mirror of
https://github.com/kernelkit/infix.git
synced 2026-07-22 09:13:01 +02:00
Compare commits
451
Commits
v24.11.2
...
v25.03.1-rc1
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
e3fe203005 | ||
|
|
18f7c779c9 | ||
|
|
454207c185 | ||
|
|
d877806e2b | ||
|
|
5ed7182361 | ||
|
|
3f695b6c62 | ||
|
|
4f3605a5f7 | ||
|
|
e89dde0d25 | ||
|
|
e1ecf6b71d | ||
|
|
10f62f679b | ||
|
|
fa4f7c6532 | ||
|
|
0647541988 | ||
|
|
2602ddc0b8 | ||
|
|
3886b284d3 | ||
|
|
22a9405d1e | ||
|
|
2902dccf11 | ||
|
|
644374bb29 | ||
|
|
a868307637 | ||
|
|
d213861e02 | ||
|
|
3d538d4eca | ||
|
|
06a6dd17f8 | ||
|
|
18659fd45a | ||
|
|
7253be7619 | ||
|
|
910749bab1 | ||
|
|
4f9b3146a1 | ||
|
|
b026abd0bc | ||
|
|
08658a37c4 | ||
|
|
6bbf2d02a8 | ||
|
|
538185c29e | ||
|
|
bd05715ba0 | ||
|
|
6960cd30eb | ||
|
|
c5c21dec83 | ||
|
|
73de6b6d42 | ||
|
|
f698d5f0ee | ||
|
|
7e59406436 | ||
|
|
b8a9dc9743 | ||
|
|
1b5aa16652 | ||
|
|
3f491ea785 | ||
|
|
9bdad9bc8b | ||
|
|
de711b0123 | ||
|
|
b52c462cfa | ||
|
|
f4e75dfecb | ||
|
|
c5fe10aada | ||
|
|
97623b989c | ||
|
|
ed2a776c55 | ||
|
|
ac4fcb61c6 | ||
|
|
41fa664a86 | ||
|
|
4f54cbe975 | ||
|
|
2291e9fd11 | ||
|
|
095c9c331e | ||
|
|
b8fc8b7f62 | ||
|
|
95931c8c0a | ||
|
|
dd788f5611 | ||
|
|
5d99c12089 | ||
|
|
03437fc936 | ||
|
|
56a086ef52 | ||
|
|
3f3fb4eeb4 | ||
|
|
4998e320c5 | ||
|
|
496d56e975 | ||
|
|
82df624ae9 | ||
|
|
5021a1da88 | ||
|
|
df1fc6f2d7 | ||
|
|
2ebcf26ede | ||
|
|
b1a77deadf | ||
|
|
bce1b34873 | ||
|
|
91f31c00c3 | ||
|
|
4b4ffdd14e | ||
|
|
50c83f1be7 | ||
|
|
ee86d12dc2 | ||
|
|
b388e080ad | ||
|
|
6e630018df | ||
|
|
9de5e5b802 | ||
|
|
399d3c365d | ||
|
|
3867abe4da | ||
|
|
90d2ae3868 | ||
|
|
581d1742e5 | ||
|
|
172d7607bb | ||
|
|
62a4b48679 | ||
|
|
3e07c9a960 | ||
|
|
05c197c457 | ||
|
|
77c321daa3 | ||
|
|
3d99af87d6 | ||
|
|
28c2a4a6cc | ||
|
|
1bbd62c021 | ||
|
|
ecc0b63da2 | ||
|
|
347e493542 | ||
|
|
77499790ba | ||
|
|
a960267c40 | ||
|
|
b9f3254ba7 | ||
|
|
266f18bbeb | ||
|
|
b70129f178 | ||
|
|
888f0c4207 | ||
|
|
88fa47c664 | ||
|
|
2ecc2c3602 | ||
|
|
02d8288863 | ||
|
|
d1dde5406e | ||
|
|
fd7b4bbe39 | ||
|
|
c28ea1db19 | ||
|
|
d68dacdc80 | ||
|
|
91f0094048 | ||
|
|
5660f6239d | ||
|
|
58cf5abf0b | ||
|
|
fc32d8a9db | ||
|
|
4b2f140140 | ||
|
|
67cb307f2d | ||
|
|
3811df9ab2 | ||
|
|
53d0995d0c | ||
|
|
7a692fd57d | ||
|
|
73e1c158f5 | ||
|
|
ab3b389f69 | ||
|
|
417d48f015 | ||
|
|
b6aa604cdd | ||
|
|
0dbf99cc82 | ||
|
|
7127caf6b5 | ||
|
|
638862d268 | ||
|
|
2d7dedf79c | ||
|
|
f690cd216c | ||
|
|
6a5bf66a42 | ||
|
|
5707711d84 | ||
|
|
5b3eb23aeb | ||
|
|
51987948ad | ||
|
|
e70559a68d | ||
|
|
83797ca19c | ||
|
|
d82b3e51ea | ||
|
|
e03bd37660 | ||
|
|
ee26cec88a | ||
|
|
88763034ed | ||
|
|
dad1c024aa | ||
|
|
f92d3846db | ||
|
|
ffab761274 | ||
|
|
b4c648229a | ||
|
|
1ca7acda14 | ||
|
|
8f30f88967 | ||
|
|
8eaaaa9d38 | ||
|
|
4e0ad1df1b | ||
|
|
dc3b78e678 | ||
|
|
4d7dde5366 | ||
|
|
3c0679991d | ||
|
|
fe741a92f3 | ||
|
|
f6879e24cc | ||
|
|
7e252ba941 | ||
|
|
46d5e750d7 | ||
|
|
5988249f84 | ||
|
|
7aee2600ba | ||
|
|
6f99a9c2dc | ||
|
|
eee1ce32fa | ||
|
|
d9f2f2c8f9 | ||
|
|
31d0f79a10 | ||
|
|
b290e44318 | ||
|
|
2d806de2cd | ||
|
|
c5db34b491 | ||
|
|
3d816d2525 | ||
|
|
fb394db981 | ||
|
|
da39855cec | ||
|
|
a6b79857db | ||
|
|
f1271f28b9 | ||
|
|
f62900699a | ||
|
|
cf16efe499 | ||
|
|
4260d24143 | ||
|
|
3ef1da1096 | ||
|
|
a90a39e8d8 | ||
|
|
dc5c7732d7 | ||
|
|
5bf9200880 | ||
|
|
f9b155b49f | ||
|
|
9782ac9afa | ||
|
|
773683bfd5 | ||
|
|
3dbb1759eb | ||
|
|
d7895d5c9c | ||
|
|
78499757b0 | ||
|
|
ec2e161649 | ||
|
|
18d8c439bd | ||
|
|
1ca11f1fe7 | ||
|
|
b70d0015a6 | ||
|
|
6a417f2f23 | ||
|
|
f212f0cc16 | ||
|
|
01d07b4942 | ||
|
|
039cb5db74 | ||
|
|
65bce0378e | ||
|
|
91cef6d57b | ||
|
|
f3da31b18c | ||
|
|
af1f173497 | ||
|
|
14fede3e56 | ||
|
|
d3bfbb57b6 | ||
|
|
3203ee925a | ||
|
|
fae1265587 | ||
|
|
97f3db8fdb | ||
|
|
a8b5120871 | ||
|
|
c22339c2cd | ||
|
|
b1830a36d4 | ||
|
|
05510c5001 | ||
|
|
343c465352 | ||
|
|
0cb2987de4 | ||
|
|
7d646c9494 | ||
|
|
395b21c693 | ||
|
|
6ef3ad9020 | ||
|
|
a608c4a36d | ||
|
|
e48da5bb21 | ||
|
|
f389a1f087 | ||
|
|
84521ea9b5 | ||
|
|
4ba43e2ddd | ||
|
|
3606bc05cf | ||
|
|
5e89d8ef3e | ||
|
|
028fc578b1 | ||
|
|
52e957d47f | ||
|
|
95cfcaa2fe | ||
|
|
340330b75b | ||
|
|
af8a90d651 | ||
|
|
ee44da6272 | ||
|
|
a5aba02ddd | ||
|
|
cb73ddf6bf | ||
|
|
e45fcfca41 | ||
|
|
27dae1edf0 | ||
|
|
d1e1c9ad33 | ||
|
|
d28fff67f2 | ||
|
|
62d539c424 | ||
|
|
3c1e9f3199 | ||
|
|
b196194e5f | ||
|
|
5ee78e28ad | ||
|
|
bcfd3d4a5b | ||
|
|
f86f184783 | ||
|
|
60f459687c | ||
|
|
455c384164 | ||
|
|
1fef35f77c | ||
|
|
8bc389987c | ||
|
|
ee56ebc205 | ||
|
|
9198383742 | ||
|
|
b010ad04bf | ||
|
|
4458e03cd2 | ||
|
|
4a37369750 | ||
|
|
7af75c0786 | ||
|
|
0fbe225b05 | ||
|
|
2405c002e4 | ||
|
|
1cc9e3c9c8 | ||
|
|
a64c9695cc | ||
|
|
d9be0b3a64 | ||
|
|
8b4682ac8b | ||
|
|
a975da2159 | ||
|
|
e483ddb487 | ||
|
|
267c8e0103 | ||
|
|
25f0d8ca2e | ||
|
|
be0edc00cc | ||
|
|
dc393946ce | ||
|
|
80a522ce08 | ||
|
|
b3ad9e5693 | ||
|
|
cc8c917de1 | ||
|
|
2a3fcbacd0 | ||
|
|
5c9cf276df | ||
|
|
76203b392a | ||
|
|
18913770fe | ||
|
|
2f23baf745 | ||
|
|
a7ce8c2ab4 | ||
|
|
d7ac84cf99 | ||
|
|
04b739b0bd | ||
|
|
131c0b1d4b | ||
|
|
f42c35d8ab | ||
|
|
0187d62246 | ||
|
|
01201708e3 | ||
|
|
986a28c891 | ||
|
|
0bbcd7ec43 | ||
|
|
f9dacaa0ff | ||
|
|
8f6a75806f | ||
|
|
05cb07c0ec | ||
|
|
d6ace7cc73 | ||
|
|
9ef6d2d038 | ||
|
|
c1e6f0c53b | ||
|
|
0e82c108bc | ||
|
|
9427b6a655 | ||
|
|
6a09e2c797 | ||
|
|
3b0b38360c | ||
|
|
3b3fe18f9d | ||
|
|
dedab8c2a2 | ||
|
|
3e0b816351 | ||
|
|
3f8fae2f16 | ||
|
|
70bcebc451 | ||
|
|
6a384bf48b | ||
|
|
10add98d90 | ||
|
|
a2257731ca | ||
|
|
6be990f1bb | ||
|
|
370920e931 | ||
|
|
ee441e172d | ||
|
|
5e90bde8b9 | ||
|
|
0b2f53e3b4 | ||
|
|
1fd55c484a | ||
|
|
1d13c5ea9e | ||
|
|
26303f5168 | ||
|
|
19c1f49fd3 | ||
|
|
5b8b1eec57 | ||
|
|
d83c333b2d | ||
|
|
4598585d4a | ||
|
|
c2959cf41e | ||
|
|
a640460baf | ||
|
|
5d6180a395 | ||
|
|
28c0cee4e3 | ||
|
|
27bba2c47c | ||
|
|
4753e35d7f | ||
|
|
28f67ff608 | ||
|
|
e1a033b97d | ||
|
|
2b7d2b4005 | ||
|
|
39de797b10 | ||
|
|
de9b1cdd2d | ||
|
|
f0c57da4ab | ||
|
|
b5218f7149 | ||
|
|
7cb311b5bc | ||
|
|
254c922254 | ||
|
|
4fb26b1119 | ||
|
|
ad262459b7 | ||
|
|
71b89d06d7 | ||
|
|
72b3058774 | ||
|
|
57c8d0cf1b | ||
|
|
f4c9a57bb5 | ||
|
|
9879e8b685 | ||
|
|
beecff2acf | ||
|
|
6f2face898 | ||
|
|
ddc8282dd7 | ||
|
|
c244042e55 | ||
|
|
78b7b34799 | ||
|
|
e397012394 | ||
|
|
5cc73ab97c | ||
|
|
be1b7cdf45 | ||
|
|
41f3fe15a6 | ||
|
|
df3a55d6a0 | ||
|
|
4e83520b0e | ||
|
|
94cd526772 | ||
|
|
4782cee201 | ||
|
|
907401f6f2 | ||
|
|
9a831217e4 | ||
|
|
1aab75d86a | ||
|
|
147cb713ed | ||
|
|
12b6146551 | ||
|
|
29031be4e9 | ||
|
|
b2db59f3bc | ||
|
|
cf129d1f9c | ||
|
|
41b96e8a01 | ||
|
|
805ddf6c92 | ||
|
|
547a9cd632 | ||
|
|
2ec226640e | ||
|
|
a0e4e813dd | ||
|
|
8812ae7052 | ||
|
|
28bf2d6c3c | ||
|
|
dadf0e2d16 | ||
|
|
c4a79766b7 | ||
|
|
385eab2016 | ||
|
|
bc33d8bc8a | ||
|
|
061fa5fc72 | ||
|
|
ac0acfe7c1 | ||
|
|
f3f313bb98 | ||
|
|
3ef40031dd | ||
|
|
44b60956a8 | ||
|
|
e4535aa856 | ||
|
|
343400c5fe | ||
|
|
bfeeade43b | ||
|
|
b425edffce | ||
|
|
f041d009b5 | ||
|
|
26d06bd13b | ||
|
|
9d51470ee2 | ||
|
|
49a003088b | ||
|
|
c099d887af | ||
|
|
08990556e2 | ||
|
|
cd5b076751 | ||
|
|
081f8e8412 | ||
|
|
465d8cbc82 | ||
|
|
323c77b702 | ||
|
|
780077e729 | ||
|
|
324bcb2533 | ||
|
|
e29a721571 | ||
|
|
389fc96794 | ||
|
|
da260fabf9 | ||
|
|
79bec6877c | ||
|
|
37b97d9e4c | ||
|
|
2e81e99224 | ||
|
|
bea18c2fa9 | ||
|
|
0233fdbf35 | ||
|
|
23ca94ea42 | ||
|
|
a8545e3369 | ||
|
|
1f2973d93f | ||
|
|
e00737ef78 | ||
|
|
a90294fe08 | ||
|
|
77215aeb87 | ||
|
|
7dfb1f131e | ||
|
|
7fecac2973 | ||
|
|
bb939ccdff | ||
|
|
8e38b34c55 | ||
|
|
ff8669e735 | ||
|
|
6a4c8f738e | ||
|
|
03cab6d1e4 | ||
|
|
96779c2620 | ||
|
|
e9a71ec3f7 | ||
|
|
b3da4c50fc | ||
|
|
eb9ae5e4dd | ||
|
|
9591093379 | ||
|
|
68d8c19b53 | ||
|
|
dc2ced8e09 | ||
|
|
02a8c3d78d | ||
|
|
a4ef38fbee | ||
|
|
5608e9457d | ||
|
|
34f0c5a462 | ||
|
|
5675f89d37 | ||
|
|
6d6f4e6dd9 | ||
|
|
f06a42987a | ||
|
|
76ab0fe07a | ||
|
|
734958b89d | ||
|
|
397568f1c8 | ||
|
|
a2c3919c0f | ||
|
|
e08576b008 | ||
|
|
83238aad7e | ||
|
|
1863297b5a | ||
|
|
9cd9440515 | ||
|
|
ec64c1585c | ||
|
|
429c4f1573 | ||
|
|
28ae8fca42 | ||
|
|
c076f0a770 | ||
|
|
219c61081d | ||
|
|
ad32129a13 | ||
|
|
1db039d6b4 | ||
|
|
f023304823 | ||
|
|
85603eb53d | ||
|
|
1f231c2b2a | ||
|
|
967388395f | ||
|
|
94cffd2c48 | ||
|
|
89c5b67a13 | ||
|
|
3436cd68ac | ||
|
|
d16ad7eedc | ||
|
|
e635e3e720 | ||
|
|
42b7cf9f94 | ||
|
|
7d9211a3ba | ||
|
|
1895e161d2 | ||
|
|
7804787201 | ||
|
|
3576450982 | ||
|
|
bb987cfe9e | ||
|
|
997310f9a2 | ||
|
|
bf23f53770 | ||
|
|
e8f9032339 | ||
|
|
80e4018b20 | ||
|
|
27b7d831d0 | ||
|
|
f0ae1aa835 | ||
|
|
88f7c6070a | ||
|
|
a3f85a3872 | ||
|
|
7467b2fcf4 | ||
|
|
3e387d74c2 | ||
|
|
f961bcfe86 | ||
|
|
ce05139452 | ||
|
|
a74eb58000 | ||
|
|
5cafd18b79 | ||
|
|
7334d0e54b | ||
|
|
fffe427497 | ||
|
|
168647ace9 | ||
|
|
0e14e05ae5 | ||
|
|
3ab7a7d531 | ||
|
|
fcef1ead3a | ||
|
|
784b391467 | ||
|
|
6d18ba4c39 |
@@ -0,0 +1,26 @@
|
||||
# Security Policy
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
If you discover a security vulnerability in Infix, please use GitHub's built-in
|
||||
[Report a Vulnerability](https://github.com/kernelkit/infix/security/advisories/new)
|
||||
feature for a private and secure disclosure.
|
||||
|
||||
When reporting, include:
|
||||
|
||||
- A clear description of the vulnerability.
|
||||
- Steps to reproduce the issue.
|
||||
- Potential impact of the vulnerability.
|
||||
|
||||
## Supported Versions
|
||||
|
||||
We provide security updates only for the main branch.
|
||||
|
||||
Individual support contracts are provided by _Wires_. See
|
||||
[Support](https://github.com/kernelkit/infix/blob/main/.github/SUPPORT.md)
|
||||
for more information.
|
||||
|
||||
## Acknowledgments
|
||||
|
||||
We appreciate the efforts of the security community to help improve the security
|
||||
of Infix. Thank you for your responsible disclosure.
|
||||
+3
-3
@@ -6,7 +6,7 @@ project on GitHub, and Discord, see <https://github.com/kernelkit>:
|
||||
|
||||
Support contracts, development of new features, fast-tracking of reviews
|
||||
and contributions, customer branding of Infix, and even customer specific
|
||||
features for dedicated products is provided by Addiva Elektronik.
|
||||
features for dedicated products is provided by _Wires_.
|
||||
|
||||
:globe_with_meridians: <https://www.addiva.se/electronics/>
|
||||
:e-mail: <mailto:ael@addiva.se>
|
||||
:globe_with_meridians: <https://www.wires.se>
|
||||
:e-mail: <mailto:infix@wires.se>
|
||||
|
||||
@@ -22,6 +22,8 @@ jobs:
|
||||
matrix:
|
||||
target: [aarch64, x86_64]
|
||||
fail-fast: false
|
||||
outputs:
|
||||
build_id: ${{ steps.vars.outputs.INFIX_BUILD_ID }}
|
||||
steps:
|
||||
- name: Cleanup Build Folder
|
||||
run: |
|
||||
@@ -33,11 +35,22 @@ jobs:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
clean: true
|
||||
fetch-depth: 0
|
||||
submodules: recursive
|
||||
|
||||
- name: Set Build Variables
|
||||
id: vars
|
||||
run: |
|
||||
if [ -n "${{ github.event.pull_request.head.sha }}" ]; then
|
||||
# Since PRs are built from an internally generated merge
|
||||
# commit, reverse lookups of PRs and/or commits from
|
||||
# image version information are cumbersome. Therefore:
|
||||
# explicitly set a build id that references both the PR
|
||||
# and the commit.
|
||||
printf "INFIX_BUILD_ID=pr%d.%.7s\n" \
|
||||
"${{ github.event.number }}" "${{ github.event.pull_request.head.sha }}" \
|
||||
| tee -a $GITHUB_OUTPUT $GITHUB_ENV
|
||||
fi
|
||||
if [ "${{ github.event_name }}" == "workflow_dispatch" ]; then
|
||||
if [ "${{ github.event.inputs.minimal }}" == "true" ]; then
|
||||
flavor="_minimal"
|
||||
@@ -112,7 +125,7 @@ jobs:
|
||||
cd output/
|
||||
mv images ${{ steps.vars.outputs.dir }}
|
||||
ln -s ${{ steps.vars.outputs.dir }} images
|
||||
tar chfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||
tar cfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
@@ -132,6 +145,11 @@ jobs:
|
||||
- name: Set Build Variables
|
||||
id: vars
|
||||
run: |
|
||||
if [ -n "${{ needs.build.outputs.build_id }}" ]; then
|
||||
echo "INFIX_BUILD_ID=${{ needs.build.outputs.build_id }}" \
|
||||
>>$GITHUB_ENV
|
||||
fi
|
||||
|
||||
if [ "$GITHUB_REF_NAME" != "main" ]; then
|
||||
flavor="_minimal"
|
||||
else
|
||||
@@ -166,6 +184,22 @@ jobs:
|
||||
if: always()
|
||||
run: cat test/.log/last/result-gh.md >> $GITHUB_STEP_SUMMARY
|
||||
|
||||
- name: Generate Test Report for x86_64${{ steps.vars.outputs.flv }}
|
||||
# Ensure this runs even if Regression Test fails
|
||||
if: always()
|
||||
run: |
|
||||
asciidoctor-pdf \
|
||||
--theme test/9pm/report/theme.yml \
|
||||
-a pdf-fontsdir=test/9pm/report/fonts \
|
||||
test/.log/last/report.adoc \
|
||||
-o test/.log/last/report.pdf
|
||||
|
||||
- name: Upload Test Report as Artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: test-report
|
||||
path: test/.log/last/report.pdf
|
||||
|
||||
release:
|
||||
if: ${{github.repository_owner == 'kernelkit' && github.ref_name == 'main'}}
|
||||
name: Upload Latest Build
|
||||
|
||||
@@ -55,7 +55,7 @@ jobs:
|
||||
sudo apt-get -y update
|
||||
sudo apt-get -y install pkg-config libjansson-dev libev-dev \
|
||||
libcrypt-dev libglib2.0-dev libpcre2-dev \
|
||||
libuev-dev libite-dev
|
||||
libuev-dev
|
||||
|
||||
- name: Build dependencies
|
||||
run: |
|
||||
@@ -65,6 +65,8 @@ jobs:
|
||||
git clone https://github.com/sysrepo/sysrepo.git
|
||||
mkdir sysrepo/build
|
||||
(cd sysrepo/build && cmake .. && make all && sudo make install)
|
||||
git clone https://github.com/troglobit/libite.git
|
||||
(cd libite && ./autogen.sh && ./configure && make && sudo make install)
|
||||
make dep
|
||||
|
||||
- name: Check applications
|
||||
|
||||
@@ -85,10 +85,10 @@ jobs:
|
||||
cd output/
|
||||
mv images ${{ steps.vars.outputs.dir }}
|
||||
ln -s ${{ steps.vars.outputs.dir }} images
|
||||
tar chfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||
tar cfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||
|
||||
mv legal-info legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}
|
||||
tar chfz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}.tar.gz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}
|
||||
tar cfz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}.tar.gz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}
|
||||
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
|
||||
@@ -106,6 +106,16 @@ more information, see: [Infix in Virtual Environments](doc/virtual.md).
|
||||
>
|
||||
> For *customer specific builds* of Infix, see your product repository.
|
||||
|
||||
|
||||
----
|
||||
|
||||
<div align="center">
|
||||
<a href="https://github.com/wires-se"><img src="https://raw.githubusercontent.com/wires-se/.github/main/profile/logo.png" width=300></a>
|
||||
<br />Infix development is sponsored by <a href="https://wires.se">Wires<a>
|
||||
</div>
|
||||
|
||||
----
|
||||
|
||||
[^1]: An immutable operating system is one with read-only file systems,
|
||||
atomic updates, rollbacks, declarative configuration, and workload
|
||||
isolation. All to improve reliability, scalability, and security.
|
||||
|
||||
@@ -128,5 +128,9 @@ SD-card partition.
|
||||
> If possible, serve `infix-aarch64.pkg` over HTTP instead, as
|
||||
> libcurl's TFTP implementation is quite slow.
|
||||
|
||||
## Console Port
|
||||
|
||||
The console port runs at 115200 baud, 8N1.
|
||||
|
||||
[release]: https://github.com/kernelkit/infix/releases
|
||||
[mvebu64boot]: https://github.com/addiva-elektronik/mvebu64boot
|
||||
|
||||
@@ -34,6 +34,10 @@ CONFIG_PROFILING=y
|
||||
CONFIG_ARCH_SPARX5=y
|
||||
CONFIG_ARCH_MVEBU=y
|
||||
CONFIG_ARCH_VEXPRESS=y
|
||||
CONFIG_ARM64_ERRATUM_2441007=y
|
||||
CONFIG_ARM64_ERRATUM_1286807=y
|
||||
CONFIG_ARM64_ERRATUM_1542419=y
|
||||
CONFIG_ARM64_ERRATUM_2441009=y
|
||||
CONFIG_ARM64_VA_BITS_48=y
|
||||
CONFIG_SCHED_MC=y
|
||||
CONFIG_NR_CPUS=64
|
||||
@@ -57,6 +61,7 @@ CONFIG_MODULE_UNLOAD=y
|
||||
CONFIG_KSM=y
|
||||
CONFIG_TRANSPARENT_HUGEPAGE=y
|
||||
CONFIG_CMA=y
|
||||
CONFIG_CMA_AREAS=7
|
||||
CONFIG_NET=y
|
||||
CONFIG_PACKET=y
|
||||
CONFIG_XDP_SOCKETS=y
|
||||
@@ -165,7 +170,6 @@ CONFIG_BRIDGE_EBT_REDIRECT=m
|
||||
CONFIG_BRIDGE_EBT_SNAT=m
|
||||
CONFIG_BRIDGE_EBT_LOG=m
|
||||
CONFIG_BRIDGE_EBT_NFLOG=m
|
||||
CONFIG_BPFILTER=y
|
||||
CONFIG_BRIDGE=y
|
||||
CONFIG_BRIDGE_VLAN_FILTERING=y
|
||||
CONFIG_BRIDGE_MRP=y
|
||||
@@ -227,6 +231,7 @@ CONFIG_SCSI_SAS_ATA=y
|
||||
CONFIG_SCSI_VIRTIO=y
|
||||
CONFIG_ATA=y
|
||||
CONFIG_SATA_AHCI=y
|
||||
CONFIG_SATA_MOBILE_LPM_POLICY=0
|
||||
CONFIG_SATA_AHCI_PLATFORM=y
|
||||
CONFIG_AHCI_MVEBU=y
|
||||
CONFIG_PATA_OF_PLATFORM=y
|
||||
@@ -282,6 +287,7 @@ CONFIG_NET_DSA_MV88E6XXX_PTP=y
|
||||
CONFIG_MVNETA=m
|
||||
CONFIG_MVPP2=m
|
||||
# CONFIG_NET_VENDOR_MELLANOX is not set
|
||||
# CONFIG_NET_VENDOR_META is not set
|
||||
# CONFIG_NET_VENDOR_MICREL is not set
|
||||
CONFIG_SPARX5_SWITCH=y
|
||||
# CONFIG_NET_VENDOR_MICROSEMI is not set
|
||||
@@ -353,13 +359,14 @@ CONFIG_SERIAL_XILINX_PS_UART=y
|
||||
CONFIG_SERIAL_XILINX_PS_UART_CONSOLE=y
|
||||
CONFIG_SERIAL_MVEBU_UART=y
|
||||
CONFIG_VIRTIO_CONSOLE=y
|
||||
CONFIG_HW_RANDOM_CN10K=m
|
||||
CONFIG_I2C=y
|
||||
CONFIG_I2C_CHARDEV=y
|
||||
CONFIG_I2C_MUX=y
|
||||
CONFIG_I2C_MUX_GPIO=y
|
||||
CONFIG_I2C_MUX_PCA954x=y
|
||||
CONFIG_I2C_MUX_PINCTRL=y
|
||||
CONFIG_I2C_DESIGNWARE_PLATFORM=y
|
||||
CONFIG_I2C_DESIGNWARE_CORE=y
|
||||
CONFIG_I2C_MV64XXX=y
|
||||
CONFIG_I2C_SLAVE=y
|
||||
CONFIG_SPI=y
|
||||
@@ -495,6 +502,7 @@ CONFIG_EXTCON_USB_GPIO=y
|
||||
CONFIG_IIO=y
|
||||
CONFIG_TI_ADC081C=y
|
||||
CONFIG_PWM=y
|
||||
CONFIG_RESET_GPIO=y
|
||||
CONFIG_PHY_MVEBU_CP110_COMPHY=y
|
||||
CONFIG_PHY_MVEBU_CP110_UTMI=y
|
||||
CONFIG_PHY_SAMSUNG_USB2=y
|
||||
@@ -523,13 +531,13 @@ CONFIG_9P_FS=y
|
||||
CONFIG_NLS_CODEPAGE_437=y
|
||||
CONFIG_NLS_ISO8859_1=y
|
||||
CONFIG_SECURITY=y
|
||||
CONFIG_LSM="landlock,lockdown,yama,loadpin,safesetid,bpf"
|
||||
CONFIG_CRYPTO_CCM=m
|
||||
CONFIG_CRYPTO_ECHAINIV=y
|
||||
CONFIG_CRYPTO_ANSI_CPRNG=y
|
||||
CONFIG_CRYPTO_GHASH_ARM64_CE=y
|
||||
CONFIG_CRYPTO_SHA1_ARM64_CE=y
|
||||
CONFIG_CRYPTO_SHA2_ARM64_CE=y
|
||||
CONFIG_CRYPTO_AES_ARM64_CE_BLK=y
|
||||
CONFIG_CRYPTO_AES_ARM64_CE_CCM=y
|
||||
CONFIG_DMA_CMA=y
|
||||
CONFIG_CMA_SIZE_MBYTES=0
|
||||
|
||||
@@ -101,6 +101,13 @@ Worth noting, unlike many other boards, the Rockchip family of chipsets
|
||||
runs the UART at 1500000 bps (1.5 Mbps) 8N1.
|
||||
|
||||
|
||||
Console Port
|
||||
------------
|
||||
|
||||
Unlike many other boards, the NanoPi R2S console, and in fact all
|
||||
Rockchip family chipsets, runs at 1500000 bps (1.5 Mbps) 8N1.
|
||||
|
||||
|
||||
Secure Boot
|
||||
-----------
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
#
|
||||
# Automatically generated make config: don't edit
|
||||
# Busybox version: 1.36.1
|
||||
# Tue Oct 22 13:12:02 2024
|
||||
# Sun Feb 9 12:25:37 2025
|
||||
#
|
||||
CONFIG_HAVE_DOT_CONFIG=y
|
||||
|
||||
@@ -17,7 +17,7 @@ CONFIG_SHOW_USAGE=y
|
||||
CONFIG_FEATURE_VERBOSE_USAGE=y
|
||||
# CONFIG_FEATURE_COMPRESS_USAGE is not set
|
||||
CONFIG_LFS=y
|
||||
# CONFIG_PAM is not set
|
||||
CONFIG_PAM=y
|
||||
CONFIG_FEATURE_DEVPTS=y
|
||||
CONFIG_FEATURE_UTMP=y
|
||||
CONFIG_FEATURE_WTMP=y
|
||||
@@ -325,7 +325,7 @@ CONFIG_FEATURE_STAT_FILESYSTEM=y
|
||||
CONFIG_STTY=y
|
||||
CONFIG_SUM=y
|
||||
CONFIG_SYNC=y
|
||||
# CONFIG_FEATURE_SYNC_FANCY is not set
|
||||
CONFIG_FEATURE_SYNC_FANCY=y
|
||||
CONFIG_FSYNC=y
|
||||
# CONFIG_TAC is not set
|
||||
CONFIG_TAIL=y
|
||||
@@ -336,7 +336,7 @@ CONFIG_TEST=y
|
||||
CONFIG_TEST1=y
|
||||
CONFIG_TEST2=y
|
||||
CONFIG_FEATURE_TEST_64=y
|
||||
# CONFIG_TIMEOUT is not set
|
||||
CONFIG_TIMEOUT=y
|
||||
CONFIG_TOUCH=y
|
||||
CONFIG_FEATURE_TOUCH_SUSV3=y
|
||||
CONFIG_TR=y
|
||||
@@ -357,7 +357,7 @@ CONFIG_BASE32=y
|
||||
CONFIG_BASE64=y
|
||||
CONFIG_UUENCODE=y
|
||||
CONFIG_WC=y
|
||||
# CONFIG_FEATURE_WC_LARGE is not set
|
||||
CONFIG_FEATURE_WC_LARGE=y
|
||||
CONFIG_WHO=y
|
||||
CONFIG_W=y
|
||||
CONFIG_USERS=y
|
||||
|
||||
@@ -2,8 +2,6 @@
|
||||
|
||||
set -e
|
||||
|
||||
GIT_VERSION=$(git -C "$BR2_EXTERNAL_INFIX_PATH" describe --always --dirty --tags)
|
||||
|
||||
name=$1
|
||||
compat=$2
|
||||
sign=$3
|
||||
@@ -26,7 +24,7 @@ cp -f "$BINARIES_DIR/rootfs.itbh" "$work/rootfs.itbh"
|
||||
cat >"$work/manifest.raucm" <<EOF
|
||||
[update]
|
||||
compatible=${compat}
|
||||
version=${GIT_VERSION}
|
||||
version=${INFIX_VERSION}
|
||||
|
||||
[bundle]
|
||||
format=verity
|
||||
|
||||
@@ -39,22 +39,6 @@ if [ -n "${ID_LIKE}" ]; then
|
||||
ID="${ID} ${ID_LIKE}"
|
||||
fi
|
||||
|
||||
if [ -z "$GIT_VERSION" ]; then
|
||||
infix_path="$BR2_EXTERNAL_INFIX_PATH"
|
||||
if [ -n "$INFIX_OEM_PATH" ]; then
|
||||
# Use version from br2-external OEM:ing Infix
|
||||
infix_path="$INFIX_OEM_PATH"
|
||||
fi
|
||||
GIT_VERSION=$(git -C "$infix_path" describe --always --dirty --tags)
|
||||
fi
|
||||
|
||||
# Override VERSION in /etc/os-release and filenames for release builds
|
||||
if [ -n "$INFIX_RELEASE" ]; then
|
||||
VERSION="$INFIX_RELEASE"
|
||||
else
|
||||
VERSION=$GIT_VERSION
|
||||
fi
|
||||
|
||||
if [ -n "$INFIX_IMAGE_ID" ]; then
|
||||
NAME="$INFIX_IMAGE_ID"
|
||||
else
|
||||
@@ -71,12 +55,12 @@ rm -f "$TARGET_DIR/etc/os-release"
|
||||
{
|
||||
echo "NAME=\"$INFIX_NAME\""
|
||||
echo "ID=$INFIX_ID"
|
||||
echo "PRETTY_NAME=\"$INFIX_TAGLINE $VERSION\""
|
||||
echo "PRETTY_NAME=\"$INFIX_TAGLINE $INFIX_VERSION\""
|
||||
echo "ID_LIKE=\"${ID}\""
|
||||
echo "DEFAULT_HOSTNAME=$BR2_TARGET_GENERIC_HOSTNAME"
|
||||
echo "VERSION=\"${VERSION}\""
|
||||
echo "VERSION_ID=${VERSION}"
|
||||
echo "BUILD_ID=\"${GIT_VERSION}\""
|
||||
echo "VERSION=\"${INFIX_VERSION}\""
|
||||
echo "VERSION_ID=${INFIX_VERSION}"
|
||||
echo "BUILD_ID=\"${INFIX_BUILD_ID}\""
|
||||
if [ -n "$INFIX_IMAGE_ID" ]; then
|
||||
echo "IMAGE_ID=\"$INFIX_IMAGE_ID\""
|
||||
fi
|
||||
@@ -102,7 +86,7 @@ rm -f "$TARGET_DIR/etc/os-release"
|
||||
fi
|
||||
} > "$TARGET_DIR/etc/os-release"
|
||||
|
||||
echo "$INFIX_TAGLINE $VERSION -- $(date +"%b %e %H:%M %Z %Y")" > "$TARGET_DIR/etc/version"
|
||||
echo "$INFIX_TAGLINE $INFIX_VERSION -- $(date +"%b %e %H:%M %Z %Y")" > "$TARGET_DIR/etc/version"
|
||||
|
||||
# In case of ambguities, this is what the image was built from
|
||||
cp "$BR2_CONFIG" "$TARGET_DIR/usr/share/infix/config"
|
||||
|
||||
@@ -90,7 +90,7 @@ if [ "$BR2_TARGET_ROOTFS_SQUASHFS" = "y" ]; then
|
||||
rel=$(ver)
|
||||
ln -sf rootfs.squashfs "$BINARIES_DIR/${NAME}${rel}.img"
|
||||
if [ -n "$rel" ]; then
|
||||
ln -sf "$BINARIES_DIR/${NAME}${rel}.img" "$BINARIES_DIR/${NAME}.img"
|
||||
ln -sf "${NAME}${rel}.img" "$BINARIES_DIR/${NAME}.img"
|
||||
fi
|
||||
fi
|
||||
|
||||
|
||||
@@ -66,7 +66,7 @@ endchoice
|
||||
|
||||
config QEMU_MACHINE
|
||||
string "Select emulated machine"
|
||||
default "qemu-system-aarch64 -M virt,accel=kvm:tcg -cpu max" if QEMU_aarch64
|
||||
default "qemu-system-aarch64 -M virt,accel=kvm:tcg -cpu max,pauth-impdef=on" if QEMU_aarch64
|
||||
default "qemu-system-x86_64 -M pc,accel=kvm:tcg -cpu max" if QEMU_x86_64
|
||||
help
|
||||
You should not have to change this setting, although you may
|
||||
|
||||
@@ -9,46 +9,20 @@
|
||||
# $3 IP adddress
|
||||
|
||||
PATH="$PATH:/usr/bin:/usr/sbin:/bin:/sbin"
|
||||
NAME="/etc/frr/static.d/$2-zeroconf.conf"
|
||||
NEXT="${NAME}+"
|
||||
|
||||
log()
|
||||
{
|
||||
logger -I $$ -t zeroconf -p user.notice "$*"
|
||||
}
|
||||
|
||||
# Reduce changes needed by comparing with previous route(s)
|
||||
act()
|
||||
{
|
||||
case $1 in
|
||||
add)
|
||||
echo "! Generated by avahi-autoipd" > "$NEXT"
|
||||
echo "ip route 0.0.0.0/0 $2 254" >> "$NEXT"
|
||||
cmp -s "$NAME" "$NEXT" && return
|
||||
mv "$NEXT" "$NAME"
|
||||
;;
|
||||
del)
|
||||
[ -f "$NAME" ] || return
|
||||
rm "$NAME"
|
||||
;;
|
||||
*)
|
||||
return
|
||||
;;
|
||||
esac
|
||||
|
||||
initctl -nbq restart staticd
|
||||
}
|
||||
|
||||
case "$1" in
|
||||
BIND)
|
||||
ip addr flush dev "$2" proto random
|
||||
ip addr add "$3"/16 brd 169.254.255.255 scope link dev "$2" proto random
|
||||
act add "$2"
|
||||
log "set ipv4ll $3 on iface $2"
|
||||
;;
|
||||
|
||||
CONFLICT|UNBIND|STOP)
|
||||
act del "$2"
|
||||
ip addr flush dev "$2" proto random
|
||||
log "clr ipv4ll on iface $2"
|
||||
;;
