Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
eb7c031270 | ||
|
|
1d23f73bfd | ||
|
|
119b92f94e | ||
|
|
96fad208cb | ||
|
|
0a3879f521 | ||
|
|
6f6bb412f9 | ||
|
|
b04bae1ad6 | ||
|
|
73edf1bbd6 | ||
|
|
2557eb4900 | ||
|
|
f71722c111 | ||
|
|
5ea99680c8 | ||
|
|
55b038d999 | ||
|
|
83b55ee4d8 | ||
|
|
68e7167902 | ||
|
|
25a26fe7c6 | ||
|
|
6c8bd25cee | ||
|
|
ea300137ef | ||
|
|
44e9c87376 | ||
|
|
e708f21444 | ||
|
|
3508b8d0bb | ||
|
|
eec867bd5f | ||
|
|
daa0bd81e8 | ||
|
|
4ccc70aeee | ||
|
|
923443b620 | ||
|
|
9ad51c31bf | ||
|
|
6272c9c46c | ||
|
|
4750f96774 | ||
|
|
81bc143883 | ||
|
|
58b3fb30be | ||
|
|
6dfc305f0b | ||
|
|
8ca3d3a3ff | ||
|
|
7ae4de3a17 | ||
|
|
7c019190c8 | ||
|
|
17df77ca0f | ||
|
|
a188f4269d | ||
|
|
6cdcd5775d | ||
|
|
1d0c2be515 | ||
|
|
fc7e1d0745 | ||
|
|
950a6ef794 | ||
|
|
7f829cfbdf | ||
|
|
86df54c107 | ||
|
|
34dead1a50 | ||
|
|
313554d12e | ||
|
|
8b39d3fdc7 | ||
|
|
66a5e5304b | ||
|
|
12df83e6d2 | ||
|
|
6b0145f92e | ||
|
|
b21043c7e5 | ||
|
|
ab9b2f555b | ||
|
|
cfeefc1d86 | ||
|
|
d65c478a28 | ||
|
|
477f7aed72 | ||
|
|
da3bf57515 | ||
|
|
0d43e135a9 | ||
|
|
ddd5172a6b | ||
|
|
6717bbbe26 | ||
|
|
7683466424 | ||
|
|
6cc380d8ce | ||
|
|
8740b2eb23 | ||
|
|
7244fad2e8 | ||
|
|
edbc28a48b | ||
|
|
33c95e860b | ||
|
|
a60968b7b2 | ||
|
|
8abc27e698 | ||
|
|
2646a48227 | ||
|
|
a8f57618b8 | ||
|
|
9374feefb0 | ||
|
|
d4726aff82 | ||
|
|
3ac6eaa16b | ||
|
|
e6bd55c0be | ||
|
|
c3975f4ce5 | ||
|
|
611c1a6d51 | ||
|
|
d5536fa536 | ||
|
|
ce895a4c59 | ||
|
|
a7d91b4f80 | ||
|
|
bb19d064d5 | ||
|
|
fa7c743843 | ||
|
|
a2a11e816a | ||
|
|
7c73ddeaaf | ||
|
|
bc6180680d | ||
|
|
21df66d221 | ||
|
|
684bbafad5 | ||
|
|
ce6b4729cd | ||
|
|
b0a6e167bc | ||
|
|
54bb3a01e2 | ||
|
|
fcce71fe23 | ||
|
|
de4db3e6bc | ||
|
|
7803f6bc10 | ||
|
|
5c1bcbaf44 | ||
|
|
eefe84fd4b | ||
|
|
a3c26c4ef3 | ||
|
|
a845c3e9f3 | ||
|
|
d151b5ef7c | ||
|
|
0491c1f195 | ||
|
|
1c04409cf3 | ||
|
|
14dd7cbc33 | ||
|
|
ebf4157e2c | ||
|
|
8a1747db2c | ||
|
|
ded65cf94a | ||
|
|
30757c8160 | ||
|
|
b3fe0d58d8 | ||
|
|
15a2221b23 | ||
|
|
c135230289 | ||
|
|
99af0ba0e5 | ||
|
|
2f296e9857 | ||
|
|
f02048e904 | ||
|
|
bdc391b4ce | ||
|
|
9aacd251b8 | ||
|
|
867ea6e92a | ||
|
|
ce89499518 | ||
|
|
cf4a29da84 | ||
|
|
edc1346753 | ||
|
|
ed5baf5839 | ||
|
|
5b100fb99e | ||
|
|
dc8fc40002 | ||
|
|
5a339e46cb | ||
|
|
90ec35c69e | ||
|
|
f98b00fcca | ||
|
|
83f2c27e6d | ||
|
|
b0adf85f12 | ||
|
|
fcbd75a0ef | ||
|
|
d1e71454cf | ||
|
|
fdf1aaebcc | ||
|
|
238ea9118b | ||
|
|
67838fa66b | ||
|
|
c574f23210 | ||
|
|
a66e000699 | ||
|
|
c692c93f94 | ||
|
|
a491f2a88b | ||
|
|
9d912446a7 | ||
|
|
3d3a4cac55 | ||
|
|
fc0a68a18a | ||
|
|
ea2627d4f6 | ||
|
|
21321f0196 | ||
|
|
dadb90a6d8 | ||
|
|
d5d3eef08b | ||
|
|
14fb93f5cf | ||
|
|
7b3cd7d663 | ||
|
|
67817a182c | ||
|
|
692fa166d1 | ||
|
|
c5d9a7c8b3 | ||
|
|
45c588567d | ||
|
|
2a8580edcc | ||
|
|
ffd0c05f41 | ||
|
|
9271c2439f | ||
|
|
7295077f27 | ||
|
|
b3d76de8f3 | ||
|
|
56f14ff520 | ||
|
|
9845e3b0c7 | ||
|
|
08e6833266 | ||
|
|
df54982978 | ||
|
|
efd6cce842 | ||
|
|
1dc84af095 | ||
|
|
d6c0d4bea7 | ||
|
|
85c4b579d3 | ||
|
|
1f268a7b90 | ||
|
|
562fd253c4 | ||
|
|
be547ba9a8 | ||
|
|
40e94883c6 | ||
|
|
9f268606e4 | ||
|
|
de113503ea | ||
|
|
6f203b1c78 | ||
|
|
c31bbbefa9 | ||
|
|
0d03f874ee | ||
|
|
51176c7d26 | ||
|
|
88958a0b1f | ||
|
|
e3f87799b6 | ||
|
|
ebcb38be37 | ||
|
|
889fb3eb79 | ||
|
|
2a6e7e5208 | ||
|
|
9629e2eef4 | ||
|
|
a0c48e7b5f | ||
|
|
edd2e60dd5 | ||
|
|
ec82d68a9f | ||
|
|
20d5426935 | ||
|
|
9d6d0e2388 | ||
|
|
6167f2a6a4 | ||
|
|
4ad2664b78 | ||
|
|
fe031f1a10 | ||
|
|
0a3277caf2 | ||
|
|
cac357458c | ||
|
|
7b8bc43bca | ||
|
|
5c7fc3f570 | ||
|
|
bae70ec85a | ||
|
|
eeb10b0f07 | ||
|
|
b92c9daedd | ||
|
|
eabaaac7c2 | ||
|
|
de33df14e2 | ||
|
|
5eeed0e743 | ||
|
|
24852caad0 | ||
|
|
08f4207277 | ||
|
|
5fbb30fed5 | ||
|
|
f25f0ab050 | ||
|
|
b53c1612f0 | ||
|
|
57d5bf1577 | ||
|
|
0ad8fab5c7 | ||
|
|
ecabce86c7 | ||
|
|
a7e72a46d9 | ||
|
|
915bef2dd4 | ||
|
|
7f9a1df6f7 | ||
|
|
67a6fc18d5 | ||
|
|
8538888069 | ||
|
|
5a1cf7f9f8 | ||
|
|
6755011b25 | ||
|
|
e5a8514fa0 | ||
|
|
82c3eb1ee7 | ||
|
|
159135786a | ||
|
|
8a9415f0b4 | ||
|
|
93cffaedde | ||
|
|
991364b411 | ||
|
|
22cf97fdbd | ||
|
|
16c1b50349 | ||
|
|
d2e5c2cd29 | ||
|
|
8bca1bed9e | ||
|
|
b88841952a | ||
|
|
9c3e951286 | ||
|
|
c7c01e3616 | ||
|
|
a6889fa8c5 | ||
|
|
6cd92c25a8 | ||
|
|
ff4e20221c | ||
|
|
808edf0a29 | ||
|
|
3f68e297ef | ||
|
|
0158fe1adb | ||
|
|
4345ec1694 | ||
|
|
ebace5020b | ||
|
|
ae4424dafe | ||
|
|
50036e086d | ||
|
|
6d53d92346 | ||
|
|
e0696c453a | ||
|
|
8b9a452f0c | ||
|
|
8bc7858694 | ||
|
|
0065aeef47 | ||
|
|
dfc350a783 | ||
|
|
21a78c7639 | ||
|
|
d6d621af36 | ||
|
|
e6ea2991e1 | ||
|
|
00f69baace | ||
|
|
e5299fff1c | ||
|
|
d5e96a8232 | ||
|
|
aff385f37f | ||
|
|
e40fc33a55 | ||
|
|
71b4aed05d | ||
|
|
50a94e8175 | ||
|
|
2cbba5cf1f | ||
|
|
00f2a4cf33 | ||
|
|
ec7891c097 | ||
|
|
9c0a8e39ec | ||
|
|
4a4325baa3 | ||
|
|
cae5cfd3f0 | ||
|
|
fa7c3d0a51 | ||
|
|
874c0a54c4 | ||
|
|
6a2abd962f | ||
|
|
aa995e3321 | ||
|
|
0a74ba341f | ||
|
|
13de8be58d | ||
|
|
606aee68db | ||
|
|
e4578364b6 | ||
|
|
5cdaebf5e8 | ||
|
|
2848cd62bc | ||
|
|
2303fc08aa | ||
|
|
6277aaedcd | ||
|
|
f81b74458d | ||
|
|
8f61879966 | ||
|
|
5560266e19 | ||
|
|
d8cbdd7d92 | ||
|
|
7560da80a7 | ||
|
|
413cb61112 | ||
|
|
e3c6f749ad | ||
|
|
a990e559f7 | ||
|
|
a0b06b2593 | ||
|
|
354650c0a5 | ||
|
|
12e5b4c1b4 | ||
|
|
cfbdce1b90 | ||
|
|
0b29e9eee4 | ||
|
|
3f0a0e3df0 | ||
|
|
3b261b331d | ||
|
|
066ec71736 | ||
|
|
71295e0e37 | ||
|
|
ac89f94580 | ||
|
|
399984082f | ||
|
|
3375555911 | ||
|
|
794872ca0c | ||
|
|
b7f110dbdc | ||
|
|
af20325cc4 | ||
|
|
7a5c9d0324 | ||
|
|
a2533aa9c4 | ||
|
|
4d650bad7f | ||
|
|
ff5b71b825 | ||
|
|
2b5cf29bb9 | ||
|
|
513c03a764 | ||
|
|
5a982ab9ff | ||
|
|
4ea451362f | ||
|
|
44be4e57f0 | ||
|
|
dc0871a093 | ||
|
|
c6b44db18a | ||
|
|
a4def1379c | ||
|
|
028ab7c1f9 | ||
|
|
cc03a59725 | ||
|
|
092964a10b | ||
|
|
d0277de958 | ||
|
|
2df84e20af | ||
|
|
9de4633c13 | ||
|
|
50f955c242 | ||
|
|
f2f539b492 | ||
|
|
2b439298fb | ||
|
|
2ef759a9d8 | ||
|
|
6fe4db8431 | ||
|
|
b2525e29e1 | ||
|
|
7ef5223fca | ||
|
|
323bfc9d66 | ||
|
|
d6be23fa6b | ||
|
|
c7c2998e33 | ||
|
|
184ed470d7 | ||
|
|
75352a9f77 | ||
|
|
e3c601f2fd | ||
|
|
0ab9e2a36a | ||
|
|
7b20665cf9 | ||
|
|
3d86ecd2ee | ||
|
|
403b79d370 | ||
|
|
740ecbcc43 | ||
|
|
42af6eec30 | ||
|
|
c584af356b | ||
|
|
827dc098e4 | ||
|
|
bc5dd949d7 | ||
|
|
4a932dec11 | ||
|
|
d5c5e38604 | ||
|
|
02080bfb6c | ||
|
|
d3fa51e4fa | ||
|
|
6cfe5f8c58 | ||
|
|
b4f3e4eab8 | ||
|
|
b188e781ee | ||
|
|
8156179f1b | ||
|
|
55632eebaa | ||
|
|
71b11026bb | ||
|
|
2b28733fda | ||
|
|
8c115e17c4 | ||
|
|
10f62f679b | ||
|
|
fa4f7c6532 | ||
|
|
0647541988 | ||
|
|
2602ddc0b8 | ||
|
|
3886b284d3 | ||
|
|
22a9405d1e | ||
|
|
2902dccf11 | ||
|
|
644374bb29 | ||
|
|
a868307637 | ||
|
|
d213861e02 | ||
|
|
3d538d4eca | ||
|
|
06a6dd17f8 | ||
|
|
18659fd45a | ||
|
|
7253be7619 | ||
|
|
910749bab1 | ||
|
|
4f9b3146a1 | ||
|
|
b026abd0bc | ||
|
|
08658a37c4 | ||
|
|
6bbf2d02a8 | ||
|
|
538185c29e | ||
|
|
bd05715ba0 | ||
|
|
6960cd30eb | ||
|
|
c5c21dec83 | ||
|
|
73de6b6d42 | ||
|
|
f698d5f0ee | ||
|
|
7e59406436 | ||
|
|
b8a9dc9743 | ||
|
|
1b5aa16652 | ||
|
|
3f491ea785 | ||
|
|
9bdad9bc8b | ||
|
|
de711b0123 | ||
|
|
b52c462cfa | ||
|
|
f4e75dfecb | ||
|
|
c5fe10aada | ||
|
|
97623b989c | ||
|
|
ed2a776c55 | ||
|
|
ac4fcb61c6 | ||
|
|
41fa664a86 | ||
|
|
4f54cbe975 | ||
|
|
2291e9fd11 | ||
|
|
095c9c331e | ||
|
|
b8fc8b7f62 | ||
|
|
95931c8c0a | ||
|
|
dd788f5611 | ||
|
|
5d99c12089 | ||
|
|
03437fc936 | ||
|
|
56a086ef52 | ||
|
|
3f3fb4eeb4 | ||
|
|
4998e320c5 | ||
|
|
496d56e975 | ||
|
|
82df624ae9 | ||
|
|
5021a1da88 | ||
|
|
df1fc6f2d7 | ||
|
|
2ebcf26ede | ||
|
|
b1a77deadf | ||
|
|
bce1b34873 | ||
|
|
91f31c00c3 | ||
|
|
4b4ffdd14e | ||
|
|
50c83f1be7 | ||
|
|
ee86d12dc2 | ||
|
|
b388e080ad | ||
|
|
6e630018df | ||
|
|
9de5e5b802 | ||
|
|
399d3c365d | ||
|
|
3867abe4da | ||
|
|
90d2ae3868 | ||
|
|
581d1742e5 | ||
|
|
172d7607bb | ||
|
|
62a4b48679 | ||
|
|
3e07c9a960 | ||
|
|
05c197c457 | ||
|
|
77c321daa3 | ||
|
|
3d99af87d6 | ||
|
|
28c2a4a6cc | ||
|
|
1bbd62c021 | ||
|
|
ecc0b63da2 | ||
|
|
347e493542 | ||
|
|
77499790ba | ||
|
|
a960267c40 | ||
|
|
b9f3254ba7 | ||
|
|
266f18bbeb | ||
|
|
b70129f178 | ||
|
|
888f0c4207 | ||
|
|
88fa47c664 | ||
|
|
2ecc2c3602 | ||
|
|
02d8288863 | ||
|
|
d1dde5406e | ||
|
|
fd7b4bbe39 | ||
|
|
c28ea1db19 | ||
|
|
d68dacdc80 | ||
|
|
91f0094048 | ||
|
|
5660f6239d | ||
|
|
58cf5abf0b | ||
|
|
fc32d8a9db | ||
|
|
4b2f140140 | ||
|
|
67cb307f2d | ||
|
|
3811df9ab2 | ||
|
|
53d0995d0c | ||
|
|
7a692fd57d | ||
|
|
73e1c158f5 | ||
|
|
ab3b389f69 | ||
|
|
417d48f015 | ||
|
|
b6aa604cdd | ||
|
|
0dbf99cc82 | ||
|
|
7127caf6b5 | ||
|
|
638862d268 | ||
|
|
2d7dedf79c | ||
|
|
f690cd216c | ||
|
|
6a5bf66a42 | ||
|
|
5707711d84 | ||
|
|
5b3eb23aeb | ||
|
|
51987948ad | ||
|
|
e70559a68d | ||
|
|
83797ca19c | ||
|
|
d82b3e51ea | ||
|
|
e03bd37660 | ||
|
|
ee26cec88a | ||
|
|
88763034ed | ||
|
|
dad1c024aa | ||
|
|
f92d3846db | ||
|
|
ffab761274 | ||
|
|
b4c648229a | ||
|
|
1ca7acda14 | ||
|
|
8f30f88967 | ||
|
|
8eaaaa9d38 | ||
|
|
4e0ad1df1b | ||
|
|
dc3b78e678 | ||
|
|
4d7dde5366 | ||
|
|
3c0679991d | ||
|
|
fe741a92f3 | ||
|
|
f6879e24cc | ||
|
|
7e252ba941 | ||
|
|
46d5e750d7 | ||
|
|
5988249f84 | ||
|
|
7aee2600ba | ||
|
|
6f99a9c2dc | ||
|
|
eee1ce32fa | ||
|
|
d9f2f2c8f9 | ||
|
|
31d0f79a10 | ||
|
|
b290e44318 | ||
|
|
2d806de2cd | ||
|
|
c5db34b491 | ||
|
|
3d816d2525 | ||
|
|
fb394db981 | ||
|
|
da39855cec | ||
|
|
a6b79857db | ||
|
|
f1271f28b9 | ||
|
|
f62900699a | ||
|
|
cf16efe499 | ||
|
|
4260d24143 | ||
|
|
3ef1da1096 | ||
|
|
a90a39e8d8 | ||
|
|
dc5c7732d7 | ||
|
|
5bf9200880 | ||
|
|
f9b155b49f | ||
|
|
9782ac9afa | ||
|
|
773683bfd5 | ||
|
|
3dbb1759eb | ||
|
|
d7895d5c9c | ||
|
|
78499757b0 | ||
|
|
ec2e161649 | ||
|
|
18d8c439bd | ||
|
|
1ca11f1fe7 | ||
|
|
b70d0015a6 | ||
|
|
6a417f2f23 | ||
|
|
f212f0cc16 | ||
|
|
01d07b4942 | ||
|
|
039cb5db74 | ||
|
|
65bce0378e | ||
|
|
91cef6d57b | ||
|
|
f3da31b18c | ||
|
|
af1f173497 | ||
|
|
14fede3e56 | ||
|
|
d3bfbb57b6 | ||
|
|
3203ee925a | ||
|
|
fae1265587 | ||
|
|
97f3db8fdb | ||
|
|
a8b5120871 | ||
|
|
c22339c2cd | ||
|
|
b1830a36d4 | ||
|
|
05510c5001 | ||
|
|
343c465352 | ||
|
|
0cb2987de4 | ||
|
|
7d646c9494 | ||
|
|
395b21c693 | ||
|
|
6ef3ad9020 | ||
|
|
a608c4a36d | ||
|
|
e48da5bb21 | ||
|
|
f389a1f087 | ||
|
|
84521ea9b5 | ||
|
|
4ba43e2ddd | ||
|
|
3606bc05cf | ||
|
|
5e89d8ef3e | ||
|
|
028fc578b1 | ||
|
|
52e957d47f | ||
|
|
95cfcaa2fe | ||
|
|
340330b75b | ||
|
|
af8a90d651 | ||
|
|
ee44da6272 | ||
|
|
a5aba02ddd | ||
|
|
cb73ddf6bf | ||
|
|
e45fcfca41 | ||
|
|
27dae1edf0 | ||
|
|
d1e1c9ad33 | ||
|
|
d28fff67f2 | ||
|
|
62d539c424 | ||
|
|
3c1e9f3199 | ||
|
|
b196194e5f | ||
|
|
5ee78e28ad | ||
|
|
bcfd3d4a5b | ||
|
|
f86f184783 | ||
|
|
60f459687c | ||
|
|
455c384164 | ||
|
|
1fef35f77c | ||
|
|
8bc389987c | ||
|
|
ee56ebc205 | ||
|
|
9198383742 | ||
|
|
b010ad04bf | ||
|
|
4458e03cd2 | ||
|
|
4a37369750 | ||
|
|
7af75c0786 | ||
|
|
0fbe225b05 | ||
|
|
2405c002e4 | ||
|
|
1cc9e3c9c8 | ||
|
|
a64c9695cc | ||
|
|
d9be0b3a64 | ||
|
|
8b4682ac8b | ||
|
|
a975da2159 | ||
|
|
e483ddb487 | ||
|
|
267c8e0103 | ||
|
|
25f0d8ca2e | ||
|
|
be0edc00cc | ||
|
|
dc393946ce | ||
|
|
80a522ce08 | ||
|
|
b3ad9e5693 | ||
|
|
cc8c917de1 | ||
|
|
2a3fcbacd0 | ||
|
|
5c9cf276df | ||
|
|
76203b392a | ||
|
|
18913770fe | ||
|
|
2f23baf745 | ||
|
|
a7ce8c2ab4 | ||
|
|
d7ac84cf99 | ||
|
|
04b739b0bd | ||
|
|
131c0b1d4b | ||
|
|
f42c35d8ab | ||
|
|
0187d62246 | ||
|
|
01201708e3 | ||
|
|
986a28c891 | ||
|
|
0bbcd7ec43 | ||
|
|
f9dacaa0ff | ||
|
|
8f6a75806f | ||
|
|
05cb07c0ec | ||
|
|
d6ace7cc73 | ||
|
|
9ef6d2d038 | ||
|
|
c1e6f0c53b | ||
|
|
0e82c108bc | ||
|
|
9427b6a655 | ||
|
|
6a09e2c797 | ||
|
|
3b0b38360c | ||
|
|
3b3fe18f9d | ||
|
|
dedab8c2a2 | ||
|
|
3e0b816351 | ||
|
|
3f8fae2f16 | ||
|
|
70bcebc451 | ||
|
|
6a384bf48b | ||
|
|
10add98d90 | ||
|
|
a2257731ca | ||
|
|
6be990f1bb | ||
|
|
370920e931 | ||
|
|
ee441e172d | ||
|
|
5e90bde8b9 | ||
|
|
0b2f53e3b4 | ||
|
|
1fd55c484a | ||
|
|
1d13c5ea9e | ||
|
|
26303f5168 | ||
|
|
19c1f49fd3 | ||
|
|
5b8b1eec57 | ||
|
|
d83c333b2d | ||
|
|
4598585d4a | ||
|
|
c2959cf41e | ||
|
|
a640460baf | ||
|
|
5d6180a395 | ||
|
|
28c0cee4e3 | ||
|
|
27bba2c47c | ||
|
|
4753e35d7f | ||
|
|
28f67ff608 | ||
|
|
e1a033b97d | ||
|
|
2b7d2b4005 | ||
|
|
39de797b10 | ||
|
|
de9b1cdd2d | ||
|
|
f0c57da4ab | ||
|
|
b5218f7149 | ||
|
|
7cb311b5bc | ||
|
|
254c922254 | ||
|
|
4fb26b1119 | ||
|
|
ad262459b7 | ||
|
|
71b89d06d7 | ||
|
|
72b3058774 | ||
|
|
57c8d0cf1b | ||
|
|
f4c9a57bb5 | ||
|
|
9879e8b685 | ||
|
|
beecff2acf | ||
|
|
6f2face898 | ||
|
|
ddc8282dd7 | ||
|
|
c244042e55 | ||
|
|
78b7b34799 | ||
|
|
e397012394 | ||
|
|
5cc73ab97c | ||
|
|
be1b7cdf45 | ||
|
|
41f3fe15a6 | ||
|
|
df3a55d6a0 | ||
|
|
4e83520b0e | ||
|
|
94cd526772 | ||
|
|
4782cee201 | ||
|
|
907401f6f2 | ||
|
|
9a831217e4 | ||
|
|
1aab75d86a | ||
|
|
147cb713ed | ||
|
|
12b6146551 | ||
|
|
29031be4e9 | ||
|
|
b2db59f3bc | ||
|
|
cf129d1f9c | ||
|
|
41b96e8a01 | ||
|
|
805ddf6c92 | ||
|
|
547a9cd632 | ||
|
|
2ec226640e | ||
|
|
a0e4e813dd | ||
|
|
8812ae7052 | ||
|
|
28bf2d6c3c | ||
|
|
dadf0e2d16 | ||
|
|
c4a79766b7 | ||
|
|
385eab2016 | ||
|
|
bc33d8bc8a | ||
|
|
061fa5fc72 | ||
|
|
ac0acfe7c1 | ||
|
|
f3f313bb98 | ||
|
|
3ef40031dd | ||
|
|
44b60956a8 | ||
|
|
e4535aa856 | ||
|
|
343400c5fe | ||
|
|
bfeeade43b | ||
|
|
b425edffce | ||
|
|
f041d009b5 | ||
|
|
26d06bd13b | ||
|
|
9d51470ee2 | ||
|
|
49a003088b | ||
|
|
c099d887af | ||
|
|
08990556e2 | ||
|
|
cd5b076751 | ||
|
|
081f8e8412 | ||
|
|
465d8cbc82 | ||
|
|
323c77b702 | ||
|
|
780077e729 | ||
|
|
324bcb2533 | ||
|
|
e29a721571 | ||
|
|
389fc96794 | ||
|
|
da260fabf9 | ||
|
|
79bec6877c | ||
|
|
37b97d9e4c | ||
|
|
2e81e99224 | ||
|
|
bea18c2fa9 | ||
|
|
0233fdbf35 | ||
|
|
23ca94ea42 | ||
|
|
a8545e3369 | ||
|
|
1f2973d93f | ||
|
|
e00737ef78 | ||
|
|
a90294fe08 | ||
|
|
77215aeb87 | ||
|
|
7dfb1f131e | ||
|
|
7fecac2973 | ||
|
|
bb939ccdff | ||
|
|
8e38b34c55 | ||
|
|
ff8669e735 | ||
|
|
6a4c8f738e | ||
|
|
03cab6d1e4 | ||
|
|
96779c2620 | ||
|
|
e9a71ec3f7 | ||
|
|
b3da4c50fc | ||
|
|
eb9ae5e4dd | ||
|
|
9591093379 | ||
|
|
68d8c19b53 | ||
|
|
dc2ced8e09 | ||
|
|
02a8c3d78d | ||
|
|
a4ef38fbee | ||
|
|
5608e9457d | ||
|
|
34f0c5a462 | ||
|
|
5675f89d37 | ||
|
|
6d6f4e6dd9 | ||
|
|
f06a42987a | ||
|
|
76ab0fe07a | ||
|
|
734958b89d | ||
|
|
397568f1c8 | ||
|
|
a2c3919c0f | ||
|
|
e08576b008 | ||
|
|
83238aad7e | ||
|
|
1863297b5a | ||
|
|
9cd9440515 | ||
|
|
ec64c1585c | ||
|
|
429c4f1573 | ||
|
|
28ae8fca42 | ||
|
|
c076f0a770 | ||
|
|
219c61081d | ||
|
|
ad32129a13 | ||
|
|
1db039d6b4 | ||
|
|
f023304823 | ||
|
|
85603eb53d | ||
|
|
1f231c2b2a | ||
|
|
967388395f | ||
|
|
94cffd2c48 | ||
|
|
89c5b67a13 | ||
|
|
3436cd68ac | ||
|
|
d16ad7eedc | ||
|
|
e635e3e720 | ||
|
|
42b7cf9f94 | ||
|
|
7d9211a3ba | ||
|
|
1895e161d2 | ||
|
|
7804787201 | ||
|
|
3576450982 | ||
|
|
bb987cfe9e | ||
|
|
997310f9a2 | ||
|
|
bf23f53770 | ||
|
|
e8f9032339 | ||
|
|
80e4018b20 | ||
|
|
27b7d831d0 | ||
|
|
f0ae1aa835 | ||
|
|
88f7c6070a | ||
|
|
a3f85a3872 | ||
|
|
7467b2fcf4 | ||
|
|
3e387d74c2 | ||
|
|
f961bcfe86 | ||
|
|
ce05139452 | ||
|
|
a74eb58000 | ||
|
|
5cafd18b79 | ||
|
|
7334d0e54b | ||
|
|
fffe427497 | ||
|
|
168647ace9 | ||
|
|
0e14e05ae5 | ||
|
|
3ab7a7d531 | ||
|
|
fcef1ead3a | ||
|
|
784b391467 | ||
|
|
6d18ba4c39 |
@@ -0,0 +1,26 @@
|
||||
# Security Policy
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
If you discover a security vulnerability in Infix, please use GitHub's built-in
|
||||
[Report a Vulnerability](https://github.com/kernelkit/infix/security/advisories/new)
|
||||
feature for a private and secure disclosure.
|
||||
|
||||
When reporting, include:
|
||||
|
||||
- A clear description of the vulnerability.
|
||||
- Steps to reproduce the issue.
|
||||
- Potential impact of the vulnerability.
|
||||
|
||||
## Supported Versions
|
||||
|
||||
We provide security updates only for the main branch.
|
||||
|
||||
Individual support contracts are provided by _Wires_. See
|
||||
[Support](https://github.com/kernelkit/infix/blob/main/.github/SUPPORT.md)
|
||||
for more information.
|
||||
|
||||
## Acknowledgments
|
||||
|
||||
We appreciate the efforts of the security community to help improve the security
|
||||
of Infix. Thank you for your responsible disclosure.
|
||||
@@ -6,7 +6,7 @@ project on GitHub, and Discord, see <https://github.com/kernelkit>:
|
||||
|
||||
Support contracts, development of new features, fast-tracking of reviews
|
||||
and contributions, customer branding of Infix, and even customer specific
|
||||
features for dedicated products is provided by Addiva Elektronik.
|
||||
features for dedicated products is provided by _Wires_.
|
||||
|
||||
:globe_with_meridians: <https://www.addiva.se/electronics/>
|
||||
:e-mail: <mailto:ael@addiva.se>
|
||||
:globe_with_meridians: <https://www.wires.se>
|
||||
:e-mail: <mailto:infix@wires.se>
|
||||
|
||||
@@ -0,0 +1,143 @@
|
||||
name: Build Bootloaders
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
branch:
|
||||
description: 'Branch to build from'
|
||||
default: 'main'
|
||||
type: string
|
||||
|
||||
jobs:
|
||||
build:
|
||||
name: Build ${{ matrix.defconfig }}
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
defconfig:
|
||||
- fireant_boot
|
||||
- cn9130_crb_boot
|
||||
- aarch64_qemu_boot
|
||||
- rpi4_boot
|
||||
env:
|
||||
MAKEFLAGS: -j5
|
||||
steps:
|
||||
- name: Cleanup Build Folder
|
||||
run: |
|
||||
ls -la ./
|
||||
rm -rf ./* || true
|
||||
rm -rf ./.??* || true
|
||||
ls -la ./
|
||||
|
||||
- name: Checkout infix repo
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.branch || github.ref }}
|
||||
clean: true
|
||||
fetch-depth: 0
|
||||
submodules: recursive
|
||||
|
||||
- name: Set Build Variables
|
||||
id: vars
|
||||
run: |
|
||||
defconfig=${{ matrix.defconfig }}
|
||||
version=$(awk -F'"' '/BR2_TARGET_UBOOT_CUSTOM_VERSION_VALUE=/ {print $2}' configs/${defconfig}_defconfig)
|
||||
version=${version:-git}
|
||||
filename=$(echo "${defconfig}" | tr '_' '-')
|
||||
|
||||
# TODO: Replace hardcoded rev with actual revision stepping
|
||||
rev="latest"
|
||||
|
||||
archive="${filename}-${version}-${rev}.tar.gz"
|
||||
dirname="${filename}-${version}-${rev}"
|
||||
|
||||
echo "defconfig=${defconfig}" >> $GITHUB_OUTPUT
|
||||
echo "version=${version}" >> $GITHUB_OUTPUT
|
||||
echo "rev=${rev}" >> $GITHUB_OUTPUT
|
||||
echo "archive=${archive}" >> $GITHUB_OUTPUT
|
||||
echo "dirname=${dirname}" >> $GITHUB_OUTPUT
|
||||
|
||||
echo "Building ${defconfig}_defconfig, version ${version}-${rev}, artifact ${archive} ..."
|
||||
|
||||
- name: Restore Cache of dl/
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
path: dl/
|
||||
key: dl-boot-${{ hashFiles('.git/modules/buildroot/HEAD', 'configs/*', 'package/*/*.hash') }}
|
||||
restore-keys: |
|
||||
dl-boot-
|
||||
dl-
|
||||
|
||||
- name: Restore Cache of .ccache/
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
path: .ccache/
|
||||
key: ccache-boot-${{ matrix.defconfig }}-${{ hashFiles('.git/modules/buildroot/HEAD', 'package/*/*.hash') }}
|
||||
restore-keys: |
|
||||
ccache-boot-${{ matrix.defconfig }}-
|
||||
ccache-boot-
|
||||
ccache-
|
||||
|
||||
- name: Configure ${{ matrix.defconfig }}_defconfig
|
||||
run: |
|
||||
make ${{ matrix.defconfig }}_defconfig
|
||||
|
||||
- name: Build ${{ matrix.defconfig }}_defconfig
|
||||
run: |
|
||||
echo "Building ${{ matrix.defconfig }}_defconfig ..."
|
||||
make -j$((`getconf _NPROCESSORS_ONLN` / 2 + 2))
|
||||
|
||||
- name: Resulting size of build
|
||||
run: |
|
||||
printf "Size of output/images/: "
|
||||
ls -l output/images/
|
||||
|
||||
- name: Prepare ${{ matrix.defconfig }} Artifact
|
||||
run: |
|
||||
cd output/
|
||||
mv images ${{ steps.vars.outputs.dirname }}
|
||||
tar cfz ${{ steps.vars.outputs.archive }} ${{ steps.vars.outputs.dirname }}/
|
||||
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
path: output/${{ steps.vars.outputs.archive }}
|
||||
name: artifact-${{ matrix.defconfig }}
|
||||
|
||||
publish:
|
||||
name: Upload Bootloader Artifacts
|
||||
runs-on: ubuntu-latest
|
||||
needs: build
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- uses: actions/download-artifact@v4
|
||||
with:
|
||||
pattern: "artifact-*"
|
||||
merge-multiple: true
|
||||
|
||||
- name: Create checksums ...
|
||||
run: |
|
||||
for file in *.tar.gz; do
|
||||
sha256sum $file > $file.sha256
|
||||
done
|
||||
|
||||
- uses: ncipollo/release-action@v1
|
||||
with:
|
||||
allowUpdates: true
|
||||
omitName: true
|
||||
omitBody: true
|
||||
omitBodyDuringUpdate: true
|
||||
prerelease: true
|
||||
tag: "latest-boot"
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
artifacts: "*.tar.gz*"
|
||||
|
||||
- name: Summary
|
||||
run: |
|
||||
cat <<EOF >> $GITHUB_STEP_SUMMARY
|
||||
# Bootloader Build Complete! :rocket:
|
||||
|
||||
For the public download links of these bootloader artifacts, please see:
|
||||
<https://github.com/kernelkit/infix/releases/tag/latest-boot>
|
||||
EOF
|
||||
@@ -1,27 +1,57 @@
|
||||
name: Bob the Builder
|
||||
name: Build
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, synchronize, reopened, labeled]
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
minimal:
|
||||
description: 'Build minimal defconfigs'
|
||||
required: false
|
||||
target:
|
||||
description: "Build target (e.g. aarch64 or aarch64_minimal)"
|
||||
default: "x86_64"
|
||||
type: string
|
||||
parallel:
|
||||
description: 'Massive parallel build of each image'
|
||||
default: true
|
||||
type: boolean
|
||||
name:
|
||||
description: "Name (for spin overrides)"
|
||||
default: "infix"
|
||||
type: string
|
||||
infix_repo:
|
||||
description: 'Repo to checkout (for spin overrides)'
|
||||
default: kernelkit/infix
|
||||
type: string
|
||||
|
||||
workflow_call:
|
||||
inputs:
|
||||
target:
|
||||
required: true
|
||||
type: string
|
||||
name:
|
||||
required: true
|
||||
type: string
|
||||
infix_repo:
|
||||
required: false
|
||||
type: string
|
||||
default: kernelkit/infix
|
||||
parallel:
|
||||
required: false
|
||||
type: boolean
|
||||
default: false
|
||||
|
||||
env:
|
||||
NAME: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.name || inputs.name }}
|
||||
TARGET: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.target || inputs.target }}
|
||||
INFIX_REPO: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.infix_repo || inputs.infix_repo }}
|
||||
|
||||
jobs:
|
||||
build:
|
||||
name: Build Infix ${{ matrix.target }}
|
||||
name: Build ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.name || inputs.name }} ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.target || inputs.target }}
|
||||
runs-on: [ self-hosted, latest ]
|
||||
env:
|
||||
PARALLEL: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.parallel == 'true' || github.event_name != 'workflow_dispatch' && inputs.parallel == true }}
|
||||
strategy:
|
||||
matrix:
|
||||
target: [aarch64, x86_64]
|
||||
fail-fast: false
|
||||
outputs:
|
||||
build_id: ${{ steps.vars.outputs.INFIX_BUILD_ID }}
|
||||
steps:
|
||||
- name: Cleanup Build Folder
|
||||
run: |
|
||||
@@ -30,34 +60,35 @@ jobs:
|
||||
rm -rf ./.??* || true
|
||||
ls -la ./
|
||||
|
||||
- uses: actions/checkout@v4
|
||||
- name: Checkout infix repo
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
repository: ${{ env.INFIX_REPO }}
|
||||
ref: ${{ github.ref }}
|
||||
clean: true
|
||||
fetch-depth: 0
|
||||
submodules: recursive
|
||||
|
||||
- name: Set Build Variables
|
||||
id: vars
|
||||
run: |
|
||||
if [ "${{ github.event_name }}" == "workflow_dispatch" ]; then
|
||||
if [ "${{ github.event.inputs.minimal }}" == "true" ]; then
|
||||
flavor="_minimal"
|
||||
fi
|
||||
else
|
||||
# Ensure 'release' job get the proper image when building main
|
||||
if [ "$GITHUB_REF_NAME" != "main" ]; then
|
||||
flavor="_minimal"
|
||||
else
|
||||
flavor=""
|
||||
fi
|
||||
if ${{ contains(github.event.pull_request.labels.*.name, 'ci:main') }}; then
|
||||
flavor=""
|
||||
fi
|
||||
if [ -n "${{ github.event.pull_request.head.sha }}" ]; then
|
||||
# Since PRs are built from an internally generated merge
|
||||
# commit, reverse lookups of PRs and/or commits from
|
||||
# image version information are cumbersome. Therefore:
|
||||
# explicitly set a build id that references both the PR
|
||||
# and the commit.
|
||||
printf "INFIX_BUILD_ID=pr%d.%.7s\n" \
|
||||
"${{ github.event.number }}" "${{ github.event.pull_request.head.sha }}" \
|
||||
| tee -a $GITHUB_OUTPUT $GITHUB_ENV
|
||||
fi
|
||||
target=${{ matrix.target }}
|
||||
echo "dir=infix-$target" >> $GITHUB_OUTPUT
|
||||
echo "tgz=infix-$target.tar.gz" >> $GITHUB_OUTPUT
|
||||
echo "flv=$flavor" >> $GITHUB_OUTPUT
|
||||
echo "Building target ${target}${flavor}_defconfig"
|
||||
|
||||
target=${{ env.TARGET }}
|
||||
name=${{ env.NAME }}
|
||||
echo "dir=${name}-${target}" >> $GITHUB_OUTPUT
|
||||
echo "tgz=${name}-${target}.tar.gz" >> $GITHUB_OUTPUT
|
||||
echo "Building target ${target}_defconfig"
|
||||
|
||||
- name: Restore Cache of dl/
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
@@ -70,23 +101,37 @@ jobs:
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
path: .ccache/
|
||||
key: ccache-${{ matrix.target }}-${{ hashFiles('.git/modules/buildroot/HEAD', 'package/*/*.hash') }}
|
||||
key: ccache-${{ env.TARGET }}-${{ hashFiles('.git/modules/buildroot/HEAD', 'package/*/*.hash') }}
|
||||
restore-keys: |
|
||||
ccache-${{ matrix.target }}-
|
||||
ccache-${{ env.TARGET }}-
|
||||
ccache-
|
||||
|
||||
- name: Configure ${{ matrix.target }}${{ steps.vars.outputs.flv }}
|
||||
- name: Configure ${{ env.TARGET }}
|
||||
run: |
|
||||
make ${{ matrix.target }}${{ steps.vars.outputs.flv }}_defconfig
|
||||
make ${{ env.TARGET }}_defconfig
|
||||
|
||||
- name: Unit Test ${{ matrix.target }}
|
||||
- name: Unit Test ${{ env.TARGET }}
|
||||
run: |
|
||||
make test-unit
|
||||
|
||||
- name: Build ${{ matrix.target }}${{ steps.vars.outputs.flv }}
|
||||
- name: Prepare parallel build
|
||||
id: parallel
|
||||
run: |
|
||||
echo "Building ${{ matrix.target }}${{ steps.vars.outputs.flv }}_defconfig ..."
|
||||
make
|
||||
|
||||
if [ "$PARALLEL" == "true" ]; then
|
||||
echo "BR2_PER_PACKAGE_DIRECTORIES=y" >> output/.config
|
||||
MAKE="make -j$((`getconf _NPROCESSORS_ONLN` / 2 + 2))"
|
||||
echo "Building in parallel with -j$((`getconf _NPROCESSORS_ONLN` / 2 + 2))"
|
||||
else
|
||||
echo "Disabling parallel build"
|
||||
MAKE="make"
|
||||
fi
|
||||
echo "MAKE=$MAKE" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: Build ${{ env.TARGET }}
|
||||
run: |
|
||||
echo "Building ${{ env.TARGET }}_defconfig ..."
|
||||
eval "${{ steps.parallel.outputs.MAKE }}"
|
||||
|
||||
- name: Check SBOM from Build
|
||||
run: |
|
||||
@@ -107,100 +152,14 @@ jobs:
|
||||
printf "Size of output/images/: "
|
||||
ls -l output/images/
|
||||
|
||||
- name: Prepare ${{ matrix.target }} Artifact
|
||||
- name: Prepare ${{ env.TARGET }} Artifact
|
||||
run: |
|
||||
cd output/
|
||||
mv images ${{ steps.vars.outputs.dir }}
|
||||
ln -s ${{ steps.vars.outputs.dir }} images
|
||||
tar chfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||
tar cfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
path: output/${{ steps.vars.outputs.tgz }}
|
||||
name: artifact-${{ matrix.target }}
|
||||
|
||||
test:
|
||||
name: Regression Test of Infix x86_64
|
||||
needs: build
|
||||
runs-on: [ self-hosted, regression ]
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
clean: true
|
||||
submodules: recursive
|
||||
|
||||
- name: Set Build Variables
|
||||
id: vars
|
||||
run: |
|
||||
if [ "$GITHUB_REF_NAME" != "main" ]; then
|
||||
flavor="_minimal"
|
||||
else
|
||||
flavor=""
|
||||
fi
|
||||
echo "flv=$flavor" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: Configure x86_64${{ steps.vars.outputs.flv }}
|
||||
run: |
|
||||
make x86_64${{ steps.vars.outputs.flv }}_defconfig
|
||||
|
||||
- uses: actions/download-artifact@v4
|
||||
with:
|
||||
pattern: "artifact-*"
|
||||
merge-multiple: true
|
||||
|
||||
- name: Restore x86-64${{ steps.vars.outputs.flv }} output/
|
||||
run: |
|
||||
ls -l
|
||||
mkdir -p output
|
||||
mv infix-x86_64.tar.gz output/
|
||||
cd output/
|
||||
tar xf infix-x86_64.tar.gz
|
||||
ln -s infix-x86_64 images
|
||||
|
||||
- name: Regression Test x86_64${{ steps.vars.outputs.flv }}
|
||||
run: |
|
||||
make test
|
||||
|
||||
- name: Publish Test Result for x86_64${{ steps.vars.outputs.flv }}
|
||||
# Ensure this runs even if Regression Test fails
|
||||
if: always()
|
||||
run: cat test/.log/last/result-gh.md >> $GITHUB_STEP_SUMMARY
|
||||
|
||||
release:
|
||||
if: ${{github.repository_owner == 'kernelkit' && github.ref_name == 'main'}}
|
||||
name: Upload Latest Build
|
||||
needs: test
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- uses: actions/download-artifact@v4
|
||||
with:
|
||||
pattern: "artifact-*"
|
||||
merge-multiple: true
|
||||
|
||||
- name: Create checksums ...
|
||||
run: |
|
||||
for file in *.tar.gz; do
|
||||
sha256sum $file > $file.sha256
|
||||
done
|
||||
|
||||
- uses: ncipollo/release-action@v1
|
||||
with:
|
||||
allowUpdates: true
|
||||
omitName: true
|
||||
omitBody: true
|
||||
omitBodyDuringUpdate: true
|
||||
prerelease: true
|
||||
tag: "latest"
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
artifacts: "*.tar.gz*"
|
||||
|
||||
- name: Summary
|
||||
run: |
|
||||
cat <<EOF >> $GITHUB_STEP_SUMMARY
|
||||
# Latest Build Complete! :rocket:
|
||||
|
||||
For the public download links of these build artifacts, please see:
|
||||
<https://github.com/kernelkit/infix/releases/tag/latest>
|
||||
EOF
|
||||
name: artifact-${{ env.TARGET }}
|
||||
|
||||
@@ -55,7 +55,7 @@ jobs:
|
||||
sudo apt-get -y update
|
||||
sudo apt-get -y install pkg-config libjansson-dev libev-dev \
|
||||
libcrypt-dev libglib2.0-dev libpcre2-dev \
|
||||
libuev-dev libite-dev
|
||||
libuev-dev
|
||||
|
||||
- name: Build dependencies
|
||||
run: |
|
||||
@@ -65,6 +65,8 @@ jobs:
|
||||
git clone https://github.com/sysrepo/sysrepo.git
|
||||
mkdir sysrepo/build
|
||||
(cd sysrepo/build && cmake .. && make all && sudo make install)
|
||||
git clone https://github.com/troglobit/libite.git
|
||||
(cd libite && ./autogen.sh && ./configure && make && sudo make install)
|
||||
make dep
|
||||
|
||||
- name: Check applications
|
||||
|
||||
@@ -0,0 +1,67 @@
|
||||
name: User Guide Generator
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- doc
|
||||
- main
|
||||
tags:
|
||||
- 'v*'
|
||||
paths:
|
||||
- 'doc/**'
|
||||
- 'mkdocs.yml'
|
||||
- '.github/workflows/docs.yml'
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
|
||||
concurrency:
|
||||
group: "docs-${{ github.ref }}"
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
docs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Setup Python
|
||||
uses: actions/setup-python@v4
|
||||
with:
|
||||
python-version: '3.x'
|
||||
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
pipx install mkdocs
|
||||
pipx inject mkdocs mkdocs-material
|
||||
pipx inject mkdocs pymdown-extensions
|
||||
pipx inject mkdocs mkdocs-callouts
|
||||
pipx inject mkdocs mike
|
||||
pipx inject mkdocs mkdocs-to-pdf
|
||||
# Workaround, if pipx inject fails to install symlink
|
||||
ln -s "$(pipx environment -V PIPX_LOCAL_VENVS)/mkdocs/bin/mike" \
|
||||
"$(pipx environment -V PIPX_BIN_DIR)/mike" || true
|
||||
|
||||
- name: Configure Git
|
||||
run: |
|
||||
git config --global user.name "github-actions[bot]"
|
||||
git config --global user.email "github-actions[bot]@users.noreply.github.com"
|
||||
|
||||
- name: Deploy dev version
|
||||
if: github.event_name == 'push' && (github.ref == 'refs/heads/doc' || github.ref == 'refs/heads/main')
|
||||
run: |
|
||||
mike deploy --push --update-aliases dev latest
|
||||
mike set-default --push latest
|
||||
|
||||
- name: Deploy tagged version
|
||||
if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')
|
||||
run: |
|
||||
TAG=${GITHUB_REF#refs/tags/v}
|
||||
# Extract YEAR.MONTH from tag (e.g., v25.06.0-beta1 -> 25.06)
|
||||
VERSION=$(echo $TAG | sed -E 's/^([0-9]+\.[0-9]+)(\.[0-9]+)?(-.*)?$/\1/')
|
||||
echo "Deploying tag $TAG as docs version $VERSION"
|
||||
mike deploy --push --update-aliases $VERSION latest
|
||||
mike set-default --push latest
|
||||
@@ -0,0 +1,73 @@
|
||||
name: Generic X86 GitHub Build
|
||||
|
||||
on:
|
||||
push:
|
||||
|
||||
jobs:
|
||||
build:
|
||||
if: github.repository != 'kernelkit/infix'
|
||||
name: Infix x86_64
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- name: Install build dependencies
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y \
|
||||
bc binutils build-essential bzip2 cpio \
|
||||
diffutils file findutils git gzip \
|
||||
libncurses-dev libssl-dev perl patch \
|
||||
python3 rsync sed tar unzip wget \
|
||||
autopoint bison flex autoconf automake \
|
||||
mtools
|
||||
|
||||
- name: Checkout infix repo
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
repository: ${{ github.repository }}
|
||||
ref: ${{ github.ref }}
|
||||
fetch-depth: 0
|
||||
submodules: recursive
|
||||
|
||||
- name: Set Build Variables
|
||||
id: vars
|
||||
run: |
|
||||
echo "INFIX_BUILD_ID=${{ github.run_id }}" >> $GITHUB_OUTPUT
|
||||
echo "dir=Infix-x86_64" >> $GITHUB_OUTPUT
|
||||
echo "tgz=Infix-x86_64.tar.gz" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: Configure x86_64_minimal
|
||||
run: |
|
||||
make x86_64_minimal_defconfig
|
||||
|
||||
- name: Unit Test x86_64
|
||||
run: |
|
||||
make test-unit
|
||||
|
||||
- name: Build x86_64_minimal
|
||||
run: |
|
||||
make
|
||||
|
||||
- name: Check SBOM
|
||||
run: |
|
||||
make legal-info
|
||||
|
||||
- name: Report Build Size
|
||||
run: |
|
||||
du -sh .
|
||||
du -sh output
|
||||
du -sh dl || true
|
||||
ls -l output/images/
|
||||
|
||||
- name: Prepare Artifact
|
||||
run: |
|
||||
cd output/
|
||||
mv images Infix-x86_64
|
||||
ln -s Infix-x86_64 images
|
||||
tar cfz Infix-x86_64.tar.gz Infix-x86_64
|
||||
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
path: output/Infix-x86_64.tar.gz
|
||||
name: artifact-x86_64
|
||||
|
||||
@@ -0,0 +1,44 @@
|
||||
name: Publish latest Infix
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
workflow_call:
|
||||
|
||||
jobs:
|
||||
publish:
|
||||
name: Upload Latest Build
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- uses: actions/download-artifact@v4
|
||||
with:
|
||||
pattern: "artifact-*"
|
||||
merge-multiple: true
|
||||
|
||||
- name: Create checksums ...
