y
|
||||||
|
BR2_PACKAGE_TETRIS=y
|
||||||
|
BR2_PACKAGE_ROUSETTE=y
|
||||||
|
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||||
|
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||||
|
TRUSTED_KEYS=y
|
||||||
|
TRUSTED_KEYS_DEVELOPMENT=y
|
||||||
|
SDCARD_AUX=y
|
||||||
@@ -12,8 +12,8 @@ BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
|||||||
BR2_INIT_FINIT=y
|
BR2_INIT_FINIT=y
|
||||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
|
||||||
BR2_ROOTFS_MERGED_USR=y
|
BR2_ROOTFS_MERGED_USR=y
|
||||||
|
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||||
BR2_SYSTEM_BIN_SH_BASH=y
|
BR2_SYSTEM_BIN_SH_BASH=y
|
||||||
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
||||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||||
@@ -26,7 +26,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INF
|
|||||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||||
BR2_LINUX_KERNEL=y
|
BR2_LINUX_KERNEL=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.52"
|
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.35"
|
||||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||||
@@ -34,6 +34,7 @@ BR2_LINUX_KERNEL_NEEDS_HOST_LIBELF=y
|
|||||||
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
||||||
BR2_PACKAGE_STRACE=y
|
BR2_PACKAGE_STRACE=y
|
||||||
BR2_PACKAGE_STRESS_NG=y
|
BR2_PACKAGE_STRESS_NG=y
|
||||||
|
BR2_PACKAGE_SYSREPO_GROUP="sys-cli"
|
||||||
BR2_PACKAGE_JQ=y
|
BR2_PACKAGE_JQ=y
|
||||||
BR2_PACKAGE_E2FSPROGS=y
|
BR2_PACKAGE_E2FSPROGS=y
|
||||||
BR2_PACKAGE_DBUS_CXX=y
|
BR2_PACKAGE_DBUS_CXX=y
|
||||||
@@ -54,10 +55,8 @@ BR2_PACKAGE_PYTHON_GUNICORN=y
|
|||||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||||
BR2_PACKAGE_LIBSSH2=y
|
BR2_PACKAGE_LIBSSH2=y
|
||||||
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
||||||
BR2_PACKAGE_LIBXCRYPT=y
|
|
||||||
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
||||||
BR2_PACKAGE_LIBCURL_CURL=y
|
BR2_PACKAGE_LIBCURL_CURL=y
|
||||||
BR2_PACKAGE_LIBMNL=y
|
|
||||||
BR2_PACKAGE_NETOPEER2_CLI=y
|
BR2_PACKAGE_NETOPEER2_CLI=y
|
||||||
BR2_PACKAGE_NSS_MDNS=y
|
BR2_PACKAGE_NSS_MDNS=y
|
||||||
BR2_PACKAGE_LINUX_PAM=y
|
BR2_PACKAGE_LINUX_PAM=y
|
||||||
@@ -76,6 +75,7 @@ BR2_PACKAGE_IPROUTE2=y
|
|||||||
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
||||||
BR2_PACKAGE_IPUTILS=y
|
BR2_PACKAGE_IPUTILS=y
|
||||||
BR2_PACKAGE_LLDPD=y
|
BR2_PACKAGE_LLDPD=y
|
||||||
|
BR2_PACKAGE_MSTPD=y
|
||||||
BR2_PACKAGE_NETCALC=y
|
BR2_PACKAGE_NETCALC=y
|
||||||
BR2_PACKAGE_NETCAT_OPENBSD=y
|
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||||
BR2_PACKAGE_NETSNMP=y
|
BR2_PACKAGE_NETSNMP=y
|
||||||
@@ -105,6 +105,7 @@ BR2_PACKAGE_RAUC=y
|
|||||||
BR2_PACKAGE_RAUC_DBUS=y
|
BR2_PACKAGE_RAUC_DBUS=y
|
||||||
BR2_PACKAGE_RAUC_GPT=y
|
BR2_PACKAGE_RAUC_GPT=y
|
||||||
BR2_PACKAGE_RAUC_NETWORK=y
|
BR2_PACKAGE_RAUC_NETWORK=y
|
||||||
|
BR2_PACKAGE_RAUC_JSON=y
|
||||||
BR2_PACKAGE_SYSKLOGD=y
|
BR2_PACKAGE_SYSKLOGD=y
|
||||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||||
BR2_PACKAGE_WATCHDOGD=y
|
BR2_PACKAGE_WATCHDOGD=y
|
||||||
@@ -124,13 +125,14 @@ BR2_PACKAGE_HOST_E2FSPROGS=y
|
|||||||
BR2_PACKAGE_HOST_ENVIRONMENT_SETUP=y
|
BR2_PACKAGE_HOST_ENVIRONMENT_SETUP=y
|
||||||
BR2_PACKAGE_HOST_GENEXT2FS=y
|
BR2_PACKAGE_HOST_GENEXT2FS=y
|
||||||
BR2_PACKAGE_HOST_GENIMAGE=y
|
BR2_PACKAGE_HOST_GENIMAGE=y
|
||||||
|
BR2_PACKAGE_HOST_GO_BIN=y
|
||||||
BR2_PACKAGE_HOST_MTOOLS=y
|
BR2_PACKAGE_HOST_MTOOLS=y
|
||||||
BR2_PACKAGE_HOST_RAUC=y
|
BR2_PACKAGE_HOST_RAUC=y
|
||||||
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||||
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||||
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
|
INFIX_DESC="Infix is an operating system based on Linux and modeled with YANG. It can be set up both as a switch, with offloading using switchdev, a router with firewalling, or a secure end device. All while supporting advanced networking scenarios and running Docker containers."
|
||||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||||
@@ -138,9 +140,9 @@ BR2_PACKAGE_CONFD=y
|
|||||||
BR2_PACKAGE_CONFD_TEST_MODE=y
|
BR2_PACKAGE_CONFD_TEST_MODE=y
|
||||||
BR2_PACKAGE_CURIOS_HTTPD=y
|
BR2_PACKAGE_CURIOS_HTTPD=y
|
||||||
BR2_PACKAGE_CURIOS_NFTABLES=y
|
BR2_PACKAGE_CURIOS_NFTABLES=y
|
||||||
BR2_PACKAGE_EXECD=y
|
|
||||||
BR2_PACKAGE_GENCERT=y
|
BR2_PACKAGE_GENCERT=y
|
||||||
BR2_PACKAGE_STATD=y
|
BR2_PACKAGE_STATD=y
|
||||||
|
BR2_PACKAGE_SHOW=y
|
||||||
BR2_PACKAGE_FACTORY=y
|
BR2_PACKAGE_FACTORY=y
|
||||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||||
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
||||||
@@ -151,7 +153,6 @@ BR2_PACKAGE_FINIT_RTC_FILE="/var/lib/misc/rtc"
|
|||||||
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
|
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
|
||||||
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
|
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
|
||||||
BR2_PACKAGE_IITO=y
|
BR2_PACKAGE_IITO=y
|
||||||
BR2_PACKAGE_K8S_LOGGER=y
|
|
||||||
BR2_PACKAGE_KEYACK=y
|
BR2_PACKAGE_KEYACK=y
|
||||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||||
BR2_PACKAGE_LANDING=y
|
BR2_PACKAGE_LANDING=y
|
||||||
@@ -165,7 +166,12 @@ BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
|||||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||||
BR2_PACKAGE_TETRIS=y
|
BR2_PACKAGE_TETRIS=y
|
||||||
BR2_PACKAGE_ROUSETTE=y
|
BR2_PACKAGE_ROUSETTE=y
|
||||||
|
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||||
|
BR2_PACKAGE_FEATURE_WIFI=y
|
||||||
|
BR2_PACKAGE_FEATURE_WIFI_DONGLE_REALTEK=y
|
||||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||||
|
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
||||||
|
BR2_PACKAGE_GETENT=y
|
||||||
TRUSTED_KEYS=y
|
TRUSTED_KEYS=y
|
||||||
TRUSTED_KEYS_DEVELOPMENT=y
|
TRUSTED_KEYS_DEVELOPMENT=y
|
||||||
GNS3_APPLIANCE_RAM=512
|
GNS3_APPLIANCE_RAM=512
|
||||||
|
|||||||
@@ -7,13 +7,14 @@ BR2_CCACHE=y
|
|||||||
BR2_CCACHE_DIR="${BR2_EXTERNAL_INFIX_PATH}/.ccache"
|
BR2_CCACHE_DIR="${BR2_EXTERNAL_INFIX_PATH}/.ccache"
|
||||||
BR2_ENABLE_DEBUG=y
|
BR2_ENABLE_DEBUG=y
|
||||||
BR2_GLOBAL_PATCH_DIR="${BR2_EXTERNAL_INFIX_PATH}/patches"
|
BR2_GLOBAL_PATCH_DIR="${BR2_EXTERNAL_INFIX_PATH}/patches"
|
||||||
|
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
||||||
BR2_TARGET_GENERIC_HOSTNAME="ix"
|
BR2_TARGET_GENERIC_HOSTNAME="ix"
|
||||||
BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||||
BR2_INIT_FINIT=y
|
BR2_INIT_FINIT=y
|
||||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
|
||||||
BR2_ROOTFS_MERGED_USR=y
|
BR2_ROOTFS_MERGED_USR=y
|
||||||
|
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||||
BR2_SYSTEM_BIN_SH_BASH=y
|
BR2_SYSTEM_BIN_SH_BASH=y
|
||||||
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
||||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||||
@@ -26,7 +27,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INF
|
|||||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||||
BR2_LINUX_KERNEL=y
|
BR2_LINUX_KERNEL=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.52"
|
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.35"
|
||||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||||
@@ -34,6 +35,7 @@ BR2_LINUX_KERNEL_NEEDS_HOST_LIBELF=y
|
|||||||
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
||||||
BR2_PACKAGE_STRACE=y
|
BR2_PACKAGE_STRACE=y
|
||||||
BR2_PACKAGE_STRESS_NG=y
|
BR2_PACKAGE_STRESS_NG=y
|
||||||
|
BR2_PACKAGE_SYSREPO_GROUP="sys-cli"
|
||||||
BR2_PACKAGE_JQ=y
|
BR2_PACKAGE_JQ=y
|
||||||
BR2_PACKAGE_E2FSPROGS=y
|
BR2_PACKAGE_E2FSPROGS=y
|
||||||
BR2_PACKAGE_DBUS_CXX=y
|
BR2_PACKAGE_DBUS_CXX=y
|
||||||
@@ -50,10 +52,7 @@ BR2_PACKAGE_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
|||||||
BR2_PACKAGE_UBOOT_TOOLS_FIT_CHECK_SIGN=y
|
BR2_PACKAGE_UBOOT_TOOLS_FIT_CHECK_SIGN=y
|
||||||
BR2_PACKAGE_UBOOT_TOOLS_MKENVIMAGE=y
|
BR2_PACKAGE_UBOOT_TOOLS_MKENVIMAGE=y
|
||||||
BR2_PACKAGE_PYTHON3=y
|
BR2_PACKAGE_PYTHON3=y
|
||||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
|
||||||
BR2_PACKAGE_LIBSSH2=y
|
BR2_PACKAGE_LIBSSH2=y
|
||||||
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
|
||||||
BR2_PACKAGE_LIBXCRYPT=y
|
|
||||||
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
||||||
BR2_PACKAGE_LIBCURL_CURL=y
|
BR2_PACKAGE_LIBCURL_CURL=y
|
||||||
BR2_PACKAGE_LIBMNL=y
|
BR2_PACKAGE_LIBMNL=y
|
||||||
@@ -71,6 +70,7 @@ BR2_PACKAGE_FRR=y
|
|||||||
BR2_PACKAGE_IPROUTE2=y
|
BR2_PACKAGE_IPROUTE2=y
|
||||||
BR2_PACKAGE_IPUTILS=y
|
BR2_PACKAGE_IPUTILS=y
|
||||||
BR2_PACKAGE_LLDPD=y
|
BR2_PACKAGE_LLDPD=y
|
||||||
|
BR2_PACKAGE_MSTPD=y
|
||||||
BR2_PACKAGE_NETCALC=y
|
BR2_PACKAGE_NETCALC=y
|
||||||
BR2_PACKAGE_NGINX=y
|
BR2_PACKAGE_NGINX=y
|
||||||
BR2_PACKAGE_NGINX_HTTP_SSL_MODULE=y
|
BR2_PACKAGE_NGINX_HTTP_SSL_MODULE=y
|
||||||
@@ -82,12 +82,14 @@ BR2_PACKAGE_TCPDUMP=y
|
|||||||
BR2_PACKAGE_WHOIS=y
|
BR2_PACKAGE_WHOIS=y
|
||||||
BR2_PACKAGE_BASH_COMPLETION=y
|
BR2_PACKAGE_BASH_COMPLETION=y
|
||||||
BR2_PACKAGE_SUDO=y
|
BR2_PACKAGE_SUDO=y
|
||||||
|
BR2_PACKAGE_GETENT=y
|
||||||
BR2_PACKAGE_KMOD_TOOLS=y
|
BR2_PACKAGE_KMOD_TOOLS=y
|
||||||
BR2_PACKAGE_PWGEN=y
|
BR2_PACKAGE_PWGEN=y
|
||||||
BR2_PACKAGE_RAUC=y
|
BR2_PACKAGE_RAUC=y
|
||||||
BR2_PACKAGE_RAUC_DBUS=y
|
BR2_PACKAGE_RAUC_DBUS=y
|
||||||
BR2_PACKAGE_RAUC_GPT=y
|
BR2_PACKAGE_RAUC_GPT=y
|
||||||
BR2_PACKAGE_RAUC_NETWORK=y
|
BR2_PACKAGE_RAUC_NETWORK=y
|
||||||
|
BR2_PACKAGE_RAUC_JSON=y
|
||||||
BR2_PACKAGE_SYSKLOGD=y
|
BR2_PACKAGE_SYSKLOGD=y
|
||||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||||
BR2_PACKAGE_WATCHDOGD=y
|
BR2_PACKAGE_WATCHDOGD=y
|
||||||
@@ -113,7 +115,7 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
|||||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||||
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||||
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
|
INFIX_DESC="Infix is an operating system based on Linux and modeled with YANG. It can be set up both as a switch, with offloading using switchdev, a router with firewalling, or a secure end device. All while supporting advanced networking scenarios and running Docker containers."
|
||||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||||
@@ -136,7 +138,9 @@ BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
|||||||
BR2_PACKAGE_LOWDOWN=y
|
BR2_PACKAGE_LOWDOWN=y
|
||||||
BR2_PACKAGE_MCD=y
|
BR2_PACKAGE_MCD=y
|
||||||
BR2_PACKAGE_MDNS_ALIAS=y
|
BR2_PACKAGE_MDNS_ALIAS=y
|
||||||
|
BR2_PACKAGE_SHOW=y
|
||||||
BR2_PACKAGE_ROUSETTE=y
|
BR2_PACKAGE_ROUSETTE=y
|
||||||
|
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||||
TRUSTED_KEYS=y
|
TRUSTED_KEYS=y
|
||||||
TRUSTED_KEYS_DEVELOPMENT=y
|
TRUSTED_KEYS_DEVELOPMENT=y
|
||||||
GNS3_APPLIANCE_RAM=512
|
GNS3_APPLIANCE_RAM=512
|
||||||
|
|||||||
+332
-4
@@ -3,8 +3,290 @@ Change Log
|
|||||||
|
|
||||||
All notable changes to the project are documented in this file.
|
All notable changes to the project are documented in this file.
|
||||||
|
|
||||||
|
[v25.06.0][] - 2025-07-01
|
||||||
|
-------------------------
|
||||||
|
|
||||||
[v24.10.2][UNRELEASED]
|
### Changes
|
||||||
|
- Upgrade Buildroot to 2025.02.4 (LTS)
|
||||||
|
- Upgrade Linux kernel to 6.12.35 (LTS)
|
||||||
|
- Upgrade curiOS built-in containers to v25.06.0
|
||||||
|
- Add support for setting mode of a container content mount, issue #1070
|
||||||
|
- Add Wi-Fi client support and add support for some USB-Wi-Fi cards
|
||||||
|
- New slogan: Infix OS — Immutable.Friendly.Secure
|
||||||
|
|
||||||
|
### Fixes
|
||||||
|
- cli: fix by-word movement, detect word barrier using non-alphanum chars
|
||||||
|
- cli: fix delete word left/right, make sure to save word in kill buffer
|
||||||
|
|
||||||
|
|
||||||
|
[v25.05.1][] - 2025-06-12
|
||||||
|
-------------------------
|
||||||
|
|
||||||
|
### Changes
|
||||||
|
- Upgrade Linux kernel to 6.12.32 (LTS)
|
||||||
|
|
||||||
|
### Fixes
|
||||||
|
- Fix #1060: Restore of missing CLI commands, regression in Infix v25.05.0
|
||||||
|
|
||||||
|
[v25.05.0][] - 2025-05-27
|
||||||
|
-------------------------
|
||||||
|
|
||||||
|
### Changes
|
||||||
|
- Upgrade Buildroot to 2025.02.3 (LTS)
|
||||||
|
- Upgrade Linux kernel to 6.12.30 (LTS)
|
||||||
|
- Upgrade libyang to 3.12.2
|
||||||
|
- Upgrade sysrepo to 3.6.11
|
||||||
|
- Upgrade netopeer2 (NETCONF) to 2.4.1
|
||||||
|
- New hardware support: Raspberry Pi 4B (aarch64)
|
||||||
|
- Add documentation on Infix upgrading and downgrading, issue #1009
|
||||||
|
- Add HDMI and USB support for iMX8MP-evk
|
||||||
|
- Enforced strict format for LLDP destination MAC address:
|
||||||
|
- Only accepts colon-separated format: `01:80:C2:00:00:0E`
|
||||||
|
- Add `show lldp` command to show discovered neighbors per interface.