|
||||
|
||||
@@ -3,16 +3,19 @@
|
||||
# and similar events feed servers and configuration to dnsmasq.
|
||||
domain-needed
|
||||
|
||||
# Only listen to loopback (local system)
|
||||
interface=lo
|
||||
bind-dynamic
|
||||
#listen-address=127.0.0.1,::1
|
||||
|
||||
# Allow configuration and cache clear over D-Bus
|
||||
enable-dbus
|
||||
|
||||
# Disable the following dnsmasq default DHCP options
|
||||
#dhcp-option=option:netmask
|
||||
#dhcp-option=28 # option:broadcast
|
||||
#dhcp-option=option:domain-name
|
||||
dhcp-option=option:router
|
||||
dhcp-option=option:dns-server
|
||||
dhcp-option=12 # option:hostname
|
||||
|
||||
# Generated by openresolv
|
||||
resolv-file=/var/lib/misc/resolv.conf
|
||||
|
||||
# Include all files in a directory which end in .conf
|
||||
conf-dir=/etc/dnsmasq.d/,*.conf
|
||||
|
||||
|
||||
@@ -1,4 +1,7 @@
|
||||
task name:container-%i :setup \
|
||||
[2345] container -n %i setup -- Setup container %i
|
||||
sysv <!usr/container:%i> :%i pid:!/run/container:%i.pid log:prio:local1,tag:%i kill:10 \
|
||||
[2345] container -n %i -- container %i
|
||||
# Start a container instance (%i) and redirect logs to /log/container
|
||||
# Give podman enough time to properly shut down the container. Every
|
||||
# time we start a container we run the setup stage, disable the Finit
|
||||
# timeout to allow the setup stage to run to completion.
|
||||
sysv log:prio:local1,tag:%i kill:10 pid:!/run/container:%i.pid \
|
||||
pre:0,/usr/sbin/container cleanup:0,/usr/sbin/container \
|
||||
[2345] <!> :%i container -n %i -- container %i
|
||||
|
||||
@@ -0,0 +1,9 @@
|
||||
# A single mstpd instance can manage multiple bridges, which are
|
||||
# dynamically added/removed by the kernel via the /sbin/bridge-stp
|
||||
# usermode helper. We use a manual service so that confd can
|
||||
# enable/disable it without an initctl barrier, since it needs to
|
||||
# already be running when a bridge interface with spanning tree
|
||||
# enabled is created.
|
||||
|
||||
service env:-/etc/default/mstpd manual:yes \
|
||||
[S0123456789] mstpd $MSTPD_ARGS -- Spanning Tree daemon
|
||||
@@ -1 +1 @@
|
||||
service [2345] <!> ttyd -i lo -p 8001 login -- Web terminal daemon (ttyd)
|
||||
service [2345] <!> ttyd -i lo -W -p 8001 login -- Web terminal daemon (ttyd)
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
../available/mstpd.conf
|
||||
@@ -1,3 +0,0 @@
|
||||
HostKey /var/lib/ssh/ssh_host_rsa_key
|
||||
HostKey /var/lib/ssh/ssh_host_ecdsa_key
|
||||
HostKey /var/lib/ssh/ssh_host_ed25519_key
|
||||
@@ -1,3 +0,0 @@
|
||||
net.ipv4.ip_forward=1
|
||||
net.ipv4.ip_forward_update_priority=0
|
||||
net.ipv6.conf.all.forwarding=1
|
||||
@@ -1 +1,32 @@
|
||||
# Router defaults
|
||||
net.ipv4.conf.default.rp_filter=0
|
||||
net.ipv4.conf.all.rp_filter=0
|
||||
|
||||
net.ipv4.conf.lo.rp_filter=0
|
||||
|
||||
net.ipv4.icmp_errors_use_inbound_ifaddr=1
|
||||
net.ipv4.conf.all.ignore_routes_with_linkdown=1
|
||||
|
||||
# Use neigh information on selection of nexthop for multipath hops
|
||||
net.ipv4.fib_multipath_use_neigh=1
|
||||
|
||||
# Sane ARP defaults for a switch/router
|
||||
net.ipv4.conf.default.arp_announce=2
|
||||
net.ipv4.conf.all.arp_announce=2
|
||||
|
||||
net.ipv4.conf.default.arp_notify=1
|
||||
net.ipv4.conf.all.arp_notify=1
|
||||
|
||||
net.ipv4.conf.default.arp_ignore=1
|
||||
net.ipv4.conf.all.arp_ignore=1
|
||||
|
||||
# IP Routing
|
||||
net.ipv4.ip_forward=1
|
||||
net.ipv4.ip_forward_update_priority=0
|
||||
|
||||
net.ipv4.conf.all.forwarding=0
|
||||
net.ipv4.conf.default.forwarding=0
|
||||
|
||||
# Multicast group subscriptions
|
||||
net.ipv4.igmp_max_memberships=1000
|
||||
net.ipv4.neigh.default.mcast_solicit=10
|
||||
|
||||
@@ -1,5 +1,23 @@
|
||||
net.ipv6.conf.all.forwarding=1
|
||||
# Router defaults
|
||||
net.ipv6.route.max_size=131072
|
||||
net.ipv6.conf.all.ignore_routes_with_linkdown=1
|
||||
|
||||
# IP Routing is disabled by default, enabled globally, and per
|
||||
# interface, for each interface in confd. See also accept_ra.
|
||||
net.ipv6.conf.all.forwarding=0
|
||||
net.ipv6.conf.default.forwarding=0
|
||||
|
||||
# Accept router advertisements even when forwarding is enabled
|
||||
net.ipv6.conf.all.accept_ra=2
|
||||
net.ipv6.conf.default.accept_ra=2
|
||||
|
||||
# IPv6 SLAAC
|
||||
net.ipv6.conf.all.autoconf=0
|
||||
net.ipv6.conf.default.autoconf=0
|
||||
|
||||
# Keep permanent addresses on an admin down
|
||||
net.ipv6.conf.all.keep_addr_on_down=1
|
||||
net.ipv6.conf.default.keep_addr_on_down=1
|
||||
|
||||
# Multicast group subscriptions
|
||||
net.ipv6.mld_max_msf=512
|
||||
|
||||
@@ -0,0 +1,145 @@
|
||||
Many of the defaults here are are taken from the Frr recommendations [1].
|
||||
Below are relevant excerpts from the kernel documentation.
|
||||
|
||||
|
||||
accept_ra, accept Router Advertisements; autoconfigure using them, also
|
||||
determines whether or not to transmit Router Solicitations.
|
||||
If and only if the functional setting is to accept Router
|
||||
Advertisements, Router Solicitations will be transmitted.
|
||||
|
||||
0 - Do not accept Router Advertisements.
|
||||
|
||||
1 - Accept Router Advertisements if forwarding is disabled.
|
||||
|
||||
2 - Overrule forwarding behaviour. Accept Router Advertisements even
|
||||
if forwarding is enabled.
|
||||
|
||||
Default:
|
||||
- enabled if local forwarding is disabled
|
||||
- disabled if local forwarding is enabled
|
||||
|
||||
|
||||
accept_ra_pinfo, learn Prefix Information in Router Advertisement.
|
||||
|
||||
Default:
|
||||
- enabled if accept_ra is enabled
|
||||
- disabled if accept_ra is disabled
|
||||
|
||||
|
||||
autoconf, autoconfigure IPv6 addresses using Prefix Information in
|
||||
Router Advertisements.
|
||||
|
||||
Default:
|
||||
- enabled if accept_ra_pinfo is enabled
|
||||
- disabled if accept_ra_pinfo is disabled
|
||||
|
||||
|
||||
arp_announce, define restriction level for announcing the local source
|
||||
address from IP packets in ARP requests sent on interface:
|
||||
|
||||
0 - (default) Use any local address, configured on any interface
|
||||
|
||||
1 - Try to avoid local addresses that are not in the target’s subnet
|
||||
for this interface. Useful when target hosts reachable via this
|
||||
interface require the source IP address in ARP requests to be part
|
||||
of their logical network configured on the receiving interface.
|
||||
When we generate the request we will check all our subnets that
|
||||
include the target IP and will preserve the source address if it
|
||||
is from such subnet. If there is no such subnet we select source
|
||||
address according to the rules for level 2.
|
||||
|
||||
2 - Always use the best local address for this target. In this mode we
|
||||
ignore the source address in the IP packet and try to select local
|
||||
address that we prefer for talks with the target host. Such local
|
||||
address is selected by looking for primary IP addresses on all our
|
||||
subnets on the outgoing interface that include the target address.
|
||||
If no suitable local address is found we select the first local
|
||||
address we have on the outgoing interface or on all other
|
||||
interfaces, with the hope we will receive reply for our request
|
||||
and even sometimes no matter the source IP address we announce.
|
||||
|
||||
|
||||
arp_notify, define mode for notification of address and device changes.
|
||||
|
||||
0 - (default): do nothing
|
||||
1 - generate gratuitous arp requests when device is brought up or
|
||||
hardware address changes.
|
||||
|
||||
|
||||
arp_ignore, define different modes for sending replies in response to
|
||||
received ARP requests that resolve local target addresses:
|
||||
|
||||
0 - (default): reply for any local target IP address, configured on
|
||||
any interface
|
||||
|
||||
1 - reply only if the target IP address is a local address configured
|
||||
on the incoming interface
|
||||
|
||||
2 - reply only if the target IP address is local address configured on
|
||||
the incoming interface and both with the sender’s IP address are part
|
||||
from same subnet on this interface
|
||||
|
||||
3 - do not reply for local addresses configured with scope host, only
|
||||
resolutions for global and link addresses are replied
|
||||
|
||||
4-7 - reserved
|
||||
|
||||
8 - do not reply for all local addresses
|
||||
|
||||
|
||||
arp_accept, define behavior for accepting gratuitous ARP (garp) frames
|
||||
from devices that are not already present in the ARP table:
|
||||
|
||||
0 - don’t create new entries in the ARP table
|
||||
|
||||
1 - create new entries in the ARP table
|
||||
|
||||
2 - create new entries only if the source IP address is in the same
|
||||
subnet as an address configured on the interface that received
|
||||
the garp message.
|
||||
|
||||
Both replies and requests type gratuitous arp will trigger the ARP
|
||||
table to be updated, if this setting is on. If the ARP table already
|
||||
contains the IP address of the gratuitous arp frame, the arp table
|
||||
will be updated regardless if this setting is on or off.
|
||||
|
||||
|
||||
icmp_errors_use_inbound_ifaddr
|
||||
|
||||
0 - (default): icmp error messages are sent with the primary address
|
||||
of the exiting interface.
|
||||
|
||||
1 - the message will be sent with the primary address of the interface
|
||||
that received the packet that caused the icmp error. This is the
|
||||
behaviour many network administrators will expect from a router.
|
||||
And it can make debugging complicated network layouts much easier.
|
||||
|
||||
Note, if no primary address exists for the interface selected, then
|
||||
the primary address of the first non-loopback interface that has one
|
||||
will be used regardless of this setting.
|
||||
|
||||
|
||||
rp_filter, reverse path source filtering:
|
||||
|
||||
0 - (default): no source validation.
|
||||
|
||||
1 - Strict mode as defined in RFC3704, 'Strict Reverse Path'. Each
|
||||
incoming packet is tested against the FIB and if the interface is
|
||||
not the best reverse path the packet check will fail. By default
|
||||
failed packets are discarded.
|
||||
|
||||
2 - Loose mode as defined in RFC3704, 'Loose Reverse Path'. Each
|
||||
incoming packet’s source address is also tested against the FIB
|
||||
and if the source address is not reachable via any interface the
|
||||
packet check will fail.
|
||||
|
||||
Current recommended practice in RFC3704 is to enable strict mode to
|
||||
prevent IP spoofing from DDos attacks. If using asymmetric routing or
|
||||
other complicated routing, then loose mode is recommended.
|
||||
|
||||
The max value from conf/{all,interface}/rp_filter is used when doing
|
||||
source validation on the {interface}.
|
||||
|
||||
|
||||
|
||||
[1]: https://github.com/FRRouting/frr/blob/master/doc/user/Useful_Sysctl_Settings.md
|
||||
@@ -21,7 +21,11 @@ dir()
|
||||
if [ -d "$1" ]; then
|
||||
dir "$1"
|
||||
else
|
||||
dir "$HOME"
|
||||
if [ "$USER" = "root" ]; then
|
||||
dir "$HOME"
|
||||
else
|
||||
dir "/home/$USER"
|
||||
fi
|
||||
dir "/cfg"
|
||||
dir "/log"
|
||||
fi
|
||||
|
||||
@@ -70,12 +70,14 @@ options:
|
||||
-p Show plain output, no bells or whistles
|
||||
|
||||
commands:
|
||||
dhcp Show DHCP server
|
||||
port PORT Show port configuration and link information
|
||||
ports Show ports available for bridging
|
||||
vlans Show port groups in bridge
|
||||
ifaces Show interfaces and their addresses
|
||||
fdb Show forwarding database (unicast)
|
||||
mdb Show multicast forwarding database
|
||||
stp Show spanning tree status
|
||||
ip addr Show IPv4 addresses
|
||||
route Show routing table
|
||||
ipv6 addr Show IPv6 addresses
|
||||
@@ -87,6 +89,41 @@ commands:
|
||||
EOF
|
||||
}
|
||||
|
||||
is_dhcp_running()
|
||||
{
|
||||
sysrepocfg -X -f json -m infix-dhcp-server | jq -r '
|
||||
."infix-dhcp-server:dhcp-server".enabled as $global |
|
||||
if ."infix-dhcp-server:dhcp-server".subnet? then
|
||||
(."infix-dhcp-server:dhcp-server".subnet[] |
|
||||
select(.enabled != false)) |
|
||||
if $global != false and . then "true" else "false" end
|
||||
else "false" end
|
||||
' 2>/dev/null | grep -q true
|
||||
}
|
||||
|
||||
dhcp()
|
||||
{
|
||||
if ! is_dhcp_running; then
|
||||
echo "DHCP server not enabled."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
case $1 in
|
||||
detail)
|
||||
sysrepocfg -f json -X -d operational -m infix-dhcp-server | \
|
||||
jq -C .
|
||||
;;
|
||||
stat*)
|
||||
sysrepocfg -f json -X -d operational -m infix-dhcp-server | \
|
||||
/usr/libexec/statd/cli-pretty "show-dhcp-server" -s
|
||||
;;
|
||||
*)
|
||||
sysrepocfg -f json -X -d operational -m infix-dhcp-server | \
|
||||
/usr/libexec/statd/cli-pretty "show-dhcp-server"
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
# Usage 1: show port eth0
|
||||
# Usage 2: show port
|
||||
# Usage 3: show ports
|
||||
@@ -188,6 +225,12 @@ rstp()
|
||||
mstpctl showport br0
|
||||
}
|
||||
|
||||
stp()
|
||||
{
|
||||
sysrepocfg -f json -X -d operational -m ietf-interfaces | \
|
||||
/usr/libexec/statd/cli-pretty "show-bridge-stp"
|
||||
}
|
||||
|
||||
fdb()
|
||||
{
|
||||
bridge $bopt fdb show
|
||||
@@ -288,6 +331,9 @@ case $cmd in
|
||||
help)
|
||||
usage
|
||||
;;
|
||||
dhcp | dhcp-server)
|
||||
dhcp $*
|
||||
;;
|
||||
port*)
|
||||
ports $*
|
||||
;;
|
||||
@@ -353,6 +399,9 @@ case $cmd in
|
||||
span*)
|
||||
rstp
|
||||
;;
|
||||
stp*)
|
||||
stp
|
||||
;;
|
||||
sys*)
|
||||
system
|
||||
;;
|
||||
|
||||
@@ -39,8 +39,10 @@ fi
|
||||
# init scripts to prevent select services from starting.
|
||||
initctl -nbq cond set led
|
||||
|
||||
note "Calling runparts $PRODUCT_INIT/S[0-9]+.* start"
|
||||
/usr/libexec/finit/runparts -bsp "$PRODUCT_INIT"
|
||||
if [ -d "$PRODUCT_INIT" ]; then
|
||||
note "Calling runparts $PRODUCT_INIT/S[0-9]+.* start"
|
||||
/usr/libexec/finit/runparts -bsp "$PRODUCT_INIT"
|
||||
fi
|
||||
|
||||
# Product specific init done.
|
||||
initctl -nbq cond set product
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
#!/bin/sh
|
||||
# Initialize speed/duplex of virtio interfaces
|
||||
# For virtual test systems (lacp tests)
|
||||
|
||||
ifaces=$(ip -d -json link show | jq -r '.[] | select(.parentbus == "virtio") | .ifname')
|
||||
for iface in $ifaces; do
|
||||
ethtool -s "$iface" speed 1000 duplex full
|
||||
done
|
||||
@@ -4,10 +4,14 @@
|
||||
# the migrate tool inserts old version in name before .cfg extension.
|
||||
CONFIG_FILE="/cfg/startup-config.cfg"
|
||||
BACKUP_FILE="/cfg/backup/startup-config.cfg"
|
||||
mkdir -p "$(dirname "$BACKUP_FILE")"
|
||||
BACKUP_DIR="$(dirname "$BACKUP_FILE")"
|
||||
|
||||
mkdir -p "$BACKUP_DIR"
|
||||
chown root:wheel "$BACKUP_DIR"
|
||||
chmod 0770 "$BACKUP_DIR"
|
||||
|
||||
if [ ! -f "$CONFIG_FILE" ]; then
|
||||
note "No $(basename "$CONFIG_FILE" .cfg) yet, likely factory reset."
|
||||
logger -I $$ -k -p user.notice -t $(basename "$0") "No $(basename "$CONFIG_FILE" .cfg) yet, likely factory reset."
|
||||
exit 0
|
||||
elif migrate -cq "$CONFIG_FILE"; then
|
||||
exit 0
|
||||
|
||||
+24
@@ -0,0 +1,24 @@
|
||||
#!/bin/bash
|
||||
# Store and convert RSA PUBLIC/PRIVATE KEYs to be able to use them in
|
||||
# OpenSSHd.
|
||||
set -e
|
||||
|
||||
NAME="$1"
|
||||
DIR="$2"
|
||||
PUBLIC="$3"
|
||||
PRIVATE="$4"
|
||||
TMP="$(mktemp)"
|
||||
|
||||
echo -e '-----BEGIN RSA PRIVATE KEY-----' > "$DIR/$NAME"
|
||||
echo "$PRIVATE" >> "$DIR/$NAME"
|
||||
echo -e '-----END RSA PRIVATE KEY-----' >> "$DIR/$NAME"
|
||||
|
||||
echo -e "-----BEGIN RSA PUBLIC KEY-----" > "$TMP"
|
||||
echo -e "$PUBLIC" >> "$TMP"
|
||||
echo -e "-----END RSA PUBLIC KEY-----" >> "$TMP"
|
||||
|
||||
ssh-keygen -i -m PKCS8 -f "$TMP" > "$DIR/$NAME.pub"
|
||||
chmod 0600 "$DIR/$NAME.pub"
|
||||
chmod 0600 "$DIR/$NAME"
|
||||
chown sshd:sshd "$DIR/$NAME.pub"
|
||||
chown sshd:sshd "$DIR/$NAME"
|
||||
@@ -1,4 +1,4 @@
|
||||
#!/bin/sh
|
||||
#!/bin/bash
|
||||
# This script can be used to start, stop, create, and delete containers.
|
||||
# It is what confd use, with the Finit container@.conf template, to set
|
||||
# up, run, and delete containers.
|
||||
@@ -9,6 +9,7 @@
|
||||
DOWNLOADS=/var/lib/containers/oci
|
||||
BUILTIN=/lib/oci
|
||||
TMPDIR=/var/tmp
|
||||
container=$0
|
||||
checksum=""
|
||||
extracted=
|
||||
timeout=30
|
||||
@@ -38,6 +39,11 @@ err()
|
||||
[ "$rc" -eq 0 ] || exit "$rc"
|
||||
}
|
||||
|
||||
pidfn()
|
||||
{
|
||||
echo "/run/containers/${1}.pid"
|
||||
}
|
||||
|
||||
check()
|
||||
{
|
||||
file=$1
|
||||
@@ -109,33 +115,34 @@ EOF
|
||||
# If there are more index files, this function does not handle them.
|
||||
unpack_archive()
|
||||
{
|
||||
image=$1
|
||||
name=$2
|
||||
uri=$1
|
||||
tag=$2
|
||||
img=$(basename "$uri")
|
||||
|
||||
# Supported transports for load and create
|
||||
case "$image" in
|
||||
case "$uri" in
|
||||
oci:*) # Unpacked OCI image
|
||||
file=${image#oci:}
|
||||
file=${uri#oci:}
|
||||
;;
|
||||
oci-archive:*) # Packed OCI image, .tar or .tar.gz format
|
||||
file=${image#oci-archive:}
|
||||
file=${uri#oci-archive:}
|
||||
;;
|
||||
ftp://* | http://* | https://*)
|
||||
if ! file=$(fetch "$image"); then
|
||||
if ! file=$(fetch "$uri"); then
|
||||
return 1
|
||||
fi
|
||||
;;
|
||||
*) # docker://*, docker-archive:*, or URL
|
||||
if podman image exists "$image"; then
|
||||
echo "$image"
|
||||
if podman image exists "$img"; then
|
||||
echo "$img"
|
||||
return 0
|
||||
fi
|
||||
# XXX: use --retry=0 with Podman 5.0 or later.
|
||||
if ! id=$(podman pull --quiet "$image"); then
|
||||
log "Failed pulling $image"
|
||||
if ! id=$(podman pull --quiet "$uri"); then
|
||||
log "Failed pulling $uri"
|
||||
return 1
|
||||
fi
|
||||
# Echo image name to caller
|
||||
# Echo image tag to caller
|
||||
podman images --filter id="$id" --format "{{.Repository}}:{{.Tag}}"
|
||||
return 0
|
||||
;;
|
||||
@@ -147,7 +154,7 @@ unpack_archive()
|
||||
elif [ -e "$BUILTIN/$file" ]; then
|
||||
file="$BUILTIN/$file"
|
||||
else
|
||||
err 1 "cannot find OCI archive $file in search path."
|
||||
err 1 "cannot find OCI archive $file in URI $uri"
|
||||
fi
|
||||
fi
|
||||
|
||||
@@ -171,8 +178,8 @@ unpack_archive()
|
||||
|
||||
dir=$(dirname "$index")
|
||||
if echo "$dir" | grep -q ":"; then
|
||||
if [ -z "$name" ]; then
|
||||
name="$dir"
|
||||
if [ -z "$tag" ]; then
|
||||
tag="$dir"
|
||||
fi
|
||||
sanitized_dir=$(echo "$dir" | cut -d':' -f1)
|
||||
mv "$dir" "$sanitized_dir" || err 1 "failed renaming $dir to $sanitized_dir"
|
||||
@@ -188,21 +195,21 @@ unpack_archive()
|
||||
rm -rf "$dir"
|
||||
fi
|
||||
|
||||
# Rename image from podman default $dir:latest
|
||||
if [ -n "$name" ]; then
|
||||
podman tag "$dir" "$name" >/dev/null
|
||||
podman rmi "$dir" >/dev/null
|
||||
# Retag image from podman default $dir:latest
|
||||
if [ -n "$tag" ]; then
|
||||
podman tag "$dir" "$tag" >/dev/null
|
||||
podman rmi "$dir" >/dev/null
|
||||
else
|
||||
name=$dir
|
||||
tag=$dir
|
||||
fi
|
||||
|
||||
echo "$name"
|
||||
echo "$tag"
|
||||
}
|
||||
|
||||
running()
|
||||
{
|
||||
run=$(podman inspect "$1" 2>/dev/null |jq .[].State.Running)
|
||||
[ "$run" = "true" ] && return 0
|
||||
status=$(podman inspect -f '{{.State.Status}}' "$1" 2>/dev/null)
|
||||
[ "$status" = "running" ] && return 0
|
||||
return 1
|
||||
}
|
||||
|
||||
@@ -226,14 +233,14 @@ create()
|
||||
fi
|
||||
|
||||
if [ -z "$logging" ]; then
|
||||
logging="--log-driver none"
|
||||
logging="--log-driver syslog"
|
||||
fi
|
||||
|
||||
# When we get here we've already fetched, or pulled, the image
|
||||
args="$args --read-only --replace --quiet --cgroup-parent=containers $caps"
|
||||
args="$args --restart=$restart --systemd=false --tz=local $privileged"
|
||||
args="$args $vol $mount $hostname $entrypoint $env $port $logging"
|
||||
pidfn=/run/container:${name}.pid
|
||||
pidfile=/run/container:${name}.pid
|
||||
|
||||
[ -n "$quiet" ] || log "---------------------------------------"
|
||||
[ -n "$quiet" ] || log "Got name: $name image: $image"
|
||||
@@ -256,8 +263,8 @@ create()
|
||||
fi
|
||||
|
||||
# shellcheck disable=SC2048
|
||||
log "podman create --name $name --conmon-pidfile=$pidfn $args $image $*"
|
||||
if podman create --name "$name" --conmon-pidfile="$pidfn" $args "$image" $*; then
|
||||
log "podman create --name $name --conmon-pidfile=$pidfile $args $image $*"
|
||||
if podman create --name "$name" --conmon-pidfile="$pidfile" $args "$image" $*; then
|
||||
[ -n "$quiet" ] || log "Successfully created container $name from $image"
|
||||
[ -n "$manual" ] || start "$name"
|
||||
|
||||
@@ -272,7 +279,6 @@ create()
|
||||
delete()
|
||||
{
|
||||
name=$1
|
||||
image=$2
|
||||
|
||||
if [ -z "$name" ]; then
|
||||
echo "Usage:"
|
||||
@@ -281,9 +287,11 @@ delete()
|
||||
fi
|
||||
|
||||
# Should already be stopped, but if not ...
|
||||
container stop "$name"
|
||||
log "$name: should already be stopped, double checking ..."
|
||||
container stop "$name" >/dev/null
|
||||
|
||||
while running "$name"; do
|
||||
log "$name: still running, waiting for it to stop ..."
|
||||
_=$((timeout -= 1))
|
||||
if [ $timeout -le 0 ]; then
|
||||
err 1 "timed out waiting for container $1 to stop before deleting it."
|
||||
@@ -291,6 +299,7 @@ delete()
|
||||
sleep 1
|
||||
done
|
||||
|
||||
log "$name: calling podman rm -vif ..."
|
||||
podman rm -vif "$name" >/dev/null 2>&1
|
||||
[ -n "$quiet" ] || log "Container $name has been removed."
|
||||
}
|
||||
@@ -315,7 +324,7 @@ start()
|
||||
return
|
||||
fi
|
||||
|
||||
initctl -bq cond set "container:$name"
|
||||
initctl start container:$name
|
||||
# Real work is done by wrap() courtesy of finit sysv emulation
|
||||
}
|
||||
|
||||
@@ -328,7 +337,7 @@ stop()
|
||||
return
|
||||
fi
|
||||
|
||||
initctl -bq cond clr "container:$name"
|
||||
initctl stop container:$name
|
||||
# Real work is done by wrap() courtesy of finit sysv emulation
|
||||
}
|
||||
|
||||
@@ -336,8 +345,27 @@ wrap()
|
||||
{
|
||||
name=$1
|
||||
cmd=$2
|
||||
pidfile=$(pidfn "$name")
|
||||
|
||||
podman "$cmd" "$name"
|
||||
# Containers have three phases: setup, running, and teardown.
|
||||
|
||||
# The setup phase may run forever in the background trying to fetch
|
||||
# the image. It saves its PID in /run/containers/${name}.pid
|
||||
if [ "$cmd" = "stop" ] && [ -f "$pidfile" ]; then
|
||||
pid=$(cat "$pidfile")
|
||||
|
||||
# Check if setup is still running ...
|
||||
if kill -0 "$pid" 2>/dev/null; then
|
||||
kill "$pid"
|
||||
wait "$pid" 2>/dev/null
|
||||
fi
|
||||
|
||||
rm -f "$pidfile"
|
||||
return 0
|
||||
fi
|
||||
|
||||
# Skip "echo $name" from podman start in log
|
||||
podman "$cmd" "$name" >/dev/null
|
||||
}
|
||||
|
||||
# Removes network $1 from all containers
|
||||
@@ -370,7 +398,14 @@ netrestart()
|
||||
|
||||
cleanup()
|
||||
{
|
||||
pidfile=$(pidfn "$name")
|
||||
|
||||
log "Received signal, exiting."
|
||||
if [ -n "$name" ] && [ -f "$pidfile" ]; then
|
||||
log "$name: in setup phase, removing $pidfile ..."
|
||||
rm -f "$pidfile"
|
||||
fi
|
||||
|
||||
exit 1
|
||||
}
|
||||
|
||||
@@ -426,11 +461,12 @@ commands:
|
||||
run NAME [CMD] Run a container interactively, with an optional command
|
||||
save IMAGE FILE Save a container image to an OCI tarball FILE[.tar.gz]
|
||||
setup NAME Create and set up container as a Finit task
|
||||
shell Start a shell inside a container
|
||||
shell [CMD] Start a shell, or run CMD, inside a container
|
||||
show [image | volume] Show containers, images, or volumes
|
||||
stat Show continuous stats about containers (Ctrl-C aborts)
|
||||
start [NAME] Start a container, see -n
|
||||
stop [NAME] Stop a container, see -n
|
||||
upgrade NAME Upgrade a running container (stop, pull, restart)
|
||||
volume [prune] Prune unused volumes
|
||||
EOF
|
||||
}
|
||||
@@ -568,7 +604,7 @@ if [ -n "$cmd" ]; then
|
||||
shift
|
||||
fi
|
||||
|
||||
trap cleanup INT TERM
|
||||
trap cleanup INT HUP TERM
|
||||
|
||||
case $cmd in
|
||||
# Does not work atm., cannot attach to TTY because
|
||||
@@ -582,19 +618,24 @@ case $cmd in
|
||||
;;
|
||||
delete)
|
||||
cmd=$1
|
||||
name=$2
|
||||
[ -n "$name" ] || name=$2
|
||||
if [ "$cmd" = "network" ] && [ -n "$name" ]; then
|
||||
netwrm "$name"
|
||||
else
|
||||
delete "$@"
|
||||
[ -n "$name" ] || name=$1
|
||||
delete "$name"
|
||||
fi
|
||||
;;
|
||||
exec)
|
||||
podman exec -it "$@"
|
||||
if [ -z "$name" ]; then
|
||||
name="$1"
|
||||
shift
|
||||
fi
|
||||
podman exec -i "$name" "$@"
|
||||
;;
|
||||
flush)
|
||||
echo "Cleaning up any lingering containers";
|
||||
podman rm -av
|
||||
podman rm -av $force
|
||||
;;
|
||||
find)
|
||||
cmd=$1
|
||||
@@ -699,18 +740,34 @@ case $cmd in
|
||||
[ -n "$name" ] || err 1 "setup: missing container name."
|
||||
script=/run/containers/${name}.sh
|
||||
[ -x "$script" ] || err 1 "setup: $script does not exist or is not executable."
|
||||
|
||||
# Save our PID in case we get stuck here and someone wants to
|
||||
# stop us, e.g., due to reconfiguration or reboot.
|
||||
pidfile=$(pidfn "${name}")
|
||||
echo $$ > "$pidfile"
|
||||
|
||||
while ! "$script"; do
|
||||
# Wait for address/route changes, or retry every 60 secods
|
||||
# shellcheck disable=2162,3045
|
||||
ip monitor address route | while read -t 60 _; do break; done
|
||||
log "${name}: setup failed, waiting for network changes ..."
|
||||
read -t 60 _ < <(ip monitor address route)
|
||||
|
||||
# On IP address/route changes, wait a few seconds more to ensure
|
||||
# the system has ample time to react and set things up for us.
|
||||
log "${name}: retrying ..."
