mirror of
https://github.com/kernelkit/infix.git
synced 2026-07-26 18:53:01 +02:00
Compare commits
@@ -2,16 +2,15 @@ Contributing to Infix
|
||||
=====================
|
||||
|
||||
We welcome any and all help in the form of bug reports, fixes, patches
|
||||
to add new features -- *preferably as GitHub pull requests*. Other
|
||||
methods are of course also possible: emailing the [maintainers][] a
|
||||
patch or even a raw file, a feature request or an alert of a problem.
|
||||
to add new features -- *preferably as GitHub pull requests*.
|
||||
|
||||
If you are unsure of what to do, or how to implement an idea or bugfix,
|
||||
open an issue with `"[RFC: Unsure if this is a bug ... ?"`, or use the
|
||||
GitHub discussions forum, so we can discuss it. Talking about the code
|
||||
first is the best way to get started before submitting a pull request.
|
||||
If you are unsure of what to do, or how to implement an idea or bug fix,
|
||||
open an issue with `"[RFC]: Unsure if this is a bug ... ?"`, or use the
|
||||
[GitHub discussions forum](https://github.com/orgs/kernelkit/discussions).
|
||||
Talking about code and problems first is often the best way to get started
|
||||
before submitting a pull request.
|
||||
|
||||
Either way, when sending an email, patch, or pull request, start by
|
||||
When submitting a bug report, patch, or pull request, please start by
|
||||
stating the version the change is made against, what it does, and why.
|
||||
|
||||
Please take care to ensure you follow the project coding style and the
|
||||
@@ -72,7 +71,6 @@ The *"maintainers have the right and responsibility to remove, edit,
|
||||
or reject comments, commits, code, wiki edits, issues, and other
|
||||
contributions that are not aligned to this Code of Conduct."*
|
||||
|
||||
[1]: ../doc/MAINTAINERS
|
||||
[KNF]: https://en.wikipedia.org/wiki/Kernel_Normal_Form
|
||||
[gitbook]: https://git-scm.com/book/ch5-2.html
|
||||
[conduct]: CODE-OF-CONDUCT.md
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
Paid support and development provided by Addiva Elektronik <https://addiva.se>
|
||||
@@ -10,7 +10,7 @@ on:
|
||||
|
||||
jobs:
|
||||
build:
|
||||
if: ${{github.ref == 'refs/heads/main' && github.event_name == 'push'}} || github.event_name == 'workflow_dispatch'
|
||||
if: ${{github.ref_name == 'main' && github.event_name == 'push'}} || github.event_name == 'workflow_dispatch'
|
||||
name: Build ${{ matrix.platform }} ${{ matrix.variant }}
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
@@ -72,7 +72,7 @@ jobs:
|
||||
with:
|
||||
path: output/${{ steps.vars.outputs.tgz }}
|
||||
release:
|
||||
if: github.repository == 'kernelkit/infix' && github.ref == 'refs/heads/main'
|
||||
if: ${{github.repository_owner == 'kernelkit' && github.ref_name == 'main'}}
|
||||
name: Upload Latest Build
|
||||
needs: build
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
@@ -81,7 +81,7 @@ jobs:
|
||||
- uses: actions/download-artifact@v3
|
||||
- name: Extract ChangeLog entry ...
|
||||
run: |
|
||||
awk '/-----*/{if (x == 1) exit; x=1;next}x' ChangeLog.md \
|
||||
awk '/-----*/{if (x == 1) exit; x=1;next}x' doc/ChangeLog.md \
|
||||
|head -n -1 > release.md
|
||||
cat release.md
|
||||
- uses: ncipollo/release-action@v1
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
# To enable automatic sync of your Infix fork every day, or on dispatch,
|
||||
# set the repoistory or organisation variable (not secret):
|
||||
#
|
||||
# SYNC_FORK = 'true'
|
||||
#
|
||||
# See https://docs.github.com/en/actions/learn-github-actions/variables
|
||||
name: Synchronize your fork of Infix with upstream
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: 42 2 * * *
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
sync_fork:
|
||||
if: ${{github.repository_owner != 'kernelkit' && vars.SYNC_FORK == 'true' }}
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: TobKed/github-forks-sync-action@master
|
||||
with:
|
||||
github_token: ${{ secrets.GITHUB_TOKEN }}
|
||||
upstream_repository: KernelKit/infix
|
||||
upstream_branch: main
|
||||
target_branch: main
|
||||
force: true
|
||||
tags: true
|
||||
@@ -1,7 +1,9 @@
|
||||
*~
|
||||
.gdb_history
|
||||
/.backup
|
||||
/.ccache
|
||||
/dl
|
||||
/output*
|
||||
/x-*
|
||||
/test/.venv
|
||||
/local.mk
|
||||
|
||||
@@ -1,58 +0,0 @@
|
||||
Change Log
|
||||
==========
|
||||
|
||||
All notable changes to the project are documented in this file.
|
||||
|
||||
|
||||
[v23.06.0][] - 2023-06-23
|
||||
-------------------------
|
||||
|
||||
Midsummer release. The first official Infix release, based on [Buildroot
|
||||
2023.02.2][br2023.02.2], with NETCONF support using the [sysrepo][] and
|
||||
[netopeer2][].
|
||||
|
||||
Supported YANG models in addition to those used by sysrepo and netopeer:
|
||||
|
||||
- [ietf-system][]
|
||||
- Everything except radius authentication and timezone-utc-offset
|
||||
- Augmented with MotD (Message of the Day), Infix YANG model
|
||||
- [ietf-interfaces][]
|
||||
- [ietf-ip][] augmented with IPv4LL similar to standardized IPv6LL
|
||||
- [ietf-if-vlan-encapsulation][], Linux VLAN interfaces, e.g. `eth0.10`
|
||||
- Linux bridge interfaces with native VLAN support, Infix YANG model
|
||||
- Linux VETH pairs, Infix YANG model
|
||||
|
||||
> **DISCLAIMER:** the [Infix YANG models for Linux][yang23.06], are
|
||||
> still under heavy development. New revisions are expected which may
|
||||
> not be backwards compatible. When upgrading to a new release, test on
|
||||
> a GNS3 staging environment first, or start over from a factory reset.
|
||||
|
||||
[br2023.02.2]: https://git.busybox.net/buildroot/tag/?h=2023.02.2
|
||||
[ietf-system]: https://www.rfc-editor.org/rfc/rfc7317.html
|
||||
[ietf-interfaces]: https://www.rfc-editor.org/rfc/rfc7223.html
|
||||
[ietf-ip]: https://www.rfc-editor.org/rfc/rfc8344.html
|
||||
[ietf-if-vlan-encapsulation]: https://www.ietf.org/id/draft-ietf-netmod-sub-intf-vlan-model-08.html
|
||||
[yang23.06]: https://github.com/kernelkit/infix/blob/aea74842e0475441d8df834f2dcd8cbc21fa253d/src/confd/yang/infix-interfaces%402023-06-05.yang
|
||||
|
||||
### Changes
|
||||
|
||||
- Bump sysrepo to v2.2.73
|
||||
- Backport support for initializing factory-default data store with
|
||||
default config data also for sysrepo internal modules.
|
||||
- Add support for `sysrepocfg -Cfactory -d running`, for testing
|
||||
- Bump netopeer2 to v2.1.62
|
||||
- Bump libyang to v2.1.80
|
||||
- Add klish, a CLI for sysrepo
|
||||
- Add podman for container support, backported from upstream Buildroot
|
||||
- Add conmon for container support, backported from upstream Buildroot
|
||||
- Backport cni-plugins support for host-local and static plugins
|
||||
|
||||
### Fixes
|
||||
|
||||
- N/A
|
||||
|
||||
[buildroot]: https://buildroot.org/
|
||||
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v23.06.0...HEAD
|
||||
[v23.06.0]: https://github.com/kernelkit/infix/compare/BASE...v23.06.0
|
||||
[sysrepo]: https://www.sysrepo.org/
|
||||
[netopeer2]: https://github.com/CESNET/netopeer2
|
||||
@@ -1,217 +1,47 @@
|
||||
<img align="right" src="doc/text3134.png" alt="Infix Linux Networking Made Easy">
|
||||
<img align="right" src="doc/logo.png" alt="Infix - Linux <3 NETCONF" width=480>
|
||||
<details><summary><b>Documentation</b></summary>
|
||||
|
||||
* [Introduction](#introduction)
|
||||
* [NETCONF Mode](#netconf-mode)
|
||||
* [NETCONF Mode](#netconf-mode)
|
||||
* [Classic Mode](#classic-mode)
|
||||
* [Hybrid Mode](#hybrid-mode)
|
||||
* [Hardware](#hardware)
|
||||
* [Qemu](#qemu)
|
||||
* [GNS3](#gns3)
|
||||
* [Building](#building)
|
||||
* [Origin & Licensing](origin--licensing)
|
||||
- **Infix In-Depth**
|
||||
- [Infix Variants](doc/variant.md)
|
||||
- [Boot Procedure](doc/boot.md)
|
||||
- [Containers in Infix](doc/container.md)
|
||||
- [Developer's Guide](doc/developers-guide.md)
|
||||
- [Discover Your Device](doc/discovery.md)
|
||||
- [Virtual Environments](doc/virtual.md)
|
||||
- [Origin & Licensing](doc/license.md)
|
||||
- **CLI Topics**
|
||||
- [Introduction to the CLI](doc/cli/introduction.md)
|
||||
- [CLI User's Guide](doc/cli/tutorial.md)
|
||||
- [Quick Overview](doc/cli/quick.md)
|
||||
|
||||
</details>
|
||||
|
||||
Introduction
|
||||
------------
|
||||
Infix is a Linux Network Operating System (NOS) based on [Buildroot][1],
|
||||
and [sysrepo][2]. A powerful mix that ease porting to different
|
||||
platforms, simplify long-term maintenance, and provide made-easy
|
||||
management using NETCONF[^1].
|
||||
|
||||
Infix is an embedded Linux Network Operating System (NOS) based on
|
||||
[Buildroot][1], [Finit][2], [ifupdown-ng][3], and [sysrepo][6].
|
||||
Providing an easy-to-maintain and easy-to-port Open Source base for
|
||||
networked equipment.
|
||||
Infix can run on many different types of architectures and boards, much
|
||||
thanks to Linux and Buildroot. Currently the focus is on 64-bit ARM
|
||||
devices, optionally with switching fabric supported by Linux switchdev.
|
||||
The [following boards](board/aarch64/README.md) are fully supported:
|
||||
|
||||
- Marvell CN9130 CRB
|
||||
- Marvell EspressoBIN
|
||||
- Microchip SparX-5i PCB135 (eMMC)
|
||||
|
||||
An x86_64 build is also available, primarily intended for development
|
||||
and testing, but can also be used for evaluation and demo purposes. For
|
||||
more information, see: [Infix in Virtual Environments](doc/virtual.md).
|
||||
|
||||
> See the [GitHub Releases](https://github.com/kernelkit/infix/releases)
|
||||
> page for out pre-built images. The *Latest Build* has the bleeding edge
|
||||
> images, if possible we recommend using a versioned release.
|
||||
> page for our pre-built images. The *Latest Build* has the bleeding
|
||||
> edge images, if possible we recommend using a versioned release.
|
||||
>
|
||||
> For customer specific builds of Infix, see your respective repository.
|
||||
> For *customer specific builds* of Infix, see your product repository.
|
||||
|
||||
Infix has two main *flavors*, or defconfigs:
|
||||
[^1]: or RESTCONF, <https://datatracker.ietf.org/doc/html/rfc8040>, for
|
||||
mode information, see [Infix Variants](doc/variant.md).
|
||||
|
||||
- **NETCONF:** the default, managed using, e.g., the `cli` tool
|
||||
- **Classic:** built from `$ARCH_classic_defconfig`, more below
|
||||
|
||||
Both flavors have an `admin` user, which is allowed to log in from
|
||||
remote, password `admin` on standard builds. It is the recommended
|
||||
account to use for managing Infix. (The `root` account is currently
|
||||
also available, but will soon become a non-login account used only for
|
||||
running system services.)
|
||||
|
||||
|
||||
### NETCONF Mode
|
||||
|
||||
NETCONF is the primary reason Infix exists. Configuration of an Infix
|
||||
device can be done either remotely, using tools like [netconf-client][]
|
||||
or [netopeer2-cli][], or locally using the [`cli` tool](doc/cli.md).
|
||||
|
||||
Infix use [sysrepo][6] as the data store for NETCONF. A set of plugins
|
||||
configure the network, using iproute2, generate configuration files in
|
||||
`/etc`, and control the system daemons, e.g., enable DHCP client on an
|
||||
interface.
|
||||
|
||||
|
||||
### Classic Mode
|
||||
|
||||
Here it is up to the administrator to modify configuration files in
|
||||
`/etc` and control the system daemons using the `initctl` tool.
|
||||
|
||||
See the online `help` command for an introduction to the system.
|
||||
|
||||
|
||||
### Hybrid Mode
|
||||
|
||||
Since Infix is under heavy development, it does not yet have all bells
|
||||
and whistles in place, in particular in the default build. To that end
|
||||
it is possible to manually manage certain services that are not yet
|
||||
possible to configure using NETCONF.
|
||||
|
||||
At bootstrap Finit can start user scripts from a [run-parts(8)][] like
|
||||
directory: `/cfg/start.d`. For example, the following starts OSPF:
|
||||
|
||||
```sh
|
||||
root@infix:~$ mkdir /cfg/start.d
|
||||
root@infix:~$ cd /cfg/start.d
|
||||
root@infix:/cfg/start.d$ cat <<EOF >10-enable-ospf.sh
|
||||
#!/bin/sh
|
||||
# Use vtysh to modify the OSPF configuration
|
||||
rm /etc/frr/frr.conf
|
||||
ln -s /cfg/frr/frr.conf /etc/frr/
|
||||
initctl enable zebra
|
||||
initctl enable ospfd
|
||||
initctl enable bfdd
|
||||
exit 0
|
||||
EOF
|
||||
root@infix:/cfg/start.d$ chmod +x 10-enable-ospf.sh
|
||||
```
|
||||
|
||||
> **Note:** Neither [Frr](https://frrouting.org) (Zebra/OSPF/BFD) or
|
||||
> [podman](https://podman.io) are enabled in default Infix builds.
|
||||
> Please use customer specific builds, or enable it yourself in Infix by
|
||||
> using `make menuconfig` followed by rebuilding the image.
|
||||
|
||||
This is also the way to start containers (provided the images have been
|
||||
downloaded with `podman pull` first):
|
||||
|
||||
```
|
||||
root@infix:/cfg/start.d$ cat <<EOF >20-enable-container.sh
|
||||
#!/bin/sh
|
||||
podman-service -e -d "Nginx container" -p "-p 80:80" nginx:alpine
|
||||
exit 0
|
||||
EOF
|
||||
root@infix:/cfg/start.d$ chmod +x 20-enable-container.sh
|
||||
```
|
||||
|
||||
Reboot to activate the changes. To activate the changes without
|
||||
rebooting, run the script and call `initctl reload`.
|
||||
|
||||
|
||||
Hardware
|
||||
--------
|
||||
|
||||
### aarch64
|
||||
|
||||
By default, Infix builds with support for the following boards (you
|
||||
may enable additional boards in the config, of course):
|
||||
|
||||
- Marvell CN9130 CRB
|
||||
- Marvell EspressoBIN
|
||||
- Microchip SparX-5i PCB135 (eMMC)
|
||||
|
||||
See the aarch64 specific [documentation](board/aarch64/README.md) for more
|
||||
information.
|
||||
|
||||
### x86_64
|
||||
|
||||
Primarily intended to be run under [QEMU][] for development & test as
|
||||
well as evaluation, demo and [training][] purposes, e.g. using [GNS3][]
|
||||
or [Qeneth][7].
|
||||
|
||||
|
||||
QEMU
|
||||
----
|
||||
|
||||
A virtualized instance can easily be launched from a Linux system, with
|
||||
Qemu installed, by issuing `make run`.
|
||||
|
||||
Some settings, e.g. networking, can be configured via `make menuconfig`
|
||||
under `External options -> QEMU virtualization`.
|
||||
|
||||
|
||||
GNS3
|
||||
----
|
||||
|
||||
Download the [latest build][0] of the `x86_64`, or `x86_64_classic`
|
||||
flavor. Unpack in a dedicated directory and use ["Import Appliance"][9]
|
||||
to install the `.gns3a` file into GNS3. Infix (`x86_64`) is in the
|
||||
"Router" category, it has 10 interfaces available by default for use as
|
||||
switch ports or routing. The *classic* build only has one interface by
|
||||
default, geared more towards acting as an end device.
|
||||
|
||||
|
||||
Building
|
||||
--------
|
||||
|
||||
Buildroot is almost stand-alone, but need a few locally installed tools
|
||||
to bootstrap itself. For details, see the [excellent manual][manual].
|
||||
|
||||
Briefly, to build an Infix image; select the target and then make:
|
||||
|
||||
make x86_64_defconfig
|
||||
make
|
||||
|
||||
Online help is available:
|
||||
|
||||
make help
|
||||
|
||||
To see available defconfigs for supported targets, use:
|
||||
|
||||
make list-defconfigs
|
||||
|
||||
> **Note:** build dependencies (Debian/Ubuntu): <kbd>sudo apt install make libssl-dev</kbd>
|
||||
|
||||
|
||||
Origin & Licensing
|
||||
------------------
|
||||
|
||||
Infix is entirely built on Open Source components (packages). Most of
|
||||
them, as well as the build system with its helper scripts and tools, is
|
||||
from [Buiildroot][1], which is distributed under the terms of the GNU
|
||||
General Public License (GPL). See the file COPYING for details.
|
||||
|
||||
Some files in Buildroot contain a different license statement. Those
|
||||
files are licensed under the license contained in the file itself.
|
||||
|
||||
Buildroot and Infix also bundle patch files, which are applied to the
|
||||
sources of the various packages. Those patches are not covered by the
|
||||
license of Buildroot or Infix. Instead, they are covered by the license
|
||||
of the software to which the patches are applied. When said software is
|
||||
available under multiple licenses, the patches are only provided under
|
||||
the publicly accessible licenses.
|
||||
|
||||
Infix releases include the license information covering all Open Source
|
||||
packages. This is extracted automatically at build time using the tool
|
||||
`make legal-info`. Any proprietary software built on top of Infix, or
|
||||
Buildroot, would need separate auditing to ensure it does not link with
|
||||
any GPL[^1] licensed library.
|
||||
|
||||
[^1]: Infix image builds use GNU libc (GLIBC) which is covered by the
|
||||
[LGPL][4]. The LGPL *does allow* proprietary software, as long as
|
||||
said software is linking dynamically, [not statically][5], to GLIBC.
|
||||
|
||||
[0]: https://github.com/kernelkit/infix/releases/tag/latest
|
||||
[1]: https://buildroot.org/
|
||||
[2]: https://github.com/troglobit/finit
|
||||
[3]: https://github.com/ifupdown-ng/ifupdown-ng
|
||||
[4]: https://en.wikipedia.org/wiki/GNU_Lesser_General_Public_License
|
||||
[5]: https://lwn.net/Articles/117972/
|
||||
[6]: https://www.sysrepo.org/
|
||||
[7]: https://github.com/wkz/qeneth
|
||||
[8]: https://addiva-elektronik.github.io/2023/05/12/using-netconf-client-and-server-to-update-switch-configuration/
|
||||
[9]: https://docs.gns3.com/docs/using-gns3/beginners/import-gns3-appliance/
|
||||
[QEMU]: https://www.qemu.org/
|
||||
[GNS3]: https://gns3.com/
|
||||
[training]: https://addiva-elektronik.github.io/
|
||||
[manual]: https://buildroot.org/downloads/manual/manual.html
|
||||
[run-parts(8)]: https://manpages.ubuntu.com/manpages/trusty/man8/run-parts.8.html
|
||||
[netconf-client]: https://pypi.org/project/netconf-client/
|
||||
[netopeer2-cli]: https://github.com/CESNET/netopeer2
|
||||
[2]: https://www.sysrepo.org/
|
||||
|
||||
@@ -0,0 +1,51 @@
|
||||
/ {
|
||||
config {
|
||||
environment {
|
||||
/* After the MMC driver has enabled bus power,
|
||||
* the controller seems to sometimes detect a
|
||||
* card removal state , which causes it to
|
||||
* disable power again. This hack re-enables the
|
||||
* bus power in those cases.
|
||||
*/
|
||||
bootcmd = "
|
||||
setexpr.b pwrctl *0xf2780029
|
||||
setexpr pwrctl ${pwrctl} \"|\" 1
|
||||
mw.b 0xf2780029 ${pwrctl}
|
||||
|
||||
run ixboot
|
||||
";
|
||||
boot_targets = "mmc1";
|
||||
ethprime = "eth1";
|
||||
|
||||
/* Uncomment this if you're debugging U-Boot
|
||||
*
|
||||
* This will allow you to break out of the
|
||||
* normal boot flow and into the interactive
|
||||
* console.
|
||||
*
|
||||
* To upgrade U-Boot itself, simply set the
|
||||
* `bootfile` variable to the path of
|
||||
* `flash-image.bin` on your TFTP server, then
|
||||
* issue `run ixupgradeboot`.
|
||||
*/
|
||||
/* bootdelay = "2"; */
|
||||
/* ixupgradeboot = " */
|
||||
/* dhcp */
|
||||
/* setexpr fileblks ${filesize} + 0x1ff */
|
||||
/* setexpr fileblks ${fileblks} / 0x200 */
|
||||
|
||||
/* mmc dev 1 */
|
||||
/* part start mmc 1 boot bootstart */
|
||||
/* part size mmc 1 boot bootsize */
|
||||
|
||||
|
||||
/* mmc erase ${bootstart} ${bootsize} */
|
||||
/* mmc write ${fileaddr} ${bootstart} ${fileblks} */
|
||||
/* "; */
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
/* &cp0_eth0 { */
|
||||
/* phy-mode = "10gbase-r"; */
|
||||
/* }; */
|
||||
@@ -0,0 +1,4 @@
|
||||
CONFIG_DEVICE_TREE_INCLUDES="infix-env.dtsi infix-key.dtsi cn9130-crb-env.dtsi"
|
||||
|
||||
CONFIG_ENV_IS_NOWHERE=y
|
||||
# CONFIG_ENV_IS_IN_MMC is not set
|
||||
@@ -1,3 +1,4 @@
|
||||
label Infix (aarch64)
|
||||
kernel /boot/Image
|
||||
fdtdir /boot
|
||||
append ${bootargs_root} ${bootargs_rauc} ${bootargs_log}
|
||||
|
||||
@@ -1,9 +1,10 @@
|
||||
[system]
|
||||
compatible=infix-aarch64
|
||||
bootloader=uboot
|
||||
statusfile=/var/lib/rauc/status
|
||||
statusfile=/mnt/aux/rauc.status
|
||||
mountprefix=/var/lib/rauc/mnt
|
||||
bundle-formats=-plain
|
||||
max-bundle-download-size=1073741824
|
||||
|
||||
[keyring]
|
||||
directory=/etc/rauc/keys
|
||||
@@ -17,5 +18,5 @@ device=/dev/disk/by-partlabel/secondary
|
||||
bootname=secondary
|
||||
|
||||
[slot.net.0]
|
||||
device=/dev/ram
|
||||
device=/dev/ram0
|
||||
bootname=net
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
# System-wide .bashrc file for interactive bash(1) shells.
|
||||
|
||||
# If not running interactively, don't do anything
|
||||
[ -z "$PS1" ] && return
|
||||
|
||||
# Reevaluate for each line, in case hostname changes
|
||||
function prompt_command
|
||||
{
|
||||
PS1="\u@$(hostname):\w\$ "
|
||||
}
|
||||
export PROMPT_COMMAND=prompt_command
|
||||
|
||||
# check the window size after each command and, if necessary,
|
||||
# update the values of LINES and COLUMNS.
|
||||
shopt -s checkwinsize
|
||||
|
||||
# Disble built-ins
|
||||
enable -n help
|
||||
+54
-1
@@ -31,7 +31,7 @@ menuconfig DISK_IMAGE
|
||||
- Creating a GNS3 appliance
|
||||
- Developing/debugging issues in the boot process in QEMU
|
||||
|
||||
config DISK_IMAGE_SIZE
|
||||
menuconfig DISK_IMAGE_SIZE
|
||||
string "Image size"
|
||||
depends on DISK_IMAGE
|
||||
default "512M"
|
||||
@@ -44,6 +44,59 @@ config DISK_IMAGE_SIZE
|
||||
|
||||
Minimum supported size is 512M.
|
||||
|
||||
choice
|
||||
prompt "Bootloader"
|
||||
depends on DISK_IMAGE
|
||||
default DISK_IMAGE_BOOT_EFI if BR2_x86_64
|
||||
default DISK_IMAGE_BOOT_NONE
|
||||
|
||||
config DISK_IMAGE_BOOT_NONE
|
||||
bool "None"
|
||||
help
|
||||
Do not create any bootloader partition in the disk image.
|
||||
|
||||
config DISK_IMAGE_BOOT_EFI
|
||||
bool "EFI"
|
||||
help
|
||||
Create a boot partition from a directory containing an EFI
|
||||
boot application, e.g. GRUB.
|
||||
|
||||
config DISK_IMAGE_BOOT_BIN
|
||||
bool "Binary"
|
||||
help
|
||||
Create a boot partition from a raw image containing the boot
|
||||
application, e.g. U-Boot.
|
||||
|
||||
endchoice
|
||||
|
||||
config DISK_IMAGE_BOOT_DATA
|
||||
string "Bootloader data"
|
||||
depends on DISK_IMAGE
|
||||
depends on DISK_IMAGE_BOOT_EFI || DISK_IMAGE_BOOT_BIN
|
||||
default "${BINARIES_DIR}/efi-part/EFI" if BR2_x86_64
|
||||
help
|
||||
Path to the directory or file holding the bootloader data.
|
||||
|
||||
config DISK_IMAGE_BOOT_OFFSET
|
||||
hex "Bootloader offset"
|
||||
depends on DISK_IMAGE
|
||||
depends on DISK_IMAGE_BOOT_EFI || DISK_IMAGE_BOOT_BIN
|
||||
default 0x8000
|
||||
help
|
||||
Offset at which the bootloader partition is placed. Remember
|
||||
to make sure that the GPT still fits at the start of the
|
||||
image.
|
||||
|
||||
config DISK_IMAGE_RELEASE_URL
|
||||
string "Infix URL"
|
||||
depends on DISK_IMAGE
|
||||
depends on !BR2_TARGET_ROOTFS_SQUASHFS
|
||||
default "https://github.com/kernelkit/infix/releases/download/latest/infix-${BR2_ARCH}.tar.gz"
|
||||
help
|
||||
In situations where Infix itself is not being built, but a
|
||||
disk image is, i.e. when building a bootloader: place this
|
||||
Infix release in the primary and secondary partitions.