|
||||||
|
- Add configuration support for per-interface LLDP administrative status
|
||||||
|
|
||||||
|
### Fixes
|
||||||
|
- Fix containers with multiple mounts
|
||||||
|
- Correct description for LAG LACP modes
|
||||||
|
- Fix #1040: Add `mount` constraint for container config
|
||||||
|
|
||||||
|
|
||||||
|
[v25.04.0][] - 2025-04-30
|
||||||
|
-------------------------
|
||||||
|
|
||||||
|
### Changes
|
||||||
|
- Upgrade Linux kernel to 6.12.25 (LTS)
|
||||||
|
- Upgrade Buildroot to 2025.02.1 (LTS)
|
||||||
|
- Format for disk image (for QEMU) has changed to `qcow2`
|
||||||
|
|
||||||
|
### Fixes
|
||||||
|
- Fix #1002: Broken symlink in release package
|
||||||
|
- Fix #1006: NanoPi R2S corrupt startup, regression in Infix v25.02.0
|
||||||
|
- Bump R2S kernel, now same as tier one boards
|
||||||
|
- Fix #1015: Not possible to save custom SSH settings in startup-config
|
||||||
|
- Fix group owner and permissions of `/cfg/backup` directory
|
||||||
|
- Fix extraction of old version for `/cfg/backup/` files
|
||||||
|
- Fix configuration migration issues when upgrading
|
||||||
|
|
||||||
|
[v25.03.0][] - 2025-03-31
|
||||||
|
-------------------------
|
||||||
|
|
||||||
|
> [!IMPORTANT]
|
||||||
|
> This release is the first with the new Buildroot 2025.02 (LTS)
|
||||||
|
|
||||||
|
### Changes
|
||||||
|
- Upgrade Linux kernel to 6.12.21 (LTS)
|
||||||
|
- Upgrade Buildroot to 2025.02.0 (LTS)
|
||||||
|
|
||||||
|
### Fixes
|
||||||
|
- Fix #964: YANG schema warning in syslog: missing 'monitor' node for lag
|
||||||
|
- Fix #980: the system fails to reboot when a container is (stuck), for
|
||||||
|
whatever reason, in its 'setup' state
|
||||||
|
- Fix #990: web console, ttyd service, stopped working after upgrade to
|
||||||
|
Buildroot 2025.02, caused by new (missing) option `--writable`
|
||||||
|
- Fix TCAM memory corruption in `mvpp2` Ethernet controller
|
||||||
|
- Fix annoying (but harmless) usage message from the logger tool when
|
||||||
|
`startup-config` fails to load and the system reverts to failure mode
|
||||||
|
- Fix harmless log warning for product specific init when no product
|
||||||
|
specific init scripts are found
|
||||||
|
- Backport fixes for sysklogd, affecting hostname filtering and periods
|
||||||
|
in TAG names, pending official backport in Buildroot
|
||||||
|
|
||||||
|
|
||||||
|
[v25.02.0][] - 2025-03-04
|
||||||
|
-------------------------
|
||||||
|
|
||||||
|
### Changes
|
||||||
|
- Upgrade Linux kernel to 6.12.18 (LTS)
|
||||||
|
- Upgrade Buildroot to 2024.02.11 (LTS)
|
||||||
|
- Add support for link aggregation (lag), static (balance-xor) and LACP
|
||||||
|
- Add support for the [i.MX 8M Plus EVK][EVK]
|
||||||
|
- YANG type change for SSH private/public keys, from ietf-crypto-types
|
||||||
|
to infix-crypto-types
|
||||||
|
- Disable global IPv6 forwarding by default, enable by per-interface
|
||||||
|
setting. Note, route advertisements are always accepted. Issue #785
|
||||||
|
- Drop automatic default route (interface route) for IPv4 autoconf, not
|
||||||
|
necessary and causes more confusion than good. Issue #923
|
||||||
|
- Update scripting with new RESTCONF examples
|
||||||
|
|
||||||
|
### Fixes
|
||||||
|
- Fix #896: `/etc/resolv.conf` not properly generated when system runs
|
||||||
|
in fail secure mode (failing to load `startup-config`)
|
||||||
|
- Fix #902: containers "linger" in the system (state 'exited') after
|
||||||
|
having removed them from the configuration
|
||||||
|
- Fix #930: container configuration changes does not apply at runtime
|
||||||
|
only when saved to `startup-config` and system is rebooted
|
||||||
|
- Fix #936: DHCP server reconfiguration does not always take effect.
|
||||||
|
- Fix #956: CLI `copy` command complains it cannot change owner when
|
||||||
|
copying `factory-config` to `running-config`. Bogus error, the
|
||||||
|
latter is not really a file
|
||||||
|
- Fix #977: "Operation not permitted" when saving `running-config` to
|
||||||
|
`startup-config` (harmless warning but annoying and concerning)
|
||||||
|
|
||||||
|
[EVK]: https://www.nxp.com/design/design-center/development-boards-and-designs/8MPLUSLPD4-EVK
|
||||||
|
|
||||||
|
|
||||||
|
[v25.01.0][] - 2025-01-31
|
||||||
|
-------------------------
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> This release contains breaking changes in the configuration file
|
||||||
|
> syntax for DHCP clients. Specifically DHCP options *with value*,
|
||||||
|
> i.e., the syntax for sending a hexadecimal value now require `hex`
|
||||||
|
> prefix before a string of colon-separated pairs of hex values.
|
||||||
|
|
||||||
|
### Changes
|
||||||
|
|
||||||
|
- Upgrade Linux kernel to 6.12.11 (LTS)
|
||||||
|
- Upgrade Buildroot to 2024.02.10 (LTS)
|
||||||
|
- Upgrade FRR from 9.1.2 to 9.1.3
|
||||||
|
- Add support for configuring SSH server, issue #441. As a result,
|
||||||
|
both SSH and NETCONF now use the same host key in `factory-config`
|
||||||
|
- Add operational support for reading DNS resolver info, issue #510
|
||||||
|
- Add operational support for NTP client, issue #510
|
||||||
|
- Add support for more mDNS settings: allow/deny interfaces, acting
|
||||||
|
as "reflector" and filtering of reflected services. Issue #678
|
||||||
|
- Add DHCPv4 server support, multiple subnets with static hosts and
|
||||||
|
DHCP options on global, subnet, or host level, issue #703.
|
||||||
|
Contributed by [MINEx Networks](https://minexn.com/)
|
||||||
|
- DHCP client options aligned with DHCP server, `startup-config`
|
||||||
|
files with old syntax are automatically migrated
|
||||||
|
- Breaking change in DHCP client options *with value*. Hexadecimal
|
||||||
|
values must now be formatted as `{ "hex": "c0:ff:ee" }` (JSON)
|
||||||
|
- Add documentation on management via SSH, Web (RESTCONF, Web
|
||||||
|
Console), and Console Port, issue #787
|
||||||
|
- Add documentation of DNS client use and configuration, issue #798
|
||||||
|
- Add support for changing boot order for the system with an RPC,
|
||||||
|
including support for reading boot order from operational datastore
|
||||||
|
- Add support for GRE/GRETAP tunnels
|
||||||
|
- Add support for STP/RSTP on bridges
|
||||||
|
- Add support for VXLAN tunnels
|
||||||
|
- Add support for configuring global LLDP `message-tx-interval`
|
||||||
|
|
||||||
|
### Fixes
|
||||||
|
|
||||||
|
- Fix #777: Authorized SSH key not applied to `startup-config`
|
||||||
|
- Fix #829: Avahi (mDNS responder) not starting properly on switches
|
||||||
|
with *many* ports (>10). This led to a review of `sysctl`:
|
||||||
|
- New for IPv4:
|
||||||
|
- Adjust IGMP max memberships: 20 -> 1000
|
||||||
|
- Use neighbor information on nexthop selection
|
||||||
|
- Use inbound interface address on ICMP errors
|
||||||
|
- Ignore routes with link down
|
||||||
|
- Disable `rp_filter`
|
||||||
|
- ARP settings have been changed to better fit routers, i.e.,
|
||||||
|
systems with multiple interfaces:
|
||||||
|
- Always use best local address when sending ARP
|
||||||
|
- Only reply to ARP if target IP is on the inbound interface
|
||||||
|
- Generate ARP requests when device is brought up or HW address changes
|
||||||
|
- New for IPv6:
|
||||||
|
- Keep static global addresses on link down
|
||||||
|
- Ignore routes with link down
|
||||||
|
- Fix #861: Fix error when running 251+ reconfigurations in test-mode
|
||||||
|
- Fix #869: Setup of bridges is now more robust
|
||||||
|
- Fix #899: DHCP client with client-id does not work
|
||||||
|
- Minor cleanup of Networking Guide
|
||||||
|
- Fix memory leaks in `confd`
|
||||||
|
|
||||||
|
|
||||||
|
[v24.11.1][] - 2024-11-29
|
||||||
|
-------------------------
|
||||||
|
|
||||||
|
### Changes
|
||||||
|
|
||||||
|
- Upgrade Frr to 9.1.2, fixes an OSPF issue where *Zebra* lost netlink
|
||||||
|
messages and drifted out of sync with the kernel's view of addresses
|
||||||
|
and interfaces available in the system
|
||||||
|
- Allow setting IP address directly on VLAN filtering bridges. This
|
||||||
|
only works when the bridge is an untagged member of a (single) VLAN.
|
||||||
|
- cli: usability -- showing log files now automatically jump to the end
|
||||||
|
of the file, where the latest events are
|
||||||
|
- cli: usability -- showing container status, or other status that
|
||||||
|
overflows the terminal horizontally, now wrap the lines and exit the
|
||||||
|
pager immediately if the contents fit on the first screen
|
||||||
|
- The default log level of the mDNS responder, `avahi-daemon`, has been
|
||||||
|
adjusted to make it less verbose. Now only `LOG_NOTICE` and higher
|
||||||
|
severity is logged -- making it very quiet
|
||||||
|
|
||||||
|
### Fixes
|
||||||
|
|
||||||
|
- Fix #685: DSA conduit interface not always detected. Previous
|
||||||
|
attempt at a fix (v24.10.2) mitigated the issue, but did not
|
||||||
|
completely solve it.
|
||||||
|
- Fix #835: redesign how the system creates/deletes containers from the
|
||||||
|
`running-config`. Prior to this change, all removal and creation was
|
||||||
|
handled by a separate queue that ran asynchronously from the `confd`
|
||||||
|
process. This could lead to situations where new configurations are
|
||||||
|
applied before the queue had been fully processed. After this change
|
||||||
|
containers are deleted synchronously and new containers are created
|
||||||
|
in the same flow as during normal runtime operation (start/upgrade)
|
||||||
|
- Fix start of containers with `manual=True` option should now work
|
||||||
|
again, regression in v24.11.0
|
||||||
|
- Fix loss of writable volumes when temporarily disabling a container
|
||||||
|
in the configuration, now the container remains dormant with all its
|
||||||
|
volumes still available
|
||||||
|
- Fix presentation bug in CLI `show interfaces` where all line-drawing
|
||||||
|
characters showed up as hexadecimal values. Regression in v24.11.0
|
||||||
|
- Fix missing log messages from Frr Zebra daemon
|
||||||
|
- Stop the zeroconf (IPv4LL) agent, `avahi-autoipd`, when removing an
|
||||||
|
interface, e.g., `br0`
|
||||||
|
- Creating more than one container trigger restarts of previously set
|
||||||
|
up containers. Which in some cases may cause these earlier ones to
|
||||||
|
end up in an inconsistent state
|
||||||
|
- Prevent traffic assigned to locally terminated VLANs from being
|
||||||
|
forwarded, when the underlying ports are simultaneously attached to
|
||||||
|
a VLAN filtering bridge.
|
||||||
|
|
||||||
|
|
||||||
|
[v24.11.0][] - 2024-11-20
|
||||||
|
-------------------------
|
||||||
|
|
||||||
|
> [!CAUTION]
|
||||||
|
> This release contains breaking changes for container users! As of
|
||||||
|
> v24.11.0, all persistent[^1] containers always run in `read-only` mode
|
||||||
|
> and the setting itself is deprecated (kept only for compatibility
|
||||||
|
> reasons). The main reason for this change is to better serve users
|
||||||
|
> with embedded container images in their builds of Infix. I.e., they
|
||||||
|
> can now upgrade the OCI image in their build and rely on the container
|
||||||
|
> being automatically upgraded when Infix is upgraded, issue #823. For
|
||||||
|
> other users, the benefit is that *all* container configuration changes
|
||||||
|
> take when activated, issue #822, without having to perform any tricks.
|
||||||
|
|
||||||
|
### Changes
|
||||||
|
|
||||||
|
- Add validation of interface name lengths, (1..15), Linux limit
|
||||||
|
- Add support for ftp/http/https URI:s in container image, with a new
|
||||||
|
`checksum` setting for MD5/SHA256/SHA512 verification, issue #801
|
||||||
|
- Add a retry timer to the background container create service. This
|
||||||
|
will ensure failing `docker pull` operations from remote images are
|
||||||
|
retrying after 60 seconds, or quicker
|
||||||
|
- CLI base component, `klish`, has been updated with better support for
|
||||||
|
raw terminal mode and alternate quotes (' in addition to ")
|
||||||
|
- Log silenced from container activation messages, only the very bare
|
||||||
|
necessities are now logged, e.g., `podman create` command + status
|
||||||
|
- Factory reset no longer calls `shred` to "securely erase" any files
|
||||||
|
from writable data partitions. This will speed up the next boot
|
||||||
|
considerably
|
||||||
|
|
||||||
|
### Fixes
|
||||||
|
|
||||||
|
- Fix #659: paged output in CLI accessed via console port sometimes
|
||||||
|
causes lost lines, e.g. missing interfaces. With updated `klish`
|
||||||
|
and the terminal in raw mode, the pager (less) can now control both
|
||||||
|
the horizontal and vertical
|
||||||
|
- Fix #822: adding, or changing, an environment variable to a running
|
||||||
|
container does not take without the `container upgrade NAME` trick
|
||||||
|
- Fix #823: with an OCI image embedded in the Infix image, an existing
|
||||||
|
container in the configuration is not upgraded to the new OCI image
|
||||||
|
with the Infix upgrade.
|
||||||
|
- Frr leaves log files in `/var/tmp/frr` on unclean shutdowns. This
|
||||||
|
has now been fixed with a "tmpfiles" cleanup of that path at boot
|
||||||
|
|
||||||
|
[^1]: I.e., set up in the configuration, as opposed to temporary ones
|
||||||
|
started with `container run` from the CLI admin-exec context.
|
||||||
|
|
||||||
|
|
||||||
|
[v24.10.2][] - 2024-11-08
|
||||||
-------------------------
|
-------------------------
|
||||||
|
|
||||||
### Changes
|
### Changes
|
||||||
@@ -22,23 +304,44 @@ All notable changes to the project are documented in this file.
|
|||||||
- Support for saving and restoring system clock from a disk file. This
|
- Support for saving and restoring system clock from a disk file. This
|
||||||
allows restoring the system clock to a sane date in case the RTC is
|
allows restoring the system clock to a sane date in case the RTC is
|
||||||
disabled or does not have a valid time, issue #794
|
disabled or does not have a valid time, issue #794
|
||||||
|
- Update device discovery chapter with information on `infix.local` mDNS
|
||||||
|
alias, `netbrowse` support to discover *all* local units, and command
|
||||||
|
examples for disabling LLDP and mDNS services, issue #786
|
||||||
|
- Updated OSPF documentation to include information on *global OSPF
|
||||||
|
settings* (`redistribution`, `explicit-router-id`, etc.), issue #812
|
||||||
|
- Added information on *forwarding of IEEE reserved group addresses*
|
||||||
|
to bridge section of networking documentation, issue #788
|
||||||
|
- Add support for bootstrap conditions and early init product overrides
|
||||||
|
- Styx: enable second Ethernet port LED in device tree, again, rename
|
||||||
|
it: yellow -> aux, and make sure it is turned off at boot
|
||||||
|
- Styx: disable second port LED for the 4xSFP slots, does not work
|
||||||
|
- Styx: override iitod (LED daemon) with a product specific LED script
|
||||||
|
|
||||||
### Fixes
|
### Fixes
|
||||||
|
|
||||||
- Fix #685: DSA conduit interface not always detected, randomly causing
|
- Fix #685: DSA conduit interface not always detected, randomly causing
|
||||||
major issues configuring systems with multiple switch cores
|
major issues configuring systems with multiple switch cores
|
||||||
- Fix #778: reactivate OpenSSL backend for libssh/libssh2 for NanoPI R2S.
|
- Fix #778: reactivate OpenSSL backend for libssh/libssh2 for NanoPI R2S.
|
||||||
This fixes a regression in v24.10.0 causing loss of NETCONF supprt
|
This fixes a regression in v24.10.0 causing loss of NETCONF support
|
||||||
|
- Fix #809: enable syslog logging for RAUC
|
||||||
|
- Fix harmless bootstrap log error message on systems without USB ports:
|
||||||
|
`jq: error (at <stdin>:0): Cannot iterate over null (null)`
|
||||||
|
- Change confusing `tc` log error message: `Error: does not support
|
||||||
|
hardware offload` to `Skipping $iface, hardware offload not supported.`
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
[v24.10.1][] - 2024-10-18
|
[v24.10.1][] - 2024-10-18
|
||||||
-------------------------
|
-------------------------
|
||||||
|
|
||||||
### Changes
|
### Changes
|
||||||
|
|
||||||
- Add support for interface description, sometimes referred to as
|
- Add support for interface description, sometimes referred to as
|
||||||
"ifAlias". Saved as an Linux interface alias (not `altname`), e.g.,
|
"ifAlias". Saved as an Linux interface alias (not `altname`), e.g.,
|
||||||
`/sys/class/interfaces/veth0a/ifalias`, includes operational support
|
`/sys/class/interfaces/veth0a/ifalias`, includes operational support
|
||||||
|
|
||||||
### Fixes
|
### Fixes
|
||||||
|
|
||||||
- Fix #735: `copy` and `erase` commands missing from CLI, regression
|
- Fix #735: `copy` and `erase` commands missing from CLI, regression
|
||||||
in Infix v24.10.0 defconfigs, now added as dep. in klish package
|
in Infix v24.10.0 defconfigs, now added as dep. in klish package
|
||||||
|
|
||||||
@@ -53,7 +356,9 @@ Also, heads-up to all downstream users of Infix. YANG models have been
|
|||||||
renamed to ease maintenance, more info below.
|
renamed to ease maintenance, more info below.
|
||||||
|
|
||||||
### Changes
|
### Changes
|
||||||
|
|
||||||
- Software control of port LEDs on the Styx platform has been disabled.
|
- Software control of port LEDs on the Styx platform has been disabled.
|
||||||
|
|
||||||
Default driver behavior, green link and green traffic blink, is kept
|
Default driver behavior, green link and green traffic blink, is kept
|
||||||
as-is, which should mitigate issues reported in #670
|
as-is, which should mitigate issues reported in #670
|
||||||
- Correcting documentation on QoS. For packets containing both a VLAN
|
- Correcting documentation on QoS. For packets containing both a VLAN
|
||||||
@@ -89,6 +394,7 @@ renamed to ease maintenance, more info below.
