mirror of
https://github.com/kernelkit/infix.git
synced 2026-07-26 10:43:02 +02:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
10f62f679b | ||
|
|
fa4f7c6532 | ||
|
|
0647541988 | ||
|
|
2602ddc0b8 | ||
|
|
3886b284d3 | ||
|
|
22a9405d1e | ||
|
|
2902dccf11 | ||
|
|
644374bb29 | ||
|
|
a868307637 | ||
|
|
d213861e02 | ||
|
|
3d538d4eca | ||
|
|
06a6dd17f8 | ||
|
|
18659fd45a | ||
|
|
7253be7619 | ||
|
|
910749bab1 | ||
|
|
4f9b3146a1 | ||
|
|
b026abd0bc | ||
|
|
08658a37c4 | ||
|
|
6bbf2d02a8 | ||
|
|
538185c29e | ||
|
|
bd05715ba0 | ||
|
|
6960cd30eb | ||
|
|
c5c21dec83 | ||
|
|
73de6b6d42 | ||
|
|
f698d5f0ee | ||
|
|
7e59406436 | ||
|
|
b8a9dc9743 | ||
|
|
1b5aa16652 | ||
|
|
3f491ea785 | ||
|
|
9bdad9bc8b | ||
|
|
de711b0123 | ||
|
|
b52c462cfa | ||
|
|
f4e75dfecb | ||
|
|
c5fe10aada | ||
|
|
97623b989c | ||
|
|
ed2a776c55 | ||
|
|
ac4fcb61c6 | ||
|
|
41fa664a86 | ||
|
|
4f54cbe975 | ||
|
|
2291e9fd11 | ||
|
|
095c9c331e | ||
|
|
b8fc8b7f62 | ||
|
|
95931c8c0a | ||
|
|
dd788f5611 | ||
|
|
5d99c12089 | ||
|
|
03437fc936 | ||
|
|
56a086ef52 | ||
|
|
3f3fb4eeb4 | ||
|
|
4998e320c5 | ||
|
|
496d56e975 | ||
|
|
82df624ae9 | ||
|
|
5021a1da88 | ||
|
|
df1fc6f2d7 | ||
|
|
2ebcf26ede | ||
|
|
b1a77deadf | ||
|
|
bce1b34873 | ||
|
|
91f31c00c3 | ||
|
|
4b4ffdd14e | ||
|
|
50c83f1be7 | ||
|
|
ee86d12dc2 | ||
|
|
b388e080ad | ||
|
|
6e630018df | ||
|
|
9de5e5b802 | ||
|
|
399d3c365d | ||
|
|
3867abe4da | ||
|
|
90d2ae3868 | ||
|
|
581d1742e5 | ||
|
|
172d7607bb | ||
|
|
62a4b48679 | ||
|
|
3e07c9a960 | ||
|
|
05c197c457 | ||
|
|
77c321daa3 | ||
|
|
3d99af87d6 | ||
|
|
28c2a4a6cc | ||
|
|
1bbd62c021 | ||
|
|
ecc0b63da2 | ||
|
|
347e493542 | ||
|
|
77499790ba | ||
|
|
a960267c40 | ||
|
|
b9f3254ba7 | ||
|
|
266f18bbeb | ||
|
|
b70129f178 | ||
|
|
888f0c4207 | ||
|
|
88fa47c664 | ||
|
|
2ecc2c3602 | ||
|
|
02d8288863 | ||
|
|
d1dde5406e | ||
|
|
fd7b4bbe39 | ||
|
|
c28ea1db19 | ||
|
|
d68dacdc80 | ||
|
|
91f0094048 | ||
|
|
5660f6239d | ||
|
|
58cf5abf0b | ||
|
|
fc32d8a9db | ||
|
|
4b2f140140 | ||
|
|
67cb307f2d | ||
|
|
3811df9ab2 | ||
|
|
53d0995d0c | ||
|
|
7a692fd57d | ||
|
|
73e1c158f5 | ||
|
|
ab3b389f69 | ||
|
|
417d48f015 | ||
|
|
b6aa604cdd | ||
|
|
0dbf99cc82 | ||
|
|
7127caf6b5 | ||
|
|
638862d268 | ||
|
|
2d7dedf79c | ||
|
|
f690cd216c | ||
|
|
6a5bf66a42 | ||
|
|
5707711d84 | ||
|
|
5b3eb23aeb | ||
|
|
51987948ad | ||
|
|
e70559a68d | ||
|
|
83797ca19c | ||
|
|
d82b3e51ea | ||
|
|
e03bd37660 | ||
|
|
ee26cec88a | ||
|
|
88763034ed | ||
|
|
dad1c024aa | ||
|
|
f92d3846db | ||
|
|
ffab761274 | ||
|
|
b4c648229a | ||
|
|
1ca7acda14 | ||
|
|
8f30f88967 | ||
|
|
8eaaaa9d38 | ||
|
|
4e0ad1df1b | ||
|
|
dc3b78e678 | ||
|
|
4d7dde5366 | ||
|
|
3c0679991d | ||
|
|
fe741a92f3 | ||
|
|
f6879e24cc | ||
|
|
7e252ba941 | ||
|
|
46d5e750d7 | ||
|
|
5988249f84 | ||
|
|
7aee2600ba | ||
|
|
6f99a9c2dc | ||
|
|
eee1ce32fa | ||
|
|
d9f2f2c8f9 | ||
|
|
31d0f79a10 | ||
|
|
b290e44318 | ||
|
|
2d806de2cd | ||
|
|
c5db34b491 | ||
|
|
3d816d2525 | ||
|
|
fb394db981 | ||
|
|
da39855cec | ||
|
|
a6b79857db | ||
|
|
f1271f28b9 | ||
|
|
f62900699a | ||
|
|
cf16efe499 | ||
|
|
4260d24143 | ||
|
|
3ef1da1096 | ||
|
|
a90a39e8d8 | ||
|
|
dc5c7732d7 | ||
|
|
5bf9200880 | ||
|
|
f9b155b49f | ||
|
|
9782ac9afa | ||
|
|
773683bfd5 | ||
|
|
3dbb1759eb | ||
|
|
d7895d5c9c | ||
|
|
78499757b0 | ||
|
|
ec2e161649 | ||
|
|
18d8c439bd | ||
|
|
1ca11f1fe7 | ||
|
|
b70d0015a6 | ||
|
|
6a417f2f23 | ||
|
|
f212f0cc16 | ||
|
|
01d07b4942 | ||
|
|
039cb5db74 | ||
|
|
65bce0378e | ||
|
|
91cef6d57b | ||
|
|
f3da31b18c | ||
|
|
af1f173497 | ||
|
|
14fede3e56 | ||
|
|
d3bfbb57b6 | ||
|
|
3203ee925a | ||
|
|
fae1265587 | ||
|
|
97f3db8fdb | ||
|
|
a8b5120871 | ||
|
|
c22339c2cd | ||
|
|
b1830a36d4 | ||
|
|
05510c5001 | ||
|
|
343c465352 | ||
|
|
0cb2987de4 | ||
|
|
7d646c9494 | ||
|
|
395b21c693 | ||
|
|
6ef3ad9020 | ||
|
|
a608c4a36d | ||
|
|
e48da5bb21 | ||
|
|
f389a1f087 | ||
|
|
84521ea9b5 | ||
|
|
4ba43e2ddd | ||
|
|
3606bc05cf |
@@ -0,0 +1,26 @@
|
||||
# Security Policy
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
If you discover a security vulnerability in Infix, please use GitHub's built-in
|
||||
[Report a Vulnerability](https://github.com/kernelkit/infix/security/advisories/new)
|
||||
feature for a private and secure disclosure.
|
||||
|
||||
When reporting, include:
|
||||
|
||||
- A clear description of the vulnerability.
|
||||
- Steps to reproduce the issue.
|
||||
- Potential impact of the vulnerability.
|
||||
|
||||
## Supported Versions
|
||||
|
||||
We provide security updates only for the main branch.
|
||||
|
||||
Individual support contracts are provided by _Wires_. See
|
||||
[Support](https://github.com/kernelkit/infix/blob/main/.github/SUPPORT.md)
|
||||
for more information.
|
||||
|
||||
## Acknowledgments
|
||||
|
||||
We appreciate the efforts of the security community to help improve the security
|
||||
of Infix. Thank you for your responsible disclosure.
|
||||
@@ -35,6 +35,7 @@ jobs:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
clean: true
|
||||
fetch-depth: 0
|
||||
submodules: recursive
|
||||
|
||||
- name: Set Build Variables
|
||||
@@ -124,7 +125,7 @@ jobs:
|
||||
cd output/
|
||||
mv images ${{ steps.vars.outputs.dir }}
|
||||
ln -s ${{ steps.vars.outputs.dir }} images
|
||||
tar chfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||
tar cfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
|
||||
@@ -55,7 +55,7 @@ jobs:
|
||||
sudo apt-get -y update
|
||||
sudo apt-get -y install pkg-config libjansson-dev libev-dev \
|
||||
libcrypt-dev libglib2.0-dev libpcre2-dev \
|
||||
libuev-dev libite-dev
|
||||
libuev-dev
|
||||
|
||||
- name: Build dependencies
|
||||
run: |
|
||||
@@ -65,6 +65,8 @@ jobs:
|
||||
git clone https://github.com/sysrepo/sysrepo.git
|
||||
mkdir sysrepo/build
|
||||
(cd sysrepo/build && cmake .. && make all && sudo make install)
|
||||
git clone https://github.com/troglobit/libite.git
|
||||
(cd libite && ./autogen.sh && ./configure && make && sudo make install)
|
||||
make dep
|
||||
|
||||
- name: Check applications
|
||||
|
||||
@@ -85,10 +85,10 @@ jobs:
|
||||
cd output/
|
||||
mv images ${{ steps.vars.outputs.dir }}
|
||||
ln -s ${{ steps.vars.outputs.dir }} images
|
||||
tar chfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||
tar cfz ${{ steps.vars.outputs.tgz }} ${{ steps.vars.outputs.dir }}
|
||||
|
||||
mv legal-info legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}
|
||||
tar chfz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}.tar.gz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}
|
||||
tar cfz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}.tar.gz legal-info-${{ matrix.target }}-${{ steps.vars.outputs.ver }}
|
||||
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
|
||||
@@ -106,6 +106,16 @@ more information, see: [Infix in Virtual Environments](doc/virtual.md).
|
||||
>
|
||||
> For *customer specific builds* of Infix, see your product repository.
|
||||
|
||||
|
||||
----
|
||||
|
||||
<div align="center">
|
||||
<a href="https://github.com/wires-se"><img src="https://raw.githubusercontent.com/wires-se/.github/main/profile/logo.png" width=300></a>
|
||||
<br />Infix development is sponsored by <a href="https://wires.se">Wires<a>
|
||||
</div>
|
||||
|
||||
----
|
||||
|
||||
[^1]: An immutable operating system is one with read-only file systems,
|
||||
atomic updates, rollbacks, declarative configuration, and workload
|
||||
isolation. All to improve reliability, scalability, and security.