|
||||
|
||||
menuconfig GNS3_APPLIANCE
|
||||
bool "GNS3 Appliance"
|
||||
select DISK_IMAGE
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
#
|
||||
# Automatically generated make config: don't edit
|
||||
# Busybox version: 1.35.0
|
||||
# Mon Dec 12 13:47:01 2022
|
||||
# Busybox version: 1.36.0
|
||||
# Fri Jul 7 17:59:34 2023
|
||||
#
|
||||
CONFIG_HAVE_DOT_CONFIG=y
|
||||
|
||||
@@ -93,6 +93,9 @@ CONFIG_FEATURE_BUFFERS_USE_MALLOC=y
|
||||
# CONFIG_FEATURE_BUFFERS_GO_IN_BSS is not set
|
||||
CONFIG_PASSWORD_MINLEN=6
|
||||
CONFIG_MD5_SMALL=1
|
||||
CONFIG_SHA1_SMALL=3
|
||||
CONFIG_SHA1_HWACCEL=y
|
||||
CONFIG_SHA256_HWACCEL=y
|
||||
CONFIG_SHA3_SMALL=1
|
||||
CONFIG_FEATURE_NON_POSIX_CP=y
|
||||
# CONFIG_FEATURE_VERBOSE_CP_MESSAGE is not set
|
||||
@@ -123,6 +126,9 @@ CONFIG_LAST_SUPPORTED_WCHAR=0
|
||||
# CONFIG_UNICODE_BIDI_SUPPORT is not set
|
||||
# CONFIG_UNICODE_NEUTRAL_TABLE is not set
|
||||
# CONFIG_UNICODE_PRESERVE_BROKEN is not set
|
||||
# CONFIG_LOOP_CONFIGURE is not set
|
||||
# CONFIG_NO_LOOP_CONFIGURE is not set
|
||||
CONFIG_TRY_LOOP_CONFIGURE=y
|
||||
|
||||
#
|
||||
# Applets
|
||||
@@ -338,6 +344,7 @@ CONFIG_FEATURE_TR_CLASSES=y
|
||||
CONFIG_FEATURE_TR_EQUIV=y
|
||||
CONFIG_TRUE=y
|
||||
CONFIG_TRUNCATE=y
|
||||
CONFIG_TSORT=y
|
||||
CONFIG_TTY=y
|
||||
CONFIG_UNAME=y
|
||||
CONFIG_UNAME_OSNAME="GNU/Linux"
|
||||
@@ -526,13 +533,13 @@ CONFIG_USE_BB_CRYPT_SHA=y
|
||||
CONFIG_ADDGROUP=y
|
||||
CONFIG_FEATURE_ADDUSER_TO_GROUP=y
|
||||
CONFIG_ADDUSER=y
|
||||
# CONFIG_FEATURE_CHECK_NAMES is not set
|
||||
CONFIG_FEATURE_CHECK_NAMES=y
|
||||
CONFIG_LAST_ID=60000
|
||||
CONFIG_FIRST_SYSTEM_ID=100
|
||||
CONFIG_LAST_SYSTEM_ID=999
|
||||
# CONFIG_CHPASSWD is not set
|
||||
CONFIG_FEATURE_DEFAULT_PASSWD_ALGO="md5"
|
||||
# CONFIG_CRYPTPW is not set
|
||||
CONFIG_CRYPTPW=y
|
||||
CONFIG_MKPASSWD=y
|
||||
CONFIG_DELUSER=y
|
||||
CONFIG_DELGROUP=y
|
||||
@@ -831,10 +838,12 @@ CONFIG_READAHEAD=y
|
||||
CONFIG_RFKILL=y
|
||||
CONFIG_RUNLEVEL=y
|
||||
CONFIG_RX=y
|
||||
CONFIG_SEEDRNG=y
|
||||
CONFIG_SETFATTR=y
|
||||
CONFIG_SETSERIAL=y
|
||||
CONFIG_STRINGS=y
|
||||
CONFIG_TIME=y
|
||||
CONFIG_TREE=y
|
||||
CONFIG_TS=y
|
||||
CONFIG_TTYSIZE=y
|
||||
CONFIG_UBIATTACH=y
|
||||
@@ -1007,6 +1016,7 @@ CONFIG_UDHCPC=y
|
||||
CONFIG_FEATURE_UDHCPC_ARPING=y
|
||||
CONFIG_FEATURE_UDHCPC_SANITIZEOPT=y
|
||||
CONFIG_UDHCPC_DEFAULT_SCRIPT="/usr/share/udhcpc/default.script"
|
||||
CONFIG_UDHCPC6_DEFAULT_SCRIPT="/usr/share/udhcpc/default6.script"
|
||||
CONFIG_UDHCPC6=y
|
||||
CONFIG_FEATURE_UDHCPC6_RFC3646=y
|
||||
CONFIG_FEATURE_UDHCPC6_RFC4704=y
|
||||
@@ -1141,6 +1151,7 @@ CONFIG_ASH_IDLE_TIMEOUT=y
|
||||
CONFIG_ASH_ECHO=y
|
||||
CONFIG_ASH_PRINTF=y
|
||||
CONFIG_ASH_TEST=y
|
||||
CONFIG_ASH_SLEEP=y
|
||||
CONFIG_ASH_HELP=y
|
||||
CONFIG_ASH_GETOPTS=y
|
||||
CONFIG_ASH_CMDCMD=y
|
||||
|
||||
+26
-7
@@ -30,14 +30,14 @@ dimension()
|
||||
cfgsize=$((256 << M))
|
||||
# var is at least ~1.75G
|
||||
elif [ $total -ge $((1 << G)) ]; then
|
||||
bootsize=$(( 4 << M))
|
||||
auxsize=$(( 4 << M))
|
||||
bootsize=$(( 8 << M))
|
||||
auxsize=$(( 8 << M))
|
||||
imgsize=$((256 << M))
|
||||
cfgsize=$(( 64 << M))
|
||||
# var is at least ~0.5G
|
||||
elif [ $total -ge $((512 << M)) ]; then
|
||||
bootsize=$(( 4 << M))
|
||||
auxsize=$(( 4 << M))
|
||||
bootsize=$(( 8 << M))
|
||||
auxsize=$(( 8 << M))
|
||||
imgsize=$((192 << M))
|
||||
cfgsize=$(( 16 << M))
|
||||
# var is at least ~100M
|
||||
@@ -80,7 +80,7 @@ probeboot()
|
||||
|
||||
genboot()
|
||||
{
|
||||
if [ -d $BINARIES_DIR/efi-part/EFI ]; then
|
||||
if [ -d "$bootdata" ]; then
|
||||
bootimg=$(cat <<EOF
|
||||
image efi-part.vfat {
|
||||
size = $bootsize
|
||||
@@ -102,6 +102,17 @@ EOF
|
||||
EOF
|
||||
)
|
||||
|
||||
elif [ -f "$bootdata" ]; then
|
||||
bootpart=$(cat <<EOF
|
||||
partition boot {
|
||||
offset = $bootoffs
|
||||
partition-type-uuid = U
|
||||
bootable = true
|
||||
image = $bootdata
|
||||
size = $bootsize
|
||||
}
|
||||
EOF
|
||||
)
|
||||
fi
|
||||
}
|
||||
|
||||
@@ -110,15 +121,22 @@ root=$BUILD_DIR/genimage.root
|
||||
tmp=$BUILD_DIR/genimage.tmp
|
||||
|
||||
total=$((512 << M))
|
||||
bootoffs=
|
||||
bootoffs=$((32 << K))
|
||||
bootdata=
|
||||
bootimg=
|
||||
bootpart=
|
||||
|
||||
while getopts "a:s:" opt; do
|
||||
while getopts "a:b:B:s:" opt; do
|
||||
case ${opt} in
|
||||
a)
|
||||
arch=$OPTARG
|
||||
;;
|
||||
b)
|
||||
bootdata=$OPTARG
|
||||
;;
|
||||
B)
|
||||
bootoffs=$(($OPTARG))
|
||||
;;
|
||||
s)
|
||||
total=$(size2int $OPTARG)
|
||||
;;
|
||||
@@ -157,6 +175,7 @@ awk \
|
||||
mkdir -p $root/aux
|
||||
cp -f $BINARIES_DIR/rootfs.itbh $root/aux/primary.itbh
|
||||
cp -f $BINARIES_DIR/rootfs.itbh $root/aux/secondary.itbh
|
||||
cp -f $BINARIES_DIR/rauc.status $root/aux/rauc.status
|
||||
|
||||
case "$arch" in
|
||||
aarch64)
|
||||
|
||||
+12
-2
@@ -18,12 +18,22 @@ load_cfg()
|
||||
load_cfg
|
||||
[ "$FIT_IMAGE" = "y" ] || exit 0
|
||||
|
||||
work=$(pwd)/build/fit-image-local
|
||||
work=$BUILD_DIR/fit-image-local
|
||||
dtbs=$(find $BINARIES_DIR -name '*.dtb')
|
||||
kernel=$(find $BINARIES_DIR -name '*Image' | head -n1)
|
||||
squash=$BINARIES_DIR/rootfs.squashfs
|
||||
|
||||
mkdir -p $work
|
||||
gzip <$kernel >$work/Image.gz
|
||||
kernel=$work/Image.gz
|
||||
|
||||
rm -rf $work/rootfs
|
||||
unsquashfs -f -d $work/rootfs $squash
|
||||
rm -f $work/rootfs/boot/*Image
|
||||
|
||||
squash=$work/rootfs-no-kernel.squashfs
|
||||
rm -f $squash
|
||||
mksquashfs $work/rootfs $squash
|
||||
|
||||
# mkimage will only align images to 4 bytes, but U-Boot will leave
|
||||
# both DTB and ramdisk in place when starting the kernel. So we pad
|
||||
@@ -79,7 +89,7 @@ cat <<EOF >$work/infix.its
|
||||
arch = "$FIT_ARCH";
|
||||
os = "linux";
|
||||
$(cat $work/kernel-load.itsi)
|
||||
compression = "none";
|
||||
compression = "gzip";
|
||||
data = /incbin/("$kernel");
|
||||
};
|
||||
|
||||
|
||||
Executable
+35
@@ -0,0 +1,35 @@
|
||||
#!/bin/sh
|
||||
|
||||
set -e
|
||||
|
||||
# Bootstrap a RAUC status file showing the newly created image
|
||||
# installed to both the primary and secondary slots. This then bundled
|
||||
# in the aux partition in mkdisk.sh, so that RAUC (on the target) can
|
||||
# always report the installed versions.
|
||||
rauc info --no-verify --output-format=shell $1 >/tmp/rauc-$$.info
|
||||
. /tmp/rauc-$$.info
|
||||
rm /tmp/rauc-$$.info
|
||||
tstamp=$(date -u +%FT%TZ)
|
||||
cat <<EOF
|
||||
[slot.rootfs.0]
|
||||
bundle.compatible=$RAUC_MF_COMPATIBLE
|
||||
bundle.version=$RAUC_MF_VERSION
|
||||
status=ok
|
||||
sha256=$RAUC_IMAGE_DIGEST_0
|
||||
size=$RAUC_IMAGE_SIZE_0
|
||||
installed.timestamp=$tstamp
|
||||
installed.count=1
|
||||
activated.timestamp=$tstamp
|
||||
activated.count=1
|
||||
|
||||
[slot.rootfs.1]
|
||||
bundle.compatible=$RAUC_MF_COMPATIBLE
|
||||
bundle.version=$RAUC_MF_VERSION
|
||||
status=ok
|
||||
sha256=$RAUC_IMAGE_DIGEST_0
|
||||
size=$RAUC_IMAGE_SIZE_0
|
||||
installed.timestamp=$tstamp
|
||||
installed.count=1
|
||||
activated.timestamp=$tstamp
|
||||
activated.count=1
|
||||
EOF
|
||||
@@ -3,11 +3,8 @@
|
||||
set -e
|
||||
|
||||
GIT_VERSION=$(git -C $BR2_EXTERNAL_INFIX_PATH describe --always --dirty --tags)
|
||||
if [ -n "$INFIX_RELEASE" ]; then
|
||||
rel="-${INFIX_RELEASE}"
|
||||
fi
|
||||
|
||||
name=$1${rel}
|
||||
name=$1
|
||||
arch=$2
|
||||
sign=$3
|
||||
|
||||
|
||||
@@ -34,13 +34,18 @@ rm -f "$TARGET_DIR/etc/os-release"
|
||||
|
||||
echo "Infix by KernelKit $GIT_VERSION -- $(date +"%b %e %H:%M %Z %Y")" > "$TARGET_DIR/etc/version"
|
||||
|
||||
# Allow pdmenu (setup) and bash to be a login shells, bash
|
||||
# is added automatically when selected in menuyconfig, but
|
||||
# not when BusyBox provides a symlink (for ash).
|
||||
# Allow pdmenu (setup) and bash to be login shells, bash is added
|
||||
# automatically when selected in menuyconfig, but not when BusyBox
|
||||
# provides a symlink (for ash). The /bin/{true,false} are old UNIX
|
||||
# beart means of disabling a user.
|
||||
grep -qsE '^/usr/bin/pdmenu$$' "$TARGET_DIR/etc/shells" \
|
||||
|| echo "/usr/bin/pdmenu" >> "$TARGET_DIR/etc/shells"
|
||||
grep -qsE '^/bin/bash$$' "$TARGET_DIR/etc/shells" \
|
||||
|| echo "/bin/bash" >> "$TARGET_DIR/etc/shells"
|
||||
grep -qsE '^/bin/true$$' "$TARGET_DIR/etc/shells" \
|
||||
|| echo "/bin/true" >> "$TARGET_DIR/etc/shells"
|
||||
grep -qsE '^/bin/false$$' "$TARGET_DIR/etc/shells" \
|
||||
|| echo "/bin/false" >> "$TARGET_DIR/etc/shells"
|
||||
|
||||
# Menuconfig support for modifying Qemu args in release tarballs
|
||||
cp "$BR2_EXTERNAL_INFIX_PATH/board/common/qemu/qemu.sh" "$BINARIES_DIR/"
|
||||
|
||||
+27
-10
@@ -2,8 +2,10 @@
|
||||
common=$(dirname "$(readlink -f "$0")")
|
||||
. $common/lib.sh
|
||||
|
||||
load_cfg BR2_ARCH
|
||||
load_cfg BR2_DEFCONFIG
|
||||
load_cfg BR2_EXTERNAL_INFIX_PATH
|
||||
load_cfg BR2_TARGET_ROOTFS
|
||||
NAME=infix-$(basename "$BR2_DEFCONFIG" _defconfig | tr _ - | sed 's/x86-64/x86_64/')
|
||||
|
||||
ver()
|
||||
@@ -23,14 +25,27 @@ if [ "$SIGN_ENABLED" = "y" ]; then
|
||||
$common/sign.sh $BR2_ARCH $SIGN_KEY
|
||||
|
||||
ixmsg "Creating RAUC Update Bundle"
|
||||
$common/mkrauc.sh $NAME $BR2_ARCH $SIGN_KEY
|
||||
$common/mkrauc.sh "$NAME$(ver)" $BR2_ARCH $SIGN_KEY
|
||||
fi
|
||||
|
||||
load_cfg DISK_IMAGE
|
||||
load_cfg DISK_IMAGE_SIZE
|
||||
if [ "$DISK_IMAGE" = "y" ]; then
|
||||
ixmsg "Creating Disk Image"
|
||||
$common/mkdisk.sh -a $BR2_ARCH -s $DISK_IMAGE_SIZE
|
||||
|
||||
bootcfg=
|
||||
if [ "$DISK_IMAGE_BOOT_DATA" ]; then
|
||||
bootcfg="-b $DISK_IMAGE_BOOT_DATA -B $DISK_IMAGE_BOOT_OFFSET"
|
||||
fi
|
||||
|
||||
if [ "$BR2_TARGET_ROOTFS_SQUASHFS" != "y" ] && \
|
||||
[ ! -f "$BINARIES_DIR/rootfs.squashfs" ]; then
|
||||
ixmsg " Injecting $DISK_IMAGE_RELEASE_URL"
|
||||
archive="$BINARIES_DIR/$(basename $DISK_IMAGE_RELEASE_URL)"
|
||||
[ -f "$archive" ] || wget -O"$archive" "$DISK_IMAGE_RELEASE_URL"
|
||||
tar -xa --strip-components=1 -C "$BINARIES_DIR" -f "$archive"
|
||||
fi
|
||||
$common/mkrauc-status.sh "$BINARIES_DIR/${NAME}.pkg" >"$BINARIES_DIR/rauc.status"
|
||||
$common/mkdisk.sh -a $BR2_ARCH -s $DISK_IMAGE_SIZE $bootcfg
|
||||
fi
|
||||
|
||||
load_cfg GNS3_APPLIANCE
|
||||
@@ -47,12 +62,14 @@ if [ "$FIT_IMAGE" = "y" ]; then
|
||||
$common/mkfit.sh
|
||||
fi
|
||||
|
||||
if [ -z "${NAME##*minimal*}" ]; then
|
||||
NAME=$(echo "$NAME" | sed 's/-minimal//')
|
||||
fi
|
||||
if [ "$BR2_TARGET_ROOTFS_SQUASHFS" = "y" ]; then
|
||||
if [ -z "${NAME##*minimal*}" ]; then
|
||||
NAME=$(echo "$NAME" | sed 's/-minimal//')
|
||||
fi
|
||||
|
||||
rel=$(ver)
|
||||
ln -sf rootfs.squashfs "$BINARIES_DIR/${NAME}${rel}.img"
|
||||
if [ -n "$rel" ]; then
|
||||
ln -sf "$BINARIES_DIR/${NAME}${rel}.img" "$BINARIES_DIR/${NAME}.img"
|
||||
rel=$(ver)
|
||||
ln -sf rootfs.squashfs "$BINARIES_DIR/${NAME}${rel}.img"
|
||||
if [ -n "$rel" ]; then
|
||||
ln -sf "$BINARIES_DIR/${NAME}${rel}.img" "$BINARIES_DIR/${NAME}.img"
|
||||
fi
|
||||
fi
|
||||
|
||||
@@ -37,15 +37,30 @@ choice
|
||||
|
||||
config QEMU_ROOTFS_MMC
|
||||
bool "MMC"
|
||||
depends on QEMU_aarch64
|
||||
|
||||
config QEMU_ROOTFS_INITRD
|
||||
bool "Initrd"
|
||||
depends on QEMU_LOADER_KERNEL
|
||||
|
||||
config QEMU_ROOTFS_VSCSI
|
||||
bool "Virtio SCSI"
|
||||
|
||||
endchoice
|
||||
|
||||
choice
|
||||
prompt "Console"
|
||||
default QEMU_CONSOLE_VIRTIO
|
||||
|
||||
config QEMU_CONSOLE_VIRTIO
|
||||
bool "Virtio (hvc0)"
|
||||
depends on QEMU_LOADER_KERNEL
|
||||
|
||||
config QEMU_CONSOLE_SERIAL
|
||||
bool "Serial (ttyS0/ttyAMA0)"
|
||||
|
||||
endchoice
|
||||
|
||||
config QEMU_MACHINE
|
||||
string
|
||||
default "qemu-system-aarch64 -M virt -cpu cortex-a72 -m 256M" if QEMU_aarch64
|
||||
@@ -68,12 +83,6 @@ config QEMU_ROOTFS
|
||||
default "disk.img" if !QEMU_ROOTFS_INITRD
|
||||
default "rootfs.squashfs" if QEMU_ROOTFS_INITRD
|
||||
|
||||
config QEMU_CONSOLE
|
||||
string
|
||||
depends on !QEMU_ROOTFS_MMC
|
||||
default "ttyAMA0" if QEMU_aarch64
|
||||
default "ttyS0" if QEMU_x86_64
|
||||
|
||||
config QEMU_DTB_EXTEND
|
||||
bool
|
||||
depends on QEMU_LOADER_UBOOT
|
||||
@@ -127,7 +136,7 @@ endchoice
|
||||
|
||||
config QEMU_NET_MODEL
|
||||
string "Interface model"
|
||||
default "virtio"
|
||||
default "virtio-net-pci"
|
||||
|
||||
config QEMU_NET_BRIDGE_DEV
|
||||
string "Bridge device"
|
||||
|
||||
+55
-23
@@ -69,14 +69,20 @@ loader_args()
|
||||
|
||||
append_args()
|
||||
{
|
||||
# Disabled, not needed anymore with virtconsole (hvc0)
|
||||
# [ "$CONFIG_QEMU_CONSOLE" ] && echo -n "console=$CONFIG_QEMU_CONSOLE "
|
||||
if [ "$CONFIG_QEMU_CONSOLE_VIRTIO" ]; then
|
||||
echo -n "console=hvc0 "
|
||||
elif [ "$CONFIG_QEMU_x86_64" ]; then
|
||||
echo -n "console=ttyS0 "
|
||||
elif [ "$CONFIG_QEMU_aarch64" ]; then
|
||||
echo -n "console=ttyAMA0 "
|
||||
else
|
||||
die "Unknown console"
|
||||
fi
|
||||
|
||||
echo -n "console=hvc0 "
|
||||
if [ "$CONFIG_QEMU_ROOTFS_INITRD" = "y" ]; then
|
||||
# Size of initrd, rounded up to nearest kb
|
||||
local size=$((($(stat -c %s $CONFIG_QEMU_ROOTFS) + 1023) >> 10))
|
||||
echo -n "root=/dev/ram ramdisk_size=${size} "
|
||||
echo -n "root=/dev/ram0 ramdisk_size=${size} "
|
||||
elif [ "$CONFIG_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
||||
echo -n "root=PARTLABEL=primary "
|
||||
fi
|
||||
@@ -103,6 +109,26 @@ rootfs_args()
|
||||
fi
|
||||
}
|
||||
|
||||
serial_args()
|
||||
{
|
||||
echo -n "-display none "
|
||||
echo -n "-device virtio-serial "
|
||||
|
||||
echo -n "-chardev stdio,id=console0,mux=on "
|
||||
echo -n "-mon chardev=console0 "
|
||||
|
||||
if [ "$CONFIG_QEMU_CONSOLE_VIRTIO" ]; then
|
||||
echo -n "-device virtconsole,nr=0,name=console,chardev=console0 "
|
||||
elif [ "$CONFIG_QEMU_CONSOLE_SERIAL" ]; then
|
||||
echo -n "-serial chardev:console0 "
|
||||
else
|
||||
die "Unknown console"
|
||||
fi
|
||||
|
||||
echo -n "-chardev socket,id=gdbserver,path=gdbserver.sock,server=on,wait=off "
|
||||
echo -n "-device virtconsole,nr=1,name=gdbserver,chardev=gdbserver "
|
||||
}
|
||||
|
||||
rw_args()
|
||||
{
|
||||
[ "$CONFIG_QEMU_RW" ] || return
|
||||
@@ -126,31 +152,41 @@ rw_args()
|
||||
|
||||
host_args()
|
||||
{
|
||||
[ "${QEMU_HOST}" ] || return
|
||||
[ "$CONFIG_QEMU_HOST" ] || return
|
||||
|
||||
echo -n "-virtfs local,path=${QEMU_HOST},security_model=none,writeout=immediate,mount_tag=hostfs "
|
||||
echo -n "-virtfs local,path=$CONFIG_QEMU_HOST,security_model=none,writeout=immediate,mount_tag=hostfs "
|
||||
}
|
||||
|
||||
net_dev_args()
|
||||
{
|
||||
local name="e$1"
|
||||
local mac=$(printf "02:00:00:00:00:%02x" $1)
|
||||
|
||||
echo -n "-device $CONFIG_QEMU_NET_MODEL,netdev=$name,mac=$mac "
|
||||
echo "$name $mac" >>"$mactab"
|
||||
}
|
||||
|
||||
net_args()
|
||||
{
|
||||
QEMU_NET_MODEL=${QEMU_NET_MODEL:-virtio}
|
||||
# Infix will pick up this file via fwcfg and install it to /etc
|
||||
mactab=$(dirname "$CONFIG_QEMU_ROOTFS")/mactab
|
||||
:> "$mactab"
|
||||
echo -n "-fw_cfg name=opt/mactab,file=$mactab "
|
||||
|
||||
if [ "$CONFIG_QEMU_NET_BRIDGE" = "y" ]; then
|
||||
QEMU_NET_BRIDGE_DEV=${QEMU_NET_BRIDGE_DEV:-virbr0}
|
||||
echo -n "-nic bridge,br=$CONFIG_QEMU_NET_BRIDGE_DEV,model=$CONFIG_QEMU_NET_MODEL "
|
||||
echo -n "-netdev bridge,id=e0,br=$CONFIG_QEMU_NET_BRIDGE_DEV "
|
||||
net_dev_args 0
|
||||
elif [ "$CONFIG_QEMU_NET_TAP" = "y" ]; then
|
||||
QEMU_NET_TAP_N=${QEMU_NET_TAP_N:-1}
|
||||
mactab=$(dirname "$CONFIG_QEMU_ROOTFS")/mactab
|
||||
rm -f "$mactab"
|
||||
for i in $(seq 0 $(($CONFIG_QEMU_NET_TAP_N - 1))); do
|
||||
printf "e$i 52:54:00:12:34:%02x\n" $((0x56 + i)) >>"$mactab"
|
||||
echo -n "-netdev tap,id=nd$i,ifname=qtap$i -device e1000,netdev=nd$i "
|
||||
echo -n "-netdev tap,id=e$i,ifname=qtap$i "
|
||||
net_dev_args $i
|
||||
done
|
||||
echo -n "-fw_cfg name=opt/mactab,file=$mactab "
|
||||
elif [ "$CONFIG_QEMU_NET_USER" = "y" ]; then
|
||||
[ "$CONFIG_QEMU_NET_USER_OPTS" ] && QEMU_NET_USER_OPTS="$CONFIG_QEMU_NET_USER_OPTS,"
|
||||
local useropts=
|
||||
[ "$CONFIG_QEMU_NET_USER_OPTS" ] && useropts=",$CONFIG_QEMU_NET_USER_OPTS"
|
||||
|
||||
echo -n "-nic user,${QEMU_NET_USER_OPTS}model=$CONFIG_QEMU_NET_MODEL "
|
||||
echo -n "-netdev user,id=e0${useropts} "
|
||||
net_dev_args 0
|
||||
else
|
||||
echo -n "-nic none"
|
||||
fi
|
||||
@@ -166,13 +202,9 @@ run_qemu()
|
||||
local qemu
|
||||
read qemu <<EOF
|
||||
$CONFIG_QEMU_MACHINE \
|
||||
-display none -rtc base=utc,clock=vm \
|
||||
-device virtio-serial -chardev stdio,mux=on,id=console0 \
|
||||
-device virtconsole,chardev=console0 -mon chardev=console0 \
|
||||
-chardev socket,id=gdbserver,path=gdbserver.sock,server=on,wait=off \
|
||||
-device virtconsole,name=console1,chardev=gdbserver \
|
||||
$(loader_args) \
|
||||
$(rootfs_args) \
|
||||
$(serial_args) \
|
||||
$(rw_args) \
|
||||
$(host_args) \
|
||||
$(net_args) \
|
||||
@@ -219,7 +251,7 @@ generate_dot()
|
||||
|
||||
hostports="<qtap0> qtap0"
|
||||
targetports="<e0> e0"
|
||||
edges="host:qtap0 -- target:e0;"
|
||||
edges="host:qtap0 -- target:e0 [kind=mgmt];"
|
||||
for tap in $(seq 1 $(($CONFIG_QEMU_NET_TAP_N - 1))); do
|
||||
hostports="$hostports | <qtap$tap> qtap$tap "
|
||||
targetports="$targetports | <e$tap> e$tap "
|
||||
|
||||
@@ -1,5 +0,0 @@
|
||||
{
|
||||
"ietf-system:system": {
|
||||
"hostname": "infix"
|
||||
}
|
||||
}
|
||||
@@ -13,6 +13,3 @@ export PROMPT_COMMAND=prompt_command
|
||||
# check the window size after each command and, if necessary,
|
||||
# update the values of LINES and COLUMNS.
|
||||
shopt -s checkwinsize
|
||||
|
||||
# Disble built-ins
|
||||
enable -n help
|
||||
|
||||
@@ -0,0 +1,141 @@
|
||||
_cond()
|
||||
{
|
||||
initctl -pt cond dump | awk '{print $4}' | sed 's/<\(.*\)>/\1/'
|
||||
}
|
||||
|
||||
_ident()
|
||||
{
|
||||
if [ -n "$1" ]; then
|
||||
initctl ident | grep -q $1
|
||||
else
|
||||
initctl ident
|
||||
fi
|
||||
}
|
||||
|
||||
_svc()
|
||||
{
|
||||
initctl ls -pt | grep $1 | sed "s/.*\/\(.*\)/\1/g" | sort -u
|
||||
}
|
||||
|
||||
_enabled()
|
||||
{
|
||||
echo "$(_svc enabled)"
|
||||
}
|
||||
|
||||
_available()
|
||||
{
|
||||
all=$(mktemp)
|
||||
ena=$(mktemp)
|
||||
echo "$(_svc available)" >$all
|
||||
echo "$(_svc enabled)" >$ena
|
||||
grep -v -f $ena $all
|
||||
rm $all $ena
|
||||
}
|
||||
|
||||
# Determine first non-option word. Usually the command
|
||||
_firstword() {
|
||||
local firstword i
|
||||
|
||||
firstword=
|
||||
for ((i = 1; i < ${#COMP_WORDS[@]}; ++i)); do
|
||||
if [[ ${COMP_WORDS[i]} != -* ]]; then
|
||||
firstword=${COMP_WORDS[i]}
|
||||
break
|
||||
fi
|
||||
done
|
||||
|
||||
echo $firstword
|
||||
}
|
||||
|
||||
# Determine last non-option word. Uusally a sub-command
|
||||
_lastword() {
|
||||
local lastword i
|
||||
|
||||
lastword=
|
||||
for ((i = 1; i < ${#COMP_WORDS[@]}; ++i)); do
|
||||
if [[ ${COMP_WORDS[i]} != -* ]] && [[ -n ${COMP_WORDS[i]} ]] && [[ ${COMP_WORDS[i]} != $cur ]]; then
|
||||
lastword=${COMP_WORDS[i]}
|
||||
fi
|
||||
done
|
||||
|
||||
echo $lastword
|
||||
}
|
||||
|
||||
_initctl()
|
||||
{
|
||||
local cur command
|
||||
|
||||
cur=${COMP_WORDS[COMP_CWORD]}
|
||||
prev="${COMP_WORDS[COMP_CWORD-1]}"
|
||||
firstword=$(_firstword)
|
||||
lastword=$(_lastword)
|
||||
|
||||
commands="status cond debug help kill ls log version list enable \
|
||||
disable touch show cat edit create delete reload start \
|
||||
stop restart signal cgroup ps top plugins runlevel reboot \
|
||||
halt poweroff suspend utmp"
|
||||
cond_cmds="set get clear status dump"
|
||||
cond_types="hook net pid service task usr"
|
||||
signals="int term hup stop tstp cont usr1 usr2 pwr"
|
||||
options="-b --batch \
|
||||
-c --create \
|
||||
-d --debug \
|
||||
-f --force \
|
||||
-h --help \
|
||||
-j --json \
|
||||
-n --noerr \
|
||||
-1 --once \
|
||||
-p --plain \
|
||||
-q --quiet \
|
||||
-t --no-heading \
|
||||
-v --verbose \
|
||||
-V --version"
|
||||
|
||||
case "${firstword}" in
|
||||
enable)
|
||||
COMPREPLY=($(compgen -W "$(_available)" -- $cur))
|
||||
;;
|
||||
disable|touch)
|
||||
COMPREPLY=($(compgen -W "$(_enabled)" -- $cur))
|
||||
;;
|
||||
show|cat|edit|delete)
|
||||
COMPREPLY=($(compgen -W "$(_svc .)" -- $cur))
|
||||
;;
|
||||
start|stop|restart|log|status)
|
||||
COMPREPLY=($(compgen -W "$(_ident)" -- $cur))
|
||||
;;
|
||||
signal|kill)
|
||||
if $(_ident "${prev}"); then
|
||||
COMPREPLY=($(compgen -W "$signals" -- $cur))
|
||||
else
|
||||
COMPREPLY=($(compgen -W "$(_ident)" -- $cur))
|
||||
fi
|
||||
;;
|
||||
cond)
|
||||
case "${lastword}" in
|
||||
set|clear)
|
||||
compopt -o nospace
|
||||
COMPREPLY=($(compgen -W "usr/" -- $cur))
|
||||
;;
|
||||
get)
|
||||
COMPREPLY=($(compgen -W "$(_cond)" -- $cur))
|
||||
;;
|
||||
dump)
|
||||
COMPREPLY=($(compgen -W "$cond_types" -- $cur))
|
||||
;;
|
||||
*)
|
||||
COMPREPLY=($(compgen -W "$cond_cmds" -- $cur))
|
||||
;;
|
||||
esac
|
||||
;;
|
||||
*)
|
||||
COMPREPLY=($(compgen -W "$commands" -- $cur))
|
||||
;;
|
||||
esac
|
||||
|
||||
if [[ $cur == -* ]]; then
|
||||
COMPREPLY=($(compgen -W "$options" -- $cur))