|
||||
run: |
|
||||
for file in *.tar.gz; do
|
||||
sha256sum $file > $file.sha256
|
||||
done
|
||||
|
||||
- uses: ncipollo/release-action@v1
|
||||
with:
|
||||
allowUpdates: true
|
||||
replacesArtifacts: true
|
||||
omitName: true
|
||||
omitBody: true
|
||||
omitBodyDuringUpdate: true
|
||||
prerelease: true
|
||||
tag: "latest"
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
artifacts: "*.tar.gz*"
|
||||
|
||||
- name: Summary
|
||||
run: |
|
||||
cat <<EOF >> $GITHUB_STEP_SUMMARY
|
||||
# Latest Build Complete! :rocket:
|
||||
|
||||
For the public download links of these build artifacts, please see:
|
||||
<https://github.com/kernelkit/infix/releases/tag/latest>
|
||||
EOF
|
||||
@@ -85,16 +85,21 @@ jobs:
|
||||
cd output/
|
||||
mv images ${{ steps.vars.outputs.dir }}
|
||||
ln -s ${{ steps.vars.outputs.dir }} images
|
||||
tar chfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||
tar cfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||
|
||||
mv legal-info legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}
|
||||
tar chfz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}.tar.gz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}
|
||||
tar cfz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}.tar.gz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}
|
||||
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: artifact-${{ matrix.target }}
|
||||
path: output/*.tar.gz
|
||||
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: artifact-disk-image-${{ matrix.target }}
|
||||
path: output/images/*.qcow2
|
||||
|
||||
release:
|
||||
name: Release Infix ${{ github.ref_name }}
|
||||
needs: build
|
||||
@@ -120,7 +125,7 @@ jobs:
|
||||
if echo $ver | grep -qE 'v[0-9.]+(-alpha|-beta|-rc)[0-9]*'; then
|
||||
echo "pre=true" >> $GITHUB_OUTPUT
|
||||
echo "latest=false" >> $GITHUB_OUTPUT
|
||||
elif echo $ver | grep -qE '^v[0-9.]+\.[0-9.]+(\.[0-9]+)?$'; then
|
||||
elif echo $ver | grep -qE '^v[0-9]+\.[0-9]+(\.0)?$'; then
|
||||
echo "pre=false" >> $GITHUB_OUTPUT
|
||||
echo "latest=true" >> $GITHUB_OUTPUT
|
||||
echo "cat=Releases" >> $GITHUB_OUTPUT
|
||||
@@ -141,6 +146,11 @@ jobs:
|
||||
for file in *.tar.gz; do
|
||||
sha256sum $file > $file.sha256
|
||||
done
|
||||
if ls *.qcow2 &>/dev/null; then
|
||||
for file in *.qcow2; do
|
||||
sha256sum "$file" > "$file.sha256"
|
||||
done
|
||||
fi
|
||||
|
||||
- name: Extract ChangeLog entry ...
|
||||
run: |
|
||||
@@ -155,7 +165,7 @@ jobs:
|
||||
makeLatest: ${{ steps.rel.outputs.latest }}
|
||||
discussionCategory: ${{ steps.rel.outputs.cat }}
|
||||
bodyFile: release.md
|
||||
artifacts: "*.tar.gz*"
|
||||
artifacts: "*.tar.gz*,*.qcow2*"
|
||||
|
||||
- name: Summary
|
||||
run: |
|
||||
|
||||
@@ -0,0 +1,105 @@
|
||||
name: Test Infix
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
infix_repo:
|
||||
description: 'Repo to checkout (for spin overrides)'
|
||||
required: false
|
||||
default: kernelkit/infix
|
||||
type: string
|
||||
|
||||
workflow_call:
|
||||
inputs:
|
||||
target:
|
||||
required: true
|
||||
type: string
|
||||
name:
|
||||
required: true
|
||||
type: string
|
||||
infix_repo:
|
||||
required: false
|
||||
type: string
|
||||
default: kernelkit/infix
|
||||
ninepm-conf:
|
||||
required: false
|
||||
type: string
|
||||
default: ''
|
||||
test-path:
|
||||
required: false
|
||||
type: string
|
||||
default: 'test'
|
||||
|
||||
env:
|
||||
TARGET: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.target || inputs.target }}
|
||||
INFIX_REPO: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.infix_repo || inputs.infix_repo }}
|
||||
NINEPM_CONF: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.ninepm-conf || inputs.ninepm-conf }}
|
||||
TEST_PATH: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.test-path || inputs.test-path }}
|
||||
|
||||
jobs:
|
||||
test:
|
||||
name: Regression Test ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.name || inputs.name }} ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.target || inputs.target }}
|
||||
runs-on: [self-hosted, regression]
|
||||
steps:
|
||||
- name: Checkout infix repo
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
repository: ${{ env.INFIX_REPO }}
|
||||
ref: ${{ github.ref }}
|
||||
clean: true
|
||||
fetch-depth: 0
|
||||
submodules: recursive
|
||||
|
||||
- name: Set Build Variables
|
||||
id: vars
|
||||
run: |
|
||||
if [ -n "${{ needs.build.outputs.build_id }}" ]; then
|
||||
echo "INFIX_BUILD_ID=${{ needs.build.outputs.build_id }}" \
|
||||
>>$GITHUB_ENV
|
||||
fi
|
||||
|
||||
- name: Configure ${{ env.TARGET }}
|
||||
run: |
|
||||
make ${{ env.TARGET }}_defconfig
|
||||
|
||||
- uses: actions/download-artifact@v4
|
||||
with:
|
||||
pattern: "artifact-*"
|
||||
merge-multiple: true
|
||||
|
||||
- name: Restore ${{ env.TARGET }} output/
|
||||
run: |
|
||||
target=${{ env.TARGET }}
|
||||
name=${{ inputs.name }}
|
||||
|
||||
ls -l
|
||||
mkdir -p output
|
||||
mv ${name}-${target}.tar.gz output/
|
||||
cd output/
|
||||
tar xf ${name}-${target}.tar.gz
|
||||
ln -s ${name}-${target} images
|
||||
|
||||
- name: Regression Test ${{ env.TARGET }}
|
||||
run: |
|
||||
if [ -n "$NINEPM_CONF" ]; then
|
||||
export NINEPM_PROJ_CONFIG="${GITHUB_WORKSPACE}/$NINEPM_CONF"
|
||||
echo "DEBUG: NINEPM_PROJ_CONFIG is '$NINEPM_PROJ_CONFIG'"
|
||||
fi
|
||||
make test
|
||||
|
||||
- name: Publish Test Result for ${{ env.TARGET }}
|
||||
# Ensure this runs even if Regression Test fails
|
||||
if: always()
|
||||
run: cat $TEST_PATH/.log/last/result-gh.md >> $GITHUB_STEP_SUMMARY
|
||||
|
||||
- name: Generate Test Report for ${{ env.TARGET }}
|
||||
# Ensure this runs even if Regression Test fails
|
||||
if: always()
|
||||
run: |
|
||||
make test-dir="$(pwd)/$TEST_PATH" test-report
|
||||
|
||||
- name: Upload Test Report as Artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: test-report
|
||||
path: output/images/test-report.pdf
|
||||
@@ -0,0 +1,42 @@
|
||||
name: Kernelkit Trigger
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, synchronize, reopened, labeled]
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
- ci-work
|
||||
workflow_dispatch:
|
||||
|
||||
concurrency:
|
||||
group: ci-${{ github.event.pull_request.number || github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
build-x86_64:
|
||||
if: startsWith(github.repository, 'kernelkit/')
|
||||
uses: ./.github/workflows/build.yml
|
||||
with:
|
||||
name: "infix"
|
||||
target: ${{ github.event_name == 'pull_request' && !contains(github.event.pull_request.labels.*.name, 'ci:main') && 'x86_64_minimal' || 'x86_64' }}
|
||||
|
||||
build-aarch64:
|
||||
if: startsWith(github.repository, 'kernelkit/')
|
||||
uses: ./.github/workflows/build.yml
|
||||
with:
|
||||
name: "infix"
|
||||
target: ${{ github.event_name == 'pull_request' && !contains(github.event.pull_request.labels.*.name, 'ci:main') && 'aarch64_minimal' || 'aarch64' }}
|
||||
|
||||
test-run-x86_64:
|
||||
if: startsWith(github.repository, 'kernelkit/')
|
||||
needs: build-x86_64
|
||||
uses: ./.github/workflows/test.yml
|
||||
with:
|
||||
target: ${{ github.event_name == 'pull_request' && !contains(github.event.pull_request.labels.*.name, 'ci:main') && 'x86_64_minimal' || 'x86_64' }}
|
||||
name: "infix"
|
||||
|
||||
test-publish-x86_64:
|
||||
if: ${{ github.repository_owner == 'kernelkit' && github.ref_name == 'main' }}
|
||||
needs: test-run-x86_64
|
||||
uses: ./.github/workflows/publish.yml
|
||||
@@ -65,7 +65,7 @@ config INFIX_COMPATIBLE
|
||||
|
||||
config INFIX_TAGLINE
|
||||
string "Operating system tagline"
|
||||
default "Infix -- a Network Operating System"
|
||||
default "Infix OS — Immutable.Friendly.Secure"
|
||||
help
|
||||
Mandatory. Used for identifying the OS, e.g. as PRETTY_NAME in
|
||||
/etc/os-release and description in the GNS3 appliance.
|
||||
|
||||
@@ -2,55 +2,69 @@
|
||||
|
||||
<img align="right" src="doc/logo.png" alt="Infix - Linux <3 NETCONF" width=480 border=10>
|
||||
|
||||
Infix is a free, Linux based, immutable Network Operating System (NOS)
|
||||
built on [Buildroot][1], and [sysrepo][2]. A powerful mix that ease
|
||||
porting to different platforms, simplify long-term maintenance, and
|
||||
provide made-easy management using NETCONF, RESTCONF[^2], or the
|
||||
built-in command line interface (CLI) from a console or SSH login.
|
||||
Turn any ARM or x86 device into a powerful, manageable network appliance
|
||||
in minutes. From $35 Raspberry Pi boards to enterprise switches — deploy
|
||||
routers, IoT gateways, edge devices, or custom network solutions that
|
||||
just work.
|
||||
|
||||
> Click the **▶ Example CLI Session** foldout below for an example, or
|
||||
> head on over to the [Infix Documentation](doc/README.md) for more
|
||||
> information on how to set up the system.
|
||||
## Our Values
|
||||
|
||||
Although primarily focused on switches and routers, the core values
|
||||
may be appealing for other use-cases as well:
|
||||
**🔒 Immutable**
|
||||
Your system never breaks. Read-only filesystem with atomic upgrades
|
||||
means no configuration drift, no corrupted updates, and instant rollback
|
||||
if something goes wrong. Deploy once, trust forever.
|
||||
|
||||
- Runs from a squashfs image on a read-only partition
|
||||
- Single configuration file on a separate partition
|
||||
- Built around YANG with standard IETF models
|
||||
- Linux switchdev provides open switch APIs
|
||||
- Atomic upgrades to secondary partition
|
||||
- Highly security focused
|
||||
**🤝 Friendly**
|
||||
Actually easy to use. Auto-generated CLI from standard YANG models comes
|
||||
with built-in help for every command — just hit `?` or TAB for
|
||||
context-aware assistance. Familiar NETCONF/RESTCONF APIs and
|
||||
[comprehensive documentation][4] mean you're never stuck. Whether
|
||||
you're learning networking or managing enterprise infrastructure.
|
||||
|
||||
An immutable[^1] operating system enhances security and inherently makes
|
||||
it maintenance-free. Configuration and data, e.g, containers, is stored
|
||||
on separate partitions to ensure complete separation from system files
|
||||
and allow for seamless backup, restore, and provisioning.
|
||||
**🛡️ Secure**
|
||||
Built with security as a foundation, not an afterthought. Minimal
|
||||
attack surface, separation between system and data, and container
|
||||
isolation. Sleep better knowing your infrastructure is protected.
|
||||
|
||||
In itself, Infix is perfectly suited for dedicated networking tasks, and
|
||||
with native support for Docker containers, the operating system provides
|
||||
a versatile platform that can easily be adapted to any customer need.
|
||||
Be it legacy applications, network protocols, process monitoring, or
|
||||
edge data analysis, it can run close to end equipment. Either directly
|
||||
connected on dedicated Ethernet ports or indirectly using virtual
|
||||
network cables to exist on the same LAN as other connected equipment.
|
||||
## Why Choose Infix
|
||||
|
||||
The simple design of Infix provides complete control over both system
|
||||
and data, minimal cognitive burden, and makes it incredibly easy to get
|
||||
started.
|
||||
**Hardware Flexibility**: Start with a $35 Raspberry Pi, scale to
|
||||
enterprise switching hardware. Same OS, same tools, same reliability.
|
||||
|
||||
<details><summary><b>Example CLI Session</b></summary>
|
||||
**Standards-Based**: Built around YANG models and IETF standards. Learn
|
||||
once, use everywhere - no vendor lock-in.
|
||||
|
||||
The CLI configure context is automatically generated from the loaded
|
||||
YANG models and their corresponding [sysrepo][2] plugins. The following
|
||||
is brief example of how to set the IP address of an interface:
|
||||
**Container Ready**: Run your applications alongside networking
|
||||
functions. GPIO access, dedicated Ethernet ports, custom protocols —
|
||||
your device, your rules.
|
||||
|
||||
```
|
||||
## Use Cases
|
||||
|
||||
1. **Home Labs & Hobbyists**:
|
||||
Transform a Raspberry Pi into a full-featured router with WiFi
|
||||
1. **IoT & Edge Computing**:
|
||||
Bridge devices to the cloud with reliable, updatable gateways
|
||||
1. **Small Business Networks**:
|
||||
Enterprise-grade features without the complexity or cost
|
||||
1. **Developers & Makers**:
|
||||
Test networking concepts, prototype IoT solutions, or build custom
|
||||
appliances
|
||||
1. **Network Professionals**:
|
||||
Consistent tooling from development to production deployment.
|
||||
How about a digital twin using raw Qemu or [GNS3](https://gns3.com/infix)!
|
||||
|
||||
## See It In Action
|
||||
|
||||
Configure an interface in seconds - the CLI guides you with built-in help:
|
||||
|
||||
<details><summary><b>Click Here for an example CLI Session</b></summary>
|
||||
|
||||
```bash
|
||||
admin@infix-12-34-56:/> configure
|
||||
admin@infix-12-34-56:/config/> edit interface eth0
|
||||
admin@infix-12-34-56:/config/interface/eth0/> set ipv4 <TAB>
|
||||
address autoconf bind-ni-name enabled
|
||||
forwarding mtu neighbor
|
||||
forwarding mtu neighbor
|
||||
admin@infix-12-34-56:/config/interface/eth0/> set ipv4 address 192.168.2.200 prefix-length 24
|
||||
admin@infix-12-34-56:/config/interface/eth0/> show
|
||||
type ethernet;
|
||||
@@ -59,7 +73,6 @@ ipv4 {
|
||||
prefix-length 24;
|
||||
}
|
||||
}
|
||||
ipv6
|
||||
admin@infix-12-34-56:/config/interface/eth0/> diff
|
||||
interfaces {
|
||||
interface eth0 {
|
||||
@@ -82,43 +95,65 @@ lo ethernet UP 00:00:00:00:00:00
|
||||
admin@infix-12-34-56:/> copy running-config startup-config
|
||||
```
|
||||
|
||||
[Click here][3] for more details.
|
||||
Notice how TAB completion shows available options, `show` displays
|
||||
current config, and `diff` shows exactly what changed before you
|
||||
commit your changes with the `leave` command.
|
||||
|
||||
</details>
|
||||
|
||||
Infix can run on many different types of architectures and boards, much
|
||||
thanks to Linux and Buildroot. Currently the focus is on 64-bit ARM
|
||||
devices, optionally with switching fabric supported by Linux switchdev.
|
||||
The [following boards](board/aarch64/README.md) are fully supported:
|
||||
> [Full CLI documentation →][3]
|
||||
|
||||
- Marvell CN9130 CRB
|
||||
- Marvell EspressoBIN
|
||||
- Microchip SparX-5i PCB135 (eMMC)
|
||||
- StarFive VisionFive2
|
||||
- NanoPi R2S
|
||||
## Get Started
|
||||
|
||||
An x86_64 build is also available, primarily intended for development
|
||||
and testing, but can also be used for evaluation and demo purposes. For
|
||||
more information, see: [Infix in Virtual Environments](doc/virtual.md).
|
||||
Get [pre-built images][5] for your hardware. Use the CLI, web
|
||||
interface, or standard NETCONF/RESTCONF tools, e.g., `curl`. Add
|
||||
containers for any custom functionality you need.
|
||||
|
||||
> See the [GitHub Releases](https://github.com/kernelkit/infix/releases)
|
||||
> page for our pre-built images. The *[Latest Build][]* has bleeding
|
||||
> edge images, if possible we recommend using a versioned release.
|
||||
>
|
||||
> For *customer specific builds* of Infix, see your product repository.
|
||||
### Supported Platforms
|
||||
|
||||
[^1]: An immutable operating system is one with read-only file systems,
|
||||
atomic updates, rollbacks, declarative configuration, and workload
|
||||
isolation. All to improve reliability, scalability, and security.
|
||||
For more information, see <https://ceur-ws.org/Vol-3386/paper9.pdf>
|
||||
and <https://www.zdnet.com/article/what-is-immutable-linux-heres-why-youd-run-an-immutable-linux-distro/>.
|
||||
- **Raspberry Pi 4B** - Perfect for home labs, learning, and prototyping
|
||||
- **NanoPi R2S** - Compact dual-port router in a tiny package
|
||||
- **x86_64** - Run in VMs or on mini PCs for development and testing
|
||||
- **Marvell CN9130 CRB, EspressoBIN** - High-performance ARM platforms
|
||||
- **Microchip SparX-5i, NXP i.MX8MP EVK** - Enterprise switching capabilities
|
||||
- **StarFive VisionFive2** - RISC-V architecture support
|
||||
|
||||
[^2]: Partial RESTCONF support, features like HTTP PATCH, OPTIONS, HEAD,
|
||||
and copying between datastores are still missing.
|
||||
*Why start with Raspberry Pi?* It's affordable, widely available, has
|
||||
built-in WiFi + Ethernet, and runs the exact same Infix OS you'd deploy
|
||||
in production. Perfect for learning, prototyping, or even small-scale
|
||||
deployments.
|
||||
|
||||
[1]: https://buildroot.org/
|
||||
[2]: https://www.sysrepo.org/
|
||||
[3]: doc/cli/introduction.md
|
||||
[Latest Build]: https://github.com/kernelkit/infix/releases/tag/latest
|
||||
> 📖 **[Complete documentation][4]** • 💬 **[Join our Discord][discord-url]**
|
||||
|
||||
## Technical Details
|
||||
|
||||
Built on proven open-source foundations ([Buildroot][1] + [sysrepo][2])
|
||||
for reliability you can trust:
|
||||
|
||||
- **Immutable OS**: Read-only filesystem, atomic updates, instant rollback
|
||||
- **YANG Configuration**: Industry-standard models with auto-generated tooling
|
||||
- **Hardware Acceleration**: Linux switchdev support for wire-speed packet processing
|
||||
- **Container Integration**: Docker support with flexible network and hardware access
|
||||
- **Memory Efficient**: Runs comfortably on devices with as little as 256 MB RAM
|
||||
|
||||
Perfect for everything from resource-constrained edge devices to
|
||||
high-throughput network appliances.
|
||||
|
||||
> Check the *[Latest Build][]* for bleeding-edge features.
|
||||
|
||||
---
|
||||
|
||||
<div align="center">
|
||||
<a href="https://github.com/wires-se"><img src="https://raw.githubusercontent.com/wires-se/.github/main/profile/play.svg" width=300></a>
|
||||
<br />Infix development is sponsored by <a href="https://wires.se">Wires</a>
|
||||
</div>
|
||||
|
||||
[1]: https://buildroot.org/ "Buildroot Homepage"
|
||||
[2]: https://www.sysrepo.org/ "Sysrepo Homepage"
|
||||
[3]: https://kernelkit.org/infix/latest/cli/introduction/
|
||||
[4]: https://kernelkit.org/infix/
|
||||
[5]: https://github.com/kernelkit/infix/releases
|
||||
[Latest Build]: https://github.com/kernelkit/infix/releases/tag/latest "Latest build"
|
||||
[License]: https://en.wikipedia.org/wiki/GPL_license
|
||||
[License Badge]: https://img.shields.io/badge/License-GPL%20v2-blue.svg
|
||||
[GitHub]: https://github.com/kernelkit/infix/actions/workflows/build.yml/
|
||||
|
||||
@@ -7,3 +7,48 @@ Board Specific Documentation
|
||||
- [Marvell CN9130-CRB](cn9130-crb/)
|
||||
- [Microchip SparX-5i PCB135 (eMMC)](sparx5-pcb135/)
|
||||
- [NanoPi R2S](r2s/)
|
||||
- [Raspberry Pi 4 b](#raspberry-pi-4-b)
|
||||
|
||||
# Raspberry Pi 4 b
|
||||
|
||||
## Support level
|
||||
Full support for base board but not any extension board on the
|
||||
GPIOs.
|
||||
|
||||
### Touch screen
|
||||
The [Raspberry Pi touch display v1][RPI-TOUCH] is supported, including
|
||||
touch functionality. There are multiple touchscreens on the market for
|
||||
Raspberry Pi, but only the official (first version with 800x480
|
||||
resolution) is currently supported. Infix supplies all drivers
|
||||
required to utilize the hardware, but you need to add the actual
|
||||
graphical application in a container.
|
||||
|
||||
There are some important considerations you need to know about when
|
||||
using Infix for graphical applications. The container needs access to
|
||||
/dev/dri/ to be able to access the graphics card, and it also needs
|
||||
access to /run/udev to be able to find the input devices.
|
||||
|
||||
Example of running Doom in Infix:
|
||||
|
||||
```cli
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit container doom
|
||||
admin@example:/config/container/doom/> set image docker://mattiaswal/alpine-doom:latest
|
||||
admin@example:/config/container/doom/> set privileged
|
||||
admin@example:/config/container/doom/> edit mount udev
|
||||
admin@example:/config/container/doom/mount/udev/> set type bind
|
||||
admin@example:/config/container/doom/mount/udev/> set target /run/udev/
|
||||
admin@example:/config/container/doom/mount/udev/> set source /run/udev/
|
||||
admin@example:/config/container/doom/mount/udev/> end
|
||||
admin@example:/config/container/doom/mount/xorg.conf/> set content U2VjdGlvbiAiT3V0cHV0Q2xhc3MiCiAgSWRlbnRpZmllciAidmM0IgogIE1hdGNoRHJpdmVyICJ2YzQiCiAgRHJpdmVyICJtb2Rlc2V0dGluZyIKICBPcHRpb24gIlByaW1hcnlHUFUiICJ0cnVlIgpFbmRTZWN0aW9uCg==
|
||||
admin@example:/config/container/doom/mount/xorg.conf/> set target /etc/X11/xorg.conf
|
||||
admin@example:/config/container/doom/mount/xorg.conf/> end
|
||||
admin@example:/config/container/doom/> edit volume var
|
||||
admin@example:/config/container/doom/volume/var/> set target /var
|
||||
admin@example:/config/container/doom/volume/var/> leave
|
||||
admin@example:/>
|
||||
|
||||
```
|
||||
|
||||
|
||||
[RPI-TOUCH]: https://www.raspberrypi.com/products/raspberry-pi-touch-display/
|
||||
|
||||
@@ -128,5 +128,9 @@ SD-card partition.
|
||||
> If possible, serve `infix-aarch64.pkg` over HTTP instead, as
|
||||
> libcurl's TFTP implementation is quite slow.
|
||||
|
||||
## Console Port
|
||||
|
||||
The console port runs at 115200 baud, 8N1.
|
||||
|
||||
[release]: https://github.com/kernelkit/infix/releases
|
||||
[mvebu64boot]: https://github.com/addiva-elektronik/mvebu64boot
|
||||
|
||||
@@ -34,6 +34,10 @@ CONFIG_PROFILING=y
|
||||
CONFIG_ARCH_SPARX5=y
|
||||
CONFIG_ARCH_MVEBU=y
|
||||
CONFIG_ARCH_VEXPRESS=y
|
||||
CONFIG_ARM64_ERRATUM_2441007=y
|
||||
CONFIG_ARM64_ERRATUM_1286807=y
|
||||
CONFIG_ARM64_ERRATUM_1542419=y
|
||||
CONFIG_ARM64_ERRATUM_2441009=y
|
||||
CONFIG_ARM64_VA_BITS_48=y
|
||||
CONFIG_SCHED_MC=y
|
||||
CONFIG_NR_CPUS=64
|
||||
@@ -57,6 +61,7 @@ CONFIG_MODULE_UNLOAD=y
|
||||
CONFIG_KSM=y
|
||||
CONFIG_TRANSPARENT_HUGEPAGE=y
|
||||
CONFIG_CMA=y
|
||||
CONFIG_CMA_AREAS=7
|
||||
CONFIG_NET=y
|
||||
CONFIG_PACKET=y
|
||||
CONFIG_XDP_SOCKETS=y
|
||||
@@ -165,7 +170,6 @@ CONFIG_BRIDGE_EBT_REDIRECT=m
|
||||
CONFIG_BRIDGE_EBT_SNAT=m
|
||||
CONFIG_BRIDGE_EBT_LOG=m
|
||||
CONFIG_BRIDGE_EBT_NFLOG=m
|
||||
CONFIG_BPFILTER=y
|
||||
CONFIG_BRIDGE=y
|
||||
CONFIG_BRIDGE_VLAN_FILTERING=y
|
||||
CONFIG_BRIDGE_MRP=y
|
||||
@@ -227,6 +231,7 @@ CONFIG_SCSI_SAS_ATA=y
|
||||
CONFIG_SCSI_VIRTIO=y
|
||||
CONFIG_ATA=y
|
||||
CONFIG_SATA_AHCI=y
|
||||
CONFIG_SATA_MOBILE_LPM_POLICY=0
|
||||
CONFIG_SATA_AHCI_PLATFORM=y
|
||||
CONFIG_AHCI_MVEBU=y
|
||||
CONFIG_PATA_OF_PLATFORM=y
|
||||
@@ -282,6 +287,7 @@ CONFIG_NET_DSA_MV88E6XXX_PTP=y
|
||||
CONFIG_MVNETA=m
|
||||
CONFIG_MVPP2=m
|
||||
# CONFIG_NET_VENDOR_MELLANOX is not set
|
||||
# CONFIG_NET_VENDOR_META is not set
|
||||
# CONFIG_NET_VENDOR_MICREL is not set
|
||||
CONFIG_SPARX5_SWITCH=y
|
||||
# CONFIG_NET_VENDOR_MICROSEMI is not set
|
||||
@@ -353,13 +359,14 @@ CONFIG_SERIAL_XILINX_PS_UART=y
|
||||
CONFIG_SERIAL_XILINX_PS_UART_CONSOLE=y
|
||||
CONFIG_SERIAL_MVEBU_UART=y
|
||||
CONFIG_VIRTIO_CONSOLE=y
|
||||
CONFIG_HW_RANDOM_CN10K=m
|
||||
CONFIG_I2C=y
|
||||
CONFIG_I2C_CHARDEV=y
|
||||
CONFIG_I2C_MUX=y
|
||||
CONFIG_I2C_MUX_GPIO=y
|
||||
CONFIG_I2C_MUX_PCA954x=y
|
||||
CONFIG_I2C_MUX_PINCTRL=y
|
||||
CONFIG_I2C_DESIGNWARE_PLATFORM=y
|
||||
CONFIG_I2C_DESIGNWARE_CORE=y
|
||||
CONFIG_I2C_MV64XXX=y
|
||||
CONFIG_I2C_SLAVE=y
|
||||
CONFIG_SPI=y
|
||||
@@ -394,6 +401,7 @@ CONFIG_WATCHDOG=y
|
||||
CONFIG_WATCHDOG_SYSFS=y
|
||||
CONFIG_SOFT_WATCHDOG=y
|
||||
CONFIG_GPIO_WATCHDOG=y
|
||||
CONFIG_ARM_SBSA_WATCHDOG=y
|
||||
CONFIG_ARMADA_37XX_WATCHDOG=y
|
||||
CONFIG_I6300ESB_WDT=y
|
||||
CONFIG_MFD_MAX77620=y
|
||||
@@ -495,6 +503,7 @@ CONFIG_EXTCON_USB_GPIO=y
|
||||
CONFIG_IIO=y
|
||||
CONFIG_TI_ADC081C=y
|
||||
CONFIG_PWM=y
|
||||
CONFIG_RESET_GPIO=y
|
||||
CONFIG_PHY_MVEBU_CP110_COMPHY=y
|
||||
CONFIG_PHY_MVEBU_CP110_UTMI=y
|
||||
CONFIG_PHY_SAMSUNG_USB2=y
|
||||
@@ -523,13 +532,13 @@ CONFIG_9P_FS=y
|
||||
CONFIG_NLS_CODEPAGE_437=y
|
||||
CONFIG_NLS_ISO8859_1=y
|
||||
CONFIG_SECURITY=y
|
||||
CONFIG_LSM="landlock,lockdown,yama,loadpin,safesetid,bpf"
|
||||
CONFIG_CRYPTO_CCM=m
|
||||
CONFIG_CRYPTO_ECHAINIV=y
|
||||
CONFIG_CRYPTO_ANSI_CPRNG=y
|
||||
CONFIG_CRYPTO_GHASH_ARM64_CE=y
|
||||
CONFIG_CRYPTO_SHA1_ARM64_CE=y
|
||||
CONFIG_CRYPTO_SHA2_ARM64_CE=y
|
||||
CONFIG_CRYPTO_AES_ARM64_CE_BLK=y
|
||||
CONFIG_CRYPTO_AES_ARM64_CE_CCM=y
|
||||
CONFIG_DMA_CMA=y
|
||||
CONFIG_CMA_SIZE_MBYTES=0
|
||||
@@ -541,7 +550,14 @@ CONFIG_MAGIC_SYSRQ=y
|
||||
CONFIG_DEBUG_FS=y
|
||||
CONFIG_PANIC_ON_OOPS=y
|
||||
CONFIG_PANIC_TIMEOUT=20
|
||||
CONFIG_DETECT_HUNG_TASK=y
|
||||
CONFIG_BOOTPARAM_SOFTLOCKUP_PANIC=y
|
||||
CONFIG_HARDLOCKUP_DETECTOR=y
|
||||
CONFIG_HARDLOCKUP_DETECTOR_PREFER_BUDDY=y
|
||||
CONFIG_BOOTPARAM_HARDLOCKUP_PANIC=y
|
||||
CONFIG_BOOTPARAM_HUNG_TASK_PANIC=y
|
||||
CONFIG_WQ_WATCHDOG=y
|
||||
CONFIG_WQ_CPU_INTENSIVE_REPORT=y
|
||||
CONFIG_TEST_LOCKUP=m
|
||||
# CONFIG_SCHED_DEBUG is not set
|
||||
# CONFIG_RCU_TRACE is not set
|
||||
CONFIG_FUNCTION_TRACER=y
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
# QEMU-specific U-Boot config
|
||||
# Enable PCI MMC for QEMU virtualized environment
|
||||
CONFIG_MMC_PCI=y
|
||||
@@ -101,6 +101,13 @@ Worth noting, unlike many other boards, the Rockchip family of chipsets
|
||||
runs the UART at 1500000 bps (1.5 Mbps) 8N1.
|
||||
|
||||
|
||||
Console Port
|
||||
------------
|
||||
|
||||
Unlike many other boards, the NanoPi R2S console, and in fact all
|
||||
Rockchip family chipsets, runs at 1500000 bps (1.5 Mbps) 8N1.
|
||||
|
||||
|
||||
Secure Boot
|
||||
-----------
|
||||
|
||||
|
||||
@@ -230,7 +230,6 @@ CONFIG_MAC80211_LEDS=y
|
||||
CONFIG_RFKILL=y
|
||||
CONFIG_NET_9P=y
|
||||
CONFIG_NET_9P_VIRTIO=y
|
||||
# CONFIG_ETHTOOL_NETLINK is not set
|
||||
CONFIG_PCI=y
|
||||
CONFIG_PCIEPORTBUS=y
|
||||
CONFIG_PCI_IOV=y
|
||||
@@ -481,7 +480,6 @@ CONFIG_I2C=y
|
||||
CONFIG_I2C_CHARDEV=y
|
||||
CONFIG_I2C_MUX=y
|
||||
CONFIG_I2C_MUX_PCA954x=y
|
||||
CONFIG_I2C_DESIGNWARE_PLATFORM=y
|
||||
CONFIG_I2C_GPIO=m
|
||||
CONFIG_I2C_RK3X=y
|
||||
CONFIG_I2C_SLAVE=y
|
||||
|
||||
@@ -0,0 +1,161 @@
|
||||
#!/bin/sh
|
||||
|
||||
set -e
|
||||
|
||||
# Build a map of phandle -> device tree node path for all PHY nodes
|
||||
build_phandle_map()
|
||||
{
|
||||
for phy_node in /sys/firmware/devicetree/base/cp*/config-space*/mdio*/switch*/mdio/ethernet-phy@* \
|
||||
/sys/firmware/devicetree/base/cp*/config-space*/mdio*/ethernet-phy@*; do
|
||||
[ -f "$phy_node/phandle" ] || continue
|
||||
|
||||
phandle=$(od -An -t x4 -N 4 "$phy_node/phandle" 2>/dev/null | tr -d ' ')
|
||||
if [ -n "$phandle" ]; then
|
||||
echo "$phandle:$phy_node"
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
build_phy_map()
|
||||
{
|
||||
phandle_map=$(build_phandle_map)
|
||||
|
||||
# Build a mapping of PHY of_node path -> interface name
|
||||
for iface in /sys/class/net/*; do
|
||||
[ -d "$iface" ] || continue
|
||||
|
||||
iface_name=$(basename "$iface")
|
||||
|
||||
# Try regular phydev approach first (for non-DSA interfaces)
|
||||
if [ -L "$iface/phydev/of_node" ]; then
|
||||
phy_of_node=$(readlink -f "$iface/phydev/of_node" 2>/dev/null)
|
||||
if [ -n "$phy_of_node" ]; then
|
||||
echo "$phy_of_node:$iface_name"
|
||||
continue
|
||||
fi
|
||||
fi
|
||||
|
||||
# For DSA interfaces, resolve via of_node's phy-handle
|
||||
if [ -L "$iface/of_node" ]; then
|
||||
iface_of_node=$(readlink -f "$iface/of_node" 2>/dev/null)
|
||||
[ -n "$iface_of_node" ] || continue
|
||||
|
||||
# Try to read phy-handle property (4-byte phandle)
|
||||
if [ -f "$iface_of_node/phy-handle" ]; then
|
||||
phy_phandle=$(od -An -t x4 -N 4 "$iface_of_node/phy-handle" 2>/dev/null | tr -d ' ')
|
||||
|
||||
if [ -n "$phy_phandle" ]; then
|
||||
# Look up the PHY node path from our phandle map
|
||||
phy_of_node=$(echo "$phandle_map" | grep "^$phy_phandle:" | cut -d: -f2)
|
||||
if [ -n "$phy_of_node" ]; then
|
||||
echo "$phy_of_node:$iface_name"
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
zone_map()
|
||||
{
|
||||
type="$1"
|
||||
|
||||
case "$type" in
|
||||
ap-ic-thermal)
|
||||
echo "Application processor interconnect"
|
||||
;;
|
||||
ap-cpu[0-9]*-thermal)
|
||||
cpu=${type#ap-cpu}
|
||||
cpu=${cpu%-thermal}
|
||||
echo "Application processor core $cpu"
|
||||
;;
|
||||
cp[0-9]*-ic-thermal)
|
||||
cp=${type%%-*}
|
||||
cp=${cp#cp}
|
||||
echo "Communication processor $cp interconnect"
|
||||
;;
|
||||
*)
|
||||
echo "$type"
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
thermal_zones()
|
||||
{
|
||||
echo "Thermal Zones"
|
||||
echo "============="
|
||||
echo
|
||||
|
||||
for zone in /sys/class/thermal/thermal_zone*; do
|
||||
[ -d "$zone" ] || continue
|
||||
|
||||
name=$(basename "$zone")
|
||||
type=$(cat "$zone/type" 2>/dev/null || echo "unknown")
|
||||
data=$(cat "$zone/temp" 2>/dev/null)
|
||||
desc=$(zone_map "$type")
|
||||
|
||||
if [ -n "$data" ] && [ "$data" != "N/A" ]; then
|
||||
# Convert millidegrees to degrees Celsius
|
||||
temp_c=$(awk "BEGIN {printf \"%.1f\", $data / 1000}")
|
||||
printf "%-20s %8s°C %s\n" "$name" "$temp_c" "$desc"
|
||||
else
|
||||
printf "%-20s %8s %s\n" "$name" "N/A" "$desc"
|
||||
fi
|
||||
done
|
||||
echo
|
||||
}
|
||||
|
||||
hwmon()
|
||||
{
|
||||
tmpfile=$(mktemp)
|
||||
|
||||
echo "Hardware Monitors"
|
||||
echo "================="
|
||||
echo
|
||||
|
||||
phy_map=$(build_phy_map)
|
||||
|
||||
for hwmon in /sys/class/hwmon/hwmon*; do
|
||||
[ -d "$hwmon" ] || continue
|
||||
|
||||
name=$(basename "$hwmon")
|
||||
data=$(cat "$hwmon/temp1_input" 2>/dev/null)
|
||||
|
||||
# Try to find the associated network interface
|
||||
iface=
|
||||
if [ -L "$hwmon/of_node" ]; then
|
||||
hwmon_of_node=$(readlink -f "$hwmon/of_node" 2>/dev/null)
|
||||
if [ -n "$hwmon_of_node" ]; then
|
||||
iface=$(echo "$phy_map" | grep "^$hwmon_of_node:" | cut -d: -f2)
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ -n "$iface" ]; then
|
||||
description="Phy $iface temperature"
|
||||
else
|
||||
description="N/A"
|
||||
fi
|
||||
|
||||
if [ -n "$data" ] && [ "$data" != "N/A" ]; then
|
||||
# Convert millidegrees to degrees Celsius
|
||||
temp_c=$(awk "BEGIN {printf \"%.1f\", $data / 1000}")
|
||||
# Format: sortkey|hwmon|temp|description (sortkey for natural sort by interface)
|
||||
printf "%s|%-20s %8s°C %s\n" "$iface" "$name" "$temp_c" "$description" >> "$tmpfile"
|
||||
else
|
||||
printf "%s|%-20s %8s %s\n" "$iface" "$name" "N/A" "$description" >> "$tmpfile"
|
||||
fi
|
||||
done
|
||||
|
||||
# Sort by interface name naturally (e2 before e10), with N/A entries at the end
|
||||
# Then strip the sort key before displaying
|
||||
sort -V -t'|' -k1,1 "$tmpfile" | cut -d'|' -f2-
|
||||
rm -f "$tmpfile"
|
||||
echo
|
||||
}
|
||||
|
||||
[ -n "$1" ] || { echo "usage: $0 OUT-DIR"; exit 1; }
|
||||
work="$1"/system
|
||||
mkdir -p "${work}"
|
||||
|
||||
thermal_zones > "${work}"/temperature.txt
|
||||
hwmon >> "${work}"/temperature.txt
|
||||
@@ -0,0 +1,26 @@
|
||||
#!/bin/sh
|
||||
|
||||
set -e
|
||||
|
||||
ecc_stat()
|
||||
{
|
||||
local chan=
|
||||
local base=
|
||||
|
||||
for chan in 0 1; do
|
||||
base=$((0xf0020360 + 0x200 * chan))
|
||||
|
||||
echo "DRAM Channel $chan ECC Status"
|
||||
echo -n " Log config: "; devmem $((base + 0x0)) 32
|
||||
echo -n " 1b errors: "; devmem $((base + 0x4)) 32
|
||||
echo -n " Info 0: "; devmem $((base + 0x8)) 32
|
||||
echo -n " Info 1: "; devmem $((base + 0xc)) 32
|
||||
echo
|
||||
done
|
||||
}
|
||||
|
||||
[ -n "$1" ] || { echo "usage: $0 OUT-DIR"; exit 1; }
|
||||
work="$1"/marvell-cn913x
|
||||
mkdir -p "${work}"
|
||||
|
||||
ecc_stat >"${work}"/ecc-stat
|
||||
@@ -45,11 +45,11 @@ The default credentials for the demo builds is
|
||||
login: admin
|
||||
password: admin
|
||||
|
||||
Infix -- a Network Operating System v24.09.0-rc1 (hvc0)
|
||||
Infix OS — Immutable.Friendly.Secure v24.09.0-rc1 (hvc0)
|
||||
infix-00-00-00 login: admin
|
||||
Password:
|
||||
.-------.
|
||||
| . . | Infix -- a Network Operating System
|
||||
| . . | Infix OS — Immutable.Friendly.Secure
|
||||
|-. v .-| https://kernelkit.org
|
||||
'-'---'-'
|
||||
|
||||
@@ -122,9 +122,9 @@ There's a lot of tutorials and guides online, start here:
|
||||
About
|
||||
-----
|
||||
|
||||
Infix is a free, Linux based, immutable Network Operating System (NOS)
|
||||
built on Buildroot, and sysrepo. A powerful mix that ease porting to
|
||||
different platforms, simplify long-term maintenance, and provide easy
|
||||
management using NETCONF, RESTCONF, or the built-in command line
|
||||
interface (CLI) from a console or SSH login.
|
||||
Infix is a free, Linux-based, immutable operating system built around
|
||||
Buildroot, and sysrepo. A powerful mix that ease porting to different
|
||||
platforms, simplify long-term maintenance, and provide easy management
|
||||
using NETCONF, RESTCONF, or the built-in command line interface (CLI)
|
||||
from a console or SSH login.
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
#
|
||||
# Automatically generated make config: don't edit
|
||||
# Busybox version: 1.36.1
|
||||
# Tue Oct 22 13:12:02 2024
|
||||
# Sun Feb 9 12:25:37 2025
|
||||
#
|
||||
CONFIG_HAVE_DOT_CONFIG=y
|
||||
|
||||
@@ -17,7 +17,7 @@ CONFIG_SHOW_USAGE=y
|
||||
CONFIG_FEATURE_VERBOSE_USAGE=y
|
||||
# CONFIG_FEATURE_COMPRESS_USAGE is not set
|
||||
CONFIG_LFS=y
|
||||
# CONFIG_PAM is not set
|
||||
CONFIG_PAM=y
|
||||
CONFIG_FEATURE_DEVPTS=y
|
||||
CONFIG_FEATURE_UTMP=y
|
||||
CONFIG_FEATURE_WTMP=y
|
||||
@@ -325,7 +325,7 @@ CONFIG_FEATURE_STAT_FILESYSTEM=y
|
||||
CONFIG_STTY=y
|
||||
CONFIG_SUM=y
|
||||
CONFIG_SYNC=y
|
||||
# CONFIG_FEATURE_SYNC_FANCY is not set
|
||||
CONFIG_FEATURE_SYNC_FANCY=y
|
||||
CONFIG_FSYNC=y
|
||||
# CONFIG_TAC is not set
|
||||
CONFIG_TAIL=y
|
||||
@@ -336,7 +336,7 @@ CONFIG_TEST=y
|
||||
CONFIG_TEST1=y
|
||||
CONFIG_TEST2=y
|
||||
CONFIG_FEATURE_TEST_64=y
|
||||
# CONFIG_TIMEOUT is not set
|
||||
CONFIG_TIMEOUT=y
|
||||
CONFIG_TOUCH=y
|
||||
CONFIG_FEATURE_TOUCH_SUSV3=y
|
||||
CONFIG_TR=y
|
||||
@@ -357,7 +357,7 @@ CONFIG_BASE32=y
|
||||
CONFIG_BASE64=y
|
||||
CONFIG_UUENCODE=y
|
||||
CONFIG_WC=y
|
||||
# CONFIG_FEATURE_WC_LARGE is not set
|
||||
CONFIG_FEATURE_WC_LARGE=y
|
||||
CONFIG_WHO=y
|
||||
CONFIG_W=y
|
||||
CONFIG_USERS=y
|
||||
|
||||
@@ -83,7 +83,7 @@ genboot()
|
||||
{
|
||||
if [ -d "$bootdata" ]; then
|
||||
bootimg=$(cat <<EOF
|
||||
image efi-part.vfat {
|
||||
image $BINARIES_DIR/efi-part.vfat {
|
||||
size = $bootsize
|
||||
vfat {
|
||||
file EFI {
|
||||
@@ -98,7 +98,7 @@ EOF
|
||||
offset = $bootoffs
|
||||
partition-type-uuid = U
|
||||
bootable = true
|
||||
image = efi-part.vfat
|
||||
image = $BINARIES_DIR/efi-part.vfat
|
||||
}
|
||||
EOF
|
||||
)
|
||||
@@ -127,7 +127,7 @@ bootdata=
|
||||
diskimg=disk.img
|
||||
bootimg=
|
||||
bootpart=
|
||||
|
||||
tmpimage=$(mktemp)
|
||||
while getopts "a:b:B:n:s:" opt; do
|
||||
case ${opt} in
|
||||
a)
|
||||
@@ -166,7 +166,7 @@ awk \
|
||||
-vimgsize=$imgsize \
|
||||
-vcfgsize=$cfgsize \
|
||||
-vvarsize=$varsize \
|
||||
-vdiskimg=$diskimg \
|
||||
-vdiskimg=$tmpimage \
|
||||
-vbootimg="$bootimg" -vbootpart="$bootpart" \
|
||||
'{
|
||||
sub(/@TOTALSIZE@/, total);
|
||||
@@ -211,5 +211,7 @@ genimage \
|
||||
--rootpath "$root" \
|
||||
--tmppath "$tmp" \
|
||||
--inputpath "$BINARIES_DIR" \
|
||||
--outputpath "$BINARIES_DIR" \
|
||||
--config "$root/genimage.cfg"
|
||||
|
||||
qemu-img convert -c -O qcow2 "$tmpimage" "$BINARIES_DIR/$diskimg"
|
||||
rm "$tmpimage"
|
||||
|
||||
@@ -2,8 +2,6 @@
|
||||
|
||||
set -e
|
||||
|
||||
GIT_VERSION=$(git -C "$BR2_EXTERNAL_INFIX_PATH" describe --always --dirty --tags)
|
||||
|
||||
name=$1
|
||||
compat=$2
|
||||
sign=$3
|
||||
@@ -26,7 +24,7 @@ cp -f "$BINARIES_DIR/rootfs.itbh" "$work/rootfs.itbh"
|
||||
cat >"$work/manifest.raucm" <<EOF
|
||||
[update]
|
||||
compatible=${compat}
|
||||
version=${GIT_VERSION}
|
||||
version=${INFIX_VERSION}
|
||||
|
||||
[bundle]
|
||||
format=verity
|
||||
|
||||
@@ -39,22 +39,6 @@ if [ -n "${ID_LIKE}" ]; then
|
||||
ID="${ID} ${ID_LIKE}"
|
||||
fi
|
||||
|
||||
if [ -z "$GIT_VERSION" ]; then
|
||||
infix_path="$BR2_EXTERNAL_INFIX_PATH"
|
||||
if [ -n "$INFIX_OEM_PATH" ]; then
|
||||
# Use version from br2-external OEM:ing Infix
|
||||
infix_path="$INFIX_OEM_PATH"
|
||||
fi
|
||||
GIT_VERSION=$(git -C "$infix_path" describe --always --dirty --tags)
|
||||
fi
|
||||
|
||||
# Override VERSION in /etc/os-release and filenames for release builds
|
||||
if [ -n "$INFIX_RELEASE" ]; then
|
||||
VERSION="$INFIX_RELEASE"
|
||||
else
|
||||
VERSION=$GIT_VERSION
|
||||
fi
|
||||
|
||||
if [ -n "$INFIX_IMAGE_ID" ]; then
|
||||
NAME="$INFIX_IMAGE_ID"
|
||||
else
|
||||
@@ -71,12 +55,12 @@ rm -f "$TARGET_DIR/etc/os-release"
|
||||
{
|
||||
echo "NAME=\"$INFIX_NAME\""
|
||||
echo "ID=$INFIX_ID"
|
||||
echo "PRETTY_NAME=\"$INFIX_TAGLINE $VERSION\""
|
||||
echo "PRETTY_NAME=\"$INFIX_TAGLINE $INFIX_VERSION\""
|
||||
echo "ID_LIKE=\"${ID}\""
|
||||
echo "DEFAULT_HOSTNAME=$BR2_TARGET_GENERIC_HOSTNAME"
|
||||
echo "VERSION=\"${VERSION}\""
|
||||
echo "VERSION_ID=${VERSION}"
|
||||
echo "BUILD_ID=\"${GIT_VERSION}\""
|
||||
echo "VERSION=\"${INFIX_VERSION}\""
|
||||
echo "VERSION_ID=${INFIX_VERSION}"
|
||||
echo "BUILD_ID=\"${INFIX_BUILD_ID}\""
|
||||
if [ -n "$INFIX_IMAGE_ID" ]; then
|
||||
echo "IMAGE_ID=\"$INFIX_IMAGE_ID\""
|
||||
fi
|
||||
@@ -102,7 +86,7 @@ rm -f "$TARGET_DIR/etc/os-release"
|
||||
fi
|
||||
} > "$TARGET_DIR/etc/os-release"
|
||||
|
||||
echo "$INFIX_TAGLINE $VERSION -- $(date +"%b %e %H:%M %Z %Y")" > "$TARGET_DIR/etc/version"
|
||||
echo "$INFIX_TAGLINE $INFIX_VERSION -- $(date +"%b %e %H:%M %Z %Y")" > "$TARGET_DIR/etc/version"
|
||||
|
||||
# In case of ambguities, this is what the image was built from
|
||||
cp "$BR2_CONFIG" "$TARGET_DIR/usr/share/infix/config"
|
||||
@@ -130,6 +114,12 @@ grep -qsE '^/bin/true$$' "$TARGET_DIR/etc/shells" \
|
||||
grep -qsE '^/bin/false$$' "$TARGET_DIR/etc/shells" \
|
||||
|| echo "/bin/false" >> "$TARGET_DIR/etc/shells"
|
||||
|
||||
boards=$(${BR2_EXTERNAL_INFIX_PATH}/board/common/selected-boards.sh ${BR2_EXTERNAL_INFIX_PATH} ${O})
|
||||
|
||||
for board in $boards; do
|
||||
[ ! -f "${BR2_EXTERNAL_INFIX_PATH}/src/board/${board}/post-build.sh" ] && continue
|
||||
${BR2_EXTERNAL_INFIX_PATH}/src/board/${board}/post-build.sh
|
||||
done
|
||||
# Allow clish (symlink to /usr/bin/klish) to be a login shell
|
||||
grep -qsE '^/bin/clish$$' "$TARGET_DIR/etc/shells" \
|
||||
|| echo "/bin/clish" >> "$TARGET_DIR/etc/shells"
|
||||
|
||||
@@ -23,7 +23,7 @@ if [ -n "$IMAGE_ID" ]; then
|
||||
else
|
||||
NAME="$INFIX_ID"-$(echo "$BR2_ARCH" | tr _ - | sed 's/x86-64/x86_64/')
|
||||
fi
|
||||
diskimg=disk.img
|
||||
diskimg=disk.qcow2
|
||||
|
||||
ver()
|
||||
{
|
||||
@@ -48,7 +48,7 @@ fi
|
||||
load_cfg DISK_IMAGE
|
||||
if [ "$DISK_IMAGE" = "y" ]; then
|
||||
ixmsg "Creating Disk Image"
|
||||
diskimg="${NAME}-disk$(ver).img"
|
||||
diskimg="${NAME}-disk$(ver).qcow2"
|
||||
bootcfg=
|
||||
if [ "$DISK_IMAGE_BOOT_DATA" ]; then
|
||||
bootcfg="-b $DISK_IMAGE_BOOT_DATA -B $DISK_IMAGE_BOOT_OFFSET"
|
||||
@@ -86,25 +86,27 @@ if [ "$FIT_IMAGE" = "y" ]; then
|
||||
$common/mkfit.sh
|
||||
fi
|
||||
|
||||
# Only for regular builds, not bootloader-only builds
|
||||
if [ "$BR2_TARGET_ROOTFS_SQUASHFS" = "y" ]; then
|
||||
rel=$(ver)
|
||||
ln -sf rootfs.squashfs "$BINARIES_DIR/${NAME}${rel}.img"
|
||||
if [ -n "$rel" ]; then
|
||||
ln -sf "$BINARIES_DIR/${NAME}${rel}.img" "$BINARIES_DIR/${NAME}.img"
|
||||
ln -sf "${NAME}${rel}.img" "$BINARIES_DIR/${NAME}.img"
|
||||
fi
|
||||
|
||||
cp "$BR2_EXTERNAL_INFIX_PATH/board/common/rootfs/usr/bin/onieprom" "$BINARIES_DIR/"
|
||||
|
||||
# Menuconfig support for modifying Qemu args in release tarballs
|
||||
cp "$BR2_EXTERNAL_INFIX_PATH/board/common/qemu/qemu.sh" "$BINARIES_DIR/"
|
||||
sed -e "s/@ARCH@/QEMU_$BR2_ARCH/" \
|
||||
-e "s/@DISK_IMG@/$diskimg/" \
|
||||
< "$BR2_EXTERNAL_INFIX_PATH/board/common/qemu/Config.in.in" \
|
||||
> "$BINARIES_DIR/Config.in"
|
||||
rm -f "$BINARIES_DIR/qemu.cfg"
|
||||
CONFIG_="CONFIG_" BR2_CONFIG="$BINARIES_DIR/qemu.cfg" \
|
||||
"$O/build/buildroot-config/conf" --olddefconfig "$BINARIES_DIR/Config.in"
|
||||
rm -f "$BINARIES_DIR/qemu.cfg.old" "$BINARIES_DIR/.config.old"
|
||||
|
||||
# Quick intro for beginners, with links to more information
|
||||
cp "$BR2_EXTERNAL_INFIX_PATH/board/common/README.txt" "$BINARIES_DIR/"
|
||||
fi
|
||||
|
||||
# Menuconfig support for modifying Qemu args in release tarballs
|
||||
cp "$BR2_EXTERNAL_INFIX_PATH/board/common/rootfs/usr/bin/onieprom" "$BINARIES_DIR/"
|
||||
cp "$BR2_EXTERNAL_INFIX_PATH/board/common/qemu/qemu.sh" "$BINARIES_DIR/"
|
||||
sed -e "s/@ARCH@/QEMU_$BR2_ARCH/" \
|
||||
-e "s/@DISK_IMG@/$diskimg/" \
|
||||
< "$BR2_EXTERNAL_INFIX_PATH/board/common/qemu/Config.in.in" \
|
||||
> "$BINARIES_DIR/Config.in"
|
||||
rm -f "$BINARIES_DIR/qemu.cfg"
|
||||
CONFIG_="CONFIG_" BR2_CONFIG="$BINARIES_DIR/qemu.cfg" \
|
||||
"$O/build/buildroot-config/conf" --olddefconfig "$BINARIES_DIR/Config.in"
|
||||
rm -f "$BINARIES_DIR/qemu.cfg.old" "$BINARIES_DIR/.config.old"
|
||||
|
||||
# Quick intro for beginners, with links to more information
|
||||
cp "$BR2_EXTERNAL_INFIX_PATH/board/common/README.txt" "$BINARIES_DIR/"
|
||||
|
||||
@@ -66,7 +66,7 @@ endchoice
|
||||
|
||||
config QEMU_MACHINE
|
||||
string "Select emulated machine"
|
||||
default "qemu-system-aarch64 -M virt,accel=kvm:tcg -cpu max" if QEMU_aarch64
|
||||
default "qemu-system-aarch64 -M virt,accel=kvm:tcg -cpu max,pauth-impdef=on" if QEMU_aarch64
|
||||
default "qemu-system-x86_64 -M pc,accel=kvm:tcg -cpu max" if QEMU_x86_64
|
||||
help
|
||||
You should not have to change this setting, although you may
|
||||
@@ -78,7 +78,7 @@ config QEMU_MACHINE
|
||||
|
||||
config QEMU_MACHINE_RAM
|
||||
string "RAM size (k/M/G)"
|
||||
default "384M"
|
||||
default "448M"
|
||||
help
|
||||
The default, 384 MiB, works for most configurations. However,
|
||||
if you get kernel panic with: "System is deadlocked on memory",
|
||||
|
||||
@@ -120,7 +120,7 @@ rootfs_args()
|
||||
echo -n "-device sd-card,drive=mmc "
|
||||
echo -n "-drive id=mmc,file=$CONFIG_QEMU_ROOTFS,if=none,format=raw "
|
||||
elif [ "$CONFIG_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
||||
echo -n "-drive file=$CONFIG_QEMU_ROOTFS.qcow2,if=virtio,format=qcow2,bus=0,unit=0 "
|
||||
echo -n "-drive file=qemu.qcow2,if=virtio,format=qcow2,bus=0,unit=0 "
|
||||
fi
|
||||
}
|
||||
|
||||
@@ -316,13 +316,13 @@ gdb_args()
|
||||
run_qemu()
|
||||
{
|
||||
if [ "$CONFIG_QEMU_ROOTFS_VSCSI" = "y" ]; then
|
||||
if ! qemu-img check "${CONFIG_QEMU_ROOTFS}.qcow2"; then
|
||||
rm -f "${CONFIG_QEMU_ROOTFS}.qcow2"
|
||||
if ! qemu-img check "qemu.qcow2"; then
|
||||
rm -f "qemu.qcow2"
|
||||
fi
|
||||
if [ ! -f "${CONFIG_QEMU_ROOTFS}.qcow2" ]; then
|
||||
if [ ! -f "qemu.qcow2" ]; then
|
||||
echo "Creating qcow2 disk image for Qemu ..."