|
|||||||
see <https://kernelkit.org/posts/firewall-container/>
|
see <https://kernelkit.org/posts/firewall-container/>
|
||||||
|
|
||||||
### Fixes
|
### Fixes
|
||||||
|
|
||||||
- Fix #499: add an NACM rule to factory-config, which by default deny
|
- Fix #499: add an NACM rule to factory-config, which by default deny
|
||||||
everyone to read user password hash(es)
|
everyone to read user password hash(es)
|
||||||
- Fix #663: internal Ethernet interfaces shown in CLI tab completion
|
- Fix #663: internal Ethernet interfaces shown in CLI tab completion
|
||||||
@@ -100,7 +406,7 @@ renamed to ease maintenance, more info below.
|
|||||||
with `custom-phys-address` to allow for constructing more free-form
|
with `custom-phys-address` to allow for constructing more free-form
|
||||||
MAC addresses based on the chassis MAC (a.k.a., base MAC) address.
|
MAC addresses based on the chassis MAC (a.k.a., base MAC) address.
|
||||||
For more information, see the YANG model, a few examples are listed in
|
For more information, see the YANG model, a few examples are listed in
|
||||||
the updated documentation.
|
the updated documentation.
|
||||||
The syntax will be automatically updated in the `startup-config` and
|
The syntax will be automatically updated in the `startup-config` and
|
||||||
`factory-config` -- make sure to verify the changes and update any
|
`factory-config` -- make sure to verify the changes and update any
|
||||||
static `factory-config` used for your products
|
static `factory-config` used for your products
|
||||||
@@ -137,6 +443,7 @@ also been added to facilitate site specific adaptations. Please see the
|
|||||||
documentation for details.
|
documentation for details.
|
||||||
|
|
||||||
### Known Issues
|
### Known Issues
|
||||||
|
|
||||||
- The CLI command `show interfaces` may for some terminal resolutions
|
- The CLI command `show interfaces` may for some terminal resolutions
|
||||||
not display all interfaces (on systems with >20 interfaces). This
|
not display all interfaces (on systems with >20 interfaces). This
|
||||||
problem is limited to the console port and only occurs for smaller
|
problem is limited to the console port and only occurs for smaller
|
||||||
@@ -145,6 +452,7 @@ documentation for details.
|
|||||||
using the CLI from an SSH session, is not affected. Issue #659
|
using the CLI from an SSH session, is not affected. Issue #659
|
||||||
|
|
||||||
### Changes
|
### Changes
|
||||||
|
|
||||||
- Upgrade Buildroot to 2024.02.6 (LTS)
|
- Upgrade Buildroot to 2024.02.6 (LTS)
|
||||||
- Upgrade Linux kernel to 6.6.52 (LTS)
|
- Upgrade Linux kernel to 6.6.52 (LTS)
|
||||||
- Upgrade libyang to 3.4.2
|
- Upgrade libyang to 3.4.2
|
||||||
@@ -164,6 +472,7 @@ documentation for details.
|
|||||||
by `mctl` reporting no multicast filtering enabled on bridge
|
by `mctl` reporting no multicast filtering enabled on bridge
|
||||||
|
|
||||||
### Fixes
|
### Fixes
|
||||||
|
|
||||||
- Fix #357: EUI-64 based IPv6 autoconf address on bridges seem to be
|
- Fix #357: EUI-64 based IPv6 autoconf address on bridges seem to be
|
||||||
randomized. Problem caused by kernel setting a random MAC before any
|
randomized. Problem caused by kernel setting a random MAC before any
|
||||||
bridge port is added. Fixed by using the device's base MAC address on
|
bridge port is added. Fixed by using the device's base MAC address on
|
||||||
@@ -226,6 +535,7 @@ Finally, the following consumer boards are now fully supported:
|
|||||||
- StarFive VisionFive2 (RISC-V)
|
- StarFive VisionFive2 (RISC-V)
|
||||||
|
|
||||||
### Changes
|
### Changes
|
||||||
|
|
||||||
- Upgrade Buildroot to 2024.02.5 (LTS)
|
- Upgrade Buildroot to 2024.02.5 (LTS)
|
||||||
- Upgrade Linux kernel to 6.6.46 (LTS)
|
- Upgrade Linux kernel to 6.6.46 (LTS)
|
||||||
- Issue #158: enhance security of factory reset. All file content
|
- Issue #158: enhance security of factory reset. All file content
|
||||||
@@ -277,6 +587,7 @@ Finally, the following consumer boards are now fully supported:
|
|||||||
log messages. See `/var/log/debug` for *all* log messages
|
log messages. See `/var/log/debug` for *all* log messages
|
||||||
|
|
||||||
### Fixes
|
### Fixes
|
||||||
|
|
||||||
- Fix #274: add missing link/traffic LEDs on NanoPi R2S LAN port
|
- Fix #274: add missing link/traffic LEDs on NanoPi R2S LAN port
|
||||||
- Fix #489: ensure all patches are versioned, including Linux kernel
|
- Fix #489: ensure all patches are versioned, including Linux kernel
|
||||||
- Fix #531: creating a new VLAN interface named `vlanN` should not set
|
- Fix #531: creating a new VLAN interface named `vlanN` should not set
|
||||||
@@ -306,6 +617,7 @@ Finally, the following consumer boards are now fully supported:
|
|||||||
> upgrade, but before reboot, a factory reset is required!
|
> upgrade, but before reboot, a factory reset is required!
|
||||||
|
|
||||||
### Changes
|
### Changes
|
||||||
|
|
||||||
- Upgrade Buildroot to 2024.02.3 (LTS)
|
- Upgrade Buildroot to 2024.02.3 (LTS)
|
||||||
- Upgrade Linux kernel to 6.6.34 (LTS)
|
- Upgrade Linux kernel to 6.6.34 (LTS)
|
||||||
- Upgrade bundled curiOS httpd container to v24.05.0
|
- Upgrade bundled curiOS httpd container to v24.05.0
|
||||||
@@ -372,6 +684,7 @@ Finally, the following consumer boards are now fully supported:
|
|||||||
[yescrypt]: https://en.wikipedia.org/wiki/Yescrypt
|
[yescrypt]: https://en.wikipedia.org/wiki/Yescrypt
|
||||||
|
|
||||||
### Fixes
|
### Fixes
|
||||||
|
|
||||||
- Fix #424: regression, root user can log in without password
|
- Fix #424: regression, root user can log in without password
|
||||||
- Fix build regressions in `cn9130_crb_boot_defconfig` caused by upgrade
|
- Fix build regressions in `cn9130_crb_boot_defconfig` caused by upgrade
|
||||||
to Buildroot v2024.02 and recent multi-key support in RAUC and U-Boot
|
to Buildroot v2024.02 and recent multi-key support in RAUC and U-Boot
|
||||||
@@ -403,11 +716,13 @@ Finally, the following consumer boards are now fully supported:
|
|||||||
-------------------------
|
-------------------------
|
||||||
|
|
||||||
### Changes
|
### Changes
|
||||||
|
|
||||||
- Add small delay in U-Boot to allow stopping boot on reference boards
|
- Add small delay in U-Boot to allow stopping boot on reference boards
|
||||||
- Document how to provision the bootloader and Infix on a blank board
|
- Document how to provision the bootloader and Infix on a blank board
|
||||||
- Use initial hostname from `/etc/os-release` as configuration fallback
|
- Use initial hostname from `/etc/os-release` as configuration fallback
|
||||||
|
|
||||||
### Fixes
|
### Fixes
|
||||||
|
|
||||||
- Fix build regressions in `cn9130_crb_boot_defconfig` caused by upgrade
|
- Fix build regressions in `cn9130_crb_boot_defconfig` caused by upgrade
|
||||||
to Buildroot v2024.02 and recent multi-key support in RAUC and U-Boot
|
to Buildroot v2024.02 and recent multi-key support in RAUC and U-Boot
|
||||||
- Fix provisioning script after changes to make GRUB loading more robust
|
- Fix provisioning script after changes to make GRUB loading more robust
|
||||||
@@ -422,6 +737,7 @@ Finally, the following consumer boards are now fully supported:
|
|||||||
-------------------------
|
-------------------------
|
||||||
|
|
||||||
### Changes
|
### Changes
|
||||||
|
|
||||||
- Default web landing page refactored into a Buildroot package to make
|
- Default web landing page refactored into a Buildroot package to make
|
||||||
it possible to overload from customer repos.
|
it possible to overload from customer repos.
|
||||||
- Enable DCB support in aarch64 kernel (for EtherType prio override)
|
- Enable DCB support in aarch64 kernel (for EtherType prio override)
|
||||||
@@ -432,6 +748,7 @@ Finally, the following consumer boards are now fully supported:
|
|||||||
- Issue #374: add timestamps to dagger .log files
|
- Issue #374: add timestamps to dagger .log files
|
||||||
|
|
||||||
### Fixes
|
### Fixes
|
||||||
|
|
||||||
- Add missing LICENSE hash for factory reset tool
|
- Add missing LICENSE hash for factory reset tool
|
||||||
- Fix #424: regression, root user can log in without password
|
- Fix #424: regression, root user can log in without password
|
||||||
|
|
||||||
@@ -453,6 +770,7 @@ idea is to generate supported features from the models and include in
|
|||||||
future releases.
|
future releases.
|
||||||
|
|
||||||
### Changes
|
### Changes
|
||||||
|
|
||||||
- Bump the base Buildroot version to v2024.02 LTS
|
- Bump the base Buildroot version to v2024.02 LTS
|
||||||
- Bump the base Linux kernel version to 6.6 LTS
|
- Bump the base Linux kernel version to 6.6 LTS
|
||||||
- Drop Classic variant to reduce overhead, simplify build & release
|
- Drop Classic variant to reduce overhead, simplify build & release
|
||||||
@@ -533,6 +851,7 @@ future releases.
|
|||||||
named 'default'
|
named 'default'
|
||||||
|
|
||||||
### Fixes
|
### Fixes
|
||||||
|
|
||||||
- confd: Fix memory leak when operating on candidate configuration
|
- confd: Fix memory leak when operating on candidate configuration
|
||||||
- probe: Fix crash on systems without USB
|
- probe: Fix crash on systems without USB
|
||||||
- Reduced syslog errors for accesses no non-existing xpaths
|
- Reduced syslog errors for accesses no non-existing xpaths
|
||||||
@@ -1275,7 +1594,16 @@ Supported YANG models in addition to those used by sysrepo and netopeer:
|
|||||||
- N/A
|
- N/A
|
||||||
|
|
||||||
[buildroot]: https://buildroot.org/
|
[buildroot]: https://buildroot.org/
|
||||||
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v24.10.1...HEAD
|
[v25.06.0]: https://github.com/kernelkit/infix/compare/v25.05.1...v26.06.0
|
||||||
|
[v25.05.1]: https://github.com/kernelkit/infix/compare/v25.05.0...v25.05.1
|
||||||
|
[v25.05.0]: https://github.com/kernelkit/infix/compare/v25.04.0...v25.05.0
|
||||||
|
[v25.04.0]: https://github.com/kernelkit/infix/compare/v25.03.0...v25.04.0
|
||||||
|
[v25.03.0]: https://github.com/kernelkit/infix/compare/v25.02.0...v25.03.0
|
||||||
|
[v25.02.0]: https://github.com/kernelkit/infix/compare/v25.01.0...v25.02.0
|
||||||
|
[v25.01.0]: https://github.com/kernelkit/infix/compare/v24.11.0...v25.01.0
|
||||||
|
[v24.11.1]: https://github.com/kernelkit/infix/compare/v24.11.0...v24.11.1
|
||||||
|
[v24.11.0]: https://github.com/kernelkit/infix/compare/v24.10.0...v24.11.0
|
||||||
|
[v24.10.2]: https://github.com/kernelkit/infix/compare/v24.10.1...v24.10.2
|
||||||
[v24.10.1]: https://github.com/kernelkit/infix/compare/v24.10.0...v24.10.1
|
[v24.10.1]: https://github.com/kernelkit/infix/compare/v24.10.0...v24.10.1
|
||||||
[v24.10.0]: https://github.com/kernelkit/infix/compare/v24.09.0...v24.10.0
|
[v24.10.0]: https://github.com/kernelkit/infix/compare/v24.09.0...v24.10.0
|
||||||
[v24.09.0]: https://github.com/kernelkit/infix/compare/v24.08.0...v24.09.0
|
[v24.09.0]: https://github.com/kernelkit/infix/compare/v24.08.0...v24.09.0
|
||||||
|
|||||||
+11
-7
@@ -1,13 +1,16 @@
|
|||||||
|
<img align="right" src="logo.png" alt="Infix - Linux <3 NETCONF" width=480 border=10>
|
||||||
|
|
||||||
Welcome to Infix, your friendly Network Operating System! On these
|
Welcome to Infix, your immutable, friendly, and secure operating system!
|
||||||
pages you can find both user and developer documentation.
|
On these pages you can find both user and developer documentation.
|
||||||
|
|
||||||
> Topics on configuring the system include CLI examples, every setting
|
Most topics on configuring the system include CLI examples, but every
|
||||||
> is also possible to perform using NETCONF. In fact, the Infix test
|
setting, as well as status read-back from the operational datastore, is
|
||||||
> system solely relies on NETCONF for configuring network topologies.
|
also possible to perform using NETCONF or RESTCONF. In fact, the Infix
|
||||||
|
regression test system solely relies on NETCONF and RESTCONF.
|
||||||
|
|
||||||
The CLI documentation is also available from inside the CLI itself using
|
> [!TIP]
|
||||||
the `help` command.
|
> The CLI documentation is also available from inside the CLI itself
|
||||||
|
> using the `help` command in admin-exec mode.
|
||||||
|
|
||||||
- **CLI Topics**
|
- **CLI Topics**
|
||||||
- [Introduction to the CLI](cli/introduction.md)
|
- [Introduction to the CLI](cli/introduction.md)
|
||||||
@@ -18,6 +21,7 @@ the `help` command.
|
|||||||
- [Introduction](introduction.md)
|
- [Introduction](introduction.md)
|
||||||
- [System Configuration](system.md)
|
- [System Configuration](system.md)
|
||||||
- [Network Configuration](networking.md)
|
- [Network Configuration](networking.md)
|
||||||
|
- [DHCP Server](dhcp.md)
|
||||||
- [Syslog Support](syslog.md)
|
- [Syslog Support](syslog.md)
|
||||||
- **Infix In-Depth**
|
- **Infix In-Depth**
|
||||||
- [Boot Procedure](boot.md)
|
- [Boot Procedure](boot.md)
|
||||||
|
|||||||
+6
-3
@@ -63,7 +63,7 @@ bootloader's validation procedure, user configuration is kept to a
|
|||||||
minimum. Two settings are available:
|
minimum. Two settings are available:
|
||||||
|
|
||||||
- **Boot order**: Since Infix maintains two copies of its software image,
|
- **Boot order**: Since Infix maintains two copies of its software image,
|
||||||
and as some bootloaders support netbooting, the order in which boot
|
and as some bootloaders support [netbooting][2], the order in which boot
|
||||||
sources are considered can be configured. To select the active
|
sources are considered can be configured. To select the active
|
||||||
source, use [RAUC][]:
|
source, use [RAUC][]:
|
||||||
|
|
||||||
@@ -349,5 +349,8 @@ can funtion reasonably well without a persistent `/var`, loosing
|
|||||||
If `var` is not available, Infix will still persist `/var/lib` using
|
If `var` is not available, Infix will still persist `/var/lib` using
|
||||||
`cfg` as the backing storage.
|
`cfg` as the backing storage.
|
||||||
|
|
||||||
[^1]: See [CLI Upgrade](cli/upgrade.md) for information on upgrading
|
[^1]: See [Upgrading procedures and boot
|
||||||
via CLI.
|
order](system.md#upgrade-procedures-and-boot-order) for
|
||||||
|
information on upgrading via CLI.
|
||||||
|
|
||||||
|
[2]: netboot.md
|
||||||
|
|||||||
+47
-19
@@ -60,14 +60,14 @@ rootfs overlay -- with a [VPD](vpd.md) you can even support several!
|
|||||||
### Variables & Format Specifiers
|
### Variables & Format Specifiers
|
||||||
|
|
||||||
Parts of the configuration you likely always want to generated, like the
|
Parts of the configuration you likely always want to generated, like the
|
||||||
SSH hostkey used by NETCONF, a unique hostname, or the `admin` user's
|
SSH hostkey used by SSH server and NETCONF, a unique hostname, or the `admin` user's
|
||||||
unique (per-device with a VPD) password hash. This section lists the
|
unique (per-device with a VPD) password hash. This section lists the
|
||||||
available keywords, see the next section for examples of how to use
|
available keywords, see the next section for examples of how to use
|
||||||
them:
|
them:
|
||||||
|
|
||||||
- **Default password hash:** `$factory$` (from VPD, .dtb, or built-in)
|
- **Default password hash:** `$factory$` (from VPD, .dtb, or built-in)
|
||||||
XPath: `/ietf-system:system/authentication/user/password`
|
XPath: `/ietf-system:system/authentication/user/password`
|
||||||
- **Default NETCONF hostkey:** `genkey` (regenerated at factory reset)
|
- **Default SSH and NETCONF hostkey:** `genkey` (regenerated at factory reset)
|
||||||
XPath: `/ietf-keystore:keystore/asymmetric-keys/asymmetric-key[name='genkey']`
|
XPath: `/ietf-keystore:keystore/asymmetric-keys/asymmetric-key[name='genkey']`
|
||||||
- **Hostname format specifiers:**
|
- **Hostname format specifiers:**
|
||||||
XPath: `/ietf-system:system/hostname`
|
XPath: `/ietf-system:system/hostname`
|
||||||
@@ -214,15 +214,15 @@ text file without line breaks (`-w0`):
|
|||||||
```bash
|
```bash
|
||||||
$ echo "Li0tLS0tLS0uCnwgIC4gLiAgfCBJbmZpeCAtLSBhIE5ldHdvcmsgT3BlcmF0aW5nIFN5c3RlbQp8LS4gdiAuLXwgaHR0cHM6Ly9rZXJuZWxraXQuZ2l0aHViLmlvCictJy0tLSctJwo=" |base64 -d
|
$ echo "Li0tLS0tLS0uCnwgIC4gLiAgfCBJbmZpeCAtLSBhIE5ldHdvcmsgT3BlcmF0aW5nIFN5c3RlbQp8LS4gdiAuLXwgaHR0cHM6Ly9rZXJuZWxraXQuZ2l0aHViLmlvCictJy0tLSctJwo=" |base64 -d
|
||||||
.-------.