|
||||
fi
|
||||
}
|
||||
|
||||
complete -F _initctl initctl
|
||||
@@ -1,2 +1 @@
|
||||
set COLORTERM=yes
|
||||
runparts /cfg/start.d
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
service [2345789] log:prio:user.notice rauc service -- Software update service
|
||||
@@ -0,0 +1 @@
|
||||
../available/rauc.conf
|
||||
@@ -1 +0,0 @@
|
||||
../available/sshd.conf
|
||||
@@ -11,9 +11,6 @@ sysfs /sys sysfs defaults 0 0
|
||||
debugfs /sys/kernel/debug debugfs nofail 0 0
|
||||
cfgfs /config configfs nofail,noauto 0 0
|
||||
|
||||
# Optional host share when running in Qemu
|
||||
hostfs /host 9p nofail,cache=none,msize=16384 0 0
|
||||
|
||||
# The chosen backing storage for the overlays placed on /cfg, /etc,
|
||||
# /home, /root, and /var, are determined dynamically by /lib/infix/mnt
|
||||
# depending on the available devices.
|
||||
|
||||
@@ -1,2 +1,3 @@
|
||||
1 port
|
||||
2 iface
|
||||
3 internal
|
||||
|
||||
@@ -4,6 +4,8 @@ alias ll='ls -alF'
|
||||
alias ls='ls --color=auto'
|
||||
|
||||
export EDITOR=/usr/bin/edit
|
||||
export VISUAL=/usr/bin/edit
|
||||
export LESS="-P %f (press h for help or q to quit)"
|
||||
alias vim='vi'
|
||||
alias view='vi -R'
|
||||
alias emacs='mg'
|
||||
@@ -15,6 +17,5 @@ alias ipb='ip -br'
|
||||
alias ipaddr='ip addr'
|
||||
alias iplink='ip link'
|
||||
alias bridge='bridge --color=auto'
|
||||
alias cli='klish'
|
||||
|
||||
alias docker=podman
|
||||
|
||||
@@ -0,0 +1,361 @@
|
||||
# Network services, Internet style
|
||||
#
|
||||
# Updated from https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml .
|
||||
#
|
||||
# New ports will be added on request if they have been officially assigned
|
||||
# by IANA and used in the real-world or are needed by a debian package.
|
||||
# If you need a huge list of used numbers please install the nmap package.
|
||||
|
||||
tcpmux 1/tcp # TCP port service multiplexer
|
||||
echo 7/tcp
|
||||
echo 7/udp
|
||||
discard 9/tcp sink null
|
||||
discard 9/udp sink null
|
||||
systat 11/tcp users
|
||||
daytime 13/tcp
|
||||
daytime 13/udp
|
||||
netstat 15/tcp
|
||||
qotd 17/tcp quote
|
||||
chargen 19/tcp ttytst source
|
||||
chargen 19/udp ttytst source
|
||||
ftp-data 20/tcp
|
||||
ftp 21/tcp
|
||||
fsp 21/udp fspd
|
||||
ssh 22/tcp # SSH Remote Login Protocol
|
||||
telnet 23/tcp
|
||||
smtp 25/tcp mail
|
||||
time 37/tcp timserver
|
||||
time 37/udp timserver
|
||||
whois 43/tcp nicname
|
||||
tacacs 49/tcp # Login Host Protocol (TACACS)
|
||||
tacacs 49/udp
|
||||
domain 53/tcp # Domain Name Server
|
||||
domain 53/udp
|
||||
bootps 67/udp
|
||||
bootpc 68/udp
|
||||
tftp 69/udp
|
||||
gopher 70/tcp # Internet Gopher
|
||||
finger 79/tcp
|
||||
http 80/tcp www # WorldWideWeb HTTP
|
||||
kerberos 88/tcp kerberos5 krb5 kerberos-sec # Kerberos v5
|
||||
kerberos 88/udp kerberos5 krb5 kerberos-sec # Kerberos v5
|
||||
iso-tsap 102/tcp tsap # part of ISODE
|
||||
acr-nema 104/tcp dicom # Digital Imag. & Comm. 300
|
||||
pop3 110/tcp pop-3 # POP version 3
|
||||
sunrpc 111/tcp portmapper # RPC 4.0 portmapper
|
||||
sunrpc 111/udp portmapper
|
||||
auth 113/tcp authentication tap ident
|
||||
nntp 119/tcp readnews untp # USENET News Transfer Protocol
|
||||
ntp 123/udp # Network Time Protocol
|
||||
epmap 135/tcp loc-srv # DCE endpoint resolution
|
||||
netbios-ns 137/udp # NETBIOS Name Service
|
||||
netbios-dgm 138/udp # NETBIOS Datagram Service
|
||||
netbios-ssn 139/tcp # NETBIOS session service
|
||||
imap2 143/tcp imap # Interim Mail Access P 2 and 4
|
||||
snmp 161/tcp # Simple Net Mgmt Protocol
|
||||
snmp 161/udp
|
||||
snmp-trap 162/tcp snmptrap # Traps for SNMP
|
||||
snmp-trap 162/udp snmptrap
|
||||
cmip-man 163/tcp # ISO mgmt over IP (CMOT)
|
||||
cmip-man 163/udp
|
||||
cmip-agent 164/tcp
|
||||
cmip-agent 164/udp
|
||||
mailq 174/tcp # Mailer transport queue for Zmailer
|
||||
xdmcp 177/udp # X Display Manager Control Protocol
|
||||
bgp 179/tcp # Border Gateway Protocol
|
||||
smux 199/tcp # SNMP Unix Multiplexer
|
||||
qmtp 209/tcp # Quick Mail Transfer Protocol
|
||||
z3950 210/tcp wais # NISO Z39.50 database
|
||||
ipx 213/udp # IPX [RFC1234]
|
||||
ptp-event 319/udp
|
||||
ptp-general 320/udp
|
||||
pawserv 345/tcp # Perf Analysis Workbench
|
||||
zserv 346/tcp # Zebra server
|
||||
rpc2portmap 369/tcp
|
||||
rpc2portmap 369/udp # Coda portmapper
|
||||
codaauth2 370/tcp
|
||||
codaauth2 370/udp # Coda authentication server
|
||||
clearcase 371/udp Clearcase
|
||||
ldap 389/tcp # Lightweight Directory Access Protocol
|
||||
ldap 389/udp
|
||||
svrloc 427/tcp # Server Location
|
||||
svrloc 427/udp
|
||||
https 443/tcp # http protocol over TLS/SSL
|
||||
https 443/udp # HTTP/3
|
||||
snpp 444/tcp # Simple Network Paging Protocol
|
||||
microsoft-ds 445/tcp # Microsoft Naked CIFS
|
||||
kpasswd 464/tcp
|
||||
kpasswd 464/udp
|
||||
submissions 465/tcp ssmtp smtps urd # Submission over TLS [RFC8314]
|
||||
saft 487/tcp # Simple Asynchronous File Transfer
|
||||
isakmp 500/udp # IPSEC key management
|
||||
rtsp 554/tcp # Real Time Stream Control Protocol
|
||||
rtsp 554/udp
|
||||
nqs 607/tcp # Network Queuing system
|
||||
asf-rmcp 623/udp # ASF Remote Management and Control Protocol
|
||||
qmqp 628/tcp
|
||||
ipp 631/tcp # Internet Printing Protocol
|
||||
ldp 646/tcp # Label Distribution Protocol
|
||||
ldp 646/udp
|
||||
#
|
||||
# UNIX specific services
|
||||
#
|
||||
exec 512/tcp
|
||||
biff 512/udp comsat
|
||||
login 513/tcp
|
||||
who 513/udp whod
|
||||
shell 514/tcp cmd syslog # no passwords used
|
||||
syslog 514/udp
|
||||
printer 515/tcp spooler # line printer spooler
|
||||
talk 517/udp
|
||||
ntalk 518/udp
|
||||
route 520/udp router routed # RIP
|
||||
gdomap 538/tcp # GNUstep distributed objects
|
||||
gdomap 538/udp
|
||||
uucp 540/tcp uucpd # uucp daemon
|
||||
klogin 543/tcp # Kerberized `rlogin' (v5)
|
||||
kshell 544/tcp krcmd # Kerberized `rsh' (v5)
|
||||
dhcpv6-client 546/udp
|
||||
dhcpv6-server 547/udp
|
||||
afpovertcp 548/tcp # AFP over TCP
|
||||
nntps 563/tcp snntp # NNTP over SSL
|
||||
submission 587/tcp # Submission [RFC4409]
|
||||
ldaps 636/tcp # LDAP over SSL
|
||||
ldaps 636/udp
|
||||
tinc 655/tcp # tinc control port
|
||||
tinc 655/udp
|
||||
silc 706/tcp
|
||||
kerberos-adm 749/tcp # Kerberos `kadmin' (v5)
|
||||
#
|
||||
domain-s 853/tcp # DNS over TLS [RFC7858]
|
||||
domain-s 853/udp # DNS over DTLS [RFC8094]
|
||||
rsync 873/tcp
|
||||
ftps-data 989/tcp # FTP over SSL (data)
|
||||
ftps 990/tcp
|
||||
telnets 992/tcp # Telnet over SSL
|
||||
imaps 993/tcp # IMAP over SSL
|
||||
pop3s 995/tcp # POP-3 over SSL
|
||||
#
|
||||
# From ``Assigned Numbers'':
|
||||
#
|
||||
#> The Registered Ports are not controlled by the IANA and on most systems
|
||||
#> can be used by ordinary user processes or programs executed by ordinary
|
||||
#> users.
|
||||
#
|
||||
#> Ports are used in the TCP [45,106] to name the ends of logical
|
||||
#> connections which carry long term conversations. For the purpose of
|
||||
#> providing services to unknown callers, a service contact port is
|
||||
#> defined. This list specifies the port used by the server process as its
|
||||
#> contact port. While the IANA can not control uses of these ports it
|
||||
#> does register or list uses of these ports as a convienence to the
|
||||
#> community.
|
||||
#
|
||||
socks 1080/tcp # socks proxy server
|
||||
proofd 1093/tcp
|
||||
rootd 1094/tcp
|
||||
openvpn 1194/tcp
|
||||
openvpn 1194/udp
|
||||
rmiregistry 1099/tcp # Java RMI Registry
|
||||
lotusnote 1352/tcp lotusnotes # Lotus Note
|
||||
ms-sql-s 1433/tcp # Microsoft SQL Server
|
||||
ms-sql-m 1434/udp # Microsoft SQL Monitor
|
||||
ingreslock 1524/tcp
|
||||
datametrics 1645/tcp old-radius
|
||||
datametrics 1645/udp old-radius
|
||||
sa-msg-port 1646/tcp old-radacct
|
||||
sa-msg-port 1646/udp old-radacct
|
||||
kermit 1649/tcp
|
||||
groupwise 1677/tcp
|
||||
l2f 1701/udp l2tp
|
||||
radius 1812/tcp
|
||||
radius 1812/udp
|
||||
radius-acct 1813/tcp radacct # Radius Accounting
|
||||
radius-acct 1813/udp radacct
|
||||
cisco-sccp 2000/tcp # Cisco SCCP
|
||||
nfs 2049/tcp # Network File System
|
||||
nfs 2049/udp # Network File System
|
||||
gnunet 2086/tcp
|
||||
gnunet 2086/udp
|
||||
rtcm-sc104 2101/tcp # RTCM SC-104 IANA 1/29/99
|
||||
rtcm-sc104 2101/udp
|
||||
gsigatekeeper 2119/tcp
|
||||
gris 2135/tcp # Grid Resource Information Server
|
||||
cvspserver 2401/tcp # CVS client/server operations
|
||||
venus 2430/tcp # codacon port
|
||||
venus 2430/udp # Venus callback/wbc interface
|
||||
venus-se 2431/tcp # tcp side effects
|
||||
venus-se 2431/udp # udp sftp side effect
|
||||
codasrv 2432/tcp # not used
|
||||
codasrv 2432/udp # server port
|
||||
codasrv-se 2433/tcp # tcp side effects
|
||||
codasrv-se 2433/udp # udp sftp side effect
|
||||
mon 2583/tcp # MON traps
|
||||
mon 2583/udp
|
||||
dict 2628/tcp # Dictionary server
|
||||
f5-globalsite 2792/tcp
|
||||
gsiftp 2811/tcp
|
||||
gpsd 2947/tcp
|
||||
gds-db 3050/tcp gds_db # InterBase server
|
||||
icpv2 3130/udp icp # Internet Cache Protocol
|
||||
isns 3205/tcp # iSNS Server Port
|
||||
isns 3205/udp # iSNS Server Port
|
||||
iscsi-target 3260/tcp
|
||||
mysql 3306/tcp
|
||||
ms-wbt-server 3389/tcp
|
||||
nut 3493/tcp # Network UPS Tools
|
||||
nut 3493/udp
|
||||
distcc 3632/tcp # distributed compiler
|
||||
daap 3689/tcp # Digital Audio Access Protocol
|
||||
svn 3690/tcp subversion # Subversion protocol
|
||||
suucp 4031/tcp # UUCP over SSL
|
||||
sysrqd 4094/tcp # sysrq daemon
|
||||
sieve 4190/tcp # ManageSieve Protocol
|
||||
epmd 4369/tcp # Erlang Port Mapper Daemon
|
||||
remctl 4373/tcp # Remote Authenticated Command Service
|
||||
f5-iquery 4353/tcp # F5 iQuery
|
||||
ntske 4460/tcp # Network Time Security Key Establishment
|
||||
ipsec-nat-t 4500/udp # IPsec NAT-Traversal [RFC3947]
|
||||
iax 4569/udp # Inter-Asterisk eXchange
|
||||
mtn 4691/tcp # monotone Netsync Protocol
|
||||
radmin-port 4899/tcp # RAdmin Port
|
||||
sip 5060/tcp # Session Initiation Protocol
|
||||
sip 5060/udp
|
||||
sip-tls 5061/tcp
|
||||
sip-tls 5061/udp
|
||||
xmpp-client 5222/tcp jabber-client # Jabber Client Connection
|
||||
xmpp-server 5269/tcp jabber-server # Jabber Server Connection
|
||||
cfengine 5308/tcp
|
||||
mdns 5353/udp # Multicast DNS
|
||||
postgresql 5432/tcp postgres # PostgreSQL Database
|
||||
freeciv 5556/tcp rptp # Freeciv gameplay
|
||||
amqps 5671/tcp # AMQP protocol over TLS/SSL
|
||||
amqp 5672/tcp
|
||||
amqp 5672/sctp
|
||||
x11 6000/tcp x11-0 # X Window System
|
||||
x11-1 6001/tcp
|
||||
x11-2 6002/tcp
|
||||
x11-3 6003/tcp
|
||||
x11-4 6004/tcp
|
||||
x11-5 6005/tcp
|
||||
x11-6 6006/tcp
|
||||
x11-7 6007/tcp
|
||||
gnutella-svc 6346/tcp # gnutella
|
||||
gnutella-svc 6346/udp
|
||||
gnutella-rtr 6347/tcp # gnutella
|
||||
gnutella-rtr 6347/udp
|
||||
redis 6379/tcp
|
||||
sge-qmaster 6444/tcp sge_qmaster # Grid Engine Qmaster Service
|
||||
sge-execd 6445/tcp sge_execd # Grid Engine Execution Service
|
||||
mysql-proxy 6446/tcp # MySQL Proxy
|
||||
babel 6696/udp # Babel Routing Protocol
|
||||
ircs-u 6697/tcp # Internet Relay Chat via TLS/SSL
|
||||
bbs 7000/tcp
|
||||
afs3-fileserver 7000/udp
|
||||
afs3-callback 7001/udp # callbacks to cache managers
|
||||
afs3-prserver 7002/udp # users & groups database
|
||||
afs3-vlserver 7003/udp # volume location database
|
||||
afs3-kaserver 7004/udp # AFS/Kerberos authentication
|
||||
afs3-volser 7005/udp # volume managment server
|
||||
afs3-bos 7007/udp # basic overseer process
|
||||
afs3-update 7008/udp # server-to-server updater
|
||||
afs3-rmtsys 7009/udp # remote cache manager service
|
||||
font-service 7100/tcp xfs # X Font Service
|
||||
http-alt 8080/tcp webcache # WWW caching service
|
||||
puppet 8140/tcp # The Puppet master service
|
||||
bacula-dir 9101/tcp # Bacula Director
|
||||
bacula-fd 9102/tcp # Bacula File Daemon
|
||||
bacula-sd 9103/tcp # Bacula Storage Daemon
|
||||
xmms2 9667/tcp # Cross-platform Music Multiplexing System
|
||||
nbd 10809/tcp # Linux Network Block Device
|
||||
zabbix-agent 10050/tcp # Zabbix Agent
|
||||
zabbix-trapper 10051/tcp # Zabbix Trapper
|
||||
amanda 10080/tcp # amanda backup services
|
||||
dicom 11112/tcp
|
||||
hkp 11371/tcp # OpenPGP HTTP Keyserver
|
||||
db-lsp 17500/tcp # Dropbox LanSync Protocol
|
||||
dcap 22125/tcp # dCache Access Protocol
|
||||
gsidcap 22128/tcp # GSI dCache Access Protocol
|
||||
wnn6 22273/tcp # wnn6
|
||||
|
||||
#
|
||||
# Datagram Delivery Protocol services
|
||||
#
|
||||
rtmp 1/ddp # Routing Table Maintenance Protocol
|
||||
nbp 2/ddp # Name Binding Protocol
|
||||
echo 4/ddp # AppleTalk Echo Protocol
|
||||
zip 6/ddp # Zone Information Protocol
|
||||
|
||||
#=========================================================================
|
||||
# The remaining port numbers are not as allocated by IANA.
|
||||
#=========================================================================
|
||||
|
||||
# Kerberos (Project Athena/MIT) services
|
||||
kerberos4 750/udp kerberos-iv kdc # Kerberos (server)
|
||||
kerberos4 750/tcp kerberos-iv kdc
|
||||
kerberos-master 751/udp kerberos_master # Kerberos authentication
|
||||
kerberos-master 751/tcp
|
||||
passwd-server 752/udp passwd_server # Kerberos passwd server
|
||||
krb-prop 754/tcp krb_prop krb5_prop hprop # Kerberos slave propagation
|
||||
zephyr-srv 2102/udp # Zephyr server
|
||||
zephyr-clt 2103/udp # Zephyr serv-hm connection
|
||||
zephyr-hm 2104/udp # Zephyr hostmanager
|
||||
iprop 2121/tcp # incremental propagation
|
||||
supfilesrv 871/tcp # Software Upgrade Protocol server
|
||||
supfiledbg 1127/tcp # Software Upgrade Protocol debugging
|
||||
|
||||
#
|
||||
# Services added for the Debian GNU/Linux distribution
|
||||
#
|
||||
poppassd 106/tcp # Eudora
|
||||
moira-db 775/tcp moira_db # Moira database
|
||||
moira-update 777/tcp moira_update # Moira update protocol
|
||||
moira-ureg 779/udp moira_ureg # Moira user registration
|
||||
spamd 783/tcp # spamassassin daemon
|
||||
skkserv 1178/tcp # skk jisho server port
|
||||
predict 1210/udp # predict -- satellite tracking
|
||||
rmtcfg 1236/tcp # Gracilis Packeten remote config server
|
||||
xtel 1313/tcp # french minitel
|
||||
xtelw 1314/tcp # french minitel
|
||||
zebrasrv 2600/tcp # zebra service
|
||||
zebra 2601/tcp # zebra vty
|
||||
ripd 2602/tcp # ripd vty (zebra)
|
||||
ripngd 2603/tcp # ripngd vty (zebra)
|
||||
ospfd 2604/tcp # ospfd vty (zebra)
|
||||
bgpd 2605/tcp # bgpd vty (zebra)
|
||||
ospf6d 2606/tcp # ospf6d vty (zebra)
|
||||
ospfapi 2607/tcp # OSPF-API
|
||||
isisd 2608/tcp # ISISd vty (zebra)
|
||||
fax 4557/tcp # FAX transmission service (old)
|
||||
hylafax 4559/tcp # HylaFAX client-server protocol (new)
|
||||
munin 4949/tcp lrrd # Munin
|
||||
rplay 5555/udp # RPlay audio service
|
||||
nrpe 5666/tcp # Nagios Remote Plugin Executor
|
||||
nsca 5667/tcp # Nagios Agent - NSCA
|
||||
canna 5680/tcp # cannaserver
|
||||
syslog-tls 6514/tcp # Syslog over TLS [RFC5425]
|
||||
sane-port 6566/tcp sane saned # SANE network scanner daemon
|
||||
ircd 6667/tcp # Internet Relay Chat
|
||||
zope-ftp 8021/tcp # zope management by ftp
|
||||
tproxy 8081/tcp # Transparent Proxy
|
||||
omniorb 8088/tcp # OmniORB
|
||||
clc-build-daemon 8990/tcp # Common lisp build daemon
|
||||
xinetd 9098/tcp
|
||||
git 9418/tcp # Git Version Control System
|
||||
zope 9673/tcp # zope server
|
||||
webmin 10000/tcp
|
||||
kamanda 10081/tcp # amanda backup services (Kerberos)
|
||||
amandaidx 10082/tcp # amanda backup services
|
||||
amidxtape 10083/tcp # amanda backup services
|
||||
sgi-cmsd 17001/udp # Cluster membership services daemon
|
||||
sgi-crsd 17002/udp
|
||||
sgi-gcd 17003/udp # SGI Group membership daemon
|
||||
sgi-cad 17004/tcp # Cluster Admin daemon
|
||||
binkp 24554/tcp # binkp fidonet protocol
|
||||
asp 27374/tcp # Address Search Protocol
|
||||
asp 27374/udp
|
||||
csync2 30865/tcp # cluster synchronization tool
|
||||
dircproxy 57000/tcp # Detachable IRC Proxy
|
||||
tfido 60177/tcp # fidonet EMSI over telnet
|
||||
fido 60179/tcp # fidonet EMSI over TCP
|
||||
|
||||
# Local services
|
||||
@@ -1 +1,2 @@
|
||||
net.core.fb_tunnels_only_for_init_net=2
|
||||
net.core.rmem_max=1000000
|
||||
|
||||
@@ -1 +0,0 @@
|
||||
local7.* -/var/log/profinet.log
|
||||
@@ -25,7 +25,7 @@ for netif in /sys/class/net/*; do
|
||||
|
||||
dsa="dsa$num"
|
||||
logger -k -p user.notice -t "$ident" "Found DSA interface, renaming $iface -> $dsa"
|
||||
ip link set dev "$iface" name $dsa
|
||||
ip link set dev "$iface" name $dsa group internal
|
||||
num=$((num + 1))
|
||||
done
|
||||
|
||||
@@ -35,12 +35,5 @@ for iface in $ports; do
|
||||
ip link set "$iface" group port
|
||||
done
|
||||
|
||||
# Testing, e.g., using /etc/mactab may use TAP devices to create
|
||||
# emulated switch ports, make sure to mark them as well
|
||||
ports=$(ip -json link | jq -r '.[].ifname | match("^e[[:digit:]]+").string')
|
||||
for iface in $ports; do
|
||||
ip link set "$iface" group port
|
||||
done
|
||||
|
||||
# At least loopback in iface group
|
||||
ip link set lo group iface
|
||||
|
||||
@@ -4,11 +4,14 @@
|
||||
# existing interfaces. This syncs the default settings to all known
|
||||
# interfaces at boot, such that physical interfaces will start from
|
||||
# the same point as virtual ones.
|
||||
tmp=$(mktemp)
|
||||
|
||||
sysctl net.ipv4.conf.default >/tmp/sysctl-ip-default
|
||||
sysctl net.ipv6.conf.default >>/tmp/sysctl-ip-default
|
||||
sysctl net.ipv4.conf.default >$tmp
|
||||
sysctl net.ipv6.conf.default >>$tmp
|
||||
|
||||
for iface in $(ip -j link show | jq -r .[].ifname); do
|
||||
sed -e "s/.default./.${iface}./g" /tmp/sysctl-ip-default \
|
||||
| sysctl -p -
|
||||
sed -e "s/.default./.${iface}./g" $tmp | sysctl -p -
|
||||
done
|
||||
|
||||
rm $tmp
|
||||
|
||||
|
||||
@@ -1 +1 @@
|
||||
nano
|
||||
mg
|
||||
@@ -1 +1 @@
|
||||
nano
|
||||
mg
|
||||
@@ -3,11 +3,17 @@ CONFIG_DEVICE_TREE_INCLUDES="infix-env.dtsi infix-key.dtsi"
|
||||
|
||||
CONFIG_ENV_IMPORT_FDT=y
|
||||
|
||||
CONFIG_RSA=y
|
||||
CONFIG_RSA_VERIFY=y
|
||||
|
||||
CONFIG_FIT=y
|
||||
CONFIG_FIT_SIGNATURE=y
|
||||
CONFIG_BLKMAP=y
|
||||
|
||||
CONFIG_NET_RANDOM_ETHADDR=y
|
||||
|
||||
CONFIG_DISTRO_DEFAULTS=y
|
||||
CONFIG_CMD_SETEXPR=y
|
||||
CONFIG_CMD_SETEXPR_FMT=y
|
||||
|
||||
CONFIG_MMC=y
|
||||
|
||||
@@ -2,9 +2,11 @@ for tgt in "${boot_targets}"; do
|
||||
if test "${tgt}" = "mmc0"; then
|
||||
setenv devtype "mmc"
|
||||
setenv devnum 0
|
||||
mmc dev 0
|
||||
elif test "${tgt}" = "mmc1"; then
|
||||
setenv devtype "mmc"
|
||||
setenv devnum 1
|
||||
mmc dev 1
|
||||
else
|
||||
setenv devtype "${tgt}"
|
||||
setenv devnum 0
|
||||
|
||||
@@ -5,7 +5,7 @@ if test "${slot}" = "primary"; then
|
||||
run ixprepblk
|
||||
elif test "${slot}" = "secondary"; then
|
||||
run ixprepblk
|
||||
elif test "${slot}" = "dhcp"; then
|
||||
elif test "${slot}" = "net"; then
|
||||
run ixprepdhcp
|
||||
fi
|
||||
|
||||
|
||||
@@ -10,7 +10,7 @@ if load ${devtype} ${devnum}:${auxpart} ${ramdisk_addr_r} /${slot}.itbh; then
|
||||
|
||||
if part start ${devtype} ${devnum} ${slot} devoffs; then
|
||||
if ${devtype} read ${sqaddr} ${devoffs} ${sqblkcnt}; then
|
||||
setenv bootargs_root "root=PARTLABEL=${slot}"
|
||||
setenv bootargs_root "root=PARTLABEL=${slot} rootwait"
|
||||
setenv prepared ok
|
||||
fi
|
||||
fi
|
||||
|
||||
@@ -7,3 +7,7 @@ if [ -L "$TARGET_DIR/var/lib/avahi-autoipd" ]; then
|
||||
rm "$TARGET_DIR/var/lib/avahi-autoipd"
|
||||
mkdir "$TARGET_DIR/var/lib/avahi-autoipd"
|
||||
fi
|
||||
|
||||
# Allow clish (symlink to /usr/bin/klish) to be a login shell
|
||||
grep -qsE '^/bin/clish$$' "$TARGET_DIR/etc/shells" \
|
||||
|| echo "/bin/clish" >> "$TARGET_DIR/etc/shells"
|
||||
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
../usr/bin/klish
|
||||
@@ -4,7 +4,8 @@
|
||||
"user": [
|
||||
{
|
||||
"name": "admin",
|
||||
"password": "$6$bKPp6xu45L1cmp70$fcwDhGZct4q8LxwPASf9iVHyWqnklcdjeYi/SupLo1K9nb.aAQUz48.3qTcW38XL6gQzfHyGoyeDG2orjPUwm1"
|
||||
"password": "$6$bKPp6xu45L1cmp70$fcwDhGZct4q8LxwPASf9iVHyWqnklcdjeYi/SupLo1K9nb.aAQUz48.3qTcW38XL6gQzfHyGoyeDG2orjPUwm1",
|
||||
"infix-system:shell": "infix-shell-type:clish"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
{
|
||||
"ietf-system:system": {
|
||||
"hostname": "infix"
|
||||
},
|
||||
"ieee802-dot1ab-lldp:lldp": {
|
||||
"infix-lldp:enabled": true
|
||||
},
|
||||
"infix-services:mdns": {
|
||||
"enabled": true
|
||||
},
|
||||
"infix-services:ssdp": {
|
||||
"enabled": true
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1 @@
|
||||
alias cli='clish'
|
||||
+6
-2
@@ -13,11 +13,15 @@ gen-interfaces >$FACTORY_D/20-auto-interfaces.json
|
||||
|
||||
[ -s $GENCFG_D/20-auto-hostkey.json ] || gen-hostkeys >$GENCFG_D/20-auto-hostkey.json