|
||||
qemu-img create -f qcow2 -o backing_file="$CONFIG_QEMU_ROOTFS" \
|
||||
-F raw "${CONFIG_QEMU_ROOTFS}.qcow2" > /dev/null
|
||||
-F qcow2 "qemu.qcow2" > /dev/null
|
||||
fi
|
||||
fi
|
||||
|
||||
|
||||
@@ -9,46 +9,20 @@
|
||||
# $3 IP adddress
|
||||
|
||||
PATH="$PATH:/usr/bin:/usr/sbin:/bin:/sbin"
|
||||
NAME="/etc/frr/static.d/$2-zeroconf.conf"
|
||||
NEXT="${NAME}+"
|
||||
|
||||
log()
|
||||
{
|
||||
logger -I $$ -t zeroconf -p user.notice "$*"
|
||||
}
|
||||
|
||||
# Reduce changes needed by comparing with previous route(s)
|
||||
act()
|
||||
{
|
||||
case $1 in
|
||||
add)
|
||||
echo "! Generated by avahi-autoipd" > "$NEXT"
|
||||
echo "ip route 0.0.0.0/0 $2 254" >> "$NEXT"
|
||||
cmp -s "$NAME" "$NEXT" && return
|
||||
mv "$NEXT" "$NAME"
|
||||
;;
|
||||
del)
|
||||
[ -f "$NAME" ] || return
|
||||
rm "$NAME"
|
||||
;;
|
||||
*)
|
||||
return
|
||||
;;
|
||||
esac
|
||||
|
||||
initctl -nbq restart staticd
|
||||
}
|
||||
|
||||
case "$1" in
|
||||
BIND)
|
||||
ip addr flush dev "$2" proto random
|
||||
ip addr add "$3"/16 brd 169.254.255.255 scope link dev "$2" proto random
|
||||
act add "$2"
|
||||
log "set ipv4ll $3 on iface $2"
|
||||
;;
|
||||
|
||||
CONFLICT|UNBIND|STOP)
|
||||
act del "$2"
|
||||
ip addr flush dev "$2" proto random
|
||||
log "clr ipv4ll on iface $2"
|
||||
;;
|
||||
|
||||
@@ -3,16 +3,19 @@
|
||||
# and similar events feed servers and configuration to dnsmasq.
|
||||
domain-needed
|
||||
|
||||
# Only listen to loopback (local system)
|
||||
interface=lo
|
||||
bind-dynamic
|
||||
#listen-address=127.0.0.1,::1
|
||||
|
||||
# Allow configuration and cache clear over D-Bus
|
||||
enable-dbus
|
||||
|
||||
# Disable the following dnsmasq default DHCP options
|
||||
#dhcp-option=option:netmask
|
||||
#dhcp-option=28 # option:broadcast
|
||||
#dhcp-option=option:domain-name
|
||||
dhcp-option=option:router
|
||||
dhcp-option=option:dns-server
|
||||
dhcp-option=12 # option:hostname
|
||||
|
||||
# Generated by openresolv
|
||||
resolv-file=/var/lib/misc/resolv.conf
|
||||
|
||||
# Include all files in a directory which end in .conf
|
||||
conf-dir=/etc/dnsmasq.d/,*.conf
|
||||
|
||||
|
||||
@@ -1,4 +1,7 @@
|
||||
task name:container-%i :setup \
|
||||
[2345] container -n %i setup -- Setup container %i
|
||||
sysv <!usr/container:%i> :%i pid:!/run/container:%i.pid log:prio:local1,tag:%i kill:10 \
|
||||
[2345] container -n %i -- container %i
|
||||
# Start a container instance (%i) and redirect logs to /log/container
|
||||
# Give podman enough time to properly shut down the container, kill:30
|
||||
# The pre:script, which is responsibe for fetching a remote image, must
|
||||
# not have a timeout. The cleanup should take no longer than a minute.
|
||||
sysv log:prio:local1,tag:%i kill:30 pid:!/run/container:%i.pid \
|
||||
pre:0,/usr/sbin/container cleanup:60,/usr/sbin/container \
|
||||
[2345] <!> :%i container -n %i -- container %i
|
||||
|
||||
@@ -0,0 +1,9 @@
|
||||
# A single mstpd instance can manage multiple bridges, which are
|
||||
# dynamically added/removed by the kernel via the /sbin/bridge-stp
|
||||
# usermode helper. We use a manual service so that confd can
|
||||
# enable/disable it without an initctl barrier, since it needs to
|
||||
# already be running when a bridge interface with spanning tree
|
||||
# enabled is created.
|
||||
|
||||
service env:-/etc/default/mstpd manual:yes \
|
||||
[S0123456789] mstpd $MSTPD_ARGS -- Spanning Tree daemon
|
||||
@@ -1 +1 @@
|
||||
service [2345] <!> ttyd -i lo -p 8001 login -- Web terminal daemon (ttyd)
|
||||
service [2345] <!> ttyd -i lo -W -p 8001 login -- Web terminal daemon (ttyd)
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
service name:wpa_supplicant :%i \
|
||||
[2345] wpa_supplicant -s -i %i -c /etc/wpa_supplicant-%i.conf -P/var/run/wpa_supplicant-%i.pid \
|
||||
-- WPA supplicant @%i
|
||||
|
||||
task name:wifi-scanner :%i [2345] <pid/wpa_supplicant:%i> /usr/libexec/infix/wifi-scanner %i -- Start scanning for SSID @ %i
|
||||
@@ -0,0 +1 @@
|
||||
../available/mstpd.conf
|
||||
@@ -1,4 +1,4 @@
|
||||
.-------.
|
||||
| . . | Infix -- a Network Operating System
|
||||
| . . | Infix OS — Immutable.Friendly.Secure
|
||||
|-. v .-| https://kernelkit.org
|
||||
'-'---'-'
|
||||
|
||||
@@ -1,3 +0,0 @@
|
||||
HostKey /var/lib/ssh/ssh_host_rsa_key
|
||||
HostKey /var/lib/ssh/ssh_host_ecdsa_key
|
||||
HostKey /var/lib/ssh/ssh_host_ed25519_key
|
||||
@@ -1,3 +0,0 @@
|
||||
net.ipv4.ip_forward=1
|
||||
net.ipv4.ip_forward_update_priority=0
|
||||
net.ipv6.conf.all.forwarding=1
|
||||
@@ -1 +1,32 @@
|
||||
# Router defaults
|
||||
net.ipv4.conf.default.rp_filter=0
|
||||
net.ipv4.conf.all.rp_filter=0
|
||||
|
||||
net.ipv4.conf.lo.rp_filter=0
|
||||
|
||||
net.ipv4.icmp_errors_use_inbound_ifaddr=1
|
||||
net.ipv4.conf.all.ignore_routes_with_linkdown=1
|
||||
|
||||
# Use neigh information on selection of nexthop for multipath hops
|
||||
net.ipv4.fib_multipath_use_neigh=1
|
||||
|
||||
# Sane ARP defaults for a switch/router
|
||||
net.ipv4.conf.default.arp_announce=2
|
||||
net.ipv4.conf.all.arp_announce=2
|
||||
|
||||
net.ipv4.conf.default.arp_notify=1
|
||||
net.ipv4.conf.all.arp_notify=1
|
||||
|
||||
net.ipv4.conf.default.arp_ignore=1
|
||||
net.ipv4.conf.all.arp_ignore=1
|
||||
|
||||
# IP Routing
|
||||
net.ipv4.ip_forward=1
|
||||
net.ipv4.ip_forward_update_priority=0
|
||||
|
||||
net.ipv4.conf.all.forwarding=0
|
||||
net.ipv4.conf.default.forwarding=0
|
||||
|
||||
# Multicast group subscriptions
|
||||
net.ipv4.igmp_max_memberships=1000
|
||||
net.ipv4.neigh.default.mcast_solicit=10
|
||||
|
||||
@@ -1,5 +1,23 @@
|
||||
net.ipv6.conf.all.forwarding=1
|
||||
# Router defaults
|
||||
net.ipv6.route.max_size=131072
|
||||
net.ipv6.conf.all.ignore_routes_with_linkdown=1
|
||||
|
||||
# IP Routing is disabled by default, enabled globally, and per
|
||||
# interface, for each interface in confd. See also accept_ra.
|
||||
net.ipv6.conf.all.forwarding=0
|
||||
net.ipv6.conf.default.forwarding=0
|
||||
|
||||
# Accept router advertisements even when forwarding is enabled
|
||||
net.ipv6.conf.all.accept_ra=2
|
||||
net.ipv6.conf.default.accept_ra=2
|
||||
|
||||
# IPv6 SLAAC
|
||||
net.ipv6.conf.all.autoconf=0
|
||||
net.ipv6.conf.default.autoconf=0
|
||||
|
||||
# Keep permanent addresses on an admin down
|
||||
net.ipv6.conf.all.keep_addr_on_down=1
|
||||
net.ipv6.conf.default.keep_addr_on_down=1
|
||||
|
||||
# Multicast group subscriptions
|
||||
net.ipv6.mld_max_msf=512
|
||||
|
||||
@@ -0,0 +1,145 @@
|
||||
Many of the defaults here are are taken from the Frr recommendations [1].
|
||||
Below are relevant excerpts from the kernel documentation.
|
||||
|
||||
|
||||
accept_ra, accept Router Advertisements; autoconfigure using them, also
|
||||
determines whether or not to transmit Router Solicitations.
|
||||
If and only if the functional setting is to accept Router
|
||||
Advertisements, Router Solicitations will be transmitted.
|
||||
|
||||
0 - Do not accept Router Advertisements.
|
||||
|
||||
1 - Accept Router Advertisements if forwarding is disabled.
|
||||
|
||||
2 - Overrule forwarding behaviour. Accept Router Advertisements even
|
||||
if forwarding is enabled.
|
||||
|
||||
Default:
|
||||
- enabled if local forwarding is disabled
|
||||
- disabled if local forwarding is enabled
|
||||
|
||||
|
||||
accept_ra_pinfo, learn Prefix Information in Router Advertisement.
|
||||
|
||||
Default:
|
||||
- enabled if accept_ra is enabled
|
||||
- disabled if accept_ra is disabled
|
||||
|
||||
|
||||
autoconf, autoconfigure IPv6 addresses using Prefix Information in
|
||||
Router Advertisements.
|
||||
|
||||
Default:
|
||||
- enabled if accept_ra_pinfo is enabled
|
||||
- disabled if accept_ra_pinfo is disabled
|
||||
|
||||
|
||||
arp_announce, define restriction level for announcing the local source
|
||||
address from IP packets in ARP requests sent on interface:
|
||||
|
||||
0 - (default) Use any local address, configured on any interface
|
||||
|
||||
1 - Try to avoid local addresses that are not in the target’s subnet
|
||||
for this interface. Useful when target hosts reachable via this
|
||||
interface require the source IP address in ARP requests to be part
|
||||
of their logical network configured on the receiving interface.
|
||||
When we generate the request we will check all our subnets that
|
||||
include the target IP and will preserve the source address if it
|
||||
is from such subnet. If there is no such subnet we select source
|
||||
address according to the rules for level 2.
|
||||
|
||||
2 - Always use the best local address for this target. In this mode we
|
||||
ignore the source address in the IP packet and try to select local
|
||||
address that we prefer for talks with the target host. Such local
|
||||
address is selected by looking for primary IP addresses on all our
|
||||
subnets on the outgoing interface that include the target address.
|
||||
If no suitable local address is found we select the first local
|
||||
address we have on the outgoing interface or on all other
|
||||
interfaces, with the hope we will receive reply for our request
|
||||
and even sometimes no matter the source IP address we announce.
|
||||
|
||||
|
||||
arp_notify, define mode for notification of address and device changes.
|
||||
|
||||
0 - (default): do nothing
|
||||
1 - generate gratuitous arp requests when device is brought up or
|
||||
hardware address changes.
|
||||
|
||||
|
||||
arp_ignore, define different modes for sending replies in response to
|
||||
received ARP requests that resolve local target addresses:
|
||||
|
||||
0 - (default): reply for any local target IP address, configured on
|
||||
any interface
|
||||
|
||||
1 - reply only if the target IP address is a local address configured
|
||||
on the incoming interface
|
||||
|
||||
2 - reply only if the target IP address is local address configured on
|
||||
the incoming interface and both with the sender’s IP address are part
|
||||
from same subnet on this interface
|
||||
|
||||
3 - do not reply for local addresses configured with scope host, only
|
||||
resolutions for global and link addresses are replied
|
||||
|
||||
4-7 - reserved
|
||||
|
||||
8 - do not reply for all local addresses
|
||||
|
||||
|
||||
arp_accept, define behavior for accepting gratuitous ARP (garp) frames
|
||||
from devices that are not already present in the ARP table:
|
||||
|
||||
0 - don’t create new entries in the ARP table
|
||||
|
||||
1 - create new entries in the ARP table
|
||||
|
||||
2 - create new entries only if the source IP address is in the same
|
||||
subnet as an address configured on the interface that received
|
||||
the garp message.
|
||||
|
||||
Both replies and requests type gratuitous arp will trigger the ARP
|
||||
table to be updated, if this setting is on. If the ARP table already
|
||||
contains the IP address of the gratuitous arp frame, the arp table
|
||||
will be updated regardless if this setting is on or off.
|
||||
|
||||
|
||||
icmp_errors_use_inbound_ifaddr
|
||||
|
||||
0 - (default): icmp error messages are sent with the primary address
|
||||
of the exiting interface.
|
||||
|
||||
1 - the message will be sent with the primary address of the interface
|
||||
that received the packet that caused the icmp error. This is the
|
||||
behaviour many network administrators will expect from a router.
|
||||
And it can make debugging complicated network layouts much easier.
|
||||
|
||||
Note, if no primary address exists for the interface selected, then
|
||||
the primary address of the first non-loopback interface that has one
|
||||
will be used regardless of this setting.
|
||||
|
||||
|
||||
rp_filter, reverse path source filtering:
|
||||
|
||||
0 - (default): no source validation.
|
||||
|
||||
1 - Strict mode as defined in RFC3704, 'Strict Reverse Path'. Each
|
||||
incoming packet is tested against the FIB and if the interface is
|
||||
not the best reverse path the packet check will fail. By default
|
||||
failed packets are discarded.
|
||||
|
||||
2 - Loose mode as defined in RFC3704, 'Loose Reverse Path'. Each
|
||||
incoming packet’s source address is also tested against the FIB
|
||||
and if the source address is not reachable via any interface the
|
||||
packet check will fail.
|
||||
|
||||
Current recommended practice in RFC3704 is to enable strict mode to
|
||||
prevent IP spoofing from DDos attacks. If using asymmetric routing or
|
||||
other complicated routing, then loose mode is recommended.
|
||||
|
||||
The max value from conf/{all,interface}/rp_filter is used when doing
|
||||
source validation on the {interface}.
|
||||
|
||||
|
||||
|
||||
[1]: https://github.com/FRRouting/frr/blob/master/doc/user/Useful_Sysctl_Settings.md
|
||||
@@ -0,0 +1 @@
|
||||
SUBSYSTEM=="net", ACTION=="add", TEST=="/sys/class/net/$name/wireless", NAME="wifi%n"
|
||||
@@ -0,0 +1,174 @@
|
||||
# /etc/watchdogd.conf sample
|
||||
# Commented out values are program defaults.
|
||||
#
|
||||
# The checker/monitor `warning` and `critical` levels are 0.00-1.00,
|
||||
# i.e. 0-100%, except for load average which can vary a lot between
|
||||
# systems and use-cases, not just because of the number of CPU cores.
|
||||
# Use the `script = ...` setting to call script when `warning` and
|
||||
# `critical` are reached for a monitor. In `critical` the monitor
|
||||
# otherwise triggers an unconditional reboot.
|
||||
#
|
||||
# NOTE: `critical` is optional, omitting it disables the reboot action.
|
||||
#
|
||||
|
||||
### Watchdogs ##########################################################
|
||||
# Global settings that can be overridden per watchdog
|
||||
|
||||
# Do not set WDT timeout and kick interval too low, the daemon runs at
|
||||
# SCHED_OTHER level with all other tasks, unless the process supervisor
|
||||
# is enabled. The monitor plugins (below) need CPU time as well.
|
||||
#timeout = 20
|
||||
#interval = 10
|
||||
|
||||
# With safe-exit enabled (true) the daemon will ask the driver disable
|
||||
# the WDT before exiting (SIGINT). However, some WDT drivers (or HW)
|
||||
# may not support this.
|
||||
#safe-exit = true
|
||||
|
||||
# Multiple watchdogs can be kicked, the default, even if no .conf file
|
||||
# is found or device node given on the command line, is /dev/watchdog
|
||||
device /dev/watchdog {
|
||||
timeout = 60
|
||||
interval = 5
|
||||
safe-exit = true
|
||||
}
|
||||
|
||||
#device /dev/watchdog2 {
|
||||
# timeout = 20
|
||||
# interval = 10
|
||||
# safe-exit = true
|
||||
#}
|
||||
|
||||
### Supervisor #########################################################
|
||||
# Instrumented processes can have their main loop supervised. Processes
|
||||
# subscribe to this service using the libwdog API, see the docs for more
|
||||
# on this. When the supervisor is enabled and the priority is set to a
|
||||
# value > 0, watchdogd runs as a SCHED_RR process with elevated realtime
|
||||
# priority. When disabled, or the priority is set to zero (0), it runs
|
||||
# as a regular SCHED_OTHER process, this is the default.
|
||||
#
|
||||
# When a supervised process fails to meet its deadline, the daemon will
|
||||
# perform an unconditional reset having saved the reset reason. If a
|
||||
# script is provided in this section it will be called instead. The
|
||||
# script is called as:
|
||||
#
|
||||
# script.sh supervisor CODE PID LABEL
|
||||
#
|
||||
# Availabel CODEs for the reset reason are avilable in wdog.h
|
||||
#
|
||||
#supervisor {
|
||||
# !!!REMEMBER TO ENABLE reset-reason (below) AS WELL!!!
|
||||
# enabled = true
|
||||
# priority = 98
|
||||
# script = "/path/to/supervisor-script.sh"
|
||||
#}
|
||||
|
||||
### Reset reason #######################################################
|
||||
# The following section controls if/how the reset reason & reset counter
|
||||
# is tracked. By default this is disabled, since not all systems allow
|
||||
# writing to disk, e.g. embedded systems using MTD devices with limited
|
||||
# number of write cycles.
|
||||
#
|
||||
# The default file setting is a non-volatile path, according to the FHS.
|
||||
# It can be changed to another location, but make sure that location is
|
||||
# writable first.
|
||||
reset-reason {
|
||||
enabled = true
|
||||
file = "/var/lib/misc/watchdogd.state"
|
||||
}
|
||||
|
||||
### Checkers/Monitors ##################################################
|
||||
#
|
||||
# Script or command to run instead of reboot when a monitor plugin
|
||||
# reaches any of its critical or warning level. Setting this will
|
||||
# disable the built-in reboot on critical, it is therefore up to the
|
||||
# script to perform reboot, if needed. The script is called as:
|
||||
#
|
||||
# script.sh {filenr, fsmon, loadavg, meminfo} {crit, warn} VALUE
|
||||
#
|
||||
#script = "/path/to/reboot-action.sh"
|
||||
|
||||
# Monitors file descriptor leaks based on /proc/sys/fs/file-nr
|
||||
filenr {
|
||||
enabled = true
|
||||
interval = 3600
|
||||
logmark = true
|
||||
warning = 0.9
|
||||
critical = 1.0
|
||||
# script = "/path/to/alt-reboot-action.sh"
|
||||
}
|
||||
|
||||
# Monitors a file system, blocks and inode usage against watermarks
|
||||
# The script is called with fsmon as the first argument and there
|
||||
# are two environment variables FSMON_NAME, for the monitored path,
|
||||
# and FSMON_TYPE indicating either 'blocks' or 'inodes'.
|
||||
fsmon /var {
|
||||
enabled = true
|
||||
interval = 3600
|
||||
logmark = true
|
||||
warning = 0.95
|
||||
critical = 1.0
|
||||
# script = "/path/to/alt-reboot-action.sh"
|
||||
}
|
||||
|
||||
fsmon /tmp {
|
||||
enabled = true
|
||||
interval = 3600
|
||||
logmark = true
|
||||
warning = 0.95
|
||||
critical = 1.0
|
||||
# script = "/path/to/alt-reboot-action.sh"
|
||||
}
|
||||
|
||||
# Monitors load average based on sysinfo() from /proc/loadavg
|
||||
# The level is composed from the average of the 1 and 5 min marks.
|
||||
#loadavg {
|
||||
# enabled = true
|
||||
# interval = 300
|
||||
# logmark = true
|
||||
# warning = 1.0
|
||||
# critical = 2.0
|
||||
# script = "/path/to/alt-reboot-action.sh"
|
||||
#}
|
||||
|
||||
# Monitors free RAM based on data from /proc/meminfo
|
||||
meminfo {
|
||||
enabled = true
|
||||
interval = 3600
|
||||
logmark = true
|
||||
warning = 0.9
|
||||
critical = 0.97
|
||||
# script = "/path/to/alt-reboot-action.sh"
|
||||
}
|
||||
|
||||
# Monitor temperature. The critical value is unset by default, so no
|
||||
# action is taken at that watermark (by default). Both the critical and
|
||||
# warning watermarks are relative to the trip/critical/max value from
|
||||
# sysfs. The warning is default 0.9, i.e., 90% of critical. Use script
|
||||
# to to reset the fan controller or poweroff(8) the system.
|
||||
#
|
||||
# Each temp monitor caches the last 10 values, calculates the mean, and
|
||||
# compares that to the warning and critical levels. Logging is only
|
||||
# done every 10 x interval (if enabled).
|
||||
#tempmon /sys/class/hwmon/hwmon0/temp1_input {
|
||||
# enabled = true
|
||||
# interval = 30
|
||||
# warning = 0.9
|
||||
# critical = 0.95
|
||||
# logmark = true
|
||||
# script = "/script/to/log/and/poweroff.sh"
|
||||
#}
|
||||
|
||||
# Monitor a generic script, executes 'monitor-script' every 'interval'
|
||||
# seconds, with a max runtime of 'timeout' seconds. When the exit code
|
||||
# of the monitor script is above the critical level watchdogd either
|
||||
# starts the reboot, or calls the alternate 'script' to determin the
|
||||
# next cause of action.
|
||||
#generic /path/to/monitor-script.sh {
|
||||
# enabled = true
|
||||
# interval = 300
|
||||
# timeout = 60
|
||||
# warning = 1
|
||||
# critical = 10
|
||||
# script = "/path/to/alt-reboot-action.sh"
|
||||
#}
|
||||
@@ -21,7 +21,11 @@ dir()
|
||||
if [ -d "$1" ]; then
|
||||
dir "$1"
|
||||
else
|
||||
dir "$HOME"
|
||||
if [ "$USER" = "root" ]; then
|
||||
dir "$HOME"
|
||||
else
|
||||
dir "/home/$USER"
|
||||
fi
|
||||
dir "/cfg"
|
||||
dir "/log"
|
||||
fi
|
||||
|
||||
@@ -70,12 +70,14 @@ options:
|
||||
-p Show plain output, no bells or whistles
|
||||
|
||||
commands:
|
||||
dhcp Show DHCP server
|
||||
port PORT Show port configuration and link information
|
||||
ports Show ports available for bridging
|
||||
vlans Show port groups in bridge
|
||||
ifaces Show interfaces and their addresses
|
||||
fdb Show forwarding database (unicast)
|
||||
mdb Show multicast forwarding database
|
||||
stp Show spanning tree status
|
||||
ip addr Show IPv4 addresses
|
||||
route Show routing table
|
||||
ipv6 addr Show IPv6 addresses
|
||||
@@ -87,6 +89,41 @@ commands:
|
||||
EOF
|
||||
}
|
||||
|
||||
is_dhcp_running()
|
||||
{
|
||||
sysrepocfg -X -f json -m infix-dhcp-server | jq -r '
|
||||
."infix-dhcp-server:dhcp-server".enabled as $global |
|
||||
if ."infix-dhcp-server:dhcp-server".subnet? then
|
||||
(."infix-dhcp-server:dhcp-server".subnet[] |
|
||||
select(.enabled != false)) |
|
||||
if $global != false and . then "true" else "false" end
|
||||
else "false" end
|
||||
' 2>/dev/null | grep -q true
|
||||
}
|
||||
|
||||
dhcp()
|
||||
{
|
||||
if ! is_dhcp_running; then
|
||||
echo "DHCP server not enabled."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
case $1 in
|
||||
detail)
|
||||
sysrepocfg -f json -X -d operational -m infix-dhcp-server | \
|
||||
jq -C .
|
||||
;;
|
||||
stat*)
|
||||
sysrepocfg -f json -X -d operational -m infix-dhcp-server | \
|
||||
/usr/libexec/statd/cli-pretty "show-dhcp-server" -s
|
||||
;;
|
||||
*)
|
||||
sysrepocfg -f json -X -d operational -m infix-dhcp-server | \
|
||||
/usr/libexec/statd/cli-pretty "show-dhcp-server"
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
# Usage 1: show port eth0
|
||||
# Usage 2: show port
|
||||
# Usage 3: show ports
|
||||
@@ -188,6 +225,12 @@ rstp()
|
||||
mstpctl showport br0
|
||||
}
|
||||
|
||||
stp()
|
||||
{
|
||||
sysrepocfg -f json -X -d operational -m ietf-interfaces | \
|
||||
/usr/libexec/statd/cli-pretty "show-bridge-stp"
|
||||
}
|
||||
|
||||
fdb()
|
||||
{
|
||||
bridge $bopt fdb show
|
||||
@@ -288,6 +331,9 @@ case $cmd in
|
||||
help)
|
||||
usage
|
||||
;;
|
||||
dhcp | dhcp-server)
|
||||
dhcp $*
|
||||
;;
|
||||
port*)
|
||||
ports $*
|
||||
;;
|
||||
@@ -353,6 +399,9 @@ case $cmd in
|
||||
span*)
|
||||
rstp
|
||||
;;
|
||||
stp*)
|
||||
stp
|
||||
;;
|
||||
sys*)
|
||||
system
|
||||
;;
|
||||
@@ -0,0 +1,12 @@
|
||||
#!/bin/sh
|
||||
if [ $# -lt 2 ]; then
|
||||
echo "usage: $0 <quirk-name> <ifname>"
|
||||
exit 1
|
||||
fi
|
||||
quirk=$1
|
||||
ifname=$2
|
||||
if [ -f "/etc/product/interface-quirks.json" ]; then
|
||||
echo "$(jq -r --arg iface "$ifname" --arg quirk "$quirk" '.[$iface][$quirk] // "false"' /etc/product/interface-quirks.json)"
|
||||
else
|
||||
echo "false"
|
||||
fi
|
||||
@@ -308,16 +308,52 @@ def probe_qemusystem(out):
|
||||
subprocess.run("initctl -nbq cond set qemu".split(), check=False)
|
||||
return 0
|
||||
|
||||
def rasberry_pi_4_usb_ports(out):
|
||||
out["usb-ports"] = [
|
||||
{
|
||||
"name": "USB",
|
||||
"path": "/sys/devices/platform/scb/fd500000.pcie/pci0000:00/0000:00:00.0/0000:01:00.0/usb1/authorized"
|
||||
},
|
||||
{
|
||||
"name": "USB",
|
||||
"path": "/sys/devices/platform/scb/fd500000.pcie/pci0000:00/0000:00:00.0/0000:01:00.0/usb1/authorized_default"
|
||||
},
|
||||
{
|
||||
"name": "USB",
|
||||
"path": "/sys/devices/platform/scb/fd500000.pcie/pci0000:00/0000:00:00.0/0000:01:00.0/usb1/1-1/authorized",
|
||||
},
|
||||
{
|
||||
"name": "USB",
|
||||
"path": "/sys/devices/platform/scb/fd500000.pcie/pci0000:00/0000:00:00.0/0000:01:00.0/usb1/1-0:1.0/authorized"
|
||||
},
|
||||
{
|
||||
"name": "USB",
|
||||
"path": "/sys/devices/platform/scb/fd500000.pcie/pci0000:00/0000:00:00.0/0000:01:00.0/usb2/authorized"
|
||||
},
|
||||
{
|
||||
"name": "USB",
|
||||
"path": "/sys/devices/platform/scb/fd500000.pcie/pci0000:00/0000:00:00.0/0000:01:00.0/usb2/authorized_default"
|
||||
},
|
||||
{
|
||||
"name": "USB3",
|
||||
"path": "/sys/devices/platform/scb/fd500000.pcie/pci0000:00/0000:00:00.0/0000:01:00.0/usb2/2-0:1.0/authorized"
|
||||
}
|
||||
]
|
||||
|
||||
def probe_dtsystem(out):
|
||||
"""Probe DTS based system, expects a VPD in ONIE PROM format."""
|
||||
dtsys = DTSystem()
|
||||
vpds = dtsys.infix_vpds()
|
||||
dtsys.infix_usb_devices(out)
|
||||
|
||||
model = dtsys.base.str("model")
|
||||
if model:
|
||||
out["product-name"] = model
|
||||
|
||||
# Since rpi4 has USB on PCIe, there is no phandle reference
|
||||
if model and model.startswith("Raspberry Pi 4"):
|
||||
rasberry_pi_4_usb_ports(out)
|
||||
else:
|
||||
dtsys.infix_usb_devices(out)
|
||||
out["compatible"] = dtsys.base.str_array("compatible")
|
||||
|
||||
staticpw = dtsys.infix.str("factory-password-hash")
|
||||
|
||||
@@ -39,8 +39,10 @@ fi
|
||||
# init scripts to prevent select services from starting.
|
||||
initctl -nbq cond set led
|
||||
|
||||
note "Calling runparts $PRODUCT_INIT/S[0-9]+.* start"
|
||||
/usr/libexec/finit/runparts -bsp "$PRODUCT_INIT"
|
||||
if [ -d "$PRODUCT_INIT" ]; then
|
||||
note "Calling runparts $PRODUCT_INIT/S[0-9]+.* start"
|
||||
/usr/libexec/finit/runparts -bsp "$PRODUCT_INIT"
|
||||
fi
|
||||
|
||||
# Product specific init done.
|
||||
initctl -nbq cond set product
|
||||
|
||||
@@ -43,6 +43,7 @@ while [ "$1" ]; do
|
||||
txqs="$2"
|
||||
shift 2
|
||||
|
||||
[ $(/usr/libexec/infix/has-quirk "broken-mqprio" "$iface") = "true" ] && echo "Skipping $iface, does not support mqprio" && continue
|
||||
[ $txqs -lt 2 ] && continue
|
||||
[ $txqs -gt 8 ] && txqs=8
|
||||
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
#!/bin/sh
|
||||
# Initialize speed/duplex of virtio interfaces
|
||||
# For virtual test systems (lacp tests)
|
||||
|
||||
ifaces=$(ip -d -json link show | jq -r '.[] | select(.parentbus == "virtio") | .ifname')
|
||||
for iface in $ifaces; do
|
||||
ethtool -s "$iface" speed 1000 duplex full
|
||||
done
|
||||
@@ -4,10 +4,14 @@
|
||||
# the migrate tool inserts old version in name before .cfg extension.
|
||||
CONFIG_FILE="/cfg/startup-config.cfg"
|
||||
BACKUP_FILE="/cfg/backup/startup-config.cfg"
|
||||
mkdir -p "$(dirname "$BACKUP_FILE")"
|
||||
BACKUP_DIR="$(dirname "$BACKUP_FILE")"
|
||||
|
||||
mkdir -p "$BACKUP_DIR"
|
||||
chown root:wheel "$BACKUP_DIR"
|
||||
chmod 0770 "$BACKUP_DIR"
|
||||
|
||||
if [ ! -f "$CONFIG_FILE" ]; then
|
||||
note "No $(basename "$CONFIG_FILE" .cfg) yet, likely factory reset."
|
||||
logger -I $$ -k -p user.notice -t $(basename "$0") "No $(basename "$CONFIG_FILE" .cfg) yet, likely factory reset."
|
||||
exit 0
|
||||
elif migrate -cq "$CONFIG_FILE"; then
|
||||
exit 0
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
#!/bin/bash
|
||||
# Store and convert RSA PUBLIC/PRIVATE KEYs to be able to use them in
|
||||
# OpenSSHd.
|
||||
set -e
|
||||
|
||||
NAME="$1"
|
||||
DIR="$2"
|
||||
PUBLIC="$3"
|
||||
PRIVATE="$4"
|
||||
TMP="$(mktemp)"
|
||||
|
||||
echo -e '-----BEGIN RSA PRIVATE KEY-----' > "$DIR/$NAME"
|
||||
echo "$PRIVATE" >> "$DIR/$NAME"
|
||||
echo -e '-----END RSA PRIVATE KEY-----' >> "$DIR/$NAME"
|
||||
|
||||
echo -e "-----BEGIN RSA PUBLIC KEY-----" > "$TMP"
|
||||
echo -e "$PUBLIC" >> "$TMP"
|
||||
echo -e "-----END RSA PUBLIC KEY-----" >> "$TMP"
|
||||
|
||||
ssh-keygen -i -m PKCS8 -f "$TMP" > "$DIR/$NAME.pub"
|
||||
chmod 0600 "$DIR/$NAME.pub"
|
||||
chmod 0600 "$DIR/$NAME"
|
||||
chown sshd:sshd "$DIR/$NAME.pub"
|
||||
chown sshd:sshd "$DIR/$NAME"
|
||||
@@ -0,0 +1,16 @@
|
||||
#!/bin/sh
|
||||
|
||||
if [ $# -ne 1 ]; then
|
||||
echo "usage: $0 <ifname>"
|
||||
exit 1
|
||||
fi
|
||||
ifname=$1
|
||||
|
||||
TIMEOUT=300
|
||||
status=$(wpa_cli -i $ifname scan)
|
||||
while [ "$status" != "OK" ]; do
|
||||
status=$(wpa_cli -i $ifname scan)
|
||||
TIMEOUT=$((TIMEOUT-1))
|
||||
[ $TIMEOUT -eq 0 ] && logger -t wifi-scanner "Failed to start scanning $ifname" && exit 1
|
||||
sleep 0.5
|
||||
done
|
||||
@@ -1,4 +1,4 @@
|
||||
#!/bin/sh
|
||||
#!/bin/bash
|
||||
# This script can be used to start, stop, create, and delete containers.
|
||||
# It is what confd use, with the Finit container@.conf template, to set
|
||||
# up, run, and delete containers.
|
||||
@@ -8,7 +8,8 @@
|
||||
#
|
||||
DOWNLOADS=/var/lib/containers/oci
|
||||
BUILTIN=/lib/oci
|
||||
TMPDIR=/var/tmp
|
||||
BASEDIR=/var/tmp
|
||||
container=$0
|
||||
checksum=""
|
||||
extracted=
|
||||
timeout=30
|
||||
@@ -28,16 +29,21 @@ err()
|
||||
rc=$1; shift
|
||||
logger -I $PPID -t container -p local1.err -- "Error: $*"
|
||||
|
||||
if [ -n "$extracted" ]; then
|
||||
if [ -d "$TMPDIR/$dir" ]; then
|
||||
log "Cleaning up extracted $dir"
|
||||
rm -rf "$dir"
|
||||
if [ -n "$extracted" ] && [ -n "$tmpdir" ]; then
|
||||
if [ -d "$tmpdir" ]; then
|
||||
log "Cleaning up temporary directory $tmpdir"
|
||||
rm -rf "$tmpdir"
|
||||
fi
|
||||
fi
|
||||
|
||||
[ "$rc" -eq 0 ] || exit "$rc"
|
||||
}
|
||||
|
||||
pidfn()
|
||||
{
|
||||
echo "/run/containers/${1}.pid"
|
||||
}
|
||||
|
||||
check()
|
||||
{
|
||||
file=$1
|
||||
@@ -104,38 +110,40 @@ EOF
|
||||
return 1
|
||||
}
|
||||
|
||||
# Unpacks a given oci-archive.tar[.gz] in the current directory. Sanity
|
||||
# checks, at least one index.json in the top-level dir of the archive.
|
||||
# If there are more index files, this function does not handle them.
|
||||
unpack_archive()
|
||||
# Extracts an oci-archive.tar[.gz] in a temporary directory. Finds and
|
||||
# sanity checks that at least one index.json exist in the archive. This
|
||||
# is the OCI directory fed to `podman load` and also used as repo name.
|
||||
# NOTE: if there are >1 index.json, this function does not handle them.
|
||||
load_archive()
|
||||
{
|
||||
image=$1
|
||||
name=$2
|
||||
uri=$1
|
||||
tag=$2
|
||||
img=$(basename "$uri")
|
||||
|
||||
# Supported transports for load and create
|
||||
case "$image" in
|
||||
case "$uri" in
|
||||
oci:*) # Unpacked OCI image
|
||||
file=${image#oci:}
|
||||
file=${uri#oci:}
|
||||
;;
|
||||
oci-archive:*) # Packed OCI image, .tar or .tar.gz format
|
||||
file=${image#oci-archive:}
|
||||
file=${uri#oci-archive:}
|
||||
;;
|
||||
ftp://* | http://* | https://*)
|
||||
if ! file=$(fetch "$image"); then
|
||||
if ! file=$(fetch "$uri"); then
|
||||
return 1
|
||||
fi
|
||||
;;
|
||||
*) # docker://*, docker-archive:*, or URL
|
||||
if podman image exists "$image"; then
|
||||
echo "$image"
|
||||
if podman image exists "$img"; then
|
||||
echo "$img"
|
||||
return 0
|
||||
fi
|
||||
# XXX: use --retry=0 with Podman 5.0 or later.
|
||||
if ! id=$(podman pull --quiet "$image"); then
|
||||
log "Failed pulling $image"
|
||||
if ! id=$(podman pull --quiet "$uri"); then
|
||||
log "Failed pulling $uri"
|
||||
return 1
|
||||
fi
|
||||
# Echo image name to caller
|
||||
# Echo image tag to caller
|
||||
podman images --filter id="$id" --format "{{.Repository}}:{{.Tag}}"
|
||||
return 0
|
||||
;;
|
||||
@@ -147,62 +155,94 @@ unpack_archive()
|
||||
elif [ -e "$BUILTIN/$file" ]; then
|
||||
file="$BUILTIN/$file"
|
||||
else
|
||||
err 1 "cannot find OCI archive $file in search path."
|
||||
err 1 "cannot find OCI archive $file in URI $uri"
|
||||
fi
|
||||
fi
|
||||
|
||||
file=$(realpath "$file")
|
||||
if [ -d "$file" ]; then
|
||||
index=$(find "$file" -name index.json)
|
||||
if [ -z "$index" ]; then
|
||||
err 1 "cannot find index.json in OCI image $file"
|
||||
fi
|
||||
else
|
||||
cd "$TMPDIR" || err 0 "failed cd $TMPDIR, wiill use $(pwd) for OCI archive extraction."
|
||||
# Extract files in a temporary directory, because most OCI
|
||||
# archives are flat/bare, all files in the root w/o a dir/
|
||||
tmpdir=$(mktemp -d -p "$BASEDIR") || err 1 "failed creating temporary directory"
|
||||
cd "$tmpdir" || err 1 "failed cd to temporary directory $tmpdir"
|
||||
|
||||
index=$(tar tf "$file" |grep index.json)
|
||||
index="$tmpdir/$(tar tf "$file" |grep index.json)"
|
||||
if [ -z "$index" ]; then
|
||||
err 1 "invalid OCI archive, cannot find index.json in $file"
|
||||
fi
|
||||
|
||||
[ -n "$quiet" ] || log "Extracting OCI archive $file ..."
|
||||
tar xf "$file" || err 1 "failed unpacking $file in $(pwd)"
|
||||
tar xf "$file" || err 1 "failed unpacking $file in $tmpdir"
|
||||
extracted=true
|
||||
cd - >/dev/null || err 0 "failed cd -"
|
||||
fi
|
||||
|
||||
dir=$(dirname "$index")
|
||||
if echo "$dir" | grep -q ":"; then
|
||||
if [ -z "$name" ]; then
|
||||
name="$dir"
|
||||
|
||||
# Handle flat tarballs without a sub-directory, because
|
||||
# the $dir name is used as fallback when retagging below.
|
||||
if [ -n "$extracted" ] && [ "$dir" = "$tmpdir" ]; then
|
||||
parent=$(dirname "$dir")
|
||||
dirnam=$(echo "$img" | sed 's/\(.*\)\.tar.*/\1/')
|
||||
tmpdir="${parent}/${dirnam}"
|
||||
mv "$dir" "$tmpdir"
|
||||
dir="$tmpdir"
|
||||
fi
|
||||
|
||||
if basename "$dir" | grep -q ":"; then
|
||||
if [ -z "$tag" ]; then
|
||||
tag=$(basename "$dir")
|
||||
fi
|
||||
|
||||
sanitized_dir=$(echo "$dir" | cut -d':' -f1)
|
||||
mv "$dir" "$sanitized_dir" || err 1 "failed renaming $dir to $sanitized_dir"
|
||||
dir="$sanitized_dir"
|
||||
fi
|
||||
|
||||
[ -n "$quiet" ] || log "Loading OCI image $dir ..."
|
||||
podman load -qi "$dir" >/dev/null
|
||||
output=$(podman load -qi "$dir")
|
||||
|
||||
# Extract image ID from podman load output:
|
||||
# "Loaded image: sha256:cd9d0aaf81be..."
|
||||
if echo "$output" | grep -q "sha256:"; then
|
||||
img_id="${output##*sha256:}"
|
||||
else
|
||||
# Fallback to directory name if no SHA found
|
||||
img_id="$dir"
|
||||
fi
|
||||
|
||||
# On podman < 4.7.0 we had to retag images from default $dir:latest
|
||||
# From >= 4.7.0 we always tag since loads come in as <none>:<none>
|
||||
if [ -z "$tag" ]; then
|
||||
tag=$(basename "$dir")
|
||||
fi
|
||||
|
||||
# Repo names must be lowercase, and only '[a-z0-9._/-]+' and ':tag'
|
||||
tag=$(printf "%s" "$tag" | tr '[:upper:]' '[:lower:]' | tr -c 'a-z0-9._/:-' '-')
|
||||
|
||||
[ -n "$quiet" ] || log "Tagging loaded image $img_id as $tag"
|
||||
if ! podman tag "$img_id" "$tag"; then
|
||||
err 1 "failed tagging image as $tag"
|
||||
fi
|
||||
|
||||
# Clean up after ourselves
|
||||
if [ -n "$extracted" ]; then
|
||||
log "Cleaning up extracted $dir"
|
||||
rm -rf "$dir"
|
||||
rm -rf "$tmpdir"
|
||||
fi
|
||||
|
||||
# Rename image from podman default $dir:latest
|
||||
if [ -n "$name" ]; then
|
||||
podman tag "$dir" "$name" >/dev/null
|
||||
podman rmi "$dir" >/dev/null
|
||||
else
|
||||
name=$dir
|
||||
fi
|
||||
|
||||
echo "$name"
|
||||
echo "$tag"
|
||||
}
|
||||
|
||||
running()
|
||||
{
|
||||
run=$(podman inspect "$1" 2>/dev/null |jq .[].State.Running)
|
||||
[ "$run" = "true" ] && return 0
|
||||
status=$(podman inspect -f '{{.State.Status}}' "$1" 2>/dev/null)
|
||||
[ "$status" = "running" ] && return 0
|
||||
return 1
|
||||
}
|
||||
|
||||
@@ -221,19 +261,19 @@ create()
|
||||
|
||||
# Unpack and load docker-archive/oci/oci-archive, returning image
|
||||
# name, or return docker:// URL for download.
|
||||
if ! image=$(unpack_archive "$image"); then
|
||||
if ! image=$(load_archive "$image"); then
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [ -z "$logging" ]; then
|
||||
logging="--log-driver none"
|
||||
logging="--log-driver syslog"
|
||||
fi
|
||||
|
||||
# When we get here we've already fetched, or pulled, the image
|
||||
args="$args --read-only --replace --quiet --cgroup-parent=containers $caps"
|
||||
args="$args --restart=$restart --systemd=false --tz=local $privileged"
|
||||
args="$args $vol $mount $hostname $entrypoint $env $port $logging"
|
||||
pidfn=/run/container:${name}.pid
|
||||
pidfile=/run/container:${name}.pid
|
||||
|
||||
[ -n "$quiet" ] || log "---------------------------------------"
|
||||
[ -n "$quiet" ] || log "Got name: $name image: $image"
|
||||
@@ -256,8 +296,8 @@ create()
|
||||
fi
|
||||
|
||||
# shellcheck disable=SC2048
|
||||
log "podman create --name $name --conmon-pidfile=$pidfn $args $image $*"
|
||||
if podman create --name "$name" --conmon-pidfile="$pidfn" $args "$image" $*; then
|
||||
log "podman create --name $name --conmon-pidfile=$pidfile $args $image $*"
|
||||
if podman create --name "$name" --conmon-pidfile="$pidfile" $args "$image" $*; then
|
||||
[ -n "$quiet" ] || log "Successfully created container $name from $image"
|
||||
[ -n "$manual" ] || start "$name"
|
||||
|
||||
@@ -272,7 +312,6 @@ create()
|
||||
delete()
|
||||
{
|
||||
name=$1
|
||||
image=$2
|
||||
|
||||
if [ -z "$name" ]; then
|
||||
echo "Usage:"
|
||||
@@ -281,9 +320,10 @@ delete()
|
||||
fi
|
||||
|
||||
# Should already be stopped, but if not ...
|
||||
container stop "$name"
|
||||
container stop "$name" >/dev/null
|
||||
|
||||
while running "$name"; do
|
||||
log "$name: still running, waiting for it to stop ..."
|
||||
_=$((timeout -= 1))
|
||||
if [ $timeout -le 0 ]; then
|
||||
err 1 "timed out waiting for container $1 to stop before deleting it."
|
||||
@@ -293,6 +333,9 @@ delete()
|
||||
|
||||
podman rm -vif "$name" >/dev/null 2>&1
|
||||
[ -n "$quiet" ] || log "Container $name has been removed."