|
||||
sleep 2
|
||||
done
|
||||
|
||||
rm -f "$pidfile"
|
||||
;;
|
||||
shell)
|
||||
podman exec -it "$1" sh -l
|
||||
if [ -z "$name" ]; then
|
||||
name="$1"
|
||||
shift
|
||||
fi
|
||||
if [ $# -gt 0 ]; then
|
||||
podman exec -i "$name" sh -c "$*"
|
||||
else
|
||||
podman exec -it "$name" sh -l
|
||||
fi
|
||||
;;
|
||||
show)
|
||||
cmd=$1
|
||||
@@ -803,15 +860,15 @@ case $cmd in
|
||||
|
||||
# Likely an OCI archive, or local directory, assume user has updated image.
|
||||
if echo "$img" | grep -Eq '^localhost/'; then
|
||||
file=$(awk '{s=$NF} END{print s}' "$script")
|
||||
echo "Upgrading container ${1} with local archive: $file ..."
|
||||
file=$(awk '/^# meta-image:/ {print $3}' "$script")
|
||||
echo ">> Upgrading container $1 using $file ..."
|
||||
else
|
||||
printf ">> Stopping ... "
|
||||
podman stop "$1"
|
||||
printf ">> "
|
||||
podman pull "$img" || (echo "Failed fetching $img, check your network (settings)."; exit 1)
|
||||
echo ">> Starting $1 ..."
|
||||
fi
|
||||
echo ">> Starting $1 ..."
|
||||
if ! "$script"; then
|
||||
echo ">> Failed recreating container $1"
|
||||
exit 1
|
||||
@@ -831,6 +888,22 @@ case $cmd in
|
||||
esac
|
||||
;;
|
||||
*)
|
||||
if [ -n "$SERVICE_SCRIPT_TYPE" ] && [ -n "$SERVICE_ID" ]; then
|
||||
case "$SERVICE_SCRIPT_TYPE" in
|
||||
pre)
|
||||
# Called as pre-script from Finit service
|
||||
exec $container -q -n "$SERVICE_ID" setup
|
||||
;;
|
||||
cleanup)
|
||||
# Called as cleanup-script from Finit service
|
||||
log "Calling $container -n $SERVICE_ID delete"
|
||||
exec $container -q -n "$SERVICE_ID" delete
|
||||
;;
|
||||
*)
|
||||
false
|
||||
;;
|
||||
esac
|
||||
fi
|
||||
usage
|
||||
exit 1
|
||||
;;
|
||||
|
||||
@@ -145,7 +145,6 @@ CONFIG_BRIDGE_EBT_REDIRECT=m
|
||||
CONFIG_BRIDGE_EBT_SNAT=m
|
||||
CONFIG_BRIDGE_EBT_LOG=m
|
||||
CONFIG_BRIDGE_EBT_NFLOG=m
|
||||
CONFIG_BPFILTER=y
|
||||
CONFIG_BRIDGE=y
|
||||
CONFIG_BRIDGE_VLAN_FILTERING=y
|
||||
CONFIG_BRIDGE_MRP=y
|
||||
|
||||
+1
-1
Submodule buildroot updated: 897bb2cf43...06a983c964
@@ -13,8 +13,8 @@ BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||
BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_ROOTFS_MERGED_USR=y
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_SYSTEM_BIN_SH_BASH=y
|
||||
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
@@ -27,13 +27,9 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.52"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.21"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_DTS_SUPPORT=y
|
||||
BR2_LINUX_KERNEL_INTREE_DTS_NAME="alder/alder styx/dcp-sc-28p-a styx/dcp-sc-28p-b marvell/armada-3720-espressobin marvell/armada-3720-espressobin-emmc marvell/armada-3720-espressobin-v7 marvell/armada-3720-espressobin-v7-emmc marvell/armada-3720-espressobin-ultra marvell/cn9130-crb-A marvell/cn9130-crb-B microchip/sparx5_pcb135_emmc_no_psci"
|
||||
BR2_LINUX_KERNEL_CUSTOM_DTS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/dts"
|
||||
BR2_LINUX_KERNEL_DTB_KEEP_DIRNAME=y
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
||||
BR2_PACKAGE_STRACE=y
|
||||
@@ -59,8 +55,8 @@ BR2_PACKAGE_PYTHON_GUNICORN=y
|
||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||
BR2_PACKAGE_LIBSSH2=y
|
||||
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
||||
BR2_PACKAGE_LIBXCRYPT=y
|
||||
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
||||
BR2_PACKAGE_LIBINPUT=y
|
||||
BR2_PACKAGE_LIBCURL_CURL=y
|
||||
BR2_PACKAGE_NETOPEER2_CLI=y
|
||||
BR2_PACKAGE_NSS_MDNS=y
|
||||
@@ -80,6 +76,7 @@ BR2_PACKAGE_IPROUTE2=y
|
||||
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
||||
BR2_PACKAGE_IPUTILS=y
|
||||
BR2_PACKAGE_LLDPD=y
|
||||
BR2_PACKAGE_MSTPD=y
|
||||
BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||
BR2_PACKAGE_NETSNMP=y
|
||||
@@ -109,6 +106,7 @@ BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_DBUS=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_RAUC_JSON=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
@@ -121,6 +119,7 @@ BR2_PACKAGE_HOST_E2FSPROGS=y
|
||||
BR2_PACKAGE_HOST_ENVIRONMENT_SETUP=y
|
||||
BR2_PACKAGE_HOST_GENEXT2FS=y
|
||||
BR2_PACKAGE_HOST_GENIMAGE=y
|
||||
BR2_PACKAGE_HOST_GO_BIN=y
|
||||
BR2_PACKAGE_HOST_RAUC=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
@@ -130,6 +129,10 @@ INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set u
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_ALDER_ALDER=y
|
||||
BR2_PACKAGE_MARVELL_CN9130_CRB=y
|
||||
BR2_PACKAGE_MARVELL_ESPRESSOBIN=y
|
||||
BR2_PACKAGE_STYX_DCP_SC_28P=y
|
||||
BR2_PACKAGE_CONFD=y
|
||||
BR2_PACKAGE_CONFD_TEST_MODE=y
|
||||
BR2_PACKAGE_CURIOS_HTTPD=y
|
||||
@@ -159,10 +162,10 @@ BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_LIBINPUT=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
DISK_IMAGE_BOOT_BIN=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
DISK_IMAGE_BOOT_BIN=y
|
||||
GNS3_APPLIANCE_RAM=512
|
||||
GNS3_APPLIANCE_IFNUM=10
|
||||
|
||||
@@ -27,13 +27,9 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.52"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.21"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_DTS_SUPPORT=y
|
||||
BR2_LINUX_KERNEL_INTREE_DTS_NAME="alder/alder styx/dcp-sc-28p-a styx/dcp-sc-28p-b marvell/armada-3720-espressobin marvell/armada-3720-espressobin-emmc marvell/armada-3720-espressobin-v7 marvell/armada-3720-espressobin-v7-emmc marvell/armada-3720-espressobin-ultra marvell/cn9130-crb-A marvell/cn9130-crb-B microchip/sparx5_pcb135_emmc_no_psci"
|
||||
BR2_LINUX_KERNEL_CUSTOM_DTS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/dts"
|
||||
BR2_LINUX_KERNEL_DTB_KEEP_DIRNAME=y
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
||||
BR2_PACKAGE_STRACE=y
|
||||
@@ -75,6 +71,7 @@ BR2_PACKAGE_FRR=y
|
||||
BR2_PACKAGE_IPROUTE2=y
|
||||
BR2_PACKAGE_IPUTILS=y
|
||||
BR2_PACKAGE_LLDPD=y
|
||||
BR2_PACKAGE_MSTPD=y
|
||||
BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NGINX=y
|
||||
BR2_PACKAGE_NGINX_HTTP_SSL_MODULE=y
|
||||
@@ -92,6 +89,7 @@ BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_DBUS=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_RAUC_JSON=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
@@ -113,6 +111,10 @@ INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set u
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_ALDER_ALDER=y
|
||||
BR2_PACKAGE_MARVELL_CN9130_CRB=y
|
||||
BR2_PACKAGE_MARVELL_ESPRESSOBIN=y
|
||||
BR2_PACKAGE_STYX_DCP_SC_28P=y
|
||||
BR2_PACKAGE_CONFD=y
|
||||
BR2_PACKAGE_CONFD_TEST_MODE=y
|
||||
BR2_PACKAGE_GENCERT=y
|
||||
@@ -134,6 +136,7 @@ BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_MDNS_ALIAS=y
|
||||
BR2_PACKAGE_LIBINPUT=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
DISK_IMAGE_BOOT_BIN=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -128,6 +128,7 @@ BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_DBUS=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_RAUC_JSON=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
@@ -201,6 +202,7 @@ BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
# GNS3_APPLIANCE is not set
|
||||
|
||||
@@ -88,6 +88,7 @@ BR2_PACKAGE_IPROUTE2=y
|
||||
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
||||
BR2_PACKAGE_IPUTILS=y
|
||||
BR2_PACKAGE_LLDPD=y
|
||||
BR2_PACKAGE_MSTPD=y
|
||||
BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||
BR2_PACKAGE_NETSNMP=y
|
||||
@@ -117,6 +118,7 @@ BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_DBUS=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_RAUC_JSON=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
@@ -191,6 +193,7 @@ BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
# GNS3_APPLIANCE is not set
|
||||
|
||||
@@ -12,8 +12,8 @@ BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||
BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_ROOTFS_MERGED_USR=y
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_SYSTEM_BIN_SH_BASH=y
|
||||
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
@@ -26,7 +26,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INF
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.52"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.21"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -54,10 +54,8 @@ BR2_PACKAGE_PYTHON_GUNICORN=y
|
||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||
BR2_PACKAGE_LIBSSH2=y
|
||||
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
||||
BR2_PACKAGE_LIBXCRYPT=y
|
||||
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
||||
BR2_PACKAGE_LIBCURL_CURL=y
|
||||
BR2_PACKAGE_LIBMNL=y
|
||||
BR2_PACKAGE_NETOPEER2_CLI=y
|
||||
BR2_PACKAGE_NSS_MDNS=y
|
||||
BR2_PACKAGE_LINUX_PAM=y
|
||||
@@ -76,6 +74,7 @@ BR2_PACKAGE_IPROUTE2=y
|
||||
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
||||
BR2_PACKAGE_IPUTILS=y
|
||||
BR2_PACKAGE_LLDPD=y
|
||||
BR2_PACKAGE_MSTPD=y
|
||||
BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||
BR2_PACKAGE_NETSNMP=y
|
||||
@@ -105,6 +104,7 @@ BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_DBUS=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_RAUC_JSON=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
@@ -124,6 +124,7 @@ BR2_PACKAGE_HOST_E2FSPROGS=y
|
||||
BR2_PACKAGE_HOST_ENVIRONMENT_SETUP=y
|
||||
BR2_PACKAGE_HOST_GENEXT2FS=y
|
||||
BR2_PACKAGE_HOST_GENIMAGE=y
|
||||
BR2_PACKAGE_HOST_GO_BIN=y
|
||||
BR2_PACKAGE_HOST_MTOOLS=y
|
||||
BR2_PACKAGE_HOST_RAUC=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
@@ -163,6 +164,7 @@ BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -26,7 +26,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INF
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.52"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.21"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -71,6 +71,7 @@ BR2_PACKAGE_FRR=y
|
||||
BR2_PACKAGE_IPROUTE2=y
|
||||
BR2_PACKAGE_IPUTILS=y
|
||||
BR2_PACKAGE_LLDPD=y
|
||||
BR2_PACKAGE_MSTPD=y
|
||||
BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NGINX=y
|
||||
BR2_PACKAGE_NGINX_HTTP_SSL_MODULE=y
|
||||
@@ -88,6 +89,7 @@ BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_DBUS=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_RAUC_JSON=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
@@ -137,6 +139,7 @@ BR2_PACKAGE_LOWDOWN=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_MDNS_ALIAS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
GNS3_APPLIANCE_RAM=512
|
||||
|
||||
+132
-2
@@ -3,6 +3,132 @@ Change Log
|
||||
|
||||
All notable changes to the project are documented in this file.
|
||||
|
||||
[v25.03.1][] - 2025-04-11
|
||||
-------------------------
|
||||
|
||||
### Fixes
|
||||
- Fix configuration migration issues when upgrading
|
||||
|
||||
|
||||
[v25.03.0][] - 2025-03-31
|
||||
-------------------------
|
||||
|
||||
> [!IMPORTANT]
|
||||
> This release is the first with the new Buildroot 2025.02 (LTS)
|
||||
|
||||
### Changes
|
||||
- Upgrade Linux kernel to 6.12.21 (LTS)
|
||||
- Upgrade Buildroot to 2025.02.0 (LTS)
|
||||
|
||||
### Fixes
|
||||
- Fix #964: YANG schema warning in syslog: missing 'monitor' node for lag
|
||||
- Fix #980: the system fails to reboot when a container is (stuck), for
|
||||
whatever reason, in its 'setup' state
|
||||
- Fix #990: web console, ttyd service, stopped working after upgrade to
|
||||
Buildroot 2025.02, caused by new (missing) option `--writable`
|
||||
- Fix TCAM memory corruption in `mvpp2` Ethernet controller
|
||||
- Fix annoying (but harmless) usage message from the logger tool when
|
||||
`startup-config` fails to load and the system reverts to failure mode
|
||||
- Fix harmless log warning for product specific init when no product
|
||||
specific init scripts are found
|
||||
- Backport fixes for sysklogd, affecting hostname filtering and periods
|
||||
in TAG names, pending official backport in Buildroot
|
||||
|
||||
|
||||
[v25.02.0][] - 2025-03-04
|
||||
-------------------------
|
||||
|
||||
### Changes
|
||||
- Upgrade Linux kernel to 6.12.18 (LTS)
|
||||
- Upgrade Buildroot to 2024.02.11 (LTS)
|
||||
- Add support for link aggregation (lag), static (balance-xor) and LACP
|
||||
- Add support for the [i.MX 8M Plus EVK][EVK]
|
||||
- YANG type change for SSH private/public keys, from ietf-crypto-types
|
||||
to infix-crypto-types
|
||||
- Disable global IPv6 forwarding by default, enable by per-interface
|
||||
setting. Note, route advertisements are always accepted. Issue #785
|
||||
- Drop automatic default route (interface route) for IPv4 autoconf, not
|
||||
necessary and causes more confusion than good. Issue #923
|
||||
- Update scripting with new RESTCONF examples
|
||||
|
||||
### Fixes
|
||||
- Fix #896: `/etc/resolv.conf` not properly generated when system runs
|
||||
in fail secure mode (failing to load `startup-config`)
|
||||
- Fix #902: containers "linger" in the system (state 'exited') after
|
||||
having removed them from the configuration
|
||||
- Fix #930: container configuration changes does not apply at runtime
|
||||
only when saved to `startup-config` and system is rebooted
|
||||
- Fix #936: DHCP server reconfiguration does not always take effect.
|
||||
- Fix #956: CLI `copy` command complains it cannot change owner when
|
||||
copying `factory-config` to `running-config`. Bogus error, the
|
||||
latter is not really a file
|
||||
- Fix #977: "Operation not permitted" when saving `running-config` to
|
||||
`startup-config` (harmless warning but annoying and concerning)
|
||||
|
||||
[EVK]: https://www.nxp.com/design/design-center/development-boards-and-designs/8MPLUSLPD4-EVK
|
||||
|
||||
|
||||
[v25.01.0][] - 2025-01-31
|
||||
-------------------------
|
||||
|
||||
> [!NOTE]
|
||||
> This release contains breaking changes in the configuration file
|
||||
> syntax for DHCP clients. Specifically DHCP options *with value*,
|
||||
> i.e., the syntax for sending a hexadecimal value now require `hex`
|
||||
> prefix before a string of colon-separated pairs of hex values.
|
||||
|
||||
### Changes
|
||||
|
||||
- Upgrade Linux kernel to 6.12.11 (LTS)
|
||||
- Upgrade Buildroot to 2024.02.10 (LTS)
|
||||
- Upgrade FRR from 9.1.2 to 9.1.3
|
||||
- Add support for configuring SSH server, issue #441. As a result,
|
||||
both SSH and NETCONF now use the same host key in `factory-config`
|
||||
- Add operational support for reading DNS resolver info, issue #510
|
||||
- Add operational support for NTP client, issue #510
|
||||
- Add support for more mDNS settings: allow/deny interfaces, acting
|
||||
as "reflector" and filtering of reflected services. Issue #678
|
||||
- Add DHCPv4 server support, multiple subnets with static hosts and
|
||||
DHCP options on global, subnet, or host level, issue #703.
|
||||
Contributed by [MINEx Networks](https://minexn.com/)
|
||||
- DHCP client options aligned with DHCP server, `startup-config`
|
||||
files with old syntax are automatically migrated
|
||||
- Breaking change in DHCP client options *with value*. Hexadecimal
|
||||
values must now be formatted as `{ "hex": "c0:ff:ee" }` (JSON)
|
||||
- Add documentation on management via SSH, Web (RESTCONF, Web
|
||||
Console), and Console Port, issue #787
|
||||
- Add documentation of DNS client use and configuration, issue #798
|
||||
- Add support for changing boot order for the system with an RPC,
|
||||
including support for reading boot order from operational datastore
|
||||
- Add support for GRE/GRETAP tunnels
|
||||
- Add support for STP/RSTP on bridges
|
||||
- Add support for VXLAN tunnels
|
||||
|
||||
### Fixes
|
||||
|
||||
- Fix #777: Authorized SSH key not applied to `startup-config`
|
||||
- Fix #829: Avahi (mDNS responder) not starting properly on switches
|
||||
with *many* ports (>10). This led to a review of `sysctl`:
|
||||
- New for IPv4:
|
||||
- Adjust IGMP max memberships: 20 -> 1000
|
||||
- Use neighbor information on nexthop selection
|
||||
- Use inbound interface address on ICMP errors
|
||||
- Ignore routes with link down
|
||||
- Disable `rp_filter`
|
||||
- ARP settings have been changed to better fit routers, i.e.,
|
||||
systems with multiple interfaces:
|
||||
- Always use best local address when sending ARP
|
||||
- Only reply to ARP if target IP is on the inbound interface
|
||||
- Generate ARP requests when device is brought up or HW address changes
|
||||
- New for IPv6:
|
||||
- Keep static global addresses on link down
|
||||
- Ignore routes with link down
|
||||
- Fix #861: Fix error when running 251+ reconfigurations in test-mode
|
||||
- Fix #869: Setup of bridges is now more robust
|
||||
- Fix #899: DHCP client with client-id does not work
|
||||
- Minor cleanup of Networking Guide
|
||||
- Fix memory leaks in `confd`
|
||||
|
||||
|
||||
[v24.11.1][] - 2024-11-29
|
||||
-------------------------
|
||||
@@ -221,7 +347,7 @@ renamed to ease maintenance, more info below.
|
||||
with `custom-phys-address` to allow for constructing more free-form
|
||||
MAC addresses based on the chassis MAC (a.k.a., base MAC) address.
|
||||
For more information, see the YANG model, a few examples are listed in
|
||||
the updated documentation.
|
||||
the updated documentation.
|
||||
The syntax will be automatically updated in the `startup-config` and
|
||||
`factory-config` -- make sure to verify the changes and update any
|
||||
static `factory-config` used for your products
|
||||
@@ -1409,7 +1535,11 @@ Supported YANG models in addition to those used by sysrepo and netopeer:
|
||||
- N/A
|
||||
|
||||
[buildroot]: https://buildroot.org/
|
||||
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v24.11.0...HEAD
|
||||
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v25.03.0...HEAD
|
||||
[v25.03.1]: https://github.com/kernelkit/infix/compare/v25.03.0...v25.03.1
|
||||
[v25.03.0]: https://github.com/kernelkit/infix/compare/v25.02.0...v25.03.0
|
||||
[v25.02.0]: https://github.com/kernelkit/infix/compare/v25.01.0...v25.02.0
|
||||
[v25.01.0]: https://github.com/kernelkit/infix/compare/v24.11.0...v25.01.0
|
||||
[v24.11.1]: https://github.com/kernelkit/infix/compare/v24.11.0...v24.11.1
|
||||
[v24.11.0]: https://github.com/kernelkit/infix/compare/v24.10.0...v24.11.0
|
||||
[v24.10.2]: https://github.com/kernelkit/infix/compare/v24.10.1...v24.10.2
|
||||
|
||||
+9
-5
@@ -1,13 +1,16 @@
|
||||
<img align="right" src="logo.png" alt="Infix - Linux <3 NETCONF" width=480 border=10>
|
||||
|
||||
Welcome to Infix, your friendly Network Operating System! On these
|
||||
pages you can find both user and developer documentation.
|
||||
|
||||
> Topics on configuring the system include CLI examples, every setting
|
||||
> is also possible to perform using NETCONF. In fact, the Infix test
|
||||
> system solely relies on NETCONF for configuring network topologies.
|
||||
Most topics on configuring the system include CLI examples, but every
|
||||
setting, as well as status read-back from the operational datastore, is
|
||||
also possible to perform using NETCONF or RESTCONF. In fact, the Infix
|
||||
regression test system solely relies on NETCONF and RESTCONF.
|
||||
|
||||
The CLI documentation is also available from inside the CLI itself using
|
||||
the `help` command.
|
||||
> [!TIP]
|
||||
> The CLI documentation is also available from inside the CLI itself
|
||||
> using the `help` command in admin-exec mode.
|
||||
|
||||
- **CLI Topics**
|
||||
- [Introduction to the CLI](cli/introduction.md)
|
||||
@@ -18,6 +21,7 @@ the `help` command.
|
||||
- [Introduction](introduction.md)
|
||||
- [System Configuration](system.md)
|
||||
- [Network Configuration](networking.md)
|
||||
- [DHCP Server](dhcp.md)
|
||||
- [Syslog Support](syslog.md)
|
||||
- **Infix In-Depth**
|
||||
- [Boot Procedure](boot.md)
|
||||
|
||||
+46
-18
@@ -60,14 +60,14 @@ rootfs overlay -- with a [VPD](vpd.md) you can even support several!
|
||||
### Variables & Format Specifiers
|
||||
|
||||
Parts of the configuration you likely always want to generated, like the
|
||||
SSH hostkey used by NETCONF, a unique hostname, or the `admin` user's
|
||||
SSH hostkey used by SSH server and NETCONF, a unique hostname, or the `admin` user's
|
||||
unique (per-device with a VPD) password hash. This section lists the
|
||||
available keywords, see the next section for examples of how to use
|
||||
them:
|
||||
|
||||
- **Default password hash:** `$factory$` (from VPD, .dtb, or built-in)
|
||||
XPath: `/ietf-system:system/authentication/user/password`
|
||||
- **Default NETCONF hostkey:** `genkey` (regenerated at factory reset)
|
||||
- **Default SSH and NETCONF hostkey:** `genkey` (regenerated at factory reset)
|
||||
XPath: `/ietf-keystore:keystore/asymmetric-keys/asymmetric-key[name='genkey']`
|
||||
- **Hostname format specifiers:**
|
||||
XPath: `/ietf-system:system/hostname`
|
||||
@@ -221,8 +221,8 @@ $ echo "Li0tLS0tLS0uCnwgIC4gLiAgfCBJbmZpeCAtLSBhIE5ldHdvcmsgT3BlcmF0aW5nIFN5c3Rl
|
||||
|
||||
**IETF Keystore**
|
||||
|
||||
Notice how both the public and private keys are left empty here. The
|
||||
`genkey` is always automatically regenerated after each factory reset.
|
||||
Notice how both the public and private keys are left empty here, this
|
||||
cause them to be always automatically regenerated after each factory reset.
|
||||
Keeping the `factory-config` snippet like this means we can use the same
|
||||
file on multiple devices, without risking them sharing the same host
|
||||
keys. Sometimes you may want the same host keys, but that is the easy
|
||||
@@ -245,8 +245,6 @@ use-case and not documented here.
|
||||
},
|
||||
```
|
||||
|
||||
The `genkey` is currently only used by the NETCONF SSH backend.
|
||||
|
||||
**IETF NETCONF Server**
|
||||
|
||||
```json
|
||||
@@ -280,6 +278,28 @@ The `genkey` is currently only used by the NETCONF SSH backend.
|
||||
},
|
||||
```
|
||||
|
||||
**Infix Services**
|
||||
```json
|
||||
"infix-services:ssh": {
|
||||
"enabled": true,
|
||||
"hostkey": [
|
||||
"genkey"
|
||||
],
|
||||
"listen": [
|
||||
{
|
||||
"name": "ipv4",
|
||||
"address": "0.0.0.0",
|
||||
"port": 22
|
||||
},
|
||||
{
|
||||
"name": "ipv6",
|
||||
"address": "::1",
|
||||
"port": 22
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
|
||||
|
||||
Integration
|
||||
@@ -370,22 +390,30 @@ But you can of course use only two numbers, *major.minor*, as well.
|
||||
> with your own versioning scheme.
|
||||
|
||||
|
||||
### `INFIX_RELEASE`
|
||||
### Specifying Versioning Information
|
||||
|
||||
This global variable **must be** a lower-case string (no spaces or
|
||||
other characters outside of 0–9, a–z, '.', '_' and '-') identifying
|
||||
the operating system version, excluding any OS name information or
|
||||
release code name, and suitable for processing by scripts or usage
|
||||
in generated filenames.
|
||||
Two optional environment variables control the version information
|
||||
recorded in images. Both of these **must be** a lower-case string (no
|
||||
spaces or other characters outside of 0–9, a–z, '.', '_' and '-')
|
||||
identifying the operating system version, excluding any OS name
|
||||
information or release code name, and suitable for processing by
|
||||
scripts or usage in generated filenames.
|
||||
|
||||
#### `INFIX_BUILD_ID`
|
||||
|
||||
Used for `BUILD_ID` in `/etc/os-release`.
|
||||
|
||||
**Default:** `$(git describe --always --dirty --tags)`, from the _top
|
||||
directory_. By default, the top directory refers to the root of the
|
||||
Infix source tree, but this can be changed by setting the branding
|
||||
variable `INFIX_OEM_PATH`, e.g. in a `defconfig` file or via `make
|
||||
menuconfig`, to the path of an enclosing br2-external.
|
||||
|
||||
#### `INFIX_RELEASE`
|
||||
|
||||
Used for `VERSION` and `VERSION_ID` in `/etc/os-release` and
|
||||
generated file names like disk images, etc.
|
||||
|
||||
**Default:** generated using `git describe --always --dirty --tags`,
|
||||
with an additional `-C $infix_path`. This variable defaults to the
|
||||
Infix tree and can be changed by setting the menuconfig branding
|
||||
variable `INFIX_OEM_PATH` to that of the br2-external. It is also
|
||||
possible to set the `GIT_VERSION` variable in your `post-build.sh`
|
||||
script to change how the VCS version is extracted.
|
||||
**Default:** `${INFIX_BUILD_ID}`
|
||||
|
||||
[NanoPi R2S]: https://github.com/kernelkit/infix/blob/main/board/aarch64/r2s/rootfs/etc/factory-config.cfg
|
||||
|
||||
+40
-31
@@ -31,9 +31,9 @@ Infix comes with native support for Docker containers using [podman][].
|
||||
The [YANG model][1] describes the current level of support, complete
|
||||
enough to run both system and application containers.
|
||||
|
||||
Key design features, like using Linux switchdev, allow users to assign
|
||||
switch ports directly to containers, not just bridged VETH pairs, this
|
||||
is a rare and in many cases *unique* feature of Infix.
|
||||
Key design features of Infix, like using Linux switchdev, allow users to
|
||||
assign switch ports directly to containers, not just bridged VETH pairs.
|
||||
This is a rare and in many cases *unique* feature of Infix.
|
||||
|
||||
All network specific settings are done using the IETF interfaces YANG
|
||||
model, with augments for containers to ensure smooth integration with
|
||||
@@ -43,7 +43,7 @@ container networking in podman.
|
||||
> Even though the `podman` command can be used directly from a shell
|
||||
> prompt, we strongly recommend using the CLI commands instead. They
|
||||
> employ the services of a wrapper `container` script which handles the
|
||||
> integration of containers in the system.
|
||||
> integration of Docker containers in the system.
|
||||
|
||||
|
||||
Caution
|
||||
@@ -83,18 +83,20 @@ In the CLI, containers can be run in one of two ways:
|
||||
1. `container run IMAGE [COMMAND]`, or
|
||||
2. enter `configure` context, then `edit container NAME`
|
||||
|
||||
The former is useful mostly for testing, or running single commands in
|
||||
an image. It is a wrapper for `podman run -it --rm ...`, while the
|
||||
latter is a wrapper and adaptation of `podman create ...`.
|
||||
The first is useful mostly for testing, or running single commands in
|
||||
an image. It is a wrapper for `podman run -it --rm ...`.
|
||||
|
||||
The second creates a read-only container that is automatically started
|
||||
at every boot. When non-volatile storage is needed, data stored in a
|
||||
volume is persisted until explicitly removed from the configuration,
|
||||
i.e., across host and container reboots and upgrades.
|
||||
The second creates a read-only container that by default automatically
|
||||
start at every boot. It basically wraps `podman create ...`.
|
||||
|
||||
Another option is [Content Mounts](#content-mounts), where the content
|
||||
of a file mounted into the container is kept along with the container
|
||||
configuration in the device's `startup-config`.
|
||||
When non-volatile storage is needed two complementary options exist:
|
||||
|
||||
- **Volumes:** data stored in a volume is persisted until explicitly
|
||||
removed from the configuration, i.e., across host reboots and
|
||||
container upgrades
|
||||
- **[Content Mounts](#content-mounts):** where the content of a file
|
||||
mounted into the container is kept along with the container
|
||||
configuration in the device's `startup-config`
|
||||
|
||||
Podman ensures (using tmpfs) all containers have writable directories
|
||||
for certain critical file system paths: `/dev`, `/dev/shm`, `/run`,
|
||||
@@ -127,24 +129,30 @@ Classic Hello World:
|
||||
Hello from Docker!
|
||||
This message shows that your installation appears to be working correctly.
|
||||
|
||||
Persistent web server using nginx, sharing the host's network:
|
||||
A web server with [nginx][], using standard docker bridge. Podman will
|
||||
automatically create a VETH pair for us, connecting the container to the
|
||||
`docker0` bridge:
|
||||
|
||||
admin@example:/> configure
|
||||
admin@example:/config> edit container web
|
||||
admin@example:/config/container/web> set image docker://nginx:alpine
|
||||
admin@example:/config/container/web> set publish 80:80
|
||||
admin@example:/config/container/web> set network host
|
||||
admin@example:/config/container/web> leave
|
||||
admin@example:/config/> edit interface docker0
|
||||
admin@example:/config/interface/docker0/> set container-network
|
||||
admin@example:/config/interface/docker0/> end
|
||||
admin@example:/config/> edit container web
|
||||
admin@example:/config/container/web/> set image docker://nginx:alpine
|
||||
admin@example:/config/container/web/> set network publish 8080:80
|
||||
admin@example:/config/container/web/> set network interface docker0
|
||||
admin@example:/config/container/web/> set volume cache target /var/cache
|
||||
admin@example:/config/container/web/> leave
|
||||
admin@example:/> show container
|
||||
|
||||
Exit to the shell and verify the service with curl, or try to attach
|
||||
to your device's IP address using your browser:
|
||||
|
||||
admin@example:~$ curl http://localhost
|
||||
admin@example:~$ curl http://localhost:8080
|
||||
|
||||
or connect to port 80 of your running Infix system with a browser. See
|
||||
the following sections for how to add more interfaces and manage your
|
||||
container at runtime.
|
||||
or connect to port 8080 of your running Infix system with a browser.
|
||||
See the following sections for how to add more interfaces and manage
|
||||
your container at runtime.
|
||||
|
||||
|
||||
Container Images
|
||||
@@ -456,11 +464,11 @@ in a `bridge`. Below an example of a system container calls `set
|
||||
network interface docker0`, here we show how to set options for that
|
||||
network:
|
||||
|
||||
admin@example:/config/container/ntpd/> edit network docker0
|
||||
admin@example:/config/container/ntpd/network/docker0/>
|
||||
admin@example:/config/container/ntpd/network/docker0/> set option
|
||||
admin@example:/config/container/ntpd/> edit network interface docker0
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/>
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> set option
|
||||
<string> Options for masquerading container bridges.
|
||||
admin@example:/config/container/ntpd/network/docker0/> help option
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> help option
|
||||
NAME
|
||||
option <string>
|
||||
|
||||
@@ -471,9 +479,9 @@ network:
|
||||
mac=00:01:02:c0:ff:ee -- set fixed MAC address in container
|
||||
interface_name=foo0 -- set interface name inside container
|
||||
|
||||
admin@example:/config/container/ntpd/network/docker0/> set option ip=172.17.0.2
|
||||
admin@example:/config/container/ntpd/network/docker0/> set option interface_name=wan
|
||||
admin@example:/config/container/ntpd/network/docker0/> leave
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> set option ip=172.17.0.2
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> set option interface_name=wan
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> leave
|
||||
|
||||
|
||||
### Container Host Interface
|
||||
@@ -903,4 +911,5 @@ Container Image](#upgrading-a-container-image) (above).
|
||||
[14]: https://github.com/kernelkit/curiOS/
|
||||
[15]: https://github.com/kernelkit/curiOS/blob/2e4748f65e356b2c117f586cd9420d7ba66f79d5/board/system/rootfs/etc/inittab
|
||||
[tini]: https://github.com/krallin/tini
|
||||
[nginx]: https://hub.docker.com/_/nginx
|
||||
[podman]: https://podman.io
|
||||
|
||||
@@ -164,6 +164,59 @@ Now you can rebuild `confd`, just as described above, and restart Infix:
|
||||
make confd-rebuild all run
|
||||
|
||||
|
||||
### `statd`
|
||||
|
||||
The Infix status daemon, `src/statd`, is responsible for populating the
|
||||
sysrepo `operational` datastore. Like `confd`, it uses XPath subscriptions,
|
||||
but unlike `confd`, it relies entirely on `yanger`, a Python script that
|
||||
gathers data from local linux services and feeds it into sysrepo.
|
||||
|
||||
To apply changes, rebuild the image:
|
||||
|
||||
make python-statd-rebuild statd-rebuild all
|
||||
|
||||
Rebuilding the image and testing on target for every change during
|
||||
development process can be tedious. Instead, `yanger` allows remote
|
||||
execution, running the script directly on the host system (test
|
||||
container):
|
||||
|
||||
infamy0:test # ../src/statd/python/yanger/yanger -x "../utils/ixll -A ssh d3a" ieee802-dot1ab-lldp
|
||||
|
||||
`ixll` is a utility script that lets you run network commands using an
|
||||
**interface name** instead of a hostname. It makes operations like
|
||||
`ssh`, `scp`, and network discovery easier.
|
||||
|
||||
Normally, `yanger` runs commands **locally** to retrieve data
|
||||
(e.g., `lldpcli` when handling `ieee802-dot1ab-lldp`). However, when
|
||||
executed with `-x "../utils/ixll -A ssh d3a"` it redirects these
|
||||
commands to a remote system connected to the local `d3a` interface via
|
||||
SSH. This setup is used for running `yanger` in an
|
||||
[interactive test environment](testing.md#interactive-usage). The yanger
|
||||
script runs on the `host` system, but key commands are executed on the
|
||||
`target` system.
|
||||
|
||||
For debugging or testing, you can capture system command output and
|
||||
replay it later without needing a live system.
|
||||
|
||||
To capture:
|
||||
|
||||
infamy0:test # ../src/statd/python/yanger/yanger -c /tmp/capture ieee802-dot1ab-lldp
|
||||
|
||||
To replay:
|
||||
|
||||
infamy0:test # ../src/statd/python/yanger/yanger -r /tmp/capture ieee802-dot1ab-lldp
|
||||
|
||||
This is especially useful when working in isolated environments or debugging
|
||||
issues without direct access to the DUT.