|
.-------.
|
||||||
| . . | Infix -- a Network Operating System
|
| . . | Infix OS — Immutable.Friendly.Secure
|
||||||
|-. v .-| https://kernelkit.github.io
|
|-. v .-| https://kernelkit.github.io
|
||||||
'-'---'-'
|
'-'---'-'
|
||||||
```
|
```
|
||||||
|
|
||||||
**IETF Keystore**
|
**IETF Keystore**
|
||||||
|
|
||||||
Notice how both the public and private keys are left empty here. The
|
Notice how both the public and private keys are left empty here, this
|
||||||
`genkey` is always automatically regenerated after each factory reset.
|
cause them to be always automatically regenerated after each factory reset.
|
||||||
Keeping the `factory-config` snippet like this means we can use the same
|
Keeping the `factory-config` snippet like this means we can use the same
|
||||||
file on multiple devices, without risking them sharing the same host
|
file on multiple devices, without risking them sharing the same host
|
||||||
keys. Sometimes you may want the same host keys, but that is the easy
|
keys. Sometimes you may want the same host keys, but that is the easy
|
||||||
@@ -245,8 +245,6 @@ use-case and not documented here.
|
|||||||
},
|
},
|
||||||
```
|
```
|
||||||
|
|
||||||
The `genkey` is currently only used by the NETCONF SSH backend.
|
|
||||||
|
|
||||||
**IETF NETCONF Server**
|
**IETF NETCONF Server**
|
||||||
|
|
||||||
```json
|
```json
|
||||||
@@ -280,6 +278,28 @@ The `genkey` is currently only used by the NETCONF SSH backend.
|
|||||||
},
|
},
|
||||||
```
|
```
|
||||||
|
|
||||||
|
**Infix Services**
|
||||||
|
```json
|
||||||
|
"infix-services:ssh": {
|
||||||
|
"enabled": true,
|
||||||
|
"hostkey": [
|
||||||
|
"genkey"
|
||||||
|
],
|
||||||
|
"listen": [
|
||||||
|
{
|
||||||
|
"name": "ipv4",
|
||||||
|
"address": "0.0.0.0",
|
||||||
|
"port": 22
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "ipv6",
|
||||||
|
"address": "::1",
|
||||||
|
"port": 22
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
Integration
|
Integration
|
||||||
@@ -370,22 +390,30 @@ But you can of course use only two numbers, *major.minor*, as well.
|
|||||||
> with your own versioning scheme.
|
> with your own versioning scheme.
|
||||||
|
|
||||||
|
|
||||||
### `INFIX_RELEASE`
|
### Specifying Versioning Information
|
||||||
|
|
||||||
This global variable **must be** a lower-case string (no spaces or
|
Two optional environment variables control the version information
|
||||||
other characters outside of 0–9, a–z, '.', '_' and '-') identifying
|
recorded in images. Both of these **must be** a lower-case string (no
|
||||||
the operating system version, excluding any OS name information or
|
spaces or other characters outside of 0–9, a–z, '.', '_' and '-')
|
||||||
release code name, and suitable for processing by scripts or usage
|
identifying the operating system version, excluding any OS name
|
||||||
in generated filenames.
|
information or release code name, and suitable for processing by
|
||||||
|
scripts or usage in generated filenames.
|
||||||
|
|
||||||
|
#### `INFIX_BUILD_ID`
|
||||||
|
|
||||||
|
Used for `BUILD_ID` in `/etc/os-release`.
|
||||||
|
|
||||||
|
**Default:** `$(git describe --always --dirty --tags)`, from the _top
|
||||||
|
directory_. By default, the top directory refers to the root of the
|
||||||
|
Infix source tree, but this can be changed by setting the branding
|
||||||
|
variable `INFIX_OEM_PATH`, e.g. in a `defconfig` file or via `make
|
||||||
|
menuconfig`, to the path of an enclosing br2-external.
|
||||||
|
|
||||||
|
#### `INFIX_RELEASE`
|
||||||
|
|
||||||
Used for `VERSION` and `VERSION_ID` in `/etc/os-release` and
|
Used for `VERSION` and `VERSION_ID` in `/etc/os-release` and
|
||||||
generated file names like disk images, etc.
|
generated file names like disk images, etc.
|
||||||
|
|
||||||
**Default:** generated using `git describe --always --dirty --tags`,
|
**Default:** `${INFIX_BUILD_ID}`
|
||||||
with an additional `-C $infix_path`. This variable defaults to the
|
|
||||||
Infix tree and can be changed by setting the menuconfig branding
|
|
||||||
variable `INFIX_OEM_PATH` to that of the br2-external. It is also
|
|
||||||
possible to set the `GIT_VERSION` variable in your `post-build.sh`
|
|
||||||
script to change how the VCS version is extracted.
|
|
||||||
|
|
||||||
[NanoPi R2S]: https://github.com/kernelkit/infix/blob/main/board/aarch64/r2s/rootfs/etc/factory-config.cfg
|
[NanoPi R2S]: https://github.com/kernelkit/infix/blob/main/board/aarch64/r2s/rootfs/etc/factory-config.cfg
|
||||||
|
|||||||
@@ -39,7 +39,12 @@ The secondary partition (`rootfs.1`) has now been upgraded and will be used as
|
|||||||
the *active* partition on the next boot. Leaving the primary partition, with
|
the *active* partition on the next boot. Leaving the primary partition, with
|
||||||
the version we are currently running, intact in case of trouble.
|
the version we are currently running, intact in case of trouble.
|
||||||
|
|
||||||
|
See [upgrading procedures and boot order][2] for more information on
|
||||||
|
upgrading.
|
||||||
|
|
||||||
[^1]: It is not possible to upgrade the partition we booted from. Thankfully
|
[^1]: It is not possible to upgrade the partition we booted from. Thankfully
|
||||||
the underlying "rauc" subsystem keeps track of this. Hence, to upgrade
|
the underlying "rauc" subsystem keeps track of this. Hence, to upgrade
|
||||||
both partitions you must reboot to the new version (to verify it works)
|
both partitions you must reboot to the new version (to verify it works)
|
||||||
and then repeat the same command.
|
and then repeat the same command.
|
||||||
|
|
||||||
|
[2]: ../system.md#upgrade-procedures-and-boot-order
|
||||||
|
|||||||
+257
-99
@@ -20,6 +20,9 @@ Containers in Infix
|
|||||||
* [Application Container: ntpd](#application-container-ntpd)
|
* [Application Container: ntpd](#application-container-ntpd)
|
||||||
* [Advanced](#advanced)
|
* [Advanced](#advanced)
|
||||||
* [Running Host Commands From Container](#running-host-commands-from-container)
|
* [Running Host Commands From Container](#running-host-commands-from-container)
|
||||||
|
* [Container Requirements](#container-requirements)
|
||||||
|
* [Advanced Users](#advanced-users)
|
||||||
|
|
||||||
|
|
||||||
Introduction
|
Introduction
|
||||||
------------
|
------------
|
||||||
@@ -28,18 +31,19 @@ Infix comes with native support for Docker containers using [podman][].
|
|||||||
The [YANG model][1] describes the current level of support, complete
|
The [YANG model][1] describes the current level of support, complete
|
||||||
enough to run both system and application containers.
|
enough to run both system and application containers.
|
||||||
|
|
||||||
Key design features, like using Linux switchdev, allow users to assign
|
Key design features of Infix, like using Linux switchdev, allow users to
|
||||||
switch ports directly to containers, not just bridged VETH pairs, this
|
assign switch ports directly to containers, not just bridged VETH pairs.
|
||||||
is a rare and in many cases *unique* feature of Infix.
|
This is a rare and in many cases *unique* feature of Infix.
|
||||||
|
|
||||||
All network specific settings are done using the IETF interfaces YANG
|
All network specific settings are done using the IETF interfaces YANG
|
||||||
model, with augments for containers to ensure smooth integration with
|
model, with augments for containers to ensure smooth integration with
|
||||||
container networking in podman.
|
container networking in podman.
|
||||||
|
|
||||||
> **Note:** even though the `podman` command can be used directly from a
|
> [!IMPORTANT]
|
||||||
> shell prompt, we strongly recommend using the CLI commands instead.
|
> Even though the `podman` command can be used directly from a shell
|
||||||
> They employ the services of a wrapper `container` script which handles
|
> prompt, we strongly recommend using the CLI commands instead. They
|
||||||
> the integration of containers in the system.
|
> employ the services of a wrapper `container` script which handles the
|
||||||
|
> integration of Docker containers in the system.
|
||||||
|
|
||||||
|
|
||||||
Caution
|
Caution
|
||||||
@@ -79,30 +83,32 @@ In the CLI, containers can be run in one of two ways:
|
|||||||
1. `container run IMAGE [COMMAND]`, or
|
1. `container run IMAGE [COMMAND]`, or
|
||||||
2. enter `configure` context, then `edit container NAME`
|
2. enter `configure` context, then `edit container NAME`
|
||||||
|
|
||||||
The former is useful mostly for testing, or running single commands in
|
The first is useful mostly for testing, or running single commands in
|
||||||
an image. It is a wrapper for `podman run -it --rm ...`, while the
|
an image. It is a wrapper for `podman run -it --rm ...`.
|
||||||
latter is a wrapper and adaptation of `podman create ...`.
|
|
||||||
|
|
||||||
The second create a container with a semi-persistent writable layer that
|
The second creates a read-only container that by default automatically
|
||||||
survives container restarts and host system restarts. However, if you
|
start at every boot. It basically wraps `podman create ...`.
|
||||||
change the container configuration or upgrade the image (see below), the
|
|
||||||
container will be recreated and the writable layer is lost. This is why
|
|
||||||
it is recommended to set up a named volume for directories, or use file
|
|
||||||
[Content Mounts](#content-mounts), in your container if you want truly
|
|
||||||
persistent content.
|
|
||||||
|
|
||||||
In fact, in many cases the best way is to create a `read-only` container
|
When non-volatile storage is needed two complementary options exist:
|
||||||
and use file mounts and volumes only for the critical parts. Podman
|
|
||||||
ensures (using tmpfs) `read-only` containers still have writable
|
|
||||||
directories for certain critical file system paths: `/dev`, `/dev/shm`,
|
|
||||||
`/run`, `/tmp`, and `/var/tmp`. Meaning, what you most often need is
|
|
||||||
writable volumes for `/var/lib` and `/etc`, or only file mounts for a
|
|
||||||
few files in `/etc`. The actual needs depend on the container image and
|
|
||||||
application to run.
|
|
||||||
|
|
||||||
> **Note:** when running containers from public registries, double-check
|
- **Volumes:** data stored in a volume is persisted until explicitly
|
||||||
> that they support the CPU architecture of your host system. Remember,
|
removed from the configuration, i.e., across host reboots and
|
||||||
> unlike virtualization, containers reuse the host's CPU and kernel.
|
container upgrades
|
||||||
|
- **[Content Mounts](#content-mounts):** where the content of a file
|
||||||
|
mounted into the container is kept along with the container
|
||||||
|
configuration in the device's `startup-config`
|
||||||
|
|
||||||
|
Podman ensures (using tmpfs) all containers have writable directories
|
||||||
|
for certain critical file system paths: `/dev`, `/dev/shm`, `/run`,
|
||||||
|
`/tmp`, and `/var/tmp`. Meaning, what you most often need is writable
|
||||||
|
volumes for `/var/lib` and `/etc`, or only file mounts for a few files
|
||||||
|
in `/etc`. The [actual requirements](#container-requirements) depend on
|
||||||
|
your container image and application to run.
|
||||||
|
|
||||||
|
> [!IMPORTANT]
|
||||||
|
> When running containers from public registries, double-check that they
|
||||||
|
> support the CPU architecture of your host system. Remember, unlike
|
||||||
|
> virtualization, containers reuse the host's CPU and kernel.
|
||||||
|
|
||||||
|
|
||||||
<img align="right" src="img/docker-hello-world.svg" alt="Hello World" width=360>
|
<img align="right" src="img/docker-hello-world.svg" alt="Hello World" width=360>
|
||||||
@@ -123,24 +129,30 @@ Classic Hello World:
|
|||||||
Hello from Docker!
|
Hello from Docker!
|
||||||
This message shows that your installation appears to be working correctly.
|
This message shows that your installation appears to be working correctly.
|
||||||
|
|
||||||
Persistent web server using nginx, sharing the host's network:
|
A web server with [nginx][], using standard docker bridge. Podman will
|
||||||
|
automatically create a VETH pair for us, connecting the container to the
|
||||||
|
`docker0` bridge:
|
||||||
|
|
||||||
admin@example:/> configure
|
admin@example:/> configure
|
||||||
admin@example:/config> edit container web
|
admin@example:/config/> edit interface docker0
|
||||||
admin@example:/config/container/web> set image docker://nginx:alpine
|
admin@example:/config/interface/docker0/> set container-network
|
||||||
admin@example:/config/container/web> set publish 80:80
|
admin@example:/config/interface/docker0/> end
|
||||||
admin@example:/config/container/web> set network host
|
admin@example:/config/> edit container web
|
||||||
admin@example:/config/container/web> leave
|
admin@example:/config/container/web/> set image docker://nginx:alpine
|
||||||
|
admin@example:/config/container/web/> set network publish 8080:80
|
||||||
|
admin@example:/config/container/web/> set network interface docker0
|
||||||
|
admin@example:/config/container/web/> set volume cache target /var/cache
|
||||||
|
admin@example:/config/container/web/> leave
|
||||||
admin@example:/> show container
|
admin@example:/> show container
|
||||||
|
|
||||||
Exit to the shell and verify the service with curl, or try to attach
|
Exit to the shell and verify the service with curl, or try to attach
|
||||||
to your device's IP address using your browser:
|
to your device's IP address using your browser:
|
||||||
|
|
||||||
admin@example:~$ curl http://localhost
|
admin@example:~$ curl http://localhost:8080
|
||||||
|
|
||||||
or connect to port 80 of your running Infix system with a browser. See
|
or connect to port 8080 of your running Infix system with a browser.
|
||||||
the following sections for how to add more interfaces and manage your
|
See the following sections for how to add more interfaces and manage
|
||||||
container at runtime.
|
your container at runtime.
|
||||||
|
|
||||||
|
|
||||||
Container Images
|
Container Images
|
||||||
@@ -168,13 +180,20 @@ The CLI help shows:
|
|||||||
oci-archive:/lib/oci/archive -- Use archive:latest from OCI archive
|
oci-archive:/lib/oci/archive -- Use archive:latest from OCI archive
|
||||||
May be in .tar or .tar.gz format
|
May be in .tar or .tar.gz format
|
||||||
|
|
||||||
|
Additionally, the following URIs are also supported for setups
|
||||||
|
that do not use a HUB or similar. Recommend using 'checksum'!
|
||||||
|
|
||||||
|
ftp://addr/path/to/archive -- Downloaded using wget
|
||||||
|
http://addr/path/to/archive -- Downloaded using curl
|
||||||
|
https://addr/path/to/archive -- Downloaded using curl
|
||||||
|
|
||||||
Note: if a remote repository cannot be reached, the creation of the
|
Note: if a remote repository cannot be reached, the creation of the
|
||||||
container will be put on a queue that retries pull every time
|
container will be put on a queue that retries pull every time
|
||||||
there is a route change in the host's system.
|
there is a route change in the host's system.
|
||||||
|
|
||||||
> **Note::** the built-in help system in the CLI is generated from the
|
> [!TIP]
|
||||||
> YANG model, so the same information is also available for remote
|
> The built-in help system in the CLI is generated from the YANG model,
|
||||||
> NETCONF users.
|
> so the same information is also available for remote NETCONF users.
|
||||||
|
|
||||||
The two most common variants are `docker://` and `oci-archive:/`.
|
The two most common variants are `docker://` and `oci-archive:/`.
|
||||||
|
|
||||||
@@ -217,21 +236,46 @@ mind.
|
|||||||
-rw-r--r-- 1 root root 7261785 Mar 27 14:22 curios-oci-amd64.tar.gz
|
-rw-r--r-- 1 root root 7261785 Mar 27 14:22 curios-oci-amd64.tar.gz
|
||||||
drwx------ 6 frr frr 4096 Mar 27 11:57 frr/
|
drwx------ 6 frr frr 4096 Mar 27 11:57 frr/
|
||||||
|
|
||||||
Importing the image into podman can be done either from the CLI
|
Importing the image into Podman can be done either from the CLI
|
||||||
admin-exec context ...
|
admin-exec context ...
|
||||||
|
|
||||||
admin@example:/var/tmp$ cli
|
admin@example:/var/tmp$ cli
|
||||||
admin@example:/> container load /var/tmp/curios-oci-amd64.tar.gz name curios:edge
|
admin@example:/> container load /var/tmp/curios-oci-amd64.tar.gz name curios:edge
|
||||||
|
|
||||||
> The `name curios:edge` is the tag you give the imported
|
> [!TIP]
|
||||||
> (raw) archive which you can then reference in your container image
|
> The `name curios:edge` is the tag you give the imported (raw) archive
|
||||||
> configuration: `set image curios:edge`.
|
> which you can then reference in your container image configuration:
|
||||||
|
> `set image curios:edge`.
|
||||||
|
|
||||||
... or by giving the container configuration the full path to the OCI
|
... or by giving the container configuration the full path to the OCI
|
||||||
archive, which helps greatly with container upgrades (see below):
|
archive, which helps greatly with container upgrades (see below):
|
||||||
|
|
||||||
admin@example:/config/container/system/> set image oci-archive:/var/tmp/curios-oci-amd64.tar.gz
|
admin@example:/config/container/system/> set image oci-archive:/var/tmp/curios-oci-amd64.tar.gz
|
||||||
|
|
||||||
|
**Checksum Example:**
|
||||||
|
|
||||||
|
admin@example:/> configure
|
||||||
|
admin@example:/config/> edit container sys
|
||||||
|
admin@example:/config/container/sys/> set hostname sys
|
||||||
|
admin@example:/config/container/sys/> set image ftp://192.168.122.1/curios-oci-amd64-v24.05.0.tar.gz
|
||||||
|
admin@example:/config/container/sys/> set checksum
|
||||||
|
md5 sha256 sha512
|
||||||
|
admin@example:/config/container/sys/> set checksum sha256 4f01077036527498ed910f1a3e80645ae3eff629d10043cf80ebc6850c99c629
|
||||||
|
admin@example:/config/container/sys/> leave
|
||||||
|
admin@example:/> copy running-config startup-config
|
||||||
|
admin@example:/> show container
|
||||||
|
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
|
||||||
|
b02e945c43c9 localhost/curios-oci-amd64-v24.05.0:latest 5 seconds ago Up 5 seconds sys
|
||||||
|
|
||||||
|
admin@example:/> show log
|
||||||
|
...