|
||||
|
||||
cnt=$(podman image prune -af | wc -l)
|
||||
log "Pruned $cnt image(s)"
|
||||
}
|
||||
|
||||
waitfor()
|
||||
@@ -315,7 +358,7 @@ start()
|
||||
return
|
||||
fi
|
||||
|
||||
initctl -bq cond set "container:$name"
|
||||
initctl start container:$name
|
||||
# Real work is done by wrap() courtesy of finit sysv emulation
|
||||
}
|
||||
|
||||
@@ -328,7 +371,7 @@ stop()
|
||||
return
|
||||
fi
|
||||
|
||||
initctl -bq cond clr "container:$name"
|
||||
initctl stop container:$name
|
||||
# Real work is done by wrap() courtesy of finit sysv emulation
|
||||
}
|
||||
|
||||
@@ -336,8 +379,27 @@ wrap()
|
||||
{
|
||||
name=$1
|
||||
cmd=$2
|
||||
pidfile=$(pidfn "$name")
|
||||
|
||||
podman "$cmd" "$name"
|
||||
# Containers have three phases: setup, running, and teardown.
|
||||
|
||||
# The setup phase may run forever in the background trying to fetch
|
||||
# the image. It saves its PID in /run/containers/${name}.pid
|
||||
if [ "$cmd" = "stop" ] && [ -f "$pidfile" ]; then
|
||||
pid=$(cat "$pidfile")
|
||||
|
||||
# Check if setup is still running ...
|
||||
if kill -0 "$pid" 2>/dev/null; then
|
||||
kill "$pid"
|
||||
wait "$pid" 2>/dev/null
|
||||
fi
|
||||
|
||||
rm -f "$pidfile"
|
||||
return 0
|
||||
fi
|
||||
|
||||
# Skip "echo $name" from podman start in log
|
||||
podman "$cmd" "$name" >/dev/null
|
||||
}
|
||||
|
||||
# Removes network $1 from all containers
|
||||
@@ -370,7 +432,14 @@ netrestart()
|
||||
|
||||
cleanup()
|
||||
{
|
||||
pidfile=$(pidfn "$name")
|
||||
|
||||
log "Received signal, exiting."
|
||||
if [ -n "$name" ] && [ -f "$pidfile" ]; then
|
||||
log "$name: in setup phase, removing $pidfile ..."
|
||||
rm -f "$pidfile"
|
||||
fi
|
||||
|
||||
exit 1
|
||||
}
|
||||
|
||||
@@ -407,7 +476,7 @@ options:
|
||||
-q, --quiet Quiet operation, called from confd
|
||||
-r, --restart POLICY One of "no", "always", or "on-failure:NUM"
|
||||
-s, --simple Show output in simplified format
|
||||
-t, --timeout SEC Set timeout for delete/restart commands, default: 20
|
||||
-t, --timeout SEC Set timeout for delete/restart commands, default: 30
|
||||
-v, --volume NAME:PATH Create named volume mounted inside container on PATH
|
||||
|
||||
commands:
|
||||
@@ -426,11 +495,12 @@ commands:
|
||||
run NAME [CMD] Run a container interactively, with an optional command
|
||||
save IMAGE FILE Save a container image to an OCI tarball FILE[.tar.gz]
|
||||
setup NAME Create and set up container as a Finit task
|
||||
shell Start a shell inside a container
|
||||
shell [CMD] Start a shell, or run CMD, inside a container
|
||||
show [image | volume] Show containers, images, or volumes
|
||||
stat Show continuous stats about containers (Ctrl-C aborts)
|
||||
start [NAME] Start a container, see -n
|
||||
stop [NAME] Stop a container, see -n
|
||||
upgrade NAME Upgrade a running container (stop, pull, restart)
|
||||
volume [prune] Prune unused volumes
|
||||
EOF
|
||||
}
|
||||
@@ -514,7 +584,7 @@ while [ "$1" != "" ]; do
|
||||
;;
|
||||
-m | --mount)
|
||||
shift
|
||||
mount="--mount=$1"
|
||||
mount="$mount --mount=$1"
|
||||
;;
|
||||
--manual)
|
||||
manual=true
|
||||
@@ -568,7 +638,7 @@ if [ -n "$cmd" ]; then
|
||||
shift
|
||||
fi
|
||||
|
||||
trap cleanup INT TERM
|
||||
trap cleanup INT HUP TERM
|
||||
|
||||
case $cmd in
|
||||
# Does not work atm., cannot attach to TTY because
|
||||
@@ -582,19 +652,24 @@ case $cmd in
|
||||
;;
|
||||
delete)
|
||||
cmd=$1
|
||||
name=$2
|
||||
[ -n "$name" ] || name=$2
|
||||
if [ "$cmd" = "network" ] && [ -n "$name" ]; then
|
||||
netwrm "$name"
|
||||
else
|
||||
delete "$@"
|
||||
[ -n "$name" ] || name=$1
|
||||
delete "$name"
|
||||
fi
|
||||
;;
|
||||
exec)
|
||||
podman exec -it "$@"
|
||||
if [ -z "$name" ]; then
|
||||
name="$1"
|
||||
shift
|
||||
fi
|
||||
podman exec -i "$name" "$@"
|
||||
;;
|
||||
flush)
|
||||
echo "Cleaning up any lingering containers";
|
||||
podman rm -av
|
||||
podman rm -av $force
|
||||
;;
|
||||
find)
|
||||
cmd=$1
|
||||
@@ -622,7 +697,7 @@ case $cmd in
|
||||
;;
|
||||
load)
|
||||
# shellcheck disable=SC2086
|
||||
name=$(unpack_archive "$1" $2)
|
||||
name=$(load_archive "$1" $2)
|
||||
[ -n "$name" ] || exit 1
|
||||
|
||||
# Show resulting image(s) matching $name
|
||||
@@ -655,7 +730,7 @@ case $cmd in
|
||||
oci)
|
||||
find $BUILTIN $DOWNLOADS -type f 2>/dev/null
|
||||
;;
|
||||
*)
|
||||
*)
|
||||
podman ps $all --format "{{.Names}}"
|
||||
;;
|
||||
esac
|
||||
@@ -699,18 +774,40 @@ case $cmd in
|
||||
[ -n "$name" ] || err 1 "setup: missing container name."
|
||||
script=/run/containers/${name}.sh
|
||||
[ -x "$script" ] || err 1 "setup: $script does not exist or is not executable."
|
||||
|
||||
# Save our PID in case we get stuck here and someone wants to
|
||||
# stop us, e.g., due to reconfiguration or reboot.
|
||||
pidfile=$(pidfn "${name}")
|
||||
echo $$ > "$pidfile"
|
||||
|
||||
while ! "$script"; do
|
||||
# Wait for address/route changes, or retry every 60 secods
|
||||
# shellcheck disable=2162,3045
|
||||
ip monitor address route | while read -t 60 _; do break; done
|
||||
log "${name}: setup failed, waiting for network changes ..."
|
||||
|
||||
# Timeout and retry after 60 seconds, on SIGTERM, or when
|
||||
# any network event is caught.
|
||||
timeout -s TERM -k 1 60 sh -c \
|
||||
'ip monitor address route 2>/dev/null | head -n1 >/dev/null' || true
|
||||
|
||||
# On IP address/route changes, wait a few seconds more to ensure
|
||||
# the system has ample time to react and set things up for us.
|
||||
log "${name}: retrying ..."
|
||||
sleep 2
|
||||
done
|
||||
|
||||
rm -f "$pidfile"
|
||||
cnt=$(podman image prune -f | wc -l)
|
||||
log "setup: pruned $cnt image(s)"
|
||||
;;
|
||||
shell)
|
||||
podman exec -it "$1" sh -l
|
||||
if [ -z "$name" ]; then
|
||||
name="$1"
|
||||
shift
|
||||
fi
|
||||
if [ $# -gt 0 ]; then
|
||||
podman exec -i "$name" sh -c "$*"
|
||||
else
|
||||
podman exec -it "$name" sh -l
|
||||
fi
|
||||
;;
|
||||
show)
|
||||
cmd=$1
|
||||
@@ -803,15 +900,15 @@ case $cmd in
|
||||
|
||||
# Likely an OCI archive, or local directory, assume user has updated image.
|
||||
if echo "$img" | grep -Eq '^localhost/'; then
|
||||
file=$(awk '{s=$NF} END{print s}' "$script")
|
||||
echo "Upgrading container ${1} with local archive: $file ..."
|
||||
file=$(awk '/^# meta-image:/ {print $3}' "$script")
|
||||
echo ">> Upgrading container $1 using $file ..."
|
||||
else
|
||||
printf ">> Stopping ... "
|
||||
podman stop "$1"
|
||||
printf ">> "
|
||||
podman pull "$img" || (echo "Failed fetching $img, check your network (settings)."; exit 1)
|
||||
echo ">> Starting $1 ..."
|
||||
fi
|
||||
echo ">> Starting $1 ..."
|
||||
if ! "$script"; then
|
||||
echo ">> Failed recreating container $1"
|
||||
exit 1
|
||||
@@ -831,6 +928,22 @@ case $cmd in
|
||||
esac
|
||||
;;
|
||||
*)
|
||||
if [ -n "$SERVICE_SCRIPT_TYPE" ] && [ -n "$SERVICE_ID" ]; then
|
||||
case "$SERVICE_SCRIPT_TYPE" in
|
||||
pre)
|
||||
# Called as pre-script from Finit service
|
||||
exec $container -q -n "$SERVICE_ID" setup
|
||||
;;
|
||||
cleanup)
|
||||
# Called as cleanup-script from Finit service
|
||||
log "Calling $container -n $SERVICE_ID delete"
|
||||
exec $container -q -n "$SERVICE_ID" delete
|
||||
;;
|
||||
*)
|
||||
false
|
||||
;;
|
||||
esac
|
||||
fi
|
||||
usage
|
||||
exit 1
|
||||
;;
|
||||
|
||||
@@ -20,7 +20,6 @@ CONFIG_CMD_SETEXPR_FMT=y
|
||||
|
||||
CONFIG_MMC=y
|
||||
CONFIG_MMC_SDHCI=y
|
||||
CONFIG_MMC_PCI=y
|
||||
CONFIG_CMD_MMC=y
|
||||
|
||||
CONFIG_FS_SQUASHFS=y
|
||||
|
||||
@@ -17,14 +17,23 @@ endef
|
||||
# U-Boot build tree. This will then be built in to the final U-Boot
|
||||
# image's control DT via the CONFIG_DEVICE_TREE_INCLUDES option (see
|
||||
# extras.config).
|
||||
#
|
||||
# Some platforms, most notably Raspberry Pi, load the device tree
|
||||
# from the SPL, effectively overriding the built-in control DT.
|
||||
# For that we bundle an overlay that can be included instead.
|
||||
define UBOOT_PRE_BUILD_INSTALL_KEY
|
||||
$(HOST_DIR)/bin/dtc <(echo '/dts-v1/; / { signature {}; };') >$(@D)/infix-key.dtb
|
||||
$(HOST_DIR)/bin/dtc -a 1024 <(echo '/dts-v1/; / { signature {}; };') \
|
||||
>$(@D)/infix-key.dtb
|
||||
$(foreach key, \
|
||||
$(call qstrip,$(TRUSTED_KEYS_DEVELOPMENT_PATH)) $(call qstrip,$(TRUSTED_KEYS_EXTRA_PATH)),\
|
||||
$(call uboot-add-pubkey,$(key),$(@D)/infix-key.dtb))
|
||||
$(HOST_DIR)/bin/dtc -I dtb -O dts \
|
||||
<$(@D)/infix-key.dtb \
|
||||
| sed -e 's:/dts-v[0-9]\+/;::' >$(@D)/arch/$(UBOOT_ARCH)/dts/infix-key.dtsi
|
||||
| sed -e 's:/dts-v[0-9]\+/;::' \
|
||||
| tee $(@D)/arch/$(UBOOT_ARCH)/dts/infix-key.dtsi \
|
||||
| sed -e '1i\/dts-v1/;\n/plugin/;\n' -e '/^$$/d' -e 's:/ {:\&{/} {:' \
|
||||
>$(@D)/arch/$(UBOOT_ARCH)/dts/infix-key.dtso
|
||||
|
||||
rm $(@D)/infix-key.dtb
|
||||
endef
|
||||
UBOOT_PRE_BUILD_HOOKS += UBOOT_PRE_BUILD_INSTALL_KEY
|
||||
|
||||
@@ -461,8 +461,16 @@ CONFIG_DEBUG_FS=y
|
||||
# CONFIG_SLUB_DEBUG is not set
|
||||
CONFIG_DEBUG_RODATA_TEST=y
|
||||
CONFIG_DEBUG_WX=y
|
||||
CONFIG_SOFTLOCKUP_DETECTOR=y
|
||||
CONFIG_PANIC_ON_OOPS=y
|
||||
CONFIG_PANIC_TIMEOUT=20
|
||||
CONFIG_BOOTPARAM_SOFTLOCKUP_PANIC=y
|
||||
CONFIG_HARDLOCKUP_DETECTOR=y
|
||||
CONFIG_HARDLOCKUP_DETECTOR_PREFER_BUDDY=y
|
||||
CONFIG_BOOTPARAM_HARDLOCKUP_PANIC=y
|
||||
CONFIG_BOOTPARAM_HUNG_TASK_PANIC=y
|
||||
CONFIG_WQ_WATCHDOG=y
|
||||
CONFIG_WQ_CPU_INTENSIVE_REPORT=y
|
||||
CONFIG_TEST_LOCKUP=m
|
||||
# CONFIG_SCHED_DEBUG is not set
|
||||
CONFIG_STACKTRACE=y
|
||||
CONFIG_RCU_CPU_STALL_TIMEOUT=60
|
||||
|
||||
@@ -145,7 +145,6 @@ CONFIG_BRIDGE_EBT_REDIRECT=m
|
||||
CONFIG_BRIDGE_EBT_SNAT=m
|
||||
CONFIG_BRIDGE_EBT_LOG=m
|
||||
CONFIG_BRIDGE_EBT_NFLOG=m
|
||||
CONFIG_BPFILTER=y
|
||||
CONFIG_BRIDGE=y
|
||||
CONFIG_BRIDGE_VLAN_FILTERING=y
|
||||
CONFIG_BRIDGE_MRP=y
|
||||
@@ -262,11 +261,18 @@ CONFIG_NLS_ISO8859_1=y
|
||||
CONFIG_CRYPTO_AES=y
|
||||
CONFIG_CRYPTO_GCM=y
|
||||
CONFIG_DEBUG_KERNEL=y
|
||||
CONFIG_DEBUG_INFO_DWARF_TOOLCHAIN_DEFAULT=y
|
||||
CONFIG_MAGIC_SYSRQ=y
|
||||
CONFIG_DEBUG_FS=y
|
||||
CONFIG_PANIC_ON_OOPS=y
|
||||
CONFIG_PANIC_TIMEOUT=20
|
||||
CONFIG_DETECT_HUNG_TASK=y
|
||||
CONFIG_BOOTPARAM_SOFTLOCKUP_PANIC=y
|
||||
CONFIG_HARDLOCKUP_DETECTOR=y
|
||||
CONFIG_HARDLOCKUP_DETECTOR_PREFER_BUDDY=y
|
||||
CONFIG_BOOTPARAM_HARDLOCKUP_PANIC=y
|
||||
CONFIG_BOOTPARAM_HUNG_TASK_PANIC=y
|
||||
CONFIG_WQ_WATCHDOG=y
|
||||
CONFIG_WQ_CPU_INTENSIVE_REPORT=y
|
||||
CONFIG_TEST_LOCKUP=m
|
||||
CONFIG_FUNCTION_TRACER=y
|
||||
CONFIG_UNWINDER_FRAME_POINTER=y
|
||||
|
||||
@@ -13,8 +13,8 @@ BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||
BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_ROOTFS_MERGED_USR=y
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_SYSTEM_BIN_SH_BASH=y
|
||||
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
@@ -27,17 +27,14 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.52"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.63"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_DTS_SUPPORT=y
|
||||
BR2_LINUX_KERNEL_INTREE_DTS_NAME="alder/alder styx/dcp-sc-28p-a styx/dcp-sc-28p-b marvell/armada-3720-espressobin marvell/armada-3720-espressobin-emmc marvell/armada-3720-espressobin-v7 marvell/armada-3720-espressobin-v7-emmc marvell/armada-3720-espressobin-ultra marvell/cn9130-crb-A marvell/cn9130-crb-B microchip/sparx5_pcb135_emmc_no_psci"
|
||||
BR2_LINUX_KERNEL_CUSTOM_DTS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/dts"
|
||||
BR2_LINUX_KERNEL_DTB_KEEP_DIRNAME=y
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
||||
BR2_PACKAGE_STRACE=y
|
||||
BR2_PACKAGE_STRESS_NG=y
|
||||
BR2_PACKAGE_SYSREPO_GROUP="sys-cli"
|
||||
BR2_PACKAGE_JQ=y
|
||||
BR2_PACKAGE_E2FSPROGS=y
|
||||
BR2_PACKAGE_DBUS_CXX=y
|
||||
@@ -59,8 +56,8 @@ BR2_PACKAGE_PYTHON_GUNICORN=y
|
||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||
BR2_PACKAGE_LIBSSH2=y
|
||||
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
||||
BR2_PACKAGE_LIBXCRYPT=y
|
||||
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
||||
BR2_PACKAGE_LIBINPUT=y
|
||||
BR2_PACKAGE_LIBCURL_CURL=y
|
||||
BR2_PACKAGE_NETOPEER2_CLI=y
|
||||
BR2_PACKAGE_NSS_MDNS=y
|
||||
@@ -80,6 +77,7 @@ BR2_PACKAGE_IPROUTE2=y
|
||||
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
||||
BR2_PACKAGE_IPUTILS=y
|
||||
BR2_PACKAGE_LLDPD=y
|
||||
BR2_PACKAGE_MSTPD=y
|
||||
BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||
BR2_PACKAGE_NETSNMP=y
|
||||
@@ -109,9 +107,16 @@ BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_DBUS=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_RAUC_JSON=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
BR2_PACKAGE_WATCHDOGD_GENERIC=y
|
||||
BR2_PACKAGE_WATCHDOGD_LOADAVG=y
|
||||
BR2_PACKAGE_WATCHDOGD_FILENR=y
|
||||
BR2_PACKAGE_WATCHDOGD_MEMINFO=y
|
||||
BR2_PACKAGE_WATCHDOGD_FSMON=y
|
||||
BR2_PACKAGE_WATCHDOGD_TEMPMON
|
||||
BR2_PACKAGE_LESS=y
|
||||
BR2_PACKAGE_MG=y
|
||||
BR2_PACKAGE_NANO=y
|
||||
@@ -121,21 +126,28 @@ BR2_PACKAGE_HOST_E2FSPROGS=y
|
||||
BR2_PACKAGE_HOST_ENVIRONMENT_SETUP=y
|
||||
BR2_PACKAGE_HOST_GENEXT2FS=y
|
||||
BR2_PACKAGE_HOST_GENIMAGE=y
|
||||
BR2_PACKAGE_HOST_GO_BIN=y
|
||||
BR2_PACKAGE_HOST_RAUC=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
|
||||
INFIX_DESC="Infix is an operating system based on Linux and modeled with YANG. It can be set up both as a switch, with offloading using switchdev, a router with firewalling, or a secure end device. All while supporting advanced networking scenarios and running Docker containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_ALDER_ALDER=y
|
||||
BR2_PACKAGE_MARVELL_CN9130_CRB=y
|
||||
BR2_PACKAGE_MARVELL_ESPRESSOBIN=y
|
||||
BR2_PACKAGE_STYX_DCP_SC_28P=y
|
||||
BR2_PACKAGE_RASPBERRY_PI_4=y
|
||||
BR2_PACKAGE_CONFD=y
|
||||
BR2_PACKAGE_CONFD_TEST_MODE=y
|
||||
BR2_PACKAGE_CURIOS_HTTPD=y
|
||||
BR2_PACKAGE_CURIOS_NFTABLES=y
|
||||
BR2_PACKAGE_GENCERT=y
|
||||
BR2_PACKAGE_STATD=y
|
||||
BR2_PACKAGE_SHOW=y
|
||||
BR2_PACKAGE_FACTORY=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
||||
@@ -159,10 +171,14 @@ BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_LIBINPUT=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
BR2_PACKAGE_FEATURE_WIFI=y
|
||||
BR2_PACKAGE_FEATURE_WIFI_DONGLE_REALTEK=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
DISK_IMAGE_BOOT_BIN=y
|
||||
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
||||
BR2_PACKAGE_GETENT=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
DISK_IMAGE_BOOT_BIN=y
|
||||
GNS3_APPLIANCE_RAM=512
|
||||
GNS3_APPLIANCE_IFNUM=10
|
||||
|
||||
@@ -27,17 +27,14 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.52"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.63"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_DTS_SUPPORT=y
|
||||
BR2_LINUX_KERNEL_INTREE_DTS_NAME="alder/alder styx/dcp-sc-28p-a styx/dcp-sc-28p-b marvell/armada-3720-espressobin marvell/armada-3720-espressobin-emmc marvell/armada-3720-espressobin-v7 marvell/armada-3720-espressobin-v7-emmc marvell/armada-3720-espressobin-ultra marvell/cn9130-crb-A marvell/cn9130-crb-B microchip/sparx5_pcb135_emmc_no_psci"
|
||||
BR2_LINUX_KERNEL_CUSTOM_DTS_OVERLAY="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/dts"
|
||||
BR2_LINUX_KERNEL_DTB_KEEP_DIRNAME=y
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
||||
BR2_PACKAGE_STRACE=y
|
||||
BR2_PACKAGE_STRESS_NG=y
|
||||
BR2_PACKAGE_SYSREPO_GROUP="sys-cli"
|
||||
BR2_PACKAGE_JQ=y
|
||||
BR2_PACKAGE_E2FSPROGS=y
|
||||
BR2_PACKAGE_DBUS_CXX=y
|
||||
@@ -75,6 +72,7 @@ BR2_PACKAGE_FRR=y
|
||||
BR2_PACKAGE_IPROUTE2=y
|
||||
BR2_PACKAGE_IPUTILS=y
|
||||
BR2_PACKAGE_LLDPD=y
|
||||
BR2_PACKAGE_MSTPD=y
|
||||
BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NGINX=y
|
||||
BR2_PACKAGE_NGINX_HTTP_SSL_MODULE=y
|
||||
@@ -92,9 +90,16 @@ BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_DBUS=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_RAUC_JSON=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
BR2_PACKAGE_WATCHDOGD_GENERIC=y
|
||||
BR2_PACKAGE_WATCHDOGD_LOADAVG=y
|
||||
BR2_PACKAGE_WATCHDOGD_FILENR=y
|
||||
BR2_PACKAGE_WATCHDOGD_MEMINFO=y
|
||||
BR2_PACKAGE_WATCHDOGD_FSMON=y
|
||||
BR2_PACKAGE_WATCHDOGD_TEMPMON
|
||||
BR2_PACKAGE_LESS=y
|
||||
BR2_PACKAGE_MG=y
|
||||
BR2_PACKAGE_NANO=y
|
||||
@@ -109,14 +114,19 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
|
||||
INFIX_DESC="Infix is an operating system based on Linux and modeled with YANG. It can be set up both as a switch, with offloading using switchdev, a router with firewalling, or a secure end device. All while supporting advanced networking scenarios and running Docker containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_ALDER_ALDER=y
|
||||
BR2_PACKAGE_MARVELL_CN9130_CRB=y
|
||||
BR2_PACKAGE_MARVELL_ESPRESSOBIN=y
|
||||
BR2_PACKAGE_STYX_DCP_SC_28P=y
|
||||
BR2_PACKAGE_CONFD=y
|
||||
BR2_PACKAGE_CONFD_TEST_MODE=y
|
||||
BR2_PACKAGE_GENCERT=y
|
||||
BR2_PACKAGE_STATD=y
|
||||
BR2_PACKAGE_SHOW=y
|
||||
BR2_PACKAGE_FACTORY=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
||||
@@ -134,6 +144,9 @@ BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_MDNS_ALIAS=y
|
||||
BR2_PACKAGE_LIBINPUT=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
||||
BR2_PACKAGE_GETENT=y
|
||||
DISK_IMAGE_BOOT_BIN=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
|
||||
@@ -20,15 +20,11 @@ BR2_TARGET_UBOOT_BUILD_SYSTEM_KCONFIG=y
|
||||
BR2_TARGET_UBOOT_CUSTOM_VERSION=y
|
||||
BR2_TARGET_UBOOT_CUSTOM_VERSION_VALUE="2023.07.02"
|
||||
BR2_TARGET_UBOOT_BOARD_DEFCONFIG="qemu_arm64"
|
||||
BR2_TARGET_UBOOT_CONFIG_FRAGMENT_FILES="$(BR2_EXTERNAL_INFIX_PATH)/board/common/uboot/extras.config"
|
||||
BR2_TARGET_UBOOT_CONFIG_FRAGMENT_FILES="$(BR2_EXTERNAL_INFIX_PATH)/board/common/uboot/extras.config $(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/qemu/uboot/extras.config"
|
||||
BR2_TARGET_UBOOT_FORMAT_DTB=y
|
||||
BR2_PACKAGE_HOST_GENIMAGE=y
|
||||
BR2_PACKAGE_HOST_RAUC=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
DISK_IMAGE_BOOT_BIN=y
|
||||
DISK_IMAGE_BOOT_DATA="${BINARIES_DIR}/flash-image.bin"
|
||||
DISK_IMAGE_BOOT_OFFSET=0x00200000
|
||||
# GNS3_APPLIANCE is not set
|
||||
|
||||
@@ -38,8 +38,4 @@ BR2_PACKAGE_HOST_RAUC=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
DISK_IMAGE_BOOT_BIN=y
|
||||
DISK_IMAGE_BOOT_DATA="${BINARIES_DIR}/flash-image.bin"
|
||||
DISK_IMAGE_BOOT_OFFSET=0x00200000
|
||||
# GNS3_APPLIANCE is not set
|
||||
|
||||
@@ -11,6 +11,7 @@ BR2_GLOBAL_PATCH_DIR="$(BR2_EXTERNAL_INFIX_PATH)/patches"
|
||||
BR2_INIT_NONE=y
|
||||
BR2_SYSTEM_BIN_SH_NONE=y
|
||||
# BR2_PACKAGE_BUSYBOX is not set
|
||||
BR2_PACKAGE_LIBBSD=y
|
||||
# BR2_PACKAGE_IFUPDOWN_SCRIPTS is not set
|
||||
# BR2_TARGET_ROOTFS_TAR is not set
|
||||
BR2_TARGET_UBOOT=y
|
||||
@@ -20,3 +21,5 @@ BR2_TARGET_UBOOT_CUSTOM_REPO_URL="https://github.com/kernelkit/u-boot.git"
|
||||
BR2_TARGET_UBOOT_CUSTOM_REPO_VERSION="c3d9cdcc7d9e3eb490d4036f5eece3fb91a2485c"
|
||||
BR2_TARGET_UBOOT_BOARD_DEFCONFIG="mscc_fireant_pcb135_emmc"
|
||||
BR2_TARGET_UBOOT_CONFIG_FRAGMENT_FILES="$(BR2_EXTERNAL_INFIX_PATH)/board/common/uboot/extras.config"
|
||||
BR2_TARGET_UBOOT_NEEDS_DTC=y
|
||||
# GNS3_APPLIANCE is not set
|
||||
|
||||
@@ -8,7 +8,6 @@ BR2_CCACHE=y
|
||||
BR2_CCACHE_DIR="${BR2_EXTERNAL_INFIX_PATH}/.ccache"
|
||||
BR2_ENABLE_DEBUG=y
|
||||
BR2_GLOBAL_PATCH_DIR="${BR2_EXTERNAL_INFIX_PATH}/patches"
|
||||
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
||||
BR2_TARGET_GENERIC_HOSTNAME="infix"
|
||||
BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||
BR2_INIT_FINIT=y
|
||||
@@ -30,7 +29,7 @@ BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image
|
||||
BR2_ROOTFS_POST_SCRIPT_ARGS="-c $(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/r2s/genimage.cfg"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.10.3"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.44"
|
||||
BR2_LINUX_KERNEL_PATCH="$(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/r2s/rk3328-nanopi-r2s-dts.patch"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/r2s/linux_defconfig"
|
||||
@@ -42,6 +41,7 @@ BR2_LINUX_KERNEL_NEEDS_HOST_OPENSSL=y
|
||||
BR2_PACKAGE_BUSYBOX_CONFIG="$(BR2_EXTERNAL_INFIX_PATH)/board/common/busybox_defconfig"
|
||||
BR2_PACKAGE_STRACE=y
|
||||
BR2_PACKAGE_STRESS_NG=y
|
||||
BR2_PACKAGE_SYSREPO_GROUP="sys-cli"
|
||||
BR2_PACKAGE_JQ=y
|
||||
BR2_PACKAGE_E2FSPROGS=y
|
||||
BR2_PACKAGE_LINUX_FIRMWARE=y
|
||||
@@ -74,7 +74,6 @@ BR2_PACKAGE_PYTHON_GUNICORN=y
|
||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||
BR2_PACKAGE_LIBSSH2=y
|
||||
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
||||
BR2_PACKAGE_LIBXCRYPT=y
|
||||
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
||||
BR2_PACKAGE_LIBINPUT=y
|
||||
BR2_PACKAGE_LIBCURL_CURL=y
|
||||
@@ -128,6 +127,7 @@ BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_DBUS=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_RAUC_JSON=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
@@ -170,13 +170,14 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||
INFIX_IMAGE_ID="${INFIX_ID}-r2s"
|
||||
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
|
||||
INFIX_DESC="Infix is an operating system based on Linux and modeled with YANG. It can be set up both as a switch, with offloading using switchdev, a router with firewalling, or a secure end device. All while supporting advanced networking scenarios and running Docker containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
BR2_PACKAGE_CONFD=y
|
||||
BR2_PACKAGE_GENCERT=y
|
||||
BR2_PACKAGE_STATD=y
|
||||
BR2_PACKAGE_SHOW=y
|
||||
BR2_PACKAGE_FACTORY=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
||||
@@ -200,7 +201,10 @@ BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
||||
BR2_PACKAGE_GETENT=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
# GNS3_APPLIANCE is not set
|
||||
|
||||
@@ -39,6 +39,7 @@ BR2_LINUX_KERNEL_NEEDS_HOST_OPENSSL=y
|
||||
BR2_PACKAGE_BUSYBOX_CONFIG="$(BR2_EXTERNAL_INFIX_PATH)/board/common/busybox_defconfig"
|
||||
BR2_PACKAGE_STRACE=y
|
||||
BR2_PACKAGE_STRESS_NG=y
|
||||
BR2_PACKAGE_SYSREPO_GROUP="sys-cli"
|
||||
BR2_PACKAGE_JQ=y
|
||||
BR2_PACKAGE_E2FSPROGS=y
|
||||
BR2_PACKAGE_LINUX_FIRMWARE=y
|
||||
@@ -88,6 +89,7 @@ BR2_PACKAGE_IPROUTE2=y
|
||||
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
||||
BR2_PACKAGE_IPUTILS=y
|
||||
BR2_PACKAGE_LLDPD=y
|
||||
BR2_PACKAGE_MSTPD=y
|
||||
BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||
BR2_PACKAGE_NETSNMP=y
|
||||
@@ -117,9 +119,16 @@ BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_DBUS=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_RAUC_JSON=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
BR2_PACKAGE_WATCHDOGD_GENERIC=y
|
||||
BR2_PACKAGE_WATCHDOGD_LOADAVG=y
|
||||
BR2_PACKAGE_WATCHDOGD_FILENR=y
|
||||
BR2_PACKAGE_WATCHDOGD_MEMINFO=y
|
||||
BR2_PACKAGE_WATCHDOGD_FSMON=y
|
||||
BR2_PACKAGE_WATCHDOGD_TEMPMON
|
||||
BR2_PACKAGE_LESS=y
|
||||
BR2_PACKAGE_MG=y
|
||||
BR2_PACKAGE_NANO=y
|
||||
@@ -159,7 +168,7 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
|
||||
INFIX_DESC="Infix is an operating system based on Linux and modeled with YANG. It can be set up both as a switch, with offloading using switchdev, a router with firewalling, or a secure end device. All while supporting advanced networking scenarios and running Docker containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
@@ -167,6 +176,7 @@ BR2_PACKAGE_CONFD=y
|
||||
# BR2_PACKAGE_CONFD_TEST_MODE is not set
|
||||
BR2_PACKAGE_GENCERT=y
|
||||
BR2_PACKAGE_STATD=y
|
||||
BR2_PACKAGE_SHOW=y
|
||||
BR2_PACKAGE_FACTORY=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
||||
@@ -191,6 +201,9 @@ BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
||||
BR2_PACKAGE_GETENT=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
# GNS3_APPLIANCE is not set
|
||||
|
||||
@@ -0,0 +1,37 @@
|
||||
BR2_aarch64=y
|
||||
BR2_cortex_a72=y
|
||||
BR2_TOOLCHAIN_EXTERNAL=y
|
||||
BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
|
||||
BR2_DL_DIR="$(BR2_EXTERNAL_INFIX_PATH)/dl"
|
||||
BR2_CCACHE=y
|
||||
BR2_CCACHE_DIR="$(BR2_EXTERNAL_INFIX_PATH)/.ccache"
|
||||
BR2_ENABLE_DEBUG=y
|
||||
BR2_PACKAGE_OVERRIDE_FILE="$(BR2_EXTERNAL_INFIX_PATH)/local.mk"
|
||||
BR2_GLOBAL_PATCH_DIR="$(BR2_EXTERNAL_INFIX_PATH)/patches"
|
||||
BR2_SSP_NONE=y
|
||||
BR2_INIT_NONE=y
|
||||
BR2_SYSTEM_BIN_SH_NONE=y
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
# BR2_PACKAGE_BUSYBOX is not set
|
||||
BR2_PACKAGE_RPI_FIRMWARE=y
|
||||
BR2_PACKAGE_RPI_FIRMWARE_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/src/board/raspberry-pi-4/config.txt"
|
||||
BR2_PACKAGE_RPI_FIRMWARE_CMDLINE_FILE="${BR2_EXTERNAL_INFIX_PATH}/src/board/raspberry-pi-4/cmdline.txt"
|
||||
# BR2_PACKAGE_IFUPDOWN_SCRIPTS is not set
|
||||
# BR2_TARGET_ROOTFS_TAR is not set
|
||||
BR2_TARGET_UBOOT=y
|
||||
BR2_TARGET_UBOOT_BUILD_SYSTEM_KCONFIG=y
|
||||
BR2_TARGET_UBOOT_CUSTOM_VERSION=y
|
||||
BR2_TARGET_UBOOT_CUSTOM_VERSION_VALUE="2025.01"
|
||||
BR2_TARGET_UBOOT_BOARD_DEFCONFIG="rpi_arm64"
|
||||
BR2_TARGET_UBOOT_CONFIG_FRAGMENT_FILES="${BR2_EXTERNAL_INFIX_PATH}/board/common/uboot/extras.config ${BR2_EXTERNAL_INFIX_PATH}/src/board/raspberry-pi-4/uboot/extras.config"
|
||||
BR2_TARGET_UBOOT_NEEDS_DTC=y
|
||||
BR2_TARGET_UBOOT_FORMAT_DTB=y
|
||||
BR2_TARGET_UBOOT_FORMAT_CUSTOM=y
|
||||
BR2_TARGET_UBOOT_FORMAT_CUSTOM_NAME="arch/arm/dts/infix-key.dtbo arch/arm/dts/rpi-env.dtbo"
|
||||
BR2_TARGET_UBOOT_CUSTOM_DTS_PATH="${BR2_EXTERNAL_INFIX_PATH}/src/board/raspberry-pi-4/uboot/rpi-env.dtso"
|
||||
BR2_PACKAGE_HOST_GENIMAGE=y
|
||||
BR2_PACKAGE_HOST_RAUC=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
# GNS3_APPLIANCE is not set
|
||||
@@ -12,8 +12,8 @@ BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||
BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_ROOTFS_MERGED_USR=y
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_SYSTEM_BIN_SH_BASH=y
|
||||
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
@@ -26,7 +26,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INF
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.52"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.63"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -34,6 +34,7 @@ BR2_LINUX_KERNEL_NEEDS_HOST_LIBELF=y
|
||||
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
||||
BR2_PACKAGE_STRACE=y
|
||||
BR2_PACKAGE_STRESS_NG=y
|
||||
BR2_PACKAGE_SYSREPO_GROUP="sys-cli"
|
||||
BR2_PACKAGE_JQ=y
|
||||
BR2_PACKAGE_E2FSPROGS=y
|
||||
BR2_PACKAGE_DBUS_CXX=y
|
||||
@@ -54,10 +55,8 @@ BR2_PACKAGE_PYTHON_GUNICORN=y
|
||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||
BR2_PACKAGE_LIBSSH2=y
|
||||
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
||||
BR2_PACKAGE_LIBXCRYPT=y
|
||||
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
||||
BR2_PACKAGE_LIBCURL_CURL=y
|
||||
BR2_PACKAGE_LIBMNL=y
|
||||
BR2_PACKAGE_NETOPEER2_CLI=y
|
||||
BR2_PACKAGE_NSS_MDNS=y
|
||||
BR2_PACKAGE_LINUX_PAM=y
|
||||
@@ -76,6 +75,7 @@ BR2_PACKAGE_IPROUTE2=y
|
||||
BR2_PACKAGE_IPTABLES_NFTABLES=y
|
||||
BR2_PACKAGE_IPUTILS=y
|
||||
BR2_PACKAGE_LLDPD=y
|
||||
BR2_PACKAGE_MSTPD=y
|
||||
BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NETCAT_OPENBSD=y
|
||||
BR2_PACKAGE_NETSNMP=y
|
||||
@@ -105,9 +105,16 @@ BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_DBUS=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_RAUC_JSON=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
BR2_PACKAGE_WATCHDOGD_GENERIC=y
|
||||
BR2_PACKAGE_WATCHDOGD_LOADAVG=y
|
||||
BR2_PACKAGE_WATCHDOGD_FILENR=y
|
||||
BR2_PACKAGE_WATCHDOGD_MEMINFO=y
|
||||
BR2_PACKAGE_WATCHDOGD_FSMON=y
|
||||
BR2_PACKAGE_WATCHDOGD_TEMPMON
|
||||
BR2_PACKAGE_LESS=y
|
||||
BR2_PACKAGE_MG=y
|
||||
BR2_PACKAGE_NANO=y
|
||||
@@ -124,13 +131,14 @@ BR2_PACKAGE_HOST_E2FSPROGS=y
|
||||
BR2_PACKAGE_HOST_ENVIRONMENT_SETUP=y
|
||||
BR2_PACKAGE_HOST_GENEXT2FS=y
|
||||
BR2_PACKAGE_HOST_GENIMAGE=y
|
||||
BR2_PACKAGE_HOST_GO_BIN=y
|
||||
BR2_PACKAGE_HOST_MTOOLS=y
|
||||
BR2_PACKAGE_HOST_RAUC=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
|
||||
INFIX_DESC="Infix is an operating system based on Linux and modeled with YANG. It can be set up both as a switch, with offloading using switchdev, a router with firewalling, or a secure end device. All while supporting advanced networking scenarios and running Docker containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
@@ -140,6 +148,7 @@ BR2_PACKAGE_CURIOS_HTTPD=y
|
||||
BR2_PACKAGE_CURIOS_NFTABLES=y
|
||||
BR2_PACKAGE_GENCERT=y
|
||||
BR2_PACKAGE_STATD=y
|
||||
BR2_PACKAGE_SHOW=y
|
||||
BR2_PACKAGE_FACTORY=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
|
||||
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
|
||||
@@ -163,7 +172,12 @@ BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
BR2_PACKAGE_FEATURE_WIFI=y
|
||||
BR2_PACKAGE_FEATURE_WIFI_DONGLE_REALTEK=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
||||
BR2_PACKAGE_GETENT=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
GNS3_APPLIANCE_RAM=512
|
||||
|
||||
@@ -7,13 +7,14 @@ BR2_CCACHE=y
|
||||
BR2_CCACHE_DIR="${BR2_EXTERNAL_INFIX_PATH}/.ccache"
|
||||
BR2_ENABLE_DEBUG=y
|
||||
BR2_GLOBAL_PATCH_DIR="${BR2_EXTERNAL_INFIX_PATH}/patches"
|
||||
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
|
||||
BR2_TARGET_GENERIC_HOSTNAME="ix"
|
||||
BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||
BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_ROOTFS_MERGED_USR=y
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_SYSTEM_BIN_SH_BASH=y
|
||||
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
@@ -26,7 +27,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INF
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.6.52"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.63"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -34,6 +35,7 @@ BR2_LINUX_KERNEL_NEEDS_HOST_LIBELF=y
|
||||
BR2_PACKAGE_BUSYBOX_CONFIG="${BR2_EXTERNAL_INFIX_PATH}/board/common/busybox_defconfig"
|
||||
BR2_PACKAGE_STRACE=y
|
||||
BR2_PACKAGE_STRESS_NG=y
|
||||
BR2_PACKAGE_SYSREPO_GROUP="sys-cli"
|
||||
BR2_PACKAGE_JQ=y
|
||||
BR2_PACKAGE_E2FSPROGS=y
|
||||
BR2_PACKAGE_DBUS_CXX=y
|
||||
@@ -50,10 +52,7 @@ BR2_PACKAGE_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_FIT_CHECK_SIGN=y
|
||||
BR2_PACKAGE_UBOOT_TOOLS_MKENVIMAGE=y
|
||||
BR2_PACKAGE_PYTHON3=y
|
||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||
BR2_PACKAGE_LIBSSH2=y
|
||||
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
||||
BR2_PACKAGE_LIBXCRYPT=y
|
||||
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
||||
BR2_PACKAGE_LIBCURL_CURL=y
|
||||
BR2_PACKAGE_LIBMNL=y
|
||||
@@ -71,6 +70,7 @@ BR2_PACKAGE_FRR=y
|
||||
BR2_PACKAGE_IPROUTE2=y
|
||||
BR2_PACKAGE_IPUTILS=y
|
||||
BR2_PACKAGE_LLDPD=y
|
||||
BR2_PACKAGE_MSTPD=y
|
||||
BR2_PACKAGE_NETCALC=y
|
||||
BR2_PACKAGE_NGINX=y
|
||||
BR2_PACKAGE_NGINX_HTTP_SSL_MODULE=y
|
||||
@@ -82,15 +82,23 @@ BR2_PACKAGE_TCPDUMP=y
|
||||
BR2_PACKAGE_WHOIS=y
|
||||
BR2_PACKAGE_BASH_COMPLETION=y
|
||||
BR2_PACKAGE_SUDO=y
|
||||
BR2_PACKAGE_GETENT=y
|
||||
BR2_PACKAGE_KMOD_TOOLS=y
|
||||
BR2_PACKAGE_PWGEN=y
|
||||
BR2_PACKAGE_RAUC=y
|
||||
BR2_PACKAGE_RAUC_DBUS=y
|
||||
BR2_PACKAGE_RAUC_GPT=y
|
||||
BR2_PACKAGE_RAUC_NETWORK=y
|
||||
BR2_PACKAGE_RAUC_JSON=y
|
||||
BR2_PACKAGE_SYSKLOGD=y
|
||||
BR2_PACKAGE_SYSKLOGD_LOGGER=y
|
||||
BR2_PACKAGE_WATCHDOGD=y
|
||||
BR2_PACKAGE_WATCHDOGD_GENERIC=y
|
||||
BR2_PACKAGE_WATCHDOGD_LOADAVG=y
|
||||
BR2_PACKAGE_WATCHDOGD_FILENR=y
|
||||
BR2_PACKAGE_WATCHDOGD_MEMINFO=y
|
||||
BR2_PACKAGE_WATCHDOGD_FSMON=y
|
||||
BR2_PACKAGE_WATCHDOGD_TEMPMON=y
|
||||
BR2_PACKAGE_LESS=y
|
||||
BR2_PACKAGE_MG=y
|
||||
BR2_PACKAGE_NANO=y
|
||||
@@ -113,7 +121,7 @@ BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SIGNATURE_SUPPORT=y
|
||||
INFIX_VENDOR_HOME="https://github.com/kernelkit"
|
||||
INFIX_DESC="Infix is a Network Operating System based on Linux. It can be set up both as a switch, with offloading using switchdev, and a router with firewalling."
|
||||
INFIX_DESC="Infix is an operating system based on Linux and modeled with YANG. It can be set up both as a switch, with offloading using switchdev, a router with firewalling, or a secure end device. All while supporting advanced networking scenarios and running Docker containers."
|
||||
INFIX_HOME="https://github.com/kernelkit/infix/"
|
||||
INFIX_DOC="https://github.com/kernelkit/infix/tree/main/doc"
|
||||
INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
|
||||
@@ -136,7 +144,9 @@ BR2_PACKAGE_KLISH_PLUGIN_INFIX=y
|
||||
BR2_PACKAGE_LOWDOWN=y
|
||||
BR2_PACKAGE_MCD=y
|
||||
BR2_PACKAGE_MDNS_ALIAS=y
|
||||
BR2_PACKAGE_SHOW=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
GNS3_APPLIANCE_RAM=512
|
||||
|
||||
@@ -3,6 +3,248 @@ Change Log
|
||||
|
||||
All notable changes to the project are documented in this file.
|
||||
|
||||
[v25.08.2][] - 2025-12-19
|
||||
-------------------------
|
||||
|
||||
### Changes
|
||||
|
||||
- Upgrade Linux kernel to 6.12.63 (LTS)
|
||||
- Enable workaround for issue #670 by disabling iitod on styx platform. This
|
||||
prohibits software control of LEDs, leaving the default HW control, which
|
||||
has proven more stable on this platform
|
||||
- Add support for configurable OSPF debug logging, issue #1281. Debug options
|
||||
can now be enabled per category (bfd, packet, ism, nsm, default-information,
|
||||
nssa). All debug options are disabled by default to prevent log flooding in
|
||||
production environments. See the documentation for usage examples
|
||||
- Add support data collection script, useful when troubleshooting issues on
|
||||
deployed systems. Gathers system information, logs, and more. Issue #1287
|
||||
- Enable kernel panic on lockups + hung tasks => console log + reboot. Also,
|
||||
enable watchdogd resource monitors, logs: memory/file system + descriptor
|
||||
usage. Issue #1318
|
||||
- Enable CN9130 HW watchdog, and kernel `test_lockup` module, issue #1320
|
||||
|
||||
### Fixes
|
||||
|
||||
- Fix #981: copying any file, including `running-config`, to the persistent
|
||||
back-end store for `startup-config`, does not take
|
||||
- Fix #1203: copying any file, including `startup-config`, to `running-config`
|
||||
does not take
|
||||
|
||||
[v25.08.1][] - 2025-10-03
|
||||
-------------------------
|
||||
|
||||
### Changes
|
||||
- N/A
|
||||
|
||||
### Fixes
|
||||
- Fix #1150: `show-legacy` wrapper permissions
|
||||
- Fix #1155: `show ospf` commands regression
|
||||
- Fix #1169: Expected OSPF neighbors not shown in `sysrepocfg` when the
|
||||
system has at least one non-OSPF interface
|
||||
|
||||
[v25.08.0][] - 2025-09-01
|
||||
-------------------------
|
||||
|
||||
### Changes
|
||||
- Upgrade Buildroot to 2025.02.5 (LTS)
|
||||
- Upgrade Linux kernel to 6.12.44 (LTS)
|
||||
- Raspberry Pi 4 is now a part of the aarch64 image.
|
||||
- Add support for [Raspberry Pi touch display][RPI-TOUCH] on Raspberry Pi 4
|
||||
|
||||
### Fixes
|
||||
- Fix #1098: Prune dangling container images to reclaim disk space
|
||||
- Fix #1123: Disabling or removing a container may cause podman to hang
|
||||
- Fix #1124: Container setup with unreachable remote image spawns
|
||||
excessive `ip monitor` processes
|
||||
- Fix #1127: Silence libyang Obsolete schema node warnings in log
|
||||
|
||||
[RPI-TOUCH]: https://www.raspberrypi.com/products/raspberry-pi-touch-display/
|
||||
|
||||
[v25.06.0][] - 2025-07-01
|
||||
-------------------------
|
||||
|
||||
### Changes
|
||||
- Upgrade Buildroot to 2025.02.4 (LTS)
|
||||
- Upgrade Linux kernel to 6.12.35 (LTS)
|
||||
- Upgrade curiOS built-in containers to v25.06.0
|
||||
- Add support for setting mode of a container content mount, issue #1070
|
||||
- Add Wi-Fi client support and add support for some USB-Wi-Fi cards
|
||||
- New slogan: Infix OS — Immutable.Friendly.Secure
|
||||
|
||||
### Fixes
|
||||
- cli: fix by-word movement, detect word barrier using non-alphanum chars
|
||||
- cli: fix delete word left/right, make sure to save word in kill buffer
|
||||
|
||||
|
||||
[v25.05.1][] - 2025-06-12
|
||||
-------------------------
|
||||
|
||||
### Changes
|
||||
- Upgrade Linux kernel to 6.12.32 (LTS)
|
||||
|
||||
### Fixes
|
||||
- Fix #1060: Restore of missing CLI commands, regression in Infix v25.05.0
|
||||
|
||||
[v25.05.0][] - 2025-05-27
|
||||
-------------------------
|
||||
|
||||
### Changes
|
||||
- Upgrade Buildroot to 2025.02.3 (LTS)
|
||||
- Upgrade Linux kernel to 6.12.30 (LTS)
|
||||
- Upgrade libyang to 3.12.2
|
||||
- Upgrade sysrepo to 3.6.11
|
||||
- Upgrade netopeer2 (NETCONF) to 2.4.1
|
||||
- New hardware support: Raspberry Pi 4B (aarch64)
|
||||
- Add documentation on Infix upgrading and downgrading, issue #1009
|
||||
- Add HDMI and USB support for iMX8MP-evk
|
||||
- Enforced strict format for LLDP destination MAC address:
|
||||
- Only accepts colon-separated format: `01:80:C2:00:00:0E`
|
||||
- Add `show lldp` command to show discovered neighbors per interface.
|
||||
- Add configuration support for per-interface LLDP administrative status
|
||||
|
||||
### Fixes
|
||||
- Fix containers with multiple mounts
|
||||
- Correct description for LAG LACP modes
|
||||
- Fix #1040: Add `mount` constraint for container config
|
||||
|
||||
|
||||
[v25.04.0][] - 2025-04-30
|
||||
-------------------------
|
||||
|
||||
### Changes
|
||||
- Upgrade Linux kernel to 6.12.25 (LTS)
|
||||
- Upgrade Buildroot to 2025.02.1 (LTS)
|
||||
- Format for disk image (for QEMU) has changed to `qcow2`
|
||||
|
||||
### Fixes
|
||||
- Fix #1002: Broken symlink in release package
|
||||
- Fix #1006: NanoPi R2S corrupt startup, regression in Infix v25.02.0
|
||||
- Bump R2S kernel, now same as tier one boards
|
||||
- Fix #1015: Not possible to save custom SSH settings in startup-config
|
||||
- Fix group owner and permissions of `/cfg/backup` directory
|
||||
- Fix extraction of old version for `/cfg/backup/` files
|
||||
- Fix configuration migration issues when upgrading
|
||||
|
||||
[v25.03.0][] - 2025-03-31
|
||||
-------------------------
|
||||
|
||||
> [!IMPORTANT]
|
||||
> This release is the first with the new Buildroot 2025.02 (LTS)
|
||||
|
||||
### Changes
|
||||
- Upgrade Linux kernel to 6.12.21 (LTS)
|
||||
- Upgrade Buildroot to 2025.02.0 (LTS)
|
||||
|
||||
### Fixes
|
||||
- Fix #964: YANG schema warning in syslog: missing 'monitor' node for lag
|
||||
- Fix #980: the system fails to reboot when a container is (stuck), for
|
||||
whatever reason, in its 'setup' state
|
||||
- Fix #990: web console, ttyd service, stopped working after upgrade to
|
||||
Buildroot 2025.02, caused by new (missing) option `--writable`
|
||||
- Fix TCAM memory corruption in `mvpp2` Ethernet controller
|
||||
- Fix annoying (but harmless) usage message from the logger tool when
|
||||
`startup-config` fails to load and the system reverts to failure mode
|
||||
- Fix harmless log warning for product specific init when no product
|
||||
specific init scripts are found
|
||||
- Backport fixes for sysklogd, affecting hostname filtering and periods
|
||||
in TAG names, pending official backport in Buildroot
|
||||
|
||||
|
||||
[v25.02.0][] - 2025-03-04
|
||||
-------------------------
|
||||
|
||||
### Changes
|
||||
- Upgrade Linux kernel to 6.12.18 (LTS)
|
||||
- Upgrade Buildroot to 2024.02.11 (LTS)
|
||||
- Add support for link aggregation (lag), static (balance-xor) and LACP
|
||||
- Add support for the [i.MX 8M Plus EVK][EVK]
|
||||
- YANG type change for SSH private/public keys, from ietf-crypto-types
|
||||
to infix-crypto-types
|
||||
- Disable global IPv6 forwarding by default, enable by per-interface
|
||||
setting. Note, route advertisements are always accepted. Issue #785
|
||||
- Drop automatic default route (interface route) for IPv4 autoconf, not
|
||||
necessary and causes more confusion than good. Issue #923
|
||||
- Update scripting with new RESTCONF examples
|
||||
|
||||
### Fixes
|
||||
- Fix #896: `/etc/resolv.conf` not properly generated when system runs
|
||||
in fail secure mode (failing to load `startup-config`)
|
||||
- Fix #902: containers "linger" in the system (state 'exited') after
|
||||
having removed them from the configuration
|
||||
- Fix #930: container configuration changes does not apply at runtime
|
||||
only when saved to `startup-config` and system is rebooted
|
||||
- Fix #936: DHCP server reconfiguration does not always take effect.