|
||||
|
||||
### Agree on YANG Model
|
||||
|
||||
When making changes to the `confd` and `statd` services, you will often need to update
|
||||
the YANG models. If you are adding a new YANG module, it's best to follow the
|
||||
structure of an existing one. However, before making any changes, **always discuss
|
||||
them with the Infix core team**. This helps avoid issues later in development and
|
||||
makes pull request reviews smoother.
|
||||
|
||||
Testing
|
||||
-------
|
||||
|
||||
@@ -175,6 +228,11 @@ The Infix automated test suite is built around Qemu and [Qeneth][2], see:
|
||||
* [Testing](testing.md)
|
||||
* [Docker Image](../test/docker/README.md)
|
||||
|
||||
With any new feature added to Infix, it is essential to include a
|
||||
relevant test case. See the
|
||||
[Test Development](testing.md#test-development) section for guidance
|
||||
on adding test cases.
|
||||
|
||||
|
||||
Reviewing
|
||||
---------
|
||||
|
||||
+171
@@ -0,0 +1,171 @@
|
||||
DHCP Server
|
||||
===========
|
||||
|
||||
The DHCPv4 server provides automatic IP address assignment and network
|
||||
configuration for clients. It supports address pools, static host
|
||||
assignments, and customizable DHCP options. It also serves as a DNS
|
||||
proxy for local subnets and can even forward queries to upstream DNS
|
||||
servers[^1].
|
||||
|
||||
> [!NOTE]
|
||||
> When using the CLI, the system automatically enables essential options
|
||||
> like DNS servers and default gateway based on the system's network
|
||||
> configuration. These options can be disabled, changed or overridden,
|
||||
> at any level: global, subnet, or per-host.
|
||||
|
||||
|
||||
## Basic Configuration
|
||||
|
||||
The following example configures a DHCP server for subnet 192.168.2.0/24
|
||||
with an address pool:
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit dhcp-server
|
||||
admin@example:/config/dhcp-server/> edit subnet 192.168.2.0/24
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> set pool start-address 192.168.2.100 end-address 192.168.2.200
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> leave
|
||||
```
|
||||
|
||||
When setting up the server from the CLI, the system automatically adds a
|
||||
few default DHCP options that will be sent to clients: both DNS server
|
||||
and default gateway will use the system address on the matching
|
||||
interface.
|
||||
|
||||
```
|
||||
admin@example:/> show running-config
|
||||
"infix-dhcp-server:dhcp-server": {
|
||||
"subnet": [
|
||||
{
|
||||
"subnet": "192.168.2.0/24",
|
||||
"option": [
|
||||
{
|
||||
"id": "dns-server",
|
||||
"address": "auto"
|
||||
},
|
||||
{
|
||||
"id": "router",
|
||||
"address": "auto"
|
||||
}
|
||||
],
|
||||
"pool": {
|
||||
"start-address": "192.168.2.100",
|
||||
"end-address": "192.168.2.200"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
> [!IMPORTANT]
|
||||
> Remember to set up an interface in this subnet, avoid using addresses
|
||||
> in the DHCP pool, or reserved for static hosts. In Class C networks
|
||||
> the router usually has address `.1`. Depending on the use-case, you
|
||||
> may also want to set up routing.
|
||||
|
||||
|
||||
## Static Host Assignment
|
||||
|
||||
To reserve specific IP addresses for clients based on their MAC address,
|
||||
hostname, or client ID:
|
||||
|
||||
```
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> edit host 192.168.2.10
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/host/192.168.2.10/> set match mac-address 00:11:22:33:44:55
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/host/192.168.2.10/> set hostname printer
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/host/192.168.2.10/> leave
|
||||
```
|
||||
|
||||
Match hosts using a client identifier instead of MAC address:
|
||||
|
||||
```
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/> edit host 192.168.1.50
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/> edit match
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/match/> set client-id hex c0:ff:ee
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/match/> leave
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/> set lease-time infinite
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/> leave
|
||||
```
|
||||
|
||||
The `hex` prefix here ensures matching of client ID is done using the
|
||||
hexadecimal octets `c0:ff:ee`, three bytes. Without the prefix the
|
||||
ASCII string "c0:ff:ee", eight bytes, is used.
|
||||
|
||||
> [!NOTE]
|
||||
> The DHCP server is fully RFC conformant, in the case of option 61 this
|
||||
> means that using the `hex` prefix will require the client to set the
|
||||
> `htype` field of the option to `00`. See RFC 2132 for details.
|
||||
|
||||
|
||||
## Custom DHCP Options
|
||||
|
||||
Configure additional DHCP options globally, per subnet, or per host:
|
||||
|
||||
```
|
||||
admin@example:/config/dhcp-server/> edit subnet 192.168.2.0/24
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> edit option dns-server
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/option/dns-server/> set address 8.8.8.8
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/option/dns-server/> leave
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> edit option ntp-server
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/option/ntp-server/> set address 192.168.2.1
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/option/ntp-server/> leave
|
||||
```
|
||||
|
||||
When configuring, e.g., `dns-server`, or `router` options with the value
|
||||
`auto`, the system uses the IP address from the interface matching the
|
||||
subnet. For example:
|
||||
|
||||
```
|
||||
admin@example:/> show interfaces brief
|
||||
Interface Status Address
|
||||
eth0 UP 192.168.1.1/24
|
||||
eth1 UP 192.168.2.1/24
|
||||
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/> edit option dns-server
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/option/dns-server/> set address auto
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/option/dns-server/> leave
|
||||
```
|
||||
|
||||
In this case, clients in subnet 192.168.1.0/24 will receive 192.168.1.1
|
||||
as their DNS server address.
|
||||
|
||||
|
||||
## Multiple Subnets
|
||||
|
||||
Configure DHCP for multiple networks:
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit dhcp-server
|
||||
admin@example:/config/dhcp-server/> edit subnet 192.168.1.0/24
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/> set pool start-address 192.168.1.100 end-address 192.168.1.200
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/> leave
|
||||
admin@example:/config/dhcp-server/> edit subnet 192.168.2.0/24
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> set pool start-address 192.168.2.100 end-address 192.168.2.200
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> leave
|
||||
```
|
||||
|
||||
|
||||
## Monitoring
|
||||
|
||||
View active leases and server statistics:
|
||||
|
||||
```
|
||||
admin@example:/> show dhcp-server
|
||||
IP ADDRESS MAC HOSTNAME CLIENT ID EXPIRES
|
||||
192.168.2.22 00:a0:85:00:02:05 00:c0:ff:ee 3591s
|
||||
192.168.1.11 00:a0:85:00:04:06 foo 01:00:a0:85:00:04:06 3591s
|
||||
|
||||
admin@example:/> show dhcp-server statistics
|
||||
DHCP offers sent : 6
|
||||
DHCP ACK messages sent : 5
|
||||
DHCP NAK messages sent : 0
|
||||
DHCP decline messages received : 0
|
||||
DHCP discover messages received : 6
|
||||
DHCP request messages received : 5
|
||||
DHCP release messages received : 6
|
||||
DHCP inform messages received : 6
|
||||
```
|
||||
|
||||
|
||||
[^1]: This requires the system DNS resolver to be configured.
|
||||
+92
-58
@@ -1,21 +1,21 @@
|
||||
Discover Infix Units
|
||||
====================
|
||||
# Discover Devices
|
||||
|
||||
Infix advertises itself via the [mDNS-SD](#mdns-sd) and [LLDP](#lldp)
|
||||
discovery protocols. mDNS-SD has good client support in Windows, macOS
|
||||
and on Linux systems. More on these protocols later.
|
||||
|
||||
An even simpler method is available when directly attached to an Infix
|
||||
device:
|
||||
|
||||
```
|
||||
.----. Ethernet .-------.
|
||||
| PC +---------------------+ Infix |
|
||||
'----' if1 eth0 '-------'
|
||||
.----. Ethernet .-------.
|
||||
| PC +---------------------+ Infix |
|
||||
'----' if1 e1 '-------'
|
||||
```
|
||||
Figure 1: PC directly connected over Ethernet to Infix unit (here eth0).
|
||||
|
||||
|
||||
When you wish to discover the IP address of an Infix switch, the simplest
|
||||
way is probably to *ping the IPv6 all-hosts* address (ff02::1) over a
|
||||
directly connected Ethernet cable. The unit's link-local IPv6 address is
|
||||
seen in the response.
|
||||
|
||||
In the example below, the PC is connected to Infix via interface *tap0*
|
||||
(*tap0* is *if1* in Figure 1) and Infix responds with address
|
||||
With IPv6 you can *ping the all-hosts* address (ff02::1), the device's
|
||||
link-local IPv6 address is then seen in the response. In the following
|
||||
example, the PC here uses *tap0* as *if1*, Infix responds with address
|
||||
*fe80::ff:fec0:ffed*.
|
||||
|
||||
```
|
||||
@@ -31,7 +31,11 @@ rtt min/avg/max/mdev = 0.389/0.455/0.558/0.073 ms
|
||||
linux-pc:#
|
||||
```
|
||||
|
||||
The PC could connect then connect to Infix, e.g., using SSH.
|
||||
> [!TIP]
|
||||
> The `-L` option ignores local responses from the PC.
|
||||
|
||||
This address can then be used to connect to the device, e.g., using SSH.
|
||||
Notice the syntax `username@address%interface`:
|
||||
|
||||
```
|
||||
linux-pc:# ssh admin@fe80::ff:fec0:ffed%tap0
|
||||
@@ -39,17 +43,13 @@ admin@fe80::ff:fec0:ffed%tap0's password: admin
|
||||
admin@infix-c0-ff-ee:~$
|
||||
```
|
||||
|
||||
## Discovery mechanisms available in Infix
|
||||
|
||||
Infix advertises its presence via the [mDNS](#mdns) and [LLDP](#lldp)
|
||||
discovery protocols.
|
||||
## LLDP
|
||||
|
||||
Infix supports LLDP (IEEE 802.1AB). For a device with factory default
|
||||
settings, the link-local IPv6 address can be read from the Management
|
||||
Address TLV using *tcpdump* or other sniffing tools[^1]:
|
||||
|
||||
### LLDP
|
||||
|
||||
Infix supports LLDP (IEEE 802.1AB). For a unit with factory default
|
||||
settings, the PC can readout the link-local IPv6 address from the
|
||||
Management Address TLV using *tcpdump* or other sniffing tools[^1].
|
||||
```
|
||||
linux-pc:# tcpdump -i tap0 -Qin -v ether proto 0x88cc
|
||||
tcpdump: listening on tap0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
|
||||
@@ -83,11 +83,12 @@ tcpdump: listening on tap0, link-type EN10MB (Ethernet), snapshot length 262144
|
||||
linux-pc:#
|
||||
```
|
||||
|
||||
If the unit has an IPv4 address assigned, it is shown in an additional
|
||||
If the device has an IPv4 address assigned, it is shown in an additional
|
||||
Management Address TLV.
|
||||
|
||||
> **Note** The Management Addresses shown by LLDP are not
|
||||
> necessarily associated with the port transmitting the LLDP message.
|
||||
> [!NOTE]
|
||||
> The Management Addresses shown by LLDP are not necessarily associated
|
||||
> with the port transmitting the LLDP message.
|
||||
|
||||
In the example below, the IPv4 address (10.0.1.1) happens to be
|
||||
assigned to *eth0*, while the IPv6 address (2001:db8::1) is not.
|
||||
@@ -130,10 +131,6 @@ tcpdump: listening on tap0, link-type EN10MB (Ethernet), snapshot length 262144
|
||||
linux-pc:#
|
||||
```
|
||||
|
||||
[^1]: [lldpd: implementation of IEEE 802.1ab
|
||||
(LLDP)](https://github.com/lldp/lldpd) includes *lldpcli*, which
|
||||
is handy to sniff and display LLDP packets.
|
||||
|
||||
The LLDP service can be disabled using the following commands.
|
||||
|
||||
```
|
||||
@@ -143,13 +140,38 @@ admin@infix-c0-ff-ee:/config/> leave
|
||||
admin@infix-c0-ff-ee:/>
|
||||
```
|
||||
|
||||
### mDNS
|
||||
|
||||
DNS-SD/mDNS can be used to discover Infix units and services. Infix
|
||||
units present their IP addresses, services and hostname within the
|
||||
.local domain. This method has good client support in Apple and Linux
|
||||
systems. On Linux, tools such as *avahi-browse* or *mdns-scan*[^2] can
|
||||
be used to search for devices advertising their services via mDNS.
|
||||
## mDNS-SD
|
||||
|
||||
DNS-SD/mDNS-SD can be used to discover Infix devices and services. By
|
||||
default, Infix use the `.local` domain for advertising services. Some
|
||||
networks use `.lan` instead, so this configurable:
|
||||
|
||||
```
|
||||
admin@infix-c0-ff-ee:/> configure
|
||||
admin@infix-c0-ff-ee:/config/> edit mdns
|
||||
admin@infix-c0-ff-ee:/config/mdns/> set domain lan
|
||||
```
|
||||
|
||||
Other available settings include limiting the interfaces mDNS responder
|
||||
acts on:
|
||||
|
||||
```
|
||||
admin@infix-c0-ff-ee:/config/> set interfaces allow e1
|
||||
```
|
||||
|
||||
or
|
||||
|
||||
```
|
||||
admin@infix-c0-ff-ee:/config/> set interfaces deny wan
|
||||
```
|
||||
|
||||
The `allow` and `deny` settings are complementary, `deny` always wins.
|
||||
|
||||
----
|
||||
|
||||
In Linux, tools such as *avahi-browse* or *mdns-scan*[^2] can be used to
|
||||
search for devices advertising their services via mDNS.
|
||||
|
||||
```
|
||||
linux-pc:# avahi-browse -ar
|
||||
@@ -181,9 +203,15 @@ linux-pc:# avahi-browse -ar
|
||||
linux-pc:#
|
||||
```
|
||||
|
||||
> [!TIP]
|
||||
> The `-t` option is also very useful, it stops browsing automatically
|
||||
> when a "more or less complete list" has been printed. However, some
|
||||
> devices on the LAN may be in deep sleep so run the command again if
|
||||
> you cannot find the device you are looking for.
|
||||
|
||||
Additionally, *avahi-resolve-host-name* can be used to verify domain
|
||||
name mappings for IP addresses. By default, it translates from IPv4
|
||||
addresses. This function allows users to confirm that addresses are
|
||||
name mappings for IP addresses. By default, it translates from IPv4
|
||||
addresses. This function allows users to confirm that addresses are
|
||||
mapped correctly.
|
||||
|
||||
```
|
||||
@@ -219,20 +247,21 @@ linux-pc:#
|
||||
```
|
||||
|
||||
To disable mDNS/mDNS-SD, type the commands:
|
||||
|
||||
```
|
||||
admin@infix-c0-ff-ee:/> configure
|
||||
admin@infix-c0-ff-ee:/config/> no mdns
|
||||
admin@infix-c0-ff-ee:/config/> leave
|
||||
```
|
||||
|
||||
#### Human-Friendly Hostname Alias
|
||||
### Human-Friendly Hostname Alias
|
||||
|
||||
Each Infix unit will advertise itself as *infix.local*, in addition to
|
||||
its full hostname (e.g., *infix-c0-ff-ee.local* or *foo.local*). This
|
||||
alias works seamlessly on a network with a single Infix device, and
|
||||
makes it easy to connect when the exact hostname is not known in
|
||||
advance. The examples below show how the alias can be used for
|
||||
actions such as pinging or establishing an SSH connection:
|
||||
Each Infix deviuce advertise itself as *infix.local*, in addition to its
|
||||
full hostname (e.g., *infix-c0-ff-ee.local* or *foo.local*). This alias
|
||||
works seamlessly on a network with a single Infix device, and makes it
|
||||
easy to connect when the exact hostname is not known in advance. The
|
||||
examples below show how the alias can be used for actions such as
|
||||
pinging or establishing an SSH connection:
|
||||
|
||||
```
|
||||
linux-pc:# ping infix.local -c 3
|
||||
@@ -254,30 +283,33 @@ linux-pc:# ssh admin@infix.local
|
||||
|
||||
Run the command 'cli' for interactive OAM
|
||||
|
||||
linux-pc:#
|
||||
admin@infix-c0-ff-ee:~$
|
||||
```
|
||||
|
||||
When multiple Infix devices are present on the LAN the alias will not
|
||||
uniquely identify a device; *infix.local* will refer to any of the
|
||||
Infix devices, likely the one that first appeared.
|
||||
|
||||
> When multiple Infix units are present, use the full hostname (e.g.,
|
||||
> *infix-c0-ff-ee.local* or *foo.local*) rather than the alias
|
||||
> infix.local to deterministically connect to a unit.
|
||||
> [!NOTE]
|
||||
> When multiple Infix devices are present on the LAN, use the full name,
|
||||
> e.g., *infix-c0-ff-ee.local* or *foo.local* rather than the alias
|
||||
> *infix.local* to deterministically connect to the device.
|
||||
|
||||
|
||||
#### Netbrowse service to find all your devices
|
||||
### Browse Network Using *network.local*
|
||||
|
||||
Another mDNS alias that all Infix devices can advertise is
|
||||
*network.local*. This is a web service which basically runs avahi-browse
|
||||
and displays a table of other Infix devices and their services.
|
||||
Another mDNS alias that all Infix devices advertise is *network.local*.
|
||||
This is a web service which basically runs `avahi-browse` and displays a
|
||||
table of other Infix devices and their services.
|
||||
|
||||

|
||||
|
||||
With multiple Infix devices on the LAN, one will be your portal to
|
||||
access all others, if it goes down another will take its place.
|
||||
With multiple Infix devices on the LAN, one will take the role of your
|
||||
portal to access all others, if it goes down another takes its place.
|
||||
|
||||
To disable the netbrowse service, and the *network.local* alias, the
|
||||
following commands can be used:
|
||||
|
||||
To disable the netbrowse service, the following commands can be used:
|
||||
```
|
||||
admin@infix-c0-ff-ee:/> configure
|
||||
admin@infix-c0-ff-ee:/config/> edit web
|
||||
@@ -285,6 +317,8 @@ admin@infix-c0-ff-ee:/config/web/> no netbrowse
|
||||
admin@infix-c0-ff-ee:/config/web/> leave
|
||||
```
|
||||
|
||||
|
||||
[^1]: E.g., [lldpd](https://github.com/lldp/lldpd) which includes the
|
||||
*lldpcli* too, handy to sniff and display LLDP packets.
|
||||
[^2]: [mdns-scan](http://0pointer.de/lennart/projects/mdns-scan/): a
|
||||
tool for scanning for mDNS/DNS-SD published services on the local
|
||||
network
|
||||
tool for scanning for mDNS/DNS-SD services on the local network.
|
||||
|
||||
+17
-8
@@ -6,13 +6,7 @@ This column contains the mapping between YANG and Linux / Ethtool counters.
|
||||
┌─────────────────────────────────┬──────────────────────────────────┐
|
||||
│ YANG │ Linux / Ethtool │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-frames │ FramesTransmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-multicast-frames │ MulticastFramesXmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-broadcast-frames │ BroadcastFramesXmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-total-frames │ FramesReceivedOK, │
|
||||
│ in-total-octets │ FramesReceivedOK, │
|
||||
│ │ FrameCheckSequenceErrors │
|
||||
│ │ FramesLostDueToIntMACRcvError │
|
||||
│ │ AlignmentErrors │
|
||||
@@ -25,8 +19,23 @@ This column contains the mapping between YANG and Linux / Ethtool counters.
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-broadcast-frames │ BroadcastFramesReceivedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-error-fcs-frames │ FrameCheckSequenceErrors │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-error-undersize-frames │ undersize_pkts │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-error-fcs-frames │ FrameCheckSequenceErrors │
|
||||
| in-error-oversize-frames | etherStatsJabbers, |
|
||||
| | etherStatsOversizePkts |
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-error-mac-internal-frames │ FramesLostDueToIntMACRcvError │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-frames │ FramesTransmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-multicast-frames │ MulticastFramesXmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-broadcast-frames │ BroadcastFramesXmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ infix-eth:out-good-octets │ OctetsTransmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ infix-eth:in-good-octets │ OctetsReceivedOK │
|
||||
└─────────────────────────────────┴──────────────────────────────────┘
|
||||
```
|
||||
|
||||
File diff suppressed because one or more lines are too long
|
Before Width: | Height: | Size: 358 KiB After Width: | Height: | Size: 368 KiB |
+1
-1
File diff suppressed because one or more lines are too long
|
Before Width: | Height: | Size: 281 KiB After Width: | Height: | Size: 280 KiB |
@@ -0,0 +1,195 @@
|
||||
# Management
|
||||
|
||||
The system utilizes YANG models for keeping configuration and operational
|
||||
data. These databases can be managed through different interfaces such
|
||||
as NETCONF, RESTCONF, and CLI via SSH or Console.
|
||||
|
||||
## SSH Management
|
||||
|
||||
An SSH server (SSHv2) is provided for remote management. It can be
|
||||
enabled/disabled as shown below.
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit ssh
|
||||
admin@example:/config/ssh/> set enabled
|
||||
admin@example:/config/ssh/>
|
||||
```
|
||||
|
||||
By default the SSH server accepts connections to port 22 on all its IP
|
||||
addresses, but this can be adjusted using the `listen` command. To
|
||||
make the server (only) listen for incoming connections to IP address
|
||||
_192.168.1.1_ and port _12345_ the following commands can be used.
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit ssh
|
||||
admin@example:/config/ssh/> show
|
||||
enabled true;
|
||||
hostkey genkey;
|
||||
listen ipv4 {
|
||||
address 0.0.0.0;
|
||||
port 22;
|
||||
}
|
||||
listen ipv6 {
|
||||
address ::;
|
||||
port 22;
|
||||
}
|
||||
admin@example:/config/ssh/> no listen ipv6
|
||||
admin@example:/config/ssh/> edit listen ipv4
|
||||
admin@example:/config/ssh/listen/ipv4/> set address 192.168.1.1
|
||||
admin@example:/config/ssh/listen/ipv4/> set port 12345
|
||||
admin@example:/config/ssh/listen/ipv4/>
|
||||
```
|
||||
|
||||
The default SSH hostkey is generated on first boot and is used in both
|
||||
SSH and NETCONF (SSH transport). Custom keys can be added to the
|
||||
configuration in `ietf-keystore`. The only supported hostkey type is
|
||||
RSA for now, thus the private key must be
|
||||
`ietf-crypto-types:rsa-private-key-format` and the public key
|
||||
`ietf-crypto-types:ssh-public-key-format`
|
||||
|
||||
### Use your own SSH hostkeys
|
||||
|
||||
Hostkeys can be generated with OpenSSL:
|
||||
```bash
|
||||
openssl genpkey -quiet -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -outform PEM > mykey
|
||||
openssl rsa -RSAPublicKey_out < mykey > mykey.pub
|
||||
```
|
||||
Store the keys in `ietf-keystore` _without_ the header and footer information
|
||||
created by OpenSSL.
|
||||
|
||||
After the key has been stored in the keystore and given the name
|
||||
_mykey_ it can be added to SSH configuration:
|
||||
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit ssh
|
||||
admin@example:/config/ssh/> set hostkey mykey
|
||||
|
||||
## Console Port
|
||||
|
||||
For units with a console port, it is possible for users to login to
|
||||
shell/CLI with functionality similar to what is provided via SSH.
|
||||
|
||||
The type and setup for your console port is product specific. For
|
||||
instance, it can be a USB-C port connected to the CPU serial port
|
||||
using a USB-to-serial converter. To connect you would need a USB-C cable
|
||||
connected to the console port of the device. The serial port is
|
||||
typically setup to run at 115200 baud, 8N1.
|
||||
|
||||
|
||||
```
|
||||
Infix -- a Network Operating System v24.11.1 (ttyS0)
|
||||
example login: admin
|
||||
Password:
|
||||
.-------.
|
||||
| . . | Infix -- a Network Operating System
|
||||
|-. v .-| https://kernelkit.org
|
||||
'-'---'-'
|
||||
|
||||
Run the command 'cli' for interactive OAM
|
||||
|
||||
admin@example:~$
|
||||
```
|
||||
|
||||
The `resize` command can be used to update terminal settings to the
|
||||
size of your terminal window.
|
||||
|
||||
```
|
||||
admin@example:~$ resize
|
||||
COLUMNS=115;LINES=59;export COLUMNS LINES;
|
||||
admin@example:~$
|
||||
```
|
||||
|
||||
CLI can be entered from shell in the same way as for SSH.
|
||||
|
||||
```
|
||||
admin@example:~$ cli
|
||||
|
||||
See the 'help' command for an introduction to the system
|
||||
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
ipv6 ::1/128 (static)
|
||||
e1 ethernet LOWER-DOWN 00:53:00:06:03:01
|
||||
e2 ethernet LOWER-DOWN 00:53:00:06:03:02
|
||||
...
|
||||
admin@example:/>
|
||||
```
|
||||
|
||||
## Web, Web-console and RESTCONF
|
||||
|
||||
The system provides a set of Web services:
|
||||
|
||||
- a rudimentary Web server, currently limited to an information page
|
||||
- a RESTCONF server with equivalent management capabilities as NETCONF
|
||||
- a Web console service, where the shell/CLI can be accessed via
|
||||
HTTPS, similar to connecting via a console port or SSH
|
||||
|
||||
There is also a *Netbrowse* Web service presenting information about
|
||||
the unit's neighbors, collected via mDNS (see
|
||||
[Discovery](discovery.md) for more details).
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit web
|
||||
admin@example:/config/web/> help
|
||||
enabled Enable or disable on all web services.
|
||||
console Web console interface.
|
||||
netbrowse mDNS Network Browser.
|
||||
restconf IETF RESTCONF Server.
|
||||
admin@example:/config/web/>
|
||||
```
|
||||
|
||||
### Enable/disable Web Service and Server
|
||||
|
||||
The Web service can be enabled as shown below.
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit web
|
||||
admin@example:/config/web/> set enabled
|
||||
admin@example:/config/web/>
|
||||
```
|
||||
|
||||
Enabling the Web service implies that a Web server is
|
||||
enabled. Currently this Web server provides generic Infix information,
|
||||
as well as a link to a Web console. The Web server uses HTTPS; any
|
||||
HTTP request is redirected to HTTPS.
|
||||
|
||||
The _enabled_ setting for the Web service acts as a global
|
||||
enable/disable setting for the other Web services (Web console,
|
||||
RESTCONF and Netbrowse).
|
||||
|
||||
### Enable/disable Web Console
|
||||
|
||||
The Web console service provides a terminal service similar to Console
|
||||
or SSH. The Web console is secured via HTTPS on port 7861.
|
||||
|
||||
The Web console has its own enable/disable setting, but will only be
|
||||
activated if the Web service is enabled. The example below shows how
|
||||
to disable the Web console.
|
||||
|
||||
```
|
||||
admin@example:/config/web/> edit console
|
||||
admin@example:/config/web/console/> no enabled
|
||||
admin@example:/config/web/console/>
|
||||
```
|
||||
|
||||
### Enable/disable RESTCONF Service
|
||||
|
||||
Alternatively, the system can be managed remotely using
|
||||
RESTCONF. Meaning you can `curl` it instead of using a dedicated
|
||||
NETCONF client.
|
||||
|
||||
The RESTCONF service has its own enable/disable setting, but will
|
||||
only be activated if the Web service is enabled. The example below
|
||||
shows how to disable the RESTCONF service.
|
||||
|
||||
```
|
||||
admin@example:/config/web/> edit restconf
|
||||
admin@example:/config/web/restconf/> no enabled
|
||||
admin@example:/config/web/restconf/>
|
||||
```
|
||||
+363
-98
@@ -43,18 +43,18 @@ it. In this example, traffic assigned to the VLAN in question would be
|
||||
diverted to the VLAN interface before entering the bridge, while all
|
||||
other traffic would be bridged as usual.
|
||||
|
||||
| **Type** | **Yang Model** | **Description** |
|
||||
|----------|----------------------------|---------------------------------------------------------------|
|
||||
| bridge | infix-if-bridge | SW implementation of an IEEE 802.1Q bridge |
|
||||
| ip | ietf-ip, infix-ip | IP address to the subordinate interface |
|
||||
| vlan | infix-if-vlan | Capture all traffic belonging to a specific 802.1Q VID |
|
||||
| lag[^1] | infix-if-lag | Bonds multiple interfaces into one, creating a link aggregate |
|
||||
| lo | ietf-interfaces | Software loopback interface |
|
||||
| eth | ieee802-ethernet-interface | Physical Ethernet device/port. |
|
||||
| | infix-ethernet-interface | |
|
||||
| veth | infix-if-veth | Virtual Ethernet pair, typically one end is in a container |
|
||||
| *common* | ietf-interfaces, | Properties common to all interface types |
|
||||
| | infix-interfaces | |
|
||||
| **Type** | **Yang Model** | **Description** |
|
||||
|----------|----------------------------|--------------------------------------------------------------|
|
||||
| bridge | infix-if-bridge | SW implementation of an IEEE 802.1Q bridge |
|
||||
| ip | ietf-ip, infix-ip | IP address to the subordinate interface |
|
||||
| vlan | infix-if-vlan | Capture all traffic belonging to a specific 802.1Q VID |
|
||||
| lag | infix-if-lag | Link aggregation, static and IEEE 802.3ad (LACP) |
|
||||
| lo | ietf-interfaces | Software loopback interface |
|
||||
| eth | ieee802-ethernet-interface | Physical Ethernet device/port. |
|
||||
| | infix-ethernet-interface | |
|
||||
| veth | infix-if-veth | Virtual Ethernet pair, typically one end is in a container |
|
||||
| *common* | ietf-interfaces, | Properties common to all interface types |
|
||||
| | infix-interfaces | |
|
||||
|
||||
|
||||
## Data Plane
|
||||
@@ -154,9 +154,9 @@ fabric!
|
||||
#### MAC Bridge
|
||||
|
||||
In Infix ports are by default not switch ports, unless the customer
|
||||
specific factory config sets it up this way. To enable switching
|
||||
between ports you create a bridge and then add ports to that
|
||||
bridge. That's it.
|
||||
specific factory config sets it up this way. To enable switching, with
|
||||
offloading if you have a switch chipset, between ports you create a
|
||||
bridge and then add ports to that bridge. Like this:
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
@@ -170,13 +170,15 @@ admin@example:/config/> leave
|
||||
Here we add two ports to bridge `br0`: `eth0` and `eth1`.
|
||||
|
||||
> [!TIP]
|
||||
> Infix has many built-in helpers controlled by convention. Example,
|
||||
> naming your bridge `brN`, where `N` is a number, hints Infix to set
|
||||
> interface type automatically and unlocks all bridge features. Other
|
||||
> "magic" names are `vethNA`, where `N` is a number and `A` is a letter
|
||||
> ('a' for access port and 'b' for bridge side is common), and `ethN.M`
|
||||
> for VLAN M on top of `ethN`, or `dockerN` to create an IP masquerading
|
||||
> container bridge.
|
||||
> The CLI has several built-in helpers governed by convention. E.g.,
|
||||
> naming bridges `brN`, where `N` is a number, the type is *inferred*
|
||||
> automatically and unlocks all bridge features. Other conventions are
|
||||
> `vethNA`, where `N` is a number and `A` is a letter ('a' for access
|
||||
> port and 'b' for bridge side is common), and `ethN.M` for VLAN M on
|
||||
> top of `ethN`, or `dockerN` for a IP masquerading container bridge.
|
||||
>
|
||||
> Note, this inference only works with the CLI, configuring networking
|
||||
> over NETCONF or RESTCONF requires setting the type explicitly.
|
||||
|
||||

|
||||
|
||||
@@ -187,11 +189,11 @@ bridge should be used instead.
|
||||
|
||||
#### VLAN Filtering Bridge
|
||||
|
||||
By default bridges in Linux do not filter based on VLAN tags. It can be
|
||||
enabled in Infix when creating a bridge by adding a port to a VLAN as a
|
||||
tagged or untagged member. Use the port default VID (PVID) setting to
|
||||
control VLAN association for traffic ingressing a port untagged (default
|
||||
PVID: 1).
|
||||
By default bridges in Linux do not filter based on VLAN tags. This can
|
||||
be enabled when creating a bridge by adding a port to a VLAN as a tagged
|
||||
or untagged member. Use the port default VID (PVID) setting to control
|
||||
VLAN association for traffic ingressing a port untagged (default PVID:
|
||||
1).
|
||||
|
||||
```
|
||||
admin@example:/config/> edit interface br0
|
||||
@@ -283,15 +285,15 @@ br0 224.1.1.1 e3, e2
|
||||
br0 ff02::6a br0
|
||||
```
|
||||
|
||||
It is a small LAN, so our bridge has already become the elected IGMP
|
||||
querier. We see it is ours because the timeout is `None`, and we
|
||||
recognize our IP address. We can also see two ports that have joined
|
||||
the same IPv4 multicast group, 224.1.1.1, and one join from Infix itself
|
||||
for the IPv6 group ff02::6a.
|
||||
This is a rather small LAN, so our bridge has already become the elected
|
||||
IGMP querier. We see it is ours because the timeout is `None`, and we
|
||||
recognize the IP address the system has detected, as ours. We can also
|
||||
see two ports that have joined the same IPv4 multicast group, 224.1.1.1,
|
||||
and one join from the system itself for the IPv6 group ff02::6a.
|
||||
|
||||
Now, let's see what happens when we add another bridge, with VLAN
|
||||
filtering enabled. We skip the boring parts about how to move ports
|
||||
e4-e7 to `br1` and assign them to VLANs, and again, focus on the
|
||||
Now, let us see what happens when we add another bridge, this time with
|
||||
VLAN filtering enabled. We skip the boring parts about how to move
|
||||
ports e4-e7 to `br1` and assign them to VLANs, and again, focus on the
|
||||
multicast bits only:
|
||||
|
||||
```
|
||||
@@ -303,7 +305,7 @@ admin@example:/config/interface/br1/> leave
|
||||
admin@example:/> copy running-config startup-config
|
||||
```
|
||||
|
||||
Let's see what we get:
|
||||
Let us see what we get:
|
||||
|
||||
```
|
||||
admin@example:/> show ip multicast
|
||||
@@ -404,15 +406,15 @@ an IGMP/MLD fast-leave port.
|
||||
|
||||
#### Forwarding of IEEE Reserved Group Addresses
|
||||
|
||||
Addresses in range `01:80:C2:00:00:0X` are used by various bridge
|
||||
signaling protocols, and are not forwarded by default. Still, it is
|
||||
sometimes useful to let the bridge forward such packets, and Infix
|
||||
supports this by specifying protocol names or the last address
|
||||
*nibble* as decimal value `0..15`.
|
||||
Addresses in the range `01:80:C2:00:00:0X` are used by various bridge
|
||||
signaling protocols, and are not forwarded by default. Still, it is
|
||||
sometimes useful to let the bridge forward such packets, this can be
|
||||
done by specifying protocol names or the last address *nibble* as
|
||||
decimal value `0..15`:
|
||||
|
||||
```
|
||||
admin@example:/config/> edit interface br0 bridge
|
||||
admin@example:/config/interface/br0/bridge/> set ieee-group-forward <?>
|
||||
admin@example:/config/interface/br0/bridge/> set ieee-group-forward # Tap the ? ley for alternatives
|
||||
[0..15] List of IEEE link-local protocols to forward, e.g., STP, LLDP
|
||||
dot1x 802.1X Port-Based Network Access Control.
|
||||
lacp 802.3 Slow Protocols, e.g., LACP.