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
#
|
||||
# Automatically generated make config: don't edit
|
||||
# Busybox version: 1.36.1
|
||||
# Tue Oct 22 13:12:02 2024
|
||||
# Sun Feb 9 12:25:37 2025
|
||||
#
|
||||
CONFIG_HAVE_DOT_CONFIG=y
|
||||
|
||||
@@ -17,7 +17,7 @@ CONFIG_SHOW_USAGE=y
|
||||
CONFIG_FEATURE_VERBOSE_USAGE=y
|
||||
# CONFIG_FEATURE_COMPRESS_USAGE is not set
|
||||
CONFIG_LFS=y
|
||||
# CONFIG_PAM is not set
|
||||
CONFIG_PAM=y
|
||||
CONFIG_FEATURE_DEVPTS=y
|
||||
CONFIG_FEATURE_UTMP=y
|
||||
CONFIG_FEATURE_WTMP=y
|
||||
@@ -325,7 +325,7 @@ CONFIG_FEATURE_STAT_FILESYSTEM=y
|
||||
CONFIG_STTY=y
|
||||
CONFIG_SUM=y
|
||||
CONFIG_SYNC=y
|
||||
# CONFIG_FEATURE_SYNC_FANCY is not set
|
||||
CONFIG_FEATURE_SYNC_FANCY=y
|
||||
CONFIG_FSYNC=y
|
||||
# CONFIG_TAC is not set
|
||||
CONFIG_TAIL=y
|
||||
@@ -336,7 +336,7 @@ CONFIG_TEST=y
|
||||
CONFIG_TEST1=y
|
||||
CONFIG_TEST2=y
|
||||
CONFIG_FEATURE_TEST_64=y
|
||||
# CONFIG_TIMEOUT is not set
|
||||
CONFIG_TIMEOUT=y
|
||||
CONFIG_TOUCH=y
|
||||
CONFIG_FEATURE_TOUCH_SUSV3=y
|
||||
CONFIG_TR=y
|
||||
@@ -357,7 +357,7 @@ CONFIG_BASE32=y
|
||||
CONFIG_BASE64=y
|
||||
CONFIG_UUENCODE=y
|
||||
CONFIG_WC=y
|
||||
# CONFIG_FEATURE_WC_LARGE is not set
|
||||
CONFIG_FEATURE_WC_LARGE=y
|
||||
CONFIG_WHO=y
|
||||
CONFIG_W=y
|
||||
CONFIG_USERS=y
|
||||
|
||||
@@ -66,7 +66,7 @@ endchoice
|
||||
|
||||
config QEMU_MACHINE
|
||||
string "Select emulated machine"
|
||||
default "qemu-system-aarch64 -M virt,accel=kvm:tcg -cpu max" if QEMU_aarch64
|
||||
default "qemu-system-aarch64 -M virt,accel=kvm:tcg -cpu max,pauth-impdef=on" if QEMU_aarch64
|
||||
default "qemu-system-x86_64 -M pc,accel=kvm:tcg -cpu max" if QEMU_x86_64
|
||||
help
|
||||
You should not have to change this setting, although you may
|
||||
|
||||
@@ -9,46 +9,20 @@
|
||||
# $3 IP adddress
|
||||
|
||||
PATH="$PATH:/usr/bin:/usr/sbin:/bin:/sbin"
|
||||
NAME="/etc/frr/static.d/$2-zeroconf.conf"
|
||||
NEXT="${NAME}+"
|
||||
|
||||
log()
|
||||
{
|
||||
logger -I $$ -t zeroconf -p user.notice "$*"
|
||||
}
|
||||
|
||||
# Reduce changes needed by comparing with previous route(s)
|
||||
act()
|
||||
{
|
||||
case $1 in
|
||||
add)
|
||||
echo "! Generated by avahi-autoipd" > "$NEXT"
|
||||
echo "ip route 0.0.0.0/0 $2 254" >> "$NEXT"
|
||||
cmp -s "$NAME" "$NEXT" && return
|
||||
mv "$NEXT" "$NAME"
|
||||
;;
|
||||
del)
|
||||
[ -f "$NAME" ] || return
|
||||
rm "$NAME"
|
||||
;;
|
||||
*)
|
||||
return
|
||||
;;
|
||||
esac
|
||||
|
||||
initctl -nbq restart staticd
|
||||
}
|
||||
|
||||
case "$1" in
|
||||
BIND)
|
||||
ip addr flush dev "$2" proto random
|
||||
ip addr add "$3"/16 brd 169.254.255.255 scope link dev "$2" proto random
|
||||
act add "$2"
|
||||
log "set ipv4ll $3 on iface $2"
|
||||
;;
|
||||
|
||||
CONFLICT|UNBIND|STOP)
|
||||
act del "$2"
|
||||
ip addr flush dev "$2" proto random
|
||||
log "clr ipv4ll on iface $2"
|
||||
;;
|
||||
|
||||
@@ -1,4 +1,7 @@
|
||||
task name:container-%i :setup \
|
||||
[2345] container -n %i setup -- Setup container %i
|
||||
sysv <!usr/container:%i> :%i pid:!/run/container:%i.pid log:prio:local1,tag:%i kill:10 \
|
||||
[2345] container -n %i -- container %i
|
||||
# Start a container instance (%i) and redirect logs to /log/container
|
||||
# Give podman enough time to properly shut down the container. Every
|
||||
# time we start a container we run the setup stage, disable the Finit
|
||||
# timeout to allow the setup stage to run to completion.
|
||||
sysv log:prio:local1,tag:%i kill:10 pid:!/run/container:%i.pid \
|
||||
pre:0,/usr/sbin/container cleanup:0,/usr/sbin/container \
|
||||
[2345] <!> :%i container -n %i -- container %i
|
||||
|
||||
@@ -1 +1 @@
|
||||
service [2345] <!> ttyd -i lo -p 8001 login -- Web terminal daemon (ttyd)
|
||||
service [2345] <!> ttyd -i lo -W -p 8001 login -- Web terminal daemon (ttyd)
|
||||
|
||||
@@ -2,10 +2,15 @@
|
||||
net.ipv6.route.max_size=131072
|
||||
net.ipv6.conf.all.ignore_routes_with_linkdown=1
|
||||
|
||||
# IP Routing
|
||||
net.ipv6.conf.all.forwarding=1
|
||||
# IP Routing is disabled by default, enabled globally, and per
|
||||
# interface, for each interface in confd. See also accept_ra.
|
||||
net.ipv6.conf.all.forwarding=0
|
||||
net.ipv6.conf.default.forwarding=0
|
||||
|
||||
# Accept router advertisements even when forwarding is enabled
|
||||
net.ipv6.conf.all.accept_ra=2
|
||||
net.ipv6.conf.default.accept_ra=2
|
||||
|
||||
# IPv6 SLAAC
|
||||
net.ipv6.conf.all.autoconf=0
|
||||
net.ipv6.conf.default.autoconf=0
|
||||
|
||||
@@ -21,7 +21,11 @@ dir()
|
||||
if [ -d "$1" ]; then
|
||||
dir "$1"
|
||||
else
|
||||
dir "$HOME"
|
||||
if [ "$USER" = "root" ]; then
|
||||
dir "$HOME"
|
||||
else
|
||||
dir "/home/$USER"
|
||||
fi
|
||||
dir "/cfg"
|
||||
dir "/log"
|
||||
fi
|
||||
|
||||
@@ -39,8 +39,10 @@ fi
|
||||
# init scripts to prevent select services from starting.
|
||||
initctl -nbq cond set led
|
||||
|
||||
note "Calling runparts $PRODUCT_INIT/S[0-9]+.* start"
|
||||
/usr/libexec/finit/runparts -bsp "$PRODUCT_INIT"
|
||||
if [ -d "$PRODUCT_INIT" ]; then
|
||||
note "Calling runparts $PRODUCT_INIT/S[0-9]+.* start"
|
||||
/usr/libexec/finit/runparts -bsp "$PRODUCT_INIT"
|
||||
fi
|
||||
|
||||
# Product specific init done.
|
||||
initctl -nbq cond set product
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
#!/bin/sh
|
||||
# Initialize speed/duplex of virtio interfaces
|
||||
# For virtual test systems (lacp tests)
|
||||
|
||||
ifaces=$(ip -d -json link show | jq -r '.[] | select(.parentbus == "virtio") | .ifname')
|
||||
for iface in $ifaces; do
|
||||
ethtool -s "$iface" speed 1000 duplex full
|
||||
done
|
||||
@@ -1,4 +1,4 @@
|
||||
#!/bin/sh
|
||||
#!/bin/bash
|
||||
# This script can be used to start, stop, create, and delete containers.
|
||||
# It is what confd use, with the Finit container@.conf template, to set
|
||||
# up, run, and delete containers.
|
||||
@@ -9,6 +9,7 @@
|
||||
DOWNLOADS=/var/lib/containers/oci
|
||||
BUILTIN=/lib/oci
|
||||
TMPDIR=/var/tmp
|
||||
container=$0
|
||||
checksum=""
|
||||
extracted=
|
||||
timeout=30
|
||||
@@ -38,6 +39,11 @@ err()
|
||||
[ "$rc" -eq 0 ] || exit "$rc"
|
||||
}
|
||||
|
||||
pidfn()
|
||||
{
|
||||
echo "/run/containers/${1}.pid"
|
||||
}
|
||||
|
||||
check()
|
||||
{
|
||||
file=$1
|
||||
@@ -109,33 +115,34 @@ EOF
|
||||
# If there are more index files, this function does not handle them.
|
||||
unpack_archive()
|
||||
{
|
||||
image=$1
|
||||
name=$2
|
||||
uri=$1
|
||||
tag=$2
|
||||
img=$(basename "$uri")
|
||||
|
||||
# Supported transports for load and create
|
||||
case "$image" in
|
||||
case "$uri" in
|
||||
oci:*) # Unpacked OCI image
|
||||
file=${image#oci:}
|
||||
file=${uri#oci:}
|
||||
;;
|
||||
oci-archive:*) # Packed OCI image, .tar or .tar.gz format
|
||||
file=${image#oci-archive:}
|
||||
file=${uri#oci-archive:}
|
||||
;;
|
||||
ftp://* | http://* | https://*)
|
||||
if ! file=$(fetch "$image"); then
|
||||
if ! file=$(fetch "$uri"); then
|
||||
return 1
|
||||
fi
|
||||
;;
|
||||
*) # docker://*, docker-archive:*, or URL
|
||||
if podman image exists "$image"; then
|
||||
echo "$image"
|
||||
if podman image exists "$img"; then
|
||||
echo "$img"
|
||||
return 0
|
||||
fi
|
||||
# XXX: use --retry=0 with Podman 5.0 or later.
|
||||
if ! id=$(podman pull --quiet "$image"); then
|
||||
log "Failed pulling $image"
|
||||
if ! id=$(podman pull --quiet "$uri"); then
|
||||
log "Failed pulling $uri"
|
||||
return 1
|
||||
fi
|
||||
# Echo image name to caller
|
||||
# Echo image tag to caller
|
||||
podman images --filter id="$id" --format "{{.Repository}}:{{.Tag}}"
|
||||
return 0
|
||||
;;
|
||||
@@ -147,7 +154,7 @@ unpack_archive()
|
||||
elif [ -e "$BUILTIN/$file" ]; then
|
||||
file="$BUILTIN/$file"
|
||||
else
|
||||
err 1 "cannot find OCI archive $file in search path."