|
||||||
|
Nov 20 07:24:56 infix container[5040]: Fetching ftp://192.168.122.1/curios-oci-amd64-v24.05.0.tar.gz
|
||||||
|
Nov 20 07:24:56 infix container[5040]: curios-oci-amd64-v24.05.0.tar.gz downloaded successfully.
|
||||||
|
Nov 20 07:24:56 infix container[5040]: curios-oci-amd64-v24.05.0.tar.gz checksum verified OK.
|
||||||
|
Nov 20 07:24:57 infix container[5040]: Cleaning up extracted curios-oci-amd64-v24.05.0
|
||||||
|
Nov 20 07:24:57 infix container[5040]: podman create --name sys --conmon-pidfile=/run/container:sys.pid --read-only --replace --quiet --cgroup-parent=containers --restart=always --systemd=false --tz=local --hostname sys --log-driver k8s-file --log-opt path=/run/containers/sys.fifo --network=none curios-oci-amd64-v24.05.0
|
||||||
|
Nov 20 07:24:57 infix container[3556]: b02e945c43c9bce2c4be88e31d6f63cfdb1a3c8bdd02179376eb059a49ae05e4
|
||||||
|
|
||||||
|
|
||||||
Upgrading a Container Image
|
Upgrading a Container Image
|
||||||
---------------------------
|
---------------------------
|
||||||
@@ -240,21 +284,24 @@ Upgrading a Container Image
|
|||||||
The applications in your container are an active part of the system as a
|
The applications in your container are an active part of the system as a
|
||||||
whole, so make it a routine to keep your container images up-to-date!
|
whole, so make it a routine to keep your container images up-to-date!
|
||||||
|
|
||||||
> **Note:** the default writable layer is lost when upgrading the image.
|
Containers are created at first setup and at every boot. If the image
|
||||||
> Use named volumes for content that you want to persist across upgrades.
|
exists in the file system it is reused -- i.e., an image pulled from a
|
||||||
|
remote registry is not fetched again.
|
||||||
|
|
||||||
All container configurations are locked to the image hash at the time of
|
To upgrade a versioned image:
|
||||||
first download, not just ones that use an `:edge` or `:latest` tag. An
|
- update your `running-config` to use the new `image:tag`
|
||||||
upgrade of containers using versioned images is more obvious -- update
|
- `leave` to activate the change, if you are in the CLI
|
||||||
the configuration to use the new `image:tag` -- the latter is a bit
|
- Podman pulls the new image in the background
|
||||||
trickier. Either remove the configuration and recreate it (leave/apply
|
- Your container is recreated with the new image
|
||||||
the changes between), or use the admin-exec level command:
|
- The container is started
|
||||||
|
|
||||||
|
For "unversioned" images, e.g., images using a `:latest` or `:edge` tag,
|
||||||
|
use the following CLI command (`NAME` is the name of your container):
|
||||||
|
|
||||||
admin@example:/> container upgrade NAME
|
admin@example:/> container upgrade NAME
|
||||||
|
|
||||||
Where `NAME` is the name of your container. This command stops the
|
This stops the container, does `container pull IMAGE`, and recreates it
|
||||||
container, does `container pull IMAGE`, and then recreates it with the
|
with the new image. Upgraded containers are automatically restarted.
|
||||||
new image. Upgraded containers are automatically restarted.
|
|
||||||
|
|
||||||
**Example using registry:**
|
**Example using registry:**
|
||||||
|
|
||||||
@@ -279,12 +326,30 @@ the upgrade command as
|
|||||||
Upgrading container system with local archive: oci-archive:/var/tmp/curios-oci-amd64.tar.gz ...
|
Upgrading container system with local archive: oci-archive:/var/tmp/curios-oci-amd64.tar.gz ...
|
||||||
7ab4a07ee0c6039837419b7afda4da1527a70f0c60c0f0ac21cafee05ba24b52
|
7ab4a07ee0c6039837419b7afda4da1527a70f0c60c0f0ac21cafee05ba24b52
|
||||||
|
|
||||||
|
OCI archives can also be fetched from ftp/http/https URL, in that case
|
||||||
|
the upgrade can be done the same way as a registry image (above).
|
||||||
|
|
||||||
|
> [!TIP]
|
||||||
|
> Containers running from OCI images embedded in the operating system,
|
||||||
|
> e.g., `/lib/oci/mycontainer.tar.gz`, always run from the version in
|
||||||
|
> the operating system. To upgrade, install the new container image at
|
||||||
|
> build time, after system upgrade the container is also upgraded. The
|
||||||
|
> system unpacks and loads the OCI images into Podman every boot, which
|
||||||
|
> ensures the running container always has known starting state.
|
||||||
|
>
|
||||||
|
> **Example:** default builds of Infix include a couple of OCI images
|
||||||
|
> for reference, one is `/lib/oci/curios-nftables-v24.11.0.tar.gz`, but
|
||||||
|
> there is also a symlink called `curios-nftables-latest.tar.gz` in the
|
||||||
|
> same directory, which is what the Infix regression tests use in the
|
||||||
|
> image configuration of the container. This is what enables easy
|
||||||
|
> upgrades of the container along with the system itself.
|
||||||
|
|
||||||
|
|
||||||
Capabilities
|
Capabilities
|
||||||
-------------
|
-------------
|
||||||
|
|
||||||
An unprivileged container works for almost all use-cases, but there are
|
An unprivileged container works for almost all use-cases, but there are
|
||||||
occasions where they are too restricted and users being looking for the
|
occasions where they are too restricted and users start looking for the
|
||||||
`privileged` flag. Capabilities offers a middle ground.
|
`privileged` flag. Capabilities offers a middle ground.
|
||||||
|
|
||||||
For example, a system container from which `ping` does not work:
|
For example, a system container from which `ping` does not work:
|
||||||
@@ -300,9 +365,9 @@ For example, a system container from which `ping` does not work:
|
|||||||
...
|
...
|
||||||
|
|
||||||
Infix supports a subset of all [capabilities][6] that are relevant for
|
Infix supports a subset of all [capabilities][6] that are relevant for
|
||||||
containers. Please note, that this is and advanced topic and will
|
containers. Please note, that this is an advanced topic that require
|
||||||
require time and analysis of your container application to figure out
|
time and analysis of your container application to figure out which
|
||||||
which capabilities you need.
|
capabilities you need.
|
||||||
|
|
||||||
|
|
||||||
Networking and Containers
|
Networking and Containers
|
||||||
@@ -312,9 +377,16 @@ By default, unlike other systems, persistent[^1] containers have no
|
|||||||
networking enabled. All network access has to be set up explicitly.
|
networking enabled. All network access has to be set up explicitly.
|
||||||
Currently two types of of container networks are supported:
|
Currently two types of of container networks are supported:
|
||||||
|
|
||||||
- `host`: one end of a VETH pair, or a physical Ethernet port
|
- `host`: an managed host interface, e.g., one end of a VETH pair,
|
||||||
|
or even a physical interface
|
||||||
- `bridge`: an IP masquerading bridge
|
- `bridge`: an IP masquerading bridge
|
||||||
|
|
||||||
|
In the former the interface is delegated to (moved into) the container,
|
||||||
|
while in the latter a VETH pair is automatically created by Podman and
|
||||||
|
one end delegated to the container, while the other end is assigned to
|
||||||
|
the bridge (see the next section).
|
||||||
|
|
||||||
|
> [!TIP]
|
||||||
> For more information on VETH pairs, see the [Networking Guide][0].
|
> For more information on VETH pairs, see the [Networking Guide][0].
|
||||||
|
|
||||||
|
|
||||||
@@ -347,10 +419,12 @@ have to set manually:
|
|||||||
admin@example:/config/interface/docker0/> set type bridge
|
admin@example:/config/interface/docker0/> set type bridge
|
||||||
admin@example:/config/interface/docker0/> set container-network type bridge
|
admin@example:/config/interface/docker0/> set container-network type bridge
|
||||||
|
|
||||||
> **Note:** when doing the same operation over NETCONF there is no
|
> [!IMPORTANT]
|
||||||
> inference, so all the "magic" settings need to be defined. This
|
> When configuring the system via an API such as NETCONF or RESTCONF, no
|
||||||
> makes the CLI very useful for first setup and then extracting the
|
> settings are inferred. Instead it is up to the caller to fully define
|
||||||
> resulting XML from the shell using the `cfg -X` command.
|
> the desired setup. This makes the CLI very useful for first setup and
|
||||||
|
> then extracting the resulting XML from the shell using the `cfg -X`
|
||||||
|
> command.
|
||||||
|
|
||||||
We have to declare the interface as a container network, ensuring the
|
We have to declare the interface as a container network, ensuring the
|
||||||
interface cannot be used by the system for any other purpose. E.g., a
|
interface cannot be used by the system for any other purpose. E.g., a
|
||||||
@@ -390,11 +464,11 @@ in a `bridge`. Below an example of a system container calls `set
|
|||||||
network interface docker0`, here we show how to set options for that
|
network interface docker0`, here we show how to set options for that
|
||||||
network:
|
network:
|
||||||
|
|
||||||
admin@example:/config/container/ntpd/> edit network docker0
|
admin@example:/config/container/ntpd/> edit network interface docker0
|
||||||
admin@example:/config/container/ntpd/network/docker0/>
|
admin@example:/config/container/ntpd/network/interface/docker0/>
|
||||||
admin@example:/config/container/ntpd/network/docker0/> set option
|
admin@example:/config/container/ntpd/network/interface/docker0/> set option
|
||||||
<string> Options for masquerading container bridges.
|
<string> Options for masquerading container bridges.
|
||||||
admin@example:/config/container/ntpd/network/docker0/> help option
|
admin@example:/config/container/ntpd/network/interface/docker0/> help option
|
||||||
NAME
|
NAME
|
||||||
option <string>
|
option <string>
|
||||||
|
|
||||||
@@ -405,9 +479,9 @@ network:
|
|||||||
mac=00:01:02:c0:ff:ee -- set fixed MAC address in container
|
mac=00:01:02:c0:ff:ee -- set fixed MAC address in container
|
||||||
interface_name=foo0 -- set interface name inside container
|
interface_name=foo0 -- set interface name inside container
|
||||||
|
|
||||||
admin@example:/config/container/ntpd/network/docker0/> set option ip=172.17.0.2
|
admin@example:/config/container/ntpd/network/interface/docker0/> set option ip=172.17.0.2
|
||||||
admin@example:/config/container/ntpd/network/docker0/> set option interface_name=wan
|
admin@example:/config/container/ntpd/network/interface/docker0/> set option interface_name=wan
|
||||||
admin@example:/config/container/ntpd/network/docker0/> leave
|
admin@example:/config/container/ntpd/network/interface/docker0/> leave
|
||||||
|
|
||||||
|
|
||||||
### Container Host Interface
|
### Container Host Interface
|
||||||
@@ -419,8 +493,12 @@ example.
|
|||||||
|
|
||||||
The network `option` setting is available also for this case, but only
|
The network `option` setting is available also for this case, but only
|
||||||
the `interface_name=foo0` option works. Which is still very useful. To
|
the `interface_name=foo0` option works. Which is still very useful. To
|
||||||
change the MAC address, you need to use the `custom-phys-address` in the
|
set:
|
||||||
general network settings.
|
|
||||||
|
- IP address, use IPv4/IPv6 settings in the interface settings
|
||||||
|
- MAC address, to use the `custom-phys-address` in the interface settings
|
||||||
|
|
||||||
|
For an example of both, see the next section.
|
||||||
|
|
||||||
[^3]: Something which the container bridge network type does behind the
|
[^3]: Something which the container bridge network type does behind the
|
||||||
scenes with one end of an automatically created VETH pair.
|
scenes with one end of an automatically created VETH pair.
|
||||||
@@ -447,6 +525,7 @@ line where we declare the `ntpd` end as a container network interface:
|
|||||||
admin@example:/config/interface/ntpd/> set custom-phys-address static 00:c0:ff:ee:00:01
|
admin@example:/config/interface/ntpd/> set custom-phys-address static 00:c0:ff:ee:00:01
|
||||||
admin@example:/config/interface/ntpd/> set container-network
|
admin@example:/config/interface/ntpd/> set container-network
|
||||||
|
|
||||||
|
> [!TIP]
|
||||||
> Notice how you can also set a custom MAC address at the same time.
|
> Notice how you can also set a custom MAC address at the same time.
|
||||||
|
|
||||||
Adding the interface to the container is the same as before, but since
|
Adding the interface to the container is the same as before, but since
|
||||||
@@ -456,6 +535,7 @@ can take a bit of a shortcut.
|
|||||||
admin@example:/config/container/ntpd/> set network interface ntpd
|
admin@example:/config/container/ntpd/> set network interface ntpd
|
||||||
admin@example:/config/container/ntpd/> leave
|
admin@example:/config/container/ntpd/> leave
|
||||||
|
|
||||||
|
> [!TIP]
|
||||||
> Use the `set network interface ntpd option interface_name=foo0` to set
|
> Use the `set network interface ntpd option interface_name=foo0` to set
|
||||||
> the name of the interface inside the container to `foo0`.
|
> the name of the interface inside the container to `foo0`.
|
||||||
|
|
||||||
@@ -478,6 +558,7 @@ We start by adding the second VETH pair:
|
|||||||
admin@example:/config/interface/veth1a/> set veth peer veth1
|
admin@example:/config/interface/veth1a/> set veth peer veth1
|
||||||
admin@example:/config/interface/veth1a/> set ipv4 address 192.168.1.2 prefix-length 24
|
admin@example:/config/interface/veth1a/> set ipv4 address 192.168.1.2 prefix-length 24
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
> The LAN bridge (br1) in this example has IP address 192.168.1.1.
|
> The LAN bridge (br1) in this example has IP address 192.168.1.1.
|
||||||
|
|
||||||
When a container has multiple host interfaces it can often be useful to
|
When a container has multiple host interfaces it can often be useful to
|
||||||
@@ -529,29 +610,40 @@ file system:
|
|||||||
admin@example:/config/container/system/mount/leds> end
|
admin@example:/config/container/system/mount/leds> end
|
||||||
admin@example:/config/container/system/>
|
admin@example:/config/container/system/>
|
||||||
|
|
||||||
Sometimes *volumes* are a better fit. A volume is an automatically
|
Any type of file can be *bind mounted* into the container, just watch
|
||||||
|
out for permissions though. In the example above, `/sys/class/leds` is
|
||||||
|
not writable from a container unless it runs in *privileged* mode. For
|
||||||
|
plain configuration files you get more freedom, and your container can
|
||||||
|
rely on, e.g., *inotify* events to trigger reloading its services when
|
||||||
|
you change the file on the host.
|
||||||
|
|
||||||
|
So it depends on the container, and indeed your overall setup, what to
|
||||||
|
use. An intriguing option is *Content Mounts*, which when changed also
|
||||||
|
trigger a container restart.
|
||||||
|
|
||||||
|
Other times *volumes* are a better fit. A volume is an automatically
|
||||||
created read-writable entity that follows the life of your container.
|
created read-writable entity that follows the life of your container.
|
||||||
|
|
||||||
admin@example:/config/container/ntpd/> set volume varlib target /var/lib
|
admin@example:/config/container/ntpd/> set volume varlib target /var/lib
|
||||||
|
|
||||||
Volumes survive reboots and upgrading of the base image, unlike the
|
Volumes are persistent across both reboots and upgrades of the base
|
||||||
persistent writable layer you get by default, which does not survive
|
image. They are created by Podman when the container first starts up,
|
||||||
upgrades. The volume is created by podman when the container first
|
unlike a regular bind mount it synchronizes with the contents of the
|
||||||
starts up, unlike a regular bind mount it synchronizes with the contents
|
underlying container image's path at first use. I.e., "bind-mount, if
|
||||||
of the underlying container image's path on the first start. I.e.,
|
empty: then rsync".
|
||||||
"bind-mount, if empty: then rsync".
|
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
> Infix support named volumes (only), and it is not possible to share a
|
> Infix support named volumes (only), and it is not possible to share a
|
||||||
> volume between containers. All the tricks possible with volumes may
|
> volume between containers. All the tricks possible with volumes may
|
||||||
> be added in a later release.
|
> be added in a later release.
|
||||||
|
|
||||||
### Content Mounts
|
### Content Mounts
|
||||||
|
|
||||||
Content mount is a special type of where the file contents for the
|
Content mounts are a special type of file mount where the file contents
|
||||||
container is stored alongside the container configuration. This can be
|
is stored with the container configuration. This can be very useful
|
||||||
very useful when deploying similar systems at multiple sites. When the
|
when deploying similar systems at multiple sites. When the host loads
|
||||||
host loads its `startup-config` (or even `factory-config`) a temporary
|
its `startup-config` (or even `factory-config`) a temporary file is
|
||||||
file is created using the decoded base64 data from the `content` node.
|
created using the decoded base64 data from the `content` node.
|
||||||
|
|
||||||
admin@example:/config/container/ntpd/> edit mount ntpd.conf
|
admin@example:/config/container/ntpd/> edit mount ntpd.conf
|
||||||
admin@example:/config/container/ntpd/mount/ntpd.conf> text-editor content
|
admin@example:/config/container/ntpd/mount/ntpd.conf> text-editor content
|
||||||
@@ -564,9 +656,10 @@ The editor is a small [Emacs clone called Mg][2], see the built-in help
|
|||||||
text, or press Ctrl-x Ctrl-c to exit and save. When the editor exits
|
text, or press Ctrl-x Ctrl-c to exit and save. When the editor exits
|
||||||
the contents are base64 encoded and stored in the candidate datastore.
|
the contents are base64 encoded and stored in the candidate datastore.
|
||||||
|
|
||||||
> **Note:** since these files are always recreated when the host is
|
> [!NOTE]
|
||||||
> restarted, changes made by the container are not preserved, or saved
|
> Since these files are always recreated when the host is restarted,
|
||||||
> back to the host's startup-config even if the read-only option is off.
|
> changes made by the container are not preserved, or saved back to the
|
||||||
|
> host's startup-config.
|
||||||
|
|
||||||
Infix has three different text editors available. For more information,
|
Infix has three different text editors available. For more information,
|
||||||
see [CLI Text Editor](cli/text-editor.md).