|
||||
|
||||
# Allow regenerating default factory-config, but keep it read-ony
|
||||
# to prevent it from being overwritten by mistake by users.
|
||||
rm -f $CFG_D/auto-factory-config.cfg
|
||||
# shellcheck disable=SC2046
|
||||
jq -s 'reduce .[] as $item ({}; . * $item)' \
|
||||
$(find $FACTORY_D -name '*.json') \
|
||||
$(find $GENCFG_D -name '*.json') \
|
||||
>$CFG_D/auto-factory-config.cfg
|
||||
>$CFG_D/auto-factory-config.cfg
|
||||
chmod 444 $CFG_D/auto-factory-config.cfg
|
||||
|
||||
# TODO: Look for statically defined factory-config, based on the
|
||||
# system's product ID.
|
||||
@@ -28,4 +32,4 @@ jq -s 'reduce .[] as $item ({}; . * $item)' \
|
||||
ln -sf auto-factory-config.cfg $CFG_D/factory-config.cfg
|
||||
|
||||
# Bootstrap sysrepo db with all modules required by confd
|
||||
sysrepo-bootstrap.sh $CFG_D/factory-config.cfg $CFG_D/startup-config.cfg
|
||||
/usr/libexec/confd/confd-bootstrap.sh $CFG_D/factory-config.cfg $CFG_D/startup-config.cfg
|
||||
+5
-9
@@ -7,14 +7,9 @@ gen_interface()
|
||||
cat <<EOF
|
||||
,{
|
||||
"name": "$1",
|
||||
"type": "iana-if-type:ethernetCsmacd",
|
||||
"type": "infix-if-type:ethernet",
|
||||
"ietf-ip:ipv6": {
|
||||
"enabled": true,
|
||||
"forwarding": false,
|
||||
"dup-addr-detect-transmits": 1,
|
||||
"autoconf": {
|
||||
"create-global-addresses": true
|
||||
}
|
||||
"enabled": true
|
||||
}
|
||||
}
|
||||
EOF
|
||||
@@ -23,7 +18,8 @@ EOF
|
||||
phys_ifaces=$(ip -d -j link show | jq -r '
|
||||
.[] |
|
||||
select(.link_type == "ether") |
|
||||
select(has("linkinfo") | not) |
|
||||
select(.group != "internal") |
|
||||
select(has("parentbus")) |
|
||||
.ifname')
|
||||
|
||||
cat <<EOF
|
||||
@@ -32,7 +28,7 @@ cat <<EOF
|
||||
"interface": [
|
||||
{
|
||||
"name": "lo",
|
||||
"type": "iana-if-type:softwareLoopback",
|
||||
"type": "infix-if-type:loopback",
|
||||
"ietf-ip:ipv4": {
|
||||
"address": [{ "ip": "127.0.0.1", "prefix-length": 8 }]
|
||||
},
|
||||
+127
@@ -0,0 +1,127 @@
|
||||
#!/bin/bash
|
||||
|
||||
CYAN='\033[0;36m' # Used in headers
|
||||
RED='\033[0;31m'
|
||||
GREEN='\033[0;32m'
|
||||
NC='\033[0m' # No Color
|
||||
|
||||
GREY_BG="\e[48;5;235m"
|
||||
RESET="\e[0m"
|
||||
|
||||
HEADER_WIDHT=80
|
||||
declare -A IETF_TYPE_MAP
|
||||
|
||||
IETF_TYPE_MAP["iana-if-type:softwareLoopback"]="loopback"
|
||||
IETF_TYPE_MAP["iana-if-type:ethernetCsmacd"]="ethernet"
|
||||
IETF_TYPE_MAP["iana-if-type:l2vlan"]="vlan"
|
||||
IETF_TYPE_MAP["infix-if-type:veth"]="veth"
|
||||
IETF_TYPE_MAP["iana-if-type:bridge"]="bridge"
|
||||
|
||||
usage() {
|
||||
printf "Please provide a valid base field as the first argument\n"
|
||||
exit 1
|
||||
}
|
||||
|
||||
if [ -z "$1" ]; then
|
||||
usage
|
||||
fi
|
||||
|
||||
json=$(cat)
|
||||
|
||||
show_ietf_interface() {
|
||||
name="$1"
|
||||
shift
|
||||
|
||||
iface=$(echo "$json" | jq --arg name "$name" \
|
||||
'.["ietf-interfaces:interfaces"].interface[] | select(.name == $name)')
|
||||
if [ -z "$iface" ]; then
|
||||
printf "Error, interface named \"$name\" not found"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
printf "%-20s : %s\n" "name" "$name"
|
||||
printf "%-20s : %s\n" "interface-index" "$(echo "$iface" | jq -r '.["if-index"]')"
|
||||
printf "%-20s : %s\n" "operational-status" "$(echo "$iface" | jq -r '.["oper-status"]')"
|
||||
printf "%-20s : %s\n" "physical-address" "$(echo "$iface" | jq -r '.["phys-address"]')"
|
||||
|
||||
# MTU isn't set for loopback
|
||||
mtu="$(echo "$iface" | jq -r '.["ietf-ip:ipv4"] | select(.mtu != null) | .mtu')"
|
||||
if [ -n "$mtu" ]; then
|
||||
printf "%-20s : %s\n" "mtu" "$mtu"
|
||||
fi
|
||||
|
||||
printf "\n${CYAN}%-5s${NC}\n" "ipv4:"
|
||||
addresses=$(echo "$iface" | jq -c --arg field "$field" '.["ietf-ip:ipv4"].address[]' 2>/dev/null)
|
||||
for addr in $addresses; do
|
||||
ip="$(echo "$addr" | jq -r '."ip"')"
|
||||
prefix="$(echo "$addr" | jq -r '."prefix-length"')"
|
||||
printf "%-5s %s/%s\n" "" "$ip" "$prefix"
|
||||
done
|
||||
|
||||
printf "\n${CYAN}%-5s %5s\n${NC}" "in:" "octets"
|
||||
printf "%-5s %s\n" "" "$(echo "$iface" | jq -r '.statistics["in-octets"]')"
|
||||
|
||||
printf "\n${CYAN}%-5s %5s${NC}\n" "out:" "octets"
|
||||
printf "%-5s %s\n" "" "$(echo "$iface" | jq -r '.statistics["out-octets"]')"
|
||||
}
|
||||
|
||||
show_ietf_interfaces() {
|
||||
field="ietf-interfaces:interfaces"
|
||||
|
||||
if [ $# -ne 0 ]; then
|
||||
show_ietf_interface "$1"
|
||||
return
|
||||
fi
|
||||
|
||||
interfaces=$(echo "$json" | jq -c --arg field "$field" '.[$field].interface[]')
|
||||
|
||||
HEADER=$(printf "%-15s %-14s %-25s %s\n" "INTERFACE" "STATE" "PROTOCOL/ADDRESS" "SOURCE")
|
||||
HEADER_LEN=${#HEADER}
|
||||
RIGHT_PADDING=$(( HEADER_WIDHT - HEADER_LEN ))
|
||||
|
||||
printf "${GREY_BG}%s%${RIGHT_PADDING}s${RESET}\n" "$HEADER" ""
|
||||
|
||||
for iface in $interfaces; do
|
||||
name="$(echo "$iface" | jq -r '.["name"]')"
|
||||
state="$(echo "$iface" | jq -r '.["oper-status"]')"
|
||||
mac="$(echo "$iface" | jq -r '.["phys-address"]')"
|
||||
type="$(echo "$iface" | jq -r '.["type"]')"
|
||||
state_color=""
|
||||
|
||||
if [[ -v IETF_TYPE_MAP["$type"] ]]; then
|
||||
src="${IETF_TYPE_MAP["$type"]}"
|
||||
else
|
||||
src="unknown"
|
||||
fi
|
||||
|
||||
if [ "$state" = "up" ]; then
|
||||
state_color="$GREEN"
|
||||
elif [ "$state" = "down" ]; then
|
||||
state_color="$RED"
|
||||
fi
|
||||
printf "%-15s ${state_color}%-15s${NC}%s" "$name" "$state"
|
||||
|
||||
addresses=$(echo "$iface" | jq -c --arg field "$field" '.["ietf-ip:ipv4"].address[]' 2>/dev/null)
|
||||
printf "%-25s %s\n" "$mac" "$src"
|
||||
for addr in $addresses; do
|
||||
ip="$(echo "$addr" | jq -r '."ip"')"
|
||||
prefix="$(echo "$addr" | jq -r '."prefix-length"')"
|
||||
printf "%-30s %s/%s\n" "" "$ip" "$prefix"
|
||||
done
|
||||
if [ -n "$addresses" ]; then
|
||||
printf "\n"
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
field="$1"
|
||||
shift
|
||||
|
||||
case "$field" in
|
||||
"ietf-interfaces")
|
||||
show_ietf_interfaces $*
|
||||
;;
|
||||
*)
|
||||
usage
|
||||
;;
|
||||
esac
|
||||
@@ -3,6 +3,7 @@ INFIX_TESTS ?= $(test-dir)/case/all.yaml
|
||||
|
||||
test-env = $(test-dir)/env \
|
||||
-f $(BINARIES_DIR)/infix-x86_64.img \
|
||||
-p $(BINARIES_DIR)/infix-x86_64.pkg \
|
||||
$(1) $(2)
|
||||
|
||||
test-env-qeneth = $(call test-env,-q $(test-dir)/virt/dual,$(1))
|
||||
@@ -21,8 +22,11 @@ test-run: | ~/.infix-test-venv
|
||||
$(call test-env-run,\
|
||||
$(BR2_EXTERNAL_INFIX_PATH)/9pm/9pm.py \
|
||||
$(INFIX_TESTS))
|
||||
test-run-sh:
|
||||
test-run-sh: | ~/.infix-test-venv
|
||||
$(call test-env-run,/bin/sh)
|
||||
|
||||
test-run-play: | ~/.infix-test-venv
|
||||
$(call test-env-run,$(test-dir)/case/meta/play.py)
|
||||
|
||||
~/.infix-test-venv:
|
||||
$(test-dir)/docker/init-venv.sh $(test-dir)/docker/pip-requirements.txt
|
||||
|
||||
@@ -56,7 +56,7 @@ submenu "net" "$log" {
|
||||
set root=(initrd)
|
||||
|
||||
set slot="$1"
|
||||
set append="console=ttyS0 root=/dev/ram ramdisk_size=65536 $2"
|
||||
set append="console=ttyS0 root=/dev/ram0 ramdisk_size=65536 $2"
|
||||
source /boot/grub/grub.cfg
|
||||
else
|
||||
if [ -z "$net_efinet0_dhcp_next_server" ]; then
|
||||
|
||||
@@ -2,9 +2,10 @@
|
||||
compatible=infix-x86_64
|
||||
bootloader=grub
|
||||
grubenv=/mnt/aux/grub/grubenv
|
||||
statusfile=/var/lib/rauc/status
|
||||
statusfile=/mnt/aux/rauc.status
|
||||
mountprefix=/var/lib/rauc/mnt
|
||||
bundle-formats=-plain
|
||||
max-bundle-download-size=1073741824
|
||||
|
||||
[keyring]
|
||||
directory=/etc/rauc/keys
|
||||
@@ -18,5 +19,5 @@ device=/dev/disk/by-partlabel/secondary
|
||||
bootname=secondary
|
||||
|
||||
[slot.net.0]
|
||||
device=/dev/ram
|
||||
device=/dev/ram0
|
||||
bootname=net
|
||||
|
||||
@@ -12,7 +12,7 @@ BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||
BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_MDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="linux"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
BR2_SYSTEM_DHCP="eth0"
|
||||
BR2_ENABLE_LOCALE_WHITELIST="C en_US en_CA"
|
||||
BR2_GENERATE_LOCALE="en_US en_CA"
|
||||
@@ -21,8 +21,6 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/classic/post-build.sh"
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="5.19.17"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_DTS_SUPPORT=y
|
||||
|
||||
@@ -14,7 +14,7 @@ BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/xattrs"
|
||||
BR2_SYSTEM_BIN_SH_BASH=y
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="linux"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
BR2_SYSTEM_DHCP="eth0"
|
||||
BR2_ENABLE_LOCALE_WHITELIST="C en_US en_CA"
|
||||
BR2_GENERATE_LOCALE="en_US en_CA"
|
||||
@@ -23,13 +23,12 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/post-build.sh"
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="5.19.17"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_DTS_SUPPORT=y
|
||||
BR2_LINUX_KERNEL_INTREE_DTS_NAME="marvell/armada-3720-espressobin marvell/armada-3720-espressobin-emmc marvell/armada-3720-espressobin-v7 marvell/armada-3720-espressobin-v7-emmc marvell/armada-3720-espressobin-ultra marvell/cn9130-crb-A marvell/cn9130-crb-B sparx5_pcb135_emmc_no_psci"
|
||||
BR2_LINUX_KERNEL_CUSTOM_DTS_PATH="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/dts/microchip/sparx5_pcb135_emmc_no_psci.dts"
|
||||
BR2_LINUX_KERNEL_DTB_KEEP_DIRNAME=y
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
||||
BR2_PACKAGE_BUSYBOX_SHOW_OTHERS=y
|
||||
@@ -64,6 +63,7 @@ BR2_PACKAGE_FPING=y
|
||||
# BR2_PACKAGE_IFUPDOWN_SCRIPTS is not set
|
||||
BR2_PACKAGE_IPTABLES=y
|
||||
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
||||
BR2_PACKAGE_IPUTILS=y
|
||||
BR2_PACKAGE_LLDPD=y
|
||||
BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||
@@ -85,11 +85,13 @@ BR2_PACKAGE_IRQBALANCE=y
|
||||
BR2_PACKAGE_KMOD_TOOLS=y
|
||||
BR2_PACKAGE_PWGEN=y
|
||||
BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_DBUS=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
BR2_PACKAGE_LESS=y
|
||||
BR2_PACKAGE_MG=y
|
||||
BR2_PACKAGE_NANO=y
|
||||
BR2_TARGET_ROOTFS_SQUASHFS=y
|
||||
@@ -103,6 +105,7 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_CONFD=y
|
||||
BR2_PACKAGE_STATD=y
|
||||
BR2_PACKAGE_FACTORY=y
|
||||
BR2_PACKAGE_FINIT_SULOGIN=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||
@@ -112,7 +115,8 @@ BR2_PACKAGE_FINIT_PLUGIN_MODPROBE=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_RTC=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
|
||||
BR2_PACKAGE_KLINFIX=y
|
||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||
BR2_PACKAGE_LOWDOWN=y
|
||||
BR2_PACKAGE_NET=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_QUERIERD=y
|
||||
|
||||
@@ -11,6 +11,7 @@ BR2_GLOBAL_PATCH_DIR="$(BR2_EXTERNAL_INFIX_PATH)/patches"
|
||||
BR2_SSP_NONE=y
|
||||
BR2_INIT_NONE=y
|
||||
BR2_SYSTEM_BIN_SH_NONE=y
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
# BR2_PACKAGE_BUSYBOX is not set
|
||||
# BR2_PACKAGE_IFUPDOWN_SCRIPTS is not set
|
||||
# BR2_TARGET_ROOTFS_TAR is not set
|
||||
@@ -23,7 +24,20 @@ BR2_TARGET_ARM_TRUSTED_FIRMWARE_ADDITIONAL_VARIABLES="USE_COHERENT_MEM=0"
|
||||
BR2_TARGET_BINARIES_MARVELL=y
|
||||
BR2_TARGET_MV_DDR_MARVELL=y
|
||||
BR2_TARGET_UBOOT=y
|
||||
BR2_TARGET_UBOOT_BUILD_SYSTEM_KCONFIG=y
|
||||
BR2_TARGET_UBOOT_CUSTOM_VERSION=y
|
||||
BR2_TARGET_UBOOT_CUSTOM_VERSION_VALUE="2023.07.02"
|
||||
BR2_TARGET_UBOOT_BOARD_DEFCONFIG="mvebu_crb_cn9130"
|
||||
BR2_TARGET_UBOOT_CONFIG_FRAGMENT_FILES="$(BR2_EXTERNAL_INFIX_PATH)/board/common/uboot/extras.config $(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/cn9130-crb/uboot/extras.config"
|
||||
BR2_TARGET_UBOOT_FORMAT_DTB=y
|
||||
BR2_TARGET_UBOOT_CUSTOM_DTS_PATH="$(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/cn9130-crb/uboot/cn9130-crb-env.dtsi"
|
||||
BR2_PACKAGE_HOST_GENIMAGE=y
|
||||
BR2_PACKAGE_HOST_RAUC=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
# SIGN_ENABLED is not set
|
||||
DISK_IMAGE=y
|
||||
DISK_IMAGE_BOOT_BIN=y
|
||||
DISK_IMAGE_BOOT_DATA="${BINARIES_DIR}/flash-image.bin"
|
||||
DISK_IMAGE_BOOT_OFFSET=0x00200000
|
||||
|
||||
@@ -11,7 +11,7 @@ BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||
BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_MDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="linux"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
BR2_SYSTEM_DHCP="eth0"
|
||||
BR2_ENABLE_LOCALE_WHITELIST="C en_US en_CA"
|
||||
BR2_GENERATE_LOCALE="en_US en_CA"
|
||||
@@ -20,8 +20,6 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/classic/post-build.sh"
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="5.19.17"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
|
||||
@@ -13,7 +13,7 @@ BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/xattrs"
|
||||
BR2_SYSTEM_BIN_SH_BASH=y
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="linux"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
BR2_SYSTEM_DHCP="eth0"
|
||||
BR2_ENABLE_LOCALE_WHITELIST="C en_US en_CA"
|
||||
BR2_GENERATE_LOCALE="en_US en_CA"
|
||||
@@ -22,8 +22,6 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/post-build.sh"
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="5.19.17"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -61,6 +59,7 @@ BR2_PACKAGE_FPING=y
|
||||
# BR2_PACKAGE_IFUPDOWN_SCRIPTS is not set
|
||||
BR2_PACKAGE_IPTABLES=y
|
||||
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
||||
BR2_PACKAGE_IPUTILS=y
|
||||
BR2_PACKAGE_LLDPD=y
|
||||
BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||
@@ -82,11 +81,13 @@ BR2_PACKAGE_IRQBALANCE=y
|
||||
BR2_PACKAGE_KMOD_TOOLS=y
|
||||
BR2_PACKAGE_PWGEN=y
|
||||
BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_DBUS=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
BR2_PACKAGE_LESS=y
|
||||
BR2_PACKAGE_MG=y
|
||||
BR2_PACKAGE_NANO=y
|
||||
BR2_TARGET_ROOTFS_SQUASHFS=y
|
||||
@@ -108,6 +109,7 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_CONFD=y
|
||||
BR2_PACKAGE_STATD=y
|
||||
BR2_PACKAGE_FACTORY=y
|
||||
BR2_PACKAGE_FINIT_SULOGIN=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||
@@ -117,7 +119,8 @@ BR2_PACKAGE_FINIT_PLUGIN_MODPROBE=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_RTC=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
|
||||
BR2_PACKAGE_KLINFIX=y
|
||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||
BR2_PACKAGE_LOWDOWN=y
|
||||
BR2_PACKAGE_NET=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_QUERIERD=y
|
||||
|
||||
@@ -13,7 +13,7 @@ BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/xattrs"
|
||||
BR2_SYSTEM_BIN_SH_BASH=y
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="linux"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
BR2_SYSTEM_DHCP="eth0"
|
||||
BR2_ENABLE_LOCALE_WHITELIST="C en_US en_CA"
|
||||
BR2_GENERATE_LOCALE="en_US en_CA"
|
||||
@@ -22,8 +22,6 @@ BR2_ROOTFS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/common/rootfs ${BR2_EXTERNA
|
||||
BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build.sh ${BR2_EXTERNAL_INFIX_PATH}/board/netconf/post-build.sh"
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="5.19.17"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -59,6 +57,7 @@ BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_TARGET_ROOTFS_SQUASHFS=y
|
||||
# BR2_TARGET_ROOTFS_TAR is not set
|
||||
BR2_PACKAGE_CONFD=y
|
||||
BR2_PACKAGE_STATD=y
|
||||
BR2_PACKAGE_FACTORY=y
|
||||
BR2_PACKAGE_FINIT_SULOGIN=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||
@@ -68,7 +67,7 @@ BR2_PACKAGE_FINIT_PLUGIN_MODPROBE=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_RTC=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_TTY=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_URANDOM=y
|
||||
BR2_PACKAGE_KLINFIX=y
|
||||
BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||
BR2_PACKAGE_NET=y
|
||||
# SIGN_ENABLED is not set
|
||||
# GNS3_APPLIANCE is not set
|
||||
|
||||
@@ -0,0 +1,146 @@
|
||||
Change Log
|
||||
==========
|
||||
|
||||
All notable changes to the project are documented in this file.
|
||||
|
||||
|
||||
[v23.08.0][] - 2023-08-31
|
||||
-------------------------
|
||||
|
||||
> **Note:** upcoming releases will lock the `root` user for system-only
|
||||
> services. Instead an `admin` user will be the only default user with
|
||||
> the CLI as its login shell. This user is already available, so please
|
||||
> consider updating any guidelines or documentation you may have.
|
||||
|
||||
### YANG Status
|
||||
|
||||
- [ietf-system][]:
|
||||
- [infix-system][]: MotD (Message of the Day) augment
|
||||
- [infix-system][]: user login shell augment, default: `/bin/false`
|
||||
- [infix-system-software][]: system-state/software augment for
|
||||
remotely querying firmware version information
|
||||
- [infix-system-software][]: firmware upgrade with `install-bundle` RPC
|
||||
- [infix-system][]: timezone-name deviation, replaced with IANA timezones
|
||||
- [infix-system][]: username deviation, clarifying Linux restrictions
|
||||
- [infix-system][]: deviations for unsupported features, e.g. RADIUS
|
||||
- [ietf-interfaces][]:
|
||||
- [ietf-ip][]: augmented with IPv4LL similar to standardized IPv6LL
|
||||
- [ietf-if-vlan-encapsulation][]: Linux VLAN interfaces, e.g. `eth0.10`
|
||||
- [infix-if-bridge][]: Linux bridge interfaces with native VLAN support
|
||||
- [infix-if-veth][]: Linux VETH pairs
|
||||
- [infix-if-type][]: deviation for interface types, limiting number
|
||||
to supported types only. New identities are derived from default
|
||||
IANA interface types, ensuring compatibility with other standard
|
||||
models, e.g., `ieee802-ethernet-interface.yang`
|
||||
- Configurable services:
|
||||
- [ieee802-dot1ab-lldp][]: stripped down to an `enabled` setting
|
||||
- [infix-services][]: support for enabling mDNS and SSDP discovery
|
||||
|
||||
[br2023.02.2]: https://git.busybox.net/buildroot/tag/?h=2023.02.2
|
||||
[ieee802-dot1ab-lldp]: https://github.com/kernelkit/infix/tree/50a550b/src/confd/yang/ieee802-dot1ab-lldp%402022-03-15.yang
|
||||
[ietf-system]: https://www.rfc-editor.org/rfc/rfc7317.html
|
||||
[ietf-interfaces]: https://www.rfc-editor.org/rfc/rfc7223.html
|
||||
[ietf-ip]: https://www.rfc-editor.org/rfc/rfc8344.html
|
||||
[ietf-if-vlan-encapsulation]: https://www.ietf.org/id/draft-ietf-netmod-sub-intf-vlan-model-08.html
|
||||
[infix-if-bridge]: https://github.com/kernelkit/infix/tree/50a550b/src/confd/yang/infix-if-bridge%402023-08-21.yang
|
||||
[infix-if-veth]: https://github.com/kernelkit/infix/tree/50a550b/src/confd/yang/infix-if-veth%402023-06-05.yang
|
||||
[infix-if-type]: https://github.com/kernelkit/infix/tree/50a550b/src/confd/yang/infix-if-type%402023-08-21.yang
|
||||
[infix-services]: https://github.com/kernelkit/infix/tree/50a550b/src/confd/yang/infix-services%402023-08-22.yang
|
||||
[infix-system]: https://github.com/kernelkit/infix/tree/50a550b/src/confd/yang/infix-system%402023-08-15.yang
|
||||
[infix-system-software]: https://github.com/kernelkit/infix/tree/50a550b/src/confd/yang/infix-system-software%402023-06-27.yang
|
||||
|
||||
### Changes
|
||||
|
||||
- Bump Linux kernel: v5.19 to v6.1
|
||||
- Updated board support for Microchip SparX-5i and Marvell CN9130 CRB
|
||||
- New logo and significant updates to the documentation
|
||||
- New NETCONF RPC `factory-default` to reset `running-config`
|
||||
- Replaced limited BusyBox ping with iputils-ping
|
||||
- Most system services are now disabled by default, support for enabling
|
||||
LLDP, mDNS-SD, and SSDP using NETCONF, enabled in `factory-config`
|
||||
- Firmware upgrade framework, based on [RAUC](https://rauc.io/), added
|
||||
- Matching YANG model (see above) and an `install-bundle` RPC
|
||||
- Currently supported upgrade protocols: HTTP/HTTPS, FTP, SCP
|
||||
- Initial support for interface operational status, in ietf-interfaces
|
||||
- Add support for setting user login shell: `bash`, `clish`, `false`
|
||||
- Default login shell for new users: `false`
|
||||
- Massive updates and fixes to the CLI (klish):
|
||||
- Line editing now works as similar CLI:s from major vendors
|
||||
- Hotkey fixes: Ctrl-D and Ctrl-Z now work as expected
|
||||
- Prompt changed from JunOS style to be more similar to Bash
|
||||
- Online help commands, both in admin-exec and configure context,
|
||||
type `help` after entering the CLI to get started
|
||||
- Improved help for configure context using YANG descriptions
|
||||
- Support for reading and setting system "datetime" (RPC), an
|
||||
optional `iso` keyword can be used when reading time to see the
|
||||
format required when setting the time
|
||||
- Support for showing interfaces status, using above operational data
|
||||
- Support for showing bridge status: links, fdb, mdb, vlans
|
||||
- Support for showing log files, including tailing with `follow`
|
||||
- Support for `password generate` and `password encrypt`, highly
|
||||
useful from configure context when creating new users: use the
|
||||
`do password encrypt type sha256` to generate the hash
|
||||
- Support show uptime, version, calling `netcalc`, ping, and tcpdump
|
||||
|
||||
### Fixes
|
||||
|
||||
- Fix #57: unneccesary lldpd restarts on configuration change
|
||||
- Ensure mDNS advertises the correct hostname after hostname change
|
||||
- Fix regression in enabling IPv4 ZeroConf address
|
||||
- Loopback interface now shows `UP` operstate instead of `UNKNOWN`
|
||||
- Fix adding user without password, i.e., login using SSH keys only
|
||||
|
||||
|
||||
[v23.06.0][] - 2023-06-23
|
||||
-------------------------
|
||||
|
||||
Midsummer release. The first official Infix release, based on [Buildroot
|
||||
2023.02.2][br2023.02.2], with NETCONF support using the [sysrepo][] and
|
||||
[netopeer2][].
|
||||
|
||||
Supported YANG models in addition to those used by sysrepo and netopeer:
|
||||
|
||||
- [ietf-system][]
|
||||
- Everything except radius authentication and timezone-utc-offset
|
||||
- Augmented with MotD (Message of the Day), Infix YANG model
|
||||
- [ietf-interfaces][]
|
||||
- [ietf-ip][] augmented with IPv4LL similar to standardized IPv6LL
|
||||
- [ietf-if-vlan-encapsulation][], Linux VLAN interfaces, e.g. `eth0.10`
|
||||
- Linux bridge interfaces with native VLAN support, Infix YANG model
|
||||
- Linux VETH pairs, Infix YANG model
|
||||
|
||||
> **DISCLAIMER:** the [Infix YANG models for Linux][yang23.06], are
|
||||
> still under heavy development. New revisions are expected which may
|
||||
> not be backwards compatible. When upgrading to a new release, test on
|
||||
> a GNS3 staging environment first, or start over from a factory reset.
|
||||
|
||||
[br2023.02.2]: https://git.busybox.net/buildroot/tag/?h=2023.02.2
|
||||
[ietf-system]: https://www.rfc-editor.org/rfc/rfc7317.html
|
||||
[ietf-interfaces]: https://www.rfc-editor.org/rfc/rfc7223.html
|
||||
[ietf-ip]: https://www.rfc-editor.org/rfc/rfc8344.html
|
||||
[ietf-if-vlan-encapsulation]: https://www.ietf.org/id/draft-ietf-netmod-sub-intf-vlan-model-08.html
|
||||
[yang23.06]: https://github.com/kernelkit/infix/blob/aea74842e0475441d8df834f2dcd8cbc21fa253d/src/confd/yang/infix-interfaces%402023-06-05.yang
|
||||
|
||||
### Changes
|
||||
|
||||
- Bump sysrepo to v2.2.73
|
||||
- Backport support for initializing factory-default data store with
|
||||
default config data also for sysrepo internal modules.
|
||||
- Add support for `sysrepocfg -Cfactory -d running`, for testing
|
||||
- Bump netopeer2 to v2.1.62
|
||||
- Bump libyang to v2.1.80
|
||||
- Add klish, a CLI for sysrepo
|
||||
- Add podman for container support, backported from upstream Buildroot
|
||||
- Add conmon for container support, backported from upstream Buildroot
|
||||
- Backport cni-plugins support for host-local and static plugins
|
||||
|
||||
### Fixes
|
||||
|
||||
- N/A
|
||||
|
||||
[buildroot]: https://buildroot.org/
|
||||
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v23.08.0...HEAD
|
||||
[v23.08.0]: https://github.com/kernelkit/infix/compare/v23.06.0...v23.08.0
|
||||
[v23.06.0]: https://github.com/kernelkit/infix/compare/BASE...v23.06.0
|
||||
[sysrepo]: https://www.sysrepo.org/
|
||||
[netopeer2]: https://github.com/CESNET/netopeer2
|
||||
@@ -1,2 +0,0 @@
|
||||
Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Joachim Wiberg <troglobit@gmail.com>
|
||||
-221
@@ -1,221 +0,0 @@
|
||||
Infix System Configuration and RESTCONF API
|
||||
===========================================
|
||||
|
||||
This document shows how to configure settings in the Infix CLI and how
|
||||
to remotely inspect and change the configuration, as well as send RPC
|
||||
commands, using the RESTCONF API.
|
||||
|
||||
|
||||
Configuration
|
||||
-------------
|
||||
|
||||
|
||||
### NTP Client
|
||||
|
||||
How to configure two NTP servers with different options:
|
||||
|
||||
```
|
||||
set system ntp
|
||||
set system ntp server default
|
||||
set system ntp server default udp address 1.2.3.4
|
||||
set system ntp server default udp port 1231
|
||||
set system ntp server default iburst true
|
||||
set system ntp server default prefer true
|
||||
set system ntp server foo
|
||||
set system ntp server foo udp address 4.3.2.1
|
||||
set system ntp server foo iburst false
|
||||
commit
|
||||
```
|
||||
|
||||
How to set up an actually working configuration when the system has a
|
||||
valid IP address:
|
||||
|
||||
```
|
||||
set system ntp server bar
|
||||
set system ntp server bar udp address 192.168.122.1
|
||||
commit
|
||||
```
|
||||
|
||||
|
||||
### Static IP Address
|
||||
|
||||
DHCP support not yet ready, but would be the default in a product
|
||||
with NETCONF as the primary interface. This eliminates the need
|
||||
to set up the device and give a works-out-of-the-box experience.