|
||||
- Fix #956: CLI `copy` command complains it cannot change owner when
|
||||
copying `factory-config` to `running-config`. Bogus error, the
|
||||
latter is not really a file
|
||||
- Fix #977: "Operation not permitted" when saving `running-config` to
|
||||
`startup-config` (harmless warning but annoying and concerning)
|
||||
|
||||
[EVK]: https://www.nxp.com/design/design-center/development-boards-and-designs/8MPLUSLPD4-EVK
|
||||
|
||||
|
||||
[v25.01.0][] - 2025-01-31
|
||||
-------------------------
|
||||
|
||||
> [!NOTE]
|
||||
> This release contains breaking changes in the configuration file
|
||||
> syntax for DHCP clients. Specifically DHCP options *with value*,
|
||||
> i.e., the syntax for sending a hexadecimal value now require `hex`
|
||||
> prefix before a string of colon-separated pairs of hex values.
|
||||
|
||||
### Changes
|
||||
|
||||
- Upgrade Linux kernel to 6.12.11 (LTS)
|
||||
- Upgrade Buildroot to 2024.02.10 (LTS)
|
||||
- Upgrade FRR from 9.1.2 to 9.1.3
|
||||
- Add support for configuring SSH server, issue #441. As a result,
|
||||
both SSH and NETCONF now use the same host key in `factory-config`
|
||||
- Add operational support for reading DNS resolver info, issue #510
|
||||
- Add operational support for NTP client, issue #510
|
||||
- Add support for more mDNS settings: allow/deny interfaces, acting
|
||||
as "reflector" and filtering of reflected services. Issue #678
|
||||
- Add DHCPv4 server support, multiple subnets with static hosts and
|
||||
DHCP options on global, subnet, or host level, issue #703.
|
||||
Contributed by [MINEx Networks](https://minexn.com/)
|
||||
- DHCP client options aligned with DHCP server, `startup-config`
|
||||
files with old syntax are automatically migrated
|
||||
- Breaking change in DHCP client options *with value*. Hexadecimal
|
||||
values must now be formatted as `{ "hex": "c0:ff:ee" }` (JSON)
|
||||
- Add documentation on management via SSH, Web (RESTCONF, Web
|
||||
Console), and Console Port, issue #787
|
||||
- Add documentation of DNS client use and configuration, issue #798
|
||||
- Add support for changing boot order for the system with an RPC,
|
||||
including support for reading boot order from operational datastore
|
||||
- Add support for GRE/GRETAP tunnels
|
||||
- Add support for STP/RSTP on bridges
|
||||
- Add support for VXLAN tunnels
|
||||
- Add support for configuring global LLDP `message-tx-interval`
|
||||
|
||||
### Fixes
|
||||
|
||||
- Fix #777: Authorized SSH key not applied to `startup-config`
|
||||
- Fix #829: Avahi (mDNS responder) not starting properly on switches
|
||||
with *many* ports (>10). This led to a review of `sysctl`:
|
||||
- New for IPv4:
|
||||
- Adjust IGMP max memberships: 20 -> 1000
|
||||
- Use neighbor information on nexthop selection
|
||||
- Use inbound interface address on ICMP errors
|
||||
- Ignore routes with link down
|
||||
- Disable `rp_filter`
|
||||
- ARP settings have been changed to better fit routers, i.e.,
|
||||
systems with multiple interfaces:
|
||||
- Always use best local address when sending ARP
|
||||
- Only reply to ARP if target IP is on the inbound interface
|
||||
- Generate ARP requests when device is brought up or HW address changes
|
||||
- New for IPv6:
|
||||
- Keep static global addresses on link down
|
||||
- Ignore routes with link down
|
||||
- Fix #861: Fix error when running 251+ reconfigurations in test-mode
|
||||
- Fix #869: Setup of bridges is now more robust
|
||||
- Fix #899: DHCP client with client-id does not work
|
||||
- Minor cleanup of Networking Guide
|
||||
- Fix memory leaks in `confd`
|
||||
|
||||
|
||||
[v24.11.1][] - 2024-11-29
|
||||
-------------------------
|
||||
@@ -221,7 +463,7 @@ renamed to ease maintenance, more info below.
|
||||
with `custom-phys-address` to allow for constructing more free-form
|
||||
MAC addresses based on the chassis MAC (a.k.a., base MAC) address.
|
||||
For more information, see the YANG model, a few examples are listed in
|
||||
the updated documentation.
|
||||
the updated documentation.
|
||||
The syntax will be automatically updated in the `startup-config` and
|
||||
`factory-config` -- make sure to verify the changes and update any
|
||||
static `factory-config` used for your products
|
||||
@@ -1409,7 +1651,16 @@ Supported YANG models in addition to those used by sysrepo and netopeer:
|
||||
- N/A
|
||||
|
||||
[buildroot]: https://buildroot.org/
|
||||
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v24.11.0...HEAD
|
||||
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v25.08.0...HEAD
|
||||
[v25.08.1]: https://github.com/kernelkit/infix/compare/v25.08.0...v26.08.1
|
||||
[v25.08.0]: https://github.com/kernelkit/infix/compare/v25.06.1...v26.08.0
|
||||
[v25.06.0]: https://github.com/kernelkit/infix/compare/v25.05.1...v26.06.0
|
||||
[v25.05.1]: https://github.com/kernelkit/infix/compare/v25.05.0...v25.05.1
|
||||
[v25.05.0]: https://github.com/kernelkit/infix/compare/v25.04.0...v25.05.0
|
||||
[v25.04.0]: https://github.com/kernelkit/infix/compare/v25.03.0...v25.04.0
|
||||
[v25.03.0]: https://github.com/kernelkit/infix/compare/v25.02.0...v25.03.0
|
||||
[v25.02.0]: https://github.com/kernelkit/infix/compare/v25.01.0...v25.02.0
|
||||
[v25.01.0]: https://github.com/kernelkit/infix/compare/v24.11.0...v25.01.0
|
||||
[v24.11.1]: https://github.com/kernelkit/infix/compare/v24.11.0...v24.11.1
|
||||
[v24.11.0]: https://github.com/kernelkit/infix/compare/v24.10.0...v24.11.0
|
||||
[v24.10.2]: https://github.com/kernelkit/infix/compare/v24.10.1...v24.10.2
|
||||
|
||||
@@ -1,13 +1,16 @@
|
||||
<img align="right" src="logo.png" alt="Infix - Linux <3 NETCONF" width=480 border=10>
|
||||
|
||||
Welcome to Infix, your friendly Network Operating System! On these
|
||||
pages you can find both user and developer documentation.
|
||||
Welcome to Infix, your immutable, friendly, and secure operating system!
|
||||
On these pages you can find both user and developer documentation.
|
||||
|
||||
> Topics on configuring the system include CLI examples, every setting
|
||||
> is also possible to perform using NETCONF. In fact, the Infix test
|
||||
> system solely relies on NETCONF for configuring network topologies.
|
||||
Most topics on configuring the system include CLI examples, but every
|
||||
setting, as well as status read-back from the operational datastore, is
|
||||
also possible to perform using NETCONF or RESTCONF. In fact, the Infix
|
||||
regression test system solely relies on NETCONF and RESTCONF.
|
||||
|
||||
The CLI documentation is also available from inside the CLI itself using
|
||||
the `help` command.
|
||||
> [!TIP]
|
||||
> The CLI documentation is also available from inside the CLI itself
|
||||
> using the `help` command in admin-exec mode.
|
||||
|
||||
- **CLI Topics**
|
||||
- [Introduction to the CLI](cli/introduction.md)
|
||||
@@ -18,6 +21,7 @@ the `help` command.
|
||||
- [Introduction](introduction.md)
|
||||
- [System Configuration](system.md)
|
||||
- [Network Configuration](networking.md)
|
||||
- [DHCP Server](dhcp.md)
|
||||
- [Syslog Support](syslog.md)
|
||||
- **Infix In-Depth**
|
||||
- [Boot Procedure](boot.md)
|
||||
|
||||
@@ -1,37 +1,36 @@
|
||||
Boot Procedure
|
||||
==============
|
||||
# Boot Procedure
|
||||
|
||||
Systems running Infix will typically boot in multiple phases, forming
|
||||
a boot chain. Each link in the chain has three main responsibilities:
|
||||
|
||||
1. Ensuring the integrity of the next link before passing control to
|
||||
it. This avoids silent failures stemming from data corruption.
|
||||
|
||||
2. Ensuring the authenticity of the next link before passing control
|
||||
1. Ensuring the authenticity of the next link before passing control
|
||||
to it, commonly referred to as _Secure Boot_. This protects against
|
||||
malicious attempts to modify a system's firmware.
|
||||
|
||||
3. Preparing the system state according to the requirements of the
|
||||
1. Preparing the system state according to the requirements of the
|
||||
next link. E.g. the Linux kernel requires the system's RAM to be
|
||||
operational.
|
||||
|
||||
A typical chain consists of four stages:
|
||||
|
||||
.---------.
|
||||
| ROM >---. Determine the location of and load the SPL
|
||||
'---------' |
|
||||
.-----------------'
|
||||
| .---------.
|
||||
'---> SPL >---. Perform DDR training and load the TPL
|
||||
'---------' |
|
||||
.-----------------'
|
||||
| .---------.
|
||||
'---> TPL >---. Load Linux kernel, device tree, and root filesystem
|
||||
'---------' |
|
||||
.-----------------'
|
||||
| .---------.
|
||||
'---> Infix | Get down to business
|
||||
'---------'
|
||||
```
|
||||
.---------.
|
||||
| ROM >---. Determine the location of and load the SPL
|
||||
'---------' |
|
||||
.-----------------'
|
||||
| .---------.
|
||||
'---> SPL >---. Perform DDR training and load the TPL
|
||||
'---------' |
|
||||
.-----------------'
|
||||
| .---------.
|
||||
'---> TPL >---. Load Linux kernel, device tree, and root filesystem
|
||||
'---------' |
|
||||
.-----------------'
|
||||
| .---------.
|
||||
'---> Infix | Get down to business
|
||||
'---------'
|
||||
```
|
||||
|
||||
After a reset, hardware will pass control to a program (_ROM_) which
|
||||
is almost always programmed into the SoC by the vendor. This program
|
||||
@@ -52,9 +51,7 @@ This document's focus is to describe the final two phases of the boot
|
||||
chain, as the initial phases are very hardware dependent, better
|
||||
described by existing documentation provided by the SoC vendor.
|
||||
|
||||
|
||||
Bootloader
|
||||
----------
|
||||
## Bootloader
|
||||
|
||||
### Configuration
|
||||
|
||||
@@ -62,33 +59,42 @@ To mitigate the risk of a malicious user being able to circumvent the
|
||||
bootloader's validation procedure, user configuration is kept to a
|
||||
minimum. Two settings are available:
|
||||
|
||||
- **Boot order**: Since Infix maintains two copies of its software image,
|
||||
and as some bootloaders support netbooting, the order in which boot
|
||||
sources are considered can be configured. To select the active
|
||||
source, use [RAUC][]:
|
||||
**Boot order**: Since Infix maintains two copies of its software image,
|
||||
and as some bootloaders support [netbooting][2], the order in which boot
|
||||
sources are considered can be configured. To select the active
|
||||
source, use [RAUC][]:
|
||||
|
||||
`rauc status mark-active <slot>`
|
||||
```
|
||||
root@example:~# rauc status mark-active <slot>
|
||||
...
|
||||
```
|
||||
|
||||
Where `<slot>` is one of:
|
||||
Where `<slot>` is one of:
|
||||
|
||||
| `<slot>` | Source |
|
||||
|----------|---------------------------|
|
||||
| rootfs.0 | Primary partition |
|
||||
| rootfs.1 | Secondary partition |
|
||||
| net.0 | Netboot (where supported) |
|
||||
| **`<slot>`** | **Source** |
|
||||
|--------------|---------------------------|
|
||||
| `rootfs.0` | Primary partition |
|
||||
| `rootfs.1` | Secondary partition |
|
||||
| `net.0` | Netboot (where supported) |
|
||||
|
||||
- **Debug**: By default, the kernel will only output errors to the
|
||||
console during boot. Optionally, this can be altered such that all
|
||||
enabled messages are logged.
|
||||
**Debug**: By default, the kernel will only output errors to the
|
||||
console during boot. Optionally, this can be altered such that all
|
||||
enabled messages are logged.
|
||||
|
||||
On systems using _U-Boot_, this can be enabled by running `fw_setenv
|
||||
DEBUG 1`. To restore the default behavior, run `fw_setenv DEBUG`.
|
||||
On systems using _U-Boot_, this can be enabled by running `fw_setenv
|
||||
DEBUG 1`. To restore the default behavior, run `fw_setenv DEBUG`.
|
||||
|
||||
On systems running _GRUB_, this can be enabled by running
|
||||
`grub-editenv /mnt/aux/grub/grubenv set DEBUG=1`. To restore the
|
||||
default behavior, run `grub-editenv /mnt/aux/grub/grubenv unset
|
||||
DEBUG`
|
||||
On systems running _GRUB_, this can be enabled by running:
|
||||
|
||||
```
|
||||
root@example:~# grub-editenv /mnt/aux/grub/grubenv set DEBUG=1
|
||||
```
|
||||
|
||||
To restore the default behavior, run:
|
||||
|
||||
```
|
||||
root@example:~# grub-editenv /mnt/aux/grub/grubenv unset DEBUG
|
||||
```
|
||||
|
||||
### U-Boot
|
||||
|
||||
@@ -107,8 +113,7 @@ and TFTP to transfer the image to the system's RAM.
|
||||
|
||||
Access to U-Boot's shell is disabled to prevent side-loading of
|
||||
malicious software. To configure the active boot partition, refer to
|
||||
the [Bootloader Interface](#bootloader-interface) section.
|
||||
|
||||
the [Bootloader Configuration](#configuration) section.
|
||||
|
||||
### GRUB
|
||||
|
||||
@@ -119,14 +124,82 @@ standard [System Upgrade](#system-upgrade) can be performed on
|
||||
virtualized instances.
|
||||
|
||||
Access to the GRUB shell is not limited in any way, and the boot
|
||||
partition can be selected interactively at boot using the arrow
|
||||
keys. It is also possible to permanently configure the default
|
||||
partition from Infix using the [Bootloader
|
||||
Interface](#bootloader-interface).
|
||||
partition can be selected interactively at boot using the arrow keys. It
|
||||
is also possible to permanently configure the default partition from
|
||||
Infix using the [Bootloader Configuration](#configuration).
|
||||
|
||||
## System Boot
|
||||
|
||||
System Upgrade
|
||||
==============
|
||||
After the system firmware (BIOS or and [boot loader](boot.md) start
|
||||
Linux the following happens. The various failure modes, e.g., missing
|
||||
password in VPD, are detailed later in this section.
|
||||
|
||||

|
||||
|
||||
1. Before mounting `/cfg` and `/var` partitions, hosting read-writable
|
||||
data like `startup-config` and container images, the system first
|
||||
checks if a factory reset has been requested by the user, if so it
|
||||
wipes the contents of these partitions
|
||||
1. Linux boots with a device tree which is used for detecting generic
|
||||
make and model of the device, e.g., number of interfaces. It may
|
||||
also reference an EEPROM with [Vital Product Data](vpd.md). That is
|
||||
where the base MAC address and per-device password hash is stored.
|
||||
(Generic builds use the same MAC address and password)
|
||||
1. On every boot the system's `factory-config` and `failure-config` are
|
||||
generated from the YANG[^2] models of the current firmware version.
|
||||
This ensures that a factory reset device can always boot, and that
|
||||
there is a working fail safe, or rather *fail secure*, mode
|
||||
1. On first power-on, and after a factory reset, the system does not
|
||||
have a `startup-config`, in which case `factory-config` is copied
|
||||
to `startup-config` -- if a per-product specific version exists it
|
||||
is preferred over the generated one
|
||||
1. Provided the integrity of the `startup-config` is OK, a system
|
||||
service loads and activates the configuration
|
||||
|
||||
### Failure Modes
|
||||
|
||||
So, what happens if any of the steps above fail?
|
||||
|
||||
#### VPD Fail
|
||||
|
||||
The per-device password cannot be read, or is corrupt, so the system
|
||||
`factory-config` and `failure-config` are not generated:
|
||||
|
||||
1. First boot, or after factory reset: `startup-config` cannot be
|
||||
created or loaded, and `failure-config` cannot be loaded. The
|
||||
system ends up in an unrecoverable state, i.e., **RMA[^3] Mode**
|
||||
1. The system has booted (at least) once with correct VPD and password
|
||||
and already has a `startup-config`. Provided the `startup-config`
|
||||
is OK (see below), it is loaded and system boots successfully
|
||||
|
||||
In both cases, external factory reset modes/button will not help, and
|
||||
in the second case will cause the device to fail on the next boot.
|
||||
|
||||
> [!NOTE]
|
||||
> The second case does not yet have any warning or event that can be
|
||||
> detected from the outside. This is planned for a later release.
|
||||
|
||||
#### Broken startup-config
|
||||
|
||||
If loading `startup-config` fails for some reason, e.g., invalid JSON
|
||||
syntax, failed validation against the system's YANG model, or a bug in
|
||||
the system's `confd` service, the *Fail Secure Mode* is triggered and
|
||||
`failure-config` is loaded (unless VPD Failure, see above).
|
||||
|
||||
> [!TIP]
|
||||
> Please see the [Branding & Releases](branding.md) document for how to
|
||||
> provide per-product `failure-config`, or `factory-config` to suit your
|
||||
> product's preferences.
|
||||
|
||||
*Fail Secure Mode* is a fail-safe mode provided for debugging the
|
||||
system. The default[^4] creates a setup of isolated interfaces with
|
||||
communication only to the management CPU, SSH and console login using
|
||||
the device's factory reset password, IP connectivity only using IPv6
|
||||
link-local, and device discovery protocols: LLDP, mDNS-SD. The login
|
||||
and shell prompt are set to `failure-c0-ff-ee`, the last three octets of
|
||||
the device's base MAC address.
|
||||
|
||||
## System Upgrade
|
||||
|
||||
Much of the minutiae of software upgrades is delegated to [RAUC][],
|
||||
which offers lots of benefits out-of-the-box:
|
||||
@@ -134,21 +207,21 @@ which offers lots of benefits out-of-the-box:
|
||||
- Upgrade Bundles are always signed, such that their authenticity can
|
||||
be verified by the running operating system, before the new one is
|
||||
installed.
|
||||
|
||||
- The bureaucracy of interfacing with different bootloaders, manage
|
||||
the boot order, is a simple matter of providing a compatible
|
||||
configuration.
|
||||
|
||||
- Updates can be sourced from the local filesystem (including external
|
||||
media like USB sticks or SD-cards) and from remote servers using FTP
|
||||
or HTTP(S).
|
||||
|
||||
To initiate a system upgrade from the shell[^1], run:
|
||||
|
||||
rauc install <file|url>
|
||||
```
|
||||
root@example:~# rauc install <file|url>
|
||||
...
|
||||
```
|
||||
|
||||
Where the file or URL points to a [RAUC Upgrade
|
||||
Bundle](#rauc-upgrade-bundle).
|
||||
Where the file or URL points to a [RAUC Upgrade Bundle](#rauc-upgrade-bundle).
|
||||
|
||||
This will upgrade the partition not currently running. After a
|
||||
successful upgrade is completed, you can reboot your system, which
|
||||
@@ -156,14 +229,9 @@ will then boot from the newly installed image. Since the partition
|
||||
from which you were originally running is now inactive, running the
|
||||
same upgrade command again will bring both partitions into sync.
|
||||
|
||||
[RAUC]: https://rauc.io
|
||||
## Image Formats
|
||||
|
||||
|
||||
Image Formats
|
||||
=============
|
||||
|
||||
SquashFS Image
|
||||
--------------
|
||||
### SquashFS Image
|
||||
|
||||
**Canonical Name**: `rootfs.squashfs`
|
||||
|
||||
@@ -174,10 +242,7 @@ this image, or is dependent on it, in one way or another.
|
||||
On its own, it can be used as an [initrd][] to efficiently boot a
|
||||
virtual instance of Infix.
|
||||
|
||||
[initrd]: https://docs.kernel.org/admin-guide/initrd.html
|
||||
|
||||
FIT Framed Squash Image
|
||||
-----------------------
|
||||
### FIT Framed Squash Image
|
||||
|
||||
**Canonical Name**: `rootfs.itb`
|
||||
|
||||
@@ -194,9 +259,9 @@ stored in the `/boot` directory of the filesystem.
|
||||
|
||||
On disk, this image is then stored broken up into its two components;
|
||||
the _FIT header_ (`rootfs.itbh`) and the SquashFS image. The header
|
||||
is stored on the [Auxiliary Data](#aux---auxiliary-data) partition of
|
||||
is stored on the [Auxiliary Data](#aux-auxiliary-data) partition of
|
||||
the [Disk Image](#disk-image), while the SquashFS image is stored in
|
||||
one of the [Root Filesystem](#primarysecondary---root-filesystems)
|
||||
one of the [Root Filesystem](#primarysecondary-root-filesystems)
|
||||
partitions.
|
||||
|
||||
When the system boots, U-Boot will concatenate the two parts to
|
||||
@@ -216,25 +281,20 @@ validate the SquashFS's contents. This path was chosen because:
|
||||
In its full form, it can be used to netboot Infix, as it contains all
|
||||
the information needed by U-Boot in a single file.
|
||||
|
||||
[FIT]: https://u-boot.readthedocs.io/en/latest/usage/fit.html
|
||||
|
||||
|
||||
RAUC Upgrade Bundle
|
||||
-------------------
|
||||
### RAUC Upgrade Bundle
|
||||
|
||||
**Canonical Name**: `infix-${ARCH}.pkg`
|
||||
|
||||
Itself a SquashFS image, it contains the Infix [SquashFS
|
||||
Image](#squashfs-image) along with the header of the [FIT Framed
|
||||
Squash Image](#fit-framed-squash-image), and some supporting files to
|
||||
let [RAUC][] know how install it on the target system.
|
||||
Itself a SquashFS image, this bundle (sometimes referred to package)
|
||||
contains the Infix [SquashFS Image](#squashfs-image) along with the
|
||||
header of the [FIT Framed Squash Image](#fit-framed-squash-image), and
|
||||
some supporting files to let [RAUC][] know how install it on the target
|
||||
system.
|
||||
|
||||
When performing a [System Upgrade](#system-upgrade), this is the
|
||||
format to use.
|
||||
When performing a [System Upgrade](#system-upgrade), this is the format
|
||||
to use.
|
||||
|
||||
|
||||
Disk Image
|
||||
----------
|
||||
### Disk Image
|
||||
|
||||
**Canonical Name**: `disk.img`
|
||||
|
||||
@@ -242,35 +302,37 @@ Infix runs from a block device (e.g. eMMC or virtio disk) with the
|
||||
following layout. The disk is expected to use the GPT partitioning
|
||||
scheme. Partitions marked with an asterisk are optional.
|
||||
|
||||
.-----------.
|
||||
| GPT Table |
|
||||
:-----------:
|
||||
| boot* |
|
||||
:-----------:
|
||||
| aux |
|
||||
:-----------:
|
||||
| |
|
||||
| primary |
|
||||
| |
|
||||
:-----------:
|
||||
| |
|
||||
| secondary |
|
||||
| |
|
||||
:-----------:
|
||||
| cfg |
|
||||
:-----------:
|
||||
| |
|
||||
| var* |
|
||||
| |
|
||||
'-----------'
|
||||
```
|
||||
.-----------.
|
||||
| GPT Table |
|
||||
:-----------:
|
||||
| boot* |
|
||||
:-----------:
|
||||
| aux |
|
||||
:-----------:
|
||||
| |
|
||||
| primary |
|
||||
| |
|
||||
:-----------:
|
||||
| |
|
||||
| secondary |
|
||||
| |
|
||||
:-----------:
|
||||
| cfg |
|
||||
:-----------:
|
||||
| |
|
||||
| var* |
|
||||
| |
|
||||
'-----------'
|
||||
```
|
||||
|
||||
### `boot` - Bootloader
|
||||
#### `boot` - Bootloader
|
||||
|
||||
| Parameter | Value |
|
||||
|-----------|-----------------------------------------|
|
||||
| Required | No |
|
||||
| Size | 4 MiB |
|
||||
| Format | Raw binary, as dictated by the hardware |
|
||||
| **Parameter** | **Value** |
|
||||
|---------------|-----------------------------------------|
|
||||
| Required | No |
|
||||
| Size | 4 MiB |
|
||||
| Format | Raw binary, as dictated by the hardware |
|
||||
|
||||
Optional partition containing the system's bootloader. May also reside
|
||||
in a separate storage device, e.g. a serial FLASH.
|
||||
@@ -278,14 +340,13 @@ in a separate storage device, e.g. a serial FLASH.
|
||||
On x86_64, this partition holds the EFI system partition, containing
|
||||
the GRUB bootloader.
|
||||
|
||||
#### `aux` - Auxiliary Data
|
||||
|
||||
### `aux` - Auxiliary Data
|
||||
|
||||
| Parameter | Value |
|
||||
|-----------|-----------------|
|
||||
| Required | Yes |
|
||||
| Size | 4 MiB |
|
||||
| Format | EXT4 filesystem |
|
||||
| **Parameter** | **Value** |
|
||||
|---------------|-----------------|
|
||||
| Required | Yes |
|
||||
| Size | 4 MiB |
|
||||
| Format | EXT4 filesystem |
|
||||
|
||||
Holds information that is shared between Infix and its bootloader,
|
||||
such as image signatures required to validate the chain of trust,
|
||||
@@ -293,10 +354,12 @@ bootloader configuration etc.
|
||||
|
||||
Typical layout when using U-Boot bootloader:
|
||||
|
||||
/
|
||||
├ primary.itbh
|
||||
├ secondary.itbh
|
||||
└ uboot.env
|
||||
```
|
||||
/
|
||||
├ primary.itbh
|
||||
├ secondary.itbh
|
||||
└ uboot.env
|
||||
```
|
||||
|
||||
During boot, an ITB header along with the corresponding root
|
||||
filesystem image are concatenated in memory, by U-Boot, to form a
|
||||
@@ -307,39 +370,36 @@ Note that the bootloader's primary environment is bundled in the
|
||||
binary - `uboot.env` is only used to import a few settings that is
|
||||
required to configure the boot order.
|
||||
|
||||
#### `primary`/`secondary` - Root Filesystems
|
||||
|
||||
### `primary`/`secondary` - Root Filesystems
|
||||
|
||||
| Parameter | Value |
|
||||
|-----------|-------------------|
|
||||
| Required | Yes |
|
||||
| Size | >= 256 MiB |
|
||||
| Format | Squash filesystem |
|
||||
| **Parameter** | **Value** |
|
||||
|---------------|-------------------|
|
||||
| Required | Yes |
|
||||
| Size | >= 256 MiB |
|
||||
| Format | Squash filesystem |
|
||||
|
||||
Holds the [SquashFS Image](#squashfs-image). Two copies exist so that
|
||||
an incomplete upgrade does not brick the system, and to allow fast
|
||||
rollbacks when upgrading to a new version.
|
||||
|
||||
#### `cfg` - Configuration Data
|
||||
|
||||
### `cfg` - Configuration Data
|
||||
|
||||
| Parameter | Value |
|
||||
|-----------|-----------------|
|
||||
| Required | Yes |
|
||||
| Size | >= 16 MiB |
|
||||
| Format | EXT4 filesystem |
|
||||
| **Parameter** | **Value** |
|
||||
|---------------|-----------------|
|
||||
| Required | Yes |
|
||||
| Size | >= 16 MiB |
|
||||
| Format | EXT4 filesystem |
|
||||
|
||||
Non-volatile storage of the system configuration and user data.
|
||||
Concretely, user data is everything stored under `/root` and `/home`.
|
||||
|
||||
#### `var` - Variable Data
|
||||
|
||||
### `var` - Variable Data
|
||||
|
||||
| Parameter | Value |
|
||||
|-----------|-----------------|
|
||||
| Required | No |
|
||||
| Size | >= 16 MiB |
|
||||
| Format | EXT4 filesystem |
|
||||
| **Parameter** | **Value** |
|
||||
|---------------|-----------------|
|
||||
| Required | No |
|
||||
| Size | >= 16 MiB |
|
||||
| Format | EXT4 filesystem |
|
||||
|
||||
Persistent storage for everything under `/var`. This is maintained as
|
||||
a separate filesystem from the data in `cfg`, because while the system
|
||||
@@ -349,5 +409,20 @@ can funtion reasonably well without a persistent `/var`, loosing
|
||||
If `var` is not available, Infix will still persist `/var/lib` using
|
||||
`cfg` as the backing storage.
|
||||
|
||||
[^1]: See [CLI Upgrade](cli/upgrade.md) for information on upgrading
|
||||
via CLI.
|
||||
[^1]: See [Upgrade & Boot Order](upgrade.md) for more information.
|
||||
[^2]: YANG is a modeling language from IETF, replacing that used for
|
||||
SNMP (MIB), used to describe the subsystems and properties of
|
||||
the system.
|
||||
[^3]: Return Merchandise Authorization (RMA), i.e., broken beyond repair
|
||||
by end-user and eligible for return to manufacturer.
|
||||
[^4]: Customer specific builds can define their own `failure-config`.
|
||||
It may be the same as `factory-config`, with the hostname set to
|
||||
`failure`, or a dedicated configuration that isolates interfaces, or
|
||||
even disables ports, to ensure that the device does not cause any
|
||||
security problems on the network. E.g., start forwarding traffic
|
||||
between previously isolated VLANs.
|
||||
|
||||
[2]: netboot.md
|
||||
[FIT]: https://u-boot.readthedocs.io/en/latest/usage/fit.html
|
||||
[RAUC]: https://rauc.io
|
||||
[initrd]: https://docs.kernel.org/admin-guide/initrd.html
|
||||
|
||||
@@ -1,11 +1,9 @@
|
||||
Branding & Releases
|
||||
===================
|
||||
# Branding & Releases
|
||||
|
||||
This document is for projects using Infix as a br2-external, i.e., OEMs.
|
||||
This document is for projects using Infix as a br2-external, i.e., OEMs
|
||||
that want to create *their own "Spin"* of Infix.
|
||||
|
||||
|
||||
Branding
|
||||
--------
|
||||
## Branding
|
||||
|
||||
Branding is done in menuconfig, there are several settings affecting
|
||||
it, most are in the Infix external subsection called "Branding", but
|
||||
@@ -24,25 +22,18 @@ check this for you and you may end up with odd results.
|
||||
|
||||
Verify the result after a build by inspecting:
|
||||
|
||||
- `output/images/*`: names, missing prefix, etc.
|
||||
- `output/target/etc/os-release`: this file is sourced by
|
||||
other build scripts, e.g., `mkgns3a.sh`. For reference, see
|
||||
https://www.freedesktop.org/software/systemd/man/os-release.html
|
||||
- `output/images/*`: names, missing prefix, etc.
|
||||
- `output/target/etc/os-release`: this file is sourced by other build
|
||||
scripts, e.g., `mkgns3a.sh`. For reference, see [os-release(5)][]
|
||||
|
||||
> **Note:** to get proper GIT revision (hash) from your composed OS,
|
||||
> remember in menuconfig to set `INFIX_OEM_PATH`. When unset the
|
||||
> Infix `post-build.sh` script defaults to the Infix base path. The
|
||||
> revision is stored in the file `/etc/os-release` as BUILD_ID and
|
||||
> is also in the file `/etc/version`. See below for more info.
|
||||
> [!IMPORTANT]
|
||||
> To get a proper GIT revision (hash) from your OS spin, remember to set
|
||||
> in menuconfig `INFIX_OEM_PATH`. When unset, the Infix `post-build.sh`
|
||||
> script defaults to the Infix base path. The revision is stored in the
|
||||
> file `/etc/os-release` as `BUILD_ID`, also in the file `/etc/version`.
|
||||
> See below for more info.
|
||||
|
||||
[^1]: The base MAC address is defined in the device's Vital Product
|
||||
Data (VPD) EEPROM, or similar, which is used by the kernel to
|
||||
create the system interfaces. This MAC address is usually also
|
||||
printed on a label on the device.
|
||||
|
||||
|
||||
Factory & Failure Config
|
||||
------------------------
|
||||
## Factory & Failure Config
|
||||
|
||||
To support booting the same image (CPU architecture) on multiple boards,
|
||||
Infix by default generates the device's initial configuration every time
|
||||
@@ -50,37 +41,36 @@ at boot. This also ensures the device can always be restored to a known
|
||||
state after a factory reset, since the `factory-config` is guaranteed to
|
||||
be compatible with the YANG models for the given software version. (For
|
||||
more information on how the system boots, please see the section [Key
|
||||
Concepts](introduction.md#key-concepts) in the Introduction document.)
|
||||
Concepts](index.md#key-concepts) in the Introduction document.)
|
||||
|
||||
However, for custom builds of Infix it is possible to override this with
|
||||
a single static `/etc/factory-config.cfg` (and failure-config) in your
|
||||
rootfs overlay -- with a [VPD](vpd.md) you can even support several!
|
||||
|
||||
|
||||
### Variables & Format Specifiers
|
||||
|
||||
Parts of the configuration you likely always want to generated, like the
|
||||
SSH hostkey used by NETCONF, a unique hostname, or the `admin` user's
|
||||
SSH hostkey used by SSH server and NETCONF, a unique hostname, or the `admin` user's
|
||||
unique (per-device with a VPD) password hash. This section lists the
|
||||
available keywords, see the next section for examples of how to use
|
||||
them:
|
||||
|
||||
- **Default password hash:** `$factory$` (from VPD, .dtb, or built-in)
|
||||
XPath: `/ietf-system:system/authentication/user/password`
|
||||
- **Default NETCONF hostkey:** `genkey` (regenerated at factory reset)
|
||||
XPath: `/ietf-keystore:keystore/asymmetric-keys/asymmetric-key[name='genkey']`
|
||||
- **Hostname format specifiers:**
|
||||
XPath: `/ietf-system:system/hostname`
|
||||
- **Default password hash:** `$factory$` (from VPD, .dtb, or built-in)
|
||||
XPath: `/ietf-system:system/authentication/user/password`
|
||||
- **Default SSH and NETCONF hostkey:** `genkey` (regenerated at factory reset)
|
||||
XPath: `/ietf-keystore:keystore/asymmetric-keys/asymmetric-key[name='genkey']`
|
||||
- **Hostname format specifiers:**
|
||||
XPath: `/ietf-system:system/hostname`
|
||||
- `%i`: OS ID, from `/etc/os-release`, from Menuconfig branding
|
||||
- `%h`: Default hostname, from `/etc/os-release`, from branding
|
||||
- `%m`: NIC specific part of base MAC, e.g., to `c0-ff-ee`
|
||||
- `%%`: Literal %
|
||||
|
||||
|
||||
### Static Files
|
||||
|
||||
> **Caveat:** maintaining static a factory-config and failure-config may
|
||||
> seem like an obvious choice, but as YANG models evolve (even the IETF
|
||||
> [!CAUTION]
|
||||
> Maintaining a static `factory-config` and `failure-config` may seem
|
||||
> like an obvious choice, but as YANG models evolve (even the IETF
|
||||
> models get upgraded), you may need to upgrade your static files.
|
||||
|
||||
First, for one-off builds (one image per product), the simplest way is
|
||||
@@ -103,9 +93,8 @@ after `00-probe` has run. The lower case version of the string is used.
|
||||
|
||||
I.e., create a rootfs overlay that provides any combination of:
|
||||
|
||||
- `/usr/share/product/<PRODUCT>/etc/factory-config.cfg`
|
||||
- `/usr/share/product/<PRODUCT>/etc/failure-config.cfg`
|
||||
|
||||
- `/usr/share/product/<PRODUCT>/etc/factory-config.cfg`
|
||||
- `/usr/share/product/<PRODUCT>/etc/failure-config.cfg`
|
||||
|
||||
### Dynamically Generated
|
||||
|
||||
@@ -113,14 +102,14 @@ The generated `factory-config` and `failure-config` files consist of
|
||||
both static JSON files and part generated files at runtime for each
|
||||
device. The resulting files are written to the RAM disk in `/run`:
|
||||
|
||||
- `/run/confd/factory-config.gen`
|
||||
- `/run/confd/failure-config.gen`
|
||||
- `/run/confd/factory-config.gen`
|
||||
- `/run/confd/failure-config.gen`
|
||||
|
||||
Provided no custom overrides (see above) have been installed already,
|
||||
these files are then copied to:
|
||||
|
||||
- `/etc/factory-config.cfg`
|
||||
- `/etc/failure-config.cfg`
|
||||
- `/etc/factory-config.cfg`
|
||||
- `/etc/failure-config.cfg`
|
||||
|
||||
... where the bootstrap process expects them to be in the next step.
|
||||
|
||||
@@ -132,29 +121,33 @@ base hostname, set `BR2_TARGET_GENERIC_HOSTNAME` in your defconfig.
|
||||
The static files are installed by Infix `confd` in `/usr/share/confd/`
|
||||
at build time. It contains two subdirectories:
|
||||
|
||||
/usr/share/confd/
|
||||
|- factory.d/
|
||||
| |- 10-foo.json
|
||||
| |- 10-bar.json
|
||||
| `- 10-qux.json
|
||||
`- failure.d/
|
||||
|- 10-xyzzy.json
|
||||
`- 10-garply.json
|
||||
```
|
||||
/usr/share/confd/
|
||||
|- factory.d/
|
||||
| |- 10-foo.json
|
||||
| |- 10-bar.json
|
||||
| `- 10-qux.json
|
||||
`- failure.d/
|
||||
|- 10-xyzzy.json
|
||||
`- 10-garply.json
|
||||
```
|
||||
|
||||
To override, or extend, these files in you br2-external, set up a rootfs
|
||||
overlay and add it last in `BR2_ROOTFS_OVERLAY`. Your overlay can look
|
||||
something like this:
|
||||
|
||||
./board/common/rootfs/
|
||||
|- etc/
|
||||
| |- confdrc # See below
|
||||
| `- confdrc.local
|
||||
`- usr/
|
||||
`- share/
|
||||
`- confd/
|
||||
|- 10-foo.json # Override Infix foo
|
||||
|- 30-bar.json # Extend, probably 10-bar.json
|
||||
`- 30-fred.json # Extend, your own defaults
|
||||
```
|
||||
./board/common/rootfs/
|
||||
|- etc/
|
||||
| |- confdrc # See below
|
||||
| `- confdrc.local
|
||||
`- usr/
|
||||
`- share/
|
||||
`- confd/
|
||||
|- 10-foo.json # Override Infix foo
|
||||
|- 30-bar.json # Extend, probably 10-bar.json
|
||||
`- 30-fred.json # Extend, your own defaults
|
||||
```
|
||||
|
||||
Using the same filename in your overlay, here `10-foo.json`, completely
|
||||
replaces the contents of the same file provided by Infix. If you just
|
||||
@@ -168,17 +161,17 @@ provide a few custom ones that the `bootstrap` knows about, e.g.,
|
||||
`gen-ifs-custom` that overrides `20-interfaces.json`. See the
|
||||
bootstrap script for more help, and up-to-date information.
|
||||
|
||||
> **Note:** you may not need to provide your own `/etc/confdrc`. The
|
||||
> one installed by `confd` is usually enough. However, if you want to
|
||||
> adjust the behavior of `bootstrap` you may want to override it. There
|
||||
> is also `confdrc.local`, which usually is enough to change arguments
|
||||
> to scripts like `gen-interfaces`, e.g., to create a bridge by default,
|
||||
> you may want to look into `GEN_IFACE_OPTS`.
|
||||
|
||||
> [!TIP]
|
||||
> You may not need to provide your own `/etc/confdrc` for your spin.
|
||||
> The one installed by `confd` is usually enough. However, if you want
|
||||
> to adjust the behavior of `bootstrap` you may want to override it.
|
||||
> There is also `confdrc.local`, which usually is enough to change
|
||||
> arguments to scripts like `gen-interfaces`, e.g., to create a bridge
|
||||
> by default, you may want to look into `GEN_IFACE_OPTS`.
|
||||
|
||||
### Example Snippets
|
||||
|
||||
**IETF System:**
|
||||
#### IETF System
|
||||
|
||||
```hsib
|
||||
"ietf-system:system": {
|
||||
@@ -211,18 +204,19 @@ bootstrap script for more help, and up-to-date information.
|
||||
The `motd-banner` is a binary type, which is basically a Base64 encoded
|
||||
text file without line breaks (`-w0`):
|
||||
|
||||
```bash
|
||||
$ echo "Li0tLS0tLS0uCnwgIC4gLiAgfCBJbmZpeCAtLSBhIE5ldHdvcmsgT3BlcmF0aW5nIFN5c3RlbQp8LS4gdiAuLXwgaHR0cHM6Ly9rZXJuZWxraXQuZ2l0aHViLmlvCictJy0tLSctJwo=" |base64 -d
|
||||
```
|
||||
$ echo "Li0tLS0tLS0uCnwgIC4gLiAgfCBJbmZpeCAtLSBhIE5ldHdvcmsgT3BlcmF0aW5nIFN5c3RlbQp8LS4gdiAuLXwgaHR0cHM6Ly9rZXJuZWxraXQuZ2l0aHViLmlvCictJy0tLSctJwo=" \
|
||||
| base64 -d
|
||||
.-------.
|
||||
| . . | Infix -- a Network Operating System
|
||||
| . . | Infix OS — Immutable.Friendly.Secure
|
||||
|-. v .-| https://kernelkit.github.io
|
||||
'-'---'-'
|
||||
```
|
||||
|
||||
**IETF Keystore**
|
||||
#### IETF Keystore
|
||||
|
||||
Notice how both the public and private keys are left empty here. The
|
||||
`genkey` is always automatically regenerated after each factory reset.
|
||||
Notice how both the public and private keys are left empty here, this
|
||||
cause them to be always automatically regenerated after each factory reset.
|
||||
Keeping the `factory-config` snippet like this means we can use the same
|
||||
file on multiple devices, without risking them sharing the same host
|
||||
keys. Sometimes you may want the same host keys, but that is the easy
|
||||
@@ -245,9 +239,7 @@ use-case and not documented here.
|
||||
},
|
||||
```
|
||||
|
||||
The `genkey` is currently only used by the NETCONF SSH backend.
|
||||
|
||||
**IETF NETCONF Server**
|
||||
#### IETF NETCONF Server
|
||||
|
||||
```json
|
||||
"ietf-netconf-server:netconf-server": {
|
||||
@@ -280,10 +272,30 @@ The `genkey` is currently only used by the NETCONF SSH backend.
|
||||
},
|
||||
```
|
||||
|
||||
#### Infix Services
|
||||
|
||||
```json
|
||||
"infix-services:ssh": {
|
||||
"enabled": true,
|
||||
"hostkey": [
|
||||
"genkey"
|
||||
],
|
||||
"listen": [
|
||||
{
|
||||
"name": "ipv4",
|
||||
"address": "0.0.0.0",
|
||||
"port": 22
|
||||
},
|
||||
{
|
||||
"name": "ipv6",
|
||||
"address": "::1",
|
||||
"port": 22
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
Integration
|
||||
-----------
|
||||
## Integration
|
||||
|
||||
When integrating your software stack with Infix there may be protocols
|
||||
that want to change system settings like hostname and dynamically set
|
||||
@@ -310,7 +322,7 @@ root@infix-00-00-00:~# cat hostnm.xml
|
||||
</system>
|
||||
root@infix-00-00-00:~# edit hostnm.xml
|
||||
root@infix-00-00-00:~# sysrepocfg -Ehostnm.xml
|
||||
root@example:~#
|
||||
root@example:~#
|
||||
```
|
||||
|
||||
Second, perform all changes on `running-config`, the running datastore.
|
||||
@@ -324,8 +336,8 @@ activate all.)
|
||||
|
||||
You can consider the system composed of two entities:
|
||||
|
||||
- NETCONF starts up the system using `startup-config`, then
|
||||
- Hands over control to your application at runtime
|
||||
- NETCONF starts up the system using `startup-config`, then
|
||||
- Hands over control to your application at runtime
|
||||
|
||||
Infix is prepared for this by already having two "runlevels" for these
|
||||
two states. The `startup-config` is applied in runlevel S (bootstrap)
|
||||
@@ -333,15 +345,13 @@ and the system then enters runlevel 2 for normal operation.
|
||||
|
||||
This allow you to keep a set of functionality that is provided by the
|
||||
underlying system, and another managed by your application. You can
|
||||
of course in your br2-external provide a sysrepo plugin that block
|
||||
of course in your br2-external provide a sysrepo plugin that block
|
||||
operations on certain datastores when your application is enabled.
|
||||
E.g., to prevent changes to startup after initial deployment. In
|
||||
that case a proper factory reset would be needed to get back to a
|
||||
"pre-deployment" state where you can reconfigure your baseline.
|
||||
|
||||
|
||||
Releases
|
||||
--------
|
||||
## Releases
|
||||
|
||||
A release build requires the global variable `INFIX_RELEASE` to be set.
|
||||
It can be derived from GIT, if the source tree is kept in GIT VCS. First,
|
||||
@@ -351,14 +361,14 @@ let us talk about versioning in general.
|
||||
|
||||
Two popular scheme for versioning a product derived from Infix:
|
||||
|
||||
1. Track Infix major.minor, e.g. *Foobar v23.08.z*, where `z` is
|
||||
your patch level. I.e., Foobar v23.08.0 could be based on Infix
|
||||
v23.08.0, or v23.08.12, it is up to you. Maybe you based it on
|
||||
v23.08.12 and then back ported changes from v23.10.0, but it was
|
||||
the first release you made to your customer(s).
|
||||
2. Start from v1.0.0 and step the major number every time you sync
|
||||
with a new Infix release, or every time Infix bumps to the next
|
||||
Buildroot LTS.
|
||||
1. Track Infix major.minor, e.g. *Foobar v23.08.z*, where `z` is
|
||||
your patch level. I.e., Foobar v23.08.0 could be based on Infix
|
||||
v23.08.0, or v23.08.12, it is up to you. Maybe you based it on
|
||||
v23.08.12 and then back ported changes from v23.10.0, but it was
|
||||
the first release you made to your customer(s).
|
||||
1. Start from v1.0.0 and step the major number every time you sync
|
||||
with a new Infix release, or every time Infix bumps to the next
|
||||
Buildroot LTS.
|
||||
|
||||
The important thing is to be consistent, not only for your own sake,
|
||||
but also for your end customers. The *major.minor.patch* style is
|
||||
@@ -366,26 +376,40 @@ the most common and often recommended style, which usually maps well
|
||||
to other systems, e.g. PROFINET GSDML files require this (*VX.Y.Z*).
|
||||
But you can of course use only two numbers, *major.minor*, as well.
|
||||
|
||||
> [!WARNING]
|
||||
> What could be confusing, however, is if you use the name *Infix*
|
||||
> with your own versioning scheme.
|
||||
|
||||
### Specifying Versioning Information
|
||||
|
||||
### `INFIX_RELEASE`
|
||||
Two optional environment variables control the version information
|
||||
recorded in images. Both of these **must be** a lower-case string (no
|
||||
spaces or other characters outside of 0–9, a–z, '.', '_' and '-')
|
||||
identifying the operating system version, excluding any OS name
|
||||
information or release code name, and suitable for processing by
|
||||
scripts or usage in generated filenames.
|
||||
|
||||
This global variable **must be** a lower-case string (no spaces or
|
||||
other characters outside of 0–9, a–z, '.', '_' and '-') identifying
|
||||
the operating system version, excluding any OS name information or
|
||||
release code name, and suitable for processing by scripts or usage
|
||||
in generated filenames.
|
||||
#### `INFIX_BUILD_ID`
|
||||
|
||||
Used for `BUILD_ID` in `/etc/os-release`.
|
||||
|
||||
**Default:** `$(git describe --always --dirty --tags)`, from the _top
|
||||
directory_. By default, the top directory refers to the root of the
|
||||
Infix source tree, but this can be changed by setting the branding
|
||||
variable `INFIX_OEM_PATH`, e.g. in a `defconfig` file or via `make
|
||||
menuconfig`, to the path of an enclosing br2-external.
|
||||
|
||||
#### `INFIX_RELEASE`
|
||||
|
||||
Used for `VERSION` and `VERSION_ID` in `/etc/os-release` and
|
||||
generated file names like disk images, etc.
|
||||
|
||||
**Default:** generated using `git describe --always --dirty --tags`,
|
||||
with an additional `-C $infix_path`. This variable defaults to the
|
||||
Infix tree and can be changed by setting the menuconfig branding
|
||||
variable `INFIX_OEM_PATH` to that of the br2-external. It is also
|
||||
possible to set the `GIT_VERSION` variable in your `post-build.sh`
|
||||
script to change how the VCS version is extracted.
|
||||
**Default:** `${INFIX_BUILD_ID}`
|
||||
|
||||
[NanoPi R2S]: https://github.com/kernelkit/infix/blob/main/board/aarch64/r2s/rootfs/etc/factory-config.cfg
|
||||
[^1]: The base MAC address is defined in the device's Vital Product
|
||||
Data (VPD) EEPROM, or similar, which is used by the kernel to
|
||||
create the system interfaces. This MAC address is usually also
|
||||
printed on a label on the device.
|
||||
|
||||
[NanoPi R2S]: https://github.com/kernelkit/infix/blob/main/board/aarch64/r2s/rootfs/etc/factory-config.cfg
|
||||
[os-release(5)]: https://www.freedesktop.org/software/systemd/man/os-release.html
|
||||
|
||||
@@ -1,5 +1,4 @@
|
||||
Configure Context
|
||||
-----------------
|
||||
# CLI Configure Context
|
||||
|
||||
Enter the configure context from admin-exec by typing `configure`
|
||||
followed by Enter. Available commands, press `?` at the prompt:
|
||||
@@ -41,14 +40,17 @@ admin@host:/config/interface/eth0/> up
|
||||
admin@host:/config/>
|
||||
```
|
||||
|
||||
> **Note:** the tree structure in the configure context is automatically
|
||||
> generated from the system's supported NETCONF YANG models, which may
|
||||
> vary between products. However, the `ietf-interfaces.yang` and
|
||||
> `ietf-ip.yang` models, for instance, that provide basic networking
|
||||
----
|
||||
|
||||
> **Note:** commands in configure context are automatically generated
|
||||
> from the system's YANG models, hence different products likely have a
|
||||
> different set of commands. However, both the `ietf-interfaces.yang`
|
||||
> and `ietf-ip.yang` models, for instance, that provide the networking
|
||||
> support are common to all systems.
|
||||
|
||||
----
|
||||
|
||||
### Set IP Address on an Interface
|
||||
## Set IP Address on an Interface
|
||||
|
||||
```
|
||||
admin@host:/config/> edit interface eth0
|
||||
@@ -73,7 +75,7 @@ interfaces {
|
||||
```
|
||||
|
||||
|
||||
### Saving Changes
|
||||
## Saving Changes
|
||||
|
||||
Apply the changes (from candidate to `running-config`):
|
||||
|
||||
@@ -104,11 +106,14 @@ admin@host:/> copy running-config startup-config
|
||||
The `startup-config` can also be inspected with the `show` command to
|
||||
verify the changes are saved.
|
||||
|
||||
> **Note:** most (all) commands need to be spelled out, no short forms
|
||||
> are allowed at the moment. Use the `TAB` key to make this easier.
|
||||
----
|
||||
|
||||
> **Note:** all commands need to be spelled out, no short forms are
|
||||
> allowed in the CLI. Use the `TAB` key to make your life easier.
|
||||
|
||||
### Changing Hostname
|
||||
----
|
||||
|
||||
## Changing Hostname
|
||||
|
||||
Settings like hostname are located in the `ietf-system.yang` model.
|
||||
Here is how it can be set.
|
||||
@@ -123,11 +128,14 @@ admin@example:/>
|
||||
Notice how the hostname in the prompt does not change until the change
|
||||
is committed.
|
||||
|
||||
----
|
||||
|
||||
> **Note:** critical services like syslog, mDNS, LLDP, and similar that
|
||||
> advertise the hostname, are restarted when the hostname is changed.
|
||||
|
||||
----
|
||||
|
||||
### Changing Password
|
||||
## Changing Password
|
||||
|
||||
User management, including passwords, is also a part of `ietf-system`.
|
||||
|
||||
@@ -149,12 +157,15 @@ the `do password encrypt` command. This launches the admin-exec command
|
||||
to hash, and optionally salt, your password. This encrypted string can
|
||||
then be used with `set password ...`.
|
||||
|
||||
----
|
||||
|
||||
> **Tip:** if you are having trouble thinking of a password, there is
|
||||
> also `do password generate`, which generates random but readable
|
||||
> strings using the UNIX command `pwgen`.
|
||||
|
||||
----
|
||||
|
||||
### SSH Authorized Key
|
||||
## SSH Authorized Key
|
||||
|
||||
Logging in remotely with SSH is possible by adding a *public key* to a
|
||||
user. Here we add the authorized key to the admin user, multiple keys
|
||||
@@ -174,11 +185,15 @@ key-data AAAAB3NzaC1yc2EAAAADAQABAAABgQC8iBL42yeMBioFay7lty1C4ZDTHcHyo739gc91rTT
|
||||
admin@host:/config/system/authentication/user/admin/authorized-key/example@host/> leave
|
||||
```
|
||||
|
||||
----
|
||||
|
||||
> **Note:** the `ssh-keygen` program already base64 encodes the public
|
||||
> key data, so there is no need to use the `text-editor` command, `set`
|
||||
> does the job.
|
||||
|
||||
### Creating a VETH Pair
|
||||
----
|
||||
|
||||
## Creating a VETH Pair
|
||||
|
||||
The following example creates a `veth0a <--> veth0b` virtual Ethernet
|
||||
pair which is useful for connecting, e.g., a container to the physical
|
||||
@@ -214,12 +229,15 @@ admin@host:/config/> leave
|
||||
|
||||
See the bridging example below for more.
|
||||
|
||||
----
|
||||
|
||||
> **Note:** in the CLI you do not have to create the `veth0b` interface.
|
||||
> The system _infers_ this for you. When setting up a VETH pair using
|
||||
> NETCONF, however, you must include the `veth0b` interface.
|
||||
|
||||
----
|
||||
|
||||
### Creating a Bridge
|
||||
## Creating a Bridge
|
||||
|
||||
Building on the previous example, we now create a non-VLAN filtering
|
||||
bridge (`br0`) that forwards any, normally link-local, LLDP traffic
|
||||
@@ -273,6 +291,10 @@ the VETH pair from the previous example) are now bridged. Any traffic
|
||||
ingressing one port will egress the other. Only reserved IEEE multicast
|
||||
is filtered, except LLDP frames as shown above.
|
||||
|
||||
----
|
||||
|
||||
> **Note:** the bridge can be named anything, provided the interface
|
||||
> name is not already taken. However, for any name outside the pattern
|
||||
> `br[0-9]+`, you have to set the interface type manually to `bridge`.
|
||||
|
||||
----
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Introduction
|
||||
# CLI Introduction
|
||||
|
||||
The command line interface (CLI, see-ell-aye) implements a CISCO-like,
|
||||
or Juniper Networks JunOS-like, CLI. It is the traditional way of
|
||||
@@ -10,8 +10,7 @@ Nevertheless, when it comes to initial deployment and debugging, it
|
||||
is very useful to know how to navigate and use the CLI. This very
|
||||
short guide intends to help you with that.
|
||||
|
||||
|
||||
## About
|
||||
----
|
||||
|
||||
New users usually get the CLI as the default "shell" when logging in,
|
||||
but the default `admin` user logs in to `bash`. To access the CLI,
|
||||
@@ -35,9 +34,12 @@ admin@host-12-34-56:/> show # Try: Tab or ?
|
||||
admin@host-12-34-56:/> # Try: Tab or ?
|
||||
```
|
||||
|
||||
> **Tip:** Even on an empty command line you can tap the Tab or ? keys.
|
||||
> See `help keybindings` for more tips!
|
||||
----
|
||||
|
||||
> **Note:** even on an empty command line, you can tap the `Tab` or `?` keys.
|
||||
> See [`help keybindings`](keybindings.md) for more tips!
|
||||
|
||||
----
|
||||
|
||||
## Key Concepts
|
||||
|
||||
@@ -129,10 +131,15 @@ In *configure context* the following commands are available:
|
||||
| `do command` | Call admin-exec command: `do show log` |
|
||||
| `commit` | |
|
||||
|
||||
### Example Session
|
||||
|
||||
> Remember to use the `TAB` and `?` keys to speed up your navigation.
|
||||
> See `help keybindings` for more tips!
|
||||
## Example Session
|
||||
|
||||
----
|
||||
|
||||
> Remember to use the `TAB` and `?` keys to speed up your navigation.
|
||||
> See [`help keybindings`](keybindings.md) for more tips!
|
||||
|
||||
----
|
||||
|
||||
In this example we enter configure context to add an IPv4 address to
|
||||
interface `eth0`, then we apply the changes using the `leave` command.
|
||||
@@ -180,4 +187,3 @@ admin@host-12-34-56:/> copy startup-config running-config
|
||||
```
|
||||
|
||||
Or restarting the device.