|
see [CLI Text Editor](cli/text-editor.md).
|
||||||
@@ -588,10 +681,11 @@ we created previously:
|
|||||||
admin@example:/config/container/system/> set publish 222:22
|
admin@example:/config/container/system/> set publish 222:22
|
||||||
admin@example:/config/container/system/> leave
|
admin@example:/config/container/system/> leave
|
||||||
|
|
||||||
> **Note:** ensure you have a network connection to the registry.
|
> [!NOTE]
|
||||||
> If the image cannot be pulled, creation of the container will be
|
> Ensure you have a network connection to the registry. If the image
|
||||||
> put in a queue and be retried every time there is a change in the
|
> cannot be pulled, creation of the container will be put in a queue and
|
||||||
> routing table, e.g., default route is added.
|
> be retried every time there is a change in the routing table, e.g.,
|
||||||
|
> default route is added, and every 60 seconds.
|
||||||
|
|
||||||
Provided the image is downloaded successfully, a new `system` container
|
Provided the image is downloaded successfully, a new `system` container
|
||||||
now runs behind the docker0 interface, forwarding container port 22 to
|
now runs behind the docker0 interface, forwarding container port 22 to
|
||||||
@@ -707,12 +801,13 @@ Another *insecure* approach is to access the host system directly,
|
|||||||
bypassing the namespaces that make up the boundary between host and
|
bypassing the namespaces that make up the boundary between host and
|
||||||
container.
|
container.
|
||||||
|
|
||||||
> **Security:** Please note, this completely demolishes the isolation
|
> [!CAUTION]
|
||||||
> barrier between container and host operating system. It is only
|
> Please note, this completely demolishes the isolation barrier between
|
||||||
> suitable in situations where the container serves more as a unit of
|
> container and host operating system. It is only suitable in
|
||||||
> distribution rather than as a separate component of the system.
|
> situations where the container serves more as a unit of distribution
|
||||||
> *Strongly recommended* to use this only in trusted setups! Consider
|
> rather than as a separate component of the system. *Strongly
|
||||||
> also limiting the time frame in which this is active!
|
> recommended* to use this only in trusted setups! Consider also
|
||||||
|
> limiting the time frame in which this is active!
|
||||||
|
|
||||||
First, enable *Privileged* mode, this unlocks the door and allows the
|
First, enable *Privileged* mode, this unlocks the door and allows the
|
||||||
container to manage resources on the host system. An example is the
|
container to manage resources on the host system. An example is the
|
||||||
@@ -747,6 +842,58 @@ control an Infix system this way, see [Scripting Infix](scripting.md).
|
|||||||
it may not be enabled by default in BusyBox.
|
it may not be enabled by default in BusyBox.
|
||||||
|
|
||||||
|
|
||||||
|
Container Requirements
|
||||||
|
----------------------
|
||||||
|
|
||||||
|
In addition to general [*best practices*][7] for container images, there
|
||||||
|
are a few more things to consider when targeting embedded systems:
|
||||||
|
|
||||||
|
- Ensure the image targets the CPU architecture of the target system,
|
||||||
|
learn more about [Multi-platform Builds][8]
|
||||||
|
- Follow [best practices for naming and tagging][10], e.g., `:latest` vs `:1.0`
|
||||||
|
- Follow [OCI recommendations and layout][9],
|
||||||
|
learn more about [OCI and Docker Exporters][6]
|
||||||
|
|
||||||
|
If the [Docker documentation][11] is not enough, there are plenty of
|
||||||
|
[guides online][12] with examples on how to create your own container
|
||||||
|
image. For the more advanced, please see the next section.
|
||||||
|
|
||||||
|
|
||||||
|
### Advanced Users
|
||||||
|
|
||||||
|
Most people prefer their system containers small, often based on Alpine
|
||||||
|
Linux, or similar, with only a few small applications, including their
|
||||||
|
own, and an SSH server perhaps. For some developers, even this is too
|
||||||
|
big, so they roll their own from source. This section is for you.
|
||||||
|
|
||||||
|
Depending on your needs, here is a checklist:
|
||||||
|
|
||||||
|
- you need something that can forward signals, e.g.,
|
||||||
|
- [tini][]
|
||||||
|
- [Bash only][13], or
|
||||||
|
- BusyBox init, a classic most embedded developers know, but read on ...
|
||||||
|
- a system container only need the bare necessities of a system bringup
|
||||||
|
- E.g., BusyBox's init, [but not everything][15]
|
||||||
|
- Some of the networking is set up by Podman and CNI for you, but
|
||||||
|
you may want to run a DHCP client?
|
||||||
|
- Do *not* rename interfaces inside the container, use the dedicated
|
||||||
|
`interface_name` option in the configuration instead
|
||||||
|
- Remember, Podman provides a `tmpfs` for all critical system paths:
|
||||||
|
`/dev`, `/dev/shm`, `/run`, `/tmp`, and `/var/tmp`, so you don't
|
||||||
|
need to clean or set up any of these mount points
|
||||||
|
|
||||||
|
Examples using `tini` and BusyBox init are available from the KernelKit
|
||||||
|
[curiOS project][14]. It is a small Buildroot based container image
|
||||||
|
builder that generates OCI compatible image tarballs without any tools
|
||||||
|
from Docker or Podman -- ready-made images exist for testing on both
|
||||||
|
AMD64 and ARM64 targets, as well as `docker pull` images and and OCI
|
||||||
|
tarballs with SHA256 checksums for integrity checking.
|
||||||
|
|
||||||
|
Finally, if you build your own version of Infix, and embed OCI tarballs
|
||||||
|
in the system image, then see the tip at the end of [Upgrading a
|
||||||
|
Container Image](#upgrading-a-container-image) (above).
|
||||||
|
|
||||||
|
|
||||||
[0]: networking.md
|
[0]: networking.md
|
||||||
[1]: https://github.com/kernelkit/infix/blob/main/src/confd/yang/infix-containers.yang
|
[1]: https://github.com/kernelkit/infix/blob/main/src/confd/yang/infix-containers.yang
|
||||||
[2]: https://github.com/troglobit/mg
|
[2]: https://github.com/troglobit/mg
|
||||||
@@ -754,4 +901,15 @@ control an Infix system this way, see [Scripting Infix](scripting.md).
|
|||||||
[4]: system.md#ssh-authorized-key
|
[4]: system.md#ssh-authorized-key
|
||||||
[5]: https://docs.docker.com/build/exporters/oci-docker/
|
[5]: https://docs.docker.com/build/exporters/oci-docker/
|
||||||
[6]: https://man7.org/linux/man-pages/man7/capabilities.7.html
|
[6]: https://man7.org/linux/man-pages/man7/capabilities.7.html
|
||||||
|
[7]: https://docs.docker.com/build/building/best-practices/
|
||||||
|
[8]: https://docs.docker.com/build/building/multi-platform/
|
||||||
|
[9]: https://github.com/opencontainers/image-spec/blob/main/image-layout.md
|
||||||
|
[10]: https://docs.docker.com/get-started/docker-concepts/building-images/build-tag-and-publish-an-image/#tagging-images
|
||||||
|
[11]: https://www.docker.com/blog/multi-arch-images/
|
||||||
|
[12]: https://lemariva.com/blog/2018/05/tutorial-docker-on-embedded-systems-raspberry-pi-beagleboard
|
||||||
|
[13]: https://sirikon.me/posts/0009-pid-1-bash-script-docker-container.html
|
||||||
|
[14]: https://github.com/kernelkit/curiOS/
|
||||||
|
[15]: https://github.com/kernelkit/curiOS/blob/2e4748f65e356b2c117f586cd9420d7ba66f79d5/board/system/rootfs/etc/inittab
|
||||||
|
[tini]: https://github.com/krallin/tini
|
||||||
|
[nginx]: https://hub.docker.com/_/nginx
|
||||||
[podman]: https://podman.io
|
[podman]: https://podman.io
|
||||||
|
|||||||
+225
-1
@@ -131,6 +131,8 @@ This rebuilds (and installs) `foo` and `bar`, the `all` target calls
|
|||||||
on Buildroot to finalize the target filesystem and generate the images.
|
on Buildroot to finalize the target filesystem and generate the images.
|
||||||
The final `run` argument is explained below.
|
The final `run` argument is explained below.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
### `confd`
|
### `confd`
|
||||||
|
|
||||||
The Infix `src/confd/` is the engine of the system. Currently it is a
|
The Infix `src/confd/` is the engine of the system. Currently it is a
|
||||||
@@ -164,17 +166,239 @@ Now you can rebuild `confd`, just as described above, and restart Infix:
|
|||||||
make confd-rebuild all run
|
make confd-rebuild all run
|
||||||
|
|
||||||
|
|
||||||
|
### `statd`
|
||||||
|
|
||||||
|
The Infix status daemon, `src/statd`, is responsible for populating the
|
||||||
|
sysrepo `operational` datastore. Like `confd`, it uses XPath subscriptions,
|
||||||
|
but unlike `confd`, it relies entirely on `yanger`, a Python script that
|
||||||
|
gathers data from local linux services and feeds it into sysrepo.
|
||||||
|
|
||||||
|
To apply changes, rebuild the image:
|
||||||
|
|
||||||
|
make python-statd-rebuild statd-rebuild all
|
||||||
|
|
||||||
|
Rebuilding the image and testing on target for every change during
|
||||||
|
development process can be tedious. Instead, `yanger` allows remote
|
||||||
|
execution, running the script directly on the host system (test
|
||||||
|
container):
|
||||||
|
|
||||||
|
infamy0:test # ../src/statd/python/yanger/yanger -x "../utils/ixll -A ssh d3a" ieee802-dot1ab-lldp
|
||||||
|
|
||||||
|
`ixll` is a utility script that lets you run network commands using an
|
||||||
|
**interface name** instead of a hostname. It makes operations like
|
||||||
|
`ssh`, `scp`, and network discovery easier.
|
||||||
|
|
||||||
|
Normally, `yanger` runs commands **locally** to retrieve data
|
||||||
|
(e.g., `lldpcli` when handling `ieee802-dot1ab-lldp`). However, when
|
||||||
|
executed with `-x "../utils/ixll -A ssh d3a"` it redirects these
|
||||||
|
commands to a remote system connected to the local `d3a` interface via
|
||||||
|
SSH. This setup is used for running `yanger` in an
|
||||||
|
[interactive test environment](testing.md#interactive-usage). The yanger
|
||||||
|
script runs on the `host` system, but key commands are executed on the
|
||||||
|
`target` system.
|
||||||
|
|
||||||
|
For debugging or testing, you can capture system command output and
|
||||||
|
replay it later without needing a live system.
|
||||||
|
|
||||||
|
To capture:
|
||||||
|
|
||||||
|
infamy0:test # ../src/statd/python/yanger/yanger -c /tmp/capture ieee802-dot1ab-lldp
|
||||||
|
|
||||||
|
To replay:
|
||||||
|
|
||||||
|
infamy0:test # ../src/statd/python/yanger/yanger -r /tmp/capture ieee802-dot1ab-lldp
|
||||||
|
|
||||||
|
This is especially useful when working in isolated environments or debugging
|
||||||
|
issues without direct access to the DUT.
|
||||||
|
|
||||||
|
### Upgrading Packages
|
||||||
|
|
||||||
|
#### Buildroot
|
||||||
|
|
||||||
|
Kernelkit maintains an internal [fork of
|
||||||
|
Buildroot](https://github.com/kernelkit/buildroot), with branches
|
||||||
|
following the naming scheme `YYYY.MM.patch-kkit`
|
||||||
|
e.g. `2025.02.1-kkit`, which means a new branch should be created
|
||||||
|
whenever Buildroot is updated. These branches should contain **only**
|
||||||
|
changes to existing packages (but no new patches), modifications to
|
||||||
|
Buildroot itself or upstream backports.
|
||||||
|
|
||||||
|
KernelKit track the latest Buildroot LTS (Long-Term Support) release
|
||||||
|
and updates. The upgrade of LTS minor releases is expected to have low
|
||||||
|
impact and should be done as soon there is a patch release of
|
||||||
|
Buildroot LTS is available.
|
||||||
|
|
||||||
|
> **Depending on your setup, follow the appropriate steps below.**
|
||||||
|
|
||||||
|
🔁 If you **already have** the Buildroot repo locally
|
||||||
|
|
||||||
|
1. Navigate to the Buildroot directory
|
||||||
|
```bash
|
||||||
|
$ cd buildroot
|
||||||
|
```
|
||||||
|
2. Pull the latest changes from KernelKit
|
||||||
|
```bash
|
||||||
|
$ git pull
|
||||||
|
```
|
||||||
|
3. Fetch the latest tags from upstream
|
||||||
|
```bash
|
||||||
|
$ git fetch upstream --tags
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
🆕 If you don't have the repo locally
|
||||||
|
|
||||||
|
1. Clone the Kernelkit Buildroot repository
|
||||||
|
```bash
|
||||||
|
$ git clone git@github.com:kernelkit/buildroot.git
|
||||||
|
```
|
||||||
|
|
||||||
|
2. Add the upstream remote
|
||||||
|
```bash
|
||||||
|
$ git remote add upstream https://gitlab.com/buildroot.org/buildroot.git
|
||||||
|
```
|
||||||
|
3. Checkout old KernelKit branch
|
||||||
|
```bash
|
||||||
|
$ git checkout 2025.02.1-kkit
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
🛠 Continue from here (applies to both cases):
|
||||||
|
|
||||||
|
4. Create a new branch based on the **previous** KernelKit Buildroot
|
||||||
|
release (e.g. `2025.02.1-kkit`) and name it according to the naming scheme (e.g. `2025.02.2-kkit`)
|
||||||
|
```bash
|
||||||
|
$ git checkout -b 2025.02.2-kkit
|
||||||
|
```
|
||||||
|
5. Rebase the new branch onto the corresponding upstream release
|
||||||
|
```bash
|
||||||
|
$ git rebase 2025.02.2
|
||||||
|
```
|
||||||
|
> [!NOTE] It is **not** allowed to rebase the branch when bumped in Infix.
|
||||||
|
|
||||||
|
6. Push the new branch and tags
|
||||||
|
```bash
|
||||||
|
$ git push origin 2025.02.2-kkit --tags
|
||||||
|
```
|
||||||
|
7. In Infix, checkout new branch of Buildroot
|
||||||
|
```bash
|
||||||
|
$ cd buildroot
|
||||||
|
$ git fetch
|
||||||
|
$ git checkout 2025.02.2-kkit
|
||||||
|
```
|
||||||
|
8. Push changes
|
||||||
|
Commit and push the changes. Don’t forget to update the changelog.
|
||||||
|
|
||||||
|
9. Create a pull request.
|
||||||
|
|
||||||
|
> [!NOTE] Remember to set the pull request label to `ci:main` to ensure full CI coverage.
|
||||||
|
|
||||||
|
|
||||||
|
#### Linux kernel
|
||||||
|
|
||||||
|
KernelKit maintains an internal [fork of Linux
|
||||||
|
kernel](https://github.com/kernelkit/linux), with branches following
|
||||||
|
the naming scheme `kkit-linux-[version].y`, e.g. `kkit-6.12.y`, which
|
||||||
|
means a new branch should be created whenever the major kernel version
|
||||||
|
is updated. This branch should contain *all* kernel patches used by
|
||||||
|
Infix.
|
||||||
|
|
||||||
|
KernelKit track the latest Linux kernel LTS (Long-Term Support)
|
||||||
|
release and updates. The upgrade of LTS minor releases is expected to
|
||||||
|
have low impact and should be done as soon as a patch release of the
|
||||||
|
LTS Linux kernel is available.
|
||||||
|
|
||||||
|
|
||||||
|
🔁 If you **already have** the Linux kernel repo locally
|
||||||
|
|
||||||
|
1. Navigate to the Linux kernel directory
|
||||||
|
```bash
|
||||||
|
$ cd linux
|
||||||
|
```
|
||||||
|
2. Get latest changes from KernelKit
|
||||||
|
```bash
|
||||||
|
$ git pull
|
||||||
|
```
|
||||||
|
3. Fetch the latest tags from upstream
|
||||||
|
```bash
|
||||||
|
$ git fetch upstream --tags
|
||||||
|
```
|
||||||
|
|
||||||
|
🆕 If you don't have the repo locally
|
||||||
|
|
||||||
|
1. Clone the KernelKit Linux kernel repository
|
||||||
|
```bash
|
||||||
|
$ git clone git@github.com:kernelkit/linux.git
|
||||||
|
```
|
||||||
|
2. Add the upstream remote
|
||||||
|
```bash
|
||||||
|
$ git remote add upstream git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
|
||||||
|
```
|
||||||
|
|
||||||
|
3. Checkout correct kernel branch
|
||||||
|
```bash
|
||||||
|
$ git checkout kkit-linux-6.12.y
|
||||||
|
```
|
||||||
|
|
||||||
|
🛠 Continue from here (applies to both cases)
|
||||||
|
|
||||||
|
|
||||||
|
4. Rebase on the upstream release
|
||||||
|
```bash
|
||||||
|
$ git rebase v6.12.29
|
||||||
|
```
|
||||||
|
|
||||||
|
6. Push changes and the tags
|
||||||
|
```bash
|
||||||
|
|
||||||
|
$ git push -f origin kkit-linux-6.12.y --tags
|
||||||
|
```
|
||||||
|
|
||||||
|
**Move to your infix directory**
|
||||||
|
|
||||||
|
7. Generate patches
|
||||||
|
```bash
|
||||||
|
$ make x86_64_defconfig
|
||||||
|
$ cd output
|
||||||
|
$ ../utils/kernel-refresh.sh -k /path/to/linux -o 6.12.28 -t v6.12.29
|
||||||
|
```
|
||||||
|
> [!NOTE] See help of `kernel-refresh.sh` script for more information
|
||||||
|
|
||||||
|
|
||||||
|
8. Push changes
|
||||||
|
Commit and push the changes. Don’t forget to update the s:changelog:doc/ChangeLog.md.
|
||||||
|
|
||||||
|
9. Create a pull request.
|
||||||
|
> [!NOTE] Remember to set the pull request label to `ci:main` to ensure full CI coverage.
|
||||||
|
|
||||||
|
|
||||||
|
### Agree on YANG Model
|
||||||
|
|
||||||
|
When making changes to the `confd` and `statd` services, you will often need to update
|
||||||
|
the YANG models. If you are adding a new YANG module, it's best to follow the
|
||||||
|
structure of an existing one. However, before making any changes, **always discuss
|
||||||
|
them with the Infix core team**. This helps avoid issues later in development and
|
||||||
|
makes pull request reviews smoother.
|
||||||
|
|
||||||
|
|
||||||
Testing
|
Testing
|
||||||
-------
|
-------
|
||||||
|
|
||||||
Manual testing can be done using Qemu by calling <kbd>make run</kbd>,
|
Manual testing can be done using Qemu by calling <kbd>make run</kbd>,
|
||||||
see also [Infix in Virtual Environments](virtual.md).
|
see also [Infix in Virtual Environments](virtual.md), or on a physical
|
||||||
|
device by upgrading to the latest build or "[netbooting](netboot.md)"
|
||||||
|
and running the image from RAM. The latter is how most board porting
|
||||||
|
work is done -- **much quicker** change-load-test cycles.
|
||||||
|
|
||||||
The Infix automated test suite is built around Qemu and [Qeneth][2], see:
|
The Infix automated test suite is built around Qemu and [Qeneth][2], see:
|
||||||
|
|
||||||
* [Testing](testing.md)
|
* [Testing](testing.md)
|
||||||
* [Docker Image](../test/docker/README.md)
|
* [Docker Image](../test/docker/README.md)
|
||||||
|
|
||||||
|
With any new feature added to Infix, it is essential to include relevant
|
||||||
|
test case(s). See the [Test Development](testing.md#test-development)
|
||||||
|
section for guidance on adding test cases.
|
||||||
|
|
||||||
|
|
||||||
Reviewing
|
Reviewing
|
||||||
---------
|
---------
|
||||||
|
|||||||
+171
@@ -0,0 +1,171 @@
|
|||||||
|
DHCP Server
|
||||||
|
===========
|
||||||
|
|
||||||
|
The DHCPv4 server provides automatic IP address assignment and network
|
||||||
|
configuration for clients. It supports address pools, static host
|
||||||
|
assignments, and customizable DHCP options. It also serves as a DNS
|
||||||
|
proxy for local subnets and can even forward queries to upstream DNS
|
||||||
|
servers[^1].