|
||||
(Pending separate discussion on security aspects, of course).
|
||||
|
||||
```
|
||||
set interface eth0
|
||||
set interface eth0 type ianaift:ethernetCsmacd
|
||||
set interface eth0 enabled true
|
||||
set interface eth0 ipv4
|
||||
set interface eth0 ipv4 enabled true
|
||||
set interface eth0 ipv4 address 192.168.122.22
|
||||
set interface eth0 ipv4 address 192.168.122.22 prefix-length 24
|
||||
commit
|
||||
```
|
||||
|
||||
Multiple IP addresses per interface will be in the final product.
|
||||
|
||||
```
|
||||
> show configuration
|
||||
ietf-system:system {
|
||||
hostname flood;
|
||||
}
|
||||
ietf-interfaces:interfaces {
|
||||
interface eth0 {
|
||||
type ianaift:ethernetCsmacd;
|
||||
enabled true;
|
||||
ietf-ip:ipv4 {
|
||||
enabled true;
|
||||
address 192.168.122.22 {
|
||||
prefix-length 24;
|
||||
}
|
||||
}
|
||||
}
|
||||
interface eth1 {
|
||||
}
|
||||
}
|
||||
clixon-restconf:restconf {
|
||||
enable true;
|
||||
auth-type none;
|
||||
fcgi-socket /run/clixon/restconf.sock;
|
||||
}
|
||||
```
|
||||
|
||||
**Note:** authentication disabled for demo purposes.
|
||||
|
||||
To save the configuration so that it persists across reboots:
|
||||
|
||||
```
|
||||
copy running startup
|
||||
```
|
||||
|
||||
|
||||
RESTCONF API
|
||||
------------
|
||||
|
||||
Get a subset of the configuration:
|
||||
|
||||
```
|
||||
$ curl -X GET http://192.168.122.22/restconf/data/ietf-system:system
|
||||
{
|
||||
"ietf-system:system": {
|
||||
"hostname": "foo"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
```
|
||||
$ curl -k -X GET http://192.168.122.22/restconf/data/ietf-system:system-state/
|
||||
{
|
||||
"ietf-system:system-state": {
|
||||
"platform": {
|
||||
"os-name": "Infix",
|
||||
"os-release": "Buildroot 2023.02",
|
||||
"os-version": "latest-227-g51c35e9-dirty",
|
||||
"machine": "x86_64"
|
||||
},
|
||||
"clock": {
|
||||
"current-datetime": "2023-03-23T22:15:53+01:00",
|
||||
"boot-datetime": "2023-03-23T22:08:42+01:00"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
|
||||
List available RPC operations:
|
||||
|
||||
```
|
||||
$ curl -X GET http://192.168.122.22/restconf/operations
|
||||
{"operations": {
|
||||
"ietf-system:set-current-datetime": [null],
|
||||
"ietf-system:system-restart": [null],
|
||||
"ietf-system:system-shutdown": [null],
|
||||
"clixon-lib:debug": [null],
|
||||
"clixon-lib:ping": [null],
|
||||
"clixon-lib:stats": [null],
|
||||
"clixon-lib:restart-plugin": [null],
|
||||
"clixon-lib:process-control": [null],
|
||||
"ietf-netconf-monitoring:get-schema": [null],
|
||||
"ietf-netconf:get-config": [null],
|
||||
"ietf-netconf:edit-config": [null],
|
||||
"ietf-netconf:copy-config": [null],
|
||||
"ietf-netconf:delete-config": [null],
|
||||
"ietf-netconf:lock": [null],
|
||||
"ietf-netconf:unlock": [null],
|
||||
"ietf-netconf:get": [null],
|
||||
"ietf-netconf:close-session": [null],
|
||||
"ietf-netconf:kill-session": [null],
|
||||
"ietf-netconf:commit": [null],
|
||||
"ietf-netconf:discard-changes": [null],
|
||||
"ietf-netconf:cancel-commit": [null],
|
||||
"ietf-netconf:validate": [null],
|
||||
"clixon-rfc5277:create-subscription": [null],
|
||||
"ietf-netconf-nmda:get-data": [null],
|
||||
"ietf-netconf-nmda:edit-data": [null]}
|
||||
}
|
||||
```
|
||||
|
||||
|
||||
### Set hostname remotely
|
||||
|
||||
```
|
||||
$ curl -is -H 'Content-Type: application/yang-data+json' -H 'Accept: application/yang-data+json' -X PATCH -d @hostname.cfg http://192.168.122.22/restconf/data/ietf-system:system
|
||||
HTTP/1.1 204 No Content
|
||||
Server: nginx/1.22.1
|
||||
Date: Thu, 16 Mar 2023 13:53:53 GMT
|
||||
Connection: keep-alive
|
||||
```
|
||||
|
||||
The file `hostname.cfg` is in JSON format and looks like this:
|
||||
|
||||
```
|
||||
{
|
||||
"ietf-system:system": {
|
||||
"hostname": "foo"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
One-liner command without external `.cfg` file:
|
||||
|
||||
```
|
||||
$ curl -is -H 'Content-Type: application/yang-data+json' -H 'Accept: application/yang-data+json' -X PATCH -d '{"ietf-system:system":{"hostname":"flood"}}' http://192.168.122.22/restconf/data/ietf-system:system
|
||||
HTTP/1.1 204 No Content
|
||||
Server: nginx/1.22.1
|
||||
Date: Thu, 16 Mar 2023 14:1
|
||||
```
|
||||
|
||||
Run this on a PC connected to the "switch" to see how the settings take effect immediately:
|
||||
|
||||
```
|
||||
$ watch 'lldpcli show neighbors |grep -A20 tap0'
|
||||
```
|
||||
|
||||
### RPCs
|
||||
|
||||
Perform system reboot remotely:
|
||||
|
||||
```
|
||||
$ curl -k -X POST http://192.168.122.22/restconf/operations/ietf-system:system-restart
|
||||
```
|
||||
|
||||
Enable debug remotely:
|
||||
|
||||
```
|
||||
$ curl -Ssik -X POST -H "Content-Type: application/yang-data+json" http://192.168.122.22/restconf/operations/clixon-lib:debug -d '{"clixon-lib:input":{"level":1}}'
|
||||
```
|
||||
|
||||
Set current date/time:
|
||||
|
||||
```
|
||||
$ curl -Ssik -X POST -H "Content-Type: application/yang-data+json" http://192.168.122.22/restconf/operations/ietf-system:set-current-datetime -d '{"ietf-system:input":{"current-datetime":"2023-03-23T22:15:53+01:00"}}'
|
||||
HTTP/1.1 204 No Content
|
||||
Server: nginx/1.22.1
|
||||
Date: Thu, 23 Mar 2023 22:46:52 GMT
|
||||
Connection: keep-alive
|
||||
```
|
||||
$ curl -Ssik -X POST -H "Content-Type: application/yang-data+json" http://192.168.122.22/restconf/operations/ietf-system:set-current-datetime -d '{"ietf-system:input":{"current-datetime":"2023-03-23T20:15:53+05:00"}}'
|
||||
|
||||
+22
-22
@@ -243,26 +243,26 @@ following layout. The disk is expected to use the GPT partitioning
|
||||
scheme. Partitions marked with an asterisk are optional.
|
||||
|
||||
.-----------.
|
||||
| GPT Table |
|
||||
:-----------:
|
||||
| boot* |
|
||||
:-----------:
|
||||
| aux |
|
||||
:-----------:
|
||||
| |
|
||||
| primary |
|
||||
| |
|
||||
:-----------:
|
||||
| |
|
||||
| secondary |
|
||||
| |
|
||||
:-----------:
|
||||
| cfg |
|
||||
:-----------:
|
||||
| |
|
||||
| var* |
|
||||
| |
|
||||
'-----------'
|
||||
| GPT Table |
|
||||
:-----------:
|
||||
| boot* |
|
||||
:-----------:
|
||||
| aux |
|
||||
:-----------:
|
||||
| |
|
||||
| primary |
|
||||
| |
|
||||
:-----------:
|
||||
| |
|
||||
| secondary |
|
||||
| |
|
||||
:-----------:
|
||||
| cfg |
|
||||
:-----------:
|
||||
| |
|
||||
| var* |
|
||||
| |
|
||||
'-----------'
|
||||
|
||||
### `boot` - Bootloader
|
||||
|
||||
@@ -295,8 +295,8 @@ Typical layout when using U-Boot bootloader:
|
||||
|
||||
/
|
||||
├ primary.itbh
|
||||
├ secondary.itbh
|
||||
└ uboot.env
|
||||
├ secondary.itbh
|
||||
└ uboot.env
|
||||
|
||||
During boot, an ITB header along with the corresponding root
|
||||
filesystem image are concatenated in memory, by U-Boot, to form a
|
||||
|
||||
-139
@@ -1,139 +0,0 @@
|
||||
CLI User Guide
|
||||
==============
|
||||
|
||||
The Infix CLI is built on the [klish project][1], which is a framework
|
||||
for implementing a CISCO, or Juniper Networs JunOS-like CLI on a UNIX
|
||||
systems.
|
||||
|
||||
Currently, when the `admin` user logs in the default shell is Bash. To
|
||||
access the CLI, type:
|
||||
|
||||
cli
|
||||
|
||||
Key commands available in any context are:
|
||||
|
||||
help
|
||||
show
|
||||
|
||||
For each command it is also possible to press the `?` key and `TAB` to
|
||||
get more help and suggestions for completion.
|
||||
|
||||
|
||||
Admin Exec
|
||||
----------
|
||||
|
||||
The top-level context after logging in and starting the CLI is the
|
||||
admin-exec or "main" context. It is used for querying system status,
|
||||
managing configuration files/profiles and doing advanced debugging.
|
||||
|
||||
Available commands can be seen by pressing `?` at the prompt:
|
||||
|
||||
```
|
||||
root@infix-12-34-56:exec>
|
||||
configure Create new candidate-config based on running-config
|
||||
copy Copy
|
||||
exit Exit
|
||||
logout Alias for exit
|
||||
shell Enter system shell
|
||||
show Show
|
||||
```
|
||||
|
||||
Configure Context
|
||||
-----------------
|
||||
|
||||
Enter the configure context from admin-exec by typing `configure`
|
||||
followed by Enter. Available commands, press `?` at the prompt:
|
||||
|
||||
```
|
||||
root@infix-12-34-56:configure>
|
||||
abort Abandon candidate
|
||||
check Validate candidate
|
||||
commit Commit current candidate to running-config
|
||||
delete Delete configuration setting(s)
|
||||
diff Summarize uncommitted changes
|
||||
do Execute operational mode command
|
||||
edit Descend to the specified configuration node
|
||||
exit Ascend to the parent configuration node, or abort (from top)
|
||||
leave Finalize candidate and apply to running-config
|
||||
no Alias for delete
|
||||
rollback Restore candidate to running-config
|
||||
set Set configuration setting
|
||||
show Show configuration
|
||||
top Ascend to the configuration root
|
||||
up Ascend to the parent configuration node
|
||||
[edit]
|
||||
```
|
||||
|
||||
The `edit` command lets you change to a sub-configure context, e.g.:
|
||||
|
||||
```
|
||||
root@infix-12-34-56:configure> edit interfaces interface eth0
|
||||
[edit interfaces interface eth0]
|
||||
```
|
||||
|
||||
Notice the `[edit ...]` displayed, it shows your current location.
|
||||
Use `up` to go back to the previous context.
|
||||
|
||||
```
|
||||
root@infix-12-34-56:configure> up
|
||||
[edit]
|
||||
```
|
||||
|
||||
### Set IP Address on an Interface
|
||||
|
||||
```
|
||||
root@infix-12-34-56:configure>
|
||||
[edit]
|
||||
root@infix-12-34-56:configure> edit interfaces interface eth0
|
||||
[edit interfaces interface eth0]
|
||||
root@infix-12-34-56:configure> set ipv4 address 192.168.2.200 prefix-length 24
|
||||
[edit interfaces interface eth0]
|
||||
```
|
||||
|
||||
From anywhere in configure context you can see the changes you have
|
||||
made by typing `diff`:
|
||||
|
||||
```
|
||||
root@infix-12-34-56:configure> diff
|
||||
interfaces {
|
||||
interface eth0 {
|
||||
+ ipv4 {
|
||||
+ address 192.168.2.200 {
|
||||
+ prefix-length 24;
|
||||
+ }
|
||||
+ }
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
### Saving Changes
|
||||
|
||||
Apply the changes (from candidate to running):
|
||||
|
||||
```
|
||||
root@infix-12-34-56:configure> leave
|
||||
root@infix-12-34-56:exec> show running-config
|
||||
interfaces {
|
||||
interface eth0 {
|
||||
type ethernetCsmacd;
|
||||
ipv4 {
|
||||
address 192.168.2.200 {
|
||||
prefix-length 24;
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
Since we did not get any warnings we can save the running (RAM only)
|
||||
configuration to startup, so the changes are made persistent across
|
||||
reboots:
|
||||
|
||||
```
|
||||
root@infix-12-34-56:exec> copy running-config startup-config
|
||||
```
|
||||
|
||||
> **Note:** most (all) commands need to be spelled out, no short forms
|
||||
> are allowed at the moment. Use the `TAB` key to make this easier.
|
||||
|
||||
|
||||
[1]: https://src.libcode.org/pkun/klish
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
introduction.md
|
||||
@@ -0,0 +1,106 @@
|
||||
# Introduction
|
||||
|
||||
The command line interface (CLI, see-ell-i) is the traditional way of
|
||||
interacting with single network equipment like switches and routers.
|
||||
Today more advanced graphical NETCONF-based tools are available that
|
||||
allows for managing entire fleets of installed equipment.
|
||||
|
||||
Nevertheless, when it comes to initial deployment and debugging, it
|
||||
is very useful to know how to navigate and use the CLI. This very
|
||||
short guide intends to help you with that.
|
||||
|
||||
## Key Concepts
|
||||
|
||||
The two modes in the CLI are the admin-exec and the configure context.
|
||||
When logging in to the system, be it from console or SSH, you land in
|
||||
admin-exec. Here you can inspect the system status and do operations
|
||||
to debug networking issues, e.g. ping. You can also enter configure
|
||||
context by typing: `configure`
|
||||
|
||||
The system has several datastores (or files):
|
||||
|
||||
- `factory-config` consists of a set of default configurations, some
|
||||
static and others generated per-device, e.g., a unique hostname and
|
||||
number of ports/interfaces. This file is generated at boot, if it
|
||||
does not exist, i.e., only on first boot or after factory reset.
|
||||
- `startup-config` is created from `factory-config` at boot if it does
|
||||
not exist. It is loaded as the system configuration on each boot.
|
||||
- `running-config` is what is actively running on the system. If no
|
||||
changes have been made since the system booted, it is the same as
|
||||
`startup-config`.
|
||||
- `candidate-config` is created from `running-config` when entering the
|
||||
configure context. Any changes made here can be discarded (`abort`,
|
||||
`rollback`) or committed (`commit`, `leave`) to `running-config`.
|
||||
|
||||
To save configuration changes made to the `running-config` so the system
|
||||
will use them consecutive reboots, use the `copy` command:
|
||||
|
||||
admin@infix-12-34-56:/> copy running-config startup-config
|
||||
|
||||
In *configure context* the following commands are available:
|
||||
|
||||
| **Command** | **Description** |
|
||||
|-------------------|--------------------------------------------------------|
|
||||
| `set foo bar val` | Set `bar` leaf node in `foo` subcontext to `val` |
|
||||
| `no foo bar` | Clear/delete configuration made to `bar` in `foo` |
|
||||
| `edit foo baz` | Enter `baz` sub-sub-context in `foo` subcontext |
|
||||
| `abort` | Abort changes in configuration, return to admin-exec |
|
||||
| `exit` | Exit one level sub-context, or abort from top-level |
|
||||
| `leave` | Save changes to `running-config`, return to admin-exec |
|
||||
| `show [foo]` | Show configured values (optionally in subcontext) |
|
||||
| `diff [foo]` | Show uncommitted changes in candidate |
|
||||
| `do command` | Call admin-exec command: `do show log` |
|
||||
| `commit` | |
|
||||
|
||||
### Example Session
|
||||
|
||||
> Remember to use the `TAB` and `?` keys to speed up your navigation.
|
||||
> See `help keybindings` for more tips!
|
||||
|
||||
In this example we enter configure context to add an IPv4 address to
|
||||
interface `eth0`, then we apply the changes using the `leave` command.
|
||||
|
||||
We inspect the system status to ensure the change took effect. Then we
|
||||
save the changes for the next reboot.
|
||||
|
||||
```
|
||||
admin@infix-12-34-56:/> configure
|
||||
admin@infix-12-34-56:/config/> edit interfaces interface eth0
|
||||
admin@infix-12-34-56:/config/interfaces/interface/eth0/> set ipv4 <TAB>
|
||||
address autoconf bind-ni-name enabled
|
||||
forwarding mtu neighbor
|
||||
admin@infix-12-34-56:/config/interfaces/interface/eth0/> set ipv4 address 192.168.2.200 prefix-length 24
|
||||
admin@infix-12-34-56:/config/interfaces/interface/eth0/> show
|
||||
type ethernetCsmacd;
|
||||
ipv4 address 192.168.2.200 prefix-length 24;
|
||||
ipv6 enabled true;
|
||||
admin@infix-12-34-56:/config/interfaces/interface/eth0/> diff
|
||||
interfaces {
|
||||
interface eth0 {
|
||||
+ ipv4 {
|
||||
+ address 192.168.2.200 {
|
||||
+ prefix-length 24;
|
||||
+ }
|
||||
+ }
|
||||
}
|
||||
}
|
||||
admin@infix-12-34-56:/config/interfaces/interface/eth0/> leave
|
||||
admin@infix-12-34-56:/> show interfaces brief
|
||||
lo UNKNOWN 00:00:00:00:00:00 <LOOPBACK,UP,LOWER_UP>
|
||||
eth0 UP 52:54:00:12:34:56 <BROADCAST,MULTICAST,UP,LOWER_UP>
|
||||
admin@infix-12-34-56:exec> show ip brief
|
||||
lo UNKNOWN 127.0.0.1/8 ::1/128
|
||||
eth0 UP 192.168.2.200/24 fe80::5054:ff:fe12:3456/64
|
||||
admin@infix-12-34-56:/> copy running-config startup-config
|
||||
```
|
||||
|
||||
One of the ideas behind a separate running and startup configuration is
|
||||
to be able to verify a configuration change. In case of an inadvertent
|
||||
change that, e.g., breaks networking, it is trivial to revert back by:
|
||||
|
||||
```
|
||||
admin@infix-12-34-56:/> copy startup-config running-config
|
||||
```
|
||||
|
||||
Or restarting the device.
|
||||
|
||||
@@ -0,0 +1,48 @@
|
||||
# Keybindings
|
||||
|
||||
Writing CLI commands by hand is very tedious. To make things easier the
|
||||
CLI has several keybindings, most significant first:
|
||||
|
||||
| **Key** | **Cmd/Key** | **Description** |
|
||||
|---------|----------------|--------------------------------------------------|
|
||||
| TAB | | Complete current command, see below for example |
|
||||
| ? | | Show available commands, or arguments, with help |
|
||||
| Ctrl-c | | Cancel everything on current line |
|
||||
| Ctrl-d | `abort`/`exit` | Delete character, or abort/exit on empty line |
|
||||
| Ctrl-z | `leave` | Leave and activate changes in configure context |
|
||||
| Ctrl-f | Right arrow | Move cursor forward one character |
|
||||
| Ctrl-b | Left arrow | Move cursor back one character |
|
||||
| Meta-f | Ctrl-Right | Move cursor forward one word |
|
||||
| Meta-b | Ctrl-Left | Move cursor back one word |
|
||||
| Ctrl-e | End | Move cursor to end of line |
|
||||
| Ctrl-a | Home | Move cursor to beginning of line |
|
||||
| Ctrl-k | | Kill (cut) text from cursor to end of line |
|
||||
| Ctrl-u | | Delete (cut) entire line |
|
||||
| Ctrl-y | | Yank (paste) from kill buffer to cursor |
|
||||
| Meta-. | | Yank (paste) last argument from previous line |
|
||||
| Ctrl-w | Meta-Backspace | Delete (cut) word to the left |
|
||||
| | Meta-Delete | Delete (cut) word to the right |
|
||||
| Ctrl-l | | Clear screen and refresh current line |
|
||||
| Ctrl-p | Up arrow | History, previous command |
|
||||
| Ctrl-n | Down arrow | History, next command |
|
||||
| Ctrl-r | | History, reversed interactive search (i-search) |
|
||||
|
||||
> **Note:** the Meta key is called Alt on most modern keyboards. If you
|
||||
> have neither, first tap the Esc key instead of holding down Alt/Meta.
|
||||
|
||||
## Examples
|
||||
|
||||
Complete a word. Start by typing a few characters, then tap the TAB key
|
||||
on your keyboard:
|
||||
|
||||
conf<TAB> --> configure
|
||||
|
||||
See possible arguments, with brief help text, to a command:
|
||||
|
||||
show ?
|
||||
bridge Show bridge (ports/fdb/mdb/vlans)
|
||||
datetime Show current date and time, default RFC2822 format
|
||||
...
|
||||
|
||||
Type the command, then tap the `?` key.
|
||||
|
||||
@@ -0,0 +1,25 @@
|
||||
# Quick Overview
|
||||
|
||||
The question mark `?` key along with the `Tab` key are your best friends
|
||||
in the command line interface. They provide context help and completion
|
||||
of commands you input. See the table below for a handful of examples.
|
||||
|
||||
| **Command** | **Description** |
|
||||
|---------------------|----------------------------------------------------|
|
||||
| `help` | Overview of topics/settings in the current context |
|
||||
| `?` | Lists commands + brief help in the current context |
|
||||
| `<Tab>` | Lists commands available in the current context |
|
||||
| `partial<Tab>` | Completes a partial command name |
|
||||
| `command <Tab>` | Lists keywords/arguments associated with a command |
|
||||
| `command keyword ?` | Lists arguments associated with a keyword + help |
|
||||
|
||||
Explore the following topics for more information. Note, the
|
||||
keybindings are really useful to learn!
|
||||
|
||||
| **Command** | **Description** |
|
||||
|---------------------|--------------------------------------------|
|
||||
| `help introduction` | An introduction to the CLI |
|
||||
| `help keybindings` | Lists keybindings and other helpful tricks |
|
||||
| `help tutorial` | The CLI User Guide |
|
||||
|
||||
|
||||
@@ -0,0 +1,296 @@
|
||||
User Guide
|
||||
==========
|
||||
|
||||
The command line interface (CLI, see-el-i) is built on the open source
|
||||
component [klish][1], which implements a CISCO like, or Juniper Networks
|
||||
JunOS-like CLI on a UNIX system.
|
||||
|
||||
New users always get the CLI as the default "shell" when logging in, but
|
||||
the default `admin` user logs in to the Bash. To access the CLI, type:
|
||||
|
||||
cli
|
||||
|
||||
Key commands available in any context are:
|
||||
|
||||
help
|
||||
show
|
||||
|
||||
For each command it also possible to press the `?` key and `TAB` to get
|
||||
more help and suggestions for completion.
|
||||
|
||||
> **Note:** for the sake of brevity, the hostname in the following
|
||||
> examples has been shortened to `host`. The default name is composed
|
||||
> from a product specific string followed by the last three octets of
|
||||
> the system base MAC address, e.g., `infix-12-34-56`. An example of
|
||||
> how to change the hostname is included below.
|
||||
|
||||
|
||||
Admin Exec
|
||||
----------
|
||||
|
||||
The top-level context after logging in and starting the CLI is the
|
||||
admin-exec or "main" context. It is used for querying system status,
|
||||
managing configuration files/profiles and doing advanced debugging.
|
||||
|
||||
Available commands can be seen by pressing `?` at the prompt:
|
||||
|
||||
```
|
||||
admin@host:/>
|
||||
configure Create new candidate-config based on running-config
|
||||
copy Copy
|
||||
exit Exit
|
||||
logout Alias for exit
|
||||
shell Enter system shell
|
||||
show Show
|
||||
```
|
||||
|
||||
Configure Context
|
||||
-----------------
|
||||
|
||||
Enter the configure context from admin-exec by typing `configure`
|
||||
followed by Enter. Available commands, press `?` at the prompt:
|
||||
|
||||
```
|
||||
admin@host:/>
|
||||
admin@host:/config/>
|
||||
abort Abandon candidate
|
||||
check Validate candidate
|
||||
commit Commit current candidate to running-config
|
||||
delete Delete configuration setting(s)
|
||||
diff Summarize uncommitted changes
|
||||
do Execute operational mode command
|
||||
edit Descend to the specified configuration node
|
||||
exit Ascend to the parent configuration node, or abort (from top)
|
||||
leave Finalize candidate and apply to running-config
|
||||
no Alias for delete
|
||||
rollback Restore candidate to running-config
|
||||
set Set configuration setting
|
||||
show Show configuration
|
||||
top Ascend to the configuration root
|
||||
up Ascend to the parent configuration node
|
||||
```
|
||||
|
||||
The `edit` command lets you change to a sub-configure context, e.g.:
|
||||
|
||||
```
|
||||
admin@host:/config/> edit interfaces interface eth0
|
||||
admin@host:/config/interfaces/interface/eth0/>
|
||||
```
|
||||
|
||||
Use `up` to go up one level.
|
||||
|
||||
```
|
||||
admin@host:/config/interfaces/interface/eth0/> up
|
||||
admin@host:/config/interfaces/>
|
||||
```
|
||||
|
||||
> **Note:** the tree structure in the configure context is automatically
|
||||
> generated from the system's supported NETCONF YANG models, which may
|
||||
> vary between products. However, the `ietf-interfaces.yang` and
|
||||
> `ietf-ip.yang` models, for instance, that provide basic networking
|
||||
> support are common to all systems.
|
||||
|
||||
|
||||
### Set IP Address on an Interface
|
||||
|
||||
```
|
||||
admin@host:/config/> edit interfaces interface eth0
|
||||
admin@host:/config/interfaces/interface/eth0/>
|
||||
admin@host:/config/interfaces/interface/eth0/> set ipv4 address 192.168.2.200 prefix-length 24
|
||||
```
|
||||
|
||||
From anywhere in configure context you can see the changes you have
|
||||
made by typing `diff`:
|
||||
|
||||
```
|
||||
admin@host:/config/interfaces/interface/eth0/> diff
|
||||
interfaces {
|
||||
interface eth0 {
|
||||
+ ipv4 {
|
||||
+ address 192.168.2.200 {
|
||||
+ prefix-length 24;
|
||||
+ }
|
||||
+ }
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
|
||||
### Saving Changes
|
||||
|
||||
Apply the changes (from candidate to `running-config`):
|
||||
|
||||
```
|
||||
admin@host:/config/interfaces/> leave
|
||||
admin@host:/> show running-config
|
||||
...
|
||||
interfaces {
|
||||
interface eth0 {
|
||||
type ethernetCsmacd;
|
||||
ipv4 {
|
||||
address 192.168.2.200 {
|
||||
prefix-length 24;
|
||||
}
|
||||
}
|
||||
}
|
||||
...
|
||||
```
|
||||
|
||||
Since we did not get any warnings we can save the running (RAM only)
|
||||
configuration to startup, so the changes are made persistent across
|
||||
reboots:
|
||||
|
||||
```
|
||||
admin@host:/> copy running-config startup-config
|
||||
```
|
||||
|
||||
The `startup-config` can also be inspected with the `show` command to
|
||||
verify the changes are saved.
|
||||
|
||||
> **Note:** most (all) commands need to be spelled out, no short forms
|
||||
> are allowed at the moment. Use the `TAB` key to make this easier.
|
||||
|
||||
|
||||
### Changing Hostname
|
||||
|
||||
Settings like hostname are located in the `ietf-system.yang` model.
|
||||
Here is how it can be set.
|
||||
|
||||
```
|
||||
admin@host:/config/> edit system
|
||||
admin@host:/config/system/> set hostname example
|
||||
admin@host:/config/system/> leave
|
||||
admin@example:/>
|
||||
```
|
||||
|
||||
Notice how the hostname in the prompt does not change until the change
|
||||
is committed.
|
||||
|
||||
> **Note:** critical services like syslog, mDNS, LLDP, and similar that
|
||||
> advertise the hostname, are restarted when the hostname is changed.
|
||||
|
||||
|
||||
### Changing Password
|
||||
|
||||
User management, including passwords, is also a part of `ietf-system`.
|
||||
|
||||
```
|
||||
admin@host:/config/> edit system authentication
|
||||
admin@host:/config/system/authentication/> do password encrypt
|
||||
Password: ******
|
||||
$1$oVHGR0AP$6Pad1Pm8jPwPsan5WHULS1
|
||||
admin@host:/config/system/authentication/> set user admin password $1$oVHGR0AP$6Pad1Pm8jPwPsan5WHULS1
|
||||
admin@host:/config/system/> leave
|
||||
```
|
||||
|
||||
The call to `do password encrypt` brings up the helpful admin-exec
|
||||
command to hash, and optionally salt, your password. This encrypted
|
||||
string is what goes into the system configuration.
|
||||
|
||||
> **Tip:** if you are having trouble thinking of a password, there is
|
||||
> also `do password generate`, which generates random but readable
|
||||
> strings using the UNIX command `pwgen`.
|
||||
|
||||
|
||||
### Creating a VETH Pair
|
||||
|
||||
The following example creates a `veth0a <--> veth0b` virtual Ethernet
|
||||
pair which is useful for connecting, e.g., a container to the physical
|
||||
world. Here we also add an IPv4 address to one end of the pair.