|
||||
err 1 "cannot find OCI archive $file in URI $uri"
|
||||
fi
|
||||
fi
|
||||
|
||||
@@ -171,8 +178,8 @@ unpack_archive()
|
||||
|
||||
dir=$(dirname "$index")
|
||||
if echo "$dir" | grep -q ":"; then
|
||||
if [ -z "$name" ]; then
|
||||
name="$dir"
|
||||
if [ -z "$tag" ]; then
|
||||
tag="$dir"
|
||||
fi
|
||||
sanitized_dir=$(echo "$dir" | cut -d':' -f1)
|
||||
mv "$dir" "$sanitized_dir" || err 1 "failed renaming $dir to $sanitized_dir"
|
||||
@@ -188,21 +195,21 @@ unpack_archive()
|
||||
rm -rf "$dir"
|
||||
fi
|
||||
|
||||
# Rename image from podman default $dir:latest
|
||||
if [ -n "$name" ]; then
|
||||
podman tag "$dir" "$name" >/dev/null
|
||||
podman rmi "$dir" >/dev/null
|
||||
# Retag image from podman default $dir:latest
|
||||
if [ -n "$tag" ]; then
|
||||
podman tag "$dir" "$tag" >/dev/null
|
||||
podman rmi "$dir" >/dev/null
|
||||
else
|
||||
name=$dir
|
||||
tag=$dir
|
||||
fi
|
||||
|
||||
echo "$name"
|
||||
echo "$tag"
|
||||
}
|
||||
|
||||
running()
|
||||
{
|
||||
run=$(podman inspect "$1" 2>/dev/null |jq .[].State.Running)
|
||||
[ "$run" = "true" ] && return 0
|
||||
status=$(podman inspect -f '{{.State.Status}}' "$1" 2>/dev/null)
|
||||
[ "$status" = "running" ] && return 0
|
||||
return 1
|
||||
}
|
||||
|
||||
@@ -233,7 +240,7 @@ create()
|
||||
args="$args --read-only --replace --quiet --cgroup-parent=containers $caps"
|
||||
args="$args --restart=$restart --systemd=false --tz=local $privileged"
|
||||
args="$args $vol $mount $hostname $entrypoint $env $port $logging"
|
||||
pidfn=/run/container:${name}.pid
|
||||
pidfile=/run/container:${name}.pid
|
||||
|
||||
[ -n "$quiet" ] || log "---------------------------------------"
|
||||
[ -n "$quiet" ] || log "Got name: $name image: $image"
|
||||
@@ -256,8 +263,8 @@ create()
|
||||
fi
|
||||
|
||||
# shellcheck disable=SC2048
|
||||
log "podman create --name $name --conmon-pidfile=$pidfn $args $image $*"
|
||||
if podman create --name "$name" --conmon-pidfile="$pidfn" $args "$image" $*; then
|
||||
log "podman create --name $name --conmon-pidfile=$pidfile $args $image $*"
|
||||
if podman create --name "$name" --conmon-pidfile="$pidfile" $args "$image" $*; then
|
||||
[ -n "$quiet" ] || log "Successfully created container $name from $image"
|
||||
[ -n "$manual" ] || start "$name"
|
||||
|
||||
@@ -272,7 +279,6 @@ create()
|
||||
delete()
|
||||
{
|
||||
name=$1
|
||||
image=$2
|
||||
|
||||
if [ -z "$name" ]; then
|
||||
echo "Usage:"
|
||||
@@ -281,9 +287,11 @@ delete()
|
||||
fi
|
||||
|
||||
# Should already be stopped, but if not ...
|
||||
container stop "$name"
|
||||
log "$name: should already be stopped, double checking ..."
|
||||
container stop "$name" >/dev/null
|
||||
|
||||
while running "$name"; do
|
||||
log "$name: still running, waiting for it to stop ..."
|
||||
_=$((timeout -= 1))
|
||||
if [ $timeout -le 0 ]; then
|
||||
err 1 "timed out waiting for container $1 to stop before deleting it."
|
||||
@@ -291,6 +299,7 @@ delete()
|
||||
sleep 1
|
||||
done
|
||||
|
||||
log "$name: calling podman rm -vif ..."
|
||||
podman rm -vif "$name" >/dev/null 2>&1
|
||||
[ -n "$quiet" ] || log "Container $name has been removed."
|
||||
}
|
||||
@@ -315,7 +324,7 @@ start()
|
||||
return
|
||||
fi
|
||||
|
||||
initctl -bq cond set "container:$name"
|
||||
initctl start container:$name
|
||||
# Real work is done by wrap() courtesy of finit sysv emulation
|
||||
}
|
||||
|
||||
@@ -328,7 +337,7 @@ stop()
|
||||
return
|
||||
fi
|
||||
|
||||
initctl -bq cond clr "container:$name"
|
||||
initctl stop container:$name
|
||||
# Real work is done by wrap() courtesy of finit sysv emulation
|
||||
}
|
||||
|
||||
@@ -336,8 +345,27 @@ wrap()
|
||||
{
|
||||
name=$1
|
||||
cmd=$2
|
||||
pidfile=$(pidfn "$name")
|
||||
|
||||
podman "$cmd" "$name"
|
||||
# Containers have three phases: setup, running, and teardown.
|
||||
|
||||
# The setup phase may run forever in the background trying to fetch
|
||||
# the image. It saves its PID in /run/containers/${name}.pid
|
||||
if [ "$cmd" = "stop" ] && [ -f "$pidfile" ]; then
|
||||
pid=$(cat "$pidfile")
|
||||
|
||||
# Check if setup is still running ...
|
||||
if kill -0 "$pid" 2>/dev/null; then
|
||||
kill "$pid"
|
||||
wait "$pid" 2>/dev/null
|
||||
fi
|
||||
|
||||
rm -f "$pidfile"
|
||||
return 0
|
||||
fi
|
||||
|
||||
# Skip "echo $name" from podman start in log
|
||||
podman "$cmd" "$name" >/dev/null
|
||||
}
|
||||
|
||||
# Removes network $1 from all containers
|
||||
@@ -370,7 +398,14 @@ netrestart()
|
||||
|
||||
cleanup()
|
||||
{
|
||||
pidfile=$(pidfn "$name")
|
||||
|
||||
log "Received signal, exiting."
|
||||
if [ -n "$name" ] && [ -f "$pidfile" ]; then
|
||||
log "$name: in setup phase, removing $pidfile ..."
|
||||
rm -f "$pidfile"
|
||||
fi
|
||||
|
||||
exit 1
|
||||
}
|
||||
|
||||
@@ -426,11 +461,12 @@ commands:
|
||||
run NAME [CMD] Run a container interactively, with an optional command
|
||||
save IMAGE FILE Save a container image to an OCI tarball FILE[.tar.gz]
|
||||
setup NAME Create and set up container as a Finit task
|
||||
shell Start a shell inside a container
|
||||
shell [CMD] Start a shell, or run CMD, inside a container
|
||||
show [image | volume] Show containers, images, or volumes
|
||||
stat Show continuous stats about containers (Ctrl-C aborts)
|
||||
start [NAME] Start a container, see -n
|
||||
stop [NAME] Stop a container, see -n
|
||||
upgrade NAME Upgrade a running container (stop, pull, restart)
|
||||
volume [prune] Prune unused volumes
|
||||
EOF
|
||||
}
|
||||
@@ -568,7 +604,7 @@ if [ -n "$cmd" ]; then
|
||||
shift
|
||||
fi
|
||||
|
||||
trap cleanup INT TERM
|
||||
trap cleanup INT HUP TERM
|
||||
|
||||
case $cmd in
|
||||
# Does not work atm., cannot attach to TTY because
|
||||
@@ -582,19 +618,24 @@ case $cmd in
|
||||
;;
|
||||
delete)
|
||||
cmd=$1
|
||||
name=$2
|
||||
[ -n "$name" ] || name=$2
|
||||
if [ "$cmd" = "network" ] && [ -n "$name" ]; then
|
||||
netwrm "$name"
|
||||
else
|
||||
delete "$@"
|
||||
[ -n "$name" ] || name=$1
|
||||
delete "$name"
|
||||
fi
|
||||
;;
|
||||
exec)
|
||||
podman exec -it "$@"
|
||||
if [ -z "$name" ]; then
|
||||
name="$1"
|
||||
shift
|
||||
fi
|
||||
podman exec -i "$name" "$@"
|
||||
;;
|
||||
flush)
|
||||
echo "Cleaning up any lingering containers";
|
||||
podman rm -av
|
||||
podman rm -av $force
|
||||
;;
|
||||
find)
|
||||
cmd=$1
|
||||
@@ -699,18 +740,34 @@ case $cmd in
|
||||
[ -n "$name" ] || err 1 "setup: missing container name."
|
||||
script=/run/containers/${name}.sh
|
||||
[ -x "$script" ] || err 1 "setup: $script does not exist or is not executable."
|
||||
|
||||
# Save our PID in case we get stuck here and someone wants to
|
||||
# stop us, e.g., due to reconfiguration or reboot.
|
||||
pidfile=$(pidfn "${name}")
|
||||
echo $$ > "$pidfile"
|
||||
|
||||
while ! "$script"; do
|
||||
# Wait for address/route changes, or retry every 60 secods
|
||||
# shellcheck disable=2162,3045
|
||||
ip monitor address route | while read -t 60 _; do break; done
|
||||
log "${name}: setup failed, waiting for network changes ..."
|
||||
read -t 60 _ < <(ip monitor address route)
|
||||
|
||||
# On IP address/route changes, wait a few seconds more to ensure
|
||||
# the system has ample time to react and set things up for us.
|
||||
log "${name}: retrying ..."
|
||||
sleep 2
|
||||
done
|
||||
|
||||
rm -f "$pidfile"
|
||||
;;
|
||||
shell)
|
||||
podman exec -it "$1" sh -l
|
||||
if [ -z "$name" ]; then
|
||||
name="$1"
|
||||
shift
|
||||
fi
|
||||
if [ $# -gt 0 ]; then
|
||||
podman exec -i "$name" sh -c "$*"
|
||||
else
|
||||
podman exec -it "$name" sh -l
|
||||
fi
|
||||
;;
|
||||
show)
|
||||
cmd=$1
|
||||
@@ -803,15 +860,15 @@ case $cmd in
|
||||
|
||||
# Likely an OCI archive, or local directory, assume user has updated image.
|
||||
if echo "$img" | grep -Eq '^localhost/'; then
|
||||
file=$(awk '{s=$NF} END{print s}' "$script")
|
||||
echo "Upgrading container ${1} with local archive: $file ..."
|
||||
file=$(awk '/^# meta-image:/ {print $3}' "$script")
|
||||
echo ">> Upgrading container $1 using $file ..."