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> When using the CLI, the system automatically enables essential options
|
||||||
|
> like DNS servers and default gateway based on the system's network
|
||||||
|
> configuration. These options can be disabled, changed or overridden,
|
||||||
|
> at any level: global, subnet, or per-host.
|
||||||
|
|
||||||
|
|
||||||
|
## Basic Configuration
|
||||||
|
|
||||||
|
The following example configures a DHCP server for subnet 192.168.2.0/24
|
||||||
|
with an address pool:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@example:/> configure
|
||||||
|
admin@example:/config/> edit dhcp-server
|
||||||
|
admin@example:/config/dhcp-server/> edit subnet 192.168.2.0/24
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> set pool start-address 192.168.2.100 end-address 192.168.2.200
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> leave
|
||||||
|
```
|
||||||
|
|
||||||
|
When setting up the server from the CLI, the system automatically adds a
|
||||||
|
few default DHCP options that will be sent to clients: both DNS server
|
||||||
|
and default gateway will use the system address on the matching
|
||||||
|
interface.
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@example:/> show running-config
|
||||||
|
"infix-dhcp-server:dhcp-server": {
|
||||||
|
"subnet": [
|
||||||
|
{
|
||||||
|
"subnet": "192.168.2.0/24",
|
||||||
|
"option": [
|
||||||
|
{
|
||||||
|
"id": "dns-server",
|
||||||
|
"address": "auto"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "router",
|
||||||
|
"address": "auto"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"pool": {
|
||||||
|
"start-address": "192.168.2.100",
|
||||||
|
"end-address": "192.168.2.200"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
> [!IMPORTANT]
|
||||||
|
> Remember to set up an interface in this subnet, avoid using addresses
|
||||||
|
> in the DHCP pool, or reserved for static hosts. In Class C networks
|
||||||
|
> the router usually has address `.1`. Depending on the use-case, you
|
||||||
|
> may also want to set up routing.
|
||||||
|
|
||||||
|
|
||||||
|
## Static Host Assignment
|
||||||
|
|
||||||
|
To reserve specific IP addresses for clients based on their MAC address,
|
||||||
|
hostname, or client ID:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> edit host 192.168.2.10
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/host/192.168.2.10/> set match mac-address 00:11:22:33:44:55
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/host/192.168.2.10/> set hostname printer
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/host/192.168.2.10/> leave
|
||||||
|
```
|
||||||
|
|
||||||
|
Match hosts using a client identifier instead of MAC address:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/> edit host 192.168.1.50
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/> edit match
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/match/> set client-id hex c0:ff:ee
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/match/> leave
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/> set lease-time infinite
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/> leave
|
||||||
|
```
|
||||||
|
|
||||||
|
The `hex` prefix here ensures matching of client ID is done using the
|
||||||
|
hexadecimal octets `c0:ff:ee`, three bytes. Without the prefix the
|
||||||
|
ASCII string "c0:ff:ee", eight bytes, is used.
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> The DHCP server is fully RFC conformant, in the case of option 61 this
|
||||||
|
> means that using the `hex` prefix will require the client to set the
|
||||||
|
> `htype` field of the option to `00`. See RFC 2132 for details.
|
||||||
|
|
||||||
|
|
||||||
|
## Custom DHCP Options
|
||||||
|
|
||||||
|
Configure additional DHCP options globally, per subnet, or per host:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@example:/config/dhcp-server/> edit subnet 192.168.2.0/24
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> edit option dns-server
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/option/dns-server/> set address 8.8.8.8
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/option/dns-server/> leave
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> edit option ntp-server
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/option/ntp-server/> set address 192.168.2.1
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/option/ntp-server/> leave
|
||||||
|
```
|
||||||
|
|
||||||
|
When configuring, e.g., `dns-server`, or `router` options with the value
|
||||||
|
`auto`, the system uses the IP address from the interface matching the
|
||||||
|
subnet. For example:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@example:/> show interfaces brief
|
||||||
|
Interface Status Address
|
||||||
|
eth0 UP 192.168.1.1/24
|
||||||
|
eth1 UP 192.168.2.1/24
|
||||||
|
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/> edit option dns-server
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/option/dns-server/> set address auto
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/option/dns-server/> leave
|
||||||
|
```
|
||||||
|
|
||||||
|
In this case, clients in subnet 192.168.1.0/24 will receive 192.168.1.1
|
||||||
|
as their DNS server address.
|
||||||
|
|
||||||
|
|
||||||
|
## Multiple Subnets
|
||||||
|
|
||||||
|
Configure DHCP for multiple networks:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@example:/> configure
|
||||||
|
admin@example:/config/> edit dhcp-server
|
||||||
|
admin@example:/config/dhcp-server/> edit subnet 192.168.1.0/24
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/> set pool start-address 192.168.1.100 end-address 192.168.1.200
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/> leave
|
||||||
|
admin@example:/config/dhcp-server/> edit subnet 192.168.2.0/24
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> set pool start-address 192.168.2.100 end-address 192.168.2.200
|
||||||
|
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> leave
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
## Monitoring
|
||||||
|
|
||||||
|
View active leases and server statistics:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@example:/> show dhcp-server
|
||||||
|
IP ADDRESS MAC HOSTNAME CLIENT ID EXPIRES
|
||||||
|
192.168.2.22 00:a0:85:00:02:05 00:c0:ff:ee 3591s
|
||||||
|
192.168.1.11 00:a0:85:00:04:06 foo 01:00:a0:85:00:04:06 3591s
|
||||||
|
|
||||||
|
admin@example:/> show dhcp-server statistics
|
||||||
|
DHCP offers sent : 6
|
||||||
|
DHCP ACK messages sent : 5
|
||||||
|
DHCP NAK messages sent : 0
|
||||||
|
DHCP decline messages received : 0
|
||||||
|
DHCP discover messages received : 6
|
||||||
|
DHCP request messages received : 5
|
||||||
|
DHCP release messages received : 6
|
||||||
|
DHCP inform messages received : 6
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
[^1]: This requires the system DNS resolver to be configured.
|
||||||
+270
-65
@@ -1,29 +1,29 @@
|
|||||||
Discover Infix Units
|
# Discover Devices
|
||||||
====================
|
|
||||||
|
Infix advertises itself via the [mDNS-SD](#mdns-sd) and [LLDP](#lldp)
|
||||||
|
discovery protocols. mDNS-SD has good client support in Windows, macOS
|
||||||
|
and on Linux systems. More on these protocols later.
|
||||||
|
|
||||||
|
An even simpler method is available when directly attached to an Infix
|
||||||
|
device:
|
||||||
|
|
||||||
```
|
```
|
||||||
.----. Ethernet .-------.
|
.----. Ethernet .-------.
|
||||||
| PC +---------------------+ Infix |
|
| PC +---------------------+ Infix |
|
||||||
'----' if1 eth0 '-------'
|
'----' if1 e1 '-------'
|
||||||
```
|
```
|
||||||
Figure 1: PC directly connected over Ethernet to Infix unit (here eth0).
|
|
||||||
|
|
||||||
|
With IPv6 you can *ping the all-hosts* address (ff02::1), the device's
|
||||||
When you wish to discover the IP address of an Infix switch, the simplest
|
link-local IPv6 address is then seen in the response. In the following
|
||||||
way is probably to *ping the IPv6 all-hosts* address (ff02::1) over a
|
example, the PC here uses *tap0* as *if1*, Infix responds with address
|
||||||
directly connected Ethernet cable. The unit's link-local IPv6 address is
|
*fe80::ff:fec0:ffed*.
|
||||||
seen in the response.
|
|
||||||
|
|
||||||
In the example below, the PC is connected to Infix via interface *tap0*
|
|
||||||
(*tap0* is *if1* in Figure 1) and Infix responds with address
|
|
||||||
*fe80::ff:fe00:0*.
|
|
||||||
|
|
||||||
```
|
```
|
||||||
linux-pc:# ping -6 -L -c 3 ff02::1%tap0
|
linux-pc:# ping -6 -L -c 3 ff02::1%tap0
|
||||||
PING ff02::1%tap0(ff02::1%tap0) 56 data bytes
|
PING ff02::1%tap0(ff02::1%tap0) 56 data bytes
|
||||||
64 bytes from fe80::ff:fe00:0%tap0: icmp_seq=1 ttl=64 time=0.558 ms
|
64 bytes from fe80::ff:fec0:ffed%tap0: icmp_seq=1 ttl=64 time=0.558 ms
|
||||||
64 bytes from fe80::ff:fe00:0%tap0: icmp_seq=2 ttl=64 time=0.419 ms
|
64 bytes from fe80::ff:fec0:ffed%tap0: icmp_seq=2 ttl=64 time=0.419 ms
|
||||||
64 bytes from fe80::ff:fe00:0%tap0: icmp_seq=3 ttl=64 time=0.389 ms
|
64 bytes from fe80::ff:fec0:ffed%tap0: icmp_seq=3 ttl=64 time=0.389 ms
|
||||||
|
|
||||||
--- ff02::1%tap0 ping statistics ---
|
--- ff02::1%tap0 ping statistics ---
|
||||||
3 packets transmitted, 3 received, 0% packet loss, time 2043ms
|
3 packets transmitted, 3 received, 0% packet loss, time 2043ms
|
||||||
@@ -31,42 +31,42 @@ rtt min/avg/max/mdev = 0.389/0.455/0.558/0.073 ms
|
|||||||
linux-pc:#
|
linux-pc:#
|
||||||
```
|
```
|
||||||
|
|
||||||
The PC could connect then connect to Infix, e.g., using SSH.
|
> [!TIP]
|
||||||
|
> The `-L` option ignores local responses from the PC.
|
||||||
|
|
||||||
|
This address can then be used to connect to the device, e.g., using SSH.
|
||||||
|
Notice the syntax `username@address%interface`:
|
||||||
|
|
||||||
```
|
```
|
||||||
linux-pc:# ssh admin@fe80::ff:fe00:0%tap0
|
linux-pc:# ssh admin@fe80::ff:fec0:ffed%tap0
|
||||||
admin@fe80::ff:fe00:0%tap0's password: admin
|
admin@fe80::ff:fec0:ffed%tap0's password: admin
|
||||||
admin@infix-00-00-00:~$
|
admin@infix-c0-ff-ee:~$
|
||||||
```
|
```
|
||||||
|
|
||||||
## Discovery mechanisms available in Infix
|
|
||||||
|
|
||||||
Infix advertises its presence via the [mDNS](#mdns) and [LLDP](#lldp)
|
## LLDP
|
||||||
discovery protocols.
|
|
||||||
|
|
||||||
|
Infix supports LLDP (IEEE 802.1AB). For a device with factory default
|
||||||
|
settings, the link-local IPv6 address can be read from the Management
|
||||||
|
Address TLV using *tcpdump* or other sniffing tools[^1]:
|
||||||
|
|
||||||
### LLDP
|
|
||||||
|
|
||||||
Infix supports LLDP (IEEE 802.1AB). For a unit with factory default
|
|
||||||
settings, the PC can readout the link-local IPv6 address from the
|
|
||||||
Management Address TLV using *tcpdump* or other sniffing tools[^1].
|
|
||||||
```
|
```
|
||||||
linux-pc:# tcpdump -i tap0 -Qin -v ether proto 0x88cc
|
linux-pc:# tcpdump -i tap0 -Qin -v ether proto 0x88cc
|
||||||
tcpdump: listening on tap0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
|
tcpdump: listening on tap0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
|
||||||
15:51:52.061071 LLDP, length 193
|
15:51:52.061071 LLDP, length 193
|
||||||
Chassis ID TLV (1), length 7
|
Chassis ID TLV (1), length 7
|
||||||
Subtype MAC address (4): 02:00:00:00:00:00 (oui Unknown)
|
Subtype MAC address (4): 02:00:00:c0:ff:ee (oui Unknown)
|
||||||
Port ID TLV (2), length 7
|
Port ID TLV (2), length 7
|
||||||
Subtype MAC address (3): 02:00:00:00:00:00 (oui Unknown)
|
Subtype MAC address (3): 02:00:00:c0:ff:ee (oui Unknown)
|
||||||
Time to Live TLV (3), length 2: TTL 120s
|
Time to Live TLV (3), length 2: TTL 120s
|
||||||
System Name TLV (5), length 14: infix-00-00-00
|
System Name TLV (5), length 14: infix-c0-ff-ee
|
||||||
System Description TLV (6), length 91
|
System Description TLV (6), length 91
|
||||||
Infix by KernelKit Linux 5.19.17 #1 SMP PREEMPT_DYNAMIC Wed Jun 7 08:47:23 CEST 2023 x86_64
|
Infix by KernelKit Linux 5.19.17 #1 SMP PREEMPT_DYNAMIC Wed Jun 7 08:47:23 CEST 2023 x86_64
|
||||||
System Capabilities TLV (7), length 4
|
System Capabilities TLV (7), length 4
|
||||||
System Capabilities [Bridge, WLAN AP, Router, Station Only] (0x009c)
|
System Capabilities [Bridge, WLAN AP, Router, Station Only] (0x009c)
|
||||||
Enabled Capabilities [Station Only] (0x0080)
|
Enabled Capabilities [Station Only] (0x0080)
|
||||||
Management Address TLV (8), length 24
|
Management Address TLV (8), length 24
|
||||||
Management Address length 17, AFI IPv6 (2): fe80::ff:fe00:0
|
Management Address length 17, AFI IPv6 (2): fe80::ff:fec0:ffed
|
||||||
Interface Index Interface Numbering (2): 2
|
Interface Index Interface Numbering (2): 2
|
||||||
Port Description TLV (4), length 4: eth0
|
Port Description TLV (4), length 4: eth0
|
||||||
Organization specific TLV (127), length 9: OUI IEEE 802.3 Private (0x00120f)
|
Organization specific TLV (127), length 9: OUI IEEE 802.3 Private (0x00120f)
|
||||||
@@ -83,11 +83,12 @@ tcpdump: listening on tap0, link-type EN10MB (Ethernet), snapshot length 262144
|
|||||||
linux-pc:#
|
linux-pc:#
|
||||||
```
|
```
|
||||||
|
|
||||||
If the unit has an IPv4 address assigned, it is shown in an additional
|
If the device has an IPv4 address assigned, it is shown in an additional
|
||||||
Management Address TLV.
|
Management Address TLV.
|
||||||
|
|
||||||
> **Note** The Management Addresses shown by LLDP are not
|
> [!NOTE]
|
||||||
> necessarily associated with the port transmitting the LLDP message.
|
> The Management Addresses shown by LLDP are not necessarily associated
|
||||||
|
> with the port transmitting the LLDP message.
|
||||||
|
|
||||||
In the example below, the IPv4 address (10.0.1.1) happens to be
|
In the example below, the IPv4 address (10.0.1.1) happens to be
|
||||||
assigned to *eth0*, while the IPv6 address (2001:db8::1) is not.
|
assigned to *eth0*, while the IPv6 address (2001:db8::1) is not.
|
||||||
@@ -97,11 +98,11 @@ linux-pc:# sudo tcpdump -i tap0 -Qin -v ether proto 0x88cc
|
|||||||
tcpdump: listening on tap0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
|
tcpdump: listening on tap0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
|
||||||
15:46:07.908665 LLDP, length 207
|
15:46:07.908665 LLDP, length 207
|
||||||
Chassis ID TLV (1), length 7
|
Chassis ID TLV (1), length 7
|
||||||
Subtype MAC address (4): 02:00:00:00:00:00 (oui Unknown)
|
Subtype MAC address (4): 02:00:00:c0:ff:ee (oui Unknown)
|
||||||
Port ID TLV (2), length 7
|
Port ID TLV (2), length 7
|
||||||
Subtype MAC address (3): 02:00:00:00:00:00 (oui Unknown)
|
Subtype MAC address (3): 02:00:00:c0:ff:ee (oui Unknown)
|
||||||
Time to Live TLV (3), length 2: TTL 120s
|
Time to Live TLV (3), length 2: TTL 120s
|
||||||
System Name TLV (5), length 14: infix-00-00-00
|
System Name TLV (5), length 14: infix-c0-ff-ee
|
||||||
System Description TLV (6), length 91
|
System Description TLV (6), length 91
|
||||||
Infix by KernelKit Linux 5.19.17 #1 SMP PREEMPT_DYNAMIC Wed Jun 7 08:47:23 CEST 2023 x86_64
|
Infix by KernelKit Linux 5.19.17 #1 SMP PREEMPT_DYNAMIC Wed Jun 7 08:47:23 CEST 2023 x86_64
|
||||||
System Capabilities TLV (7), length 4
|
System Capabilities TLV (7), length 4
|
||||||
@@ -130,47 +131,251 @@ tcpdump: listening on tap0, link-type EN10MB (Ethernet), snapshot length 262144
|
|||||||
linux-pc:#
|
linux-pc:#
|
||||||
```
|
```
|
||||||
|
|
||||||
[^1]: [lldpd: implementation of IEEE 802.1ab
|
The following capabilities are available via NETCONF/RESTCONF or the Infix CLI.