|
||||
|
||||
```
|
||||
admin@host:/config/> edit interfaces interface veth0a
|
||||
admin@host:/config/interfaces/interface/veth0a/> set veth peer veth0b
|
||||
admin@host:/config/interfaces/interface/veth0a/> set ipv4 address 192.168.0.1 prefix-length 24
|
||||
admin@host:/config/interfaces/interface/veth0a/> up
|
||||
admin@host:/config/interfaces/> diff
|
||||
interfaces {
|
||||
+ interface veth0a {
|
||||
+ type veth;
|
||||
+ ipv4 {
|
||||
+ address 192.168.0.1 {
|
||||
+ prefix-length 24;
|
||||
+ }
|
||||
+ }
|
||||
+ veth {
|
||||
+ peer veth0b;
|
||||
+ }
|
||||
+ }
|
||||
+ interface veth0b {
|
||||
+ type veth;
|
||||
+ veth {
|
||||
+ peer veth0a;
|
||||
+ }
|
||||
+ }
|
||||
}
|
||||
admin@host:/config/interfaces/> leave
|
||||
```
|
||||
|
||||
See the bridging example below for more.
|
||||
|
||||
> **Note:** in the CLI you do not have to create the `veth0b` interface.
|
||||
> The system _infers_ this for you. When setting up a VETH pair using
|
||||
> NETCONF, however, you must include the `veth0b` interface.
|
||||
|
||||
|
||||
### Creating a Bridge
|
||||
|
||||
Building on the previous example, we now create a non-VLAN filtering
|
||||
bridge (`br0`) that forwards any, normally link-local, LLDP traffic
|
||||
between both its bridge ports: `eth0` and `vet0b`.
|
||||
|
||||
```
|
||||
admin@host:/> configure
|
||||
admin@host:/config/> edit interfaces interface br0
|
||||
admin@host:/config/interfaces/interface/br0/> set bridge ieee-group-forward lldp
|
||||
admin@host:/config/interfaces/interface/br0/> up
|
||||
admin@host:/config/interfaces/> set interface eth0 bridge-port bridge br0
|
||||
admin@host:/config/interfaces/> set interface veth0b bridge-port bridge br0
|
||||
admin@host:/config/interfaces/> diff
|
||||
interfaces {
|
||||
+ interface br0 {
|
||||
+ type bridge;
|
||||
+ bridge {
|
||||
+ ieee-group-forward lldp;
|
||||
+ }
|
||||
+ }
|
||||
interface eth0 {
|
||||
+ bridge-port {
|
||||
+ bridge br0;
|
||||
+ }
|
||||
}
|
||||
+ interface veth0a {
|
||||
+ type veth;
|
||||
+ ipv4 {
|
||||
+ address 192.168.0.1 {
|
||||
+ prefix-length 24;
|
||||
+ }
|
||||
+ }
|
||||
+ veth {
|
||||
+ peer veth0b;
|
||||
+ }
|
||||
+ }
|
||||
+ interface veth0b {
|
||||
+ type veth;
|
||||
+ veth {
|
||||
+ peer veth0a;
|
||||
+ }
|
||||
+ bridge-port {
|
||||
+ bridge br0;
|
||||
+ }
|
||||
+ }
|
||||
}
|
||||
```
|
||||
|
||||
Both a physical port `eth0` and a virtual port `veth0b` (bridge side of
|
||||
the VETH pair from the previous example) are now bridged. Any traffic
|
||||
ingressing one port will egress the other. Only reserved IEEE multicast
|
||||
is filtered, except LLDP frames as shown above.
|
||||
|
||||
> **Note:** the bridge can be named anything, provided the interface
|
||||
> name is not already taken. However, for any name outside the pattern
|
||||
> `br[0-9]+`, you have to set the interface type manually to `bridge`.
|
||||
|
||||
|
||||
|
||||
[1]: https://src.libcode.org/pkun/klish
|
||||
+234
-41
@@ -1,50 +1,52 @@
|
||||
Containers in Infix
|
||||
===================
|
||||
|
||||
The default builds of Infix do not enable any container support. This
|
||||
because it is not a common customer feature, and it extends build times
|
||||
due to bringing in a build-time dependency on Go.
|
||||
* [Introduction](#introduction)
|
||||
* [Docker Containers with Podman](#docker-containers-with-podman)
|
||||
* [Multiple Networks](#multiple-networks)
|
||||
* [Hybrid Mode](#hybrid-mode)
|
||||
* [Enabling Containers](#enabling-containers)
|
||||
* [Debugging Containers](#debugging-containers)
|
||||
|
||||
However,customer specific builds may have it, and you can also roll your
|
||||
own based on any of the available `defconfigs`. For example:
|
||||
|
||||
cd infix/
|
||||
make x86_64_defconfig
|
||||
Introduction
|
||||
------------
|
||||
|
||||
Default builds of Infix do not enable any container support. See below
|
||||
section, [Enabling Container Support](#enabling-container-support), for
|
||||
details on how to enable it using Podman.
|
||||
|
||||
Networking in containers is provided by both Infix and the Container
|
||||
Network Interface ([CNI](https://www.cni.dev/)) that Podman supports.
|
||||
|
||||
> A convenience alias `docker=podman` is available in Infix, remember,
|
||||
> not all features or syntax of docker is available in podman.
|
||||
|
||||
|
||||
Docker Containers with Podman
|
||||
-----------------------------
|
||||
|
||||
Run menuconfig, search for `podman`, enable that and build:
|
||||
|
||||
make menuconfig
|
||||
...
|
||||
make
|
||||
|
||||
Enabling [podman][] select `crun`, `conmon`, and all other dependencies.
|
||||
The build will take a while, but eventually you can:
|
||||
|
||||
make run
|
||||
|
||||
> A convenience alias `docker=podman` is available, but remember, not
|
||||
> all features or syntax of docker is available in podman.
|
||||
|
||||
Test it out with an example:
|
||||
We assume you've booted into Infix and start with a familiar example.
|
||||
This downloads the `hello-world` example container image and runs it:
|
||||
|
||||
podman run -it --rm docker://hello-world
|
||||
|
||||
or a little web server:
|
||||
We can also set up a port forward to a little web server:
|
||||
|
||||
podman run -d --rm -p 80:80 docker://nginx:alpine
|
||||
|
||||
In detached (`-d`) state you can check the status using `podman ps` or
|
||||
In detached (`-d`) state you can check the status using `podman ps` and
|
||||
try to connect to the web server:
|
||||
|
||||
curl http://localhost
|
||||
|
||||
or
|
||||
or connect to port 80 of your running Infix system with a browser. See
|
||||
the following sections for how to add more interfaces and start/stop the
|
||||
container at boot/reboot.
|
||||
|
||||
lynx http://localhost
|
||||
> To add your own content to web server, place the HTML files in, e.g.,
|
||||
> `/cfg/www/*.html` and add `-v /cfg/www:/usr/share/nginx/html:ro` to
|
||||
> the command line (above). <https://hub.docker.com/_/nginx/>
|
||||
|
||||
|
||||
### Multiple Networks
|
||||
@@ -53,15 +55,16 @@ It is also possible to start a container with multiple networks. The
|
||||
approach shown here uses CNI profiles, which means the interfaces names
|
||||
inside the container will always be: `eth0`, `eth1`, etc.
|
||||
|
||||
Pending VETH support in Infix/NETCONF, the following example sets up a
|
||||
VETH pair, then creates a CNI profile, and finally starts a container
|
||||
with two profiles, the default podman bridge and the VETH profile:
|
||||
A common setup is to use a VETH pair, with one end in the container and
|
||||
the other end routed, or bridged, to the rest of the world. The Infix
|
||||
[CLI Guide](cli/introduction.md) provides examples of both. In either case you need
|
||||
to create a matching CNI profile for one end of the VETH pair before
|
||||
starting the container, here we use two network profiles, the default
|
||||
podman bridge and the VETH profile:
|
||||
|
||||
ip link add local1 type veth peer local1_peer
|
||||
ip link set local1 up
|
||||
ip addr add 192.168.0.1/24 dev local1
|
||||
cni create host net1 local1_peer 192.168.0.42/24
|
||||
podman run -d --rm --net=podman,net1 --privileged docker://troglobit/buildroot:latest
|
||||
cni create host net1 veth0a 192.168.0.42/24
|
||||
podman run -d --rm --net=podman,net1 --entrypoint "/linuxrc" \
|
||||
--privileged docker://troglobit/buildroot:latest
|
||||
|
||||
The first profile (`podman`) is a the default bridged profile. When a
|
||||
container is started with that (default behavior), podman dynamically
|
||||
@@ -79,22 +82,93 @@ used to hand over control of physical ports to a container.
|
||||
> might not be what you want for a production system. For that at least
|
||||
> SECCOMP is recommended, which is out of scope for this tutorial.
|
||||
|
||||
### Real Example
|
||||
|
||||
### NETCONF Build
|
||||
To be able to preserve state in containers between reboots we need a
|
||||
writable layer, this is done with `podman create`, after which we can
|
||||
use `podman start`. We build on the previous example:
|
||||
|
||||
If you've followed this tutorial then you now have a NETCONF based Infix
|
||||
system running. To run containers on it you need to leverage the Hybrid
|
||||
mode, described in the README but also repeated below.
|
||||
cni create host net1 veth0a 192.168.0.42/24
|
||||
podman create --name system --conmon-pidfile=/run/pod:system.pid \
|
||||
--restart=no --systemd=false --tz=local --privileged \
|
||||
--net=podman,net1 --entrypoint "/linuxrc" -p 222:22 \
|
||||
docker://troglobit/buildroot:latest
|
||||
|
||||
Here we map the host port 222 to the SSH port of the container, but one
|
||||
can just as easily map the host's port 22 (SSH). Just make sure to
|
||||
first disable the host's SSH service.
|
||||
|
||||
> **Note:** the new options used here are required for enabling
|
||||
> monitoring and automate start/stop of containers at boot/reboot.
|
||||
|
||||
This creates the named container `system` which we can now start:
|
||||
|
||||
podman start system
|
||||
|
||||
and stop:
|
||||
|
||||
podman stop system
|
||||
|
||||
For this particular image[^1] we need to modify its defaults a bit,
|
||||
because it is set up to run a DHCP client on the first Ethernet
|
||||
interface, which in our case is the `podman` default CNI bridge. In
|
||||
fact, we don't want the container to set up any networking since that is
|
||||
handled by Infix and podman.
|
||||
|
||||
root@infix-12-34-56:~$ podman start system
|
||||
root@infix-12-34-56:~$ podman exec -it system sh
|
||||
/ # rm -rf /etc/network/interfaces
|
||||
/ # exit
|
||||
root@infix-12-34-56:~$ podman stop system
|
||||
|
||||
The change is now saved in the writable layer and the next time the
|
||||
container is started it will look like this:
|
||||
|
||||
root@infix-12-34-56:~$ podman start system
|
||||
root@infix-12-34-56:~$ podman exec -it system sh
|
||||
/ # ifconfig
|
||||
eth0 Link encap:Ethernet HWaddr A2:32:4C:2B:5E:51
|
||||
inet addr:10.88.0.11 Bcast:10.88.255.255 Mask:255.255.0.0
|
||||
inet6 addr: fe80::a032:4cff:fe2b:5e51/64 Scope:Link
|
||||
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
|
||||
RX packets:204 errors:0 dropped:107 overruns:0 frame:0
|
||||
TX packets:15 errors:0 dropped:0 overruns:0 carrier:0
|
||||
collisions:0 txqueuelen:0
|
||||
RX bytes:48240 (47.1 KiB) TX bytes:1102 (1.0 KiB)
|
||||
|
||||
eth1 Link encap:Ethernet HWaddr 56:B5:4E:D1:9C:E5
|
||||
inet addr:192.168.0.42 Bcast:192.168.0.255 Mask:255.255.255.0
|
||||
inet6 addr: fe80::54b5:4eff:fed1:9ce5/64 Scope:Link
|
||||
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
|
||||
RX packets:274 errors:0 dropped:213 overruns:0 frame:0
|
||||
TX packets:16 errors:0 dropped:0 overruns:0 carrier:0
|
||||
collisions:0 txqueuelen:1000
|
||||
RX bytes:60926 (59.4 KiB) TX bytes:1377 (1.3 KiB)
|
||||
|
||||
Automating start/stop at boot/reboot is documented in the next section.
|
||||
|
||||
[^1]: A common task one has to do for many other standard images, e.g.,
|
||||
Alpine Linux and BusyBox available on Docker Hub.
|
||||
|
||||
### Hybrid Mode
|
||||
|
||||
Since container setup and configuration is not modeled in YANG yet, we
|
||||
use the Infix *Hybrid mode*, described in [Infix Variants](variant.md).
|
||||
|
||||
To start containers in *Hybrid Mode*, provided the images have been
|
||||
downloaded with `podman pull` first):
|
||||
downloaded with `podman pull docker://troglobit/buildroot:latest` and
|
||||
a container created (above):
|
||||
|
||||
```
|
||||
root@infix:/cfg/start.d$ cat <<EOF >20-enable-container.sh
|
||||
#!/bin/sh
|
||||
podman-service -e -d "Nginx container" -p "-p 80:80" nginx:alpine
|
||||
exit 0
|
||||
# Remember to create the veth0a <--> vet0b pair in the CLI first!
|
||||
cni create host net1 veth0a 192.168.0.42/24
|
||||
cat <<EOF > /etc/finit.d/available/pod:system.conf
|
||||
service name:pod :system pid:!/run/pod:system.pid podman --syslog start system -- System container
|
||||
EOF
|
||||
initctl enable pod:system
|
||||
exit 0
|
||||
root@infix:/cfg/start.d$ chmod +x 20-enable-container.sh
|
||||
```
|
||||
|
||||
@@ -106,4 +180,123 @@ rebooting, run the script and call `initctl reload`.
|
||||
> need to either save them and restore in the script above, or recreate
|
||||
> them on every boot.
|
||||
|
||||
|
||||
Enabling Container Support
|
||||
--------------------------
|
||||
|
||||
Container support is not enabled by default because it is not a common
|
||||
customer feature, it also prolongs build times a lot due to bringing in
|
||||
a build-time dependency on Go.
|
||||
|
||||
However, customer specific builds may have it, and you can also roll
|
||||
your own based on any of the available `defconfigs`. For example:
|
||||
|
||||
cd infix/
|
||||
make x86_64_defconfig
|
||||
|
||||
Run menuconfig, search for `podman` using `/`, enable it and build:
|
||||
|
||||
make menuconfig
|
||||
...
|
||||
make
|
||||
|
||||
Enabling [podman][] select `crun`, `conmon`, and all other dependencies.
|
||||
The build will take a while, but eventually you can:
|
||||
|
||||
make run
|
||||
|
||||
|
||||
Debugging Containers
|
||||
--------------------
|
||||
|
||||
If the host system is not powered down or rebooted properly, containers
|
||||
may not start up as they should on the following boot. Below is a very
|
||||
common problem and solution shown.
|
||||
|
||||
```
|
||||
root@infix-12-34-56:~$ podman ps
|
||||
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
|
||||
root@infix-12-34-56:~$ grep nginx /var/log/syslog
|
||||
Jun 25 10:15:48 infix-12-34-56 finit[1]: Service pod:nginx[2376] died, restarting in 5000 msec (10/10)
|
||||
Jun 25 10:15:48 infix-12-34-56 finit[1]: Starting pod:nginx[2408]
|
||||
Jun 25 10:15:53 infix-12-34-56 finit[1]: Service pod:nginx keeps crashing, not restarting.
|
||||
```
|
||||
|
||||
If this the system is isolated from remote network access, start by
|
||||
verifying the image is downloaded:
|
||||
|
||||
```
|
||||
root@infix-12-34-56:/cfg/start.d$ podman images
|
||||
REPOSITORY TAG IMAGE ID CREATED SIZE
|
||||
docker.io/library/nginx alpine 4937520ae206 10 days ago 43.2 MB
|
||||
docker.io/troglobit/buildroot latest 68faf6b20f1a 6 weeks ago 41.4 MB
|
||||
```
|
||||
|
||||
OK, let's see what the `podman-service` step (above) created:
|
||||
|
||||
```
|
||||
root@infix-12-34-56:/cfg/start.d$ initctl show pod-nginx.conf
|
||||
service name:pod :nginx podman run --name nginx --rm -p 80:80 nginx:alpine -- Nginx container
|
||||
```
|
||||
|
||||
Try starting the container manually. Remember to add the `-d` flag to
|
||||
emulate detached/background operation:
|
||||
|
||||
```
|
||||
root@infix-12-34-56:/cfg/start.d$ podman run --name nginx --rm -d -p 8080:80 nginx:alpine
|
||||
Error: creating container storage: the container name "nginx" is already in use by 9c73bd8d505b1585d241595bfadede361b87f6c1be9a5656253b5a4d73da57e0. You have to remove that container to be able to reuse that name: that name is already in use
|
||||
```
|
||||
|
||||
Aha, a lingering image with the same name! Where is it?
|
||||
|
||||
```
|
||||
root@infix-12-34-56:/cfg/start.d$ podman ps --all
|
||||
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
|
||||
f3386ae9517f docker.io/troglobit/buildroot:latest About an hour ago Exited (0) About an hour ago ecstatic_panini
|
||||
bf0c6178ea26 docker.io/troglobit/buildroot:latest About an hour ago Exited (0) About an hour ago determined_brown
|
||||
385155f479c0 docker.io/troglobit/buildroot:latest About an hour ago Exited (0) About an hour ago vibrant_engelbart
|
||||
99a1b3319d9e docker.io/troglobit/buildroot:latest About an hour ago Exited (0) About an hour ago dreamy_tesla
|
||||
9c73bd8d505b docker.io/library/nginx:alpine nginx -g daemon o... 11 minutes ago Created 0.0.0.0:80->80/tcp nginx
|
||||
8a5290504ebc docker.io/troglobit/buildroot:latest 10 minutes ago Created mystifying_liskov
|
||||
```
|
||||
|
||||
Oh, we have two lingering containers that were created but did not stop
|
||||
correctly. Let's remove them:
|
||||
|
||||
```
|
||||
root@infix-12-34-56:/cfg/start.d$ docker rm -f 9c73bd8d505b
|
||||
9c73bd8d505b
|
||||
root@infix-12-34-56:/cfg/start.d$ docker rm -f 8a5290504ebc
|
||||
8a5290504ebc
|
||||
```
|
||||
|
||||
Now we can manually restart the (supervised) container:
|
||||
|
||||
```
|
||||
root@infix-12-34-56:/cfg/start.d$ initctl restart pod:nginx
|
||||
root@infix-12-34-56:/cfg/start.d$ initctl status pod:nginx
|
||||
Status : running
|
||||
Identity : pod:nginx
|
||||
Description : Nginx container
|
||||
Origin : /etc/finit.d/enabled/pod-nginx.conf
|
||||
Command : podman run --name nginx --rm -p 80:80 nginx:alpine
|
||||
PID file : none
|
||||
PID : 2669
|
||||
User : root
|
||||
Group : root
|
||||
Uptime : 15 sec
|
||||
Restarts : 11 (0/10)
|
||||
Runlevels : [---234-----]
|
||||
Memory : 63.8M
|
||||
CGroup : /system/pod-nginx cpu 0 [100, max] mem [0, max]
|
||||
├─ 2669 podman run --name nginx --rm -p 80:80 nginx:alpine
|
||||
└─ 2816 conmon --api-version 1 -c 44d24aa7e98b67ff811596984462b902af3b09a04b4f9bef86e11d246b8cc2ff -u 44d24aa7e98b67ff8
|
||||
|
||||
Jun 25 10:15:48 infix-12-34-56 finit[1]: Service pod:nginx[2376] died, restarting in 5000 msec (10/10)
|
||||
Jun 25 10:15:48 infix-12-34-56 finit[1]: Starting pod:nginx[2408]
|
||||
Jun 25 10:15:53 infix-12-34-56 finit[1]: Service pod:nginx keeps crashing, not restarting.
|
||||
Jun 25 10:47:55 infix-12-34-56 finit[1]: Starting pod:nginx[2669]
|
||||
```
|
||||
|
||||
|
||||
[podman]: https://podman.io
|
||||
|
||||
@@ -0,0 +1,109 @@
|
||||
Developer's Guide
|
||||
=================
|
||||
|
||||
Cloning
|
||||
-------
|
||||
|
||||
Please see the [Contributing](#contributing) section, below, for details
|
||||
on how to fork and clone when contributing to Infix.
|
||||
|
||||
```bash
|
||||
$ mkdir ~/Projects; cd ~/Projects
|
||||
$ git clone https://github.com/kernelkit/infix.git
|
||||
$ cd infix/
|
||||
$ git submodule update --init
|
||||
```
|
||||
|
||||
### Customer Builds
|
||||
|
||||
Customer builds add product specific device trees, more OSS packages,
|
||||
e.g., Frr and podman, and sometimes integrates proprietary software.
|
||||
What's *important to remember*, however, is that they are all made by
|
||||
setting up Infix as a GIT submodule, similar to how Infix set up a GIT
|
||||
submodule for Buildroot.
|
||||
|
||||
So, in addition to using the customer's specific defconfig(s), one must
|
||||
also make sure to update *all submodules*, otherwise you will likely end
|
||||
up with a broken build.
|
||||
|
||||
```bash
|
||||
$ ...
|
||||
$ git submodule update --init --recursive
|
||||
~~~~~~~~~~~
|
||||
```
|
||||
|
||||
Other caveats should be documented in the customer specific trees.
|
||||
|
||||
|
||||
Building
|
||||
--------
|
||||
|
||||
Buildroot is almost stand-alone, it needs a few locally installed tools
|
||||
to bootstrap itself. For details, see the [excellent manual][manual].
|
||||
|
||||
> **Note:** installation for Debian/Ubuntu based systems: <kbd>sudo apt
|
||||
> install make libssl-dev</kbd>
|
||||
|
||||
Briefly, to build an Infix image; select the target and then make:
|
||||
|
||||
make x86_64_defconfig
|
||||
make
|
||||
|
||||
Online help is available:
|
||||
|
||||
make help
|
||||
|
||||
To see available defconfigs for supported targets, use:
|
||||
|
||||
make list-defconfigs
|
||||
|
||||
|
||||
Testing
|
||||
-------
|
||||
|
||||
Manual testing can be done using Qemu by calling <kbd>make run</kbd>,
|
||||
see also [Infix in Virtual Environments](virtual.md).
|
||||
|
||||
The Infix automated test suite is built around Qemu and [Qeneth][2], see:
|
||||
|
||||
* [Testing](testing.md)
|
||||
* [Docker Image](../test/docker/README.md)
|
||||
|
||||
|
||||
Contributing
|
||||
------------
|
||||
|
||||
Infix is built from many parts, when contributing you need to set up
|
||||
your own fork, create a local branch for your change, push to your fork,
|
||||
and then use GitHub to create a *Pull Reqeuest*.
|
||||
|
||||
For this to work as painlessly as possible:
|
||||
|
||||
1. Fork Infix to your own user or organization[^1]
|
||||
2. Fork all the Infix submodules, e.g., `buildroot` to your own user
|
||||
or organization as well
|
||||
3. Clone your fork of Infix to your laptop/workstation
|
||||
|
||||
If you use a GitHub organization you get the added benefit of having
|
||||
local peer reviews of changes before making a pull request to the
|
||||
upstream Infix repository.
|
||||
|
||||
```bash
|
||||
$ cd ~/Projects
|
||||
$ git clone https://github.com/YOUR_USER_NAME/infix.git
|
||||
$ cd infix/
|
||||
$ git submodule update --init
|
||||
```
|
||||
|
||||
> **Note:** when updating/synchronizing with upstream Infix changes you
|
||||
> may have to synchronize your forks as well. GitHub have a `Sync fork`
|
||||
> button in the GUI for your fork for this purpose.
|
||||
|
||||
[^1]: Organizations should make sure to lock the `main` (or `master`)
|
||||
branch of their clones to ensure members do not accidentally merge
|
||||
changes there. Keeping these branches in sync with upstream Infix
|
||||
is highly recommended as a baseline and reference. For integration
|
||||
of local changes another company-specific branch can be used instead.
|
||||
|
||||
[1]: https://buildroot.org/downloads/manual/manual.html
|
||||
[2]: https://github.com/wkz/qeneth
|
||||
@@ -1,55 +0,0 @@
|
||||
Infix Goals
|
||||
===========
|
||||
|
||||
The founding ideas that drive Infix are:
|
||||
|
||||
- Use Buildroot, it is:
|
||||
- High quality, track their LTS releases whenever possible
|
||||
- Well maintained and responsive community
|
||||
- Easy to use (c.f. Yocto or roll-your-own)
|
||||
- Well curated Open Source components
|
||||
- Take active part in Buildroot to secure investment in key components
|
||||
- Extend with other Open Source components for system monitoring,
|
||||
networking, etc. With the intent of upstreaming them to become parts
|
||||
of Buildroot proper
|
||||
- Rely on standards, i.e., use NETCONF and YANG
|
||||
- When standards are not enough create models that fit well with Linux
|
||||
and chosen Open Source components
|
||||
- Keep as much as possible Open Source, no need to maintain stuff that
|
||||
is not core business
|
||||
- Secure boot by default
|
||||
- Use RAUC for upgrades, it works
|
||||
- Serve as a stand-alone(!) base for other projects that use Infix as
|
||||
their Buildroot external -- this makes Infix a great layer for where
|
||||
to publish used Open Source components and patches used in customer
|
||||
projects
|
||||
|
||||
**Note:** projects derived from Infix (as a Buildroot external) will be
|
||||
able to seamlessly extend the CLI with other models.
|
||||
|
||||
Short Term
|
||||
----------
|
||||
|
||||
- Integrate Clixon and some well-chosen IETF/IEEE YANG models
|
||||
(ietf-system, ietf-interfaces/ip)
|
||||
- Get the (from YANG) automatically generated CLI working similar to
|
||||
Cisco, HP ProCurve, and other well-known command line interfaces,
|
||||
with a focus on usability
|
||||
- First baseline release, from Buildroot 2023.02 (LTS) -> v23.6.0
|
||||
|
||||
|
||||
Medium Term
|
||||
-----------
|
||||
|
||||
- First Web interface built on top of RESTCONF API
|
||||
- Static routing, firewalling, and other advanced YANG models
|
||||
- OSPF YANG model integrated with Frr as backend
|
||||
- Second release -> v23.10.0
|
||||
|
||||
|
||||
Long Term
|
||||
---------
|
||||
|
||||
- Not determined.