|
||||
else
|
||||
printf ">> Stopping ... "
|
||||
podman stop "$1"
|
||||
printf ">> "
|
||||
podman pull "$img" || (echo "Failed fetching $img, check your network (settings)."; exit 1)
|
||||
echo ">> Starting $1 ..."
|
||||
fi
|
||||
echo ">> Starting $1 ..."
|
||||
if ! "$script"; then
|
||||
echo ">> Failed recreating container $1"
|
||||
exit 1
|
||||
@@ -831,6 +888,22 @@ case $cmd in
|
||||
esac
|
||||
;;
|
||||
*)
|
||||
if [ -n "$SERVICE_SCRIPT_TYPE" ] && [ -n "$SERVICE_ID" ]; then
|
||||
case "$SERVICE_SCRIPT_TYPE" in
|
||||
pre)
|
||||
# Called as pre-script from Finit service
|
||||
exec $container -q -n "$SERVICE_ID" setup
|
||||
;;
|
||||
cleanup)
|
||||
# Called as cleanup-script from Finit service
|
||||
log "Calling $container -n $SERVICE_ID delete"
|
||||
exec $container -q -n "$SERVICE_ID" delete
|
||||
;;
|
||||
*)
|
||||
false
|
||||
;;
|
||||
esac
|
||||
fi
|
||||
usage
|
||||
exit 1
|
||||
;;
|
||||
|
||||
+1
-1
Submodule buildroot updated: 92e256798b...06a983c964
@@ -13,8 +13,8 @@ BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||
BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_ROOTFS_MERGED_USR=y
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_SYSTEM_BIN_SH_BASH=y
|
||||
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
@@ -27,7 +27,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.11"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.21"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -55,8 +55,8 @@ BR2_PACKAGE_PYTHON_GUNICORN=y
|
||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||
BR2_PACKAGE_LIBSSH2=y
|
||||
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
||||
BR2_PACKAGE_LIBXCRYPT=y
|
||||
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
||||
BR2_PACKAGE_LIBINPUT=y
|
||||
BR2_PACKAGE_LIBCURL_CURL=y
|
||||
BR2_PACKAGE_NETOPEER2_CLI=y
|
||||
BR2_PACKAGE_NSS_MDNS=y
|
||||
@@ -119,6 +119,7 @@ BR2_PACKAGE_HOST_E2FSPROGS=y
|
||||
BR2_PACKAGE_HOST_ENVIRONMENT_SETUP=y
|
||||
BR2_PACKAGE_HOST_GENEXT2FS=y
|
||||
BR2_PACKAGE_HOST_GENIMAGE=y
|
||||
BR2_PACKAGE_HOST_GO_BIN=y
|
||||
BR2_PACKAGE_HOST_RAUC=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS_FIT_SUPPORT=y
|
||||
@@ -161,11 +162,10 @@ BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_LIBINPUT=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
DISK_IMAGE_BOOT_BIN=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
DISK_IMAGE_BOOT_BIN=y
|
||||
GNS3_APPLIANCE_RAM=512
|
||||
GNS3_APPLIANCE_IFNUM=10
|
||||
|
||||
@@ -27,7 +27,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.11"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.21"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
|
||||
@@ -12,8 +12,8 @@ BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
|
||||
BR2_INIT_FINIT=y
|
||||
BR2_ROOTFS_DEVICE_CREATION_DYNAMIC_EUDEV=y
|
||||
BR2_ROOTFS_DEVICE_TABLE="system/device_table.txt ${BR2_EXTERNAL_INFIX_PATH}/board/common/xattrs"
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_ROOTFS_MERGED_USR=y
|
||||
# BR2_TARGET_ENABLE_ROOT_LOGIN is not set
|
||||
BR2_SYSTEM_BIN_SH_BASH=y
|
||||
BR2_TARGET_GENERIC_GETTY_PORT="@console"
|
||||
BR2_TARGET_GENERIC_GETTY_TERM="xterm"
|
||||
@@ -26,7 +26,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INF
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.11"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.21"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
@@ -54,10 +54,8 @@ BR2_PACKAGE_PYTHON_GUNICORN=y
|
||||
BR2_PACKAGE_LIBSSH_OPENSSL=y
|
||||
BR2_PACKAGE_LIBSSH2=y
|
||||
BR2_PACKAGE_LIBSSH2_OPENSSL=y
|
||||
BR2_PACKAGE_LIBXCRYPT=y
|
||||
BR2_PACKAGE_LIBOPENSSL_BIN=y
|
||||
BR2_PACKAGE_LIBCURL_CURL=y
|
||||
BR2_PACKAGE_LIBMNL=y
|
||||
BR2_PACKAGE_NETOPEER2_CLI=y
|
||||
BR2_PACKAGE_NSS_MDNS=y
|
||||
BR2_PACKAGE_LINUX_PAM=y
|
||||
@@ -126,6 +124,7 @@ BR2_PACKAGE_HOST_E2FSPROGS=y
|
||||
BR2_PACKAGE_HOST_ENVIRONMENT_SETUP=y
|
||||
BR2_PACKAGE_HOST_GENEXT2FS=y
|
||||
BR2_PACKAGE_HOST_GENIMAGE=y
|
||||
BR2_PACKAGE_HOST_GO_BIN=y
|
||||
BR2_PACKAGE_HOST_MTOOLS=y
|
||||
BR2_PACKAGE_HOST_RAUC=y
|
||||
BR2_PACKAGE_HOST_UBOOT_TOOLS=y
|
||||
@@ -165,8 +164,8 @@ BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
|
||||
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
|
||||
BR2_PACKAGE_TETRIS=y
|
||||
BR2_PACKAGE_ROUSETTE=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
|
||||
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
|
||||
TRUSTED_KEYS=y
|
||||
TRUSTED_KEYS_DEVELOPMENT=y
|
||||
GNS3_APPLIANCE_RAM=512
|
||||
|
||||
@@ -26,7 +26,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INF
|
||||
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
|
||||
BR2_LINUX_KERNEL=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.11"
|
||||
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.21"
|
||||
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
|
||||
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
|
||||
BR2_LINUX_KERNEL_INSTALL_TARGET=y
|
||||
|
||||
+61
-1
@@ -4,6 +4,64 @@ Change Log
|
||||
All notable changes to the project are documented in this file.
|
||||
|
||||
|
||||
[v25.03.0][] - 2025-03-31
|
||||
-------------------------
|
||||
|
||||
> [!IMPORTANT]
|
||||
> This release is the first with the new Buildroot 2025.02 (LTS)
|
||||
|
||||
### Changes
|
||||
- Upgrade Linux kernel to 6.12.21 (LTS)
|
||||
- Upgrade Buildroot to 2025.02.0 (LTS)
|
||||
|
||||
### Fixes
|
||||
- Fix #964: YANG schema warning in syslog: missing 'monitor' node for lag
|
||||
- Fix #980: the system fails to reboot when a container is (stuck), for
|
||||
whatever reason, in its 'setup' state
|
||||
- Fix #990: web console, ttyd service, stopped working after upgrade to
|
||||
Buildroot 2025.02, caused by new (missing) option `--writable`
|
||||
- Fix TCAM memory corruption in `mvpp2` Ethernet controller
|
||||
- Fix annoying (but harmless) usage message from the logger tool when
|
||||
`startup-config` fails to load and the system reverts to failure mode
|
||||
- Fix harmless log warning for product specific init when no product
|
||||
specific init scripts are found
|
||||
- Backport fixes for sysklogd, affecting hostname filtering and periods
|
||||
in TAG names, pending official backport in Buildroot
|
||||
|
||||
|
||||
[v25.02.0][] - 2025-03-04
|
||||
-------------------------
|
||||
|
||||
### Changes
|
||||
- Upgrade Linux kernel to 6.12.18 (LTS)
|
||||
- Upgrade Buildroot to 2024.02.11 (LTS)
|
||||
- Add support for link aggregation (lag), static (balance-xor) and LACP
|
||||
- Add support for the [i.MX 8M Plus EVK][EVK]
|
||||
- YANG type change for SSH private/public keys, from ietf-crypto-types
|
||||
to infix-crypto-types
|
||||
- Disable global IPv6 forwarding by default, enable by per-interface
|
||||
setting. Note, route advertisements are always accepted. Issue #785
|
||||
- Drop automatic default route (interface route) for IPv4 autoconf, not
|
||||
necessary and causes more confusion than good. Issue #923
|
||||
- Update scripting with new RESTCONF examples
|
||||
|
||||
### Fixes
|
||||
- Fix #896: `/etc/resolv.conf` not properly generated when system runs
|
||||
in fail secure mode (failing to load `startup-config`)
|
||||
- Fix #902: containers "linger" in the system (state 'exited') after
|
||||
having removed them from the configuration
|
||||
- Fix #930: container configuration changes does not apply at runtime
|
||||
only when saved to `startup-config` and system is rebooted
|
||||
- Fix #936: DHCP server reconfiguration does not always take effect.
|
||||
- Fix #956: CLI `copy` command complains it cannot change owner when
|
||||
copying `factory-config` to `running-config`. Bogus error, the
|
||||
latter is not really a file
|
||||
- Fix #977: "Operation not permitted" when saving `running-config` to
|
||||
`startup-config` (harmless warning but annoying and concerning)
|
||||
|
||||
[EVK]: https://www.nxp.com/design/design-center/development-boards-and-designs/8MPLUSLPD4-EVK
|
||||
|
||||
|
||||
[v25.01.0][] - 2025-01-31
|
||||
-------------------------
|
||||
|
||||
@@ -1471,7 +1529,9 @@ Supported YANG models in addition to those used by sysrepo and netopeer:
|
||||
- N/A
|
||||
|
||||
[buildroot]: https://buildroot.org/
|
||||
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v25.01.0...HEAD
|
||||
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v25.03.0...HEAD
|
||||
[v25.03.0]: https://github.com/kernelkit/infix/compare/v25.02.0...v25.03.0
|
||||
[v25.02.0]: https://github.com/kernelkit/infix/compare/v25.01.0...v25.02.0
|
||||
[v25.01.0]: https://github.com/kernelkit/infix/compare/v24.11.0...v25.01.0
|
||||
[v24.11.1]: https://github.com/kernelkit/infix/compare/v24.11.0...v24.11.1
|
||||
[v24.11.0]: https://github.com/kernelkit/infix/compare/v24.10.0...v24.11.0
|
||||
|
||||
+9
-5
@@ -1,13 +1,16 @@
|
||||
<img align="right" src="logo.png" alt="Infix - Linux <3 NETCONF" width=480 border=10>
|
||||
|
||||
Welcome to Infix, your friendly Network Operating System! On these
|
||||
pages you can find both user and developer documentation.
|
||||
|
||||
> Topics on configuring the system include CLI examples, every setting
|
||||
> is also possible to perform using NETCONF. In fact, the Infix test
|
||||
> system solely relies on NETCONF for configuring network topologies.
|
||||
Most topics on configuring the system include CLI examples, but every
|
||||
setting, as well as status read-back from the operational datastore, is
|
||||
also possible to perform using NETCONF or RESTCONF. In fact, the Infix
|
||||
regression test system solely relies on NETCONF and RESTCONF.