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Keybindings
|
||||
# CLI Keybindings
|
||||
|
||||
Writing CLI commands by hand is very tedious. To make things easier the
|
||||
CLI has several keybindings, most significant first:
|
||||
@@ -27,10 +27,12 @@ CLI has several keybindings, most significant first:
|
||||
| Ctrl-n | Down arrow | History, next command |
|
||||
| Ctrl-r | | History, reversed interactive search (i-search) |
|
||||
|
||||
> **Note:** the Meta key is called Alt on most modern keyboards. If you
|
||||
> have neither, first tap the Esc key instead of holding down Alt/Meta.
|
||||
## What is Meta?
|
||||
|
||||
## Examples
|
||||
The Meta key is called Alt on most modern keyboards. If you have
|
||||
neither, first tap the Esc key instead of holding down Alt/Meta.
|
||||
|
||||
## Usage
|
||||
|
||||
Complete a word. Start by typing a few characters, then tap the TAB key
|
||||
on your keyboard:
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
## Usage
|
||||
# Network Calculator
|
||||
|
||||
```
|
||||
netcalc <ADDRESS/LEN | NETWORK NETMASK> [split <1-32 | 64-128>]
|
||||
@@ -12,8 +12,8 @@ information about the subnet. Both IPv4 and IPv6 is supported.
|
||||
|
||||
A subnet can be entered in two ways:
|
||||
|
||||
- `192.168.2.0 255.255.255.0`: traditional IPv4 'address netmask' style
|
||||
- `192.168.2.0/24`: modern prefix length, same also for IPv6
|
||||
- `192.168.2.0 255.255.255.0`: traditional IPv4 'address netmask' style
|
||||
- `192.168.2.0/24`: modern prefix length, same also for IPv6
|
||||
|
||||
An optional `split LEN` can be given as argument, the new length value
|
||||
must be bigger than the current prefix length. See example below.
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Quick Overview
|
||||
# CLI Quickstart Guide
|
||||
|
||||
The question mark `?` key along with the `Tab` key are your best friends
|
||||
in the command line interface. They provide context help and completion
|
||||
@@ -16,14 +16,17 @@ of commands you input. See the table below for a handful of examples.
|
||||
Explore the following topics for more information. Note, the
|
||||
keybindings are really useful to learn!
|
||||
|
||||
| **Command** | **Description** |
|
||||
|---------------------|--------------------------------------------|
|
||||
| `help introduction` | An introduction to the CLI |
|
||||
| `help configure` | How to use configure context |
|
||||
| `help text-editor` | Help with the built-in text-editor command |
|
||||
| `help keybindings` | Lists keybindings and other helpful tricks |
|
||||
| **Command** | **Description** |
|
||||
|---------------------|----------------------------------------------------|
|
||||
| `help introduction` | An introduction to the CLI |
|
||||
| `help configure` | How to use configure context |
|
||||
| `help text-editor` | Help with the built-in text-editor command |
|
||||
| `help keybindings` | Lists available keybindings & other helpful tricks |
|
||||
|
||||
----
|
||||
|
||||
> In `configure` context the `help setting` command shows the YANG
|
||||
> description text for each node and container. To reach the admin
|
||||
> exec help from configure context, e.g., `do help text-editor`
|
||||
|
||||
----
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
## Network Traffic Inspection
|
||||
# Network Monitoring
|
||||
|
||||
`tcpdump` is useful tool for analyzing and diagnosing network problems.
|
||||
This document presents the limited feature set that exposed is in the
|
||||
@@ -10,7 +10,7 @@ A section called [Examples](#examples) follows that, which may be what
|
||||
you want to scroll down to.
|
||||
|
||||
|
||||
### Hardware Overview
|
||||
## Hardware Overview
|
||||
|
||||
Using `tcpdump` effectively requires an understanding of how the
|
||||
underlying hardware works. For a standard PC, or common single-board
|
||||
@@ -57,17 +57,21 @@ up the switch core to mirror traffic ingressing and/or egressing a set
|
||||
of ports to another port. On this *monitor port* you can then run your
|
||||
tcpdump, which means you need an external device (laptop).
|
||||
|
||||
----
|
||||
|
||||
> A planned feature is to support mirroring traffic to the CPU port,
|
||||
> which would be an effective way to log and monitor traffic over a
|
||||
> longer period of time. Highly effective for diagnosing intermittent
|
||||
> and other rare network issues.
|
||||
|
||||
----
|
||||
|
||||
If only "proof of life" is required, then sometimes port counters, also
|
||||
called *RMON counters*, can be very useful too. Seeing counters of a
|
||||
particular type increment means traffic is ingressing or egressing.
|
||||
|
||||
|
||||
### Examples
|
||||
## Examples
|
||||
|
||||
Listen to all traffic on an interface:
|
||||
|
||||
|
||||
@@ -44,10 +44,13 @@ C-x i insert C-x g goto-ln C-x o other win C-x C-x swap M-q reform
|
||||
- tap `c`
|
||||
- release `Ctrl`
|
||||
|
||||
----
|
||||
|
||||
> The status field at the bottom asks if you are really sure, and/or if
|
||||
> you want to add a final Enter/newline to the file. For binary content
|
||||
> that final newline may be important.
|
||||
|
||||
----
|
||||
|
||||
## Changing the Editor
|
||||
|
||||
|
||||
@@ -1,5 +1,4 @@
|
||||
Upgrading the Software
|
||||
----------------------
|
||||
# Upgrading the System
|
||||
|
||||
The admin-exec command `upgrade` can be used to install software images, or
|
||||
bundles. A bundle is a signed and self-contained package that carries all the
|
||||
@@ -39,6 +38,8 @@ The secondary partition (`rootfs.1`) has now been upgraded and will be used as
|
||||
the *active* partition on the next boot. Leaving the primary partition, with
|
||||
the version we are currently running, intact in case of trouble.
|
||||
|
||||
See [Upgrade & Boot Order](../upgrade.md) for more information on upgrading.
|
||||
|
||||
[^1]: It is not possible to upgrade the partition we booted from. Thankfully
|
||||
the underlying "rauc" subsystem keeps track of this. Hence, to upgrade
|
||||
both partitions you must reboot to the new version (to verify it works)
|
||||
|
||||
@@ -1,39 +1,15 @@
|
||||
Containers in Infix
|
||||
===================
|
||||
<img align="right" src="img/docker.webp" alt="Docker whale" width=360>
|
||||
Docker Container Support
|
||||
========================
|
||||
|
||||
* [Introduction](#introduction)
|
||||
* [Caution](#caution)
|
||||
* [Getting Started](#getting-started)
|
||||
* [Examples](#examples)
|
||||
* [Container Images](#container-images)
|
||||
* [Upgrading a Container Image](#upgrading-a-container-image)
|
||||
* [Networking and Containers](#networking-and-containers)
|
||||
* [Container Bridge](#container-bridge)
|
||||
* [Container Host Interface](#container-host-interface)
|
||||
* [Host Networking](#host-networking)
|
||||
* [Mounts and Volumes](#mounts-and-volumes)
|
||||
* [Content Mounts](#content-mounts)
|
||||
* [Example Containers](#example-containers)
|
||||
* [System Container](#system-container)
|
||||
* [Application Container: nftables](#application-container-nftables)
|
||||
* [Application Container: ntpd](#application-container-ntpd)
|
||||
* [Advanced](#advanced)
|
||||
* [Running Host Commands From Container](#running-host-commands-from-container)
|
||||
* [Container Requirements](#container-requirements)
|
||||
* [Advanced Users](#advanced-users)
|
||||
|
||||
|
||||
Introduction
|
||||
------------
|
||||
{ align=right width="360" }
|
||||
|
||||
Infix comes with native support for Docker containers using [podman][].
|
||||
The [YANG model][1] describes the current level of support, complete
|
||||
enough to run both system and application containers.
|
||||
|
||||
Key design features, like using Linux switchdev, allow users to assign
|
||||
switch ports directly to containers, not just bridged VETH pairs, this
|
||||
is a rare and in many cases *unique* feature of Infix.
|
||||
Key design features of Infix, like using Linux switchdev, allow users to
|
||||
assign switch ports directly to containers, not just bridged VETH pairs.
|
||||
This is a rare and in many cases *unique* feature of Infix.
|
||||
|
||||
All network specific settings are done using the IETF interfaces YANG
|
||||
model, with augments for containers to ensure smooth integration with
|
||||
@@ -43,7 +19,7 @@ container networking in podman.
|
||||
> Even though the `podman` command can be used directly from a shell
|
||||
> prompt, we strongly recommend using the CLI commands instead. They
|
||||
> employ the services of a wrapper `container` script which handles the
|
||||
> integration of containers in the system.
|
||||
> integration of Docker containers in the system.
|
||||
|
||||
|
||||
Caution
|
||||
@@ -83,18 +59,20 @@ In the CLI, containers can be run in one of two ways:
|
||||
1. `container run IMAGE [COMMAND]`, or
|
||||
2. enter `configure` context, then `edit container NAME`
|
||||
|
||||
The former is useful mostly for testing, or running single commands in
|
||||
an image. It is a wrapper for `podman run -it --rm ...`, while the
|
||||
latter is a wrapper and adaptation of `podman create ...`.
|
||||
The first is useful mostly for testing, or running single commands in
|
||||
an image. It is a wrapper for `podman run -it --rm ...`.
|
||||
|
||||
The second creates a read-only container that is automatically started
|
||||
at every boot. When non-volatile storage is needed, data stored in a
|
||||
volume is persisted until explicitly removed from the configuration,
|
||||
i.e., across host and container reboots and upgrades.
|
||||
The second creates a read-only container that by default automatically
|
||||
start at every boot. It basically wraps `podman create ...`.
|
||||
|
||||
Another option is [Content Mounts](#content-mounts), where the content
|
||||
of a file mounted into the container is kept along with the container
|
||||
configuration in the device's `startup-config`.
|
||||
When non-volatile storage is needed two complementary options exist:
|
||||
|
||||
- **Volumes:** data stored in a volume is persisted until explicitly
|
||||
removed from the configuration, i.e., across host reboots and
|
||||
container upgrades
|
||||
- **[Content Mounts](#content-mounts):** where the content of a file
|
||||
mounted into the container is kept along with the container
|
||||
configuration in the device's `startup-config`
|
||||
|
||||
Podman ensures (using tmpfs) all containers have writable directories
|
||||
for certain critical file system paths: `/dev`, `/dev/shm`, `/run`,
|
||||
@@ -108,10 +86,9 @@ your container image and application to run.
|
||||
> support the CPU architecture of your host system. Remember, unlike
|
||||
> virtualization, containers reuse the host's CPU and kernel.
|
||||
|
||||
{ align=right width="200" }
|
||||
|
||||
<img align="right" src="img/docker-hello-world.svg" alt="Hello World" width=360>
|
||||
|
||||
### Examples
|
||||
### Example: Hello World
|
||||
|
||||
Classic Hello World:
|
||||
|
||||
@@ -127,24 +104,32 @@ Classic Hello World:
|
||||
Hello from Docker!
|
||||
This message shows that your installation appears to be working correctly.
|
||||
|
||||
Persistent web server using nginx, sharing the host's network:
|
||||
### Example: Web Server
|
||||
|
||||
A web server with [nginx][], using standard docker bridge. Podman will
|
||||
automatically create a VETH pair for us, connecting the container to the
|
||||
`docker0` bridge:
|
||||
|
||||
admin@example:/> configure
|
||||
admin@example:/config> edit container web
|
||||
admin@example:/config/container/web> set image docker://nginx:alpine
|
||||
admin@example:/config/container/web> set publish 80:80
|
||||
admin@example:/config/container/web> set network host
|
||||
admin@example:/config/container/web> leave
|
||||
admin@example:/config/> edit interface docker0
|
||||
admin@example:/config/interface/docker0/> set container-network
|
||||
admin@example:/config/interface/docker0/> end
|
||||
admin@example:/config/> edit container web
|
||||
admin@example:/config/container/web/> set image docker://nginx:alpine
|
||||
admin@example:/config/container/web/> set network publish 8080:80
|
||||
admin@example:/config/container/web/> set network interface docker0
|
||||
admin@example:/config/container/web/> set volume cache target /var/cache
|
||||
admin@example:/config/container/web/> leave
|
||||
admin@example:/> show container
|
||||
|
||||
Exit to the shell and verify the service with curl, or try to attach
|
||||
to your device's IP address using your browser:
|
||||
|
||||
admin@example:~$ curl http://localhost
|
||||
admin@example:~$ curl http://localhost:8080
|
||||
|
||||
or connect to port 80 of your running Infix system with a browser. See
|
||||
the following sections for how to add more interfaces and manage your
|
||||
container at runtime.
|
||||
or connect to port 8080 of your running Infix system with a browser.
|
||||
See the following sections for how to add more interfaces and manage
|
||||
your container at runtime.
|
||||
|
||||
|
||||
Container Images
|
||||
@@ -271,7 +256,7 @@ archive, which helps greatly with container upgrades (see below):
|
||||
|
||||
Upgrading a Container Image
|
||||
---------------------------
|
||||
<img align="right" src="img/shield-checkmark.svg" alt="Hello World" width=100>
|
||||
{ align=right width="100" }
|
||||
|
||||
The applications in your container are an active part of the system as a
|
||||
whole, so make it a routine to keep your container images up-to-date!
|
||||
@@ -456,11 +441,11 @@ in a `bridge`. Below an example of a system container calls `set
|
||||
network interface docker0`, here we show how to set options for that
|
||||
network:
|
||||
|
||||
admin@example:/config/container/ntpd/> edit network docker0
|
||||
admin@example:/config/container/ntpd/network/docker0/>
|
||||
admin@example:/config/container/ntpd/network/docker0/> set option
|
||||
admin@example:/config/container/ntpd/> edit network interface docker0
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/>
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> set option
|
||||
<string> Options for masquerading container bridges.
|
||||
admin@example:/config/container/ntpd/network/docker0/> help option
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> help option
|
||||
NAME
|
||||
option <string>
|
||||
|
||||
@@ -471,9 +456,9 @@ network:
|
||||
mac=00:01:02:c0:ff:ee -- set fixed MAC address in container
|
||||
interface_name=foo0 -- set interface name inside container
|
||||
|
||||
admin@example:/config/container/ntpd/network/docker0/> set option ip=172.17.0.2
|
||||
admin@example:/config/container/ntpd/network/docker0/> set option interface_name=wan
|
||||
admin@example:/config/container/ntpd/network/docker0/> leave
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> set option ip=172.17.0.2
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> set option interface_name=wan
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> leave
|
||||
|
||||
|
||||
### Container Host Interface
|
||||
@@ -903,4 +888,5 @@ Container Image](#upgrading-a-container-image) (above).
|
||||
[14]: https://github.com/kernelkit/curiOS/
|
||||
[15]: https://github.com/kernelkit/curiOS/blob/2e4748f65e356b2c117f586cd9420d7ba66f79d5/board/system/rootfs/etc/inittab
|
||||
[tini]: https://github.com/krallin/tini
|
||||
[nginx]: https://hub.docker.com/_/nginx
|
||||
[podman]: https://podman.io
|
||||
|
||||
@@ -14,6 +14,9 @@ the Buildroot `make menuconfig` system.
|
||||
-> System configuration
|
||||
-> [*]Enable root login with password
|
||||
|
||||
> [!IMPORTANT]
|
||||
> Please see the [Contributing](#contributing) section, below, for
|
||||
> details on how to fork and clone when contributing to Infix.
|
||||
|
||||
Cloning
|
||||
-------
|
||||
@@ -25,14 +28,12 @@ tree to your PC:
|
||||
```bash
|
||||
$ mkdir ~/Projects; cd ~/Projects
|
||||
$ git clone https://github.com/kernelkit/infix.git
|
||||
..
|
||||
$ cd infix/
|
||||
$ git submodule update --init
|
||||
..
|
||||
```
|
||||
|
||||
> Please see the [Contributing](#contributing) section, below, for
|
||||
> details on how to fork and clone when contributing to Infix.
|
||||
|
||||
|
||||
### Customer Builds
|
||||
|
||||
Customer builds add product specific device trees, more OSS packages,
|
||||
@@ -57,6 +58,10 @@ Other caveats should be documented in the customer specific trees.
|
||||
Building
|
||||
--------
|
||||
|
||||
> [!TIP]
|
||||
> For more details, see the Getting Started and System Requirements
|
||||
> sections of the [excellent Buildroot manual][1].
|
||||
|
||||
Buildroot is almost stand-alone, it needs a few locally installed tools
|
||||
to bootstrap itself. The most common ones are usually part of the base
|
||||
install of the OS, but specific ones for building need the following.
|
||||
@@ -67,12 +72,10 @@ $ sudo apt install bc binutils build-essential bzip2 cpio \
|
||||
diffutils file findutils git gzip \
|
||||
libncurses-dev libssl-dev perl patch \
|
||||
python3 rsync sed tar unzip wget \
|
||||
autopoint bison flex autoconf automake
|
||||
autopoint bison flex autoconf automake \
|
||||
mtools
|
||||
```
|
||||
|
||||
> For details, see the Getting Started and System Requirements sections
|
||||
> of the [excellent manual][1].
|
||||
|
||||
To build an Infix image; select the target and then make:
|
||||
|
||||
make x86_64_defconfig
|
||||
@@ -95,12 +98,43 @@ and services are required on your system:
|
||||
```bash
|
||||
$ sudo apt install jq graphviz qemu-system-x86 qemu-system-arm \
|
||||
ethtool gdb-multiarch tcpdump tshark
|
||||
..
|
||||
```
|
||||
|
||||
To be able to build the test specification you also need:
|
||||
|
||||
```bash
|
||||
$ sudo apt-get install python3-graphviz ruby-asciidoctor-pdf
|
||||
..
|
||||
```
|
||||
|
||||
### Documentation
|
||||
|
||||
The documentation is written in Markdown, with GitHub extensions, and
|
||||
published using [MkDocs, material theme][11]. This means some features
|
||||
require MkDocs *hinting* which may not render fully when previewing on
|
||||
GitHub -- this is OK.
|
||||
|
||||
MkDocs is packaged and available to install via `apt`, but not all of
|
||||
the plugins and extensions we rely on are available, so instead we do
|
||||
recommend using `pipx` to install the necessary tooling:
|
||||
|
||||
```bash
|
||||
$ sudo apt install pipx
|
||||
$ pipx install mkdocs
|
||||
$ pipx inject mkdocs mkdocs-material pymdown-extensions mkdocs-callouts mike mkdocs-to-pdf
|
||||
```
|
||||
|
||||
The last two packages, `mike` and `mkdocs-to-pdf`, are used for online
|
||||
versioning and PDF generation by GitHub Actions, but since they are in
|
||||
the `mkdocs.yml` file, everyone who wants to preview the documentation
|
||||
have to install all the tooling.
|
||||
|
||||
Preview with:
|
||||
|
||||
```
|
||||
$ cd ~/src/infix/
|
||||
$ mkdocs serve
|
||||
```
|
||||
|
||||
|
||||
@@ -131,6 +165,16 @@ This rebuilds (and installs) `foo` and `bar`, the `all` target calls
|
||||
on Buildroot to finalize the target filesystem and generate the images.
|
||||
The final `run` argument is explained below.
|
||||
|
||||
|
||||
### YANG Model
|
||||
|
||||
When making changes to the `confd` and `statd` services, you will often
|
||||
need to update the YANG models. If you are adding a new YANG module,
|
||||
it's best to follow the structure of an existing one. However, before
|
||||
making any changes, **always discuss them with the Infix core team**.
|
||||
This helps avoid issues later in development and makes pull request
|
||||
reviews smoother.
|
||||
|
||||
### `confd`
|
||||
|
||||
The Infix `src/confd/` is the engine of the system. Currently it is a
|
||||
@@ -164,29 +208,232 @@ Now you can rebuild `confd`, just as described above, and restart Infix:
|
||||
make confd-rebuild all run
|
||||
|
||||
|
||||
### `statd`
|
||||
|
||||
The Infix status daemon, `src/statd`, is responsible for populating the
|
||||
sysrepo `operational` datastore. Like `confd`, it uses XPath subscriptions,
|
||||
but unlike `confd`, it relies entirely on `yanger`, a Python script that
|
||||
gathers data from local linux services and feeds it into sysrepo.
|
||||
|
||||
To apply changes, rebuild the image:
|
||||
|
||||
make python-statd-rebuild statd-rebuild all
|
||||
|
||||
Rebuilding the image and testing on target for every change during
|
||||
development process can be tedious. Instead, `yanger` allows remote
|
||||
execution, running the script directly on the host system (test
|
||||
container):
|
||||
|
||||
infamy0:test # ../src/statd/python/yanger/yanger -x "../utils/ixll -A ssh d3a" ieee802-dot1ab-lldp
|
||||
|
||||
`ixll` is a utility script that lets you run network commands using an
|
||||
**interface name** instead of a hostname. It makes operations like
|
||||
`ssh`, `scp`, and network discovery easier.
|
||||
|
||||
Normally, `yanger` runs commands **locally** to retrieve data
|
||||
(e.g., `lldpcli` when handling `ieee802-dot1ab-lldp`). However, when
|
||||
executed with `-x "../utils/ixll -A ssh d3a"` it redirects these
|
||||
commands to a remote system connected to the local `d3a` interface via
|
||||
SSH. This setup is used for running `yanger` in an
|
||||
[interactive test environment](testing.md#interactive-usage). The yanger
|
||||
script runs on the `host` system, but key commands are executed on the
|
||||
`target` system.
|
||||
|
||||
For debugging or testing, you can capture system command output and
|
||||
replay it later without needing a live system.
|
||||
|
||||
To capture:
|
||||
|
||||
infamy0:test # ../src/statd/python/yanger/yanger -c /tmp/capture ieee802-dot1ab-lldp
|
||||
|
||||
To replay:
|
||||
|
||||
infamy0:test # ../src/statd/python/yanger/yanger -r /tmp/capture ieee802-dot1ab-lldp
|
||||
|
||||
This is especially useful when working in isolated environments or debugging
|
||||
issues without direct access to the DUT.
|
||||
|
||||
|
||||
## Upgrading Packages
|
||||
|
||||
### Buildroot
|
||||
|
||||
The Kernelkit team maintains an internal [fork of Buildroot][9], with
|
||||
branches following the naming scheme `YYYY.MM.patch-kkit`
|
||||
e.g. `2025.02.1-kkit`, which means a new branch should be created
|
||||
whenever Buildroot is updated. These branches should contain **only**
|
||||
changes to existing packages (but no new patches), modifications to
|
||||
Buildroot itself or upstream backports.
|
||||
|
||||
The team tracks the latest Buildroot LTS (Long-Term Support) release and
|
||||
updates. The impact of minor LTS release upgrades is expected to have a
|
||||
very low impact and should be done as soon there is a patch release of a
|
||||
Buildroot LTS available.
|
||||
|
||||
> **Depending on your setup, follow the appropriate steps below.**
|
||||
|
||||
#### Repo locally cloned already
|
||||
|
||||
1. Navigate to the Buildroot directory
|
||||
|
||||
cd buildroot/
|
||||
|
||||
1. Pull the latest changes from KernelKit
|
||||
|
||||
git pull
|
||||
|
||||
1. Fetch the latest tags from upstream
|
||||
|
||||
git fetch upstream --tags
|
||||
|
||||
#### No local repo yet
|
||||
|
||||
1. Clone the Kernelkit Buildroot repository
|
||||
|
||||
git clone git@github.com:kernelkit/buildroot.git
|
||||
|
||||
1. Add the upstream remote
|
||||
|
||||
git remote add upstream https://gitlab.com/buildroot.org/buildroot.git
|
||||
|
||||
1. Checkout old KernelKit branch
|
||||
|
||||
git checkout 2025.02.1-kkit
|
||||
|
||||
> [!NOTE]
|
||||
> Below, it is **not** allowed to rebase the branch when bumped in Infix.
|
||||
|
||||
#### Continue Here
|
||||
|
||||
1. Create a new branch based on the **previous** KernelKit Buildroot
|
||||
release (e.g. `2025.02.1-kkit`) and name it according to the naming
|
||||
scheme (e.g. `2025.02.2-kkit`)
|
||||
|
||||
git checkout -b 2025.02.2-kkit
|
||||
|
||||
1. Rebase the new branch onto the corresponding upstream release
|
||||
|
||||
git rebase 2025.02.2
|
||||
|
||||
1. Push the new branch and tags
|
||||
|
||||
git push origin 2025.02.2-kkit --tags
|
||||
|
||||
1. In Infix, checkout new branch of Buildroot
|
||||
|
||||
cd buildroot
|
||||
git fetch
|
||||
git checkout 2025.02.2-kkit
|
||||
|
||||
1. Commit and push the changes. *Remember to update the ChangeLog!*
|
||||
|
||||
1. Create a pull request.
|
||||
|
||||
> [!NOTE]
|
||||
> Remember to set the pull request label to `ci:main` to ensure full CI
|
||||
> coverage.
|
||||
|
||||
|
||||
### Linux kernel
|
||||
|
||||
The KernelKit team maintains an internal [fork of Linux kernel][10],
|
||||
with branches following the naming scheme `kkit-linux-[version].y`,
|
||||
e.g. `kkit-6.12.y`, which means a new branch should be created whenever
|
||||
the major kernel version is updated. This branch should contain *all*
|
||||
kernel patches used by Infix.
|
||||
|
||||
The team tracks the latest Linux kernel LTS (Long-Term Support) release
|
||||
and updates. The upgrade of LTS minor releases is expected to have low
|
||||
impact and should be done as soon as a patch release of the LTS Linux
|
||||
kernel is available.
|
||||
|
||||
#### Repo locally cloned already
|
||||
|
||||
1. Navigate to the Linux kernel directory
|
||||
|
||||
cd linux
|
||||
|
||||
1. Get latest changes from KernelKit
|
||||
|
||||
git pull
|
||||
|
||||
1. Fetch the latest tags from upstream
|
||||
|
||||
git fetch upstream --tags
|
||||
|
||||
#### No local repo yet
|
||||
|
||||
1. Clone the KernelKit Linux kernel repository
|
||||
|
||||
git clone git@github.com:kernelkit/linux.git
|
||||
|
||||
1. Add the upstream remote
|
||||
|
||||
git remote add upstream git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
|
||||
|
||||
1. Checkout correct kernel branch
|
||||
|
||||
git checkout kkit-linux-6.12.y
|
||||
|
||||
#### Continue Here
|
||||
|
||||
1. Rebase on the upstream release
|
||||
|
||||
git rebase v6.12.29
|
||||
|
||||
1. Push changes and the tags
|
||||
|
||||
git push -f origin kkit-linux-6.12.y --tags
|
||||
|
||||
**Move to your Infix source tree**
|
||||
|
||||
> [!NOTE]
|
||||
> See help of `kernel-refresh.sh` script for more information.
|
||||
|
||||
1. Generate patches
|
||||
|
||||
make x86_64_defconfig
|
||||
cd output
|
||||
../utils/kernel-refresh.sh -k /path/to/linux -o 6.12.28 -t v6.12.29
|
||||
|
||||
1. Commit and push the changes. Remember to update the ChangeLog
|
||||
1. Create a pull request
|
||||
|
||||
> [!NOTE]
|
||||
> Remember to set the pull request label to `ci:main` to ensure full CI
|
||||
> coverage.
|
||||
|
||||
|
||||
|
||||
Testing
|
||||
-------
|
||||
|
||||
Manual testing can be done using Qemu by calling <kbd>make run</kbd>,
|
||||
see also [Infix in Virtual Environments](virtual.md).
|
||||
see also [Infix in Virtual Environments](virtual.md), or on a physical
|
||||
device by upgrading to the latest build or "[netbooting](netboot.md)"
|
||||
and running the image from RAM. The latter is how most board porting
|
||||
work is done -- **much quicker** change-load-test cycles.
|
||||
|
||||
The Infix automated test suite is built around Qemu and [Qeneth][2], see:
|
||||
|
||||
* [Testing](testing.md)
|
||||
* [Docker Image](../test/docker/README.md)
|
||||
* [Regression Testing with Infamy](testing.md)
|
||||
* [Docker Image](https://github.com/kernelkit/infix/blob/main/test/docker/README.md)
|
||||
|
||||
With any new feature added to Infix, it is essential to include relevant
|
||||
test case(s). See the [Test Development](testing.md#test-development)
|
||||
section for guidance on adding test cases.
|
||||
|
||||
|
||||
Reviewing
|
||||
---------
|
||||
|
||||
While reviewing a pull request, you might find yourself wanting to
|
||||
play around with a VM running that _exact_ version. For such
|
||||
occations, [gh-dl-artifact.sh](../utils/gh-dl-artifact.sh) is your
|
||||
friend in need! It will use the [GitHub CLI
|
||||
(gh)](https://cli.github.com) to locate a prebuilt image from our CI
|
||||
While reviewing a pull request, you might find yourself wanting to play
|
||||
around with a VM running that _exact_ version. For such occasions,
|
||||
[gh-dl-artifact.sh][8] is your friend in need! It employs the [GitHub
|
||||
CLI (gh)](https://cli.github.com) to locate a prebuilt image from our CI
|
||||
workflow, download it, and prepare a local output directory from which
|
||||
you can launch both `make run` instances, and run regression tests
|
||||
with `make test` and friends.
|
||||
you can launch both `make run` instances, and run regression tests with
|
||||
`make test` and friends.
|
||||
|
||||
For example, if you are curious about how PR 666 behaves in some
|
||||
particular situation, you can use `gh` to switch to that branch, from
|
||||
@@ -198,10 +445,10 @@ corresponding image for execution with our normal tooling:
|
||||
cd x-artifact-a1b2c3d4-x86_64
|
||||
make run
|
||||
|
||||
> **Note:** CI artifacts are built from a merge commit of the source
|
||||
> and target branches. Therefore, the version in the Infix banner
|
||||
> will not match the SHA of the commit you have checked out.
|
||||
|
||||
> [!NOTE]
|
||||
> CI artifacts are built from a merge commit of the source and target
|
||||
> branches. Therefore, the version in the Infix banner will not match
|
||||
> the SHA of the commit you have checked out.
|
||||
|
||||
Contributing
|
||||
------------
|
||||
@@ -213,28 +460,32 @@ fork, and then use GitHub to create a *Pull Reqeuest*.
|
||||
For this to work as *painlessly as possible* for everyone involved:
|
||||
|
||||
1. Fork Infix to your own user or organization[^1]
|
||||
2. Fork all the Infix submodules, e.g., `kernelkit/buildroot` to your
|
||||
1. Fork all the Infix submodules, e.g., `kernelkit/buildroot` to your
|
||||
own user or organization as well
|
||||
3. Clone your fork of Infix to your laptop/workstation
|
||||
4. [Deactivate the Actions][6] you don't want in your fork
|
||||
5. Please read the [Contributing Guidelines][5] as well!
|
||||
1. Clone your fork of Infix to your laptop/workstation
|
||||
1. [Deactivate the Actions][6] you don't want in your fork
|
||||
1. Please read the [Contributing Guidelines][5] as well!
|
||||
|
||||
```bash
|
||||
$ cd ~/Projects
|
||||
$ git clone https://github.com/YOUR_USER_NAME/infix.git
|
||||
...
|
||||
$ cd infix/
|
||||
$ git submodule update --init
|
||||
...
|
||||
```
|
||||
> **Note:** when updating/synchronizing with upstream Infix changes you
|
||||
> may have to synchronize your forks as well. GitHub have a `Sync fork`
|
||||
> button in the GUI for your fork for this purpose. A cronjob on your
|
||||
> server of choice can do this for you with the [GitHub CLI tool][7].
|
||||
|
||||
> [!NOTE]
|
||||
> When updating/synchronizing with upstream Infix changes you may have
|
||||
> to synchronize your forks as well. GitHub have a `Sync fork` button
|
||||
> in the GUI for your fork for this purpose. A cronjob on your server
|
||||
> of choice can do this for you with the [GitHub CLI tool][7].
|
||||
|
||||
[^1]: Organizations should make sure to lock the `main` (or `master`)
|
||||
branch of their clones to ensure members do not accidentally merge
|
||||
changes there. Keeping these branches in sync with upstream Infix
|
||||
is highly recommended as a baseline and reference. For integration
|
||||
of local changes another company-specific branch can be used instead.
|
||||
of local changes another company-specific branch can be used instead.
|
||||
|
||||
[0]: https://github.com/kernelkit/infix/releases
|
||||
[1]: https://buildroot.org/downloads/manual/manual.html
|
||||
@@ -244,3 +495,7 @@ $ git submodule update --init
|
||||
[5]: https://github.com/kernelkit/infix/blob/main/.github/CONTRIBUTING.md
|
||||
[6]: https://docs.github.com/en/actions/managing-workflow-runs-and-deployments/managing-workflow-runs/disabling-and-enabling-a-workflow
|
||||
[7]: https://cli.github.com/
|
||||
[8]: https://github.com/kernelkit/infix/blob/main/utils/gh-dl-artifact.sh
|
||||
[9]: https://github.com/kernelkit/buildroot
|
||||
[10]: https://github.com/kernelkit/linux
|
||||
[11]: https://squidfunk.github.io/mkdocs-material/
|
||||
|
||||
@@ -0,0 +1,171 @@
|
||||
DHCP Server
|
||||
===========
|
||||
|
||||
The DHCPv4 server provides automatic IP address assignment and network
|
||||
configuration for clients. It supports address pools, static host
|
||||
assignments, and customizable DHCP options. It also serves as a DNS
|
||||
proxy for local subnets and can even forward queries to upstream DNS
|
||||
servers[^1].
|
||||
|
||||
> [!NOTE]
|
||||
> When using the CLI, the system automatically enables essential options
|
||||
> like DNS servers and default gateway based on the system's network
|
||||
> configuration. These options can be disabled, changed or overridden,
|
||||
> at any level: global, subnet, or per-host.
|
||||
|
||||
|
||||
## Basic Configuration
|
||||
|
||||
The following example configures a DHCP server for subnet 192.168.2.0/24
|
||||
with an address pool:
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit dhcp-server
|
||||
admin@example:/config/dhcp-server/> edit subnet 192.168.2.0/24
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> set pool start-address 192.168.2.100 end-address 192.168.2.200
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> leave
|
||||
```
|
||||
|
||||
When setting up the server from the CLI, the system automatically adds a
|
||||
few default DHCP options that will be sent to clients: both DNS server
|
||||
and default gateway will use the system address on the matching
|
||||
interface.
|
||||
|
||||
```
|
||||
admin@example:/> show running-config
|
||||
"infix-dhcp-server:dhcp-server": {
|
||||
"subnet": [
|
||||
{
|
||||
"subnet": "192.168.2.0/24",
|
||||
"option": [
|
||||
{
|
||||
"id": "dns-server",
|
||||
"address": "auto"
|
||||
},
|
||||
{
|
||||
"id": "router",
|
||||
"address": "auto"
|
||||
}
|
||||
],
|
||||
"pool": {
|
||||
"start-address": "192.168.2.100",
|
||||
"end-address": "192.168.2.200"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
> [!IMPORTANT]
|
||||
> Remember to set up an interface in this subnet, avoid using addresses
|
||||
> in the DHCP pool, or reserved for static hosts. In Class C networks
|
||||
> the router usually has address `.1`. Depending on the use-case, you
|
||||
> may also want to set up routing.
|
||||
|
||||
|
||||
## Static Host Assignment
|
||||
|
||||
To reserve specific IP addresses for clients based on their MAC address,
|
||||
hostname, or client ID:
|
||||
|
||||
```
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> edit host 192.168.2.10
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/host/192.168.2.10/> set match mac-address 00:11:22:33:44:55
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/host/192.168.2.10/> set hostname printer
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/host/192.168.2.10/> leave
|
||||
```
|
||||
|
||||
Match hosts using a client identifier instead of MAC address:
|
||||
|
||||
```
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/> edit host 192.168.1.50
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/> edit match
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/match/> set client-id hex c0:ff:ee
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/match/> leave
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/> set lease-time infinite
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/host/192.168.1.50/> leave
|
||||
```
|
||||
|
||||
The `hex` prefix here ensures matching of client ID is done using the
|
||||
hexadecimal octets `c0:ff:ee`, three bytes. Without the prefix the
|
||||
ASCII string "c0:ff:ee", eight bytes, is used.
|
||||
|
||||
> [!NOTE]
|
||||
> The DHCP server is fully RFC conformant, in the case of option 61 this
|
||||
> means that using the `hex` prefix will require the client to set the
|
||||
> `htype` field of the option to `00`. See RFC 2132 for details.
|
||||
|
||||
|
||||
## Custom DHCP Options
|
||||
|
||||
Configure additional DHCP options globally, per subnet, or per host:
|
||||
|
||||
```
|
||||
admin@example:/config/dhcp-server/> edit subnet 192.168.2.0/24
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> edit option dns-server
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/option/dns-server/> set address 8.8.8.8
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/option/dns-server/> leave
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> edit option ntp-server
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/option/ntp-server/> set address 192.168.2.1
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/option/ntp-server/> leave
|
||||
```
|
||||
|
||||
When configuring, e.g., `dns-server`, or `router` options with the value
|
||||
`auto`, the system uses the IP address from the interface matching the
|
||||
subnet. For example:
|
||||
|
||||
```
|
||||
admin@example:/> show interfaces brief
|
||||
Interface Status Address
|
||||
eth0 UP 192.168.1.1/24
|
||||
eth1 UP 192.168.2.1/24
|
||||
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/> edit option dns-server
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/option/dns-server/> set address auto
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/option/dns-server/> leave
|
||||
```
|
||||
|
||||
In this case, clients in subnet 192.168.1.0/24 will receive 192.168.1.1
|
||||
as their DNS server address.
|
||||
|
||||
|
||||
## Multiple Subnets
|
||||
|
||||
Configure DHCP for multiple networks:
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit dhcp-server
|
||||
admin@example:/config/dhcp-server/> edit subnet 192.168.1.0/24
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/> set pool start-address 192.168.1.100 end-address 192.168.1.200
|
||||
admin@example:/config/dhcp-server/subnet/192.168.1.0/24/> leave
|
||||
admin@example:/config/dhcp-server/> edit subnet 192.168.2.0/24
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> set pool start-address 192.168.2.100 end-address 192.168.2.200
|
||||
admin@example:/config/dhcp-server/subnet/192.168.2.0/24/> leave
|
||||
```
|
||||
|
||||
|
||||
## Monitoring
|
||||
|
||||
View active leases and server statistics:
|
||||
|
||||
```
|
||||
admin@example:/> show dhcp-server
|
||||
IP ADDRESS MAC HOSTNAME CLIENT ID EXPIRES
|
||||
192.168.2.22 00:a0:85:00:02:05 00:c0:ff:ee 3591s
|
||||
192.168.1.11 00:a0:85:00:04:06 foo 01:00:a0:85:00:04:06 3591s
|
||||
|
||||
admin@example:/> show dhcp-server statistics
|
||||
DHCP offers sent : 6
|
||||
DHCP ACK messages sent : 5
|
||||
DHCP NAK messages sent : 0
|
||||
DHCP decline messages received : 0
|
||||
DHCP discover messages received : 6
|
||||
DHCP request messages received : 5
|
||||
DHCP release messages received : 6
|
||||
DHCP inform messages received : 6
|
||||
```
|
||||
|
||||
|
||||
[^1]: This requires the system DNS resolver to be configured.
|
||||
@@ -1,21 +1,21 @@
|
||||
Discover Infix Units
|
||||
====================
|
||||
# Device Discovery
|
||||
|
||||
Infix advertises itself via the [mDNS-SD](#mdns-sd) and [LLDP](#lldp)
|
||||
discovery protocols. mDNS-SD has good client support in Windows, macOS
|
||||
and on Linux systems. More on these protocols later.
|
||||
|
||||
An even simpler method is available when directly attached to an Infix
|
||||
device:
|
||||
|
||||
```
|
||||
.----. Ethernet .-------.
|
||||
| PC +---------------------+ Infix |
|
||||
'----' if1 eth0 '-------'
|
||||
.----. Ethernet .--------.
|
||||
| PC +---------------------+ Device |
|
||||
'----' if1 e1 '--------'
|
||||
```
|
||||
Figure 1: PC directly connected over Ethernet to Infix unit (here eth0).
|
||||
|
||||
|
||||
When you wish to discover the IP address of an Infix switch, the simplest
|
||||
way is probably to *ping the IPv6 all-hosts* address (ff02::1) over a
|
||||
directly connected Ethernet cable. The unit's link-local IPv6 address is
|
||||
seen in the response.
|
||||
|
||||
In the example below, the PC is connected to Infix via interface *tap0*
|
||||
(*tap0* is *if1* in Figure 1) and Infix responds with address
|
||||
With IPv6 you can *ping the all-hosts* address (ff02::1), the device's
|
||||
link-local IPv6 address is then seen in the response. In the following
|
||||
example, the PC here uses *tap0* as *if1*, Infix responds with address
|
||||
*fe80::ff:fec0:ffed*.
|
||||
|
||||
```
|
||||
@@ -31,7 +31,11 @@ rtt min/avg/max/mdev = 0.389/0.455/0.558/0.073 ms
|
||||
linux-pc:#
|
||||
```
|
||||
|
||||
The PC could connect then connect to Infix, e.g., using SSH.
|
||||
> [!TIP]
|
||||
> The `-L` option ignores local responses from the PC.
|
||||
|
||||
This address can then be used to connect to the device, e.g., using SSH.
|
||||
Notice the syntax `username@address%interface`:
|
||||
|
||||
```
|
||||
linux-pc:# ssh admin@fe80::ff:fec0:ffed%tap0
|
||||
@@ -39,17 +43,13 @@ admin@fe80::ff:fec0:ffed%tap0's password: admin
|
||||
admin@infix-c0-ff-ee:~$
|
||||
```
|
||||
|
||||
## Discovery mechanisms available in Infix
|
||||
|
||||
Infix advertises its presence via the [mDNS](#mdns) and [LLDP](#lldp)
|
||||
discovery protocols.
|
||||
## LLDP
|
||||
|
||||
Infix supports LLDP (IEEE 802.1AB). For a device with factory default
|
||||
settings, the link-local IPv6 address can be read from the Management
|
||||
Address TLV using *tcpdump* or other sniffing tools[^1]:
|
||||
|
||||
### LLDP
|
||||
|
||||
Infix supports LLDP (IEEE 802.1AB). For a unit with factory default
|
||||
settings, the PC can readout the link-local IPv6 address from the
|
||||
Management Address TLV using *tcpdump* or other sniffing tools[^1].
|
||||
```
|
||||
linux-pc:# tcpdump -i tap0 -Qin -v ether proto 0x88cc
|
||||
tcpdump: listening on tap0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
|
||||
@@ -83,11 +83,12 @@ tcpdump: listening on tap0, link-type EN10MB (Ethernet), snapshot length 262144
|
||||
linux-pc:#
|
||||
```
|
||||
|
||||
If the unit has an IPv4 address assigned, it is shown in an additional
|
||||
If the device has an IPv4 address assigned, it is shown in an additional
|
||||
Management Address TLV.
|
||||
|
||||
> **Note** The Management Addresses shown by LLDP are not
|
||||
> necessarily associated with the port transmitting the LLDP message.
|
||||
> [!NOTE]
|
||||
> The Management Addresses shown by LLDP are not necessarily associated
|
||||
> with the port transmitting the LLDP message.
|
||||
|
||||
In the example below, the IPv4 address (10.0.1.1) happens to be
|
||||
assigned to *eth0*, while the IPv6 address (2001:db8::1) is not.
|
||||
@@ -130,9 +131,9 @@ tcpdump: listening on tap0, link-type EN10MB (Ethernet), snapshot length 262144
|
||||
linux-pc:#
|
||||
```
|
||||
|
||||
[^1]: [lldpd: implementation of IEEE 802.1ab
|
||||
(LLDP)](https://github.com/lldp/lldpd) includes *lldpcli*, which
|
||||
is handy to sniff and display LLDP packets.
|
||||
The following capabilities are available via NETCONF/RESTCONF or the Infix CLI.
|
||||
|
||||
### LLDP Enable/Disable
|
||||
|
||||
The LLDP service can be disabled using the following commands.
|
||||
|
||||
@@ -143,13 +144,91 @@ admin@infix-c0-ff-ee:/config/> leave
|
||||
admin@infix-c0-ff-ee:/>
|
||||
```
|
||||
|
||||
### mDNS
|
||||
To reenable it from the CLI config mode:
|
||||
|
||||
DNS-SD/mDNS can be used to discover Infix units and services. Infix
|
||||
units present their IP addresses, services and hostname within the
|
||||
.local domain. This method has good client support in Apple and Linux
|
||||
systems. On Linux, tools such as *avahi-browse* or *mdns-scan*[^2] can
|
||||
be used to search for devices advertising their services via mDNS.
|
||||
```
|
||||
admin@test-00-01-00:/config/> set lldp enabled
|
||||
admin@test-00-01-00:/config/> leave
|
||||
```
|
||||
|
||||
### LLDP Message Transmission Interval
|
||||
|
||||
By default, LLDP uses a `message-tx-interval` of 30 seconds, as defined
|
||||
by the IEEE standard. Infix allows this value to be customized.