|
||||
- Third release -> v24.6.0
|
||||
|
||||
-296
@@ -1,296 +0,0 @@
|
||||
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
|
||||
<!-- Created with Inkscape (http://www.inkscape.org/) -->
|
||||
|
||||
<svg
|
||||
width="210mm"
|
||||
height="297mm"
|
||||
viewBox="0 0 210 297"
|
||||
version="1.1"
|
||||
id="svg5"
|
||||
inkscape:version="1.1.2 (0a00cf5339, 2022-02-04)"
|
||||
sodipodi:docname="infix1.svg"
|
||||
xmlns:inkscape="http://www.inkscape.org/namespaces/inkscape"
|
||||
xmlns:sodipodi="http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd"
|
||||
xmlns="http://www.w3.org/2000/svg"
|
||||
xmlns:svg="http://www.w3.org/2000/svg">
|
||||
<sodipodi:namedview
|
||||
id="namedview7"
|
||||
pagecolor="#ffffff"
|
||||
bordercolor="#666666"
|
||||
borderopacity="1.0"
|
||||
inkscape:pageshadow="2"
|
||||
inkscape:pageopacity="0.0"
|
||||
inkscape:pagecheckerboard="0"
|
||||
inkscape:document-units="mm"
|
||||
showgrid="false"
|
||||
inkscape:snap-others="false"
|
||||
inkscape:zoom="3.2002729"
|
||||
inkscape:cx="356.21962"
|
||||
inkscape:cy="317.00422"
|
||||
inkscape:window-width="2560"
|
||||
inkscape:window-height="1385"
|
||||
inkscape:window-x="1920"
|
||||
inkscape:window-y="0"
|
||||
inkscape:window-maximized="1"
|
||||
inkscape:current-layer="layer1" />
|
||||
<defs
|
||||
id="defs2">
|
||||
<rect
|
||||
x="321.21882"
|
||||
y="290.93293"
|
||||
width="205.09601"
|
||||
height="116.56996"
|
||||
id="rect20097" />
|
||||
<rect
|
||||
x="111.96593"
|
||||
y="295.01131"
|
||||
width="309.69414"
|
||||
height="156.1909"
|
||||
id="rect3135" />
|
||||
</defs>
|
||||
<g
|
||||
inkscape:label="Layer 1"
|
||||
inkscape:groupmode="layer"
|
||||
id="layer1">
|
||||
<text
|
||||
xml:space="preserve"
|
||||
transform="matrix(0.26458333,0,0,0.26458333,57.060209,-16.445051)"
|
||||
id="text3133"
|
||||
style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:120px;line-height:1.25;font-family:'URW Bookman';-inkscape-font-specification:'URW Bookman, Normal';font-variant-ligatures:discretionary-ligatures historical-ligatures;font-variant-caps:normal;font-variant-numeric:normal;font-variant-east-asian:normal;white-space:pre;shape-inside:url(#rect3135);fill:#000000;fill-opacity:1;stroke:none"
|
||||
inkscape:export-filename="/home/jocke/text3133.png"
|
||||
inkscape:export-xdpi="96"
|
||||
inkscape:export-ydpi="96"><tspan
|
||||
x="111.9668"
|
||||
y="396.05172"
|
||||
id="tspan64">Infix</tspan></text>
|
||||
<text
|
||||
xml:space="preserve"
|
||||
transform="scale(0.26458333)"
|
||||
id="text20095"
|
||||
style="fill:black;fill-opacity:1;line-height:1.25;stroke:none;font-family:sans-serif;font-style:normal;font-weight:normal;font-size:40px;white-space:pre;shape-inside:url(#rect20097)" />
|
||||
<path
|
||||
style="fill:#00ff00;stroke-width:0.394877"
|
||||
d=""
|
||||
id="path22971"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#ffff00;stroke-width:0.0546293"
|
||||
d=""
|
||||
id="path23388"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
id="path4"
|
||||
inkscape:connector-curvature="0"
|
||||
d="m 83.526238,68.793075 -5.55894,5.422039 2.04676,1.992008 0.50866,-0.506842 -0.50866,-0.83688 2.90663,-2.82889 -0.69032,-0.671861 1.97409,-1.909501 z m -17.197591,0.471481 c -0.363329,0 -0.726658,0.353611 -0.726658,0.707223 v 7.307966 c 0,0.35361 0.363329,0.707221 0.726658,0.707221 h 6.842702 l 0.666105,-0.942965 v -2.357405 h -0.484439 v 2.357405 h -0.484437 v -2.357405 h -0.484443 v 2.357405 h -0.484437 v -2.357405 h -0.484437 v 2.357405 h -0.484443 v -2.357405 h -0.484437 v 2.357405 h -0.484439 v -2.357405 h -0.484441 v 2.357405 h -0.484439 v -2.357405 h -0.484437 v 2.357405 h -1.69554 l -0.242221,-0.235737 v -1.650187 l 0.242221,-0.117864 v -1.296576 l -0.242221,-0.117865 v -1.296574 l 0.242221,-0.235741 h 1.816648 l 0.06056,-0.942964 h 0.908327 l 0.121104,-0.942963 h 2.906636 l 0.121104,0.942963 h 0.908325 l 0.06056,0.942964 h 1.816649 l 0.24222,0.235741 v 1.296574 l -0.24222,0.117865 v 0.82509 l 0.36333,-0.530413 0.84777,-0.648287 v -3.418243 c 0,-0.353612 -0.36334,-0.707223 -0.72666,-0.707223 z m 18.214921,0.518631 -1.71976,1.661972 0.3391,0.330036 1.70765,-1.673759 z m 0.69032,0.67186 -1.71976,1.661973 0.33911,0.330038 1.70765,-1.673761 z m 0.69033,0.671861 -1.71976,1.661973 0.33911,0.330038 1.70764,-1.67376 z m 0.67821,0.660075 -1.71976,1.661973 0.33911,0.330037 1.70765,-1.67376 z m -3.34263,0.577564 -2.6523,2.581362 0.52077,0.836879 -2.39798,2.333835 1.02944,1.001899 2.39797,-2.333834 0.85988,0.495057 2.65231,-2.581365 z m 4.03296,0.08251 -1.71976,1.661973 0.33911,0.330037 1.70765,-1.67376 z m 0.69033,0.671861 -1.71977,1.673759 0.33911,0.330037 1.70765,-1.673758 z m 0.69032,0.671862 -1.97409,1.921287 -0.70244,-0.683647 -2.90663,2.840678 -0.85988,-0.506845 -0.52077,0.506845 2.05886,2.003793 5.57105,-5.422037 z m -11.48121,0.165019 -0.7751,0.589353 -1.91354,2.805313 2.16786,2.10988 -0.52077,0.495057 -2.07097,-2.003799 -0.545,0.80152 1.92565,1.874143 -0.50866,0.506838 -1.828762,-1.768057 -0.544991,0.801521 1.683423,1.6384 -0.520768,0.506843 -1.574432,-1.532319 -0.544992,0.80152 1.441207,1.402657 -0.520774,0.506846 -1.344317,-1.308361 -0.544996,0.801515 1.198989,1.166923 c -5.122947,5.5399 -12.062538,-2.157035 -6.975926,-7.814813 v -1.768058 c -9.446566,7.89732 1.574427,18.764965 8.707797,11.221266 l 1.198982,1.166912 0.82355,-0.530416 -1.33221,-1.308357 0.50866,-0.495065 1.44121,1.402668 0.82355,-0.530416 -1.58654,-1.532329 0.52077,-0.506835 1.68343,1.638396 0.82354,-0.530415 -1.82876,-1.768053 0.52078,-0.506843 1.92565,1.874141 0.82354,-0.530416 -2.07098,-2.015584 0.52078,-0.506843 2.16786,2.10988 2.88241,-1.862355 0.59344,-0.754368 -2.56753,-2.498854 -1.97408,1.921287 -1.71977,-1.673758 1.97409,-1.921289 z"
|
||||
style="stroke-width:0.119479"
|
||||
inkscape:export-filename="/home/jocke/text3133.png"
|
||||
inkscape:export-xdpi="96"
|
||||
inkscape:export-ydpi="96" />
|
||||
</g>
|
||||
<style
|
||||
id="stylish-2"
|
||||
class="stylish"
|
||||
type="text/css">html {background:
|
||||
|
||||
/***** COPY AND PASTE THE URL OF YOUR BACKROUND-IMAGE INSIDE THE url("") *****/
|
||||
|
||||
|
||||
url("data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAANAAAAC4AgMAAADvbYrQAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAAFiUAABYlAUlSJPAAAAAJUExURQwMDA8PDxISEkrSJjgAAAVcSURBVGjevZqxjtwwDETZTOOvm2Yafp0aNvzKFJRsade3ycqHLA4IcMo70LRIDsk1iDZ/0P8VbTmAZGZmpGiejaBECpLcIUH0DAUpSpIgHZkuSfTchaIJBtk4ggTJnVL94DzJkJjZNqFsECUDjwhEQpKUyXAKExSHh0T3bYgASSNn8zLpomSSSYg4Mo58BEEETaz3N35OL3SoW0iREvcgAyHzGKfoEN4g1t+qS7UBlR2ZLfO8L5J0WQh3KOABybNJfADpDfIol88vF1I6n0Ev5kFyUWodCoSOCIgfnumfoVigk1CkQpCQAVG+D/VMAuuJQ+hXij2RaCQW1lWY0s93UGaTCCFTw7bziSvyM4/MI/pJZtuHnKIy5TmCkJ4tev7qUKZSDyFXQXGFOz1beFsh11OonvjNEeGUFJN5T6GIHh1azAu9OUKSLJN70P/7jHCvotbrTEZGG0EjTSfBDG5CQfX7uUC5QBF1IlFqm1A/4kdIOi6IDyHwA5SCApKcnk+hH82bat2/P9MN1PNUr1W3lwb3d+lbqF5XRpv0wFSomTlElmz8bh9yZt5Btl7Y34MwILvM0xIaTyF3ZsYE9VMOKMav7SFUFpakQRU1dp0lm65Rr3UPIPZ7UVUSpJmB9KBkhhkyjHDfgkb+nX1bmV5OCSGkwytP0/MhFD9BdkofjSL0DJqTb6n7zObeTzKh0CkJnkIvN7OXcMnjyDghD+5BZzM3pRDIxot8EVlrevkSIj3rysyOGIKKZx+UgQzQMtsehK56V+jUJAMaqoB8Avk7pBfIT/1h+xCZGXFnni/mRRyZvWXdg8SIiLgxz18cgQ5xD/r02dJo/KjCuJhXwb80/BRcJnpOQfg95KoCIAlmBkNQQZ3TBZsLwCPILwiCiKDEOC0kxEMBUfkIGiLxgkSVhWsnjnqSZ1DwhGCz+DhdngGZXNvQmZdWMfWa4+z+9BtoxPWiMoyekUlJqM44IchDEsWH0JIvK9m0KQhNkI+JyTNo1WhvEKQa1QFPIV+KWmZTNeiAdLhMPGv1HnQ3v5pEIs1MgsvMkMQ8bPoSMpYf+wCNFdo8U1WJLBEyOI0l/HcgjysGShCOsVZ3x3BOjR9JxS50PfTxDvncXx69NW/PIa0QLS7oiKjhrYt7kGJuEeahIGVrVa3hrWITmkdY0muykRnMNEauxJx5voS0DGpXkXglyzFFOXLuNb6GYploQjqiqd8hdt2W1YbXvGYb0hvkbbR8FxS1NXgOaZlxN+/maTLvFyB/FfMepyPMjvTRoOgJ9P8+ZcQ6vAL52rfUVKYGXnwC+Yg2Xzr7VaX6M8i7eeM0XsYlb3o4apX0PdQd4Yt55QjYEptEXzBsQq/mVXWjRKDyG/oAjbUM8V3oB9let5K80Vo/a/3PkNCVR6ZCRyRAXAuSNirCWWoy2x4EnP9hzop+C+Uj6FolHcpaLqIL/FcoUmdzvAPZnXnVHwzIZkf4NkTJlF0kesylpoIwZOybQMPliG+hGmuZGfEyP3WRNdbCuVDqV+tnqGr8PXTtlY1LARgrxt4ZD+kj8SPEv0MobQvxGKp3qJ9zR/IImiWBrRrtzjz7K4QfoPHEBhquXOUTFJd5lXL2IIyXu07UMaA+5MKSez5AnCZjb9Cc6X3xLUdO5jDcGTVj+R4aY+e5u5Iou/5WrWYjIGW0zLYHnYlFOnSpjLmoRcxF7QFkA5rME+dlfUA6ukhs7tvQ7Ai/M29Z/dDFPeg/byRXOxykJM96xZimqhJ5r5Z3oP61AHo2aCSbCeLvQTFB8xd6xmL4t6BjQF1i/zp0tg31PY0OmY1taUFYHfEV9K/7x/nzB/aTFFDPHGpXAAAAAElFTkSuQmCC")
|
||||
|
||||
/***** FOR A SIMPLE BLACK BACKGROUND JUST REMOVE THE URL LINE ABOVE *****/
|
||||
/***** Some background-images (you can also use your own url):
|
||||
|
||||
default: https://abload.de/img/bg_digital94uzx.png
|
||||
old default1: https://abload.de/img/b1fgs11.png
|
||||
old default2: https://abload.de/img/ultra_x2vm9k.jpg
|
||||
https://abload.de/img/b2w4shd.png
|
||||
https://abload.de/img/b3qrs99.png
|
||||
https://abload.de/img/b4zcse8.png
|
||||
https://abload.de/img/b5b1s7x.png
|
||||
https://abload.de/img/b6umsmy.png
|
||||
https://abload.de/img/b7ars8c.png
|
||||
https://abload.de/img/kubrickbgcolor2darkr8skc.png
|
||||
https://abload.de/img/xpattern_darkq8s3i.png
|
||||
https://abload.de/img/mainpatternolxcq.png
|
||||
|
||||
*/ #1A1A1A /* fixed */ !important}
|
||||
|
||||
|
||||
/*----- DEFAULT TEXT, BORDER & BACKGROUND COLORS -----*/
|
||||
* {
|
||||
color: #999 !important;
|
||||
text-shadow: 0 0 3px #000 !important;
|
||||
box-shadow: none !important;
|
||||
background-color: transparent !important;
|
||||
border-color: #444 !important;
|
||||
border-top-color: #444 !important;
|
||||
border-bottom-color: #444 !important;
|
||||
border-left-color: #444 !important;
|
||||
border-right-color: #444 !important}
|
||||
body {background: transparent !important}
|
||||
*:before, *:after {background-color: transparent !important; border-color: #444 !important}
|
||||
|
||||
a, a * {
|
||||
color: #409B9B !important;
|
||||
text-decoration: none !important}
|
||||
a:hover, a:hover *, a:visited:hover, a:visited:hover *, span[onclick]:hover, div[onclick]:hover, [role="link"]:hover, [role="link"]:hover *, [role="button"]:hover *, [role="menuitem"]:hover, [role="menuitem"]:hover *, .link:hover, .link:hover * {
|
||||
color: #F0F0F0 !important;
|
||||
text-shadow: 0 0 5px rgba(255,255,200,0.9) !important}
|
||||
a:visited, a:visited * {
|
||||
color: #607069 !important}
|
||||
a.highlight, a.highlight *, a.active, a.active *, .selected, .selected *, [href="#"] {
|
||||
color: #DDD !important;
|
||||
font-weight: bold !important}
|
||||
|
||||
h1, h2, h3, h4, h5, h6, h1 *, h2 *, h3 *, strong, [id*="headline"], [class*="headline"], [id*="header"], [class*="header"], [class*="header"] td {
|
||||
color: #DDD !important}
|
||||
a h1, a h2, a h3, a h4, a h5, a h6, h1 a, h2 a, h3 a, a strong, a[id*="headline"], a[class*="headline"], a[id*="header"], a[class*="header"] {
|
||||
text-decoration: underline !important}
|
||||
[class*="error"], [class*="alert"], code, span[onclick], div[onclick] {
|
||||
color: #900 !important}
|
||||
|
||||
::-moz-selection {background: #377 !important; color: #000 !important}
|
||||
::selection {background: #377 !important; color: #000 !important}
|
||||
:focus {outline: none !important}
|
||||
|
||||
|
||||
/*----- MENU & CO BACKGROUND-COLORS -----*/
|
||||
div[style="display: block;"], div[role="navigation"] {background: rgba(0,0,0,.5) !important}
|
||||
|
||||
table {
|
||||
background: rgba(40,30,30,.6) !important;
|
||||
border-radius: 6px !important}
|
||||
table > tbody > tr:nth-child(even), table > tbody > tr > td:nth-child(even) {
|
||||
background-color: rgba(0,0,0,.2) !important}
|
||||
|
||||
iframe, embed, nav, label [onclick], nav ul, div[style*="position:"][style*="left:"][style*="visible"], div[style*="z-index:"][style*="left:"][style*="visible"], div[style*="-moz-user-select"], div[role="menu"], div[role="dialog"], span[class*="script"] div, [id*="menu"], [id*="Menu"], [class*="dropdown"], [class*="popup"], [class="title"], ul[style*="display:"], ul[style*="visibility:"] ul, [id*="nav"] ul, [class*="nav"] ul, ul[class*="menu"], a[onclick][style*="display"], a[id*="ghosteryfirefox"], #ghostery-purple-bubble, #translator-popup, .menu, .tooltip, .hovercard, .vbmenu_popup {
|
||||
background: rgba(5,5,5,.9) !important;
|
||||
border-radius: 5px;
|
||||
box-shadow: 1px 1px 5px #000 !important}
|
||||
header, #header, footer, #footer {
|
||||
background: rgba(19,19,19,.9) !important;
|
||||
box-shadow: 0 0 5px #000 !important}
|
||||
body > #dialog, body > .xenOverlay {
|
||||
background: rgba(19,19,19,.96) !important;
|
||||
background-clip: padding-box !important;
|
||||
box-shadow: 0 0 15px #000, inset 0 0 0 1px rgba(200,200,200,.5), inset 0 0 5px #111 !important;
|
||||
border: 10px solid rgba(99,99,99,.7) !important;
|
||||
border-radius: 0 !important;}
|
||||
[id*="overlay"], [id*="lightbox"], blockquote {
|
||||
background-color: rgba(35,35,35,.9) !important;
|
||||
border-radius: 5px}
|
||||
pre, dl, .Message code {
|
||||
background-color: rgba(5,5,5,.5) !important}
|
||||
|
||||
|
||||
/*----- DEFAULT BUTTONS, SEARCHBOXES & CO -----*/
|
||||
input, select, button, [role="button"], a.button, a.submit, a.BigButton, a.TabLink, .install[onclick] {
|
||||
-moz-appearance: none !important;
|
||||
-webkit-appearance: none !important;
|
||||
transition: border-color 0.3s !important;
|
||||
background: #060606 !important;
|
||||
color: #BBB !important;
|
||||
text-shadow: 0 1px #000 !important;
|
||||
border: 2px solid #333 !important;
|
||||
border-radius: 4px !important;
|
||||
box-shadow: 0 0 2px rgba(0,0,0,.9) !important}
|
||||
a[href="javascript:;"], a[class*="button"]:not(:empty), a[id*="button"]:not(:empty), a[id*="Button"]:not(:empty), div[class*="button"][onclick] {
|
||||
transition: border-color 0.3s !important;
|
||||
background: #060606 !important;
|
||||
color: #BBB !important;
|
||||
text-shadow: 0 1px #000 !important;
|
||||
border-color: #333 !important;
|
||||
box-shadow: 0 0 2px rgba(0,0,0,.9) !important}
|
||||
a[href="javascript:;"]:hover, a[class*="button"]:not(:empty):hover, a[id*="button"]:hover, a[id*="Button"]:not(:empty):hover, div[class*="button"][onclick]:hover {
|
||||
background: #151515 !important;
|
||||
color: #FFF !important}
|
||||
input *, select *, button *, a.button *, a.submit * {
|
||||
color: #BBB !important;
|
||||
text-shadow: none !important}
|
||||
input:hover, input[type="button"]:hover, select:hover, button:hover, [role="button"]:hover, a.button:hover, a.submit:hover, a.BigButton:hover, a.TabLink:hover {
|
||||
border: 2px solid #555 !important;
|
||||
border-top-color: #555 !important;
|
||||
border-bottom-color: #555 !important;
|
||||
border-left-color: #555 !important;
|
||||
border-right-color: #555 !important}
|
||||
input:focus, select:focus {
|
||||
box-shadow: 0 0 5px #077 !important}
|
||||
input *:hover * {
|
||||
color: #F0F0F0 !important;
|
||||
text-shadow: 0 0 2px #FFF !important}
|
||||
input[disabled], select[disabled], button[disabled], input[disabled]:hover, select[disabled]:hover, button[disabled]:hover, input[disabled]:focus, select[disabled]:focus, button[disabled]:focus {
|
||||
opacity: 0.5 !important;
|
||||
border-color: #333 !important}
|
||||
|
||||
/*
|
||||
input[type="checkbox"], input[type="radio"] {
|
||||
box-shadow: 0 0 0 2px #444, 0 0 2px 2px #000 !important;
|
||||
opacity: 0.7;
|
||||
transition: box-shadow 0.2s, opacity 0.2s !important}
|
||||
input[type="checkbox"]:not([disabled]):hover, input[type="radio"]:not([disabled]):hover {
|
||||
opacity: 0.9}
|
||||
input[type="checkbox"]:not([disabled]):active, input[type="radio"]:not([disabled]):active {
|
||||
box-shadow: 0 0 0 2px #999, 0 0 2px 2px #000 !important}
|
||||
input[type="checkbox"]:checked, input[type="radio"]:checked {
|
||||
box-shadow: 0 0 0 2px #077, 0 0 2px 2px #000 !important}
|
||||
input[type="checkbox"][disabled], input[type="radio"][disabled] {
|
||||
opacity: 0.35}
|
||||
*/
|
||||
input[type="checkbox"] {border-radius: 1px !important}
|
||||
input[type="radio"], input[type="radio"]:focus {border-radius: 100% !important}
|
||||
input[type="checkbox"], input[type="radio"] {min-width: 12px; min-height: 12px}
|
||||
input[type="checkbox"]:checked, input[type="radio"]:checked {
|
||||
border-color: #077 !important;
|
||||
box-shadow: 0 0 5px #077 !important}
|
||||
|
||||
select {
|
||||
padding-right: 15px !important;
|
||||
background: url(data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAcAAAAECAYAAABCxiV9AAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsMAAA7DAcdvqGQAAAAeSURBVBhXY5g5c+Z/BiwALo6uAEMDTACXSWgSDAwA4jATh950E30AAAAASUVORK5CYII=) no-repeat right 4px center #060606 !important;
|
||||
transition: border-color 0.3s, background-position 0.3s !important}
|
||||
|
||||
|
||||
button:active, input[type="submit"]:active, input[type="button"]:active, a.button:active, a[class*="button"]:not(:empty):active, a.submit:active, a.BigButton:active, a.TabLink:active, .Active .TabLink {
|
||||
background: #292929 !important;
|
||||
color: #FFF !important}
|
||||
|
||||
textarea {
|
||||
-moz-appearance: none !important;
|
||||
-webkit-appearance: none !important;
|
||||
background: rgba(0,0,0,.3) !important;
|
||||
border-radius: 3px !important;
|
||||
border: 1px solid #000 !important;
|
||||
box-shadow: inset 0 0 8px #000 !important;
|
||||
transition: border-color, background, 0.3s !important}
|
||||
textarea, textarea * {
|
||||
color: #C8C8C8 !important;
|
||||
text-shadow: 0 0 1px gray !important}
|
||||
textarea:hover, textarea:focus:hover {
|
||||
border-color: #333 !important}
|
||||
textarea:focus {
|
||||
background: rgba(0,0,0,.5) !important;
|
||||
border-color: #222 !important}
|
||||
textarea:focus, textarea:focus > * {
|
||||
text-shadow: none !important;
|
||||
box-shadow: none !important}
|
||||
|
||||
option, optgroup {
|
||||
-moz-appearance: none !important;
|
||||
-webkit-appearance: none !important;
|
||||
background: none !important;
|
||||
color: #666 !important}
|
||||
optgroup {
|
||||
background: #222 !important;
|
||||
color: #DDD !important}
|
||||
option:not([disabled]):hover, option:focus, option:checked {
|
||||
background: linear-gradient(#333, #292929) !important;
|
||||
color: #DDD !important}
|
||||
|
||||
|
||||
/*----- IMAGE CHANGES -----*/
|
||||
body, *:not(:empty):not(html):not(span):not(a):not(b):not(option):not(select):not(img):not([style="display: block;"]):not([onclick*="open"]):not([onclick*="s_objectID"]):not([class*="stars"]):not([id*="stars"]):not([id="rating"]):not([class="rating"]):not([class*="SPRITE"]):not([id*="SPRITE"]):not([class*="item"]):not([id*="item"]):not([class*="thumb"]):not([class*="icon"]):not([class*="photo"]):not(.view):not(.text):not([id*="lbImage"]):not([class*="cc-in"]):not([class*="gr-body"]):not([id*="watch"]):not(#globalsearch),
|
||||
.r3_hm, .gmbutton2 b, .gtab-i, .ph, .bstab-iLft, .csb, #pagination div, [style*="sprite2.png"], #mw-head-base, #mw-page-base {
|
||||
background-image: none !important}
|
||||
|
||||
img {opacity: .7 !important; transition: opacity .2s}
|
||||
img:hover, a:hover img, #mpiv-popup {opacity: 1 !important}</style>
|
||||
</svg>
|
||||
|
Before Width: | Height: | Size: 18 KiB |
-359
File diff suppressed because one or more lines are too long
|
Before Width: | Height: | Size: 38 KiB |
@@ -0,0 +1,32 @@
|
||||
Origin & Licensing
|
||||
------------------
|
||||
|
||||
Infix is entirely built on Open Source components (packages). Most of
|
||||
them, as well as the build system with its helper scripts and tools, is
|
||||
from [Buildroot][1], which is distributed under the terms of the GNU
|
||||
General Public License (GPL). See the file COPYING for details.
|
||||
|
||||
Some files in Buildroot contain a different license statement. Those
|
||||
files are licensed under the license contained in the file itself.
|
||||
|
||||
Buildroot and Infix also bundle patch files, which are applied to the
|
||||
sources of the various packages. Those patches are not covered by the
|
||||
license of Buildroot or Infix. Instead, they are covered by the license
|
||||
of the software to which the patches are applied. When said software is
|
||||
available under multiple licenses, the patches are only provided under
|
||||
the publicly accessible licenses.
|
||||
|
||||
Infix releases include the license information covering all Open Source
|
||||
packages. This is extracted automatically at build time using the tool
|
||||
`make legal-info`. Any proprietary software built on top of Infix, or
|
||||
Buildroot, would need separate auditing to ensure it does not link with
|
||||
any GPL[^2] licensed library.
|
||||
|
||||
[^2]: Infix image builds use GNU libc (GLIBC) which is covered by the
|
||||
[LGPL][8]. The LGPL *does allow* proprietary software, as long as
|
||||
said software is linking dynamically, [not statically][5], to GLIBC.
|
||||
|
||||
[1]: https://buildroot.org/
|
||||
[2]: https://www.sysrepo.org/
|
||||
[5]: https://lwn.net/Articles/117972/
|
||||
[8]: https://en.wikipedia.org/wiki/GNU_Lesser_General_Public_License
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 16 KiB |
+181
@@ -0,0 +1,181 @@
|
||||
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
|
||||
<!-- Created with Inkscape (http://www.inkscape.org/) -->
|
||||
|
||||
<svg
|
||||
width="210mm"
|
||||
height="297mm"
|
||||
viewBox="0 0 210 297"
|
||||
version="1.1"
|
||||
id="svg5"
|
||||
inkscape:version="1.2.2 (732a01da63, 2022-12-09, custom)"
|
||||
sodipodi:docname="infix.svg"
|
||||
xmlns:inkscape="http://www.inkscape.org/namespaces/inkscape"
|
||||
xmlns:sodipodi="http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd"
|
||||
xmlns="http://www.w3.org/2000/svg"
|
||||
xmlns:svg="http://www.w3.org/2000/svg">
|
||||
<sodipodi:namedview
|
||||
id="namedview7"
|
||||
pagecolor="#ffffff"
|
||||
bordercolor="#000000"
|
||||
borderopacity="0.25"
|
||||
inkscape:showpageshadow="2"
|
||||
inkscape:pageopacity="0.0"
|
||||
inkscape:pagecheckerboard="0"
|
||||
inkscape:deskcolor="#d1d1d1"
|
||||
inkscape:document-units="mm"
|
||||
showgrid="false"
|
||||
inkscape:zoom="2.3786088"
|
||||
inkscape:cx="439.12223"
|
||||
inkscape:cy="426.29961"
|
||||
inkscape:window-width="2556"
|
||||
inkscape:window-height="1417"
|
||||
inkscape:window-x="1280"
|
||||
inkscape:window-y="19"
|
||||
inkscape:window-maximized="1"
|
||||
inkscape:current-layer="layer5" />
|
||||
<defs
|
||||
id="defs2">
|
||||
<rect
|
||||
x="505.95288"
|
||||
y="579.6032"
|
||||
width="127.6438"
|
||||
height="127.94966"
|
||||
id="rect1266" />
|
||||
<rect
|
||||
x="309.92126"
|
||||
y="404.51989"
|
||||
width="483.77954"
|
||||
height="358.02926"
|
||||
id="rect600" />
|
||||
<inkscape:path-effect
|
||||
effect="bspline"
|
||||
id="path-effect5591"
|
||||
is_visible="true"
|
||||
lpeversion="1"
|
||||
weight="33.333333"
|
||||
steps="2"
|
||||
helper_size="0"
|
||||
apply_no_weight="true"
|
||||
apply_with_weight="true"
|
||||
only_selected="false" />
|
||||
</defs>
|
||||
<g
|
||||
inkscape:groupmode="layer"
|
||||
id="layer6"
|
||||
inkscape:label="bg"
|
||||
style="display:none;fill:#ff0000;fill-opacity:1"
|
||||
transform="matrix(1.2831201,0,0,3.2117929,-26.690111,-224.39813)">
|
||||
<rect
|
||||
style="fill:#22272e;fill-opacity:1;stroke:#000000;stroke-width:0;stroke-miterlimit:0;stroke-dasharray:none;stroke-opacity:1"
|
||||
id="rect10264"
|
||||
width="163.66356"
|
||||
height="92.471725"
|
||||
x="20.800945"
|
||||
y="69.866936"
|
||||
inkscape:label="bg" />
|
||||
</g>
|
||||
<g
|
||||
inkscape:groupmode="layer"
|
||||
id="layer5"
|
||||
inkscape:label="tagline"
|
||||
style="display:inline">
|
||||
<text
|
||||
xml:space="preserve"
|
||||
style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:6.77333px;font-family:Laksaman;-inkscape-font-specification:'Laksaman, Normal';font-variant-ligatures:normal;font-variant-caps:normal;font-variant-numeric:normal;font-variant-east-asian:normal;fill:#000000;fill-opacity:1;stroke:#000000;stroke-width:0;stroke-miterlimit:0;stroke-dasharray:none;stroke-opacity:1"
|
||||
x="85.018883"
|
||||
y="131.54915"
|
||||
id="text9503"
|
||||
inkscape:label="linux-netconf"
|
||||
inkscape:export-filename="../b725e1c8/infix.png"
|
||||
inkscape:export-xdpi="191.95932"
|
||||
inkscape:export-ydpi="191.95932"><tspan
|
||||
sodipodi:role="line"
|
||||
id="tspan9519"
|
||||
x="85.018883"
|
||||
y="131.54915"><tspan
|
||||
style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:6.77333px;font-family:Laksaman;-inkscape-font-specification:'Laksaman, Normal';font-variant-ligatures:normal;font-variant-caps:normal;font-variant-numeric:normal;font-variant-east-asian:normal;fill:#808080"
|
||||
id="tspan11822">Linux</tspan> <tspan
|
||||
style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:6.77333px;font-family:Laksaman;-inkscape-font-specification:'Laksaman, Normal';font-variant-ligatures:normal;font-variant-caps:normal;font-variant-numeric:normal;font-variant-east-asian:normal;fill:#ff7f2a;fill-opacity:1"
|
||||
id="tspan9929">♥</tspan> <tspan
|
||||
style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:6.77333px;font-family:Laksaman;-inkscape-font-specification:'Laksaman, Normal';font-variant-ligatures:normal;font-variant-caps:normal;font-variant-numeric:normal;font-variant-east-asian:normal;fill:#808080"
|
||||
id="tspan11824">NETCONF</tspan></tspan></text>
|
||||
</g>
|
||||
<g
|
||||
inkscape:groupmode="layer"
|
||||
id="layer3"
|
||||
inkscape:label="heading">
|
||||
<text
|
||||
xml:space="preserve"
|
||||
style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:25.4px;font-family:'URW Bookman';-inkscape-font-specification:'URW Bookman, Normal';font-variant-ligatures:normal;font-variant-caps:normal;font-variant-numeric:normal;font-variant-east-asian:normal;fill:#808080;stroke-width:1.029;fill-opacity:1"
|
||||
x="84.745331"
|
||||
y="124.1693"
|
||||
id="text1160"
|
||||
inkscape:label="infix"><tspan
|
||||
sodipodi:role="line"
|
||||
id="tspan1272"
|
||||
x="84.745331"
|
||||
y="124.1693">Infix</tspan></text>
|
||||
</g>
|
||||
<g
|
||||
inkscape:label="tux"
|
||||
inkscape:groupmode="layer"
|
||||
id="layer1"
|
||||
style="display:inline">
|
||||
<rect
|
||||
style="fill:#f9f9f9;stroke:#808080;stroke-width:1.029;stroke-linejoin:round;stroke-dasharray:none;stroke-opacity:1;fill-opacity:1"
|
||||
id="rect1698"
|
||||
width="22.470779"
|
||||
height="16.970779"
|
||||
x="59.529221"
|
||||
y="107.02922"
|
||||
inkscape:label="body" />
|
||||
<rect
|
||||
style="fill:#ff7f2a;stroke:#808080;stroke-width:1;stroke-linejoin:round;stroke-dasharray:none;stroke-opacity:1"
|
||||
id="rect184-3"
|
||||
width="6"
|
||||
height="4"
|
||||
x="76"
|
||||
y="120"
|
||||
inkscape:label="foot-r" />
|
||||
<rect
|
||||
style="fill:#ff7f2a;stroke:#808080;stroke-width:1;stroke-linejoin:round;stroke-dasharray:none;stroke-opacity:1"
|
||||
id="rect184"
|
||||
width="6"
|
||||
height="4"
|
||||
x="59.529221"
|
||||
y="120"
|
||||
inkscape:label="foot-l" />
|
||||
<path
|
||||
sodipodi:type="star"
|
||||
style="fill:#ff7f2a;stroke:none;stroke-width:1;stroke-dasharray:none;stroke-opacity:1"
|
||||
id="path11801"
|
||||
inkscape:flatsided="true"
|
||||
sodipodi:sides="3"
|
||||
sodipodi:cx="42.414055"
|
||||
sodipodi:cy="98.701302"
|
||||
sodipodi:r1="1.9660654"
|
||||
sodipodi:r2="0.9830327"
|
||||
sodipodi:arg1="1.5707963"
|
||||
sodipodi:arg2="2.6179939"
|
||||
inkscape:rounded="0"
|
||||
inkscape:randomized="0"
|
||||
d="m 42.414055,100.66737 -1.702663,-2.949101 3.405325,0 z"
|
||||
inkscape:transform-center-y="0.49151511"
|
||||
transform="translate(28.350554,16.321792)"
|
||||
inkscape:label="nose" />
|
||||
<circle
|
||||
style="display:inline;fill:#808080;stroke:none;stroke-width:4.99999;stroke-dasharray:none;stroke-opacity:1;fill-opacity:1"
|
||||
id="path6519-5"
|
||||
cx="73.211082"
|
||||
cy="111.02191"
|
||||
r="0.5"
|
||||
inkscape:label="eye-r" />
|
||||
<circle
|
||||
style="fill:#808080;stroke:none;stroke-width:4.99999;stroke-dasharray:none;stroke-opacity:1;fill-opacity:1"
|
||||
id="path6519"
|
||||
cx="68.31813"
|
||||
cy="111.02191"
|
||||
r="0.5"
|
||||
inkscape:label="eye-l" />
|
||||
</g>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 6.8 KiB |
+85
-79
@@ -11,8 +11,8 @@ traffic at various points.