|
||||
|
||||
The CLI documentation is also available from inside the CLI itself using
|
||||
the `help` command.
|
||||
> [!TIP]
|
||||
> The CLI documentation is also available from inside the CLI itself
|
||||
> using the `help` command in admin-exec mode.
|
||||
|
||||
- **CLI Topics**
|
||||
- [Introduction to the CLI](cli/introduction.md)
|
||||
@@ -18,6 +21,7 @@ the `help` command.
|
||||
- [Introduction](introduction.md)
|
||||
- [System Configuration](system.md)
|
||||
- [Network Configuration](networking.md)
|
||||
- [DHCP Server](dhcp.md)
|
||||
- [Syslog Support](syslog.md)
|
||||
- **Infix In-Depth**
|
||||
- [Boot Procedure](boot.md)
|
||||
|
||||
+40
-31
@@ -31,9 +31,9 @@ Infix comes with native support for Docker containers using [podman][].
|
||||
The [YANG model][1] describes the current level of support, complete
|
||||
enough to run both system and application containers.
|
||||
|
||||
Key design features, like using Linux switchdev, allow users to assign
|
||||
switch ports directly to containers, not just bridged VETH pairs, this
|
||||
is a rare and in many cases *unique* feature of Infix.
|
||||
Key design features of Infix, like using Linux switchdev, allow users to
|
||||
assign switch ports directly to containers, not just bridged VETH pairs.
|
||||
This is a rare and in many cases *unique* feature of Infix.
|
||||
|
||||
All network specific settings are done using the IETF interfaces YANG
|
||||
model, with augments for containers to ensure smooth integration with
|
||||
@@ -43,7 +43,7 @@ container networking in podman.
|
||||
> Even though the `podman` command can be used directly from a shell
|
||||
> prompt, we strongly recommend using the CLI commands instead. They
|
||||
> employ the services of a wrapper `container` script which handles the
|
||||
> integration of containers in the system.
|
||||
> integration of Docker containers in the system.
|
||||
|
||||
|
||||
Caution
|
||||
@@ -83,18 +83,20 @@ In the CLI, containers can be run in one of two ways:
|
||||
1. `container run IMAGE [COMMAND]`, or
|
||||
2. enter `configure` context, then `edit container NAME`
|
||||
|
||||
The former is useful mostly for testing, or running single commands in
|
||||
an image. It is a wrapper for `podman run -it --rm ...`, while the
|
||||
latter is a wrapper and adaptation of `podman create ...`.
|
||||
The first is useful mostly for testing, or running single commands in
|
||||
an image. It is a wrapper for `podman run -it --rm ...`.
|
||||
|
||||
The second creates a read-only container that is automatically started
|
||||
at every boot. When non-volatile storage is needed, data stored in a
|
||||
volume is persisted until explicitly removed from the configuration,
|
||||
i.e., across host and container reboots and upgrades.
|
||||
The second creates a read-only container that by default automatically
|
||||
start at every boot. It basically wraps `podman create ...`.
|
||||
|
||||
Another option is [Content Mounts](#content-mounts), where the content
|
||||
of a file mounted into the container is kept along with the container
|
||||
configuration in the device's `startup-config`.
|
||||
When non-volatile storage is needed two complementary options exist:
|
||||
|
||||
- **Volumes:** data stored in a volume is persisted until explicitly
|
||||
removed from the configuration, i.e., across host reboots and
|
||||
container upgrades
|
||||
- **[Content Mounts](#content-mounts):** where the content of a file
|
||||
mounted into the container is kept along with the container
|
||||
configuration in the device's `startup-config`
|
||||
|
||||
Podman ensures (using tmpfs) all containers have writable directories
|
||||
for certain critical file system paths: `/dev`, `/dev/shm`, `/run`,
|
||||
@@ -127,24 +129,30 @@ Classic Hello World:
|
||||
Hello from Docker!
|
||||
This message shows that your installation appears to be working correctly.
|
||||
|
||||
Persistent web server using nginx, sharing the host's network:
|
||||
A web server with [nginx][], using standard docker bridge. Podman will
|
||||
automatically create a VETH pair for us, connecting the container to the
|
||||
`docker0` bridge:
|
||||
|
||||
admin@example:/> configure
|
||||
admin@example:/config> edit container web
|
||||
admin@example:/config/container/web> set image docker://nginx:alpine
|
||||
admin@example:/config/container/web> set publish 80:80
|
||||
admin@example:/config/container/web> set network host
|
||||
admin@example:/config/container/web> leave
|
||||
admin@example:/config/> edit interface docker0
|
||||
admin@example:/config/interface/docker0/> set container-network
|
||||
admin@example:/config/interface/docker0/> end
|
||||
admin@example:/config/> edit container web
|
||||
admin@example:/config/container/web/> set image docker://nginx:alpine
|
||||
admin@example:/config/container/web/> set network publish 8080:80
|
||||
admin@example:/config/container/web/> set network interface docker0
|
||||
admin@example:/config/container/web/> set volume cache target /var/cache
|
||||
admin@example:/config/container/web/> leave
|
||||
admin@example:/> show container
|
||||
|
||||
Exit to the shell and verify the service with curl, or try to attach
|
||||
to your device's IP address using your browser:
|
||||
|
||||
admin@example:~$ curl http://localhost
|
||||
admin@example:~$ curl http://localhost:8080
|
||||
|
||||
or connect to port 80 of your running Infix system with a browser. See
|
||||
the following sections for how to add more interfaces and manage your
|
||||
container at runtime.
|
||||
or connect to port 8080 of your running Infix system with a browser.
|
||||
See the following sections for how to add more interfaces and manage
|
||||
your container at runtime.
|
||||
|
||||
|
||||
Container Images
|
||||
@@ -456,11 +464,11 @@ in a `bridge`. Below an example of a system container calls `set
|
||||
network interface docker0`, here we show how to set options for that
|
||||
network:
|
||||
|
||||
admin@example:/config/container/ntpd/> edit network docker0
|
||||
admin@example:/config/container/ntpd/network/docker0/>
|
||||
admin@example:/config/container/ntpd/network/docker0/> set option
|
||||
admin@example:/config/container/ntpd/> edit network interface docker0
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/>
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> set option
|
||||
<string> Options for masquerading container bridges.
|
||||
admin@example:/config/container/ntpd/network/docker0/> help option
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> help option
|
||||
NAME
|
||||
option <string>
|
||||
|
||||
@@ -471,9 +479,9 @@ network:
|
||||
mac=00:01:02:c0:ff:ee -- set fixed MAC address in container
|
||||
interface_name=foo0 -- set interface name inside container
|
||||
|
||||
admin@example:/config/container/ntpd/network/docker0/> set option ip=172.17.0.2
|
||||
admin@example:/config/container/ntpd/network/docker0/> set option interface_name=wan
|
||||
admin@example:/config/container/ntpd/network/docker0/> leave
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> set option ip=172.17.0.2
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> set option interface_name=wan
|
||||
admin@example:/config/container/ntpd/network/interface/docker0/> leave
|
||||
|
||||
|
||||
### Container Host Interface
|
||||
@@ -903,4 +911,5 @@ Container Image](#upgrading-a-container-image) (above).
|
||||
[14]: https://github.com/kernelkit/curiOS/
|
||||
[15]: https://github.com/kernelkit/curiOS/blob/2e4748f65e356b2c117f586cd9420d7ba66f79d5/board/system/rootfs/etc/inittab
|
||||
[tini]: https://github.com/krallin/tini
|
||||
[nginx]: https://hub.docker.com/_/nginx
|
||||
[podman]: https://podman.io
|
||||
|
||||
@@ -164,6 +164,59 @@ Now you can rebuild `confd`, just as described above, and restart Infix:
|
||||
make confd-rebuild all run
|
||||
|
||||
|
||||
### `statd`
|
||||
|
||||
The Infix status daemon, `src/statd`, is responsible for populating the
|
||||
sysrepo `operational` datastore. Like `confd`, it uses XPath subscriptions,
|
||||
but unlike `confd`, it relies entirely on `yanger`, a Python script that
|
||||
gathers data from local linux services and feeds it into sysrepo.
|
||||
|
||||
To apply changes, rebuild the image:
|
||||
|
||||
make python-statd-rebuild statd-rebuild all
|
||||
|
||||
Rebuilding the image and testing on target for every change during
|
||||
development process can be tedious. Instead, `yanger` allows remote
|
||||
execution, running the script directly on the host system (test
|
||||
container):
|
||||
|
||||
infamy0:test # ../src/statd/python/yanger/yanger -x "../utils/ixll -A ssh d3a" ieee802-dot1ab-lldp
|
||||
|
||||
`ixll` is a utility script that lets you run network commands using an
|
||||
**interface name** instead of a hostname. It makes operations like
|
||||
`ssh`, `scp`, and network discovery easier.
|
||||
|
||||
Normally, `yanger` runs commands **locally** to retrieve data
|
||||
(e.g., `lldpcli` when handling `ieee802-dot1ab-lldp`). However, when
|
||||
executed with `-x "../utils/ixll -A ssh d3a"` it redirects these
|
||||
commands to a remote system connected to the local `d3a` interface via
|
||||
SSH. This setup is used for running `yanger` in an
|
||||
[interactive test environment](testing.md#interactive-usage). The yanger
|
||||
script runs on the `host` system, but key commands are executed on the
|
||||
`target` system.
|
||||
|
||||
For debugging or testing, you can capture system command output and
|
||||
replay it later without needing a live system.
|
||||
|
||||
To capture:
|
||||
|
||||
infamy0:test # ../src/statd/python/yanger/yanger -c /tmp/capture ieee802-dot1ab-lldp
|
||||
|
||||
To replay:
|
||||
|
||||
infamy0:test # ../src/statd/python/yanger/yanger -r /tmp/capture ieee802-dot1ab-lldp
|
||||
|
||||
This is especially useful when working in isolated environments or debugging
|
||||
issues without direct access to the DUT.
|
||||
|
||||
### Agree on YANG Model
|
||||
|
||||
When making changes to the `confd` and `statd` services, you will often need to update
|
||||
the YANG models. If you are adding a new YANG module, it's best to follow the
|
||||
structure of an existing one. However, before making any changes, **always discuss
|
||||
them with the Infix core team**. This helps avoid issues later in development and
|
||||
makes pull request reviews smoother.
|
||||
|
||||
Testing
|
||||
-------
|
||||
|
||||
@@ -175,6 +228,11 @@ The Infix automated test suite is built around Qemu and [Qeneth][2], see:
|
||||
* [Testing](testing.md)
|
||||
* [Docker Image](../test/docker/README.md)
|
||||
|
||||
With any new feature added to Infix, it is essential to include a
|
||||
relevant test case. See the
|
||||
[Test Development](testing.md#test-development) section for guidance
|
||||
on adding test cases.
|
||||
|
||||
|
||||
Reviewing
|
||||
---------
|
||||
|
||||
+17
-8
@@ -6,13 +6,7 @@ This column contains the mapping between YANG and Linux / Ethtool counters.
|
||||
┌─────────────────────────────────┬──────────────────────────────────┐
|
||||
│ YANG │ Linux / Ethtool │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-frames │ FramesTransmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-multicast-frames │ MulticastFramesXmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-broadcast-frames │ BroadcastFramesXmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-total-frames │ FramesReceivedOK, │
|
||||
│ in-total-octets │ FramesReceivedOK, │
|
||||
│ │ FrameCheckSequenceErrors │
|
||||
│ │ FramesLostDueToIntMACRcvError │
|
||||
│ │ AlignmentErrors │
|
||||
@@ -25,8 +19,23 @@ This column contains the mapping between YANG and Linux / Ethtool counters.