|
||||
To change it using the CLI:
|
||||
|
||||
```
|
||||
admin@test-00-01-00:/config/> set lldp message-tx-interval 1
|
||||
admin@test-00-01-00:/config/> leave
|
||||
```
|
||||
|
||||
### LLDP Administrative Status per Interface
|
||||
|
||||
Infix supports configuring the LLDP administrative status on a per-port
|
||||
basis. The default mode is `tx-and-rx`, but the following options are
|
||||
also supported:
|
||||
|
||||
- `rx-only` – Receive LLDP packets only
|
||||
- `tx-only` – Transmit LLDP packets only
|
||||
- `disabled` – Disable LLDP on the interface
|
||||
|
||||
Example configuration:
|
||||
|
||||
```
|
||||
admin@test-00-01-00:/config/> set lldp port e8 dest-mac-address 01:80:C2:00:00:0E admin-status disabled
|
||||
admin@test-00-01-00:/config/> set lldp port e5 dest-mac-address 01:80:C2:00:00:0E admin-status rx-only
|
||||
admin@test-00-01-00:/config/> set lldp port e6 dest-mac-address 01:80:C2:00:00:0E admin-status tx-only
|
||||
admin@test-00-01-00:/config/> leave
|
||||
```
|
||||
|
||||
> [!NOTE]
|
||||
> The destination MAC address must be the standard LLDP multicast
|
||||
> address: `01:80:C2:00:00:0E`.
|
||||
|
||||
### Displaying LLDP Neighbor Information
|
||||
|
||||
In CLI mode, Infix also provides a convenient `show lldp` command to
|
||||
list LLDP neighbors detected on each interface:
|
||||
|
||||
```
|
||||
admin@test-00-01-00:/> show lldp
|
||||
INTERFACE REM-IDX TIME CHASSIS-ID PORT-ID
|
||||
e5 1 902 00:a0:85:00:04:01 00:a0:85:00:04:07
|
||||
e6 3 897 00:a0:85:00:03:01 00:a0:85:00:03:07
|
||||
e8 2 901 00:a0:85:00:02:01 00:a0:85:00:02:05
|
||||
```
|
||||
|
||||
## mDNS-SD
|
||||
|
||||
DNS-SD/mDNS-SD can be used to discover Infix devices and services. By
|
||||
default, Infix use the `.local` domain for advertising services. Some
|
||||
networks use `.lan` instead, so this configurable:
|
||||
|
||||
```
|
||||
admin@infix-c0-ff-ee:/> configure
|
||||
admin@infix-c0-ff-ee:/config/> edit mdns
|
||||
admin@infix-c0-ff-ee:/config/mdns/> set domain lan
|
||||
```
|
||||
|
||||
Other available settings include limiting the interfaces mDNS responder
|
||||
acts on:
|
||||
|
||||
```
|
||||
admin@infix-c0-ff-ee:/config/> set interfaces allow e1
|
||||
```
|
||||
|
||||
or
|
||||
|
||||
```
|
||||
admin@infix-c0-ff-ee:/config/> set interfaces deny wan
|
||||
```
|
||||
|
||||
The `allow` and `deny` settings are complementary, `deny` always wins.
|
||||
|
||||
----
|
||||
|
||||
In Linux, tools such as *avahi-browse* or *mdns-scan*[^2] can be used to
|
||||
search for devices advertising their services via mDNS.
|
||||
|
||||
```
|
||||
linux-pc:# avahi-browse -ar
|
||||
@@ -181,9 +260,15 @@ linux-pc:# avahi-browse -ar
|
||||
linux-pc:#
|
||||
```
|
||||
|
||||
> [!TIP]
|
||||
> The `-t` option is also very useful, it stops browsing automatically
|
||||
> when a "more or less complete list" has been printed. However, some
|
||||
> devices on the LAN may be in deep sleep so run the command again if
|
||||
> you cannot find the device you are looking for.
|
||||
|
||||
Additionally, *avahi-resolve-host-name* can be used to verify domain
|
||||
name mappings for IP addresses. By default, it translates from IPv4
|
||||
addresses. This function allows users to confirm that addresses are
|
||||
name mappings for IP addresses. By default, it translates from IPv4
|
||||
addresses. This function allows users to confirm that addresses are
|
||||
mapped correctly.
|
||||
|
||||
```
|
||||
@@ -209,7 +294,7 @@ rtt min/avg/max/mdev = 0.852/1.105/1.348/0.202 ms
|
||||
linux-pc:# ssh admin@infix-c0-ff-ee.local
|
||||
(admin@infix-c0-ff-ee.local) Password:
|
||||
.-------.
|
||||
| . . | Infix -- a Network Operating System
|
||||
| . . | Infix OS — Immutable.Friendly.Secure
|
||||
|-. v .-| https://kernelkit.org
|
||||
'-'---'-
|
||||
|
||||
@@ -219,20 +304,21 @@ linux-pc:#
|
||||
```
|
||||
|
||||
To disable mDNS/mDNS-SD, type the commands:
|
||||
|
||||
```
|
||||
admin@infix-c0-ff-ee:/> configure
|
||||
admin@infix-c0-ff-ee:/config/> no mdns
|
||||
admin@infix-c0-ff-ee:/config/> leave
|
||||
```
|
||||
|
||||
#### Human-Friendly Hostname Alias
|
||||
### Human-Friendly Hostname Alias
|
||||
|
||||
Each Infix unit will advertise itself as *infix.local*, in addition to
|
||||
its full hostname (e.g., *infix-c0-ff-ee.local* or *foo.local*). This
|
||||
alias works seamlessly on a network with a single Infix device, and
|
||||
makes it easy to connect when the exact hostname is not known in
|
||||
advance. The examples below show how the alias can be used for
|
||||
actions such as pinging or establishing an SSH connection:
|
||||
Each Infix deviuce advertise itself as *infix.local*, in addition to its
|
||||
full hostname (e.g., *infix-c0-ff-ee.local* or *foo.local*). This alias
|
||||
works seamlessly on a network with a single Infix device, and makes it
|
||||
easy to connect when the exact hostname is not known in advance. The
|
||||
examples below show how the alias can be used for actions such as
|
||||
pinging or establishing an SSH connection:
|
||||
|
||||
```
|
||||
linux-pc:# ping infix.local -c 3
|
||||
@@ -248,36 +334,39 @@ rtt min/avg/max/mdev = 0.751/1.482/2.281/0.626 ms
|
||||
linux-pc:# ssh admin@infix.local
|
||||
(admin@infix.local) Password:
|
||||
.-------.
|
||||
| . . | Infix -- a Network Operating System
|
||||
| . . | Infix OS — Immutable.Friendly.Secure
|
||||
|-. v .-| https://kernelkit.org
|
||||
'-'---'-
|
||||
|
||||
Run the command 'cli' for interactive OAM
|
||||
|
||||
linux-pc:#
|
||||
admin@infix-c0-ff-ee:~$
|
||||
```
|
||||
|
||||
When multiple Infix devices are present on the LAN the alias will not
|
||||
uniquely identify a device; *infix.local* will refer to any of the
|
||||
Infix devices, likely the one that first appeared.
|
||||
|
||||
> When multiple Infix units are present, use the full hostname (e.g.,
|
||||
> *infix-c0-ff-ee.local* or *foo.local*) rather than the alias
|
||||
> infix.local to deterministically connect to a unit.
|
||||
> [!NOTE]
|
||||
> When multiple Infix devices are present on the LAN, use the full name,
|
||||
> e.g., *infix-c0-ff-ee.local* or *foo.local* rather than the alias
|
||||
> *infix.local* to deterministically connect to the device.
|
||||
|
||||
|
||||
#### Netbrowse service to find all your devices
|
||||
### Browse Network Using *network.local*
|
||||
|
||||
Another mDNS alias that all Infix devices can advertise is
|
||||
*network.local*. This is a web service which basically runs avahi-browse
|
||||
and displays a table of other Infix devices and their services.
|
||||
Another mDNS alias that all Infix devices advertise is *network.local*.
|
||||
This is a web service which basically runs `avahi-browse` and displays a
|
||||
table of other Infix devices and their services.
|
||||
|
||||

|
||||
|
||||
With multiple Infix devices on the LAN, one will be your portal to
|
||||
access all others, if it goes down another will take its place.
|
||||
With multiple Infix devices on the LAN, one will take the role of your
|
||||
portal to access all others, if it goes down another takes its place.
|
||||
|
||||
To disable the netbrowse service, and the *network.local* alias, the
|
||||
following commands can be used:
|
||||
|
||||
To disable the netbrowse service, the following commands can be used:
|
||||
```
|
||||
admin@infix-c0-ff-ee:/> configure
|
||||
admin@infix-c0-ff-ee:/config/> edit web
|
||||
@@ -285,6 +374,8 @@ admin@infix-c0-ff-ee:/config/web/> no netbrowse
|
||||
admin@infix-c0-ff-ee:/config/web/> leave
|
||||
```
|
||||
|
||||
|
||||
[^1]: E.g., [lldpd](https://github.com/lldp/lldpd) which includes the
|
||||
*lldpcli* too, handy to sniff and display LLDP packets.
|
||||
[^2]: [mdns-scan](http://0pointer.de/lennart/projects/mdns-scan/): a
|
||||
tool for scanning for mDNS/DNS-SD published services on the local
|
||||
network
|
||||
tool for scanning for mDNS/DNS-SD services on the local network.
|
||||
|
||||
@@ -1,32 +1,19 @@
|
||||
# YANG to Ethtool Mapping
|
||||
# RMON Counters
|
||||
|
||||
This column contains the mapping between YANG and Linux / Ethtool counters.
|
||||
This document show the mapping between YANG and Linux / Ethtool counters.
|
||||
|
||||
```
|
||||
┌─────────────────────────────────┬──────────────────────────────────┐
|
||||
│ YANG │ Linux / Ethtool │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-frames │ FramesTransmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-multicast-frames │ MulticastFramesXmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-broadcast-frames │ BroadcastFramesXmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-total-frames │ FramesReceivedOK, │
|
||||
│ │ FrameCheckSequenceErrors │
|
||||
│ │ FramesLostDueToIntMACRcvError │
|
||||
│ │ AlignmentErrors │
|
||||
│ │ etherStatsOversizePkts │
|
||||
│ │ etherStatsJabbers │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-frames │ FramesReceivedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-multicast-frames │ MulticastFramesReceivedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-broadcast-frames │ BroadcastFramesReceivedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-error-undersize-frames │ undersize_pkts │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-error-fcs-frames │ FrameCheckSequenceErrors │
|
||||
└─────────────────────────────────┴──────────────────────────────────┘
|
||||
```
|
||||
| **YANG** | **Linux / Ethtool** |
|
||||
|--------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| `in-total-octets` | `FramesReceivedOK`, `FrameCheckSequenceErrors`, `FramesLostDueToIntMACRcvError`, `AlignmentErrors`, `etherStatsOversizePkts`, `etherStatsJabbers` |
|
||||
| `in-frames` | `FramesReceivedOK` |
|
||||
| `in-multicast-frames` | `MulticastFramesReceivedOK` |
|
||||
| `in-broadcast-frames` | `BroadcastFramesReceivedOK` |
|
||||
| `in-error-fcs-frames` | `FrameCheckSequenceErrors` |
|
||||
| `in-error-undersize-frames` | `undersize_pkts` |
|
||||
| `in-error-oversize-frames` | `etherStatsJabbers`, `etherStatsOversizePkts` |
|
||||
| `in-error-mac-internal-frames` | `FramesLostDueToIntMACRcvError` |
|
||||
| `out-frames` | `FramesTransmittedOK` |
|
||||
| `out-multicast-frames` | `MulticastFramesXmittedOK` |
|
||||
| `out-broadcast-frames` | `BroadcastFramesXmittedOK` |
|
||||
| `infix-eth:out-good-octets` | `OctetsTransmittedOK` |
|
||||
| `infix-eth:in-good-octets` | `OctetsReceivedOK` |
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
.md-header__title {
|
||||
font-size: 1.1rem;
|
||||
line-height: 2.6rem;
|
||||
}
|
||||
|
||||
[data-md-color-primary="orange"] {
|
||||
--md-primary-fg-color: #ff7f2a;
|
||||
--md-primary-bg-color: #5c5f5c;
|
||||
}
|
||||
[data-md-color-primary="black"] {
|
||||
--md-primary-bg-color: #5c5f5c;
|
||||
}
|
||||
@@ -51,9 +51,10 @@ Linux to use.
|
||||
|
||||
### Configure USB port
|
||||
|
||||
> **Note:** You can only configure USB ports known to the system. See
|
||||
> `show hardware` in admin-exec context. (Use `do` prefix in configure
|
||||
> context.)
|
||||
> [!NOTE]
|
||||
> You can only configure USB ports known to the system. See the CLI
|
||||
> command `show hardware` in admin-exec context. (Use `do` prefix in
|
||||
> configure context.)
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
@@ -84,5 +85,4 @@ cached data to disk before returning the prompt:
|
||||
admin@example:~$ sudo umount /media/log
|
||||
```
|
||||
|
||||
|
||||
[1]: https://www.rfc-editor.org/rfc/rfc8348.html
|
||||
|
||||
|
Before Width: | Height: | Size: 358 KiB After Width: | Height: | Size: 368 KiB |
|
Before Width: | Height: | Size: 281 KiB After Width: | Height: | Size: 280 KiB |
@@ -0,0 +1,92 @@
|
||||
# Introduction
|
||||
|
||||
{ align=right width="480" }
|
||||
|
||||
Welcome to Infix, your immutable, friendly, and secure operating system!
|
||||
On these pages you can find both user and developer documentation.
|
||||
|
||||
Most topics on configuring the system include CLI examples, but every
|
||||
setting, as well as status read-back from the operational datastore, is
|
||||
also possible to perform using NETCONF or RESTCONF. In fact, the Infix
|
||||
regression test system solely relies on NETCONF and RESTCONF.
|
||||
|
||||
> [!TIP]
|
||||
> The CLI documentation is also available from inside the CLI itself
|
||||
> using the `help` command in admin-exec mode.
|
||||
|
||||
This document provides an introduction of key concepts, details how
|
||||
the system boots, including failure modes, and provides links to
|
||||
other documents for further study.
|
||||
|
||||
## Command Line Interface
|
||||
|
||||
The command line interface (CLI, see-ell-i) is the traditional way of
|
||||
interacting with single network equipment like switches and routers.
|
||||
Today users have come to expect more advanced graphical GUIs, like a web
|
||||
interface, to manage a device or NETCONF-based tools that allow for
|
||||
managing entire fleets of installed equipment.
|
||||
|
||||
Nevertheless, when it comes to initial deployment and debugging, it
|
||||
is very useful to know how to navigate and use the CLI.
|
||||
|
||||
> [!INFO]
|
||||
> For more information, see the [CLI Introduction](cli/introduction.md)
|
||||
> and the [CLI Configuration Tutorial](cli/configure.md).
|
||||
|
||||
## Key Concepts
|
||||
|
||||
The two modes in the CLI are the admin-exec and the configure context.
|
||||
|
||||
However, when logging in to the system, from the console port or SSH,
|
||||
you land in a standard UNIX shell, Bash. This is for advanced users
|
||||
and remote scripting purposes (production equipment):
|
||||
|
||||
```
|
||||
Run the command 'cli' for interactive OAM
|
||||
|
||||
admin@example:~$
|
||||
```
|
||||
|
||||
To enter the CLI, follow the instructions, for interactive Operations,
|
||||
Administration, and Management (OAM), type:
|
||||
|
||||
```
|
||||
admin@example:~$ cli
|
||||
admin@example:/>
|
||||
```
|
||||
|
||||
The prompt, constructed from your username and the device's hostname,
|
||||
changes slightly. You are now in the admin-exec context of the CLI.
|
||||
Here you can inspect system status and do operations to debug networking
|
||||
issues, e.g. ping. You can also enter configure context by typing:
|
||||
`configure` followed by commands to `set`, `edit`, apply changes using
|
||||
`leave`, or `abort` and return to admin-exec.
|
||||
|
||||
> [!TIP]
|
||||
> If you haven't already, the [CLI Introduction](cli/introduction.md)
|
||||
> would be useful to skim through at this point.
|
||||
|
||||
## Datastores
|
||||
|
||||
The system has several datastores (or files):
|
||||
|
||||
- `factory-config` consists of a set of default configurations, some
|
||||
static and others generated per-device, e.g., a unique hostname and
|
||||
number of ports/interfaces. This file is generated at boot.
|
||||
- `failure-config` is also generated at boot, from the same YANG models
|
||||
as `factory-config`, and holds the system *Fail Secure Mode*
|
||||
- `startup-config` is created from `factory-config` at boot if it does
|
||||
not exist. It is loaded as the system configuration on each boot.
|
||||
- `running-config` is what is actively running on the system. If no
|
||||
changes have been made since the system booted, it is the same as
|
||||
`startup-config`.
|
||||
- `candidate-config` is created from `running-config` when entering the
|
||||
configure context. Any changes made here can be discarded (`abort`,
|
||||
`rollback`) or committed (`commit`, `leave`) to `running-config`.
|
||||
|
||||
> [!TIP]
|
||||
> Please see the [Branding & Releases](branding.md) document for more
|
||||
> in-depth information on how `factory-config` and `failure-config` can
|
||||
> be adapted to different customer requirements. Including how you can
|
||||
> override the generated versions of these files with plain per-product
|
||||
> ones -- this may even protect against some of the failure modes below.
|
||||
@@ -1,152 +0,0 @@
|
||||
# Introduction
|
||||
|
||||
This document provides an introduction of key concepts, details how
|
||||
the system boots, including failure modes, and provides links to
|
||||
other documents for further study.
|
||||
|
||||
## CLI
|
||||
|
||||
The command line interface (CLI, see-ell-i) is the traditional way of
|
||||
interacting with single network equipment like switches and routers.
|
||||
Today users have come to expect more advanced graphical GUIs, like a web
|
||||
interface, to manage a device or NETCONF-based tools that allow for
|
||||
managing entire fleets of installed equipment.
|
||||
|
||||
Nevertheless, when it comes to initial deployment and debugging, it
|
||||
is very useful to know how to navigate and use the CLI.
|
||||
|
||||
> Proceed to the [CLI Introduction](cli/introduction.md) or [CLI
|
||||
> Configuration Tutorial](cli/configure.md).
|
||||
|
||||
|
||||
## Key Concepts
|
||||
|
||||
The two modes in the CLI are the admin-exec and the configure context.
|
||||
|
||||
However, when logging in to the system, from the console port or SSH,
|
||||
you land in a standard UNIX shell, Bash. This is for advanced users
|
||||
and remote scripting purposes (production equipment):
|
||||
|
||||
Run the command 'cli' for interactive OAM
|
||||
|
||||
admin@example:~$
|
||||
|
||||
To enter the CLI, follow the instructions, for interactive Operations,
|
||||
Administration, and Management (OAM), type:
|
||||
|
||||
admin@example:~$ cli
|
||||
admin@example:/>
|
||||
|
||||
The prompt, constructed from your username and the device's hostname,
|
||||
changes slightly. You are now in the admin-exec context of the CLI.
|
||||
Here you can inspect system status and do operations to debug networking
|
||||
issues, e.g. ping. You can also enter configure context by typing:
|
||||
`configure` followed by commands to `set`, `edit`, apply changes using
|
||||
`leave`, or `abort` and return to admin-exec.
|
||||
|
||||
> The [CLI Introduction](cli/introduction.md) can be useful to skim
|
||||
> through at this point.
|
||||
|
||||
The system has several datastores (or files):
|
||||
|
||||
- `factory-config` consists of a set of default configurations, some
|
||||
static and others generated per-device, e.g., a unique hostname and
|
||||
number of ports/interfaces. This file is generated at boot.
|
||||
- `failure-config` is also generated at boot, from the same YANG models
|
||||
as `factory-config`, and holds the system *Fail Secure Mode*
|
||||
- `startup-config` is created from `factory-config` at boot if it does
|
||||
not exist. It is loaded as the system configuration on each boot.
|
||||
- `running-config` is what is actively running on the system. If no
|
||||
changes have been made since the system booted, it is the same as
|
||||
`startup-config`.
|
||||
- `candidate-config` is created from `running-config` when entering the
|
||||
configure context. Any changes made here can be discarded (`abort`,
|
||||
`rollback`) or committed (`commit`, `leave`) to `running-config`.
|
||||
|
||||
> Please see the [Branding & Releases](branding.md) document for more
|
||||
> in-depth information on how `factory-config` and `failure-config` can
|
||||
> be adapted to different customer requirements. Including how you can
|
||||
> override the generated versions of these files with plain per-product
|
||||
> ones -- this may even protect against some of the failure modes below.
|
||||
|
||||
|
||||
## System Boot
|
||||
|
||||
After the system firmware (BIOS or and [boot loader](boot.md) start
|
||||
Linux the following happens. The various failure modes, e.g., missing
|
||||
password in VPD, are detailed later in this section.
|
||||
|
||||

|
||||
|
||||
1. Before mounting `/cfg` and `/var` partitions, hosting read-writable
|
||||
data like `startup-config` and container images, the system first
|
||||
checks if a factory reset has been requested by the user, if so it
|
||||
wipes the contents of these partitions
|
||||
2. Linux boots with a device tree which is used for detecting generic
|
||||
make and model of the device, e.g., number of interfaces. It may
|
||||
also reference an EEPROM with [Vital Product Data](vpd.md). That is
|
||||
where the base MAC address and per-device password hash is stored.
|
||||
(Generic builds use the same MAC address and password)
|
||||
3. On every boot the system's `factory-config` and `failure-config` are
|
||||
generated from the YANG[^1] models of the current firmware version.
|
||||
This ensures that a factory reset device can always boot, and that
|
||||
there is a working fail safe, or rather *fail secure*, mode
|
||||
4. On first power-on, and after a factory reset, the system does not
|
||||
have a `startup-config`, in which case `factory-config` is copied
|
||||
to `startup-config` -- if a per-product specific version exists it
|
||||
is preferred over the generated one
|
||||
5. Provided the integrity of the `startup-config` is OK, a system
|
||||
service loads and activates the configuration
|
||||
|
||||
### Failure Modes
|
||||
|
||||
So, what happens if any of the steps above fail?
|
||||
|
||||
**VPD Fail**
|
||||
|
||||
The per-device password cannot be read, or is corrupt, so the system
|
||||
`factory-config` and `failure-config` are not generated:
|
||||
|
||||
1. First boot, or after factory reset: `startup-config` cannot be
|
||||
created or loaded, and `failure-config` cannot be loaded. The
|
||||
system ends up in an unrecoverable state, i.e., **RMA[^2] Mode**
|
||||
2. The system has booted (at least) once with correct VPD and password
|
||||
and already has a `startup-config`. Provided the `startup-config`
|
||||
is OK (see below), it is loaded and system boots successfully
|
||||
|
||||
In both cases, external factory reset modes/button will not help, and
|
||||
in the second case will cause the device to fail on the next boot.
|
||||
|
||||
> The second case does not yet have any warning or event that can be
|
||||
> detected from the outside. This is planned for a later release.
|
||||
|
||||
**Broken startup-config**
|
||||
|
||||
If loading `startup-config` fails for some reason, e.g., invalid JSON
|
||||
syntax, failed validation against the system's YANG model, or a bug in
|
||||
the system's `confd` service, the *Fail Secure Mode* is triggered and
|
||||
`failure-config` is loaded (unless VPD Failure, see above).
|
||||
|
||||
> Again, please see the [Branding & Releases](branding.md) document for
|
||||
> how to provide a per-product hard-coded `failure-config` to suit your
|
||||
> products preferences.
|
||||
|
||||
*Fail Secure Mode* is a fail-safe mode provided for debugging the
|
||||
system. The default[^3] creates a setup of isolated interfaces with
|
||||
communication only to the management CPU, SSH and console login using
|
||||
the device's factory reset password, IP connectivity only using IPv6
|
||||
link-local, and device discovery protocols: LLDP, mDNS-SD. The login
|
||||
and shell prompt are set to `failure-c0-ff-ee`, the last three octets of
|
||||
the device's base MAC address.
|
||||
|
||||
[^1]: YANG is a modeling language from IETF, replacing that used for
|
||||
SNMP (MIB), used to describe the subsystems and properties of
|
||||
the system.
|
||||
[^2]: Return Merchandise Authorization (RMA), i.e., broken beyond repair
|
||||
by end-user and eligible for return to manufacturer.
|
||||
[^3]: Customer specific builds can define their own `failure-config`.
|
||||
It may be the same as `factory-config`, with the hostname set to
|
||||
`failure`, or a dedicated configuration that isolates interfaces, or
|
||||
even disables ports, to ensure that the device does not cause any
|
||||
security problems on the network. E.g., start forwarding traffic
|
||||
between previously isolated VLANs.
|
||||
|
Before Width: | Height: | Size: 17 KiB After Width: | Height: | Size: 1.7 KiB |
@@ -1,5 +1,5 @@
|
||||
Origin & Licensing
|
||||
------------------
|
||||
==================
|
||||
|
||||
Infix is entirely built on Open Source components (packages). Most of
|
||||
them, as well as the build system with its helper scripts and tools, is
|
||||
|
||||
|
After Width: | Height: | Size: 18 KiB |
|
After Width: | Height: | Size: 11 KiB |
@@ -0,0 +1,338 @@
|
||||
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
|
||||
<!-- Created with Inkscape (http://www.inkscape.org/) -->
|
||||
|
||||
<svg
|
||||
width="81.545341mm"
|
||||
height="26.582481mm"
|
||||
viewBox="0 0 81.545341 26.582481"
|
||||
version="1.1"
|
||||
id="svg5"
|
||||
inkscape:version="1.2.2 (b0a8486541, 2022-12-01)"
|
||||
sodipodi:docname="datadatafinal2.svg"
|
||||
xmlns:inkscape="http://www.inkscape.org/namespaces/inkscape"
|
||||
xmlns:sodipodi="http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd"
|
||||
xmlns="http://www.w3.org/2000/svg"
|
||||
xmlns:svg="http://www.w3.org/2000/svg">
|
||||
<sodipodi:namedview
|
||||
id="namedview7"
|
||||
pagecolor="#ffffff"
|
||||
bordercolor="#000000"
|
||||
borderopacity="0.25"
|
||||
inkscape:showpageshadow="2"
|
||||
inkscape:pageopacity="0.0"
|
||||
inkscape:pagecheckerboard="0"
|
||||
inkscape:deskcolor="#d1d1d1"
|
||||
inkscape:document-units="mm"
|
||||
showgrid="false"
|
||||
inkscape:zoom="4.1146545"
|
||||
inkscape:cx="339.51818"
|
||||
inkscape:cy="495.54586"
|
||||
inkscape:window-width="2560"
|
||||
inkscape:window-height="1385"
|
||||
inkscape:window-x="1920"
|
||||
inkscape:window-y="0"
|
||||
inkscape:window-maximized="1"
|
||||
inkscape:current-layer="layer5" />
|
||||
<defs
|
||||
id="defs2" />
|
||||
<g
|
||||
inkscape:groupmode="layer"
|
||||
id="layer6"
|
||||
inkscape:label="bg"
|
||||
style="display:none;fill:#ff0000;fill-opacity:1"
|
||||
transform="matrix(1.2831201,0,0,3.2117929,-85.704829,-329.92383)">
|
||||
<rect
|
||||
style="fill:#22272e;fill-opacity:1;stroke:#000000;stroke-width:0;stroke-miterlimit:0;stroke-dasharray:none;stroke-opacity:1"
|
||||
id="rect10264"
|
||||
width="163.66356"
|
||||
height="92.471725"
|
||||
x="20.800945"
|
||||
y="69.866936"
|
||||
inkscape:label="bg" />
|
||||
</g>
|
||||
<g
|
||||
inkscape:groupmode="layer"
|
||||
id="layer5"
|
||||
inkscape:label="tagline"
|
||||
style="display:inline"
|
||||
transform="translate(-59.014718,-105.5257)">
|
||||
<g
|
||||
aria-label="Immutable . Friendly . Secure"
|
||||
transform="scale(0.95128779,1.0512066)"
|
||||
id="text9503"
|
||||
style="font-size:6.44339px;font-family:Laksaman;-inkscape-font-specification:'Laksaman, Normal';stroke:#5c5f5c;stroke-width:0;stroke-miterlimit:0"
|
||||
inkscape:label="linux-netconf"
|
||||
inkscape:export-filename="minidata3.png"
|
||||
inkscape:export-xdpi="191.95932"
|
||||
inkscape:export-ydpi="191.95932">
|
||||
<path
|
||||
d="m 62.472956,124.15871 h -0.386604 v -4.61347 h 0.386604 z"
|
||||
id="path2380" />
|
||||
<path
|
||||
d="m 67.144418,120.79526 q 0.573462,0 0.869857,0.4317 0.296396,0.43171 0.296396,1.10182 v 1.82993 h -0.386603 v -1.82348 q 0,-0.54125 -0.219075,-0.8763 -0.212632,-0.3415 -0.663669,-0.3415 -0.367274,0 -0.657226,0.28995 -0.289953,0.28995 -0.289953,0.65722 v 2.09411 h -0.386603 v -1.99745 q 0,-1.04383 -0.831197,-1.04383 -0.38016,0 -0.689443,0.32861 -0.309283,0.32861 -0.309283,0.71522 v 1.99745 H 63.491016 V 121.678 q 0,-0.28995 -0.06443,-0.81187 h 0.354386 q 0.06443,0.19975 0.07732,0.58635 0.373717,-0.65722 1.108263,-0.65722 0.670113,0 0.998725,0.73454 0.386604,-0.73454 1.179141,-0.73454 z"
|
||||
id="path2382" />
|
||||
<path
|
||||
d="m 72.969238,120.79526 q 0.573462,0 0.869858,0.4317 0.296396,0.43171 0.296396,1.10182 v 1.82993 h -0.386604 v -1.82348 q 0,-0.54125 -0.219075,-0.8763 -0.212632,-0.3415 -0.663669,-0.3415 -0.367273,0 -0.657226,0.28995 -0.289953,0.28995 -0.289953,0.65722 v 2.09411 h -0.386603 v -1.99745 q 0,-1.04383 -0.831197,-1.04383 -0.38016,0 -0.689443,0.32861 -0.309283,0.32861 -0.309283,0.71522 v 1.99745 H 69.315836 V 121.678 q 0,-0.28995 -0.06443,-0.81187 h 0.354386 q 0.06443,0.19975 0.07732,0.58635 0.373717,-0.65722 1.108263,-0.65722 0.670113,0 0.998726,0.73454 0.386603,-0.73454 1.17914,-0.73454 z"
|
||||
id="path2384" />
|
||||
<path
|
||||
d="m 78.078841,124.14582 -0.36083,0.0838 q -0.115981,-0.32861 -0.154641,-0.64434 -0.431707,0.66367 -1.237131,0.66367 -1.185584,0 -1.185584,-1.53352 v -1.84926 h 0.386604 v 1.77838 q 0,1.28223 0.882744,1.28223 0.457481,0 0.786094,-0.30928 0.328613,-0.31572 0.328613,-0.76032 v -1.99101 h 0.386603 v 2.48715 q 0,0.34795 0.167528,0.79254 z"
|
||||
id="path2386" />
|
||||
<path
|
||||
d="m 79.973201,124.24891 q -0.39949,0 -0.625009,-0.29639 -0.219075,-0.30284 -0.219075,-0.76032 v -2.03611 h -0.657226 v -0.28996 h 0.657226 v -0.97939 l 0.386603,-0.17397 v 1.15336 h 1.050273 v 0.28996 H 79.51572 v 2.03611 q 0,0.73454 0.489698,0.73454 0.302839,0 0.444594,-0.058 l 0.03866,0.28996 q -0.199745,0.0902 -0.515471,0.0902 z"
|
||||
id="path2388" />
|
||||
<path
|
||||
d="m 82.015758,124.24891 q -0.43815,0 -0.747433,-0.25129 -0.302839,-0.25773 -0.302839,-0.66367 0,-1.23068 2.190752,-1.23068 0,-0.47037 -0.225519,-0.72811 -0.225518,-0.25773 -0.663669,-0.25773 -0.354386,0 -1.050272,0.21907 l -0.0451,-0.36727 q 0.541245,-0.17397 1.12115,-0.17397 1.250018,0 1.250018,1.37888 v 1.17914 q 0,0.40594 0.115981,0.80543 l -0.335057,0.0709 -0.135311,-0.5348 q -0.444594,0.55413 -1.172697,0.55413 z m -0.663669,-0.97939 q 0,0.30284 0.186858,0.48325 0.186859,0.17397 0.489698,0.17397 0.386603,0 0.753876,-0.2384 0.373717,-0.24485 0.373717,-0.59279 v -0.67012 q -1.804149,0 -1.804149,0.84409 z"
|
||||
id="path2390" />
|
||||
<path
|
||||
d="m 86.178189,120.79526 q 0.683,0 1.08249,0.47681 0.39949,0.47037 0.39949,1.19847 0,0.77965 -0.412377,1.28223 -0.412377,0.49614 -1.127593,0.49614 -0.766764,0 -1.224244,-0.67011 0,0.32861 -0.01933,0.57991 h -0.354387 q 0.02577,-0.22552 0.02577,-0.80543 v -4.09155 h 0.386603 v 2.22941 q 0.425264,-0.69588 1.243574,-0.69588 z m -1.243574,2.04255 q 0,0.46393 0.328613,0.77965 0.328613,0.30928 0.805424,0.30928 1.204914,0 1.204914,-1.44331 0,-0.61213 -0.30284,-0.98584 -0.302839,-0.38016 -0.863414,-0.38016 -0.489698,0 -0.831197,0.3415 -0.3415,0.3415 -0.3415,0.83119 z"
|
||||
id="path2392" />
|
||||
<path
|
||||
d="m 89.696285,123.92674 -0.03866,0.32217 q -1.224244,-0.058 -1.224244,-1.74615 v -3.24103 h 0.386603 v 3.10571 q 0,0.36728 0.03222,0.61857 0.03222,0.25129 0.115981,0.48325 0.09021,0.23197 0.270623,0.34795 0.180415,0.10953 0.457481,0.10953 z"
|
||||
id="path2394" />
|
||||
<path
|
||||
d="m 90.51459,122.54142 q 0.01933,0.625 0.373717,1.00516 0.36083,0.38016 0.960065,0.38016 0.560575,0 1.153367,-0.23196 l 0.03222,0.31573 q -0.573462,0.2384 -1.224245,0.2384 -0.740989,0 -1.211357,-0.45748 -0.470367,-0.46392 -0.470367,-1.19202 0,-0.77965 0.451037,-1.28868 0.457481,-0.51547 1.192027,-0.51547 1.385329,0 1.417546,1.74616 z m 2.287403,-0.32217 q -0.01289,-0.50259 -0.309282,-0.79898 -0.289953,-0.30284 -0.766764,-0.30284 -0.47681,0 -0.79898,0.31572 -0.322169,0.30929 -0.393047,0.7861 z"
|
||||
id="path2396" />
|
||||
<path
|
||||
d="m 96.345854,123.54658 q 0.135311,0 0.238405,0.1031 0.103095,0.10309 0.103095,0.2384 0,0.13532 -0.103095,0.23197 -0.103094,0.0966 -0.238405,0.0966 -0.135311,0 -0.231962,-0.0966 -0.09665,-0.0967 -0.09665,-0.23197 0,-0.13531 0.09665,-0.2384 0.09665,-0.1031 0.231962,-0.1031 z"
|
||||
id="path2398" />
|
||||
<path
|
||||
d="m 102.20934,121.94218 h -2.07477 v 2.21653 h -0.386608 v -4.61347 h 2.609578 v 0.32217 h -2.22297 v 1.7526 h 2.07477 z"
|
||||
id="path2400" />
|
||||
<path
|
||||
d="m 104.6385,121.13031 q -0.0387,-0.0129 -0.11598,-0.0129 -0.42527,0 -0.72166,0.34794 -0.28996,0.3415 -0.28996,0.9214 v 1.77194 h -0.3866 v -2.21653 q 0,-0.7281 -0.0967,-1.07605 h 0.32861 q 0.1031,0.20619 0.1031,0.65723 0.30928,-0.7281 0.99228,-0.7281 0.0902,0 0.18686,0.0193 z"
|
||||
id="path2402" />
|
||||
<path
|
||||
d="m 105.60501,124.15871 h -0.38661 v -3.29258 h 0.38661 z m -0.20619,-4.60058 q 0.13531,0 0.21907,0.0902 0.0902,0.0838 0.0902,0.21908 0,0.13531 -0.0902,0.21907 -0.0838,0.0773 -0.21907,0.0773 -0.13531,0 -0.21908,-0.0773 -0.0773,-0.0838 -0.0773,-0.21907 0,-0.13531 0.0773,-0.21908 0.0838,-0.0902 0.21908,-0.0902 z"
|
||||
id="path2404" />
|
||||
<path
|
||||
d="m 106.75838,122.54142 q 0.0193,0.625 0.37371,1.00516 0.36083,0.38016 0.96007,0.38016 0.56057,0 1.15336,-0.23196 l 0.0322,0.31573 q -0.57346,0.2384 -1.22424,0.2384 -0.74099,0 -1.21136,-0.45748 -0.47037,-0.46392 -0.47037,-1.19202 0,-0.77965 0.45104,-1.28868 0.45748,-0.51547 1.19203,-0.51547 1.38533,0 1.41754,1.74616 z m 2.2874,-0.32217 q -0.0129,-0.50259 -0.30928,-0.79898 -0.28996,-0.30284 -0.76677,-0.30284 -0.47681,0 -0.79898,0.31572 -0.32217,0.30929 -0.39304,0.7861 z"
|
||||
id="path2406" />
|
||||
<path
|
||||
d="m 113.00202,124.15871 h -0.3866 v -1.86859 q 0,-1.17269 -0.9794,-1.17269 -0.3866,0 -0.70233,0.32861 -0.31572,0.32861 -0.31572,0.71522 v 1.99745 h -0.38661 V 121.678 q 0,-0.28995 -0.0644,-0.81187 h 0.36083 q 0.0644,0.19975 0.0773,0.58635 0.37372,-0.65722 1.10826,-0.65722 1.28868,0 1.28868,1.49486 z"
|
||||
id="path2408" />
|
||||
<path
|
||||
d="m 113.77523,122.47054 q 0,-0.72166 0.39949,-1.19847 0.40593,-0.47681 1.08249,-0.47681 0.81831,0 1.24357,0.69588 v -2.22941 h 0.38661 v 4.09155 q 0,0.57991 0.0258,0.80543 h -0.35439 q -0.0193,-0.2513 -0.0193,-0.57991 -0.45748,0.67011 -1.22424,0.67011 -0.72166,0 -1.13404,-0.49614 -0.40593,-0.50258 -0.40593,-1.28223 z m 1.59152,1.4562 q 0.47681,0 0.80542,-0.30928 0.32861,-0.31572 0.32861,-0.77965 v -0.54769 q 0,-0.49614 -0.3415,-0.83119 -0.33505,-0.3415 -0.83119,-0.3415 -0.56058,0 -0.86342,0.38016 -0.30284,0.38016 -0.30284,0.98584 0,1.44331 1.20492,1.44331 z"
|
||||
id="path2410" />
|
||||
<path
|
||||
d="m 119.15547,123.92674 -0.0387,0.32217 q -1.22424,-0.058 -1.22424,-1.74615 v -3.24103 h 0.3866 v 3.10571 q 0,0.36728 0.0322,0.61857 0.0322,0.25129 0.11598,0.48325 0.0902,0.23197 0.27062,0.34795 0.18042,0.10953 0.45749,0.10953 z"
|
||||
id="path2412" />
|
||||
<path
|
||||
d="m 121.10781,124.15871 q -0.57346,1.28867 -1.52064,1.51419 l -0.0902,-0.30284 q 0.82476,-0.18685 1.25002,-1.32089 0,-0.058 -0.0258,-0.11598 l -1.366,-3.06706 h 0.40593 l 1.23069,2.78999 1.15337,-2.78999 h 0.41237 z"
|
||||
id="path2414" />
|
||||
<path
|
||||
d="m 125.44421,123.54658 q 0.13531,0 0.2384,0.1031 0.1031,0.10309 0.1031,0.2384 0,0.13532 -0.1031,0.23197 -0.10309,0.0966 -0.2384,0.0966 -0.13531,0 -0.23196,-0.0966 -0.0966,-0.0967 -0.0966,-0.23197 0,-0.13531 0.0966,-0.2384 0.0966,-0.1031 0.23196,-0.1031 z"
|
||||
id="path2416" />
|
||||
<path
|
||||
d="m 131.42367,122.95379 q 0,0.59924 -0.45103,0.94718 -0.4446,0.34794 -1.11471,0.34794 -0.76032,0 -1.26935,-0.35438 l 0.15464,-0.32862 q 0.47681,0.36083 1.15337,0.36083 0.50903,0 0.82475,-0.24484 0.31573,-0.24485 0.31573,-0.69589 0,-0.43815 -0.25129,-0.65723 -0.2513,-0.22551 -0.75388,-0.38016 -1.28868,-0.41882 -1.28868,-1.30156 0,-0.54125 0.41238,-0.85697 0.41238,-0.32217 1.01805,-0.32217 0.64434,0 1.05672,0.24485 -0.0129,0.0258 -0.0773,0.14175 -0.058,0.10954 -0.0838,0.16109 -0.41882,-0.22552 -0.90208,-0.22552 -0.45104,0 -0.74743,0.21263 -0.28995,0.21263 -0.28995,0.59924 0,0.63789 0.99872,0.98583 0.32217,0.11599 0.51547,0.21264 0.19975,0.0902 0.39949,0.24484 0.19975,0.15465 0.28995,0.38016 0.0902,0.22552 0.0902,0.52836 z"
|
||||
id="path2418" />
|
||||
<path
|
||||
d="m 132.38373,122.54142 q 0.0193,0.625 0.37372,1.00516 0.36083,0.38016 0.96006,0.38016 0.56058,0 1.15337,-0.23196 l 0.0322,0.31573 q -0.57347,0.2384 -1.22425,0.2384 -0.74099,0 -1.21136,-0.45748 -0.47036,-0.46392 -0.47036,-1.19202 0,-0.77965 0.45103,-1.28868 0.45749,-0.51547 1.19203,-0.51547 1.38533,0 1.41755,1.74616 z m 2.2874,-0.32217 q -0.0129,-0.50259 -0.30928,-0.79898 -0.28995,-0.30284 -0.76676,-0.30284 -0.47681,0 -0.79898,0.31572 -0.32217,0.30929 -0.39305,0.7861 z"
|
||||
id="path2420" />
|
||||
<path
|
||||
d="m 137.3387,121.11743 q -0.61212,0 -0.97295,0.3866 -0.36083,0.3866 -0.36083,1.01806 0,0.625 0.36727,1.01805 0.36727,0.3866 0.96651,0.3866 0.54124,0 0.90207,-0.23196 l 0.13531,0.31573 q -0.42526,0.2384 -1.01805,0.2384 -0.79898,0 -1.26935,-0.46392 -0.47037,-0.47037 -0.47037,-1.2629 0,-0.79254 0.47037,-1.25647 0.47037,-0.47036 1.26935,-0.47036 0.59923,0 1.01805,0.23196 l -0.13531,0.32217 q -0.36083,-0.23196 -0.90207,-0.23196 z"
|
||||
id="path2422" />
|
||||
<path
|
||||
d="m 141.99727,124.14582 -0.36083,0.0838 q -0.11598,-0.32861 -0.15464,-0.64434 -0.4317,0.66367 -1.23713,0.66367 -1.18558,0 -1.18558,-1.53352 v -1.84926 h 0.3866 v 1.77838 q 0,1.28223 0.88275,1.28223 0.45748,0 0.78609,-0.30928 0.32861,-0.31572 0.32861,-0.76032 v -1.99101 h 0.38661 v 2.48715 q 0,0.34795 0.16752,0.79254 z"
|
||||
id="path2424" />
|
||||
<path
|
||||
d="m 144.34911,121.13031 q -0.0387,-0.0129 -0.11598,-0.0129 -0.42526,0 -0.72166,0.34794 -0.28995,0.3415 -0.28995,0.9214 v 1.77194 h -0.38661 v -2.21653 q 0,-0.7281 -0.0967,-1.07605 h 0.32862 q 0.10309,0.20619 0.10309,0.65723 0.30928,-0.7281 0.99228,-0.7281 0.0902,0 0.18686,0.0193 z"
|
||||
id="path2426" />
|
||||
<path
|
||||
d="m 145.08366,122.54142 q 0.0193,0.625 0.37372,1.00516 0.36083,0.38016 0.96006,0.38016 0.56058,0 1.15337,-0.23196 l 0.0322,0.31573 q -0.57346,0.2384 -1.22424,0.2384 -0.74099,0 -1.21136,-0.45748 -0.47036,-0.46392 -0.47036,-1.19202 0,-0.77965 0.45103,-1.28868 0.45748,-0.51547 1.19203,-0.51547 1.38533,0 1.41755,1.74616 z m 2.2874,-0.32217 q -0.0129,-0.50259 -0.30928,-0.79898 -0.28995,-0.30284 -0.76676,-0.30284 -0.47681,0 -0.79898,0.31572 -0.32217,0.30929 -0.39305,0.7861 z"
|
||||
id="path2428" />
|
||||
</g>
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.194246;stroke-linejoin:bevel"
|
||||
d="m 223.38329,484.15901 v -9.03246 h 0.58274 0.58274 v 9.03246 9.03245 h -0.58274 -0.58274 z"
|
||||
id="path1834"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.194246;stroke-linejoin:bevel"
|
||||
d="m 228.43253,488.38386 c -6.4e-4,-2.64417 -0.0579,-5.53584 -0.12713,-6.42592 l -0.12597,-1.61833 0.56419,0.0644 c 0.53405,0.0609 0.56732,0.11883 0.6229,1.08415 0.0323,0.56089 0.12967,1.01979 0.21639,1.01979 0.0867,0 0.38929,-0.33422 0.67238,-0.74271 0.91393,-1.3188 2.66926,-2.00044 4.13506,-1.60574 0.86092,0.23182 2.04111,1.29757 2.40217,2.16924 0.12933,0.31224 0.2901,0.56535 0.35727,0.56248 0.0672,-0.003 0.34006,-0.35837 0.60644,-0.78999 1.62805,-2.638 5.25262,-2.76519 6.73464,-0.23631 0.85471,1.45845 1.03015,2.6805 1.03347,7.19885 l 0.003,4.12773 h -0.58274 -0.58274 v -3.85841 c 0,-4.04906 -0.16272,-5.48953 -0.74837,-6.62489 -0.97524,-1.89066 -3.35323,-2.11305 -4.92303,-0.4604 -1.03875,1.09356 -1.12722,1.60138 -1.12722,6.4698 v 4.4739 h -0.56535 -0.56534 l -0.0723,-4.8076 c -0.0781,-5.19309 -0.16625,-5.68505 -1.188,-6.62687 -0.5343,-0.49249 -1.87288,-0.75083 -2.74992,-0.53071 -0.72522,0.18202 -2.04937,1.44652 -2.46084,2.34999 -0.30871,0.67784 -0.35441,1.34084 -0.35813,5.19609 l -0.004,4.4191 h -0.58274 -0.58274 z"