|
||||
@@ -428,9 +430,268 @@ admin@example:/config/interface/br0/bridge/> set ieee-group-forward lldp
|
||||
admin@example:/config/interface/br0/bridge/>
|
||||
```
|
||||
|
||||
|
||||
### Link Aggregation
|
||||
|
||||
A link aggregate, or *lag*, allows multiple physical interfaces to be
|
||||
combined into a single logical interface, providing increased bandwidth
|
||||
(in some cases) and redundancy (primarily). Two modes of qualifying lag
|
||||
member ports are available:
|
||||
|
||||
1. **static**: Active members selected based on link status (carrier)
|
||||
2. **lacp:** IEEE 802.3ad Link Aggregation Control Protocol
|
||||
|
||||
In LACP mode, LACPDUs are exchanged by the link partners to qualify each
|
||||
lag member, while in static mode only carrier is used. This additional
|
||||
exchange in LACP ensures traffic can be forwarded in both directions.
|
||||
|
||||
Traffic distribution, for both modes, across the active lag member ports
|
||||
is determined by the hash policy[^1]. It uses an XOR of the source,
|
||||
destination MAC addresses and the EtherType field. This, IEEE
|
||||
802.3ad-compliant, algorithm will place all traffic to a particular
|
||||
network peer on the same link. Meaning there is no increased bandwidth
|
||||
for communication between two specific devices.
|
||||
|
||||
> [!TIP]
|
||||
> Similar to other interface types, naming your interface `lagN`, where
|
||||
> `N` is a number, allows the CLI to automatically infer the interface
|
||||
> type as LAG.
|
||||
|
||||
|
||||
#### Basic Configuration
|
||||
|
||||
Creating a link aggregate interface and adding member ports:
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit interface lag0
|
||||
admin@example:/config/interface/lag0/> set lag mode static
|
||||
admin@example:/config/interface/lag0/> end
|
||||
admin@example:/config/> set interface eth7 lag-port lag lag0
|
||||
admin@example:/config/> set interface eth8 lag-port lag lag0
|
||||
admin@example:/config/> leave
|
||||
```
|
||||
|
||||
A static lag responds only to link (carrier) changes of member ports.
|
||||
E.g., in this example egressing traffic is continuously distributed over
|
||||
the two links until link down on one link is detected, triggering all
|
||||
traffic to be steered to the sole remaining link.
|
||||
|
||||
|
||||
#### LACP Configuration
|
||||
|
||||
LACP mode provides dynamic negotiation of the link aggregate. Key
|
||||
settings include:
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit interface lag0
|
||||
admin@example:/config/interface/lag0/> set lag mode lacp
|
||||
admin@example:/config/interface/lag0/> set lag lacp mode passive
|
||||
admin@example:/config/interface/lag0/> set lag lacp rate fast
|
||||
admin@example:/config/interface/lag0/> set lag lacp system-priority 100
|
||||
```
|
||||
|
||||
LACP mode supports two operational modes:
|
||||
|
||||
- **active:** Initiates negotiation by sending LACPDUs (default)
|
||||
- **passive:** Waits for peer to initiate negotiation
|
||||
|
||||
> [!NOTE]
|
||||
> At least one end of the link must be in active mode for negotiation to occur.
|
||||
|
||||
The LACP rate setting controls protocol timing:
|
||||
|
||||
- **slow:** LACPDUs sent every 30 seconds, with 90 second timeout (default)
|
||||
- **fast:** LACPDUs sent every second, with 3 second timeout
|
||||
|
||||
|
||||
#### Link Flapping
|
||||
|
||||
To protect against link flapping, debounce timers can be configured to
|
||||
delay link qualification. Usually only the `up` delay is needed:
|
||||
|
||||
```
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/> edit debounce
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/debounce/> set up 500
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/debounce/> set down 200
|
||||
```
|
||||
|
||||
#### Operational Status, Overview
|
||||
|
||||
Like other interfaces, link aggregates are also available in the general
|
||||
interfaces overview in the CLI admin-exec context. Here is the above
|
||||
static mode aggregate:
|
||||
|
||||
```
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
ipv6 ::1/128 (static)
|
||||
.
|
||||
.
|
||||
.
|
||||
lag0 lag UP static: balance-xor, hash: layer2
|
||||
│ ethernet UP 00:a0:85:00:02:00
|
||||
├ eth7 lag ACTIVE
|
||||
└ eth8 lag ACTIVE
|
||||
```
|
||||
|
||||
Same aggregate, but in LACP mode:
|
||||
|
||||
```
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
ipv6 ::1/128 (static)
|
||||
.
|
||||
.
|
||||
.
|
||||
lag0 lag UP lacp: active, rate: fast (1s), hash: layer2
|
||||
│ ethernet UP 00:a0:85:00:02:00
|
||||
├ eth7 lag ACTIVE active, short_timeout, aggregating, in_sync, collecting, distributing
|
||||
└ eth8 lag ACTIVE active, short_timeout, aggregating, in_sync, collecting, distributing
|
||||
```
|
||||
|
||||
|
||||
#### Operational Status, Detail
|
||||
|
||||
In addition to basic status shown in the interface overview, detailed
|
||||
LAG status can be inspected:
|
||||
|
||||
```
|
||||
admin@example:/> show interfaces name lag0
|
||||
name : lag0
|
||||
index : 25
|
||||
mtu : 1500
|
||||
operational status : up
|
||||
physical address : 00:a0:85:00:02:00
|
||||
lag mode : static
|
||||
lag type : balance-xor
|
||||
lag hash : layer2
|
||||
link debounce up : 0 msec
|
||||
link debounce down : 0 msec
|
||||
ipv4 addresses :
|
||||
ipv6 addresses :
|
||||
in-octets : 0
|
||||
out-octets : 2142
|
||||
```
|
||||
|
||||
Same aggregate, but in LACP mode:
|
||||
|
||||
```
|
||||
admin@example:/> show interfaces name lag0
|
||||
name : lag0
|
||||
index : 24
|
||||
mtu : 1500
|
||||
operational status : up
|
||||
physical address : 00:a0:85:00:02:00
|
||||
lag mode : lacp
|
||||
lag hash : layer2
|
||||
lacp mode : active
|
||||
lacp rate : fast (1s)
|
||||
lacp aggregate id : 1
|
||||
lacp system priority: 65535
|
||||
lacp actor key : 9
|
||||
lacp partner key : 9
|
||||
lacp partner mac : 00:a0:85:00:03:00
|
||||
link debounce up : 0 msec
|
||||
link debounce down : 0 msec
|
||||
ipv4 addresses :
|
||||
ipv6 addresses :
|
||||
in-octets : 100892
|
||||
out-octets : 111776
|
||||
```
|
||||
|
||||
Member ports provide additional status information:
|
||||
|
||||
- Link failure counter: number of detected link failures
|
||||
- LACP state flags: various states of LACP negotiation:
|
||||
- `active`: port is actively sending LACPDUs
|
||||
- `short_timeout`: using fast rate (1s) vs. slow rate (30s)
|
||||
- `aggregating`: port is allowed to aggregate in this LAG
|
||||
- `in_sync`: port is synchronized with partner
|
||||
- `collecting`: port is allowed to receive traffic
|
||||
- `distributing`: port is allowed to send traffic
|
||||
- `defaulted`: using default partner info (partner not responding)
|
||||
- `expired`: partner info has expired (no LACPDUs received)
|
||||
- Aggregator ID: unique identifier for this LAG group
|
||||
- Actor state: LACP state flags for this port (local)
|
||||
- Partner state: LACP state flags from the remote port
|
||||
|
||||
Example member port status:
|
||||
|
||||
```
|
||||
admin@example:/> show interfaces name eth7
|
||||
name : eth7
|
||||
index : 8
|
||||
mtu : 1500
|
||||
operational status : up
|
||||
physical address : 00:a0:85:00:02:00
|
||||
lag member : lag0
|
||||
lag member state : active
|
||||
lacp aggregate id : 1
|
||||
lacp actor state : active, short_timeout, aggregating, in_sync, collecting, distributing
|
||||
lacp partner state : active, short_timeout, aggregating, in_sync, collecting, distributing
|
||||
link failure count : 0
|
||||
ipv4 addresses :
|
||||
ipv6 addresses :
|
||||
in-octets : 473244
|
||||
out-octets : 499037
|
||||
```
|
||||
|
||||
|
||||
#### Example: Switch Uplink with LACP
|
||||
|
||||
LACP mode provides the most robust operation, automatically negotiating
|
||||
the link aggregate and detecting configuration mismatches.
|
||||
|
||||
A common use case is connecting a switch to an upstream device:
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit interface lag0
|
||||
admin@example:/config/interface/lag0/> set lag mode lacp
|
||||
```
|
||||
|
||||
Enable fast LACP for quicker fail-over:
|
||||
|
||||
```
|
||||
admin@example:/config/interface/lag0/> set lag lacp rate fast
|
||||
```
|
||||
|
||||
Add uplink ports
|
||||
|
||||
```
|
||||
admin@example:/config/interface/lag0/> end
|
||||
admin@example:/config/> set interface eth7 lag-port lag lag0
|
||||
admin@example:/config/> set interface eth8 lag-port lag lag0
|
||||
```
|
||||
|
||||
Enable protection against "link flapping".
|
||||
|
||||
```
|
||||
admin@example:/config/interface/lag0/> edit lag link-monitor
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/> edit debounce
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/debounce/> set up 500
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/debounce/> set down 200
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/debounce/> top
|
||||
```
|
||||
|
||||
Add to bridge for switching
|
||||
|
||||
```
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/debounce/> end
|
||||
admin@example:/config/> set interface lag0 bridge-port bridge br0
|
||||
admin@example:/config/> leave
|
||||
```
|
||||
|
||||
|
||||
### VLAN Interfaces
|
||||
|
||||
Creating a VLAN can be done in many ways. This section assumes VLAN
|
||||
Creating a VLAN can be done in many ways. This section assumes VLAN
|
||||
interfaces created atop another Linux interface. E.g., the VLAN
|
||||
interfaces created on top of the Ethernet interface or bridge in the
|
||||
picture below.
|
||||
@@ -472,7 +733,7 @@ top of a bridge interface *br0* is named *vlan10*.
|
||||
|
||||
> [!NOTE]
|
||||
> If you name your VLAN interface `foo0.N` or `vlanN`, where `N` is a
|
||||
> number, Infix will set the interface type automatically for you.
|
||||
> number, the CLI infers the interface type automatically.
|
||||
|
||||
|
||||
### Physical Ethernet Interfaces
|
||||
@@ -638,7 +899,8 @@ admin@example:/config/>
|
||||
This section details IP Addresses And Other Per-Interface IP settings.
|
||||
|
||||
Infix support several network interface types, each can be assigned one
|
||||
or more IP addresses, both IPv4 and IPv6 are supported.
|
||||
or more IP addresses, both IPv4 and IPv6 are supported. (There is no
|
||||
concept of a "primary" address.)
|
||||
|
||||

|
||||
|
||||
@@ -661,31 +923,31 @@ are listed below. Configurable options can be disabled on a per client
|
||||
interface basis, some options, like `clientid` and option 81, are
|
||||
possible to set the value of as well.
|
||||
|
||||
| **Opt** | **Name** | **Cfg** | **Description** |
|
||||
|---------|------------------|---------|-----------------------------------------------------|
|
||||
| 1 | `subnet` | No | Request IP address and netmask |
|
||||
| 3 | `router` | Yes | Default route(s), see also option 121 and 249 |
|
||||
| 6 | `dns` | Yes | DNS server(s), static ones take precedence |
|
||||
| 12 | `hostname` | Yes | DHCP cannot set hostname, only for informing server |
|
||||
| 15 | `domain` | Yes | Default domain name, for name resolution |
|
||||
| 28 | `broadcast` | Yes | Broadcast address, calculated if disabled |
|
||||
| 42 | `ntpsrv` | Yes | NTP server(s), static ones take precedence |
|
||||
| 50 | `address` | Yes | Request (previously cached) address |
|
||||
| 61 | `clientid` | Yes | Default MAC address (and option 12) |
|
||||
| 81 | `fqdn` | Yes | Similar to option 12, request FQDN update in DNS |
|
||||
| 119 | `search` | Yes | Request domain search list |
|
||||
| 121 | `staticroutes` | Yes | Classless static routes |
|
||||
| 249 | `msstaticroutes` | Yes | Microsoft static route |
|
||||
| | | | |
|
||||
| **Opt** | **Name** | **Cfg** | **Description** |
|
||||
|---------|-----------------------------|---------|-----------------------------------------------------|
|
||||
| 1 | `netmask` | No | Request IP address and netmask |
|
||||
| 3 | `router` | Yes | Default route(s), see also option 121 and 249 |
|
||||
| 6 | `dns-server` | Yes | DNS server(s), static ones take precedence |
|
||||
| 12 | `hostname` | Yes | DHCP cannot set hostname, only for informing server |
|
||||
| 15 | `domain` | Yes | Default domain name, for name resolution |
|
||||
| 28 | `broadcast` | Yes | Broadcast address, calculated if disabled |
|
||||
| 42 | `ntp-server` | Yes | NTP server(s), static ones take precedence |
|
||||
| 50 | `address` | Yes | Request (previously cached) address |
|
||||
| 61 | `client-id` | Yes | Default MAC address (and option 12) |
|
||||
| 81 | `fqdn` | Yes | Similar to option 12, request FQDN update in DNS |
|
||||
| 119 | `search` | Yes | Request domain search list |
|
||||
| 121 | `classless-static-route` | Yes | Classless static routes |
|
||||
| 249 | `ms-classless-static-route` | Yes | Microsoft static route, same as option 121 |
|
||||
| | | | |
|
||||
|
||||
**Default:** `router`, `dns`, `domain`, `broadcast`, `ntpsrv`, `search`,
|
||||
`address`, `staticroutes`, `msstaticroutes`
|
||||
**Default:** `router`, `dns-server`, `domain`, `broadcast`, `ntp-server`, `search`,
|
||||
`address`, `classless-static-route`, `ms-classless-static-route`
|
||||
|
||||
When configuring a DHCP client, ensure that the NTP client is enabled
|
||||
for the `ntpsrv` DHCP option to be processed correctly. If the NTP
|
||||
for the `ntp-server` DHCP option to be processed correctly. If the NTP
|
||||
client is not enabled, any NTP servers provided by the DHCP server will
|
||||
be ignored. For details on how to enable the NTP client, see the
|
||||
[NTP Client Configuration](system.md#ntp-client-configuration) section.
|
||||
be ignored. For details on how to enable the NTP client, see the [NTP
|
||||
Client Configuration](system.md#ntp-client-configuration) section.
|
||||
|
||||
> [!IMPORTANT]
|
||||
> Per [RFC3442][4], if the DHCP server returns both a Classless Static
|
||||
@@ -778,7 +1040,6 @@ will be used, otherwise it falls back to the default algorithm.
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit dhcp-client
|
||||
admin@example:/config/dhcp-client/> set client-if eth0
|
||||
admin@example:/config/dhcp-client/> set enabled true
|
||||
admin@example:/config/dhcp-client/> leave
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
@@ -798,7 +1059,7 @@ The resulting address (10.1.2.100/24) is of type *dhcp*.
|
||||
The (only) way to disable IPv6 link-local addresses is by disabling IPv6
|
||||
on the interface.
|
||||
|
||||
```(disabling
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit interface eth0 ipv6
|
||||
admin@example:/config/interface/eth0/ipv6/> set enabled false
|
||||
@@ -912,33 +1173,38 @@ have changed type to *random*.
|
||||
To be able to route (static or dynamic) on the interface it is
|
||||
required to enable forwarding. This setting controls if packets
|
||||
received on this interface can be forwarded.
|
||||
```
|
||||
admin@example:/config/> edit interface eth0
|
||||
admin@example:/config/interface/eth0/> set ipv4 forwarding
|
||||
admin@example:/config/interface/eth0/> leave
|
||||
admin@example:/>
|
||||
```
|
||||
|
||||
```
|
||||
admin@example:/config/> edit interface eth0
|
||||
admin@example:/config/interface/eth0/> set ipv4 forwarding
|
||||
admin@example:/config/interface/eth0/> leave
|
||||
admin@example:/>
|
||||
```
|
||||
|
||||
|
||||
### IPv6 forwarding
|
||||
|
||||
This flag behaves totally different than for IPv4. For IPv6 the
|
||||
ability to route between interfaces is always enabled, instead this
|
||||
flag controls if the interface will be in host/router mode.
|
||||
Due to how the Linux kernel manages IPv6 forwarding, we can not fully
|
||||
control it per interface via this setting like how IPv4 works. Instead,
|
||||
IPv6 forwarding is globally enabled when at least one interface enable
|
||||
forwarding, otherwise it is disabled.
|
||||
|
||||
| **Feature** | **Forward enabled** | **Forward disabled** |
|
||||
|:-----------------------------------------|:--------------------|:---------------------|
|
||||
| IsRouter set in Neighbour Advertisements | Yes | No |
|
||||
| Transmit Router Solicitations | No | Yes |
|
||||
| Router Advertisements are ignored | No | Yes |
|
||||
| Accept Redirects | No | Yes |
|
||||
The following table shows the system IPv6 features that the `forwarding`
|
||||
setting control when it is *Enabled* or *Disabled:
|
||||
|
||||
```
|
||||
admin@example:/config/> edit interface eth0
|
||||
admin@example:/config/interface/eth0/> set ipv6 forwarding
|
||||
admin@example:/config/interface/eth0/> leave
|
||||
admin@example:/>
|
||||
```
|
||||
| **IPv6 Feature** | **Enabled** | **Disabled** |
|
||||
|:-----------------------------------------|:------------|:-------------|
|
||||
| IsRouter set in Neighbour Advertisements | Yes | No |
|
||||
| Transmit Router Solicitations | No | Yes |
|
||||
| Router Advertisements are ignored | Yes | Yes |
|
||||
| Accept Redirects | No | Yes |
|
||||
|
||||
```
|
||||
admin@example:/config/> edit interface eth0
|
||||
admin@example:/config/interface/eth0/> set ipv6 forwarding
|
||||
admin@example:/config/interface/eth0/> leave
|
||||
admin@example:/>
|
||||
```
|
||||
|
||||
|
||||
## Routing support
|
||||
@@ -1226,7 +1492,7 @@ currently supported, namely `ipv4` and `ipv6`.
|
||||
[4]: https://www.rfc-editor.org/rfc/rfc3442
|
||||
[0]: https://frrouting.org/
|
||||
|
||||
[^1]: Please note, link aggregates are not yet supported in Infix.
|
||||
[^1]: `(source MAC XOR destination MAC XOR EtherType) MODULO num_links`
|
||||
[^2]: Link-local IPv6 addresses are implicitly enabled when enabling
|
||||
IPv6. IPv6 can be enabled/disabled per interface in the
|
||||
[ietf-ip][2] YANG model.
|
||||
@@ -1237,11 +1503,10 @@ currently supported, namely `ipv4` and `ipv6`.
|
||||
[^4]: A YANG deviation was previously used to make it possible to set
|
||||
`phys-address`, but this has been replaced with the more flexible
|
||||
`custom-phys-address`.
|
||||
[^5]: Infix MAC bridges on Marvell Linkstreet devices are currently
|
||||
limited to use a single MAC database, causing issues if the same
|
||||
MAC address appears on different MAC bridges.
|
||||
[^6]: Ethernet counters are described in
|
||||
*ieee802-ethernet-interface.yang* and
|
||||
*infix-ethernet-interface.yang*. [Ethernet
|
||||
Counters](eth-counters.md) page provides additional details on
|
||||
statistics support.
|
||||
[^5]: MAC bridges on Marvell Linkstreet devices are currently limited to
|
||||
a single MAC database, this may be a problem if the same MAC address
|
||||
appears in different MAC bridges.
|
||||
[^6]: Ethernet counters are described in *ieee802-ethernet-interface.yang*
|
||||
and *infix-ethernet-interface.yang*. There is a dedicated document on
|
||||
[Ethernet Counters](eth-counters.md) that provide additional details
|
||||
on the statistics support.
|
||||
|
||||
+56
-3
@@ -853,14 +853,18 @@ models for details.
|
||||
### Factory Reset
|
||||
|
||||
```
|
||||
~$ curl -kX POST -H "Content-Type: application/yang-data+json" https://example.local/restconf/operations/ietf-factory-default:factory-reset -u admin:admin
|
||||
~$ curl -kX POST -u admin:admin \
|
||||
-H "Content-Type: application/yang-data+json" \
|
||||
https://example.local/restconf/operations/ietf-factory-default:factory-reset
|
||||
curl: (56) OpenSSL SSL_read: error:0A000126:SSL routines::unexpected eof while reading, errno 0
|
||||
```
|
||||
|
||||
### System Reboot
|
||||
|
||||
```
|
||||
~$ curl -kX POST -H "Content-Type: application/yang-data+json" https://example.local/restconf/operations/ietf-system:system-restart -u admin:admin
|
||||
~$ curl -kX POST -u admin:admin \
|
||||
-H "Content-Type: application/yang-data+json" \
|
||||
https://example.local/restconf/operations/ietf-system:system-restart
|
||||
```
|
||||
|
||||
### Set Date and Time
|
||||
@@ -868,7 +872,11 @@ curl: (56) OpenSSL SSL_read: error:0A000126:SSL routines::unexpected eof while r
|
||||
Here's an example of an RPC that takes input/argument:
|
||||
|
||||
```
|
||||
~$ curl -kX POST -H "Content-Type: application/yang-data+json" https://example.local/restconf/operations/ietf-system:set-current-datetime -u admin:admin -d '{"ietf-system:input": {"current-datetime": "2024-04-17T13:48:02-01:00"}}'
|
||||
~$ curl -kX POST -u admin:admin \
|
||||
-H "Content-Type: application/yang-data+json" \
|
||||
-d '{"ietf-system:input": {"current-datetime": "2024-04-17T13:48:02-01:00"}}' \
|
||||
https://example.local/restconf/operations/ietf-system:set-current-datetime
|
||||
|
||||
```
|
||||
|
||||
You can verify that the changes took by a remote SSH command:
|
||||
@@ -879,6 +887,51 @@ Wed Apr 17 14:48:12 UTC 2024
|
||||
~$
|
||||
```
|
||||
|
||||
### Read Hostname
|
||||
|
||||
Example of fetching JSON configuration data to stdout:
|
||||
|
||||
```
|
||||
~$ curl -kX GET -u admin:admin \
|
||||
-H 'Accept: application/yang-data+json' \
|
||||
https://example.local/restconf/data/ietf-system:system/hostname
|
||||
{
|
||||
"ietf-system:system": {
|
||||
"hostname": "foo"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
### Set Hostname
|
||||
|
||||
Example of inline JSON data:
|
||||
|
||||
```
|
||||
~$ curl -kX PATCH -u admin:admin \
|
||||
-H 'Content-Type: application/yang-data+json' \
|
||||
-d '{"ietf-system:system":{"hostname":"bar"}}' \
|
||||
https://example.local/restconf/data/ietf-system:system
|
||||
```
|
||||
|
||||
### Copy Running to Startup
|
||||
|
||||
No copy command available yet to copy between datastores, and the
|
||||
Rousette back-end also does not support "write-through" to the
|
||||
startup datastore.
|
||||
|
||||
To save running-config to startup-config, use the following example to
|
||||
fetch running to a local file and then update startup with it:
|
||||
|
||||
```
|
||||
~$ curl -kX GET -u admin:admin -o running-config.json \
|
||||
-H 'Accept: application/yang-data+json' \
|
||||
https://example.local/restconf/ds/ietf-datastores:running
|
||||
|
||||
~$ curl -kX PUT -u admin:admin -d @running-config.json \
|
||||
-H 'Content-Type: application/yang-data+json' \
|
||||
https://example.local/restconf/ds/ietf-datastores:startup
|
||||
```
|
||||
|
||||
|
||||
## Miscellaneous
|
||||
|
||||
|
||||
+106
-59
@@ -11,9 +11,10 @@ specific string followed by the last three octets of the system base MAC
|
||||
address, e.g., `switch-12-34-56`. An example of how to change the
|
||||
hostname is included below.
|
||||
|
||||
> **Note:** when issuing `leave` to activate your changes, remember to
|
||||
> also save your settings, `copy running-config startup-config`. See
|
||||
> the [CLI Introduction](cli/introduction.md) for a background.
|
||||
> [!NOTE]
|
||||
> When issuing `leave` to activate your changes, remember to also save
|
||||
> your settings, `copy running-config startup-config`. See the [CLI
|
||||
> Introduction](cli/introduction.md) for a background.
|
||||
|
||||
|
||||
## Changing Password
|
||||
@@ -24,14 +25,14 @@ available in the system authentication configuration context.
|
||||
```
|
||||
admin@host:/config/> edit system authentication user admin
|
||||
admin@host:/config/system/authentication/user/admin/> change password
|
||||
New password:
|
||||
Retype password:
|
||||
New password:
|
||||
Retype password:
|
||||
admin@host:/config/system/authentication/user/admin/> leave
|
||||
```
|
||||
|
||||
The `change password` command starts an interactive dialogue that asks
|
||||
for the new password, with a confirmation, and then salts and encrypts
|
||||
the password with sha512crypt.
|
||||
the password with sha512crypt.
|
||||
|
||||
It is also possible to use the `set password ...` command. This allows
|
||||
setting an already hashed password. To manually hash a password, use
|
||||
@@ -39,7 +40,8 @@ the `do password encrypt` command. This launches the admin-exec command
|
||||
to hash, and optionally salt, your password. This encrypted string can
|
||||
then be used with `set password ...`.
|
||||
|
||||
> **Tip:** if you are having trouble thinking of a password, Infix has a
|
||||
> [!TIP]
|
||||
> If you are having trouble thinking of a password, there is a nifty
|
||||
> `password generate` command in admin-exec context which generates
|
||||
> random passwords using the UNIX command `pwgen`. Use the `do` prefix
|
||||
> when inside any configuration context to access admin-exec commands.
|
||||
@@ -55,7 +57,7 @@ With SSH keys in place it is possible to disable password login, just
|
||||
remember to verify SSH login and network connectivity before doing so.
|
||||
|
||||
```
|
||||
admin@host:/config/> edit system authentication user admin
|
||||
admin@host:/config/> edit system authentication user admin
|
||||
admin@host:/config/system/authentication/user/admin/> edit authorized-key example@host
|
||||
admin@host:/config/system/authentication/user/admin/authorized-key/example@host/> set algorithm ssh-rsa
|
||||
admin@host:/config/system/authentication/user/admin/authorized-key/example@host/> set key-data AAAAB3NzaC1yc2EAAAADAQABAAABgQC8iBL42yeMBioFay7lty1C4ZDTHcHyo739gc91rTTH8SKvAE4g8Rr97KOz/8PFtOObBrE9G21K7d6UBuPqmd0RUF2CkXXN/eN2PBSHJ50YprRFt/z/304bsBYkDdflKlPDjuSmZ/+OMp4pTsq0R0eNFlX9wcwxEzooIb7VPEdvWE7AYoBRUdf41u3KBHuvjGd1M6QYJtbFLQMMTiVe5IUfyVSZ1RCxEyAB9fR9CBhtVheTVsY3iG0fZc9eCEo89ErDgtGUTJK4Hxt5yCNwI88YaVmkE85cNtw8YwubWQL3/tGZHfbbQ0fynfB4kWNloyRHFr7E1kDxuX5+pbv26EqRdcOVGucNn7hnGU6C1+ejLWdBD7vgsoilFrEaBWF41elJEPKDzpszEijQ9gTrrWeYOQ+x++lvmOdssDu4KvGmj2K/MQTL2jJYrMJ7GDzsUu3XikChRL7zNfS2jYYQLzovboUCgqfPUsVba9hqeX3U67GsJo+hy5MG9RSry4+ucHs=
|
||||
@@ -65,9 +67,10 @@ key-data AAAAB3NzaC1yc2EAAAADAQABAAABgQC8iBL42yeMBioFay7lty1C4ZDTHcHyo739gc91rTT
|
||||
admin@host:/config/system/authentication/user/admin/authorized-key/example@host/> leave
|
||||
```
|
||||
|
||||
> **Note:** the `ssh-keygen` program already base64 encodes the public
|
||||
> key data, so there is no need to use the `text-editor` command, `set`
|
||||
> does the job.
|
||||
> [!NOTE]
|
||||
> The `ssh-keygen` program already base64 encodes the public key data,
|
||||
> so there is no need to use the `text-editor` command, `set` does the
|
||||
> job.
|
||||
|
||||
|
||||
## Multiple Users
|
||||
@@ -145,7 +148,7 @@ is committed by issuing the `leave` command.
|
||||
admin@host:/config/> edit system
|
||||
admin@host:/config/system/> set hostname example
|
||||
admin@host:/config/system/> leave
|
||||
admin@host:/>
|
||||
admin@example:/>
|
||||
```
|
||||
|
||||
The hostname is advertised over mDNS-SD in the `.local` domain. If
|
||||
@@ -154,8 +157,24 @@ case, mDNS will advertise a "uniqified" variant, usually suffixing with
|
||||
an index, e.g., `example-1.local`. Use an mDNS browser to scan for
|
||||
available devices on your LAN.
|
||||
|
||||
> **Note:** critical services like syslog, mDNS, LLDP, and similar that
|
||||
> advertise the hostname, are restarted when the hostname is changed.
|
||||
In some cases you may want to set the device's *domain name* as well.
|
||||
This is handled the same way:
|
||||
|
||||
```
|
||||
admin@host:/config/> edit system
|
||||
admin@host:/config/system/> set hostname foo.example.com
|
||||
admin@host:/config/system/> leave
|
||||
admin@foo:/>
|
||||
```
|
||||
|
||||
Both host and domain name are stored in the system files `/etc/hosts`
|
||||
and `/etc/hostname`. The latter is exclusively for the host name. The
|
||||
domain *may* be used by the system DHCP server when handing out leases
|
||||
to clients, it is up to the clients to request the domain name *option*.
|
||||
|
||||
> [!NOTE]
|
||||
> Critical services like syslog, mDNS, LLDP, and similar that advertise
|
||||
> the hostname, are restarted when the hostname is changed.
|
||||
|
||||
|
||||
## Changing Login Banner
|
||||
@@ -164,8 +183,9 @@ The `motd-banner` setting is an Infix augment and an example of a
|
||||
`binary` type setting that can be changed interactively with the
|
||||
built-in [`text-editor` command](cli/text-editor.md).
|
||||
|
||||
> **Tip:** see the next section for how to change the editor used
|
||||
> to something you may be more familiar with.
|
||||
> [!TIP]
|
||||
> See the next section for how to change the editor used to something
|
||||
> you may be more familiar with.
|
||||
|
||||
```
|
||||
admin@host:/config/> edit system
|
||||
@@ -196,43 +216,90 @@ admin@host:/config/system/> leave
|
||||
admin@host:/>
|
||||
```
|
||||
|
||||
> **Note:** as usual, configuration changes only take effect after
|
||||
> issuing the `leave` command. I.e., you must change the editor first,
|
||||
> and then re-enter configure context to use your editor of choice.
|
||||
> [!IMPORTANT]
|
||||
> Configuration changes only take effect after issuing the `leave`
|
||||
> command. I.e., you must change the editor first, and then re-enter
|
||||
> configure context to use your editor of choice.
|
||||
|
||||
|
||||
## DNS Resolver Configuration
|
||||
|
||||
The system supports both static and dynamic (DHCP) DNS setup. The
|
||||
locally configured (static) server is preferred over any acquired
|
||||
from a DHCP client.
|
||||
|
||||
```
|
||||
admin@host:/> configure
|
||||
admin@host:/config/> edit system dns-resolver
|
||||
admin@host:/config/system/dns-resolver/> set server google udp-and-tcp address 8.8.8.8
|
||||
admin@host:/config/system/dns-resolver/> show
|
||||
server google {
|
||||
udp-and-tcp {
|
||||
address 8.8.8.8;
|
||||
}
|
||||
}
|
||||
admin@host:/config/system/dns-resolver/> leave
|
||||
```
|
||||
|
||||
It is also possible to configure resolver options like timeout and
|
||||
retry attempts. See the YANG model for details, or use the built-in
|
||||
help system in the CLI.
|
||||
|
||||
> [!NOTE]
|
||||
> When acting as a DHCP server and DNS proxy for other devices, any
|
||||
> local DNS server configured here is automatically used as upstream DNS
|
||||
> server.
|
||||
|
||||
|
||||
## NTP Client Configuration
|
||||
|
||||
Below is an example configuration for enabling NTP
|
||||
with a specific server and the `iburst` option for faster initial
|
||||
synchronization.
|
||||
Below is an example configuration for enabling NTP with a specific
|
||||
server and the `iburst` option for faster initial synchronization.
|
||||
|
||||
```
|
||||
admin@host:/> configure
|
||||
admin@host:/config/> set system ntp enabled
|
||||
admin@host:/config/> set system ntp server ntp-pool
|
||||
admin@host:/config/> set system ntp server ntp-pool udp address pool.ntp.org
|
||||
admin@host:/config/> set system ntp server ntp-pool iburst
|
||||
admin@host:/config/> set system ntp server ntp-pool prefer
|
||||
admin@host:/config/> edit system ntp
|
||||
admin@host:/config/system/ntp/> set enabled
|
||||
admin@host:/config/system/ntp/> set server ntp-pool
|
||||
admin@host:/config/system/ntp/> set server ntp-pool udp address pool.ntp.org
|
||||
admin@host:/config/system/ntp/> set server ntp-pool iburst
|
||||
admin@host:/config/system/ntp/> set server ntp-pool prefer
|
||||
admin@host:/config/system/ntp/> leave
|
||||
```
|
||||
|
||||
This configuration enables the NTP client and sets the NTP server to
|
||||
`pool.ntp.org` with the `iburst` and `prefer` options. The `iburst`
|
||||
option ensures faster initial synchronization, and the `prefer` option
|
||||
This configuration enables the NTP client and sets the NTP server to
|
||||
`pool.ntp.org` with the `iburst` and `prefer` options. The `iburst`
|
||||
option ensures faster initial synchronization, and the `prefer` option
|
||||
designates this server as preferred.
|
||||
|
||||
* `prefer false`: The NTP client will choose the best available source
|
||||
based on several factors, such as network delay, stratum, and other
|
||||
based on several factors, such as network delay, stratum, and other
|
||||
metrics (default config).
|
||||
* `prefer true`: The NTP client will try to use the preferred server
|
||||
* `prefer true`: The NTP client will try to use the preferred server
|
||||
as the primary source unless it becomes unreachable or unusable.
|
||||
|
||||
|
||||
### Show NTP Sources
|
||||
|
||||
The status for NTP sources is availble in YANG and accessable with
|
||||
CLI/NETCONF/RESTCONF.
|
||||
|
||||
To view the sources being used by the NTP client, run:
|
||||
```
|
||||
admin@target:/> show ntp
|
||||
ADDRESS MODE STATE STRATUM POLL-INTERVAL
|
||||
192.168.1.1 server candidate 1 6
|
||||
192.168.2.1 server candidate 1 6
|
||||
192.168.3.1 server selected 1 6
|
||||
```
|
||||
|
||||
### Show NTP Status
|
||||
|
||||
To check the status of NTP synchronization, use the following command:
|
||||
To check the status of NTP synchronization (only availble in CLI), use
|
||||
the following command:
|
||||
|
||||
```
|
||||
admin@host:/> show ntp
|
||||
admin@host:/> show ntp tracking
|
||||
Reference ID : C0248F86 (192.36.143.134)
|
||||
Stratum : 2
|
||||
Ref time (UTC) : Mon Oct 21 10:06:45 2024
|
||||
@@ -249,34 +316,14 @@ Leap status : Normal
|
||||
admin@host:/>
|
||||
```
|
||||
|
||||
This output provides detailed information about the NTP status, including
|
||||
This output provides detailed information about the NTP status, including
|
||||
reference ID, stratum, time offsets, frequency, and root delay.