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-broadcast-frames │ BroadcastFramesReceivedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-error-fcs-frames │ FrameCheckSequenceErrors │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-error-undersize-frames │ undersize_pkts │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-error-fcs-frames │ FrameCheckSequenceErrors │
|
||||
| in-error-oversize-frames | etherStatsJabbers, |
|
||||
| | etherStatsOversizePkts |
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ in-error-mac-internal-frames │ FramesLostDueToIntMACRcvError │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-frames │ FramesTransmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-multicast-frames │ MulticastFramesXmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ out-broadcast-frames │ BroadcastFramesXmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ infix-eth:out-good-octets │ OctetsTransmittedOK │
|
||||
├─────────────────────────────────┼──────────────────────────────────┤
|
||||
│ infix-eth:in-good-octets │ OctetsReceivedOK │
|
||||
└─────────────────────────────────┴──────────────────────────────────┘
|
||||
```
|
||||
|
||||
File diff suppressed because one or more lines are too long
|
Before Width: | Height: | Size: 358 KiB After Width: | Height: | Size: 368 KiB |
+1
-1
File diff suppressed because one or more lines are too long
|
Before Width: | Height: | Size: 281 KiB After Width: | Height: | Size: 280 KiB |
+288
-24
@@ -48,7 +48,7 @@ other traffic would be bridged as usual.
|
||||
| bridge | infix-if-bridge | SW implementation of an IEEE 802.1Q bridge |
|
||||
| ip | ietf-ip, infix-ip | IP address to the subordinate interface |
|
||||
| vlan | infix-if-vlan | Capture all traffic belonging to a specific 802.1Q VID |
|
||||
| lag[^1] | infix-if-lag | Bond multiple interfaces into one, creating a link aggregate |
|
||||
| lag | infix-if-lag | Link aggregation, static and IEEE 802.3ad (LACP) |
|
||||
| lo | ietf-interfaces | Software loopback interface |
|
||||
| eth | ieee802-ethernet-interface | Physical Ethernet device/port. |
|
||||
| | infix-ethernet-interface | |
|
||||
@@ -430,6 +430,265 @@ admin@example:/config/interface/br0/bridge/> set ieee-group-forward lldp
|
||||
admin@example:/config/interface/br0/bridge/>
|
||||
```
|
||||
|
||||
|
||||
### Link Aggregation
|
||||
|
||||
A link aggregate, or *lag*, allows multiple physical interfaces to be
|
||||
combined into a single logical interface, providing increased bandwidth
|
||||
(in some cases) and redundancy (primarily). Two modes of qualifying lag
|
||||
member ports are available:
|
||||
|
||||
1. **static**: Active members selected based on link status (carrier)
|
||||
2. **lacp:** IEEE 802.3ad Link Aggregation Control Protocol
|
||||
|
||||
In LACP mode, LACPDUs are exchanged by the link partners to qualify each
|
||||
lag member, while in static mode only carrier is used. This additional
|
||||
exchange in LACP ensures traffic can be forwarded in both directions.
|
||||
|
||||
Traffic distribution, for both modes, across the active lag member ports
|
||||
is determined by the hash policy[^1]. It uses an XOR of the source,
|
||||
destination MAC addresses and the EtherType field. This, IEEE
|
||||
802.3ad-compliant, algorithm will place all traffic to a particular
|
||||
network peer on the same link. Meaning there is no increased bandwidth
|
||||
for communication between two specific devices.
|
||||
|
||||
> [!TIP]
|
||||
> Similar to other interface types, naming your interface `lagN`, where
|
||||
> `N` is a number, allows the CLI to automatically infer the interface
|
||||
> type as LAG.
|
||||
|
||||
|
||||
#### Basic Configuration
|
||||
|
||||
Creating a link aggregate interface and adding member ports:
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit interface lag0
|
||||
admin@example:/config/interface/lag0/> set lag mode static
|
||||
admin@example:/config/interface/lag0/> end
|
||||
admin@example:/config/> set interface eth7 lag-port lag lag0
|
||||
admin@example:/config/> set interface eth8 lag-port lag lag0
|
||||
admin@example:/config/> leave
|
||||
```
|
||||
|
||||
A static lag responds only to link (carrier) changes of member ports.
|
||||
E.g., in this example egressing traffic is continuously distributed over
|
||||
the two links until link down on one link is detected, triggering all
|
||||
traffic to be steered to the sole remaining link.
|
||||
|
||||
|
||||
#### LACP Configuration
|
||||
|
||||
LACP mode provides dynamic negotiation of the link aggregate. Key
|
||||
settings include:
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit interface lag0
|
||||
admin@example:/config/interface/lag0/> set lag mode lacp
|
||||
admin@example:/config/interface/lag0/> set lag lacp mode passive
|
||||
admin@example:/config/interface/lag0/> set lag lacp rate fast
|
||||
admin@example:/config/interface/lag0/> set lag lacp system-priority 100
|
||||
```
|
||||
|
||||
LACP mode supports two operational modes:
|
||||
|
||||
- **active:** Initiates negotiation by sending LACPDUs (default)
|
||||
- **passive:** Waits for peer to initiate negotiation
|
||||
|
||||
> [!NOTE]
|
||||
> At least one end of the link must be in active mode for negotiation to occur.
|
||||
|
||||
The LACP rate setting controls protocol timing:
|
||||
|
||||
- **slow:** LACPDUs sent every 30 seconds, with 90 second timeout (default)
|
||||
- **fast:** LACPDUs sent every second, with 3 second timeout
|
||||
|
||||
|
||||
#### Link Flapping
|
||||
|
||||
To protect against link flapping, debounce timers can be configured to
|
||||
delay link qualification. Usually only the `up` delay is needed:
|
||||
|
||||
```
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/> edit debounce
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/debounce/> set up 500
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/debounce/> set down 200
|
||||
```
|
||||
|
||||
#### Operational Status, Overview
|
||||
|
||||
Like other interfaces, link aggregates are also available in the general
|
||||
interfaces overview in the CLI admin-exec context. Here is the above
|
||||
static mode aggregate:
|
||||
|
||||
```
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
ipv6 ::1/128 (static)
|
||||
.
|
||||
.
|
||||
.
|
||||
lag0 lag UP static: balance-xor, hash: layer2
|
||||
│ ethernet UP 00:a0:85:00:02:00
|
||||
├ eth7 lag ACTIVE
|
||||
└ eth8 lag ACTIVE
|
||||
```
|
||||
|
||||
Same aggregate, but in LACP mode:
|
||||
|
||||
```
|
||||
admin@example:/> show interfaces
|
||||
INTERFACE PROTOCOL STATE DATA
|
||||
lo ethernet UP 00:00:00:00:00:00
|
||||
ipv4 127.0.0.1/8 (static)
|
||||
ipv6 ::1/128 (static)
|
||||
.
|
||||
.
|
||||
.
|
||||
lag0 lag UP lacp: active, rate: fast (1s), hash: layer2
|
||||
│ ethernet UP 00:a0:85:00:02:00
|
||||
├ eth7 lag ACTIVE active, short_timeout, aggregating, in_sync, collecting, distributing
|
||||
└ eth8 lag ACTIVE active, short_timeout, aggregating, in_sync, collecting, distributing
|
||||
```
|
||||
|
||||
|
||||
#### Operational Status, Detail
|
||||
|
||||
In addition to basic status shown in the interface overview, detailed
|
||||
LAG status can be inspected:
|
||||
|
||||
```
|
||||
admin@example:/> show interfaces name lag0
|
||||
name : lag0
|
||||
index : 25
|
||||
mtu : 1500
|
||||
operational status : up
|
||||
physical address : 00:a0:85:00:02:00
|
||||
lag mode : static
|
||||
lag type : balance-xor
|
||||
lag hash : layer2
|
||||
link debounce up : 0 msec
|
||||
link debounce down : 0 msec
|
||||
ipv4 addresses :
|
||||
ipv6 addresses :
|
||||
in-octets : 0
|
||||
out-octets : 2142
|
||||
```
|
||||
|
||||
Same aggregate, but in LACP mode:
|
||||
|
||||
```
|
||||
admin@example:/> show interfaces name lag0
|
||||
name : lag0
|
||||
index : 24
|
||||
mtu : 1500
|
||||
operational status : up
|
||||
physical address : 00:a0:85:00:02:00
|
||||
lag mode : lacp
|
||||
lag hash : layer2
|
||||
lacp mode : active
|
||||
lacp rate : fast (1s)
|
||||
lacp aggregate id : 1
|
||||
lacp system priority: 65535
|
||||
lacp actor key : 9
|
||||
lacp partner key : 9
|
||||
lacp partner mac : 00:a0:85:00:03:00
|
||||
link debounce up : 0 msec
|
||||
link debounce down : 0 msec
|
||||
ipv4 addresses :
|
||||
ipv6 addresses :
|
||||
in-octets : 100892
|
||||
out-octets : 111776
|
||||
```
|
||||
|
||||
Member ports provide additional status information:
|
||||
|
||||
- Link failure counter: number of detected link failures
|
||||
- LACP state flags: various states of LACP negotiation:
|
||||
- `active`: port is actively sending LACPDUs
|
||||
- `short_timeout`: using fast rate (1s) vs. slow rate (30s)
|
||||
- `aggregating`: port is allowed to aggregate in this LAG
|
||||
- `in_sync`: port is synchronized with partner
|
||||
- `collecting`: port is allowed to receive traffic
|
||||
- `distributing`: port is allowed to send traffic
|
||||
- `defaulted`: using default partner info (partner not responding)
|
||||
- `expired`: partner info has expired (no LACPDUs received)
|
||||
- Aggregator ID: unique identifier for this LAG group
|
||||
- Actor state: LACP state flags for this port (local)
|
||||
- Partner state: LACP state flags from the remote port
|
||||
|
||||
Example member port status:
|
||||
|
||||
```
|
||||
admin@example:/> show interfaces name eth7
|
||||
name : eth7
|
||||
index : 8
|
||||
mtu : 1500
|
||||
operational status : up
|
||||
physical address : 00:a0:85:00:02:00
|
||||
lag member : lag0
|
||||
lag member state : active
|
||||
lacp aggregate id : 1
|
||||
lacp actor state : active, short_timeout, aggregating, in_sync, collecting, distributing
|
||||
lacp partner state : active, short_timeout, aggregating, in_sync, collecting, distributing
|
||||
link failure count : 0
|
||||
ipv4 addresses :
|
||||
ipv6 addresses :
|
||||
in-octets : 473244
|
||||
out-octets : 499037
|
||||
```
|
||||
|
||||
|
||||
#### Example: Switch Uplink with LACP
|
||||
|
||||
LACP mode provides the most robust operation, automatically negotiating
|
||||
the link aggregate and detecting configuration mismatches.