|
||||
id="path1836"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.194246;stroke-linejoin:bevel"
|
||||
d="m 249.39406,488.57811 c -0.01,-2.53734 -0.0756,-5.42192 -0.14569,-6.41017 l -0.12744,-1.79683 0.53048,5e-5 c 0.57465,5e-5 0.68172,0.2256 0.77747,1.63776 l 0.0518,0.76361 0.5691,-0.82445 c 1.00313,-1.45322 2.80602,-2.19608 4.33232,-1.78509 0.80947,0.21797 1.99805,1.32577 2.42291,2.25823 0.11908,0.26135 0.26804,0.47242 0.33102,0.46905 0.063,-0.003 0.34597,-0.38783 0.62888,-0.85432 0.7501,-1.23686 2.06363,-1.95451 3.57903,-1.95541 1.33872,-8e-4 2.22364,0.46503 2.97983,1.56862 0.89814,1.31075 1.04718,2.23303 1.13543,7.02607 l 0.0831,4.51623 h -0.60091 -0.60092 l -0.006,-3.44787 c -0.007,-4.03899 -0.2174,-5.95631 -0.77305,-7.04547 -1.0695,-2.09639 -3.90894,-2.05963 -5.38561,0.0697 l -0.53685,0.77414 -0.0581,4.82474 -0.0581,4.82474 h -0.54937 -0.54937 l -0.0848,-4.71047 c -0.0769,-4.27252 -0.12307,-4.79578 -0.49627,-5.62796 -1.17692,-2.62436 -4.42294,-2.20832 -5.94644,0.76215 -0.26842,0.52335 -0.31884,1.32971 -0.31884,5.09897 v 4.47731 h -0.58274 -0.58274 z"
|
||||
id="path1838"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.194246;stroke-linejoin:bevel"
|
||||
d="m 273.01323,493.28817 c -0.42734,-0.15111 -1.05549,-0.57696 -1.3959,-0.94634 -1.08415,-1.17645 -1.27314,-2.18958 -1.37243,-7.35728 l -0.0886,-4.61335 h 0.60294 0.60294 l 0.003,3.15651 c 0.004,3.91414 0.25019,6.36807 0.73168,7.3013 1.13174,2.19355 4.30257,2.12242 5.93754,-0.1332 l 0.61157,-0.84373 0.0582,-4.74044 0.0582,-4.74044 h 0.67021 0.67021 l 0.005,5.48746 c 0.003,3.0181 0.0937,5.87338 0.20243,6.34505 0.15249,0.66158 0.14031,0.89461 -0.0533,1.01955 -0.55281,0.35673 -0.83165,0.0557 -1.09962,-1.18733 -0.24582,-1.14025 -0.29208,-1.21548 -0.53608,-0.87175 -1.45497,2.04964 -3.5618,2.84756 -5.60816,2.12399 z"
|
||||
id="path1840"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 287.30474,493.62291 c -0.5234,-0.0325 -0.99929,-0.2067 -1.39355,-0.51007 -0.0711,-0.0547 -0.21266,-0.18756 -0.31455,-0.2952 -0.51237,-0.54129 -0.84906,-1.32221 -1.01656,-2.35786 l -0.0518,-0.32009 -0.007,-4.39554 -0.007,-4.39554 h -1.17681 -1.17681 v -0.56016 -0.56016 h 1.17748 1.17748 v -1.94931 -1.9493 l 0.67458,-0.33706 c 0.37102,-0.18538 0.67968,-0.33706 0.68591,-0.33706 0.006,0 0.0113,1.02886 0.0113,2.28637 v 2.28636 h 1.88625 1.88625 v 0.56016 0.56016 h -1.88681 -1.8868 l 0.007,4.42983 c 0.008,4.76198 0.003,4.54099 0.11952,5.05219 0.16032,0.70049 0.47404,1.17713 0.91502,1.3902 0.25035,0.12096 0.40253,0.14734 0.85223,0.14773 0.56364,4.8e-4 1.01334,-0.0544 1.32518,-0.16168 0.0702,-0.0241 0.13023,-0.0412 0.13351,-0.0379 0.003,0.003 0.0357,0.2528 0.072,0.5545 l 0.066,0.54854 -0.0472,0.0278 c -0.0785,0.0463 -0.33404,0.13919 -0.51588,0.18759 -0.42382,0.11279 -1.01712,0.16607 -1.509,0.13551 z"
|
||||
id="path1842"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 294.5861,493.62213 c -1.33382,-0.0703 -2.53644,-0.82061 -3.09275,-1.92964 -0.24094,-0.48033 -0.34819,-0.94143 -0.36461,-1.5675 -0.0163,-0.62035 0.0506,-1.12228 0.21568,-1.62005 0.34649,-1.04458 1.07298,-1.83524 2.204,-2.3987 1.19263,-0.59414 2.78564,-0.91132 4.79719,-0.95516 l 0.64935,-0.0142 -0.0145,-0.368 c -0.0763,-1.94209 -0.90557,-3.17288 -2.34847,-3.4855 -0.11953,-0.0259 -0.35827,-0.0588 -0.53054,-0.0732 -0.83261,-0.0693 -2.06866,0.17313 -3.73081,0.73187 -0.18772,0.0631 -0.34391,0.11214 -0.34708,0.10897 -0.003,-0.003 -0.0374,-0.29372 -0.0761,-0.64564 -0.0386,-0.35192 -0.0755,-0.67149 -0.0819,-0.71015 l -0.0116,-0.0703 0.37182,-0.11744 c 1.20391,-0.38027 2.32736,-0.55784 3.54986,-0.5611 0.7727,-0.002 1.23902,0.0602 1.77856,0.23734 1.46594,0.48137 2.35205,1.64256 2.66841,3.49679 0.12045,0.70598 0.11904,0.66437 0.1383,4.08126 0.01,1.7605 0.0238,3.23692 0.0308,3.28093 0.007,0.044 0.0291,0.23435 0.0491,0.42298 0.0465,0.43878 0.14592,1.02673 0.2474,1.4631 0.0438,0.18852 0.0764,0.34605 0.0724,0.35005 -0.01,0.01 -1.16361,0.2786 -1.16815,0.2723 -0.002,-0.003 -0.10844,-0.46785 -0.23669,-1.03372 -0.12825,-0.56588 -0.23848,-1.0443 -0.24496,-1.06316 -0.009,-0.0258 -0.0241,-0.0174 -0.0616,0.0341 -0.24974,0.34282 -0.61859,0.73947 -0.92993,1.00003 -0.98835,0.82713 -2.1679,1.2056 -3.53328,1.13367 z m 0.93086,-1.28687 c 0.65714,-0.0991 1.29513,-0.35128 1.90495,-0.7531 0.81304,-0.53573 1.28846,-1.12731 1.48996,-1.85402 l 0.0634,-0.22864 0.008,-1.55251 0.008,-1.55252 -0.63565,0.0142 c -3.56014,0.0798 -5.51289,1.02626 -5.8264,2.82409 -0.0446,0.25589 -0.0441,0.85092 10e-4,1.11538 0.18522,1.08602 0.8607,1.80366 1.87004,1.98675 0.22689,0.0412 0.84543,0.0413 1.1175,3.3e-4 z"
|
||||
id="path1844"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 309.32244,493.62288 c -0.96944,-0.0469 -1.85038,-0.37861 -2.65218,-0.99851 -0.41295,-0.31926 -0.94289,-0.9117 -1.28908,-1.44113 l -0.1399,-0.21394 -0.005,0.14535 c -0.003,0.0799 -0.0158,0.50031 -0.0286,0.93415 -0.0128,0.43384 -0.03,0.88911 -0.0382,1.01172 l -0.0148,0.22292 h -0.62644 -0.62644 l 0.0136,-0.13147 c 0.0609,-0.58676 0.0652,-1.17336 0.0733,-10.07144 l 0.008,-9.2312 h 0.68506 0.68507 l 7.2e-4,4.42983 c 5.8e-4,3.48836 0.007,4.42158 0.0286,4.39101 0.0153,-0.0214 0.0947,-0.14835 0.17647,-0.28221 0.23909,-0.39153 0.48968,-0.7084 0.83324,-1.05364 0.79409,-0.79798 1.61045,-1.19749 2.77922,-1.36008 0.2959,-0.0412 1.07923,-0.0347 1.40611,0.0117 1.32147,0.18728 2.34057,0.79358 3.15682,1.87808 0.76131,1.0115 1.19388,2.16861 1.36296,3.64582 0.0403,0.35233 0.0407,1.83298 6e-4,2.20634 -0.11974,1.1141 -0.37776,2.05613 -0.79532,2.90368 -1.03324,2.09723 -2.72255,3.11307 -4.99399,3.00306 z m 0.86193,-1.2892 c 1.76169,-0.22995 2.85867,-1.28108 3.34269,-3.20299 0.30067,-1.19391 0.35369,-2.89198 0.12825,-4.108 -0.29692,-1.60162 -1.09958,-2.84593 -2.19579,-3.40403 -0.57991,-0.29523 -1.09671,-0.4111 -1.83985,-0.41248 -0.63377,-0.001 -1.01616,0.0697 -1.55843,0.28899 -0.58207,0.23535 -1.2143,0.72589 -1.6676,1.29385 -0.44764,0.56087 -0.77863,1.27537 -0.92145,1.98914 -0.0992,0.49576 -0.10972,0.74403 -0.0998,2.35496 0.0101,1.63879 0.0104,1.64172 0.15709,2.19491 0.35782,1.34881 1.39583,2.46469 2.66595,2.86592 0.16235,0.0513 0.55199,0.13409 0.74972,0.15934 0.19748,0.0252 0.99214,0.0126 1.23918,-0.0196 z"
|
||||
id="path1846"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 321.87459,493.58992 c -0.8696,-0.12637 -1.59301,-0.47045 -2.17909,-1.03646 -1.03984,-1.00425 -1.58419,-2.59401 -1.70723,-4.98593 -0.0142,-0.27698 -0.023,-2.95931 -0.0231,-7.08202 l -2.2e-4,-6.63618 h 0.68513 0.68513 l 0.009,6.87625 c 0.009,7.02584 0.008,7.00928 0.0967,7.81365 0.10578,0.96416 0.35005,1.9335 0.62093,2.46402 0.44664,0.87476 1.13121,1.30724 2.15714,1.36279 l 0.26385,0.0143 -0.0674,0.62303 -0.0674,0.62304 -0.12782,-0.002 c -0.0703,-0.001 -0.22557,-0.0167 -0.34503,-0.034 z"
|
||||
id="path1848"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 329.71682,493.62332 c -0.82899,-0.0372 -1.61396,-0.23055 -2.30398,-0.56754 -0.37825,-0.18472 -0.54944,-0.28931 -0.89693,-0.54795 -1.01662,-0.7567 -1.78269,-1.89329 -2.17055,-3.22039 -0.0777,-0.26591 -0.16487,-0.69455 -0.21981,-1.08101 -0.0576,-0.40513 -0.0709,-1.55129 -0.0238,-2.04475 0.11581,-1.21225 0.35793,-2.09011 0.8324,-3.01808 0.61749,-1.20767 1.53413,-2.14784 2.59917,-2.66589 0.77538,-0.37715 1.4905,-0.53207 2.44641,-0.52996 0.56508,0.001 0.9552,0.047 1.4181,0.16637 1.6679,0.43005 2.77783,1.70533 3.2916,3.78196 0.19164,0.7746 0.29118,1.5435 0.34432,2.65973 l 0.0144,0.30294 h -4.81566 -4.81566 l 0.0115,0.1086 c 0.006,0.0597 0.0176,0.21149 0.025,0.33724 0.0636,1.07931 0.381,2.14843 0.87454,2.9463 0.31378,0.50727 0.79874,1.03354 1.23804,1.3435 0.55763,0.39346 1.23414,0.64767 1.97432,0.74188 0.37368,0.0476 1.35758,0.0353 1.79434,-0.0224 0.9694,-0.12807 2.04082,-0.42013 2.89393,-0.78886 0.0608,-0.0263 0.11819,-0.0478 0.1276,-0.0478 0.0179,0 0.13106,1.20581 0.11442,1.21964 -0.005,0.004 -0.11245,0.0518 -0.2382,0.10527 -1.16468,0.49571 -2.41589,0.77766 -3.61246,0.81404 -0.21378,0.007 -0.42469,0.0143 -0.46871,0.0174 -0.044,0.003 -0.23949,-0.002 -0.43441,-0.0103 z m 3.95534,-8.11924 c -2.5e-4,-0.30965 -0.0819,-0.91311 -0.17265,-1.27644 -0.21244,-0.85027 -0.58191,-1.49481 -1.19286,-2.08098 -0.59602,-0.57184 -1.29064,-0.86751 -2.19852,-0.93583 -1.41629,-0.10657 -2.61061,0.44344 -3.51878,1.62047 -0.52227,0.67689 -0.89262,1.54618 -1.04384,2.45013 -0.02,0.11931 -0.0415,0.24008 -0.0478,0.26838 l -0.0115,0.0514 h 4.09303 4.09303 l -7e-5,-0.0972 z"
|
||||
id="path1850"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 358.63935,484.12654 v -9.15689 h 4.68705 4.68705 v 0.62875 0.62875 h -4.00114 -4.00114 v 3.49814 3.49814 h 3.72678 3.72678 v 0.62875 0.62875 h -3.72678 -3.72678 v 4.40126 4.40125 h -0.68591 -0.68591 z"
|
||||
id="path1852"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 370.77972,488.3849 c -2.5e-4,-5.30842 -0.0101,-5.84482 -0.12715,-6.89911 -0.0383,-0.34527 -0.13012,-0.92558 -0.17819,-1.12641 l -0.0315,-0.13185 0.58559,0.006 0.58559,0.006 0.0735,0.21721 c 0.15373,0.45451 0.2441,1.0906 0.27609,1.94333 l 0.0167,0.44577 0.11057,-0.26286 c 0.36692,-0.87227 0.86854,-1.56026 1.46921,-2.01506 0.22423,-0.16978 0.70767,-0.41064 0.98068,-0.48859 0.44934,-0.1283 1.03347,-0.17067 1.45783,-0.10575 l 0.20005,0.0306 v 0.61599 0.61599 l -0.0857,-0.0182 c -0.13914,-0.0295 -0.64614,-0.0138 -0.8626,0.0268 -0.61492,0.11523 -1.11795,0.37837 -1.59623,0.83501 -0.69911,0.66749 -1.13847,1.50376 -1.35187,2.57318 -0.14099,0.70651 -0.13497,0.50782 -0.144,4.74916 l -0.008,3.88111 h -0.68498 -0.68498 z"
|
||||
id="path1854"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 378.32496,486.75587 v -6.52758 h 0.67448 0.67448 v 6.52758 6.52757 h -0.67448 -0.67448 z"
|
||||
id="path1856"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 388.12204,493.62228 c -1.25745,-0.0534 -2.37679,-0.45935 -3.33031,-1.20766 -0.24611,-0.19314 -0.70076,-0.64519 -0.89683,-0.89168 -1.00908,-1.26862 -1.47423,-2.80387 -1.42354,-4.69848 0.0143,-0.53323 0.0346,-0.79039 0.0969,-1.22321 0.23095,-1.60525 0.88593,-2.99875 1.90618,-4.05551 0.84662,-0.87693 1.87353,-1.39202 3.11031,-1.5601 0.38666,-0.0525 1.16134,-0.0519 1.56251,0.001 2.18606,0.29027 3.51464,1.7209 4.04732,4.35822 0.13263,0.65663 0.24325,1.71374 0.24325,2.32446 v 0.18901 h -4.80137 -4.80136 l 4.6e-4,0.1429 c 6.4e-4,0.19414 0.0574,0.76627 0.10322,1.03965 0.36981,2.20844 1.63422,3.74849 3.43951,4.18933 0.48183,0.11766 0.80028,0.14581 1.48681,0.13141 1.20975,-0.0254 2.2518,-0.2443 3.51863,-0.73929 0.20618,-0.0806 0.37851,-0.14284 0.38295,-0.1384 0.0189,0.0189 0.11827,1.19481 0.10234,1.21087 -0.0372,0.0375 -0.75552,0.31882 -1.09377,0.42834 -1.19108,0.38565 -2.40723,0.55167 -3.65322,0.49872 z m 3.93653,-8.32397 c -0.0603,-1.26072 -0.4967,-2.31101 -1.28476,-3.09231 -0.61702,-0.61174 -1.3169,-0.92024 -2.25737,-0.99504 -0.82674,-0.0657 -1.6698,0.12102 -2.31532,0.51292 -0.68961,0.41867 -1.32032,1.12589 -1.72724,1.93675 -0.26734,0.53273 -0.48183,1.23016 -0.56034,1.82199 l -0.0157,0.11863 h 4.08763 4.08763 z"
|
||||
id="path1858"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 396.33573,487.92763 c -0.007,-4.85115 -0.0113,-5.40106 -0.0474,-5.83595 -0.0419,-0.50482 -0.14345,-1.56986 -0.16734,-1.75479 l -0.014,-0.1086 h 0.64122 0.64123 l 0.0468,0.20006 c 0.0992,0.42383 0.17468,1.04371 0.20039,1.64553 0.0218,0.50978 0.0231,0.51241 0.14388,0.29078 0.59123,-1.08475 1.43569,-1.84809 2.4257,-2.19269 1.10461,-0.38449 2.66603,-0.27883 3.70071,0.25042 0.8891,0.45479 1.5357,1.23968 1.9221,2.3332 0.1634,0.46242 0.3086,1.13494 0.37746,1.74821 0.0675,0.60122 0.0799,1.38673 0.0803,5.07001 l 3.9e-4,3.70963 h -0.68487 -0.68486 l -0.009,-4.08688 c -0.009,-4.35633 -0.007,-4.24692 -0.11966,-4.90345 -0.28126,-1.6339 -1.06832,-2.63359 -2.33622,-2.96739 -0.50206,-0.13217 -1.2151,-0.16247 -1.65293,-0.0702 -0.60486,0.12742 -1.12382,0.4215 -1.65451,0.9376 -0.72158,0.70173 -1.17829,1.50047 -1.36742,2.39144 l -0.0532,0.25081 -0.006,4.22406 -0.006,4.22406 h -0.68464 -0.68464 z"
|
||||
id="path1860"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 414.26664,493.62294 c -1.83788,-0.0825 -3.26746,-1.00338 -4.2008,-2.70589 -0.3807,-0.69442 -0.68091,-1.57878 -0.82789,-2.43875 -0.32417,-1.89678 -0.14434,-3.83422 0.49126,-5.29275 0.72289,-1.65881 1.92778,-2.75033 3.42854,-3.10596 0.98187,-0.23267 2.13233,-0.17008 3.02943,0.16481 0.9147,0.34146 1.69547,0.97787 2.32066,1.89159 0.088,0.12864 0.2012,0.30739 0.2515,0.39721 0.0503,0.0898 0.0992,0.16355 0.10861,0.16384 0.009,2.9e-4 0.0171,-1.99033 0.0171,-4.42359 v -4.42412 h 0.68591 0.68591 l 5e-5,8.92254 c 5e-5,8.49944 0.007,9.65931 0.0654,10.32295 l 0.0165,0.18862 h -0.62082 -0.62083 l -0.014,-0.12003 c -0.0166,-0.14264 -0.0605,-1.34328 -0.0674,-1.84624 l -0.005,-0.35439 -0.11162,0.17148 c -0.3375,0.51847 -0.89762,1.15186 -1.29751,1.46724 -0.83405,0.65779 -1.75585,0.99446 -2.82064,1.03019 -0.1006,0.003 -0.3321,-5.6e-4 -0.51443,-0.009 z m 1.3558,-1.32012 c 0.35926,-0.0732 0.62876,-0.16658 0.96486,-0.33421 0.37422,-0.18665 0.66148,-0.3911 0.97956,-0.69717 0.53286,-0.51277 0.9243,-1.15698 1.12209,-1.84669 0.17991,-0.62736 0.20239,-0.94624 0.18986,-2.69281 -0.0111,-1.54266 -0.0188,-1.64719 -0.16426,-2.21467 -0.22385,-0.8734 -0.6468,-1.57951 -1.34393,-2.24368 -0.60411,-0.57555 -1.26473,-0.90366 -2.07518,-1.0307 -0.31902,-0.05 -0.99883,-0.0499 -1.32396,3e-4 -0.46296,0.0714 -0.93142,0.22332 -1.26637,0.41064 -1.12396,0.62855 -1.91578,1.9733 -2.16607,3.67865 -0.15488,1.05527 -0.10279,2.50934 0.12831,3.58196 0.36088,1.67489 1.20542,2.76253 2.49248,3.20992 0.54115,0.18811 0.93885,0.24428 1.66696,0.23545 0.45707,-0.006 0.58998,-0.0151 0.79565,-0.057 z"
|
||||
id="path1862"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 427.79049,493.5892 c -1.40617,-0.21864 -2.4022,-0.95029 -3.05109,-2.24123 -0.40773,-0.81115 -0.64172,-1.72903 -0.79471,-3.1174 -0.0358,-0.3249 -0.0396,-0.93786 -0.0463,-7.36781 l -0.007,-7.01343 h 0.67359 0.6736 l 0.009,6.70477 c 0.01,6.82326 0.0118,7.00237 0.0974,7.84795 0.12779,1.26122 0.41372,2.29884 0.79658,2.89067 0.13134,0.20304 0.44038,0.52728 0.61719,0.64753 0.38213,0.25992 0.95533,0.42813 1.46027,0.42851 0.12463,9e-5 0.1772,0.008 0.1772,0.0282 0,0.0501 -0.11612,1.12498 -0.12726,1.17801 -0.01,0.0465 -0.0234,0.0512 -0.14183,0.0489 -0.0721,-0.001 -0.22363,-0.017 -0.3368,-0.0346 z"
|
||||
id="path1864"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 429.95866,499.23186 c -0.008,-0.0336 -0.0795,-0.29767 -0.15796,-0.58689 -0.0785,-0.28923 -0.14107,-0.52669 -0.13906,-0.52769 0.002,-10e-4 0.1333,-0.0436 0.29174,-0.0947 1.13222,-0.36509 2.10503,-1.1714 2.90787,-2.41017 0.43294,-0.66802 0.86412,-1.56618 1.19488,-2.489 0.0949,-0.26487 0.10313,-0.37893 0.0425,-0.59175 -0.0193,-0.0677 -1.09304,-2.74786 -2.38612,-5.95598 -1.29307,-3.20811 -2.39757,-5.94868 -2.45443,-6.09015 l -0.10338,-0.25722 h 0.71428 0.71428 l 1.18482,2.96656 c 0.65166,1.63161 1.64529,4.11889 2.20807,5.52729 0.56279,1.4084 1.032,2.55843 1.0427,2.55562 0.0107,-0.003 0.94775,-2.4864 2.08233,-5.5191 1.13458,-3.0327 2.06671,-5.51783 2.07139,-5.52251 0.005,-0.005 0.33206,-0.006 0.72749,-0.002 l 0.71899,0.006 -1.49381,3.74964 c -3.35876,8.43093 -3.81479,9.57116 -3.95489,9.88854 -1.3015,2.94837 -2.97284,4.73642 -5.00775,5.35742 l -0.18866,0.0576 z"
|
||||
id="path1866"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 466.4758,493.62314 c -1.45181,-0.0518 -2.74209,-0.444 -3.79537,-1.15362 -0.13832,-0.0932 -0.27004,-0.18378 -0.29271,-0.20131 -0.0388,-0.03 -0.0255,-0.0688 0.22467,-0.65706 0.14623,-0.34386 0.26967,-0.62899 0.27431,-0.63362 0.005,-0.005 0.10416,0.0634 0.22117,0.1512 0.67232,0.50442 1.34476,0.82699 2.15829,1.03532 0.54738,0.14018 0.89369,0.18432 1.55671,0.19842 0.63362,0.0135 0.92514,-0.007 1.3677,-0.0968 1.32858,-0.26911 2.35262,-1.09378 2.72806,-2.19693 0.18459,-0.54239 0.26064,-1.19762 0.2121,-1.82751 -0.0878,-1.1388 -0.41159,-1.84567 -1.11432,-2.4323 -0.61331,-0.51197 -1.2819,-0.86992 -2.3653,-1.26634 -1.26557,-0.46308 -2.05129,-0.86777 -2.82085,-1.4529 -0.28325,-0.21536 -0.82457,-0.75065 -1.01574,-1.00442 -0.65231,-0.86591 -0.952,-1.83625 -0.90894,-2.94301 0.0533,-1.37071 0.52091,-2.37763 1.48963,-3.20783 0.644,-0.55192 1.4352,-0.94552 2.25611,-1.12235 0.46021,-0.0991 0.66417,-0.12051 1.26489,-0.13258 1.07258,-0.0215 1.99133,0.11405 2.81436,0.41535 0.24038,0.088 0.79477,0.35451 0.974,0.46822 l 0.1073,0.0681 -0.2759,0.56664 c -0.15175,0.31165 -0.28315,0.57464 -0.292,0.58442 -0.009,0.01 -0.10274,-0.0303 -0.20865,-0.089 -0.72347,-0.40119 -1.56973,-0.65953 -2.43295,-0.74271 -0.35408,-0.0341 -1.16128,-0.0144 -1.45209,0.0356 -0.86066,0.14772 -1.5369,0.47184 -2.04917,0.98215 -0.42088,0.41927 -0.65249,0.86296 -0.77831,1.491 -0.0586,0.2927 -0.0587,1.06224 -1.6e-4,1.33409 0.19406,0.90065 0.66802,1.58854 1.54586,2.24356 0.50705,0.37834 1.11699,0.69785 2.07057,1.08465 1.7404,0.70595 2.67043,1.24813 3.40775,1.98661 0.43957,0.44027 0.68634,0.84041 0.87774,1.42329 0.21093,0.64235 0.28583,1.22039 0.26905,2.07638 -0.0123,0.62679 -0.0378,0.85377 -0.1452,1.2918 -0.28152,1.14819 -0.97439,2.0959 -2.04295,2.79439 -1.06152,0.69388 -2.2618,0.98509 -3.82966,0.92913 z"
|
||||
id="path1868"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 480.25115,493.62391 c -1.76943,-0.0824 -3.28993,-0.87015 -4.32828,-2.24257 -0.2674,-0.35344 -0.42444,-0.60902 -0.62244,-1.01302 -0.33343,-0.68033 -0.52948,-1.35217 -0.64384,-2.20634 -0.0591,-0.44104 -0.0584,-1.736 0.001,-2.22921 0.1851,-1.53321 0.63888,-2.7246 1.44812,-3.802 0.22897,-0.30485 0.71268,-0.81249 0.97864,-1.02706 0.75983,-0.61301 1.63095,-0.98187 2.64075,-1.11816 0.34389,-0.0464 1.1342,-0.0519 1.47471,-0.0103 1.60517,0.19621 2.76041,0.99424 3.47192,2.39837 0.53771,1.06112 0.81782,2.35304 0.89687,4.13649 l 0.0155,0.34867 h -4.81007 -4.81008 l 0.0166,0.31284 c 0.1063,2.00432 0.90234,3.6062 2.23549,4.49853 0.52294,0.35002 1.20005,0.58817 1.92006,0.67532 0.251,0.0304 1.0811,0.03 1.41814,-6e-4 1.00947,-0.0917 2.10982,-0.3665 3.10524,-0.77539 0.12971,-0.0533 0.23905,-0.0933 0.24296,-0.0888 0.004,0.004 0.0321,0.27911 0.0627,0.61042 l 0.0556,0.60239 -0.1271,0.0563 c -1.16017,0.51427 -2.50008,0.82649 -3.7167,0.86607 -0.2012,0.007 -0.41211,0.0147 -0.4687,0.0182 -0.0566,0.003 -0.26236,-10e-4 -0.45728,-0.0102 z m 3.95517,-8.15413 c -3.8e-4,-0.20384 -0.0628,-0.7459 -0.11648,-1.01171 -0.19744,-0.97746 -0.63711,-1.77073 -1.32584,-2.39213 -0.6974,-0.62923 -1.67691,-0.93541 -2.73725,-0.85562 -0.56747,0.0427 -0.96231,0.14731 -1.43321,0.37975 -0.40065,0.19776 -0.67408,0.39776 -1.02924,0.75282 -0.60261,0.60243 -0.9847,1.22701 -1.25817,2.05663 -0.11691,0.35465 -0.26189,0.97972 -0.26189,1.12908 v 0.0727 h 4.08116 4.08117 l -2.5e-4,-0.13147 z"
|
||||
id="path1870"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 493.46635,493.62321 c -2.04371,-0.0792 -3.6873,-0.97429 -4.73803,-2.58041 -0.19454,-0.29736 -0.48014,-0.86462 -0.60714,-1.20589 -0.36186,-0.97241 -0.53611,-2.1313 -0.49935,-3.32111 0.0624,-2.02032 0.59394,-3.50094 1.69299,-4.71605 0.80338,-0.88822 1.84034,-1.47099 3.05407,-1.71638 1.36434,-0.27584 3.03495,-0.14656 4.22978,0.32732 0.23352,0.0926 0.69485,0.31495 0.8358,0.4028 l 0.0699,0.0435 -0.23456,0.61435 c -0.12902,0.33789 -0.23782,0.6176 -0.24179,0.62157 -0.004,0.004 -0.079,-0.0396 -0.16683,-0.0969 -0.23026,-0.15027 -0.71251,-0.37932 -1.01699,-0.48303 -1.18521,-0.40372 -2.66961,-0.4219 -3.74881,-0.0459 -1.39343,0.48545 -2.47138,1.75971 -2.89099,3.41748 -0.15698,0.62019 -0.2079,1.09369 -0.20616,1.91704 0.002,0.71863 0.0298,1.03925 0.13792,1.56474 0.41693,2.02586 1.72207,3.48002 3.48881,3.88718 0.68218,0.15721 1.7335,0.15662 2.52189,-10e-4 0.63562,-0.12742 1.28939,-0.38719 1.73463,-0.68923 0.10289,-0.0698 0.13852,-0.084 0.15283,-0.0608 0.0491,0.0794 0.45768,1.17263 0.44786,1.19824 -0.019,0.0494 -0.83248,0.43882 -1.12355,0.53787 -0.91263,0.31054 -1.79248,0.42769 -2.89225,0.38508 z"
|
||||
id="path1872"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 503.93791,493.62356 c -2.07746,-0.096 -3.36279,-1.42647 -3.78398,-3.91681 -0.16081,-0.95079 -0.17097,-1.28755 -0.17122,-5.67738 l -2.2e-4,-3.80108 h 0.6849 0.6849 l 0.009,3.99543 c 0.01,4.29399 0.006,4.17411 0.12928,4.93283 0.20902,1.29048 0.65545,2.18782 1.34885,2.71126 0.22059,0.16652 0.57424,0.33239 0.88637,0.41571 0.26636,0.0711 0.27564,0.0719 0.81814,0.0723 0.60452,3.7e-4 0.79632,-0.0264 1.23464,-0.17254 0.98027,-0.32675 1.85898,-1.11843 2.34438,-2.11214 0.22207,-0.45462 0.35237,-0.91771 0.40987,-1.45666 0.0154,-0.14456 0.0237,-1.64625 0.0237,-4.30408 v -4.08207 h 0.68539 0.68539 l 0.007,5.25293 c 0.007,4.8294 0.0106,5.27483 0.0469,5.52463 0.09,0.61989 0.24915,1.3115 0.43807,1.90345 0.0554,0.17357 0.0987,0.31745 0.0962,0.31975 -0.002,0.002 -0.27202,0.0726 -0.59897,0.15629 -0.32695,0.0837 -0.61099,0.15692 -0.63119,0.16279 -0.0837,0.0243 -0.40863,-1.27913 -0.53383,-2.14145 -0.0314,-0.2163 -0.0614,-0.39756 -0.0666,-0.4028 -0.005,-0.005 -0.0427,0.0484 -0.0832,0.11926 -0.19471,0.34032 -0.67239,0.94143 -0.95894,1.20673 -0.73586,0.68127 -1.55316,1.08244 -2.52759,1.24065 -0.29945,0.0486 -0.79251,0.0708 -1.17747,0.053 z"
|
||||
id="path1874"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 513.56348,488.56781 c -3e-5,-5.43156 -0.016,-6.15699 -0.16068,-7.29922 -0.0428,-0.33756 -0.14488,-0.93016 -0.17285,-1.00305 -0.013,-0.0338 0.0394,-0.0372 0.56954,-0.0372 h 0.58382 l 0.0498,0.13147 c 0.0757,0.19985 0.17257,0.60415 0.21498,0.8974 0.0351,0.24236 0.0545,0.49597 0.0991,1.29179 l 0.0167,0.29723 0.0661,-0.17148 c 0.10456,-0.27115 0.39165,-0.82502 0.56014,-1.08066 0.60146,-0.91256 1.36468,-1.43844 2.33457,-1.60862 0.26524,-0.0465 0.87847,-0.0489 1.09746,-0.004 l 0.14861,0.0303 0.006,0.61334 0.006,0.61333 -0.0633,-0.0124 c -0.26434,-0.0519 -0.73294,-0.0272 -1.07303,0.0566 -0.79128,0.19479 -1.48057,0.7114 -2.0224,1.51578 -0.37454,0.556 -0.62369,1.1928 -0.76406,1.95278 -0.12391,0.67092 -0.12487,0.70772 -0.12487,4.77523 v 3.7574 h -0.68591 -0.68591 l -3e-5,-4.71563 z"
|
||||
id="path1876"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0228637;stroke-linejoin:bevel"
|
||||
d="m 525.93275,493.62391 c -1.65452,-0.0715 -3.07447,-0.7456 -4.11474,-1.9535 -0.83427,-0.9687 -1.30115,-2.06319 -1.50149,-3.51986 -0.0581,-0.42251 -0.0589,-1.70686 -10e-4,-2.18348 0.0779,-0.64501 0.16884,-1.09602 0.32509,-1.61225 0.51873,-1.71385 1.6463,-3.14863 3.02432,-3.84831 0.84066,-0.42683 1.82792,-0.61855 2.85487,-0.55438 1.07584,0.0672 1.89386,0.35168 2.60276,0.90508 0.20635,0.16109 0.56637,0.52552 0.72259,0.73147 0.72056,0.94989 1.15786,2.26485 1.32302,3.97828 0.0318,0.32999 0.0691,0.94289 0.0692,1.13746 l 8e-5,0.15433 h -4.80491 -4.80491 l 0.0146,0.30473 c 0.0472,0.98364 0.27777,1.91316 0.66744,2.69041 0.2357,0.47015 0.50073,0.85081 0.83361,1.19731 0.63858,0.66471 1.37965,1.06361 2.30458,1.24049 0.26668,0.051 0.39656,0.0617 0.86587,0.0714 0.33057,0.007 0.67463,7.4e-4 0.85739,-0.0151 1.01661,-0.0883 1.99119,-0.32316 3.01133,-0.72583 0.20569,-0.0812 0.37732,-0.14428 0.3814,-0.1402 0.004,0.004 0.0286,0.2439 0.0545,0.53294 0.0259,0.28904 0.0517,0.55935 0.0574,0.60069 0.01,0.0723 0.005,0.0774 -0.11982,0.13367 -1.12856,0.5072 -2.5105,0.82826 -3.73119,0.86686 -0.20749,0.007 -0.41326,0.0145 -0.45728,0.0175 -0.044,0.003 -0.23949,-0.001 -0.4344,-0.01 z m 3.92525,-8.30586 c -0.0373,-0.73639 -0.22124,-1.47872 -0.50762,-2.04889 -0.28846,-0.57429 -0.77842,-1.14091 -1.28138,-1.48185 -0.64227,-0.43537 -1.49807,-0.64373 -2.37308,-0.57777 -0.56959,0.0429 -0.99582,0.15659 -1.46652,0.39103 -0.3711,0.18484 -0.65462,0.39226 -0.98382,0.71975 -0.65559,0.65217 -1.08507,1.38337 -1.34693,2.29315 -0.0801,0.27833 -0.19568,0.82804 -0.19568,0.93077 v 0.057 h 4.08469 4.08469 z"
|
||||
id="path1878"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#ff7f2a;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.00390625;stroke-linejoin:bevel"
|
||||
d="m 346.33008,493.51692 c -0.19105,-0.0158 -0.34947,-0.0666 -0.4961,-0.15884 -0.0726,-0.0457 -0.13623,-0.0975 -0.20933,-0.17041 -0.1413,-0.14094 -0.23085,-0.27268 -0.30043,-0.44196 -0.11571,-0.28148 -0.132,-0.6355 -0.0434,-0.94224 0.0788,-0.27256 0.25714,-0.54021 0.47695,-0.71562 0.25991,-0.20741 0.58983,-0.27683 0.91602,-0.19276 0.13845,0.0357 0.27496,0.10481 0.40429,0.20471 0.0575,0.0444 0.19,0.1766 0.24059,0.24004 0.1757,0.22033 0.27037,0.44545 0.30308,0.72071 0.007,0.0569 0.007,0.25165 0,0.30859 -0.0388,0.32638 -0.16923,0.58254 -0.41682,0.81856 -0.20563,0.19601 -0.44692,0.30676 -0.71433,0.32786 -0.0469,0.004 -0.12443,0.004 -0.16056,0.001 z"
|
||||
id="path2003"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#ff7f2a;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.00692709;stroke-linejoin:bevel"
|
||||
d="m 450.94689,493.51322 c -0.32583,-0.0199 -0.61424,-0.18585 -0.83574,-0.48077 -0.15606,-0.2078 -0.23824,-0.43252 -0.26022,-0.71159 -0.0326,-0.41326 0.11286,-0.81204 0.4093,-1.12247 0.16176,-0.16939 0.36357,-0.28049 0.58322,-0.32108 0.0889,-0.0164 0.2697,-0.0166 0.35975,-3.6e-4 0.24158,0.0436 0.45295,0.16241 0.64304,0.3615 0.25309,0.26509 0.38491,0.56712 0.40054,0.91773 0.0166,0.37248 -0.10928,0.7059 -0.36849,0.97597 -0.26495,0.27604 -0.57497,0.40288 -0.9314,0.38107 z"
|
||||
id="path2005"
|
||||
transform="scale(0.26458333)" />
|
||||
<path
|
||||
style="fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-width:0.0142009;stroke-linejoin:bevel"
|
||||
d="m 378.70973,477.38924 c -0.30862,-0.0605 -0.54776,-0.23712 -0.67364,-0.49739 -0.10967,-0.22674 -0.12982,-0.3282 -0.12944,-0.65164 2.8e-4,-0.24333 0.004,-0.29156 0.0328,-0.39763 0.10884,-0.40416 0.38122,-0.69509 0.74078,-0.79124 0.11521,-0.0308 0.41144,-0.0341 0.52544,-0.006 0.11426,0.0283 0.29411,0.1165 0.38193,0.18723 0.19583,0.15773 0.3649,0.41716 0.42983,0.65955 0.0444,0.16582 0.0446,0.53239 3.3e-4,0.69584 -0.11118,0.41058 -0.39121,0.69673 -0.7709,0.78775 -0.128,0.0307 -0.41275,0.0378 -0.53716,0.0134 z"
|
||||
id="path2161"
|
||||
transform="scale(0.26458333)" />
|
||||
</g>
|
||||
<g
|
||||
inkscape:groupmode="layer"
|
||||
id="layer3"
|
||||
inkscape:label="heading"
|
||||
transform="translate(-59.014718,-105.5257)">
|
||||
<g
|
||||
aria-label="Infix"
|
||||
id="text1160"
|
||||
style="font-size:25.4px;font-family:'URW Bookman';-inkscape-font-specification:'URW Bookman, Normal';fill:#5c5f5c;stroke-width:1.029"
|
||||
inkscape:label="infix">
|
||||
<path
|
||||
d="m 85.532731,107.6593 0.508,0.0762 c 1.3462,0.1778 1.6256,0.635 1.651,2.794 v 9.9822 c -0.0254,2.159 -0.3048,2.6162 -1.651,2.794 l -0.508,0.0762 v 0.7874 h 6.858 v -0.7874 l -0.508,-0.0762 c -1.3462,-0.1778 -1.6256,-0.635 -1.651,-2.794 v -9.9822 c 0.0254,-2.159 0.3048,-2.6162 1.651,-2.794 l 0.508,-0.0762 v -0.7874 h -6.858 z"
|
||||
id="path2431" />
|
||||
<path
|
||||
d="m 98.588334,111.8503 h -0.8636 c -1.5748,0.3048 -2.413,0.4064 -3.8354,0.508 v 0.762 l 0.6096,0.0508 c 1.3462,0.1524 1.6764,0.5588 1.6764,2.1082 v 5.969 c 0,1.397 -0.4572,2.0066 -1.5748,2.1082 l -0.635,0.0508 v 0.762 h 6.832596 v -0.762 l -0.635,-0.0508 c -1.117596,-0.1016 -1.574796,-0.7112 -1.574796,-2.1082 v -6.2738 c 1.574796,-1.4224 3.073396,-2.1336 4.495796,-2.1336 1.397,0 2.159,0.889 2.159,2.54 v 5.8674 c 0,1.397 -0.4826,2.0066 -1.5748,2.1082 l -0.635,0.0508 v 0.762 h 6.8326 v -0.762 l -0.635,-0.0508 c -1.1176,-0.1016 -1.5748,-0.7112 -1.5748,-2.1082 v -6.2738 c 0,-2.1082 -1.4224,-3.3528 -3.8354,-3.3528 -1.9558,0 -3.429,0.635 -5.232396,2.2352 z"
|
||||
id="path2433" />
|
||||
<path
|
||||
d="m 115.27613,111.8503 v -1.5748 c 0,-1.651 0.0508,-1.9812 0.4064,-2.5908 0.4826,-0.8382 1.4986,-1.3462 2.6416,-1.3462 1.27,0 2.4638,0.762 2.4638,1.6256 0.0254,1.0414 0.0254,1.0414 0.2286,1.397 0.2286,0.4064 0.635,0.635 1.143,0.635 0.762,0 1.27,-0.5334 1.27,-1.27 0,-0.5842 -0.2286,-1.0668 -0.762,-1.6256 -1.016,-1.0414 -2.413,-1.5748 -4.191,-1.5748 -1.9558,0 -3.7338,0.6604 -4.6482,1.7272 -0.6858,0.8128 -0.9652,1.8542 -0.9652,3.6322 v 0.9652 h -2.159 v 0.8382 h 2.159 v 8.5598 c 0,1.397 -0.4572,2.0066 -1.5748,2.1082 l -0.635,0.0508 v 0.762 h 6.8326 v -0.762 l -0.635,-0.0508 c -1.1176,-0.1016 -1.5748,-0.7112 -1.5748,-2.1082 v -8.5598 h 3.3782 c 1.8288,0 2.3368,0.5842 2.3114,2.667 v 5.8928 c 0,1.397 -0.4572,2.0066 -1.5748,2.1082 l -0.635,0.0508 v 0.762 h 6.8326 v -0.762 l -0.635,-0.0508 c -1.1176,-0.1016 -1.5748,-0.7112 -1.5748,-2.1082 v -9.398 z"
|
||||
id="path2435" />
|
||||
<path
|
||||
d="m 134.09755,117.0827 2.2098,-2.3622 c 1.397,-1.3716 2.1082,-1.778 3.81,-2.1082 v -0.762 h -5.3594 v 0.762 c 0.9144,0.1016 1.143,0.2286 1.143,0.6604 0,0.2032 -0.0762,0.4064 -0.254,0.6096 l -2.159,2.4384 -2.0066,-2.4384 c -0.1778,-0.254 -0.3048,-0.4826 -0.3048,-0.635 0,-0.3556 0.3048,-0.5334 1.0414,-0.6096 l 0.254,-0.0254 v -0.762 h -6.2992 v 0.762 c 1.2192,0.1778 1.7018,0.4826 2.5908,1.5494 l 2.9718,3.7338 -3.2258,3.6322 c -1.143,1.2954 -1.8034,1.7018 -3.0226,1.8796 v 0.762 h 5.6896 v -0.762 c -0.889,-0.1524 -1.0922,-0.2032 -1.27,-0.3048 -0.254,-0.1524 -0.4318,-0.4064 -0.4318,-0.6604 0,-0.254 0.1778,-0.5842 0.4572,-0.9144 l 2.54,-2.8448 2.286,3.2004 c 0.1524,0.2286 0.254,0.4826 0.254,0.6858 0,0.4826 -0.3048,0.6604 -1.524,0.8382 v 0.762 h 7.0358 v -0.762 c -1.3716,-0.2286 -1.8288,-0.5334 -2.9464,-1.8796 z"
|
||||
id="path2437" />
|
||||
</g>
|
||||
</g>
|
||||
<g
|
||||
inkscape:label="tux"
|
||||
inkscape:groupmode="layer"
|
||||
id="layer1"
|
||||
style="display:inline"
|
||||
transform="translate(-59.014718,-105.5257)">
|
||||
<path
|
||||
id="rect1698"
|
||||
style="fill:#f9f9f9;stroke:#5c5f5c;stroke-width:1.029;stroke-linejoin:round"
|
||||
inkscape:label="body"
|
||||
d="M 59.529221,107.02922 H 82 V 124 H 59.529221 Z" />
|
||||
<path
|
||||
id="rect184-3"
|
||||
style="fill:#ff7f2a;stroke:#5c5f5c;stroke-linejoin:round"
|
||||
inkscape:label="foot-r"
|
||||
d="m 76,120 h 6 v 4 h -6 z" />
|
||||
<path
|
||||
id="rect184"
|
||||
style="fill:#ff7f2a;stroke:#5c5f5c;stroke-linejoin:round"
|
||||
inkscape:label="foot-l"
|
||||
d="m 59.529221,120 h 6 v 4 h -6 z" />
|
||||
<path
|
||||
id="path11801"
|
||||
style="fill:#ff7f2a"
|
||||
inkscape:label="nose"
|
||||
inkscape:transform-center-y="0.49151511"
|
||||
transform="translate(28.350554,16.321792)"
|
||||
d="m 42.414055,100.66737 -1.702663,-2.949101 h 3.405325 z" />
|
||||
<path
|
||||
id="path6519-5"
|
||||
style="display:inline;fill:#5c5f5c;stroke-width:4.99999"
|
||||
inkscape:label="eye-r"
|
||||
d="m 73.711082,111.02191 a 0.5,0.5 0 0 1 -0.5,0.5 0.5,0.5 0 0 1 -0.5,-0.5 0.5,0.5 0 0 1 0.5,-0.5 0.5,0.5 0 0 1 0.5,0.5 z" />
|
||||
<path
|
||||
id="path6519"
|
||||
style="fill:#5c5f5c;stroke-width:4.99999"
|
||||
inkscape:label="eye-l"
|
||||
d="m 68.81813,111.02191 a 0.5,0.5 0 0 1 -0.5,0.5 0.5,0.5 0 0 1 -0.5,-0.5 0.5,0.5 0 0 1 0.5,-0.5 0.5,0.5 0 0 1 0.5,0.5 z" />
|
||||
</g>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 46 KiB |
|
Before Width: | Height: | Size: 16 KiB After Width: | Height: | Size: 28 KiB |
@@ -0,0 +1,187 @@
|
||||
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
|
||||
<!-- Created with Inkscape (http://www.inkscape.org/) -->
|
||||
|
||||
<svg
|
||||
width="210mm"
|
||||
height="297mm"
|
||||
viewBox="0 0 210 297"
|
||||
version="1.1"
|
||||
id="svg5"
|
||||
inkscape:version="1.2.2 (b0a8486541, 2022-12-01)"
|
||||
sodipodi:docname="logo2.svg"
|
||||
xmlns:inkscape="http://www.inkscape.org/namespaces/inkscape"
|
||||
xmlns:sodipodi="http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd"
|
||||
xmlns="http://www.w3.org/2000/svg"
|
||||
xmlns:svg="http://www.w3.org/2000/svg">
|
||||
<sodipodi:namedview
|
||||
id="namedview7"
|
||||
pagecolor="#ffffff"
|
||||
bordercolor="#000000"
|
||||
borderopacity="0.25"
|
||||
inkscape:showpageshadow="2"
|
||||
inkscape:pageopacity="0.0"
|
||||
inkscape:pagecheckerboard="0"
|
||||
inkscape:deskcolor="#d1d1d1"
|
||||
inkscape:document-units="mm"
|
||||
showgrid="false"
|
||||
inkscape:zoom="5.1481021"
|
||||
inkscape:cx="371.01052"
|
||||
inkscape:cy="472.98985"
|
||||
inkscape:window-width="2560"
|
||||
inkscape:window-height="1385"
|
||||
inkscape:window-x="1920"
|
||||
inkscape:window-y="0"
|
||||
inkscape:window-maximized="1"
|
||||
inkscape:current-layer="layer1" />
|
||||
<defs
|
||||
id="defs2">
|
||||
<rect
|
||||
x="505.95288"
|
||||
y="579.6032"
|
||||
width="127.6438"
|
||||
height="127.94966"
|
||||
id="rect1266" />
|
||||
<rect
|
||||
x="309.92126"
|
||||
y="404.51989"
|
||||
width="483.77954"
|
||||
height="358.02926"
|
||||
id="rect600" />
|
||||
<inkscape:path-effect
|
||||
effect="bspline"
|
||||
id="path-effect5591"
|
||||
is_visible="true"
|
||||
lpeversion="1"
|
||||
weight="33.333333"
|
||||
steps="2"
|
||||
helper_size="0"
|
||||
apply_no_weight="true"
|
||||
apply_with_weight="true"
|
||||
only_selected="false" />
|
||||
</defs>
|
||||
<g
|
||||
inkscape:groupmode="layer"
|
||||
id="layer6"
|
||||
inkscape:label="bg"
|
||||
style="display:none;fill:#ff0000;fill-opacity:1"
|
||||
transform="matrix(1.2831201,0,0,3.2117929,-26.690111,-224.39813)">
|
||||
<rect
|
||||
style="fill:#22272e;fill-opacity:1;stroke:#000000;stroke-width:0;stroke-miterlimit:0;stroke-dasharray:none;stroke-opacity:1"
|
||||
id="rect10264"
|
||||
width="163.66356"
|
||||
height="92.471725"
|
||||
x="20.800945"
|
||||
y="69.866936"
|
||||
inkscape:label="bg" />
|
||||
</g>
|
||||
<g
|
||||
inkscape:groupmode="layer"
|
||||
id="layer5"
|
||||
inkscape:label="tagline"
|
||||
style="display:inline">
|
||||
<text
|
||||
xml:space="preserve"
|
||||
style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:6.77333px;font-family:Laksaman;-inkscape-font-specification:'Laksaman, Normal';font-variant-ligatures:normal;font-variant-caps:normal;font-variant-numeric:normal;font-variant-east-asian:normal;fill:#000000;fill-opacity:1;stroke:#5c5f5c;stroke-width:0;stroke-miterlimit:0;stroke-dasharray:none;stroke-opacity:1"
|
||||
x="85.018883"
|
||||
y="131.54915"
|
||||
id="text9503"
|
||||
inkscape:label="linux-netconf"
|
||||
inkscape:export-filename="logo.png"
|
||||
inkscape:export-xdpi="191.95932"
|
||||
inkscape:export-ydpi="191.95932"><tspan
|
||||
sodipodi:role="line"
|
||||
id="tspan9519"
|
||||
x="85.018883"
|
||||
y="131.54915"><tspan
|
||||
style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:6.77333px;font-family:Laksaman;-inkscape-font-specification:'Laksaman, Normal';font-variant-ligatures:normal;font-variant-caps:normal;font-variant-numeric:normal;font-variant-east-asian:normal;fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-opacity:1"
|
||||
id="tspan11822">Linux</tspan> <tspan
|
||||
style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:6.77333px;font-family:Laksaman;-inkscape-font-specification:'Laksaman, Normal';font-variant-ligatures:normal;font-variant-caps:normal;font-variant-numeric:normal;font-variant-east-asian:normal;fill:#ff7f2a;fill-opacity:1;stroke:#5c5f5c;stroke-opacity:1"
|
||||
id="tspan9929">♥</tspan> <tspan
|
||||
style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:6.77333px;font-family:Laksaman;-inkscape-font-specification:'Laksaman, Normal';font-variant-ligatures:normal;font-variant-caps:normal;font-variant-numeric:normal;font-variant-east-asian:normal;fill:#5c5f5c;fill-opacity:1;stroke:#5c5f5c;stroke-opacity:1"
|
||||
id="tspan11824">NETCONF</tspan></tspan></text>
|
||||
</g>
|
||||
<g
|
||||
inkscape:groupmode="layer"
|
||||
id="layer3"
|
||||
inkscape:label="heading">
|
||||
<text
|
||||
xml:space="preserve"
|
||||
style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:25.4px;font-family:'URW Bookman';-inkscape-font-specification:'URW Bookman, Normal';font-variant-ligatures:normal;font-variant-caps:normal;font-variant-numeric:normal;font-variant-east-asian:normal;fill:#5c5f5c;stroke-width:1.029;fill-opacity:1"
|
||||
x="84.745331"
|
||||
y="124.1693"
|
||||
id="text1160"
|
||||
inkscape:label="infix"
|
||||
inkscape:export-filename="logo-plain.png"
|
||||
inkscape:export-xdpi="191.95932"
|
||||
inkscape:export-ydpi="191.95932"><tspan
|
||||
sodipodi:role="line"
|
||||
id="tspan1272"
|
||||
x="84.745331"
|
||||
y="124.1693">Infix</tspan></text>
|
||||
</g>
|
||||
<g
|
||||
inkscape:label="tux"
|
||||
inkscape:groupmode="layer"
|
||||
id="layer1"
|
||||
style="display:inline">
|
||||
<rect
|
||||
style="fill:#f9f9f9;stroke:#5c5f5c;stroke-width:1.029;stroke-linejoin:round;stroke-dasharray:none;stroke-opacity:1;fill-opacity:1"
|
||||
id="rect1698"
|
||||
width="22.470779"
|
||||
height="16.970779"
|
||||
x="59.529221"
|
||||
y="107.02922"
|
||||
inkscape:label="body"
|
||||
inkscape:export-filename="jack.png"
|
||||
inkscape:export-xdpi="191.95932"
|
||||
inkscape:export-ydpi="191.95932" />
|
||||
<rect
|
||||
style="fill:#ff7f2a;stroke:#5c5f5c;stroke-width:1;stroke-linejoin:round;stroke-dasharray:none;stroke-opacity:1"
|
||||
id="rect184-3"
|
||||
width="6"
|
||||
height="4"
|
||||
x="76"
|
||||
y="120"
|
||||
inkscape:label="foot-r" />
|
||||
<rect
|
||||
style="fill:#ff7f2a;stroke:#5c5f5c;stroke-width:1;stroke-linejoin:round;stroke-dasharray:none;stroke-opacity:1"
|
||||
id="rect184"
|
||||
width="6"
|
||||
height="4"
|
||||
x="59.529221"
|
||||
y="120"
|
||||
inkscape:label="foot-l" />
|
||||
<path
|
||||
sodipodi:type="star"
|
||||
style="fill:#ff7f2a;stroke:none;stroke-width:1;stroke-dasharray:none;stroke-opacity:1"
|
||||
id="path11801"
|
||||
inkscape:flatsided="true"
|
||||
sodipodi:sides="3"
|
||||
sodipodi:cx="42.414055"
|
||||
sodipodi:cy="98.701302"
|
||||
sodipodi:r1="1.9660654"
|
||||
sodipodi:r2="0.9830327"
|
||||
sodipodi:arg1="1.5707963"
|
||||
sodipodi:arg2="2.6179939"
|
||||
inkscape:rounded="0"
|
||||
inkscape:randomized="0"
|
||||
d="m 42.414055,100.66737 -1.702663,-2.949101 3.405325,0 z"
|
||||
inkscape:transform-center-y="0.49151511"
|
||||
transform="translate(28.350554,16.321792)"
|
||||
inkscape:label="nose" />
|
||||
<circle
|
||||
style="display:inline;fill:#5c5f5c;stroke:none;stroke-width:4.99999;stroke-dasharray:none;stroke-opacity:1;fill-opacity:1"
|
||||
id="path6519-5"
|
||||
cx="73.211082"
|
||||
cy="111.02191"
|
||||
r="0.5"
|
||||
inkscape:label="eye-r" />
|
||||
<circle
|
||||
style="fill:#5c5f5c;stroke:none;stroke-width:4.99999;stroke-dasharray:none;stroke-opacity:1;fill-opacity:1"
|
||||
id="path6519"
|
||||
cx="68.31813"
|
||||
cy="111.02191"
|
||||
r="0.5"
|
||||
inkscape:label="eye-l" />
|
||||
</g>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 7.1 KiB |