|
||||||
(LLDP)](https://github.com/lldp/lldpd) includes *lldpcli*, which
|
|
||||||
is handy to sniff and display LLDP packets.
|
|
||||||
|
|
||||||
### mDNS
|
### LLDP Enable/Disable
|
||||||
|
|
||||||
DNS-SD/mDNS can be used to discover Infix units and services. Infix
|
The LLDP service can be disabled using the following commands.
|
||||||
units present their IP addresses, services and hostname within the
|
|
||||||
.local domain. This method has good client support in Apple and Linux
|
```
|
||||||
systems. On Linux, tools such as *avahi-browse* or *mdns-scan*[^2] can
|
admin@infix-c0-ff-ee:/> configure
|
||||||
be used to search for devices advertising their services via mDNS.
|
admin@infix-c0-ff-ee:/config/> no lldp
|
||||||
|
admin@infix-c0-ff-ee:/config/> leave
|
||||||
|
admin@infix-c0-ff-ee:/>
|
||||||
|
```
|
||||||
|
|
||||||
|
To reenable it from the CLI config mode:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@test-00-01-00:/config/> set lldp enabled
|
||||||
|
admin@test-00-01-00:/config/> leave
|
||||||
|
```
|
||||||
|
|
||||||
|
### LLDP Message Transmission Interval
|
||||||
|
|
||||||
|
By default, LLDP uses a `message-tx-interval` of 30 seconds, as defined
|
||||||
|
by the IEEE standard. Infix allows this value to be customized.
|
||||||
|
To change it using the CLI:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@test-00-01-00:/config/> set lldp message-tx-interval 1
|
||||||
|
admin@test-00-01-00:/config/> leave
|
||||||
|
```
|
||||||
|
|
||||||
|
### LLDP Administrative Status per Interface
|
||||||
|
|
||||||
|
Infix supports configuring the LLDP administrative status on a per-port
|
||||||
|
basis. The default mode is `tx-and-rx`, but the following options are
|
||||||
|
also supported:
|
||||||
|
|
||||||
|
- `rx-only` – Receive LLDP packets only
|
||||||
|
- `tx-only` – Transmit LLDP packets only
|
||||||
|
- `disabled` – Disable LLDP on the interface
|
||||||
|
|
||||||
|
Example configuration:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@test-00-01-00:/config/> set lldp port e8 dest-mac-address 01:80:C2:00:00:0E admin-status disabled
|
||||||
|
admin@test-00-01-00:/config/> set lldp port e5 dest-mac-address 01:80:C2:00:00:0E admin-status rx-only
|
||||||
|
admin@test-00-01-00:/config/> set lldp port e6 dest-mac-address 01:80:C2:00:00:0E admin-status tx-only
|
||||||
|
admin@test-00-01-00:/config/> leave
|
||||||
|
```
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> The destination MAC address must be the standard LLDP multicast
|
||||||
|
> address: `01:80:C2:00:00:0E`.
|
||||||
|
|
||||||
|
### Displaying LLDP Neighbor Information
|
||||||
|
|
||||||
|
In CLI mode, Infix also provides a convenient `show lldp` command to
|
||||||
|
list LLDP neighbors detected on each interface:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@test-00-01-00:/> show lldp
|
||||||
|
INTERFACE REM-IDX TIME CHASSIS-ID PORT-ID
|
||||||
|
e5 1 902 00:a0:85:00:04:01 00:a0:85:00:04:07
|
||||||
|
e6 3 897 00:a0:85:00:03:01 00:a0:85:00:03:07
|
||||||
|
e8 2 901 00:a0:85:00:02:01 00:a0:85:00:02:05
|
||||||
|
```
|
||||||
|
|
||||||
|
## mDNS-SD
|
||||||
|
|
||||||
|
DNS-SD/mDNS-SD can be used to discover Infix devices and services. By
|
||||||
|
default, Infix use the `.local` domain for advertising services. Some
|
||||||
|
networks use `.lan` instead, so this configurable:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@infix-c0-ff-ee:/> configure
|
||||||
|
admin@infix-c0-ff-ee:/config/> edit mdns
|
||||||
|
admin@infix-c0-ff-ee:/config/mdns/> set domain lan
|
||||||
|
```
|
||||||
|
|
||||||
|
Other available settings include limiting the interfaces mDNS responder
|
||||||
|
acts on:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@infix-c0-ff-ee:/config/> set interfaces allow e1
|
||||||
|
```
|
||||||
|
|
||||||
|
or
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@infix-c0-ff-ee:/config/> set interfaces deny wan
|
||||||
|
```
|
||||||
|
|
||||||
|
The `allow` and `deny` settings are complementary, `deny` always wins.
|
||||||
|
|
||||||
|
----
|
||||||
|
|
||||||
|
In Linux, tools such as *avahi-browse* or *mdns-scan*[^2] can be used to
|
||||||
|
search for devices advertising their services via mDNS.
|
||||||
|
|
||||||
```
|
```
|
||||||
linux-pc:# avahi-browse -ar
|
linux-pc:# avahi-browse -ar
|
||||||
+ tap0 IPv6 infix-00-00-00 SFTP File Transfer local
|
+ tap0 IPv6 infix-c0-ff-ee SFTP File Transfer local
|
||||||
+ tap0 IPv4 infix-00-00-00 SFTP File Transfer local
|
+ tap0 IPv4 infix-c0-ff-ee SFTP File Transfer local
|
||||||
+ tap0 IPv6 infix-00-00-00 SSH Remote Terminal local
|
+ tap0 IPv6 infix-c0-ff-ee SSH Remote Terminal local
|
||||||
+ tap0 IPv4 infix-00-00-00 SSH Remote Terminal local
|
+ tap0 IPv4 infix-c0-ff-ee SSH Remote Terminal local
|
||||||
= tap0 IPv4 infix-00-00-00 SFTP File Transfer local
|
= tap0 IPv4 infix-c0-ff-ee SFTP File Transfer local
|
||||||
hostname = [infix-00-00-00.local]
|
hostname = [infix-c0-ff-ee.local]
|
||||||
address = [10.0.1.1]
|
address = [10.0.1.1]
|
||||||
port = [22]
|
port = [22]
|
||||||
txt = []
|
txt = []
|
||||||
= tap0 IPv4 infix-00-00-00 SSH Remote Terminal local
|
= tap0 IPv4 infix-c0-ff-ee SSH Remote Terminal local
|
||||||
hostname = [infix-00-00-00.local]
|
hostname = [infix-c0-ff-ee.local]
|
||||||
address = [10.0.1.1]
|
address = [10.0.1.1]
|
||||||
port = [22]
|
port = [22]
|
||||||
txt = []
|
txt = []
|
||||||
= tap0 IPv6 infix-00-00-00 SFTP File Transfer local
|
= tap0 IPv6 infix-c0-ff-ee SFTP File Transfer local
|
||||||
hostname = [infix-00-00-00.local]
|
hostname = [infix-c0-ff-ee.local]
|
||||||
address = [fe80::ff:fe00:0]
|
address = [fe80::ff:fec0:ffed]
|
||||||
port = [22]
|
port = [22]
|
||||||
txt = []
|
txt = []
|
||||||
= tap0 IPv6 infix-00-00-00 SSH Remote Terminal local
|
= tap0 IPv6 infix-c0-ff-ee SSH Remote Terminal local
|
||||||
hostname = [infix-00-00-00.local]
|
hostname = [infix-c0-ff-ee.local]
|
||||||
address = [fe80::ff:fe00:0]
|
address = [fe80::ff:fec0:ffed]
|
||||||
port = [22]
|
port = [22]
|
||||||
txt = []
|
txt = []
|
||||||
^C
|
^C
|
||||||
linux-pc:#
|
linux-pc:#
|
||||||
```
|
```
|
||||||
|
|
||||||
|
> [!TIP]
|
||||||
|
> The `-t` option is also very useful, it stops browsing automatically
|
||||||
|
> when a "more or less complete list" has been printed. However, some
|
||||||
|
> devices on the LAN may be in deep sleep so run the command again if
|
||||||
|
> you cannot find the device you are looking for.
|
||||||
|
|
||||||
|
Additionally, *avahi-resolve-host-name* can be used to verify domain
|
||||||
|
name mappings for IP addresses. By default, it translates from IPv4
|
||||||
|
addresses. This function allows users to confirm that addresses are
|
||||||
|
mapped correctly.
|
||||||
|
|
||||||
|
```
|
||||||
|
linux-pc:# avahi-resolve-host-name infix-c0-ff-ee.local
|
||||||
|
infix-c0-ff-ee.local 10.0.1.1
|
||||||
|
linux-pc:#
|
||||||
|
```
|
||||||
|
|
||||||
|
Thanks to mDNS we can use the advertised name instead of the IP
|
||||||
|
address for operations like `ping` and `ssh` as shown below:
|
||||||
|
|
||||||
|
```
|
||||||
|
linux-pc:# ping infix-c0-ff-ee.local -c 3
|
||||||
|
PING infix-c0-ff-ee.local (10.0.1.1) 56(84) bytes of data.
|
||||||
|
64 bytes from 10.0.1.1: icmp_seq=1 ttl=64 time=0.852 ms
|
||||||
|
64 bytes from 10.0.1.1: icmp_seq=2 ttl=64 time=1.12 ms
|
||||||
|
64 bytes from 10.0.1.1: icmp_seq=3 ttl=64 time=1.35 ms
|
||||||
|
|
||||||
|
--- infix-c0-ff-ee.local ping statistics ---
|
||||||
|
3 packets transmitted, 3 received, 0% packet loss, time 2003ms
|
||||||
|
rtt min/avg/max/mdev = 0.852/1.105/1.348/0.202 ms
|
||||||
|
|
||||||
|
linux-pc:# ssh admin@infix-c0-ff-ee.local
|
||||||
|
(admin@infix-c0-ff-ee.local) Password:
|
||||||
|
.-------.
|
||||||
|
| . . | Infix OS — Immutable.Friendly.Secure
|
||||||
|
|-. v .-| https://kernelkit.org
|
||||||
|
'-'---'-
|
||||||
|
|
||||||
|
Run the command 'cli' for interactive OAM
|
||||||
|
|
||||||
|
linux-pc:#
|
||||||
|
```
|
||||||
|
|
||||||
|
To disable mDNS/mDNS-SD, type the commands:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@infix-c0-ff-ee:/> configure
|
||||||
|
admin@infix-c0-ff-ee:/config/> no mdns
|
||||||
|
admin@infix-c0-ff-ee:/config/> leave
|
||||||
|
```
|
||||||
|
|
||||||
|
### Human-Friendly Hostname Alias
|
||||||
|
|
||||||
|
Each Infix deviuce advertise itself as *infix.local*, in addition to its
|
||||||
|
full hostname (e.g., *infix-c0-ff-ee.local* or *foo.local*). This alias
|
||||||
|
works seamlessly on a network with a single Infix device, and makes it
|
||||||
|
easy to connect when the exact hostname is not known in advance. The
|
||||||
|
examples below show how the alias can be used for actions such as
|
||||||
|
pinging or establishing an SSH connection:
|
||||||
|
|
||||||
|
```
|
||||||
|
linux-pc:# ping infix.local -c 3
|
||||||
|
PING infix.local (10.0.1.1) 56(84) bytes of data.
|
||||||
|
64 bytes from 10.0.1.1: icmp_seq=1 ttl=64 time=0.751 ms
|
||||||
|
64 bytes from 10.0.1.1: icmp_seq=2 ttl=64 time=2.28 ms
|
||||||
|
64 bytes from 10.0.1.1: icmp_seq=3 ttl=64 time=1.42 ms
|
||||||
|
|
||||||
|
--- infix.local ping statistics ---
|
||||||
|
3 packets transmitted, 3 received, 0% packet loss, time 2003ms
|
||||||
|
rtt min/avg/max/mdev = 0.751/1.482/2.281/0.626 ms
|
||||||
|
|
||||||
|
linux-pc:# ssh admin@infix.local
|
||||||
|
(admin@infix.local) Password:
|
||||||
|
.-------.
|
||||||
|
| . . | Infix OS — Immutable.Friendly.Secure
|
||||||
|
|-. v .-| https://kernelkit.org
|
||||||
|
'-'---'-
|
||||||
|
|
||||||
|
Run the command 'cli' for interactive OAM
|
||||||
|
|
||||||
|
admin@infix-c0-ff-ee:~$
|
||||||
|
```
|
||||||
|
|
||||||
|
When multiple Infix devices are present on the LAN the alias will not
|
||||||
|
uniquely identify a device; *infix.local* will refer to any of the
|
||||||
|
Infix devices, likely the one that first appeared.
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> When multiple Infix devices are present on the LAN, use the full name,
|
||||||
|
> e.g., *infix-c0-ff-ee.local* or *foo.local* rather than the alias
|
||||||
|
> *infix.local* to deterministically connect to the device.
|
||||||
|
|
||||||
|
|
||||||
|
### Browse Network Using *network.local*
|
||||||
|
|
||||||
|
Another mDNS alias that all Infix devices advertise is *network.local*.
|
||||||
|
This is a web service which basically runs `avahi-browse` and displays a
|
||||||
|
table of other Infix devices and their services.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
With multiple Infix devices on the LAN, one will take the role of your
|
||||||
|
portal to access all others, if it goes down another takes its place.
|
||||||
|
|
||||||
|
To disable the netbrowse service, and the *network.local* alias, the
|
||||||
|
following commands can be used:
|
||||||
|
|
||||||
|
```
|
||||||
|
admin@infix-c0-ff-ee:/> configure
|
||||||
|
admin@infix-c0-ff-ee:/config/> edit web
|
||||||
|
admin@infix-c0-ff-ee:/config/web/> no netbrowse
|
||||||
|
admin@infix-c0-ff-ee:/config/web/> leave
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
[^1]: E.g., [lldpd](https://github.com/lldp/lldpd) which includes the
|
||||||
|
*lldpcli* too, handy to sniff and display LLDP packets.
|
||||||
[^2]: [mdns-scan](http://0pointer.de/lennart/projects/mdns-scan/): a
|
[^2]: [mdns-scan](http://0pointer.de/lennart/projects/mdns-scan/): a
|
||||||
tool for scanning for mDNS/DNS-SD published services on the local
|
tool for scanning for mDNS/DNS-SD services on the local network.
|
||||||
network
|
|
||||||
|
|||||||
+17
-8
@@ -6,13 +6,7 @@ This column contains the mapping between YANG and Linux / Ethtool counters.
|
|||||||
┌─────────────────────────────────┬──────────────────────────────────┐
|
┌─────────────────────────────────┬──────────────────────────────────┐
|
||||||
│ YANG │ Linux / Ethtool │
|
│ YANG │ Linux / Ethtool │
|
||||||
├─────────────────────────────────┼──────────────────────────────────┤
|
├─────────────────────────────────┼──────────────────────────────────┤
|
||||||
│ out-frames │ FramesTransmittedOK │
|
│ in-total-octets │ FramesReceivedOK, │
|
||||||
├─────────────────────────────────┼──────────────────────────────────┤
|
|
||||||
│ out-multicast-frames │ MulticastFramesXmittedOK │
|
|
||||||
├─────────────────────────────────┼──────────────────────────────────┤
|
|
||||||
│ out-broadcast-frames │ BroadcastFramesXmittedOK │
|
|
||||||
├─────────────────────────────────┼──────────────────────────────────┤
|
|
||||||
│ in-total-frames │ FramesReceivedOK, │
|
|
||||||
│ │ FrameCheckSequenceErrors │
|
│ │ FrameCheckSequenceErrors │
|
||||||
│ │ FramesLostDueToIntMACRcvError │
|
│ │ FramesLostDueToIntMACRcvError │
|
||||||
│ │ AlignmentErrors │
|
│ │ AlignmentErrors │
|
||||||
@@ -25,8 +19,23 @@ This column contains the mapping between YANG and Linux / Ethtool counters.
|
|||||||
├─────────────────────────────────┼──────────────────────────────────┤
|
├─────────────────────────────────┼──────────────────────────────────┤
|
||||||
│ in-broadcast-frames │ BroadcastFramesReceivedOK │
|
│ in-broadcast-frames │ BroadcastFramesReceivedOK │
|
||||||
├─────────────────────────────────┼──────────────────────────────────┤
|
├─────────────────────────────────┼──────────────────────────────────┤
|
||||||
|
│ in-error-fcs-frames │ FrameCheckSequenceErrors │
|
||||||
|
├─────────────────────────────────┼──────────────────────────────────┤
|
||||||
│ in-error-undersize-frames │ undersize_pkts │
|
│ in-error-undersize-frames │ undersize_pkts │
|
||||||
├─────────────────────────────────┼──────────────────────────────────┤
|
├─────────────────────────────────┼──────────────────────────────────┤
|
||||||
│ in-error-fcs-frames │ FrameCheckSequenceErrors │
|
| in-error-oversize-frames | etherStatsJabbers, |
|
||||||
|
| | etherStatsOversizePkts |
|
||||||
|
├─────────────────────────────────┼──────────────────────────────────┤
|
||||||
|
│ in-error-mac-internal-frames │ FramesLostDueToIntMACRcvError │
|
||||||
|
├─────────────────────────────────┼──────────────────────────────────┤
|
||||||
|
│ out-frames │ FramesTransmittedOK │
|
||||||
|
├─────────────────────────────────┼──────────────────────────────────┤
|
||||||
|
│ out-multicast-frames │ MulticastFramesXmittedOK │
|
||||||
|
├─────────────────────────────────┼──────────────────────────────────┤
|
||||||
|
│ out-broadcast-frames │ BroadcastFramesXmittedOK │
|
||||||
|
├─────────────────────────────────┼──────────────────────────────────┤
|
||||||
|
│ infix-eth:out-good-octets │ OctetsTransmittedOK │
|
||||||
|
├─────────────────────────────────┼──────────────────────────────────┤
|
||||||
|
│ infix-eth:in-good-octets │ OctetsReceivedOK │
|
||||||
└─────────────────────────────────┴──────────────────────────────────┘
|
└─────────────────────────────────┴──────────────────────────────────┘
|
||||||
```
|
```
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user