|
||||
|
||||
A common use case is connecting a switch to an upstream device:
|
||||
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit interface lag0
|
||||
admin@example:/config/interface/lag0/> set lag mode lacp
|
||||
```
|
||||
|
||||
Enable fast LACP for quicker fail-over:
|
||||
|
||||
```
|
||||
admin@example:/config/interface/lag0/> set lag lacp rate fast
|
||||
```
|
||||
|
||||
Add uplink ports
|
||||
|
||||
```
|
||||
admin@example:/config/interface/lag0/> end
|
||||
admin@example:/config/> set interface eth7 lag-port lag lag0
|
||||
admin@example:/config/> set interface eth8 lag-port lag lag0
|
||||
```
|
||||
|
||||
Enable protection against "link flapping".
|
||||
|
||||
```
|
||||
admin@example:/config/interface/lag0/> edit lag link-monitor
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/> edit debounce
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/debounce/> set up 500
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/debounce/> set down 200
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/debounce/> top
|
||||
```
|
||||
|
||||
Add to bridge for switching
|
||||
|
||||
```
|
||||
admin@example:/config/interface/lag0/lag/link-monitor/debounce/> end
|
||||
admin@example:/config/> set interface lag0 bridge-port bridge br0
|
||||
admin@example:/config/> leave
|
||||
```
|
||||
|
||||
|
||||
### VLAN Interfaces
|
||||
|
||||
Creating a VLAN can be done in many ways. This section assumes VLAN
|
||||
@@ -800,7 +1059,7 @@ The resulting address (10.1.2.100/24) is of type *dhcp*.
|
||||
The (only) way to disable IPv6 link-local addresses is by disabling IPv6
|
||||
on the interface.
|
||||
|
||||
```(disabling
|
||||
```
|
||||
admin@example:/> configure
|
||||
admin@example:/config/> edit interface eth0 ipv6
|
||||
admin@example:/config/interface/eth0/ipv6/> set enabled false
|
||||
@@ -914,33 +1173,38 @@ have changed type to *random*.
|
||||
To be able to route (static or dynamic) on the interface it is
|
||||
required to enable forwarding. This setting controls if packets
|
||||
received on this interface can be forwarded.
|
||||
```
|
||||
admin@example:/config/> edit interface eth0
|
||||
admin@example:/config/interface/eth0/> set ipv4 forwarding
|
||||
admin@example:/config/interface/eth0/> leave
|
||||
admin@example:/>
|
||||
```
|
||||
|
||||
```
|
||||
admin@example:/config/> edit interface eth0
|
||||
admin@example:/config/interface/eth0/> set ipv4 forwarding
|
||||
admin@example:/config/interface/eth0/> leave
|
||||
admin@example:/>
|
||||
```
|
||||
|
||||
|
||||
### IPv6 forwarding
|
||||
|
||||
This flag behaves totally different than for IPv4. For IPv6 the
|
||||
ability to route between interfaces is always enabled, instead this
|
||||
flag controls if the interface will be in host/router mode.
|
||||
Due to how the Linux kernel manages IPv6 forwarding, we can not fully
|
||||
control it per interface via this setting like how IPv4 works. Instead,
|
||||
IPv6 forwarding is globally enabled when at least one interface enable
|
||||
forwarding, otherwise it is disabled.
|
||||
|
||||
| **Feature** | **Forward enabled** | **Forward disabled** |
|
||||
|:-----------------------------------------|:--------------------|:---------------------|
|
||||
| IsRouter set in Neighbour Advertisements | Yes | No |
|
||||
| Transmit Router Solicitations | No | Yes |
|
||||
| Router Advertisements are ignored | No | Yes |
|
||||
| Accept Redirects | No | Yes |
|
||||
The following table shows the system IPv6 features that the `forwarding`
|
||||
setting control when it is *Enabled* or *Disabled:
|
||||
|
||||
```
|
||||
admin@example:/config/> edit interface eth0
|
||||
admin@example:/config/interface/eth0/> set ipv6 forwarding
|
||||
admin@example:/config/interface/eth0/> leave
|
||||
admin@example:/>
|
||||
```
|
||||
| **IPv6 Feature** | **Enabled** | **Disabled** |
|
||||
|:-----------------------------------------|:------------|:-------------|
|
||||
| IsRouter set in Neighbour Advertisements | Yes | No |
|
||||
| Transmit Router Solicitations | No | Yes |
|
||||
| Router Advertisements are ignored | Yes | Yes |
|
||||
| Accept Redirects | No | Yes |
|
||||
|
||||
```
|
||||
admin@example:/config/> edit interface eth0
|
||||
admin@example:/config/interface/eth0/> set ipv6 forwarding
|
||||
admin@example:/config/interface/eth0/> leave
|
||||
admin@example:/>
|
||||
```
|
||||
|
||||
|
||||
## Routing support
|
||||
@@ -1228,7 +1492,7 @@ currently supported, namely `ipv4` and `ipv6`.
|
||||
[4]: https://www.rfc-editor.org/rfc/rfc3442
|
||||
[0]: https://frrouting.org/
|
||||
|
||||
[^1]: Please note, link aggregates are not yet supported.
|
||||
[^1]: `(source MAC XOR destination MAC XOR EtherType) MODULO num_links`
|
||||
[^2]: Link-local IPv6 addresses are implicitly enabled when enabling
|
||||
IPv6. IPv6 can be enabled/disabled per interface in the
|
||||
[ietf-ip][2] YANG model.
|
||||
|
||||
+56
-3
@@ -853,14 +853,18 @@ models for details.
|
||||
### Factory Reset
|
||||
|
||||
```
|
||||
~$ curl -kX POST -H "Content-Type: application/yang-data+json" https://example.local/restconf/operations/ietf-factory-default:factory-reset -u admin:admin
|
||||
~$ curl -kX POST -u admin:admin \
|
||||
-H "Content-Type: application/yang-data+json" \
|
||||
https://example.local/restconf/operations/ietf-factory-default:factory-reset
|
||||
curl: (56) OpenSSL SSL_read: error:0A000126:SSL routines::unexpected eof while reading, errno 0
|
||||
```
|
||||
|
||||
### System Reboot
|
||||
|
||||
```
|
||||
~$ curl -kX POST -H "Content-Type: application/yang-data+json" https://example.local/restconf/operations/ietf-system:system-restart -u admin:admin
|
||||
~$ curl -kX POST -u admin:admin \
|
||||
-H "Content-Type: application/yang-data+json" \
|
||||
https://example.local/restconf/operations/ietf-system:system-restart
|
||||
```
|
||||
|
||||
### Set Date and Time
|
||||
@@ -868,7 +872,11 @@ curl: (56) OpenSSL SSL_read: error:0A000126:SSL routines::unexpected eof while r
|
||||
Here's an example of an RPC that takes input/argument:
|
||||
|
||||
```
|
||||
~$ curl -kX POST -H "Content-Type: application/yang-data+json" https://example.local/restconf/operations/ietf-system:set-current-datetime -u admin:admin -d '{"ietf-system:input": {"current-datetime": "2024-04-17T13:48:02-01:00"}}'
|
||||
~$ curl -kX POST -u admin:admin \
|
||||
-H "Content-Type: application/yang-data+json" \
|
||||
-d '{"ietf-system:input": {"current-datetime": "2024-04-17T13:48:02-01:00"}}' \
|
||||
https://example.local/restconf/operations/ietf-system:set-current-datetime
|
||||
|
||||
```
|
||||
|
||||
You can verify that the changes took by a remote SSH command:
|
||||
@@ -879,6 +887,51 @@ Wed Apr 17 14:48:12 UTC 2024
|
||||
~$
|
||||
```
|
||||
|
||||
### Read Hostname
|
||||
|
||||
Example of fetching JSON configuration data to stdout:
|
||||
|
||||
```
|
||||
~$ curl -kX GET -u admin:admin \
|
||||
-H 'Accept: application/yang-data+json' \
|
||||
https://example.local/restconf/data/ietf-system:system/hostname
|
||||
{
|
||||
"ietf-system:system": {
|
||||
"hostname": "foo"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
### Set Hostname
|
||||
|
||||
Example of inline JSON data:
|
||||
|
||||
```
|
||||
~$ curl -kX PATCH -u admin:admin \
|
||||
-H 'Content-Type: application/yang-data+json' \
|
||||
-d '{"ietf-system:system":{"hostname":"bar"}}' \
|
||||
https://example.local/restconf/data/ietf-system:system
|
||||
```
|
||||
|
||||
### Copy Running to Startup
|
||||
|
||||
No copy command available yet to copy between datastores, and the
|
||||
Rousette back-end also does not support "write-through" to the
|
||||
startup datastore.
|
||||
|
||||
To save running-config to startup-config, use the following example to
|
||||
fetch running to a local file and then update startup with it:
|
||||
|
||||
```
|
||||
~$ curl -kX GET -u admin:admin -o running-config.json \
|
||||
-H 'Accept: application/yang-data+json' \
|
||||
https://example.local/restconf/ds/ietf-datastores:running
|
||||
|
||||
~$ curl -kX PUT -u admin:admin -d @running-config.json \
|
||||
-H 'Content-Type: application/yang-data+json' \
|
||||
https://example.local/restconf/ds/ietf-datastores:startup
|
||||
```
|
||||
|
||||
|
||||
## Miscellaneous
|
||||
|
||||
|
||||
+8
-16
@@ -243,23 +243,15 @@ spanning tree matches the expected one.
|
||||
|
||||
Integration to Infix
|
||||
--------------------
|
||||
To successfully run all Infix tests, the image must be built in
|
||||
'test-mode'. This can be achieved by setting the DISK_IMAGE_TEST_MODE
|
||||
parameter to true. Although this is the default setting, it’s advisable
|
||||
to verify it by running:
|
||||
When the test environment is started with Qeneth, it doesn't use the
|
||||
base image directly. Instead, it creates a copy and inserts a `test-mode`
|
||||
flag into it. During the bootstrap phase, the system checks for the
|
||||
presence of the test-mode flag (file).
|
||||
|
||||
$ make menuconfig
|
||||
(External Options --> -*- Disk image --> [*] Enable Test Mode)
|
||||
|
||||
Building an image in 'test-mode' results in the creation of a 'test-mode'
|
||||
file within the auxiliary (aux) partition of the Infix disk image
|
||||
(/mnt/aux/test-mode).
|
||||
|
||||
During the bootstrap phase, the system checks for the presence of this
|
||||
test-mode flag (file). If the flag exists, a 'test-config.cfg' file is
|
||||
generated. In the following step, the system loads the 'test-config'
|
||||
instead of the standard startup-config (or factory-config). This
|
||||
configuration is simple and safe, equivalent to the one used in 'Secure Mode'
|
||||
If the flag exists, a 'test-config.cfg' file is generated. In the
|
||||
following step, the system loads the 'test-config' instead of the
|
||||
standard `startup-config` (or `factory-config`). This configuration
|
||||
is simple and safe, equivalent to the one used in 'Secure Mode'
|
||||
(also known as 'failure-config').