|
||||
|
||||
### Show NTP Sources
|
||||
|
||||
To view the sources being used by the NTP client, run:
|
||||
|
||||
```
|
||||
admin@host:/> show ntp sources
|
||||
|
||||
.-- Source mode '^' = server, '=' = peer, '#' = local clock.
|
||||
/ .- Source state '*' = current best, '+' = combined, '-' = not combined,
|
||||
| / 'x' = may be in error, '~' = too variable, '?' = unusable.
|
||||
|| .- xxxx [ yyyy ] +/- zzzz
|
||||
|| Reachability register (octal) -. | xxxx = adjusted offset,
|
||||
|| Log2(Polling interval) --. | | yyyy = measured offset,
|
||||
|| \ | | zzzz = estimated error.
|
||||
|| | | \
|
||||
MS Name/IP address Stratum Poll Reach LastRx Last sample
|
||||
===============================================================================
|
||||
^* 192.36.143.134 1 6 177 9 +278ms[ -3845s] +/- 514ms
|
||||
admin@host:/>
|
||||
```
|
||||
|
||||
> The system uses `chronyd` for Network Time Protocol (NTP)
|
||||
> synchronization. The output shown here is best explained in the
|
||||
> [Chrony documentation](https://chrony-project.org/doc/4.6.1/chronyc.html).
|
||||
> [!TIP]
|
||||
> The system uses `chronyd` Network Time Protocol (NTP) daemon. The
|
||||
> output shown here is best explained in the [Chrony documentation][4].
|
||||
|
||||
[1]: https://www.rfc-editor.org/rfc/rfc7317
|
||||
[2]: https://github.com/kernelkit/infix/blob/main/src/confd/yang/infix-system%402024-02-29.yang
|
||||
[3]: https://www.rfc-editor.org/rfc/rfc8341
|
||||
[4]: https://chrony-project.org/doc/4.6.1/chronyc.html
|
||||
|
||||
+8
-16
@@ -243,23 +243,15 @@ spanning tree matches the expected one.
|
||||
|
||||
Integration to Infix
|
||||
--------------------
|
||||
To successfully run all Infix tests, the image must be built in
|
||||
'test-mode'. This can be achieved by setting the DISK_IMAGE_TEST_MODE
|
||||
parameter to true. Although this is the default setting, it’s advisable
|
||||
to verify it by running:
|
||||
When the test environment is started with Qeneth, it doesn't use the
|
||||
base image directly. Instead, it creates a copy and inserts a `test-mode`
|
||||
flag into it. During the bootstrap phase, the system checks for the
|
||||
presence of the test-mode flag (file).
|
||||
|
||||
$ make menuconfig
|
||||
(External Options --> -*- Disk image --> [*] Enable Test Mode)
|
||||
|
||||
Building an image in 'test-mode' results in the creation of a 'test-mode'
|
||||
file within the auxiliary (aux) partition of the Infix disk image
|
||||
(/mnt/aux/test-mode).
|
||||
|
||||
During the bootstrap phase, the system checks for the presence of this
|
||||
test-mode flag (file). If the flag exists, a 'test-config.cfg' file is
|
||||
generated. In the following step, the system loads the 'test-config'
|
||||
instead of the standard startup-config (or factory-config). This
|
||||
configuration is simple and safe, equivalent to the one used in 'Secure Mode'
|
||||
If the flag exists, a 'test-config.cfg' file is generated. In the
|
||||
following step, the system loads the 'test-config' instead of the
|
||||
standard `startup-config` (or `factory-config`). This configuration
|
||||
is simple and safe, equivalent to the one used in 'Secure Mode'
|
||||
(also known as 'failure-config').
|
||||
|
||||
Additionally, the configuration enables extra RPCs related to system
|
||||
|
||||
+51
-12
@@ -25,17 +25,6 @@ for `x86_64`:
|
||||
$ make
|
||||
$ make test
|
||||
|
||||
It is important to mention that Infix build system by default creates
|
||||
an image in 'test-mode'. The mode is set by DISK_IMAGE_TEST_MODE
|
||||
parameter (default=true). To generate a standard image set the
|
||||
DISK_IMAGE_TEST_MODE to 'false'. However, only the test mode ensures
|
||||
that all Infix tests are executed properly. Prior to the set of commands
|
||||
above, it is always good to check that DISK_IMAGE_TEST_MODE is properly
|
||||
set by running:
|
||||
|
||||
$ make menuconfig
|
||||
(External Options --> -*- Disk image --> [*] Enable Test Mode)
|
||||
|
||||
### Physical Devices
|
||||
|
||||
To run the tests on a preexisting topology from the host's network
|
||||
@@ -99,8 +88,11 @@ arguments:
|
||||
To run a suite of tests, e.g., only the DHCP client tests, pass the
|
||||
suite as an argument to [9PM][]:
|
||||
|
||||
11:42:53 infamy0:test # ./9pm/9pm.py case/infix_dhcp/all.yaml
|
||||
11:42:53 infamy0:test # ./9pm/9pm.py case/infix_dhcp/infix_dhcp.yaml
|
||||
|
||||
To run the suite of all tests:
|
||||
|
||||
11:42:53 infamy0:test # ./9pm/9pm.py case/all.yaml
|
||||
|
||||
### Connecting to Infamy
|
||||
|
||||
@@ -315,5 +307,52 @@ The test specifaction can be genererated with:
|
||||
|
||||
$ make test-spec
|
||||
|
||||
### Test Development
|
||||
|
||||
For adding a new test to the automated regression test suite, it's best
|
||||
to start by reviewing an existing test case.
|
||||
|
||||
All tests are located in the `infix/test/case` repository and are
|
||||
grouped by the features they verify. For example,
|
||||
`infix/test/case/infix_services` contains tests for various Infix
|
||||
services, such as LLDP and mDNS.
|
||||
|
||||
While test grouping is flexible, each test should be placed in a
|
||||
logically relevant category.
|
||||
|
||||
When creating a new test group, add it to `infix/test/case/all.yaml`,
|
||||
to enable it to run as a
|
||||
[subset of the test suite](#running-subsets-of-tests):
|
||||
|
||||
```
|
||||
- name: infix-services
|
||||
suite: infix_services/infix_services.yaml
|
||||
```
|
||||
|
||||
A new test (e.g., lldp_enable_disable) should be added to the
|
||||
corresponding test group .yaml file, such as
|
||||
`infix/test/cases/infix_services.yaml`:
|
||||
|
||||
```
|
||||
- name: lldp_enable_disable
|
||||
case: lldp_enable_disable/test.py
|
||||
```
|
||||
|
||||
It is necessary to include the test in
|
||||
`infix/test/case/infix_services/Readme.adoc` to ensure proper test
|
||||
specification generation:
|
||||
|
||||
```
|
||||
include::lldp_enable_disable/Readme.adoc[]
|
||||
```
|
||||
|
||||
Each test case should have its own directory under,
|
||||
`infix/test/case/infix_services`, containing:
|
||||
- `test.py` - the test script
|
||||
- `topology.dot` - the logical topology definition.
|
||||
|
||||
When the [test specification](#test-specification) is generated,
|
||||
`topology.svg` and `Readme.adoc` should also be created.
|
||||
|
||||
[9PM]: https://github.com/rical/9pm
|
||||
[Qeneth]: https://github.com/wkz/qeneth
|
||||
|
||||
@@ -0,0 +1,28 @@
|
||||
# Tunnel configuration
|
||||
|
||||
Tunnel traffic from point A to point B
|
||||
|
||||
|
||||
## Generic Routing Encapsulation (GRE)
|
||||
|
||||
The support for GRE tunnels includes IPv4 and IPv6 tunnels both in GRE
|
||||
(IP) and GRETAP (MAC) modes.
|
||||
```
|
||||
admin@example:/config/> edit interface gre1
|
||||
admin@example:/config/interface/gre1/> set type gretap
|
||||
admin@example:/config/interface/gre1/> set gre local 192.168.3.1 remote 192.168.3.2
|
||||
admin@example:/config/interface/gre1/> leave
|
||||
admin@example:/>
|
||||
```
|
||||
|
||||
## Virtual eXtensible Local Area Network (VXLAN)
|
||||
|
||||
The support for VXLAN tunnels includes IPv4 and IPv6.
|
||||
|
||||
```
|
||||
admin@example:/config/> edit interface vxlan100
|
||||
admin@example:/config/interface/vxlan100/> set vxlan local 192.168.3.1
|
||||
admin@example:/config/interface/vxlan100/> set vxlan remote 192.168.3.2
|
||||
admin@example:/config/interface/vxlan100/> set vxlan vni 100
|
||||
admin@example:/config/interface/vxlan100/> leave
|
||||
```
|
||||
+1
-3
@@ -1,9 +1,7 @@
|
||||
IXMSG = printf "\e[37;44m>>> $(call qstrip,$(1))\e[0m\n"
|
||||
|
||||
include $(BR2_EXTERNAL_INFIX_PATH)/infix.mk
|
||||
include $(sort $(wildcard $(BR2_EXTERNAL_INFIX_PATH)/package/*/*.mk))
|
||||
include $(BR2_EXTERNAL_INFIX_PATH)/board/common/common.mk
|
||||
-include $(BR2_EXTERNAL_INFIX_PATH)/board/$(patsubst "%",%,$(BR2_ARCH))/board.mk
|
||||
include $(BR2_EXTERNAL_INFIX_PATH)/infix.mk
|
||||
include $(BR2_EXTERNAL_INFIX_PATH)/test/test.mk
|
||||
|
||||
.PHONY: local.mk
|
||||
|
||||
@@ -1 +1,12 @@
|
||||
IXMSG = printf "\e[37;44m>>> $(call qstrip,$(1))\e[0m\n"
|
||||
|
||||
oem-dir := $(call qstrip,$(INFIX_OEM_PATH))
|
||||
INFIX_TOPDIR = $(if $(oem-dir),$(oem-dir),$(BR2_EXTERNAL_INFIX_PATH))
|
||||
|
||||
# Unless the user specifies an explicit build id, source it from git.
|
||||
# The build id also becomes the image version, unless an official
|
||||
# release is being built.
|
||||
export INFIX_BUILD_ID ?= $(shell git -C $(INFIX_TOPDIR) describe --dirty --always --tags)
|
||||
export INFIX_VERSION = $(if $(INFIX_RELEASE),$(INFIX_RELEASE),$(INFIX_BUILD_ID))
|
||||
|
||||
INFIX_CFLAGS:=-Wall -Werror -Wextra -Wno-unused-parameter -Wformat=2 -Wformat-overflow=2 -Winit-self -Wstrict-overflow=4 -Wno-format-truncation -Wno-format-nonliteral
|
||||
|
||||
@@ -1,5 +1,9 @@
|
||||
menu "Packages"
|
||||
|
||||
comment "Hardware Support"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/board/Config.in"
|
||||
|
||||
comment "Software Packages"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/bin/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/confd/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/confd-test-mode/Config.in"
|
||||
@@ -36,5 +40,6 @@ source "$BR2_EXTERNAL_INFIX_PATH/package/sysrepo-cpp/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/rousette/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/nghttp2-asio/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/date-cpp/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/rauc-installation-status/Config.in"
|
||||
|
||||
endmenu
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
menu "Boards"
|
||||
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/board/alder-alder/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/board/freescale-imx8mp-evk/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/board/marvell-cn9130-crb/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/board/marvell-espressobin/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/board/microchip-sparx5-pcb135/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/board/styx-dcp-sc-28p/Config.in"
|
||||
|
||||
endmenu
|
||||
@@ -0,0 +1,5 @@
|
||||
config BR2_PACKAGE_ALDER_ALDER
|
||||
bool "Alder"
|
||||
depends on BR2_aarch64
|
||||
help
|
||||
Alder
|
||||
@@ -0,0 +1,2 @@
|
||||
$(eval $(ix-board))
|
||||
$(eval $(generic-package))
|
||||
@@ -0,0 +1,53 @@
|
||||
define inner-ix-board
|
||||
|
||||
$(2)_VERSION = ix-board
|
||||
$(2)_LICENSE = BSD-3-Clause
|
||||
$(2)_LICENSE_FILES = LICENSE
|
||||
$(2)_SITE_METHOD = local
|
||||
$(2)_SITE = $$(BR2_EXTERNAL_INFIX_PATH)/src/board/$(1)
|
||||
$(2)_REDISTRIBUTE = NO
|
||||
|
||||
# The kernel must be built first.
|
||||
$(2)_DEPENDENCIES += \
|
||||
linux \
|
||||
$$(BR2_MAKE_HOST_DEPENDENCY)
|
||||
|
||||
# This is only defined in some infrastructures (e.g. autotools, cmake),
|
||||
# but not in others (e.g. generic). So define it here as well.
|
||||
$(2)_MAKE ?= $$(BR2_MAKE)
|
||||
|
||||
define $(2)_DTBS_BUILD
|
||||
@$$(call MESSAGE,"Building device tree blob(s)")
|
||||
$$(LINUX_MAKE_ENV) $$($$(PKG)_MAKE) \
|
||||
-C $$(LINUX_DIR) \
|
||||
$$(LINUX_MAKE_FLAGS) \
|
||||
$$($(2)_DTB_MAKE_OPTS) \
|
||||
PWD=$$(@D)/dts \
|
||||
M=$$(@D)/dts \
|
||||
modules
|
||||
endef
|
||||
$(2)_POST_BUILD_HOOKS += $(2)_DTBS_BUILD
|
||||
|
||||
define $(2)_DTBS_INSTALL_TARGET
|
||||
@$$(call MESSAGE,"Installing device tree blob(s)")
|
||||
$$(TARGET_MAKE_ENV) $$(TARGET_CONFIGURE_OPTS) $$($$(PKG)_MAKE) \
|
||||
-f $$(BR2_EXTERNAL_INFIX_PATH)/package/board/dtb-inst.makefile \
|
||||
-C $$(@D)/dts \
|
||||
DESTDIR="$$(TARGET_DIR)" \
|
||||
install
|
||||
endef
|
||||
$(2)_POST_INSTALL_TARGET_HOOKS += $(2)_DTBS_INSTALL_TARGET
|
||||
|
||||
define $(2)_OVERLAY_INSTALL_TARGET
|
||||
@test -d $$(@D)/rootfs && \
|
||||
$$(call MESSAGE,"Copying overlay") && \
|
||||
$$(call SYSTEM_RSYNC,$$(@D)/rootfs,$(TARGET_DIR)) || \
|
||||
true
|
||||
endef
|
||||
$(2)_POST_INSTALL_TARGET_HOOKS += $(2)_OVERLAY_INSTALL_TARGET
|
||||
|
||||
endef
|
||||
|
||||
ix-board = $(call inner-ix-board,$(pkgname),$(call UPPERCASE,$(pkgname)))
|
||||
|
||||
include $(sort $(wildcard $(BR2_EXTERNAL_INFIX_PATH)/package/board/*/*.mk))
|
||||
@@ -0,0 +1,9 @@
|
||||
include Makefile
|
||||
|
||||
install: $(addprefix $(DESTDIR)/boot/,$(dtb-y))
|
||||
|
||||
$(DESTDIR)/boot/%.dtb: %.dtb
|
||||
@echo " DTB-INSTALL $<"
|
||||
@install -D $< $@
|
||||
|
||||
.PHONY: install
|
||||
@@ -0,0 +1,6 @@
|
||||
config BR2_PACKAGE_FREESCALE_IMX8MP_EVK
|
||||
bool "NXP i.MX8MP EVK"
|
||||
depends on BR2_aarch64
|
||||
help
|
||||
NXP i.MX8MP EVK
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
define FREESCALE_IMX8MP_EVK_LINUX_CONFIG_FIXUPS
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_ARCH_NXP)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_ARCH_MXC)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_FEC)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_NET_VENDOR_STMICRO)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_STMMAC_ETH)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_DWMAC_IMX8)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_SERIAL_IMX)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_SERIAL_IMX_CONSOLE)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_I2C_IMX)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_SPI_IMX)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_PINCTRL_IMX8MP)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_GPIO_MXC)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_IMX2_WDT)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_MMC_SDHCI_OF_ESDHC)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_MMC_SDHCI_ESDHC_IMX)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_CLK_IMX8MP)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_NVMEM_IMX_OCOTP)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_INTERCONNECT)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_INTERCONNECT_IMX)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_INTERCONNECT_IMX8MP)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_REALTEK_PHY)
|
||||
endef
|
||||
|
||||
$(eval $(ix-board))
|
||||
$(eval $(generic-package))
|
||||
@@ -0,0 +1,5 @@
|
||||
config BR2_PACKAGE_MARVELL_CN9130_CRB
|
||||
bool "Marvell CN9130-CRB"
|
||||
depends on BR2_aarch64
|
||||
help
|
||||
Customer Reference Board for CN9130
|
||||
@@ -0,0 +1,2 @@
|
||||
$(eval $(ix-board))
|
||||
$(eval $(generic-package))
|
||||
@@ -0,0 +1,5 @@
|
||||
config BR2_PACKAGE_MARVELL_ESPRESSOBIN
|
||||
bool "Marvell ESPRESSObin"
|
||||
depends on BR2_aarch64
|
||||
help
|
||||
Marvell ESPRESSObin
|
||||
@@ -0,0 +1,2 @@
|
||||
$(eval $(ix-board))
|
||||
$(eval $(generic-package))
|
||||
@@ -0,0 +1,5 @@
|
||||
config BR2_PACKAGE_MICROCHIP_SPARX5_PCB135
|
||||
bool "Microchip SparX-5i PCB135"
|
||||
depends on BR2_aarch64
|
||||
help
|
||||
Microchip's evaluation board for SparX-5i
|
||||
@@ -0,0 +1,2 @@
|
||||
$(eval $(ix-board))
|
||||
$(eval $(generic-package))
|
||||
@@ -0,0 +1,5 @@
|
||||
config BR2_PACKAGE_STYX_DCP_SC_28P
|
||||
bool "Styx DCP-SC-28P"
|
||||
depends on BR2_aarch64
|
||||
help
|
||||
Styx DCP-SC-28P
|
||||
@@ -0,0 +1,2 @@
|
||||
$(eval $(ix-board))
|
||||
$(eval $(generic-package))
|
||||
@@ -1,3 +1,9 @@
|
||||
################################################################################
|
||||
#
|
||||
# confd-test-mode
|
||||
#
|
||||
################################################################################
|
||||
|
||||
CONFD_TEST_MODE_VERSION = 1.0
|
||||
CONFD_TEST_MODE_SITE_METHOD = local
|
||||
CONFD_TEST_MODE_SITE = $(BR2_EXTERNAL_INFIX_PATH)/src/test-mode
|
||||
@@ -16,7 +22,8 @@ COMMON_SYSREPO_ENV = \
|
||||
|
||||
define CONFD_TEST_MODE_INSTALL_YANG_MODULES
|
||||
$(COMMON_SYSREPO_ENV) \
|
||||
SEARCH_PATH="$(TARGET_DIR)/usr/share/yang/modules/test-mode/" $(BR2_EXTERNAL_INFIX_PATH)/utils/sysrepo-load-modules.sh $(@D)/yang/test-mode.inc
|
||||
SEARCH_PATH="$(TARGET_DIR)/usr/share/yang/modules/test-mode/" \
|
||||
$(BR2_EXTERNAL_INFIX_PATH)/utils/srload $(@D)/yang/test-mode.inc
|
||||
endef
|
||||
define CONFD_TEST_MODE_PERMISSIONS
|
||||
/etc/sysrepo/data/ r 660 root wheel - - - - -
|
||||
|
||||
@@ -17,17 +17,15 @@ run name:startup log:prio:user.notice norestart <pid/confd> env:/etc/default/con
|
||||
-- Loading startup-config
|
||||
|
||||
# Run if loading startup-config fails for some reason
|
||||
run name:failure log:prio:user.critical norestart <pid/confd> env:/etc/default/confd if:<run/startup/failure> \
|
||||
[S] /usr/libexec/confd/load -t $CONFD_TIMEOUT failure-config \
|
||||
run name:failure log:prio:user.crit norestart env:/etc/default/confd \
|
||||
if:<run/startup/failure> \
|
||||
[S] <pid/confd> /usr/libexec/confd/load -t $CONFD_TIMEOUT failure-config \
|
||||
-- Loading failure-config
|
||||
|
||||
run name:error :2 log:console norestart if:<run/failure/failure> \
|
||||
run name:error :2 log:console norestart \
|
||||
if:<run/failure/failure> \
|
||||
[S] /usr/libexec/confd/error --
|
||||
|
||||
service name:netopeer notify:none log <pid/confd> env:/etc/default/confd \
|
||||
[12345] netopeer2-server -F -t $CONFD_TIMEOUT -v 1 \
|
||||
service name:netopeer notify:none log env:/etc/default/confd \
|
||||
[12345] <pid/confd> netopeer2-server -F -t $CONFD_TIMEOUT -v 1 \
|
||||
-- NETCONF server
|
||||
|
||||
# Create initial /etc/resolv.conf after successful bootstrap
|
||||
task name:resolv :conf norestart <pid/dnsmasq> if:<run/startup/success> \
|
||||
[S] resolvconf -u -- Update DNS configuration
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
CONFD_VERSION = 1.2
|
||||
CONFD_VERSION = 1.5
|
||||
CONFD_SITE_METHOD = local
|
||||
CONFD_SITE = $(BR2_EXTERNAL_INFIX_PATH)/src/confd
|
||||
CONFD_LICENSE = BSD-3-Clause
|
||||
@@ -26,8 +26,10 @@ CONFD_CONF_OPTS += --disable-containers
|
||||
endif
|
||||
|
||||
define CONFD_INSTALL_EXTRA
|
||||
cp $(CONFD_PKGDIR)/confd.conf $(FINIT_D)/available/
|
||||
ln -sf ../available/confd.conf $(FINIT_D)/enabled/confd.conf
|
||||
for fn in confd.conf resolvconf.conf; do \
|
||||
cp $(CONFD_PKGDIR)/$$fn $(FINIT_D)/available/; \
|
||||
ln -sf ../available/$$fn $(FINIT_D)/enabled/$$fn; \
|
||||
done
|
||||
cp $(CONFD_PKGDIR)/tmpfiles.conf $(TARGET_DIR)/etc/tmpfiles.d/confd.conf
|
||||
mkdir -p $(TARGET_DIR)/etc/avahi/services
|
||||
cp $(CONFD_PKGDIR)/avahi.service $(TARGET_DIR)/etc/avahi/services/netconf.service
|
||||
@@ -41,13 +43,13 @@ COMMON_SYSREPO_ENV = \
|
||||
|
||||
define CONFD_INSTALL_YANG_MODULES
|
||||
$(COMMON_SYSREPO_ENV) \
|
||||
$(BR2_EXTERNAL_INFIX_PATH)/utils/sysrepo-load-modules.sh $(@D)/yang/confd.inc
|
||||
$(BR2_EXTERNAL_INFIX_PATH)/utils/srload $(@D)/yang/confd.inc
|
||||
endef
|
||||
|
||||
ifeq ($(BR2_PACKAGE_PODMAN),y)
|
||||
define CONFD_INSTALL_YANG_MODULES_CONTAINERS
|
||||
$(COMMON_SYSREPO_ENV) \
|
||||
$(BR2_EXTERNAL_INFIX_PATH)/utils/sysrepo-load-modules.sh $(@D)/yang/containers.inc
|
||||
$(BR2_EXTERNAL_INFIX_PATH)/utils/srload $(@D)/yang/containers.inc
|
||||
endef
|
||||
endif
|
||||
|
||||
@@ -63,9 +65,7 @@ endef
|
||||
CONFD_PRE_INSTALL_TARGET_HOOKS += CONFD_CLEANUP
|
||||
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_EXTRA
|
||||
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_YANG_MODULES
|
||||
ifeq ($(BR2_PACKAGE_PODMAN),y)
|
||||
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_YANG_MODULES_CONTAINERS
|
||||
endif
|
||||
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_CLEANUP
|
||||
|
||||
$(eval $(autotools-package))
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
# Create initial /etc/resolv.conf after successful bootstrap, regardless
|
||||
# of startup-config or failure-config. Condition set by confd.
|
||||
task [S12345] <usr/bootstrap> resolvconf -u -- Update DNS configuration
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally calculated
|
||||
sha256 9d9d33b873917ca5d0bdcc47a36d2fd385971ab0c045d1472fcadf95ee5bcf5b LICENCE
|
||||
sha256 f8725f39b9d9d45c8ad6fd2cfc3c1c834a80c32b4217a3d07dd8ed7fe4b6e352 faux-df1d569287bc45d8fd880287c00e3874c5627c19-br1.tar.gz
|
||||
sha256 b385d30b88cab31bf910436ceb1262947bf34a19ca85098c28510e639dc4b37d faux-df1d569287bc45d8fd880287c00e3874c5627c19-git4.tar.gz
|
||||
|
||||
@@ -1,67 +0,0 @@
|
||||
From 46ffa81f5c88ce95db011369d8bfb802313e4217 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Thu, 17 Oct 2024 14:23:24 +0200
|
||||
Subject: [PATCH 1/7] Only mark rdeps dirty if main service is nohup
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
This patch changes a behavior that's been default since Finit 4.0,
|
||||
introduced in 4d05bf9 with 4.0-rc2.
|
||||
|
||||
If service B depends on A and A needs to be reloaded, then B may be
|
||||
affected. If A is declared as NOHUP <!>, then A will be stopped and
|
||||
restarted, during which time the condition it provides is removed,
|
||||
and B will also be stopped.
|
||||
|
||||
However, and as of this patch, if A is declared supporting HUP, then the
|
||||
condition A provides will only go into flux, during which time B will be
|
||||
SIGSTOPed instead of needing to be reloaded.
|
||||
|
||||
Fix #415
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
src/service.c | 8 ++++++++
|
||||
src/svc.h | 1 +
|
||||
2 files changed, 9 insertions(+)
|
||||
|
||||
diff --git a/src/service.c b/src/service.c
|
||||
index 61be85c..b995ff4 100644
|
||||
--- a/src/service.c
|
||||
+++ b/src/service.c
|
||||
@@ -2001,6 +2001,10 @@ static void svc_mark_affected(char *cond)
|
||||
* Called on conf_reload() to update service reverse dependencies.
|
||||
* E.g., if ospfd depends on zebra and the zebra Finit conf has
|
||||
* changed, we need to mark the ospfd Finit conf as changed too.
|
||||
+ *
|
||||
+ * However, a daemon that depends on syslogd (sysklogd project), need
|
||||
+ * not be reloeaded (SIGHUP'ed or stop/started) because syslogd support
|
||||
+ * reloading its configuration file on SIGHUP.
|
||||
*/
|
||||
void service_update_rdeps(void)
|
||||
{
|
||||
@@ -2012,6 +2016,10 @@ void service_update_rdeps(void)
|
||||
if (!svc_is_changed(svc))
|
||||
continue;
|
||||
|
||||
+ /* Service supports reloading conf without stop/start */
|
||||
+ if (!svc_is_nohup(svc))
|
||||
+ continue; /* Yup, no need to stop start rdeps */
|
||||
+
|
||||
svc_mark_affected(mkcond(svc, cond, sizeof(cond)));
|
||||
}
|
||||
}
|
||||
diff --git a/src/svc.h b/src/svc.h
|
||||
index d00ac14..e2f6bd8 100644
|
||||
--- a/src/svc.h
|
||||
+++ b/src/svc.h
|
||||
@@ -259,6 +259,7 @@ static inline int svc_is_tty (svc_t *svc) { return svc && SVC_TYPE_TTY
|
||||
static inline int svc_is_runtask (svc_t *svc) { return svc && (SVC_TYPE_RUNTASK & svc->type);}
|
||||
static inline int svc_is_forking (svc_t *svc) { return svc && svc->forking; }
|
||||
static inline int svc_is_manual (svc_t *svc) { return svc && svc->manual; }
|
||||
+static inline int svc_is_nohup (svc_t *svc) { return svc && (0 == svc->sighup); }
|
||||
|
||||
static inline int svc_in_runlevel (svc_t *svc, int runlevel) { return svc && ISSET(svc->runlevels, runlevel); }
|
||||
static inline int svc_nohup (svc_t *svc) { return svc && (0 == svc->sighup || 0 != svc->args_dirty); }
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,33 +0,0 @@
|
||||
From 119e66a7e9c95283918639b51dd03a3d666955f8 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Mon, 28 Oct 2024 10:58:04 +0100
|
||||
Subject: [PATCH 2/7] Reset color attributes and clear screen when starting up
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Some boot loaders, like GRUB, leave background color artifacts from
|
||||
their boot menu. This patch resets the foreground and background
|
||||
color attributes, and then clears the screen, without clearing the
|
||||
scrollback buffer.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
src/helpers.c | 3 +++
|
||||
1 file changed, 3 insertions(+)
|
||||
|
||||
diff --git a/src/helpers.c b/src/helpers.c
|
||||
index 8768de8..99c4557 100644
|
||||
--- a/src/helpers.c
|
||||
+++ b/src/helpers.c
|
||||
@@ -87,6 +87,9 @@ void console_init(void)
|
||||
/* Enable line wrap, if disabled previously, e.g., qemu */
|
||||
dprint(STDOUT_FILENO, "\033[?7h", 5);
|
||||
|
||||
+ /* Reset atttributes, background and foreground color */
|
||||
+ dprint(STDOUT_FILENO, "\033[49m\033[39m\e[2J", 14);
|
||||
+
|
||||
log_init();
|
||||
}
|
||||
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,196 +0,0 @@
|
||||
From 0c0e880f3fdd38f7bbde618408378dc0a19ff005 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Sun, 3 Nov 2024 09:39:46 +0100
|
||||
Subject: [PATCH 3/7] plugins: refactor rtc.so
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Factor out time_set() and time_get() for readability and reuse.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
plugins/rtc.c | 116 +++++++++++++++++++++++++++++---------------------
|
||||
1 file changed, 68 insertions(+), 48 deletions(-)
|
||||
|
||||
diff --git a/plugins/rtc.c b/plugins/rtc.c
|
||||
index 238791f..9520c7d 100644
|
||||
--- a/plugins/rtc.c
|
||||
+++ b/plugins/rtc.c
|
||||
@@ -68,6 +68,60 @@ static void tz_restore(char *tz)
|
||||
tzset();
|
||||
}
|
||||
|
||||
+static int time_set(struct tm *tm)
|
||||
+{
|
||||
+ struct tm fallback = { 0 };
|
||||
+ struct timeval tv = { 0 };
|
||||
+ char tz[128];
|
||||
+ int rc = 0;
|
||||
+
|
||||
+ tz_set(tz, sizeof(tz));
|
||||
+
|
||||
+ if (!tm) {
|
||||
+ logit(LOG_NOTICE, "Resetting system clock to kernel default, %s.", rtc_timestamp);
|
||||
+ tm = &fallback;
|
||||
+
|
||||
+ /* Attempt to set RTC to a sane value ... */
|
||||
+ tv.tv_sec = rtc_date_fallback;
|
||||
+ if (!gmtime_r(&tv.tv_sec, tm)) {
|
||||
+ rc = 1;
|
||||
+ goto out;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ tm->tm_isdst = -1; /* Use tzdata to figure it out, please. */
|
||||
+ tv.tv_sec = mktime(tm);
|
||||
+ if (tv.tv_sec == (time_t)-1 || tv.tv_sec < rtc_date_fallback) {
|
||||
+ errno = EINVAL;
|
||||
+ rc = 2;
|
||||
+ } else {
|
||||
+ if (settimeofday(&tv, NULL) == -1)
|
||||
+ rc = 1;
|
||||
+ }
|
||||
+out:
|
||||
+ tz_restore(tz);
|
||||
+ return rc;
|
||||
+}
|
||||
+
|
||||
+static int time_get(struct tm *tm)
|
||||
+{
|
||||
+ struct timeval tv = { 0 };
|
||||
+ char tz[128];
|
||||
+ int rc = 0;
|
||||
+
|
||||
+ tz_set(tz, sizeof(tz));
|
||||
+
|
||||
+ rc = gettimeofday(&tv, NULL);
|
||||
+ if (rc < 0 || tv.tv_sec < rtc_date_fallback)
|
||||
+ rc = 2;
|
||||
+ else
|
||||
+ gmtime_r(&tv.tv_sec, tm);
|
||||
+
|
||||
+ tz_restore(tz);
|
||||
+
|
||||
+ return rc;
|
||||
+}
|
||||
+
|
||||
static int rtc_open(void)
|
||||
{
|
||||
char *alt[] = {
|
||||
@@ -91,10 +145,8 @@ static int rtc_open(void)
|
||||
|
||||
static void rtc_save(void *arg)
|
||||
{
|
||||
- struct timeval tv = { 0 };
|
||||
struct tm tm = { 0 };
|
||||
int fd, rc = 0;
|
||||
- char tz[128];
|
||||
|
||||
if (rescue) {
|
||||
dbg("Skipping %s plugin in rescue mode.", __FILE__);
|
||||
@@ -105,38 +157,26 @@ static void rtc_save(void *arg)
|
||||
if (fd < 0)
|
||||
return;
|
||||
|
||||
- tz_set(tz, sizeof(tz));
|
||||
- rc = gettimeofday(&tv, NULL);
|
||||
- if (rc < 0 || tv.tv_sec < rtc_date_fallback) {
|
||||
+ if ((rc = time_get(&tm))) {
|
||||
print_desc(NULL, "System clock invalid, not saving to RTC");
|
||||
- invalid:
|
||||
- logit(LOG_ERR, "System clock invalid, before %s, not saving to RTC", rtc_timestamp);
|
||||
- rc = 2;
|
||||
- goto out;
|
||||
+ } else {
|
||||
+ print_desc(NULL, "Saving system clock (UTC) to RTC");
|
||||
+ rc = ioctl(fd, RTC_SET_TIME, &tm);
|
||||
}
|
||||
|
||||
- print_desc(NULL, "Saving system time (UTC) to RTC");
|
||||
-
|
||||
- gmtime_r(&tv.tv_sec, &tm);
|
||||
- if (ioctl(fd, RTC_SET_TIME, &tm) < 0) {
|
||||
- if (EINVAL == errno)
|
||||
- goto invalid;
|
||||
- rc = 1;
|
||||
- goto out;
|
||||
+ if (rc && errno == EINVAL) {
|
||||
+ logit(LOG_ERR, "System clock invalid, before %s, not saving to RTC", rtc_timestamp);
|
||||
+ rc = 2;
|
||||
}
|
||||
|
||||
-out:
|
||||
- tz_restore(tz);
|
||||
print(rc, NULL);
|
||||
close(fd);
|
||||
}
|
||||
|
||||
static void rtc_restore(void *arg)
|
||||
{
|
||||
- struct timeval tv = { 0 };
|
||||
struct tm tm = { 0 };
|
||||
int fd, rc = 0;
|
||||
- char tz[128];
|
||||
|
||||
if (rescue) {
|
||||
dbg("Skipping %s plugin in rescue mode.", __FILE__);
|
||||
@@ -149,16 +189,19 @@ static void rtc_restore(void *arg)
|
||||
return;
|
||||
}
|
||||
|
||||
- tz_set(tz, sizeof(tz));
|
||||
- if (ioctl(fd, RTC_RD_TIME, &tm) < 0) {
|
||||
+ if ((rc = ioctl(fd, RTC_RD_TIME, &tm)) < 0) {
|
||||
char msg[120];
|
||||
|
||||
snprintf(msg, sizeof(msg), "Failed restoring system clock, %s",
|
||||
EINVAL == errno ? "RTC time is too old" :
|
||||
ENOENT == errno ? "RTC has no saved time" : "see log for details");
|
||||
print_desc(NULL, msg);
|
||||
+ } else {
|
||||
+ print_desc(NULL, "Restoring system clock (UTC) from RTC");
|
||||
+ rc = time_set(&tm);
|
||||
+ }
|
||||
|
||||
- invalid:
|
||||
+ if (rc) {
|
||||
logit(LOG_ERR, "Failed restoring system clock from RTC.");
|
||||
if (EINVAL == errno)
|
||||
logit(LOG_ERR, "RTC time is too old (before %s)", rtc_timestamp);
|
||||
@@ -167,33 +210,10 @@ static void rtc_restore(void *arg)
|
||||
else
|
||||
logit(LOG_ERR, "RTC error code %d: %s", errno, strerror(errno));
|
||||
|
||||
- /* Been here already? */
|
||||
- if (rc)
|
||||
- goto out;
|
||||
-
|
||||
- /* Attempt to set RTC to a sane value ... */
|
||||
- tv.tv_sec = rtc_date_fallback;
|
||||
- if (!gmtime_r(&tv.tv_sec, &tm))
|
||||
- goto out;
|
||||
-
|
||||
- logit(LOG_NOTICE, "Resetting RTC to kernel default, %s.", rtc_timestamp);
|
||||
+ time_set(NULL);
|
||||
rc = 2;
|
||||
}
|
||||
|
||||
- if (!rc)
|
||||
- print_desc(NULL, "Restoring system clock (UTC) from RTC");
|
||||
- tm.tm_isdst = -1; /* Use tzdata to figure it out, please. */
|
||||
- tv.tv_sec = mktime(&tm);
|
||||
- if (tv.tv_sec == (time_t)-1 || tv.tv_sec < rtc_date_fallback) {
|
||||
- errno = EINVAL;
|
||||
- goto invalid;
|
||||
- }
|
||||
-
|
||||
- if (settimeofday(&tv, NULL) == -1)
|
||||
- rc = 1;
|
||||
-
|
||||
-out:
|
||||
- tz_restore(tz);
|
||||
print(rc, NULL);
|
||||
close(fd);
|
||||
}
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,239 +0,0 @@
|
||||
From bc8118d515839dc598f437aa01f07a771646968d Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Sun, 3 Nov 2024 09:47:16 +0100
|
||||
Subject: [PATCH 4/7] Fix #418: support systems with a broken RTC
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
This patch introduces a new configure option --with-rtc-file=FILE. When
|
||||
enabled the RTC plugin detects missing RTC device and falls back to save
|
||||
and restore system time from a file instead. When --with-rtc-file is
|
||||
used without an argument the default file is /var/lib/misc/rtc, but the
|
||||
feature itself is disabled by default.