|
||||
TL;DR
|
||||
-----
|
||||
|
||||
make x86_64_defconfig
|
||||
make
|
||||
make x86_64_defconfig
|
||||
make
|
||||
make test-qeneth
|
||||
|
||||
Runs the test suite on a set of virtual Infix nodes.
|
||||
@@ -142,32 +142,34 @@ words, the test requires a _logical_ topology like the one below.
|
||||
|
||||
<img align="right" src="testing-log.dot.svg" alt="Example Logical Topology">
|
||||
|
||||
graph "dhcp-client-server" {
|
||||
host [
|
||||
label="host | { <c1> c1 | <srv> srv | <c2> c2 }",
|
||||
kind="controller",
|
||||
];
|
||||
```dot
|
||||
graph "dhcp-client-server" {
|
||||
host [
|
||||
label="host | { <c1> c1 | <srv> srv | <c2> c2 }",
|
||||
kind="controller",
|
||||
];
|
||||
|
||||
server [
|
||||
label="{ <mgmt> mgmt } | server | { <c1> c1 | <c2> c2 }",
|
||||
kind="infix",
|
||||
];
|
||||
client1 [
|
||||
label="{ <mgmt> mgmt } | client1 | { <srv> srv }",
|
||||
kind="infix",
|
||||
];
|
||||
client2 [
|
||||
label="{ <mgmt> mgmt } | client2 | { <srv> srv }",
|
||||
kind="infix",
|
||||
];
|
||||
server [
|
||||
label="{ <mgmt> mgmt } | server | { <c1> c1 | <c2> c2 }",
|
||||
kind="infix",
|
||||
];
|
||||
client1 [
|
||||
label="{ <mgmt> mgmt } | client1 | { <srv> srv }",
|
||||
kind="infix",
|
||||
];
|
||||
client2 [
|
||||
label="{ <mgmt> mgmt } | client2 | { <srv> srv }",
|
||||
kind="infix",
|
||||
];
|
||||
|
||||
host:srv -- server:mgmt
|
||||
host:c1 -- client1:mgmt
|
||||
host:c2 -- client2:mgmt
|
||||
host:srv -- server:mgmt
|
||||
host:c1 -- client1:mgmt
|
||||
host:c2 -- client2:mgmt
|
||||
|
||||
server:c1 -- client1:srv;
|
||||
server:c2 -- client2:srv;
|
||||
}
|
||||
server:c1 -- client1:srv;
|
||||
server:c2 -- client2:srv;
|
||||
}
|
||||
```
|
||||
|
||||
When running in a virtualized environment, one could simply create a
|
||||
setup that matches the test's logical topology. But in scenarios when
|
||||
@@ -187,72 +189,76 @@ _physical_ topology below.
|
||||
|
||||
<img align="right" src="testing-phy.dot.svg" alt="Example Physical Topology">
|
||||
|
||||
graph "quad-ring" {
|
||||
host [
|
||||
label="host | { <d1a> d1a | <d1b> d1b | <d1c> d1c | <d2a> d2a | <d2b> d2b | <d2c> d2c | <d3a> d3a | <d3b> d3b | <d3c> d3c | <d4a> d4a | <d4b> d4b | <d4c> d4c }",
|
||||
kind="controller",
|
||||
];
|
||||
```dot
|
||||
graph "quad-ring" {
|
||||
host [
|
||||
label="host | { <d1a> d1a | <d1b> d1b | <d1c> d1c | <d2a> d2a | <d2b> d2b | <d2c> d2c | <d3a> d3a | <d3b> d3b | <d3c> d3c | <d4a> d4a | <d4b> d4b | <d4c> d4c }",
|
||||
kind="controller",
|
||||
];
|
||||
|
||||
dut1 [
|
||||
label="{ <e1> e1 | <e2> e2 | <e3> e3 } | dut1 | { <e4> e4 | <e5> e5 }",
|
||||
kind="infix",
|
||||
];
|
||||
dut2 [
|
||||
label="{ <e1> e1 | <e2> e2 | <e3> e3 } | dut2 | { <e4> e4 | <e5> e5 }",
|
||||
kind="infix",
|
||||
];
|
||||
dut3 [
|
||||
label="{ <e1> e1 | <e2> e2 | <e3> e3 } | dut3 | { <e4> e4 | <e5> e5 }",
|
||||
kind="infix",
|
||||
];
|
||||
dut4 [
|
||||
label="{ <e1> e1 | <e2> e2 | <e3> e3 } | dut4 | { <e4> e4 | <e5> e5 }",
|
||||
kind="infix",
|
||||
];
|
||||
dut1 [
|
||||
label="{ <e1> e1 | <e2> e2 | <e3> e3 } | dut1 | { <e4> e4 | <e5> e5 }",
|
||||
kind="infix",
|
||||
];
|
||||
dut2 [
|
||||
label="{ <e1> e1 | <e2> e2 | <e3> e3 } | dut2 | { <e4> e4 | <e5> e5 }",
|
||||
kind="infix",
|
||||
];
|
||||
dut3 [
|
||||
label="{ <e1> e1 | <e2> e2 | <e3> e3 } | dut3 | { <e4> e4 | <e5> e5 }",
|
||||
kind="infix",
|
||||
];
|
||||
dut4 [
|
||||
label="{ <e1> e1 | <e2> e2 | <e3> e3 } | dut4 | { <e4> e4 | <e5> e5 }",
|
||||
kind="infix",
|
||||
];
|
||||
|
||||
host:d1a -- dut1:e1
|
||||
host:d1b -- dut1:e2
|
||||
host:d1c -- dut1:e3
|
||||
host:d1a -- dut1:e1
|
||||
host:d1b -- dut1:e2
|
||||
host:d1c -- dut1:e3
|
||||
|
||||
host:d2a -- dut2:e1
|
||||
host:d2b -- dut2:e2
|
||||
host:d2c -- dut2:e3
|
||||
host:d2a -- dut2:e1
|
||||
host:d2b -- dut2:e2
|
||||
host:d2c -- dut2:e3
|
||||
|
||||
host:d3a -- dut3:e1
|
||||
host:d3b -- dut3:e2
|
||||
host:d3c -- dut3:e3
|
||||
host:d3a -- dut3:e1
|
||||
host:d3b -- dut3:e2
|
||||
host:d3c -- dut3:e3
|
||||
|
||||
host:d4a -- dut4:e1
|
||||
host:d4b -- dut4:e2
|
||||
host:d4c -- dut4:e3
|
||||
host:d4a -- dut4:e1
|
||||
host:d4b -- dut4:e2
|
||||
host:d4c -- dut4:e3
|
||||
|
||||
dut1:e5 -- dut2:e4
|
||||
dut2:e5 -- dut3:e4
|
||||
dut3:e5 -- dut4:e4
|
||||
dut4:e5 -- dut1:e4
|
||||
}
|
||||
dut1:e5 -- dut2:e4
|
||||
dut2:e5 -- dut3:e4
|
||||
dut3:e5 -- dut4:e4
|
||||
dut4:e5 -- dut1:e4
|
||||
}
|
||||
```
|
||||
|
||||
Our test (in fact, all tests) receives the physical topology as an
|
||||
input parameter, and then maps the desired logical topology onto it,
|
||||
producing a mapping from logical nodes and ports to their physical
|
||||
counterparts.
|
||||
|
||||
{
|
||||
"client1": "dut1",
|
||||
"client1:mgmt": "dut1:e1",
|
||||
"client1:srv": "dut1:e4",
|
||||
"client2": "dut3",
|
||||
"client2:mgmt": "dut3:e2",
|
||||
"client2:srv": "dut3:e5",
|
||||
"host": "host",
|
||||
"host:c1": "host:d1a",
|
||||
"host:c2": "host:d3b",
|
||||
"host:srv": "host:d4c",
|
||||
"server": "dut4",
|
||||
"server:c1": "dut4:e5",
|
||||
"server:c2": "dut4:e4",
|
||||
"server:mgmt": "dut4:e3"
|
||||
}
|
||||
```dot
|
||||
{
|
||||
"client1": "dut1",
|
||||
"client1:mgmt": "dut1:e1",
|
||||
"client1:srv": "dut1:e4",
|
||||
"client2": "dut3",
|
||||
"client2:mgmt": "dut3:e2",
|
||||
"client2:srv": "dut3:e5",
|
||||
"host": "host",
|
||||
"host:c1": "host:d1a",
|
||||
"host:c2": "host:d3b",
|
||||
"host:srv": "host:d4c",
|
||||
"server": "dut4",
|
||||
"server:c1": "dut4:e5",
|
||||
"server:c2": "dut4:e4",
|
||||
"server:mgmt": "dut4:e3"
|
||||
}
|
||||
```
|
||||
|
||||
With this information, the test knows that, in this particular
|
||||
environment, the server should be managed via the port called `d4c` on
|
||||
|
||||
Binary file not shown.
|
Before Width: | Height: | Size: 7.1 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 15 KiB |
+135
@@ -0,0 +1,135 @@
|
||||
Infix Variants
|
||||
==============
|
||||
|
||||
Infix has two main *flavors*. Both have a default `admin` account,
|
||||
which is allowed to log in from remote, default password `admin` --
|
||||
*customer specific builds* may have something else, e.g., per-device
|
||||
generated factory password.
|
||||
|
||||
> See [Infix Discovery](discovery.md) to locate your device.
|
||||
|
||||
|
||||
NETCONF
|
||||
-------
|
||||
|
||||
Infix use by [sysrepo][1] and [Netopeer][2] to provide NETCONF support.
|
||||
A set of sysrepo plugins configure the network, using the Linux iproute2
|
||||
tool suite, generate configuration files in `/etc`, and control the all
|
||||
system daemons, e.g., enable DHCP client on an interface.
|
||||
|
||||
Configuration of an Infix device can be done remotely, using command
|
||||
line tools like [netconf-client][3] and [netopeer2-cli][2], or desktop
|
||||
GUI tools like [NETCONFc][4] and [MG-SOFT NetConf Browser][5]. It is
|
||||
also possible to log in to the device using SSH and set it up locally
|
||||
using the built-in [CLI](cli/introduction.md)[^1].
|
||||
|
||||
> **Note:** unlike Infix Classic, the `/etc` directory is a volatile RAM
|
||||
> disk populated on each boot from the `startup-config`, ensuring a
|
||||
> coherent centralized view of the system.
|
||||
|
||||
[^1]: A [RESTCONF][] based WebUI is also in progress.
|
||||
|
||||
|
||||
Classic
|
||||
-------
|
||||
|
||||
Infix Classic is very much like a traditional embedded Linux system. It
|
||||
use the same kernel as NETCONF builds, but unlike them it is up to the
|
||||
administrator to manually modify system configuration files in `/etc`
|
||||
and control the system services using the `initctl` tool.
|
||||
|
||||
For example, networking is configured by editing the [ifupdown-ng][6]
|
||||
files in `/etc/network/interfaces`.
|
||||
|
||||
> In Classic builds the `/etc` directory is saved across reboots.
|
||||
|
||||
To perform a factory reset, wiping all changes in `/etc`, and all other
|
||||
areas of the file system that are persistent, use the <kbd>factory</kbd>
|
||||
tool.
|
||||
|
||||
See the online <kbd>help</kbd> command for an introduction to the system
|
||||
and help on available tools, like text editors, network debugging, etc.
|
||||
|
||||
|
||||
Hybrid Mode
|
||||
-----------
|
||||
|
||||
Since Infix is under heavy development, it does not yet have all bells
|
||||
and whistles in place in the NETCONF builds. To that end it is possible
|
||||
to manually manage certain properties and services. It's a little bit
|
||||
tricky since any changes to the `/etc` directory is lost at reboot.
|
||||
|
||||
To work around that we use the [run-parts(8)][] feature of the system,
|
||||
available in some customer specific images. The system runs any user
|
||||
scripts in `/cfg/start.d` before leaving runlevel S (bootstrap).
|
||||
|
||||
> **Note:** a vanilla Infix build does not support Hybrid Mode out of
|
||||
> the box. You can enable it, and build your own images by adding the
|
||||
> following line to `board/common/rootfs/etc/finit.conf`:
|
||||
>
|
||||
> runparts /cfg/start.d
|
||||
>
|
||||
> See the [Developer's Guide](developers-guide.md) for a build HowTo.
|
||||
|
||||
|
||||
### Starting OSPF
|
||||
|
||||
For example, the following starts OSPF:
|
||||
|
||||
```sh
|
||||
root@infix:~$ cp -a /etc/frr /cfg/
|
||||
root@infix:~$ mkdir /cfg/start.d
|
||||
root@infix:~$ cd /cfg/start.d
|
||||
root@infix:/cfg/start.d$ cat <<EOF >10-enable-ospf.sh
|
||||
#!/bin/sh
|
||||
# Use vtysh to modify the OSPF configuration
|
||||
mount --bind /cfg/frr /etc/frr
|
||||
initctl enable zebra
|
||||
initctl enable ospfd
|
||||
initctl enable bfdd
|
||||
(sleep 1; vtysh -b) &
|
||||
exit 0
|
||||
EOF
|
||||
root@infix:/cfg/start.d$ chmod +x 10-enable-ospf.sh
|
||||
```
|
||||
|
||||
The `/cfg` area is persistent across reboots. Here we assume the user
|
||||
has already created the `/cfg/frr` directory, populated it with the
|
||||
original files from `/etc/frr`, and then modified the appropriate files
|
||||
to enable OSPF and BFD.
|
||||
|
||||
### Starting Containers
|
||||
|
||||
Using `/cfg/start.d` is also the way to start containers (provided the
|
||||
images have been downloaded with `podman pull` first):
|
||||
|
||||
```
|
||||
root@infix:/cfg/start.d$ cat <<EOF >20-enable-container.sh
|
||||
#!/bin/sh
|
||||
podman-service -e -d "Nginx container" -p "-p 80:80 -v /cfg/www:/usr/share/nginx/html:ro" nginx:alpine
|
||||
exit 0
|
||||
EOF
|
||||
root@infix:/cfg/start.d$ chmod +x 20-enable-container.sh
|
||||
```
|
||||
|
||||
Reboot to activate the changes. To activate the changes without
|
||||
rebooting, run the script and call `initctl reload`.
|
||||
|
||||
For more information, see [Containers in Infix](container.md).
|
||||
|
||||
> **Note:** Neither [Frr](https://frrouting.org) (Zebra/OSPF/BFD) or
|
||||
> [podman](https://podman.io) are enabled in the official Infix builds.
|
||||
> Some customers have them enabled in their specific builds, and you can
|
||||
> of course also enable it yourself in Infix by using `make menuconfig`
|
||||
> followed by rebuilding the image.
|
||||
|
||||
|
||||
[1]: https://www.sysrepo.org/
|
||||
[2]: https://github.com/CESNET/netopeer
|
||||
[3]: https://pypi.org/project/netconf-client/
|
||||
[4]: http://www.seguesoft.com/index.php/netconfc/
|
||||
[5]: https://www.mg-soft.si/mgNetConfBrowser.html
|
||||
[6]: https://github.com/ifupdown-ng/ifupdown-ng
|
||||
[run-parts(8)]: https://manpages.ubuntu.com/manpages/trusty/man8/run-parts.8.html
|
||||
[RESTCONF]: https://datatracker.ietf.org/doc/html/rfc8040
|
||||
|
||||
@@ -0,0 +1,57 @@
|
||||
Infix in Virtual Environments
|
||||
=============================
|
||||
|
||||
Infix primarily targets real hardware, deployment to the cloud is not a
|
||||
priority at the moment. However, for development and testing purposes
|
||||
there is an `x86_64` build that runs in [Qemu][].
|
||||
|
||||
These images also work with the Graphical Network Simulator ([GNS3][]),
|
||||
which is a very user-friendly tool for playing around with simple to
|
||||
complex network setups, verifying interoperability between vendors, etc.
|
||||
|
||||
|
||||
QEMU
|
||||
----
|
||||
|
||||
> **Note:** installation for Debian/Ubuntu based systems: <kbd>sudo apt
|
||||
> install virt-manager</kbd> -- dependencies ensure the relevant Qemu
|
||||
> packages are pulled in as well. Installing [virt-manager][virt] helps
|
||||
> set up Qemu networking on your system.
|
||||
|
||||
A virtualized Infix x86_64 instance can easily be launched from a Linux
|
||||
system, with [Qemu][] installed, by issuing:
|
||||
|
||||
./qemu.sh
|
||||
|
||||
from an unpacked [release tarball][rels]. From a built source tree of
|
||||
Infix the same functionality is bundled as:
|
||||
|
||||
make run
|
||||
|
||||
To change settings, e.g. networking, <kbd>make run-menuconfig</kbd>, or
|
||||
from a pre-built Infix release tarball, using <kbd>./qemu.sh -c</kbd>
|
||||
|
||||
The Infix test suite is built around Qemu and [Qeneth][qeth], see:
|
||||
|
||||
* [Testing](testing.md)
|
||||
* [Docker Image](../test/docker/README.md)
|
||||
|
||||
|
||||
GNS3
|
||||
----
|
||||
|
||||
Download the [latest build][rels] of the `x86_64`, or `x86_64_classic`
|
||||
flavor. Unpack the tarball in a dedicated directory and use ["Import
|
||||
Appliance"][APPL] to install the `.gns3a` file into [GNS3][].
|
||||
|
||||
Infix (`x86_64`) is in the "Router" category, it has with 10 interfaces
|
||||
available by default for use as switch ports or routing. The *classic*
|
||||
build only has one interface by default, geared more towards acting as
|
||||
an end device.
|
||||
|
||||
[Qemu]: https://www.qemu.org/
|
||||
[GNS3]: https://gns3.com/
|
||||
[virt]: https://virt-manager.org/
|
||||
[rels]: https://github.com/kernelkit/infix/releases
|
||||
[qeth]: https://github.com/wkz/qeneth
|
||||
[APPL]: https://docs.gns3.com/docs/using-gns3/beginners/import-gns3-appliance/
|
||||
+1
-1
@@ -14,6 +14,6 @@ run:
|
||||
@$(BINARIES_DIR)/qemu.sh
|
||||
|
||||
.PHONY: run-menuconfig
|
||||
run-menuconfig:
|
||||
run-menuconfig: $(BUILD_DIR)/buildroot-config/mconf
|
||||
CONFIG_="CONFIG_" BR2_CONFIG="$(BINARIES_DIR)/.config" \
|
||||
$(BUILD_DIR)/buildroot-config/mconf $(BINARIES_DIR)/Config.in
|
||||
|
||||
+4
-4
@@ -1,18 +1,18 @@
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/confd/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/statd/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/conmon/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/factory/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/faux/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/finit/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/ifupdown-ng/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/klinfix/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/klish-plugin-infix/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/klish/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/klish-plugin-sysrepo/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/libsrx/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/lowdown/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/mdnsd/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/net/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/osal/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/p-net/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/podman/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/profeth/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/skeleton-init-finit/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/tetris/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/querierd/Config.in"
|
||||
|
||||
@@ -5,6 +5,7 @@ config BR2_PACKAGE_CONFD
|
||||
select BR2_PACKAGE_LIBITE
|
||||
select BR2_PACKAGE_NETOPEER2
|
||||
select BR2_PACKAGE_SYSREPO
|
||||
select BR2_PACKAGE_LIBSRX
|
||||
help
|
||||
A plugin to sysrepo that provides the core YANG models used to
|
||||
manage an Infix based system. Configuration can be done using
|
||||
|
||||
@@ -1,15 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
reserved()
|
||||
{
|
||||
for svc in avahi dnsmasq getty klish lldpd nginx ssdpd sshd sysklogd sysrepo; do
|
||||
[ "$1" = "${svc}.conf" ] && return 0
|
||||
done
|
||||
|
||||
return 1
|
||||
}
|
||||
|
||||
for file in /etc/finit.d/enabled/*.conf; do
|
||||
reserved "$(basename "$file")" && continue
|
||||
rm "$file"
|
||||
done
|
||||
+5
-13
@@ -5,27 +5,19 @@
|
||||
################################################################################
|
||||
|
||||
CONFD_VERSION = 1.0
|
||||
CONFD_LICENSE = BSD-3-Clause
|
||||
CONFD_SITE_METHOD = local
|
||||
CONFD_SITE = $(BR2_EXTERNAL_INFIX_PATH)/src/confd
|
||||
CONFD_DEPENDENCIES = augeas jansson libite sysrepo
|
||||
CONFD_LICENSE = BSD-3-Clause
|
||||
CONFD_LICENSE_FILES = LICENSE
|
||||
CONFD_REDISTRIBUTE = NO
|
||||
CONFD_DEPENDENCIES = augeas jansson libite sysrepo libsrx
|
||||
CONFD_AUTORECONF = YES
|
||||
|
||||
ifeq ($(BR2_SYSTEM_BIN_SH_BASH),y)
|
||||
CONFD_CONF_OPTS += --with-login-shell=/bin/bash
|
||||
else
|
||||
CONFD_CONF_OPTS += --with-login-shell=/bin/sh
|
||||
endif
|
||||
|
||||
define CONFD_INSTALL_EXTRA
|
||||
cp $(CONFD_PKGDIR)/sysrepo.conf $(FINIT_D)/available/
|
||||
ln -sf ../available/sysrepo.conf $(FINIT_D)/enabled/sysrepo.conf
|
||||
cp $(CONFD_PKGDIR)/tmpfiles.conf $(TARGET_DIR)/etc/tmpfiles.d/confd.conf
|
||||
mkdir -p $(TARGET_DIR)/usr/share/factory/cfg
|
||||
cp $(CONFD_PKGDIR)/factory-config.cfg $(TARGET_DIR)/usr/share/factory/cfg/startup-config.cfg
|
||||
mkdir -p $(TARGET_DIR)/lib/infix
|
||||
cp $(CONFD_PKGDIR)/clean-etc $(TARGET_DIR)/lib/infix/
|
||||
endef
|
||||
CONFD_TARGET_FINALIZE_HOOKS += CONFD_INSTALL_EXTRA
|
||||
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_EXTRA
|
||||
|
||||
$(eval $(autotools-package))
|
||||
|
||||
@@ -1,24 +0,0 @@
|
||||
{
|
||||
"ietf-interfaces:interfaces": {
|
||||
"interface": [
|
||||
{
|
||||
"name": "eth0",
|
||||
"type": "iana-if-type:ethernetCsmacd",
|
||||
"ietf-ip:ipv4": {
|
||||
"infix-ip:autoconf": {
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
"ietf-ip:ipv6": {
|
||||
"enabled": true,
|
||||
"autoconf": {
|
||||
"create-global-addresses": true
|
||||
}
|
||||
}
|
||||
}
|
||||
]
|
||||
},
|
||||
"ietf-system:system": {
|
||||
"hostname": "infix"
|
||||
}
|
||||
}
|
||||
@@ -1,9 +1,7 @@
|
||||
run [S] /lib/infix/clean-etc --
|
||||
|
||||
run name:bootstrap log:prio:user.notice \
|
||||
[S] /lib/infix/cfg-bootstrap -- Bootstrapping YANG models
|
||||
service name:sysrepo log \
|
||||
[S12345789] sysrepo-plugind -p /run/sysrepo.pid -n -- Configuration daemon
|
||||
[S12345789] sysrepo-plugind -f -p /run/sysrepo.pid -n -- Configuration daemon
|
||||
run name:startup log:prio:user.notice \
|
||||
[S] <pid/sysrepo> sysrepocfg -I/cfg/startup-config.cfg -f json \
|
||||
-- Loading startup-config
|
||||
|
||||
@@ -3,10 +3,13 @@
|
||||
# factory
|
||||
#
|
||||
################################################################################
|
||||
|
||||
FACTORY_VERSION = 1.0
|
||||
FACTORY_LICENSE = MIT
|
||||
FACTORY_LICENSE_FILES = LICENSE
|
||||
FACTORY_SITE_METHOD = local
|
||||
FACTORY_SITE = $(BR2_EXTERNAL_INFIX_PATH)/src/factory
|
||||
FACTORY_REDISTRIBUTE = NO
|
||||
|
||||
define FACTORY_BUILD_CMDS
|
||||
$(TARGET_MAKE_ENV) $(TARGET_CONFIGURE_OPTS) $(MAKE) -C $(@D) \
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally calculated
|
||||
sha256 9d9d33b873917ca5d0bdcc47a36d2fd385971ab0c045d1472fcadf95ee5bcf5b LICENCE
|
||||
sha256 8e369f54c2da317030ff4cad905e501303d0489b98e4b208d0ff611b4484c94e faux-tags_2.1.0-br1.tar.gz
|
||||
sha256 f665a98cf5026f25a21b86d9cba55a8e6ee82f4f257a1b538bb4ebb7341c2179 faux-99c9cf7b95d8e2955519e2bec5ddb021eeda2d55-br1.tar.gz
|
||||
|
||||
@@ -4,11 +4,13 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
FAUX_VERSION = tags/2.1.0
|
||||
FAUX_SITE = https://src.libcode.org/pkun/faux.git
|
||||
FAUX_VERSION = 99c9cf7b95d8e2955519e2bec5ddb021eeda2d55
|
||||
FAUX_SITE = https://github.com/kernelkit/faux.git
|
||||
#FAUX_VERSION = tags/2.1.0
|
||||
#FAUX_SITE = https://src.libcode.org/pkun/faux.git
|
||||
FAUX_SITE_METHOD = git
|
||||
FAUX_LICENSE = BSD-3
|
||||
FAUX_LICENSE_FILES = LICENSE
|
||||
FAUX_LICENSE_FILES = LICENCE
|
||||
FAUX_INSTALL_STAGING = YES
|
||||
FAUX_AUTORECONF = YES
|
||||
|
||||
|
||||
@@ -1,14 +0,0 @@
|
||||
################################################################################
|
||||
#
|
||||
# klinfix
|
||||
#
|
||||
################################################################################
|
||||
|
||||
KLINFIX_VERSION = 1.0
|
||||
KLINFIX_LICENSE = BSD-3-Clause
|
||||
KLINFIX_SITE_METHOD = local
|
||||
KLINFIX_SITE = $(BR2_EXTERNAL_INFIX_PATH)/src/klinfix
|
||||
KLINFIX_DEPENDENCIES = klish-plugin-sysrepo
|
||||
KLINFIX_AUTORECONF = YES
|
||||
|
||||
$(eval $(autotools-package))
|
||||
@@ -1,5 +1,5 @@
|
||||
config BR2_PACKAGE_KLINFIX
|
||||
bool "klinfix"
|
||||
config BR2_PACKAGE_KLISH_PLUGIN_INFIX
|
||||
bool "klish-plugin-infix"
|
||||
select BR2_PACKAGE_KLISH
|
||||
select BR2_PACKAGE_KLISH_PLUGIN_SYSREPO
|
||||
select BR2_PACKAGE_SYSREPO
|
||||
@@ -0,0 +1,2 @@
|
||||
# Locally calculated
|
||||
sha256 9d9d33b873917ca5d0bdcc47a36d2fd385971ab0c045d1472fcadf95ee5bcf5b LICENSE
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user