|
||||
|
||||
The usefulness of this feature may not be obvious at first, but some
|
||||
systems are equipped with an RTC that resets to a random date at power
|
||||
on. This can be really bad in the case the date is far in the future,
|
||||
because an NTP sync would then cause time skips backwards, which shows
|
||||
up in logs and causes a whole lot of pain in alarm systems.
|
||||
|
||||
The solution is to disable the RTC driver or device tree node, and when
|
||||
Finit starts up, the RTC plugin detects a the device node and instead
|
||||
restores time from the last save game. Meaning time will always only
|
||||
move forwards.
|
||||
|
||||
NOTE: when Finit is built --with-rtc-file we always save to disk, but
|
||||
only restore from the "save game" if restoring from RTC fails.
|
||||
If the system has no RTC we always restore from disk.
|
||||
|
||||
As an added bonus, this change also makes sure to periodically
|
||||
sync also the RTC with the system clock. Useful for systems
|
||||
that do not run an NTP client.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
configure.ac | 12 ++++++
|
||||
plugins/rtc.c | 105 ++++++++++++++++++++++++++++++++++++++++++++++----
|
||||
2 files changed, 110 insertions(+), 7 deletions(-)
|
||||
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index 483457f..ae7cd23 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -180,6 +180,10 @@ AC_ARG_WITH(rtc-date,
|
||||
AS_HELP_STRING([--with-rtc-date=DATE], [If RTC date/time is too old, restore to DATE, format "YYYY-MM-DD HH:MM", default "2000-01-01 00:00"]),
|
||||
[rtc_date=$withval], [rtc_date=no])
|
||||
|
||||
+AC_ARG_WITH(rtc-file,
|
||||
+ AS_HELP_STRING([--with-rtc-file=FILE], [If RTC is missing, save and restore system clock from this file, default: no]),
|
||||
+ [rtc_file=$withval], [rtc_file=no])
|
||||
+
|
||||
### Enable features ###########################################################################
|
||||
|
||||
# Create config.h from selected features and fallback defaults
|
||||
@@ -281,6 +285,13 @@ AS_IF([test "x$rtc_date" != "xno"], [
|
||||
AC_DEFINE(RTC_TIMESTAMP_CUSTOM, "$rtc_date", [Custom RTC restore date, default: 2000-01-01 00:00])], [
|
||||
rtc_date=""])
|
||||
|
||||
+AS_IF([test "x$rtc_file" != "xno"], [
|
||||
+ AS_IF([test "x$rtc_file" = "xyes"], [
|
||||
+ rtc_file=/var/lib/misc/rtc])
|
||||
+ AC_EXPAND_DIR(rtcfile_path, "$rtc_file")
|
||||
+ AC_DEFINE_UNQUOTED(RTC_FILE, "$rtcfile_path", [Save and restore system time from this file if /dev/rtc is missing.])],[
|
||||
+ AC_DEFINE_UNQUOTED(RTC_FILE, NULL)])
|
||||
+
|
||||
AS_IF([test "x$with_keventd" != "xno"], [with_keventd=yes])
|
||||
|
||||
AS_IF([test "x$with_sulogin" != "xno"], [
|
||||
@@ -387,6 +398,7 @@ Behavior:
|
||||
Boot heading..........: $heading
|
||||
Plugins...............: $plugins
|
||||
RTC restore date......: $RTC_DATE
|
||||
+ RTC fallback file.....: $rtc_file
|
||||
|
||||
Optional features:
|
||||
Install doc/..........: $enable_doc
|
||||
diff --git a/plugins/rtc.c b/plugins/rtc.c
|
||||
index 9520c7d..9b4eeae 100644
|
||||
--- a/plugins/rtc.c
|
||||
+++ b/plugins/rtc.c
|
||||
@@ -36,8 +36,15 @@
|
||||
#include "helpers.h"
|
||||
#include "plugin.h"
|
||||
|
||||
-/* Kernel RTC driver validates against this date for sanity check */
|
||||
+/*
|
||||
+ * Kernel RTC driver validates against this date for sanity check. The
|
||||
+ * on NTP sync the driver can also update the RTC every 11 mins. We use
|
||||
+ * the same update interval to handle manual time set and file save.
|
||||
+ */
|
||||
#define RTC_TIMESTAMP_BEGIN_2000 "2000-01-01 00:00:00"
|
||||
+#define RTC_FMT "%Y-%m-%d %H:%M:%S"
|
||||
+#define RTC_PERIOD (11 * 60 * 1000)
|
||||
+
|
||||
#ifdef RTC_TIMESTAMP_CUSTOM
|
||||
static char *rtc_timestamp = RTC_TIMESTAMP_CUSTOM;
|
||||
#else
|
||||
@@ -45,6 +52,10 @@ static char *rtc_timestamp = RTC_TIMESTAMP_BEGIN_2000;
|
||||
#endif
|
||||
static time_t rtc_date_fallback = 946684800LL;
|
||||
|
||||
+static char *rtc_file = RTC_FILE;
|
||||
+static uev_t rtc_timer;
|
||||
+
|
||||
+
|
||||
static void tz_set(char *tz, size_t len)
|
||||
{
|
||||
char *ptr;
|
||||
@@ -122,6 +133,68 @@ static int time_get(struct tm *tm)
|
||||
return rc;
|
||||
}
|
||||
|
||||
+static void file_save(void *arg)
|
||||
+{
|
||||
+ struct tm tm = { 0 };
|
||||
+ int rc = 0;
|
||||
+ FILE *fp;
|
||||
+
|
||||
+ fp = fopen(rtc_file, "w");
|
||||
+ if (!fp) {
|
||||
+ logit(LOG_WARNING, "Failed saving system clock to %s, code %d: %s",
|
||||
+ rtc_file, errno, strerror(errno));
|
||||
+ return;
|
||||
+ }
|
||||
+
|
||||
+ if ((rc = time_get(&tm))) {
|
||||
+ logit(LOG_ERR, "System clock invalid, before %s, not saving", rtc_timestamp);
|
||||
+ print_desc(NULL, "System clock invalid, skipping");
|
||||
+ } else {
|
||||
+ char buf[32] = { 0 };
|
||||
+
|
||||
+ print_desc(NULL, "Saving system clock to file");
|
||||
+ strftime(buf, sizeof(buf), RTC_FMT, &tm);
|
||||
+ fprintf(fp, "%s\n", buf);
|
||||
+ }
|
||||
+
|
||||
+ print(rc, NULL);
|
||||
+ fclose(fp);
|
||||
+}
|
||||
+
|
||||
+static void file_restore(void *arg)
|
||||
+{
|
||||
+ struct tm tm = { 0 };
|
||||
+ int rc = 1;
|
||||
+ FILE *fp;
|
||||
+
|
||||
+ if (!rtc_file) {
|
||||
+ logit(LOG_NOTICE, "System has no RTC (missing driver?), skipping restore.");
|
||||
+ return;
|
||||
+ }
|
||||
+
|
||||
+ print_desc(NULL, "Restoring system clock from backup");
|
||||
+
|
||||
+ fp = fopen(rtc_file, "r");
|
||||
+ if (fp) {
|
||||
+ char buf[32];
|
||||
+
|
||||
+ if (fgets(buf, sizeof(buf), fp)) {
|
||||
+ chomp(buf);
|
||||
+ strptime(buf, RTC_FMT, &tm);
|
||||
+ rc = time_set(&tm);
|
||||
+ }
|
||||
+ fclose(fp);
|
||||
+ } else
|
||||
+ logit(LOG_WARNING, "Missing %s", rtc_file);
|
||||
+
|
||||
+ if (rc) {
|
||||
+ time_set(NULL);
|
||||
+ rc = 2;
|
||||
+ }
|
||||
+
|
||||
+ print(rc, NULL);
|
||||
+}
|
||||
+
|
||||
static int rtc_open(void)
|
||||
{
|
||||
char *alt[] = {
|
||||
@@ -185,7 +258,7 @@ static void rtc_restore(void *arg)
|
||||
|
||||
fd = rtc_open();
|
||||
if (fd < 0) {
|
||||
- logit(LOG_NOTICE, "System has no RTC (missing driver?), skipping restore.");
|
||||
+ file_restore(arg);
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -210,21 +283,37 @@ static void rtc_restore(void *arg)
|
||||
else
|
||||
logit(LOG_ERR, "RTC error code %d: %s", errno, strerror(errno));
|
||||
|
||||
- time_set(NULL);
|
||||
- rc = 2;
|
||||
- }
|
||||
+ print(2, NULL);
|
||||
+
|
||||
+ /* Try restoring from last save game */
|
||||
+ if (rtc_file)
|
||||
+ file_restore(arg);
|
||||
+ } else
|
||||
+ print(0, NULL);
|
||||
|
||||
- print(rc, NULL);
|
||||
close(fd);
|
||||
}
|
||||
|
||||
+
|
||||
+static void save(void *arg)
|
||||
+{
|
||||
+ rtc_save(arg);
|
||||
+ file_save(arg);
|
||||
+}
|
||||
+
|
||||
+static void update(uev_t *w, void *arg, int events)
|
||||
+{
|
||||
+ save(arg);
|
||||
+}
|
||||
+
|
||||
+
|
||||
static plugin_t plugin = {
|
||||
.name = __FILE__,
|
||||
.hook[HOOK_BASEFS_UP] = {
|
||||
.cb = rtc_restore
|
||||
},
|
||||
.hook[HOOK_SHUTDOWN] = {
|
||||
- .cb = rtc_save
|
||||
+ .cb = save
|
||||
}
|
||||
};
|
||||
|
||||
@@ -237,6 +326,8 @@ PLUGIN_INIT(plugin_init)
|
||||
else
|
||||
rtc_timestamp = RTC_TIMESTAMP_BEGIN_2000;
|
||||
|
||||
+ uev_timer_init(ctx, &rtc_timer, update, NULL, RTC_PERIOD, RTC_PERIOD);
|
||||
+
|
||||
plugin_register(&plugin);
|
||||
}
|
||||
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,73 +0,0 @@
|
||||
From 6be16f2f6d093ef495d0fe4313f7b05b4ba3e08f Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Sun, 3 Nov 2024 10:38:38 +0100
|
||||
Subject: [PATCH 5/7] Fix buggy --with-rtc-date=DATE, introduced in Finit v4.4
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
In 42ef3d3c, for v4.4-rc1, support for setting a custom RTC restore date
|
||||
was introduced. Unfortunately the configure script was wrong and caused
|
||||
config.h to contain
|
||||
|
||||
#define RTC_TIMESTAMP_CUSTOM "$rtc_date"
|
||||
|
||||
instead of
|
||||
|
||||
#define RTC_TIMESTAMP_CUSTOM "2023-04-10 14:35:42"
|
||||
|
||||
Furthermore, the error handling for strptime() was wrong, so the restore
|
||||
date was always reverted to the default.
|
||||
|
||||
This patch fixes both issues and extends the DATE of --with-rtc-date to
|
||||
also include seconds.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
configure.ac | 4 ++--
|
||||
plugins/rtc.c | 8 +++++---
|
||||
2 files changed, 7 insertions(+), 5 deletions(-)
|
||||
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index ae7cd23..58b78ac 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -177,7 +177,7 @@ AC_ARG_WITH(plugin-path,
|
||||
[plugin_path=$withval], [plugin_path=yes])
|
||||
|
||||
AC_ARG_WITH(rtc-date,
|
||||
- AS_HELP_STRING([--with-rtc-date=DATE], [If RTC date/time is too old, restore to DATE, format "YYYY-MM-DD HH:MM", default "2000-01-01 00:00"]),
|
||||
+ AS_HELP_STRING([--with-rtc-date=DATE], [If RTC date/time is too old, restore to DATE, format "YYYY-MM-DD HH:MM:SS", default "2000-01-01 00:00:00"]),
|
||||
[rtc_date=$withval], [rtc_date=no])
|
||||
|
||||
AC_ARG_WITH(rtc-file,
|
||||
@@ -282,7 +282,7 @@ AS_IF([test "x$with_random_seed" != "xno"], [
|
||||
AC_DEFINE_UNQUOTED(RANDOMSEED, "$random_path", [Improve random at boot by seeding it with sth from before.])])
|
||||
|
||||
AS_IF([test "x$rtc_date" != "xno"], [
|
||||
- AC_DEFINE(RTC_TIMESTAMP_CUSTOM, "$rtc_date", [Custom RTC restore date, default: 2000-01-01 00:00])], [
|
||||
+ AC_DEFINE_UNQUOTED(RTC_TIMESTAMP_CUSTOM, "$rtc_date", [Custom RTC restore date, default: 2000-01-01 00:00])], [
|
||||
rtc_date=""])
|
||||
|
||||
AS_IF([test "x$rtc_file" != "xno"], [
|
||||
diff --git a/plugins/rtc.c b/plugins/rtc.c
|
||||
index 9b4eeae..a733f75 100644
|
||||
--- a/plugins/rtc.c
|
||||
+++ b/plugins/rtc.c
|
||||
@@ -321,10 +321,12 @@ PLUGIN_INIT(plugin_init)
|
||||
{
|
||||
struct tm tm = { 0 };
|
||||
|
||||
- if (!strptime(rtc_timestamp, "%Y-%m-%d %H:%M", &tm))
|
||||
- rtc_date_fallback = mktime(&tm);
|
||||
- else
|
||||
+ if (!strptime(rtc_timestamp, RTC_FMT, &tm)) {
|
||||
+ logit(LOG_ERR, "Invalid restore date '%s', reverting to '%s'",
|
||||
+ rtc_timestamp, RTC_TIMESTAMP_BEGIN_2000);
|
||||
rtc_timestamp = RTC_TIMESTAMP_BEGIN_2000;
|
||||
+ } else
|
||||
+ rtc_date_fallback = mktime(&tm);
|
||||
|
||||
uev_timer_init(ctx, &rtc_timer, update, NULL, RTC_PERIOD, RTC_PERIOD);
|
||||
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,85 +0,0 @@
|
||||
From 49c0557cedd8d3c1a2f74d27fa7db83dd529914a Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Sun, 3 Nov 2024 20:49:04 +0100
|
||||
Subject: [PATCH 6/7] plugins: reduce log level LOG_ERR -> LOG_WARNING
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
These plugins signal success and failure directly to the console, the
|
||||
user should inspect syslog for more information.
|
||||
|
||||
This change is a follow-up to 340cae4, where kernel logs of LOG_ERR and
|
||||
higher are allowed to log directly to the console. Since syslogd has
|
||||
not been started before these plugins, the log messages would otherwise
|
||||
leak to the console.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
plugins/rtc.c | 14 +++++++-------
|
||||
plugins/urandom.c | 2 +-
|
||||
2 files changed, 8 insertions(+), 8 deletions(-)
|
||||
|
||||
diff --git a/plugins/rtc.c b/plugins/rtc.c
|
||||
index a733f75..96203a0 100644
|
||||
--- a/plugins/rtc.c
|
||||
+++ b/plugins/rtc.c
|
||||
@@ -147,7 +147,7 @@ static void file_save(void *arg)
|
||||
}
|
||||
|
||||
if ((rc = time_get(&tm))) {
|
||||
- logit(LOG_ERR, "System clock invalid, before %s, not saving", rtc_timestamp);
|
||||
+ logit(LOG_WARNING, "System clock invalid, before %s, not saving", rtc_timestamp);
|
||||
print_desc(NULL, "System clock invalid, skipping");
|
||||
} else {
|
||||
char buf[32] = { 0 };
|
||||
@@ -238,7 +238,7 @@ static void rtc_save(void *arg)
|
||||
}
|
||||
|
||||
if (rc && errno == EINVAL) {
|
||||
- logit(LOG_ERR, "System clock invalid, before %s, not saving to RTC", rtc_timestamp);
|
||||
+ logit(LOG_WARNING, "System clock invalid, before %s, not saving to RTC", rtc_timestamp);
|
||||
rc = 2;
|
||||
}
|
||||
|
||||
@@ -275,13 +275,13 @@ static void rtc_restore(void *arg)
|
||||
}
|
||||
|
||||
if (rc) {
|
||||
- logit(LOG_ERR, "Failed restoring system clock from RTC.");
|
||||
+ logit(LOG_WARNING, "Failed restoring system clock from RTC.");
|
||||
if (EINVAL == errno)
|
||||
- logit(LOG_ERR, "RTC time is too old (before %s)", rtc_timestamp);
|
||||
+ logit(LOG_WARNING, "RTC time is too old (before %s)", rtc_timestamp);
|
||||
else if (ENOENT == errno)
|
||||
- logit(LOG_ERR, "RTC has no previously saved (valid) time.");
|
||||
+ logit(LOG_WARNING, "RTC has no previously saved (valid) time.");
|
||||
else
|
||||
- logit(LOG_ERR, "RTC error code %d: %s", errno, strerror(errno));
|
||||
+ logit(LOG_WARNING, "RTC error code %d: %s", errno, strerror(errno));
|
||||
|
||||
print(2, NULL);
|
||||
|
||||
@@ -322,7 +322,7 @@ PLUGIN_INIT(plugin_init)
|
||||
struct tm tm = { 0 };
|
||||
|
||||
if (!strptime(rtc_timestamp, RTC_FMT, &tm)) {
|
||||
- logit(LOG_ERR, "Invalid restore date '%s', reverting to '%s'",
|
||||
+ logit(LOG_WARNING, "Invalid restore date '%s', reverting to '%s'",
|
||||
rtc_timestamp, RTC_TIMESTAMP_BEGIN_2000);
|
||||
rtc_timestamp = RTC_TIMESTAMP_BEGIN_2000;
|
||||
} else
|
||||
diff --git a/plugins/urandom.c b/plugins/urandom.c
|
||||
index b9f6039..6f82779 100644
|
||||
--- a/plugins/urandom.c
|
||||
+++ b/plugins/urandom.c
|
||||
@@ -154,7 +154,7 @@ static void setup(void *arg)
|
||||
close(fd);
|
||||
free(rpi);
|
||||
if (rc < 0)
|
||||
- logit(LOG_ERR, "Failed adding entropy to kernel random pool: %s", strerror(err));
|
||||
+ logit(LOG_WARNING, "Failed adding entropy to kernel random pool: %s", strerror(err));
|
||||
print_result(rc < 0);
|
||||
return;
|
||||
fallback:
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,57 +0,0 @@
|
||||
From 465bc17ca4b131f8c1ef27ff8279f4ea13745a78 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Thu, 28 Nov 2024 11:06:57 +0100
|
||||
Subject: [PATCH 7/7] Fix unintended restart of template siblings
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Consider the case where container@.conf is an available template. When
|
||||
creating a container@foo.conf it will share the same base .conf as an
|
||||
existing container@bar.conf, but we do not expect to restart bar just
|
||||
because foo is instantiated.
|
||||
|
||||
Up until this change, all template siblings were considered "dirty" if a
|
||||
new one was created or updated. Skipping realpath() for all files that
|
||||
have a '@' works around the problem.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
src/conf.c | 20 +++++++++++++-------
|
||||
1 file changed, 13 insertions(+), 7 deletions(-)
|
||||
|
||||
diff --git a/src/conf.c b/src/conf.c
|
||||
index 1cfcd87..531923c 100644
|
||||
--- a/src/conf.c
|
||||
+++ b/src/conf.c
|
||||
@@ -1432,16 +1432,22 @@ static int conf_change_act(char *dir, char *name, uint32_t mask)
|
||||
strlcpy(fn, dir, sizeof(fn));
|
||||
dbg("path: %s mask: %08x", fn, mask);
|
||||
|
||||
- /* Handle disabling/removal of service */
|
||||
- rp = realpath(fn, NULL);
|
||||
- if (!rp) {
|
||||
- if (errno != ENOENT)
|
||||
- goto fail;
|
||||
+ if (strchr(name, '@')) {
|
||||
+ /* Skip realpath for templates */
|
||||
rp = strdup(fn);
|
||||
- if (!rp)
|
||||
- goto fail;
|
||||
+ } else {
|
||||
+ /* Handle disabling/removal of service */
|
||||
+ rp = realpath(fn, NULL);
|
||||
+ if (!rp) {
|
||||
+ if (errno != ENOENT)
|
||||
+ goto fail;
|
||||
+ rp = strdup(fn);
|
||||
+ }
|
||||
}
|
||||
|
||||
+ if (!rp)
|
||||
+ goto fail;
|
||||
+
|
||||
node = conf_find(rp);
|
||||
if (node) {
|
||||
dbg("event already registered for %s ...", name);
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
# From https://github.com/troglobit/finit/releases/
|
||||
sha256 5026965e33f31b8fa4e2e465b9521e805fa01c31cade884c07d0fcff97cd0ddf finit-4.8.tar.gz
|
||||
sha256 7e49a3df58c5aedfff9537b7ff34b9238fc28b523d4dbacc316d606c7af5e335 finit-4.11.tar.gz
|
||||
|
||||
# Locally calculated
|
||||
sha256 2fd62c0fe6ea6d1861669f4c87bda83a0b5ceca64f4baa4d16dd078fbd218c14 LICENSE
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
FINIT_VERSION = 4.8
|
||||
FINIT_VERSION = 4.11
|
||||
FINIT_SITE = https://github.com/troglobit/finit/releases/download/$(FINIT_VERSION)
|
||||
FINIT_LICENSE = MIT
|
||||
FINIT_LICENSE_FILES = LICENSE
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally calculated
|
||||
sha256 9d9d33b873917ca5d0bdcc47a36d2fd385971ab0c045d1472fcadf95ee5bcf5b LICENCE
|
||||
sha256 b579d0028c8c88ddea27282f03c8c23fa9a758ad47918aeffb048456cf204375 klish-plugin-sysrepo-b693714a1ff5f8021651d7619556afb19945e5e6-br1.tar.gz
|
||||
sha256 598089ad964594bbbaf2b7d7214d8761c828174eef53b7cfb1cd98517f407d01 klish-plugin-sysrepo-b693714a1ff5f8021651d7619556afb19945e5e6-git4.tar.gz
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally calculated
|
||||
sha256 9d9d33b873917ca5d0bdcc47a36d2fd385971ab0c045d1472fcadf95ee5bcf5b LICENCE
|
||||
sha256 0305355dd29dc276f7957d51e2406907e0c862dfd46f496c8a921df4f3d72a8d klish-019ebd2704e322b5d500f5687d526431e535eec8-br1.tar.gz
|
||||
sha256 79c9b16b227320fea358114738933ea25be33f8f263d3eec1f83fb603c0c0b22 klish-019ebd2704e322b5d500f5687d526431e535eec8-git4.tar.gz
|
||||
|
||||
@@ -0,0 +1,82 @@
|
||||
From d0f6422fee7a46fcb7445c88f499f61b3eb0ead0 Mon Sep 17 00:00:00 2001
|
||||
From: Adam Piecek <Adam.Piecek@cesnet.cz>
|
||||
Date: Wed, 23 Oct 2024 14:37:09 +0200
|
||||
Subject: [PATCH 1/8] added support for RpcYang in Context::parseOp
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Change-Id: I25182ea2d042be1e6e4246e18aee260cc032e547
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
---
|
||||
src/Context.cpp | 6 ++++--
|
||||
tests/context.cpp | 21 +++++++++++++++++++++
|
||||
2 files changed, 25 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/Context.cpp b/src/Context.cpp
|
||||
index b844bd9..287f8c8 100644
|
||||
--- a/src/Context.cpp
|
||||
+++ b/src/Context.cpp
|
||||
@@ -221,7 +221,8 @@ std::optional<DataNode> Context::parseExtData(
|
||||
* - a NETCONF RPC,
|
||||
* - a NETCONF notification,
|
||||
* - a RESTCONF notification,
|
||||
- * - a YANG notification.
|
||||
+ * - a YANG notification,
|
||||
+ * - a YANG RPC.
|
||||
*
|
||||
* Parsing any of these requires just the schema (which is available through the Context), and the textual payload.
|
||||
* All the other information are encoded in the textual payload as per the standard.
|
||||
@@ -243,6 +244,7 @@ ParsedOp Context::parseOp(const std::string& input, const DataFormat format, con
|
||||
auto in = wrap_ly_in_new_memory(input);
|
||||
|
||||
switch (opType) {
|
||||
+ case OperationType::RpcYang:
|
||||
case OperationType::RpcNetconf:
|
||||
case OperationType::NotificationNetconf:
|
||||
case OperationType::NotificationRestconf:
|
||||
@@ -254,7 +256,7 @@ ParsedOp Context::parseOp(const std::string& input, const DataFormat format, con
|
||||
ParsedOp res;
|
||||
res.tree = tree ? std::optional{libyang::wrapRawNode(tree)} : std::nullopt;
|
||||
|
||||
- if (opType == OperationType::NotificationYang) {
|
||||
+ if ((opType == OperationType::NotificationYang) || (opType == OperationType::RpcYang)) {
|
||||
res.op = op && tree ? std::optional{DataNode(op, res.tree->m_refs)} : std::nullopt;
|
||||
} else {
|
||||
res.op = op ? std::optional{libyang::wrapRawNode(op)} : std::nullopt;
|
||||
diff --git a/tests/context.cpp b/tests/context.cpp
|
||||
index 71ae873..11019eb 100644
|
||||
--- a/tests/context.cpp
|
||||
+++ b/tests/context.cpp
|
||||
@@ -464,6 +464,27 @@ TEST_CASE("context")
|
||||
REQUIRE(data->findPath("/example-schema:leafInt8")->asTerm().valueStr() == "-43");
|
||||
}
|
||||
|
||||
+ DOCTEST_SUBCASE("Context::parseOp")
|
||||
+ {
|
||||
+ DOCTEST_SUBCASE("RPC")
|
||||
+ {
|
||||
+ ctx->parseModule(example_schema, libyang::SchemaFormat::YANG);
|
||||
+ std::string dataJson = R"({"example-schema:myRpc":{"inputLeaf":"str"}})";
|
||||
+ auto pop = ctx->parseOp(dataJson, libyang::DataFormat::JSON, libyang::OperationType::RpcYang);
|
||||
+ REQUIRE(pop.op->schema().name() == "myRpc");
|
||||
+ REQUIRE(pop.tree->findPath("/example-schema:myRpc/inputLeaf")->asTerm().valueStr() == "str");
|
||||
+ }
|
||||
+ DOCTEST_SUBCASE("action")
|
||||
+ {
|
||||
+ ctx->parseModule(example_schema, libyang::SchemaFormat::YANG);
|
||||
+ std::string datajson = R"({"example-schema:person":[{"name":"john", "poke":{}}]})";
|
||||
+ auto pop = ctx->parseOp(datajson, libyang::DataFormat::JSON, libyang::OperationType::RpcYang);
|
||||
+ REQUIRE(pop.op->schema().name() == "poke");
|
||||
+ REQUIRE(pop.tree->findPath("/example-schema:person[name='john']/poke")->schema().nodeType() == libyang::NodeType::Action);
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+
|
||||
DOCTEST_SUBCASE("Context::parseExt")
|
||||
{
|
||||
ctx->setSearchDir(TESTS_DIR / "yang");
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -0,0 +1,53 @@
|
||||
From 7e015f3486bdbb54f1dcc2e2ce51102b1d623081 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Tom=C3=A1=C5=A1=20Pecka?= <tomas.pecka@cesnet.cz>
|
||||
Date: Wed, 23 Oct 2024 12:52:24 +0200
|
||||
Subject: [PATCH 2/8] throw when lyd_validate_all returns error
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Bug: https://github.com/CESNET/libyang-cpp/issues/20
|
||||
Change-Id: I005a2f1b057978573a4046e7b4cc31d77e36fde3
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
---
|
||||
src/DataNode.cpp | 4 +++-
|
||||
tests/data_node.cpp | 7 +++++++
|
||||
2 files changed, 10 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/DataNode.cpp b/src/DataNode.cpp
|
||||
index 51c86c8..2ef17f2 100644
|
||||
--- a/src/DataNode.cpp
|
||||
+++ b/src/DataNode.cpp
|
||||
@@ -1170,7 +1170,9 @@ void validateAll(std::optional<libyang::DataNode>& node, const std::optional<Val
|
||||
}
|
||||
|
||||
// TODO: support the `diff` argument
|
||||
- lyd_validate_all(node ? &node->m_node : nullptr, nullptr, opts ? utils::toValidationOptions(*opts) : 0, nullptr);
|
||||
+ auto ret = lyd_validate_all(node ? &node->m_node : nullptr, nullptr, opts ? utils::toValidationOptions(*opts) : 0, nullptr);
|
||||
+ throwIfError(ret, "libyang:validateAll: lyd_validate_all failed");
|
||||
+
|
||||
if (!node->m_node) {
|
||||
node = std::nullopt;
|
||||
}
|
||||
diff --git a/tests/data_node.cpp b/tests/data_node.cpp
|
||||
index a23e4c2..8a2610e 100644
|
||||
--- a/tests/data_node.cpp
|
||||
+++ b/tests/data_node.cpp
|
||||
@@ -489,6 +489,13 @@ TEST_CASE("Data Node manipulation")
|
||||
REQUIRE_THROWS_WITH_AS(libyang::validateAll(node, libyang::ValidationOptions::NoState), "validateAll: Node is not a unique reference", libyang::Error);
|
||||
}
|
||||
|
||||
+ DOCTEST_SUBCASE("validateAll throws on validation failure")
|
||||
+ {
|
||||
+ ctx.parseModule(type_module, libyang::SchemaFormat::YANG);
|
||||
+ auto node = std::optional{ctx.newPath("/type_module:leafWithConfigFalse", "hi")};
|
||||
+ REQUIRE_THROWS_WITH_AS(libyang::validateAll(node, libyang::ValidationOptions::NoState), "libyang:validateAll: lyd_validate_all failed: LY_EVALID", libyang::ErrorWithCode);
|
||||
+ }
|
||||
+
|
||||
DOCTEST_SUBCASE("unlink")
|
||||
{
|
||||
auto root = ctx.parseData(data2, libyang::DataFormat::JSON);
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
From 490d8bb242d33213b948485f5b94c55e22cf86a6 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Jan=20Kundr=C3=A1t?= <jan.kundrat@cesnet.cz>
|
||||
Date: Thu, 21 Nov 2024 11:32:44 +0100
|
||||
Subject: [PATCH 3/8] remove a misleading comment
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
The whole intention within action's input/output handling here was to
|
||||
put some emphasis on the fact that we aren't tracking the input/output
|
||||
nodes directly. However, looking at all the other classes this is a bit
|
||||
redundant, we're using a pattern like this all the time. Just drop the
|
||||
comment.
|
||||
|
||||
Change-Id: Ibd9bf9f1e83c650dda3bc43ef48e61dd6d95da5a
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
---
|
||||
src/SchemaNode.cpp | 3 ---
|
||||
1 file changed, 3 deletions(-)
|
||||
|
||||
diff --git a/src/SchemaNode.cpp b/src/SchemaNode.cpp
|
||||
index 81e938f..9934cea 100644
|
||||
--- a/src/SchemaNode.cpp
|
||||
+++ b/src/SchemaNode.cpp
|
||||
@@ -640,9 +640,6 @@ bool List::isUserOrdered() const
|
||||
*/
|
||||
ActionRpcInput ActionRpc::input() const
|
||||
{
|
||||
- // I need a lysc_node* for ActionRpcInput, but m_node->input is a lysp_node_action_inout. lysp_node_action_inout is
|
||||
- // still just a lysc_node, so I'll just convert to lysc_node.
|
||||
- // This is not very pretty, but I don't want to introduce another member for ActionRpcInput and ActionRpcOutput.
|
||||
return ActionRpcInput{reinterpret_cast<const lysc_node*>(&reinterpret_cast<const lysc_node_action*>(m_node)->input), m_ctx};
|
||||
}
|
||||
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
From e1b17386cf61048d2fe27fffb3b763981a225f52 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Bed=C5=99ich=20Schindler?= <bedrich.schindler@gmail.com>
|
||||
Date: Wed, 27 Nov 2024 09:47:47 +0100
|
||||
Subject: [PATCH 4/8] schema: improve `List::keys()` not to use `std::move`
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
`List::keys()` used `std::move` while iterating over array of leafs.
|
||||
This was solved without using `std::move`.
|
||||
|
||||
Change-Id: I8cbf8780ecd8848e46c1de5d4123a08624536bba
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
---
|
||||
src/SchemaNode.cpp | 3 +--
|
||||
1 file changed, 1 insertion(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/SchemaNode.cpp b/src/SchemaNode.cpp
|
||||
index 9934cea..20e2aff 100644
|
||||
--- a/src/SchemaNode.cpp
|
||||
+++ b/src/SchemaNode.cpp
|
||||
@@ -593,8 +593,7 @@ std::vector<Leaf> List::keys() const
|
||||
LY_LIST_FOR(list->child, elem)
|
||||
{
|
||||
if (lysc_is_key(elem)) {
|
||||
- Leaf leaf(elem, m_ctx);
|
||||
- res.emplace_back(std::move(leaf));
|
||||
+ res.emplace_back(Leaf(elem, m_ctx));
|
||||
}
|
||||
}
|
||||
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -0,0 +1,124 @@
|
||||
From 1102ecdcafbc9206f59b383769687e418557838e Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Bed=C5=99ich=20Schindler?= <bedrich.schindler@gmail.com>
|
||||
Date: Mon, 25 Nov 2024 15:54:02 +0100
|
||||
Subject: [PATCH 5/8] schema: make leaf-list's `default` statement available
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Make leaf-list's `default` statement available so that it can be
|
||||
accessed if end-user requires reading schema nodes.
|
||||
|
||||
`LeafList::defaultValuesStr()` returns array of canonized string default
|
||||
values.
|
||||
|
||||
Change-Id: Idc42cd877f1fd3d717d491d09c46b59492527bff
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
---
|
||||
include/libyang-cpp/SchemaNode.hpp | 1 +
|
||||
src/SchemaNode.cpp | 17 +++++++++++++++++
|
||||
tests/context.cpp | 1 +
|
||||
tests/example_schema.hpp | 8 ++++++++
|
||||
tests/schema_node.cpp | 7 +++++++
|
||||
5 files changed, 34 insertions(+)
|
||||
|
||||
diff --git a/include/libyang-cpp/SchemaNode.hpp b/include/libyang-cpp/SchemaNode.hpp
|
||||
index 83afc06..8ddf9be 100644
|
||||
--- a/include/libyang-cpp/SchemaNode.hpp
|
||||
+++ b/include/libyang-cpp/SchemaNode.hpp
|
||||
@@ -169,6 +169,7 @@ class LIBYANG_CPP_EXPORT LeafList : public SchemaNode {
|
||||
public:
|
||||
bool isMandatory() const;
|
||||
types::Type valueType() const;
|
||||
+ std::vector<std::string> defaultValuesStr() const;
|
||||
libyang::types::constraints::ListSize maxElements() const;
|
||||
libyang::types::constraints::ListSize minElements() const;
|
||||
std::optional<std::string> units() const;
|
||||
diff --git a/src/SchemaNode.cpp b/src/SchemaNode.cpp
|
||||
index 9934cea..95bc09b 100644
|
||||
--- a/src/SchemaNode.cpp
|
||||
+++ b/src/SchemaNode.cpp
|
||||
@@ -472,6 +472,23 @@ types::Type LeafList::valueType() const
|
||||
return types::Type{reinterpret_cast<const lysc_node_leaflist*>(m_node)->type, typeParsed, m_ctx};
|
||||
}
|
||||
|
||||
+/**
|
||||
+ * @brief Retrieves the default string values for this leaf-list.
|
||||
+ *
|
||||
+ * @return The default values, or an empty vector if the leaf-list does not have default values.
|
||||
+ *
|
||||
+ * Wraps `lysc_node_leaflist::dflts`.
|
||||
+ */
|
||||
+std::vector<std::string> LeafList::defaultValuesStr() const
|
||||
+{
|
||||
+ auto dflts = reinterpret_cast<const lysc_node_leaflist*>(m_node)->dflts;
|
||||
+ std::vector<std::string> res;
|
||||
+ for (const auto& it : std::span(dflts, LY_ARRAY_COUNT(dflts))) {
|
||||
+ res.emplace_back(lyd_value_get_canonical(m_ctx.get(), it));
|
||||
+ }
|
||||
+ return res;
|
||||
+}
|
||||
+
|
||||
/**
|
||||
* @brief Retrieves the units for this leaf.
|
||||
* @return The units, or std::nullopt if no units are available.
|
||||
diff --git a/tests/context.cpp b/tests/context.cpp
|
||||
index 11019eb..902faf6 100644
|
||||
--- a/tests/context.cpp
|
||||
+++ b/tests/context.cpp
|
||||
@@ -733,6 +733,7 @@ TEST_CASE("context")
|
||||
+--rw iid-valid? instance-identifier
|
||||
+--rw iid-relaxed? instance-identifier
|
||||
+--rw leafListBasic* string
|
||||
+ +--rw leafListWithDefault* int32
|
||||
+--rw leafListWithMinMaxElements* int32
|
||||
+--rw leafListWithUnits* int32
|
||||
+--rw listBasic* [primary-key]
|
||||
diff --git a/tests/example_schema.hpp b/tests/example_schema.hpp
|
||||
index c093f50..2861b1a 100644
|
||||
--- a/tests/example_schema.hpp
|
||||
+++ b/tests/example_schema.hpp
|
||||
@@ -525,6 +525,14 @@ module type_module {
|
||||
ordered-by user;
|
||||
}
|
||||
|
||||
+ leaf-list leafListWithDefault {
|
||||
+ type int32;
|
||||
+ default -1;
|
||||
+ default +512;
|
||||
+ default 0x400;
|
||||
+ default 04000;
|
||||
+ }
|
||||
+
|
||||
leaf-list leafListWithMinMaxElements {
|
||||
type int32;
|
||||
min-elements 1;
|
||||
diff --git a/tests/schema_node.cpp b/tests/schema_node.cpp
|
||||
index a86900d..80c7407 100644
|
||||
--- a/tests/schema_node.cpp
|
||||
+++ b/tests/schema_node.cpp
|
||||
@@ -200,6 +200,7 @@ TEST_CASE("SchemaNode")
|
||||
"/type_module:iid-valid",
|
||||
"/type_module:iid-relaxed",
|
||||
"/type_module:leafListBasic",
|
||||
+ "/type_module:leafListWithDefault",
|
||||
"/type_module:leafListWithMinMaxElements",
|
||||
"/type_module:leafListWithUnits",
|
||||
"/type_module:listBasic",
|
||||
@@ -606,6 +607,12 @@ TEST_CASE("SchemaNode")
|
||||
REQUIRE(!ctx->findPath("/type_module:leafListBasic").asLeafList().isMandatory());
|
||||
}
|
||||
|
||||
+ DOCTEST_SUBCASE("LeafList::defaultValuesStr")
|
||||
+ {
|
||||
+ REQUIRE(ctx->findPath("/type_module:leafListWithDefault").asLeafList().defaultValuesStr() == std::vector<std::string>{"-1", "512", "1024", "2048"});
|
||||
+ REQUIRE(ctx->findPath("/type_module:leafListBasic").asLeafList().defaultValuesStr().size() == 0);
|
||||
+ }
|
||||
+
|
||||
DOCTEST_SUBCASE("LeafList::maxElements")
|
||||
{
|
||||
REQUIRE(ctx->findPath("/type_module:leafListWithMinMaxElements").asLeafList().maxElements() == 5);
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -0,0 +1,434 @@
|
||||
From 01f2633cef60495d5cafc4b4b1f25273b03ab3cd Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Bed=C5=99ich=20Schindler?= <bedrich.schindler@gmail.com>
|
||||
Date: Tue, 22 Oct 2024 15:11:30 +0200
|
||||
Subject: [PATCH 6/8] schema: Make choice and case statements available
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Make choice and case statements available so that they can be accessed
|
||||
if end-user requires reading schema nodes.
|
||||
|
||||
By design, choice and case statements do not exist in data tree directly.
|
||||
Only children of one case can be present in the data tree at one time.
|
||||
That means that choice and case children are not instantiable, thus
|
||||
`SchemaNode::immediateChildren` must be used (instead of
|
||||
`SchemaNode::childInstantibles`) if end-user wants to access choice
|
||||
and case substatements.
|
||||
|
||||
Change-Id: Ib089672ad21dda8a0344895835d92d3432fcccb8
|
||||
Co-authored-by: Jan Kundrát <jan.kundrat@cesnet.cz>
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
---
|
||||
include/libyang-cpp/SchemaNode.hpp | 34 +++++++++++++
|
||||
src/SchemaNode.cpp | 68 ++++++++++++++++++++++++++
|
||||
tests/context.cpp | 77 +++++++++++++++++++-----------
|
||||
tests/example_schema.hpp | 60 +++++++++++++++++++++++
|
||||
tests/schema_node.cpp | 72 ++++++++++++++++++++++++++++
|
||||
5 files changed, 284 insertions(+), 27 deletions(-)
|
||||
|
||||
diff --git a/include/libyang-cpp/SchemaNode.hpp b/include/libyang-cpp/SchemaNode.hpp
|
||||
index 8ddf9be..0f1a4c4 100644
|
||||
--- a/include/libyang-cpp/SchemaNode.hpp
|
||||
+++ b/include/libyang-cpp/SchemaNode.hpp
|
||||
@@ -22,6 +22,8 @@ class AnyDataAnyXML;
|
||||
class ActionRpc;
|
||||
class ActionRpcInput;
|
||||
class ActionRpcOutput;
|
||||
+class Case;
|
||||
+class Choice;
|
||||
class Container;
|
||||
class Leaf;
|
||||
class LeafList;
|
||||
@@ -62,6 +64,8 @@ public:
|
||||
// drectly by the user.
|
||||
// TODO: turn these into a templated `as<>` method.
|
||||
AnyDataAnyXML asAnyDataAnyXML() const;
|
||||
+ Case asCase() const;
|
||||
+ Choice asChoice() const;
|
||||
Container asContainer() const;
|
||||
Leaf asLeaf() const;
|
||||
LeafList asLeafList() const;
|
||||
@@ -129,6 +133,36 @@ private:
|
||||
using SchemaNode::SchemaNode;
|
||||
};
|
||||
|
||||
+/**
|
||||
+ * @brief Class representing a schema definition of a `case` node.
|
||||
+ *
|
||||
+ * Wraps `lysc_node_case`.
|
||||
+ */
|
||||
+class LIBYANG_CPP_EXPORT Case : public SchemaNode {
|
||||
+public:
|
||||
+ friend SchemaNode;
|
||||
+ friend Choice;
|
||||
+
|
||||
+private:
|
||||
+ using SchemaNode::SchemaNode;
|
||||
+};
|
||||
+
|
||||
+/**
|
||||
+ * @brief Class representing a schema definition of a `choice` node.
|
||||
+ *
|
||||
+ * Wraps `lysc_node_choice`.
|
||||
+ */
|
||||
+class LIBYANG_CPP_EXPORT Choice : public SchemaNode {
|
||||
+public:
|
||||
+ bool isMandatory() const;
|
||||
+ std::vector<Case> cases() const;
|
||||
+ std::optional<Case> defaultCase() const;
|
||||
+ friend SchemaNode;
|
||||
+
|
||||
+private:
|
||||
+ using SchemaNode::SchemaNode;
|
||||
+};
|
||||
+
|
||||
/**
|
||||
* @brief Class representing a schema definition of a `container` node.
|
||||
*/
|
||||
diff --git a/src/SchemaNode.cpp b/src/SchemaNode.cpp
|
||||
index bd20402..26b5099 100644
|
||||
--- a/src/SchemaNode.cpp
|
||||
+++ b/src/SchemaNode.cpp
|
||||
@@ -191,6 +191,32 @@ NodeType SchemaNode::nodeType() const
|
||||
return utils::toNodeType(m_node->nodetype);
|
||||
}
|
||||
|
||||
+/**
|
||||
+ * @brief Try to cast this SchemaNode to a Case node.
|
||||
+ * @throws Error If this node is not a case.
|
||||
+ */
|
||||
+Case SchemaNode::asCase() const
|
||||
+{
|
||||
+ if (nodeType() != NodeType::Case) {
|
||||
+ throw Error("Schema node is not a case: " + path());
|
||||
+ }
|
||||
+
|
||||
+ return Case{m_node, m_ctx};
|
||||
+}
|
||||
+
|
||||
+/**
|
||||
+ * @brief Try to cast this SchemaNode to a Choice node.
|
||||
+ * @throws Error If this node is not a choice.
|
||||
+ */
|
||||
+Choice SchemaNode::asChoice() const
|
||||
+{
|
||||
+ if (nodeType() != NodeType::Choice) {
|
||||
+ throw Error("Schema node is not a choice: " + path());
|
||||
+ }
|
||||
+
|
||||
+ return Choice{m_node, m_ctx};
|
||||
+}
|
||||
+
|
||||
/**
|
||||
* @brief Try to cast this SchemaNode to a Container node.
|
||||
* @throws Error If this node is not a container.
|
||||
@@ -401,6 +427,48 @@ bool AnyDataAnyXML::isMandatory() const
|
||||
return m_node->flags & LYS_MAND_TRUE;
|
||||
}
|
||||
|
||||
+/**
|
||||
+ * @brief Checks whether this choice is mandatory.
|
||||
+ *
|
||||
+ * Wraps flag `LYS_MAND_TRUE`.
|
||||
+ */
|
||||
+bool Choice::isMandatory() const
|
||||
+{
|
||||
+ return m_node->flags & LYS_MAND_TRUE;
|
||||
+}
|
||||
+
|
||||
+/**
|
||||
+ * @brief Retrieves the list of cases for this choice.
|
||||
+ *
|
||||
+ * Wraps `lysc_node_choice::cases`.
|
||||
+ */
|
||||
+std::vector<Case> Choice::cases() const
|
||||
+{
|
||||
+ auto choice = reinterpret_cast<const lysc_node_choice*>(m_node);
|
||||
+ auto cases = reinterpret_cast<lysc_node*>(choice->cases);
|
||||
+ std::vector<Case> res;
|
||||
+ lysc_node* elem;
|
||||
+ LY_LIST_FOR(cases, elem)
|
||||
+ {
|
||||
+ res.emplace_back(Case(elem, m_ctx));
|
||||
+ }
|
||||
+ return res;
|
||||
+}
|
||||
+
|
||||
+/**
|
||||
+ * @brief Retrieves the default case for this choice.
|
||||
+ *
|
||||
+ * Wraps `lysc_node_choice::dflt`.
|
||||
+ */
|
||||
+std::optional<Case> Choice::defaultCase() const
|
||||
+{
|
||||
+ auto choice = reinterpret_cast<const lysc_node_choice*>(m_node);
|
||||
+ if (!choice->dflt) {
|
||||
+ return std::nullopt;
|
||||
+ }
|
||||
+ return Case{reinterpret_cast<lysc_node*>(choice->dflt), m_ctx};
|
||||
+}
|
||||
+
|
||||
/**
|
||||
* @brief Checks whether this container is mandatory.
|
||||
*
|
||||
diff --git a/tests/context.cpp b/tests/context.cpp
|
||||
index 902faf6..5929b75 100644
|
||||
--- a/tests/context.cpp
|
||||
+++ b/tests/context.cpp
|
||||
@@ -709,33 +709,56 @@ TEST_CASE("context")
|
||||
auto mod = ctx_pp->parseModule(type_module, libyang::SchemaFormat::YANG);
|
||||
|
||||
REQUIRE(mod.printStr(libyang::SchemaOutputFormat::Tree) == R"(module: type_module
|
||||
- +--rw anydataBasic? anydata
|
||||
- +--rw anydataWithMandatoryChild anydata
|
||||
- +--rw anyxmlBasic? anyxml
|
||||
- +--rw anyxmlWithMandatoryChild anyxml
|
||||
- +--rw leafBinary? binary
|
||||
- +--rw leafBits? bits
|
||||
- +--rw leafEnum? enumeration
|
||||
- +--rw leafEnum2? enumeration
|
||||
- +--rw leafNumber? int32
|
||||
- +--rw leafRef? -> /custom-prefix:listAdvancedWithOneKey/lol
|
||||
- +--rw leafRefRelaxed? -> /custom-prefix:listAdvancedWithOneKey/lol
|
||||
- +--rw leafString? string
|
||||
- +--rw leafUnion? union
|
||||
- +--rw meal? identityref
|
||||
- +--ro leafWithConfigFalse? string
|
||||
- +--rw leafWithDefaultValue? string
|
||||
- +--rw leafWithDescription? string
|
||||
- +--rw leafWithMandatoryTrue string
|
||||
- x--rw leafWithStatusDeprecated? string
|
||||
- o--rw leafWithStatusObsolete? string
|
||||
- +--rw leafWithUnits? int32
|
||||
- +--rw iid-valid? instance-identifier
|
||||
- +--rw iid-relaxed? instance-identifier
|
||||
- +--rw leafListBasic* string
|
||||
- +--rw leafListWithDefault* int32
|
||||
- +--rw leafListWithMinMaxElements* int32
|
||||
- +--rw leafListWithUnits* int32
|
||||
+ +--rw anydataBasic? anydata
|
||||
+ +--rw anydataWithMandatoryChild anydata
|
||||
+ +--rw anyxmlBasic? anyxml
|
||||
+ +--rw anyxmlWithMandatoryChild anyxml
|
||||
+ +--rw choiceBasicContainer
|
||||
+ | +--rw (choiceBasic)?
|
||||
+ | +--:(case1)
|
||||
+ | | +--rw l? string
|
||||
+ | | +--rw ll* string
|
||||
+ | +--:(case2)
|
||||
+ | +--rw l2? string
|
||||
+ +--rw choiceWithMandatoryContainer
|
||||
+ | +--rw (choiceWithMandatory)
|
||||
+ | +--:(case3)
|
||||
+ | | +--rw l3? string
|
||||
+ | +--:(case4)
|
||||
+ | +--rw l4? string
|
||||
+ +--rw choiceWithDefaultContainer
|
||||
+ | +--rw (choiceWithDefault)?
|
||||
+ | +--:(case5)
|
||||
+ | | +--rw l5? string
|
||||
+ | +--:(case6)
|
||||
+ | +--rw l6? string
|
||||
+ +--rw implicitCaseContainer
|
||||
+ | +--rw (implicitCase)?
|
||||
+ | +--:(implicitLeaf)
|
||||
+ | +--rw implicitLeaf? string
|
||||
+ +--rw leafBinary? binary
|
||||
+ +--rw leafBits? bits
|
||||
+ +--rw leafEnum? enumeration
|
||||
+ +--rw leafEnum2? enumeration
|
||||
+ +--rw leafNumber? int32
|
||||
+ +--rw leafRef? -> /custom-prefix:listAdvancedWithOneKey/lol
|
||||
+ +--rw leafRefRelaxed? -> /custom-prefix:listAdvancedWithOneKey/lol
|
||||
+ +--rw leafString? string
|
||||
+ +--rw leafUnion? union
|
||||
+ +--rw meal? identityref
|
||||
+ +--ro leafWithConfigFalse? string
|
||||
+ +--rw leafWithDefaultValue? string
|
||||
+ +--rw leafWithDescription? string
|
||||
+ +--rw leafWithMandatoryTrue string
|
||||
+ x--rw leafWithStatusDeprecated? string
|
||||
+ o--rw leafWithStatusObsolete? string
|
||||
+ +--rw leafWithUnits? int32
|
||||
+ +--rw iid-valid? instance-identifier
|
||||
+ +--rw iid-relaxed? instance-identifier
|
||||
+ +--rw leafListBasic* string
|
||||
+ +--rw leafListWithDefault* int32
|
||||
+ +--rw leafListWithMinMaxElements* int32
|
||||
+ +--rw leafListWithUnits* int32
|
||||
+--rw listBasic* [primary-key]
|
||||
| +--rw primary-key string
|
||||
+--rw listAdvancedWithOneKey* [lol]
|
||||
diff --git a/tests/example_schema.hpp b/tests/example_schema.hpp
|
||||
index 2861b1a..ae3b4de 100644
|
||||
--- a/tests/example_schema.hpp
|
||||
+++ b/tests/example_schema.hpp
|
||||
@@ -390,6 +390,66 @@ module type_module {
|
||||
mandatory true;
|
||||
}
|
||||
|
||||
+ container choiceBasicContainer {
|
||||
+ choice choiceBasic {
|
||||
+ case case1 {
|
||||
+ leaf l {
|
||||
+ type string;
|
||||
+ }
|
||||
+ leaf-list ll {
|
||||
+ type string;
|
||||
+ ordered-by user;
|
||||
+ }
|
||||
+ }
|
||||
+ case case2 {
|
||||
+ leaf l2 {
|
||||
+ type string;
|
||||
+ }
|
||||
+ }
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ container choiceWithMandatoryContainer {
|
||||
+ choice choiceWithMandatory {
|
||||
+ mandatory true;
|
||||
+ case case3 {
|
||||
+ leaf l3 {
|
||||
+ type string;
|
||||
+ }
|
||||
+ }
|
||||
+ case case4 {
|
||||
+ leaf l4 {
|
||||
+ type string;
|
||||
+ }
|
||||
+ }
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ container choiceWithDefaultContainer {
|
||||
+ choice choiceWithDefault {
|
||||
+ default case5;
|
||||
+ case case5 {
|
||||
+ leaf l5 {
|
||||
+ type string;
|
||||
+ }
|
||||
+ }
|
||||
+ case case6 {
|
||||
+ leaf l6 {
|
||||
+ type string;
|
||||
+ }
|
||||
+ }
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ container implicitCaseContainer {
|
||||
+ choice implicitCase {
|
||||
+ leaf implicitLeaf {
|
||||
+ type string;
|
||||
+ }
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+
|
||||
leaf leafBinary {
|
||||
type binary;
|
||||
}
|
||||
diff --git a/tests/schema_node.cpp b/tests/schema_node.cpp
|
||||
index 80c7407..8d74bd2 100644
|
||||
--- a/tests/schema_node.cpp
|
||||
+++ b/tests/schema_node.cpp
|
||||
@@ -58,6 +58,9 @@ TEST_CASE("SchemaNode")
|
||||
],
|
||||
"type_module:anydataWithMandatoryChild": {"content": "test-string"},
|
||||
"type_module:anyxmlWithMandatoryChild": {"content": "test-string"},
|
||||
+ "type_module:choiceWithMandatoryContainer": {
|
||||
+ "l4": "test-string"
|
||||
+ },
|
||||
"type_module:containerWithMandatoryChild": {
|
||||
"leafWithMandatoryTrue": "test-string"
|
||||
},
|
||||
@@ -180,6 +183,10 @@ TEST_CASE("SchemaNode")
|
||||
"/type_module:anydataWithMandatoryChild",
|
||||
"/type_module:anyxmlBasic",
|
||||
"/type_module:anyxmlWithMandatoryChild",
|
||||
+ "/type_module:choiceBasicContainer",
|
||||
+ "/type_module:choiceWithMandatoryContainer",
|
||||
+ "/type_module:choiceWithDefaultContainer",
|
||||
+ "/type_module:implicitCaseContainer",
|
||||
"/type_module:leafBinary",
|
||||
"/type_module:leafBits",
|
||||
"/type_module:leafEnum",
|
||||
@@ -417,6 +424,71 @@ TEST_CASE("SchemaNode")
|
||||
REQUIRE(!ctx->findPath("/type_module:anyxmlBasic").asAnyDataAnyXML().isMandatory());
|
||||
}
|
||||
|
||||
+ DOCTEST_SUBCASE("Choice and Case")
|
||||
+ {
|
||||
+ std::string xpath;
|
||||
+ bool isMandatory = false;
|
||||
+ std::optional<std::string> defaultCase;
|
||||
+ std::vector<std::string> caseNames;
|
||||
+ std::optional<libyang::SchemaNode> root;
|
||||
+
|
||||
+ DOCTEST_SUBCASE("two cases with nothing fancy")
|
||||
+ {
|
||||
+ root = ctx->findPath("/type_module:choiceBasicContainer");
|
||||
+ caseNames = {"case1", "case2"};
|
||||
+ }
|
||||
+
|
||||
+ DOCTEST_SUBCASE("mandatory choice") {
|
||||
+ root = ctx->findPath("/type_module:choiceWithMandatoryContainer");
|
||||
+ isMandatory = true;
|
||||
+ caseNames = {"case3", "case4"};
|
||||
+ }
|
||||
+
|
||||
+ DOCTEST_SUBCASE("default choice") {
|
||||
+ root = ctx->findPath("/type_module:choiceWithDefaultContainer");
|
||||
+ defaultCase = "case5";
|
||||
+ caseNames = {"case5", "case6"};
|
||||
+ }
|
||||
+
|
||||
+ DOCTEST_SUBCASE("implicit case") {
|
||||
+ root = ctx->findPath("/type_module:implicitCaseContainer");
|
||||
+ caseNames = {"implicitLeaf"};
|
||||
+ }
|
||||
+
|
||||
+ // For testing purposes, we have each choice in its own container. As choice and case are not directly instantiable,
|
||||
+ // we wrap them in a container to simplify the testing process. It allows us to simply address the choice by its
|
||||
+ // container and then get the choice from it. It also prevents polluting the test schema with unnecessary nodes
|
||||
+ // and isolates the choice from other nodes.
|
||||
+ auto container = root->asContainer();
|
||||
+ auto choice = container.immediateChildren().begin()->asChoice();
|
||||
+ REQUIRE(choice.isMandatory() == isMandatory);
|
||||
+ REQUIRE(!!choice.defaultCase() == !!defaultCase);
|
||||
+ if (defaultCase) {
|
||||
+ REQUIRE(choice.defaultCase()->name() == *defaultCase);
|
||||
+ }
|
||||
+ std::vector<std::string> actualCaseNames;
|
||||
+ for (const auto& case_ : choice.cases()) {
|
||||
+ actualCaseNames.push_back(case_.name());
|
||||
+ }
|
||||
+ REQUIRE(actualCaseNames == caseNames);
|
||||
+
|
||||
+ // Also test child node access for one arbitrary choice/case combination
|
||||
+ if (root->path() == "/type_module:choiceBasicContainer") {
|
||||
+ REQUIRE(choice.cases().size() == 2);
|
||||
+ auto case1 = choice.cases()[0];
|
||||
+ auto children = case1.immediateChildren();
|
||||
+ auto it = children.begin();
|
||||
+ REQUIRE(it->asLeaf().name() == "l");
|
||||
+ ++it;
|
||||
+ REQUIRE(it->asLeafList().name() == "ll");
|
||||
+
|
||||
+ auto case2 = choice.cases()[1];
|
||||
+ children = case2.immediateChildren();
|
||||
+ it = children.begin();
|
||||
+ REQUIRE(it->asLeaf().name() == "l2");
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
DOCTEST_SUBCASE("Container::isMandatory")
|
||||
{
|
||||
REQUIRE(ctx->findPath("/type_module:containerWithMandatoryChild").asContainer().isMandatory());
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -0,0 +1,129 @@
|
||||
From a1acdc794facf8cbf113f73274ecebd5898c81a1 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Jan=20Kundr=C3=A1t?= <jan.kundrat@cesnet.cz>
|
||||
Date: Tue, 17 Dec 2024 15:08:43 +0100
|
||||
Subject: [PATCH 7/8] Wrap lyd_change_term for changing the value for a
|
||||
terminal node
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Previously, the code would require a newPath(...,
|
||||
libyang::CreationOptions::Update), which is quite a mouthful.
|
||||
|
||||
Change-Id: I8a908c0fdd3e48dda830819758522a511adedd3b
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
---
|
||||
include/libyang-cpp/DataNode.hpp | 8 ++++++
|
||||
src/DataNode.cpp | 21 ++++++++++++++++
|
||||
tests/data_node.cpp | 42 ++++++++++++++++++++++++++------
|
||||
3 files changed, 63 insertions(+), 8 deletions(-)
|
||||
|
||||
diff --git a/include/libyang-cpp/DataNode.hpp b/include/libyang-cpp/DataNode.hpp
|
||||
index 2211415..851681b 100644
|
||||
--- a/include/libyang-cpp/DataNode.hpp
|
||||
+++ b/include/libyang-cpp/DataNode.hpp
|
||||
@@ -212,6 +212,14 @@ public:
|
||||
Value value() const;
|
||||
types::Type valueType() const;
|
||||
|
||||
+ /** @brief Was the value changed? */
|
||||
+ enum class ValueChange {
|
||||
+ Changed, /**< Yes, this is an actual change of the stored value */
|
||||
+ ExplicitNonDefault, /**< It still holds the default value, but it's been set explicitly now */
|
||||
+ EqualValueNotChanged, /**< No change, the previous value is the same as the new one, and it isn't an implicit default */
|
||||
+ };
|
||||
+ ValueChange changeValue(const std::string value);
|
||||
+
|
||||
private:
|
||||
using DataNode::DataNode;
|
||||
};
|
||||
diff --git a/src/DataNode.cpp b/src/DataNode.cpp
|
||||
index 2ef17f2..84591e5 100644
|
||||
--- a/src/DataNode.cpp
|
||||
+++ b/src/DataNode.cpp
|
||||
@@ -903,6 +903,27 @@ types::Type DataNodeTerm::valueType() const
|
||||
return impl(reinterpret_cast<const lyd_node_term*>(m_node)->value);
|
||||
}
|
||||
|
||||
+/** @short Change the term's value
|
||||
+ *
|
||||
+ * Wraps `lyd_change_term`.
|
||||
+ * */
|
||||
+DataNodeTerm::ValueChange DataNodeTerm::changeValue(const std::string value)
|
||||
+{
|
||||
+ auto ret = lyd_change_term(m_node, value.c_str());
|
||||
+
|
||||
+ switch (ret) {
|
||||
+ case LY_SUCCESS:
|
||||
+ return ValueChange::Changed;
|
||||
+ case LY_EEXIST:
|
||||
+ return ValueChange::ExplicitNonDefault;
|
||||
+ case LY_ENOT:
|
||||
+ return ValueChange::EqualValueNotChanged;
|
||||
+ default:
|
||||
+ throwIfError(ret, "DataNodeTerm::changeValue failed");
|
||||
+ __builtin_unreachable();
|
||||
+ }
|
||||
+}
|
||||
+
|
||||
/**
|
||||
* @brief Returns a collection for iterating depth-first over the subtree this instance points to.
|
||||
*
|
||||
diff --git a/tests/data_node.cpp b/tests/data_node.cpp
|
||||
index 8a2610e..45fd6c1 100644
|
||||
--- a/tests/data_node.cpp
|
||||
+++ b/tests/data_node.cpp
|
||||
@@ -456,15 +456,41 @@ TEST_CASE("Data Node manipulation")
|
||||
REQUIRE(node.hasDefaultValue());
|
||||
REQUIRE(node.isImplicitDefault());
|
||||
|
||||
- data->newPath("/example-schema3:leafWithDefault", "not-default-value", libyang::CreationOptions::Update);
|
||||
- node = data->findPath("/example-schema3:leafWithDefault")->asTerm();
|
||||
- REQUIRE(!node.hasDefaultValue());
|
||||
- REQUIRE(!node.isImplicitDefault());
|
||||
+ DOCTEST_SUBCASE("newPath")
|
||||
+ {
|
||||
+ data->newPath("/example-schema3:leafWithDefault", "not-default-value", libyang::CreationOptions::Update);
|
||||
+ node = data->findPath("/example-schema3:leafWithDefault")->asTerm();
|
||||
+ REQUIRE(!node.hasDefaultValue());
|
||||
+ REQUIRE(!node.isImplicitDefault());
|
||||
|
||||
- data->newPath("/example-schema3:leafWithDefault", "AHOJ", libyang::CreationOptions::Update);
|
||||
- node = data->findPath("/example-schema3:leafWithDefault")->asTerm();
|
||||
- REQUIRE(node.hasDefaultValue());
|
||||
- REQUIRE(!node.isImplicitDefault());
|
||||
+ data->newPath("/example-schema3:leafWithDefault", "AHOJ", libyang::CreationOptions::Update);
|
||||
+ node = data->findPath("/example-schema3:leafWithDefault")->asTerm();
|
||||
+ REQUIRE(node.hasDefaultValue());
|
||||
+ REQUIRE(!node.isImplicitDefault());
|
||||
+ }
|
||||
+
|
||||
+ DOCTEST_SUBCASE("changing values")
|
||||
+ {
|
||||
+ auto node = data->findPath("/example-schema3:leafWithDefault");
|
||||
+ REQUIRE(!!node);
|
||||
+ auto term = node->asTerm();
|
||||
+
|
||||
+ DOCTEST_SUBCASE("to an arbitrary value") {
|
||||
+ REQUIRE(term.changeValue("cau") == libyang::DataNodeTerm::ValueChange::Changed);
|
||||
+ }
|
||||
+
|
||||
+ DOCTEST_SUBCASE("from an implicit default to an explicit default") {
|
||||
+ REQUIRE(term.changeValue("AHOJ") == libyang::DataNodeTerm::ValueChange::ExplicitNonDefault);
|
||||
+ REQUIRE(term.changeValue("AHOJ") == libyang::DataNodeTerm::ValueChange::EqualValueNotChanged);
|
||||
+ REQUIRE(term.changeValue("cau") == libyang::DataNodeTerm::ValueChange::Changed);
|
||||
+ REQUIRE(term.changeValue("cau") == libyang::DataNodeTerm::ValueChange::EqualValueNotChanged);
|
||||
+ }
|
||||
+
|
||||
+ DOCTEST_SUBCASE("from an implicit default to something else") {
|
||||
+ REQUIRE(term.changeValue("cau") == libyang::DataNodeTerm::ValueChange::Changed);
|
||||
+ REQUIRE(term.changeValue("cau") == libyang::DataNodeTerm::ValueChange::EqualValueNotChanged);
|
||||
+ }
|
||||
+ }
|
||||
}
|
||||
|
||||
DOCTEST_SUBCASE("isTerm")
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -0,0 +1,46 @@
|
||||
From 39c7530caa510144c17521278b721ba1e6d8ff40 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Tom=C3=A1=C5=A1=20Pecka?= <tomas.pecka@cesnet.cz>
|
||||
Date: Thu, 9 Jan 2025 15:31:37 +0100
|
||||
Subject: [PATCH 8/8] upstream stopped reporting schema-mounts node
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Change-Id: I940769d38d56fcfda3e1408c92331fdb00c161e9
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
---
|
||||
CMakeLists.txt | 2 +-
|
||||
tests/context.cpp | 3 +--
|
||||
2 files changed, 2 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/CMakeLists.txt b/CMakeLists.txt
|
||||
index 3d86809..732f52b 100644
|
||||
--- a/CMakeLists.txt
|
||||
+++ b/CMakeLists.txt
|
||||
@@ -28,7 +28,7 @@ option(WITH_DOCS "Create and install internal documentation (needs Doxygen)" ${D
|
||||
option(BUILD_SHARED_LIBS "By default, shared libs are enabled. Turn off for a static build." ON)
|
||||
|
||||
find_package(PkgConfig REQUIRED)
|
||||
-pkg_check_modules(LIBYANG REQUIRED libyang>=3.4.2 IMPORTED_TARGET)
|
||||
+pkg_check_modules(LIBYANG REQUIRED libyang>=3.7.8 IMPORTED_TARGET)
|
||||
set(LIBYANG_CPP_PKG_VERSION "3")
|
||||
|
||||
# FIXME from gcc 14.1 on we should be able to use the calendar/time from libstdc++ and thus remove the date dependency
|
||||
diff --git a/tests/context.cpp b/tests/context.cpp
|
||||
index 5929b75..9d38fea 100644
|
||||
--- a/tests/context.cpp
|
||||
+++ b/tests/context.cpp
|
||||
@@ -509,8 +509,7 @@ TEST_CASE("context")
|
||||
"error-message": "hi"
|
||||
}
|
||||
]
|
||||
- },
|
||||
- "ietf-yang-schema-mount:schema-mounts": {}
|
||||
+ }
|
||||
}
|
||||
)");
|
||||
}
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Locally calculated
|
||||
sha256 6b94f3abc1aabd0c72a7c7d92a77f79dda7c8a0cb3df839a97890b4116a2de2a COPYING
|
||||
sha256 6bd96a33f41f73d6ca524efa946b5e592227a5dd6dd21f193fadf4be3583552d nghttp2-asio-e877868abe06a83ed0a6ac6e245c07f6f20866b5-br1.tar.gz
|
||||
sha256 d971c538a31eae5714d2434d90f86794f267615e85e8d2bb0c383e83c300e1ce nghttp2-asio-e877868abe06a83ed0a6ac6e245c07f6f20866b5-git4.tar.gz
|
||||
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user