|
||||
|
||||
Additionally, the configuration enables extra RPCs related to system
|
||||
|
||||
+51
-12
@@ -25,17 +25,6 @@ for `x86_64`:
|
||||
$ make
|
||||
$ make test
|
||||
|
||||
It is important to mention that Infix build system by default creates
|
||||
an image in 'test-mode'. The mode is set by DISK_IMAGE_TEST_MODE
|
||||
parameter (default=true). To generate a standard image set the
|
||||
DISK_IMAGE_TEST_MODE to 'false'. However, only the test mode ensures
|
||||
that all Infix tests are executed properly. Prior to the set of commands
|
||||
above, it is always good to check that DISK_IMAGE_TEST_MODE is properly
|
||||
set by running:
|
||||
|
||||
$ make menuconfig
|
||||
(External Options --> -*- Disk image --> [*] Enable Test Mode)
|
||||
|
||||
### Physical Devices
|
||||
|
||||
To run the tests on a preexisting topology from the host's network
|
||||
@@ -99,8 +88,11 @@ arguments:
|
||||
To run a suite of tests, e.g., only the DHCP client tests, pass the
|
||||
suite as an argument to [9PM][]:
|
||||
|
||||
11:42:53 infamy0:test # ./9pm/9pm.py case/infix_dhcp/all.yaml
|
||||
11:42:53 infamy0:test # ./9pm/9pm.py case/infix_dhcp/infix_dhcp.yaml
|
||||
|
||||
To run the suite of all tests:
|
||||
|
||||
11:42:53 infamy0:test # ./9pm/9pm.py case/all.yaml
|
||||
|
||||
### Connecting to Infamy
|
||||
|
||||
@@ -315,5 +307,52 @@ The test specifaction can be genererated with:
|
||||
|
||||
$ make test-spec
|
||||
|
||||
### Test Development
|
||||
|
||||
For adding a new test to the automated regression test suite, it's best
|
||||
to start by reviewing an existing test case.
|
||||
|
||||
All tests are located in the `infix/test/case` repository and are
|
||||
grouped by the features they verify. For example,
|
||||
`infix/test/case/infix_services` contains tests for various Infix
|
||||
services, such as LLDP and mDNS.
|
||||
|
||||
While test grouping is flexible, each test should be placed in a
|
||||
logically relevant category.
|
||||
|
||||
When creating a new test group, add it to `infix/test/case/all.yaml`,
|
||||
to enable it to run as a
|
||||
[subset of the test suite](#running-subsets-of-tests):
|
||||
|
||||
```
|
||||
- name: infix-services
|
||||
suite: infix_services/infix_services.yaml
|
||||
```
|
||||
|
||||
A new test (e.g., lldp_enable_disable) should be added to the
|
||||
corresponding test group .yaml file, such as
|
||||
`infix/test/cases/infix_services.yaml`:
|
||||
|
||||
```
|
||||
- name: lldp_enable_disable
|
||||
case: lldp_enable_disable/test.py
|
||||
```
|
||||
|
||||
It is necessary to include the test in
|
||||
`infix/test/case/infix_services/Readme.adoc` to ensure proper test
|
||||
specification generation:
|
||||
|
||||
```
|
||||
include::lldp_enable_disable/Readme.adoc[]
|
||||
```
|
||||
|
||||
Each test case should have its own directory under,
|
||||
`infix/test/case/infix_services`, containing:
|
||||
- `test.py` - the test script
|
||||
- `topology.dot` - the logical topology definition.
|
||||
|
||||
When the [test specification](#test-specification) is generated,
|
||||
`topology.svg` and `Readme.adoc` should also be created.
|
||||
|
||||
[9PM]: https://github.com/rical/9pm
|
||||
[Qeneth]: https://github.com/wkz/qeneth
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
menu "Boards"
|
||||
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/board/alder-alder/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/board/freescale-imx8mp-evk/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/board/marvell-cn9130-crb/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/board/marvell-espressobin/Config.in"
|
||||
source "$BR2_EXTERNAL_INFIX_PATH/package/board/microchip-sparx5-pcb135/Config.in"
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
config BR2_PACKAGE_FREESCALE_IMX8MP_EVK
|
||||
bool "NXP i.MX8MP EVK"
|
||||
depends on BR2_aarch64
|
||||
help
|
||||
NXP i.MX8MP EVK
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
define FREESCALE_IMX8MP_EVK_LINUX_CONFIG_FIXUPS
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_ARCH_NXP)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_ARCH_MXC)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_FEC)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_NET_VENDOR_STMICRO)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_STMMAC_ETH)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_DWMAC_IMX8)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_SERIAL_IMX)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_SERIAL_IMX_CONSOLE)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_I2C_IMX)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_SPI_IMX)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_PINCTRL_IMX8MP)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_GPIO_MXC)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_IMX2_WDT)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_MMC_SDHCI_OF_ESDHC)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_MMC_SDHCI_ESDHC_IMX)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_CLK_IMX8MP)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_NVMEM_IMX_OCOTP)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_INTERCONNECT)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_INTERCONNECT_IMX)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_INTERCONNECT_IMX8MP)
|
||||
$(call KCONFIG_ENABLE_OPT,CONFIG_REALTEK_PHY)
|
||||
endef
|
||||
|
||||
$(eval $(ix-board))
|
||||
$(eval $(generic-package))
|
||||
@@ -1,3 +1,9 @@
|
||||
################################################################################
|
||||
#
|
||||
# confd-test-mode
|
||||
#
|
||||
################################################################################
|
||||
|
||||
CONFD_TEST_MODE_VERSION = 1.0
|
||||
CONFD_TEST_MODE_SITE_METHOD = local
|
||||
CONFD_TEST_MODE_SITE = $(BR2_EXTERNAL_INFIX_PATH)/src/test-mode
|
||||
@@ -16,7 +22,8 @@ COMMON_SYSREPO_ENV = \
|
||||
|
||||
define CONFD_TEST_MODE_INSTALL_YANG_MODULES
|
||||
$(COMMON_SYSREPO_ENV) \
|
||||
SEARCH_PATH="$(TARGET_DIR)/usr/share/yang/modules/test-mode/" $(BR2_EXTERNAL_INFIX_PATH)/utils/sysrepo-load-modules.sh $(@D)/yang/test-mode.inc
|
||||
SEARCH_PATH="$(TARGET_DIR)/usr/share/yang/modules/test-mode/" \
|
||||
$(BR2_EXTERNAL_INFIX_PATH)/utils/srload $(@D)/yang/test-mode.inc
|
||||
endef
|
||||
define CONFD_TEST_MODE_PERMISSIONS
|
||||
/etc/sysrepo/data/ r 660 root wheel - - - - -
|
||||
|
||||
@@ -17,17 +17,15 @@ run name:startup log:prio:user.notice norestart <pid/confd> env:/etc/default/con
|
||||
-- Loading startup-config
|
||||
|
||||
# Run if loading startup-config fails for some reason
|
||||
run name:failure log:prio:user.critical norestart <pid/confd> env:/etc/default/confd if:<run/startup/failure> \
|
||||
[S] /usr/libexec/confd/load -t $CONFD_TIMEOUT failure-config \
|
||||
run name:failure log:prio:user.crit norestart env:/etc/default/confd \
|
||||
if:<run/startup/failure> \
|
||||
[S] <pid/confd> /usr/libexec/confd/load -t $CONFD_TIMEOUT failure-config \
|
||||
-- Loading failure-config
|
||||
|
||||
run name:error :2 log:console norestart if:<run/failure/failure> \
|
||||
run name:error :2 log:console norestart \
|
||||
if:<run/failure/failure> \
|
||||
[S] /usr/libexec/confd/error --
|
||||
|
||||
service name:netopeer notify:none log <pid/confd> env:/etc/default/confd \
|
||||
[12345] netopeer2-server -F -t $CONFD_TIMEOUT -v 1 \
|
||||
service name:netopeer notify:none log env:/etc/default/confd \
|
||||
[12345] <pid/confd> netopeer2-server -F -t $CONFD_TIMEOUT -v 1 \
|
||||
-- NETCONF server
|
||||
|
||||
# Create initial /etc/resolv.conf after successful bootstrap
|
||||
task name:resolv :conf norestart <pid/dnsmasq> if:<run/startup/success> \
|
||||
[S] resolvconf -u -- Update DNS configuration
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
CONFD_VERSION = 1.4
|
||||
CONFD_VERSION = 1.5
|
||||
CONFD_SITE_METHOD = local
|
||||
CONFD_SITE = $(BR2_EXTERNAL_INFIX_PATH)/src/confd
|
||||
CONFD_LICENSE = BSD-3-Clause
|
||||
@@ -26,8 +26,10 @@ CONFD_CONF_OPTS += --disable-containers
|
||||
endif
|
||||
|
||||
define CONFD_INSTALL_EXTRA
|
||||
cp $(CONFD_PKGDIR)/confd.conf $(FINIT_D)/available/
|
||||
ln -sf ../available/confd.conf $(FINIT_D)/enabled/confd.conf
|
||||
for fn in confd.conf resolvconf.conf; do \
|
||||
cp $(CONFD_PKGDIR)/$$fn $(FINIT_D)/available/; \
|
||||
ln -sf ../available/$$fn $(FINIT_D)/enabled/$$fn; \
|
||||
done
|
||||
cp $(CONFD_PKGDIR)/tmpfiles.conf $(TARGET_DIR)/etc/tmpfiles.d/confd.conf
|
||||
mkdir -p $(TARGET_DIR)/etc/avahi/services
|
||||
cp $(CONFD_PKGDIR)/avahi.service $(TARGET_DIR)/etc/avahi/services/netconf.service
|
||||
@@ -41,13 +43,13 @@ COMMON_SYSREPO_ENV = \
|
||||
|
||||
define CONFD_INSTALL_YANG_MODULES
|
||||
$(COMMON_SYSREPO_ENV) \
|
||||
$(BR2_EXTERNAL_INFIX_PATH)/utils/sysrepo-load-modules.sh $(@D)/yang/confd.inc
|
||||
$(BR2_EXTERNAL_INFIX_PATH)/utils/srload $(@D)/yang/confd.inc
|
||||
endef
|
||||
|
||||
ifeq ($(BR2_PACKAGE_PODMAN),y)
|
||||
define CONFD_INSTALL_YANG_MODULES_CONTAINERS
|
||||
$(COMMON_SYSREPO_ENV) \
|
||||
$(BR2_EXTERNAL_INFIX_PATH)/utils/sysrepo-load-modules.sh $(@D)/yang/containers.inc
|
||||
$(BR2_EXTERNAL_INFIX_PATH)/utils/srload $(@D)/yang/containers.inc
|
||||
endef
|
||||
endif
|
||||
|
||||
@@ -63,9 +65,7 @@ endef
|
||||
CONFD_PRE_INSTALL_TARGET_HOOKS += CONFD_CLEANUP
|
||||
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_EXTRA
|
||||
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_YANG_MODULES
|
||||
ifeq ($(BR2_PACKAGE_PODMAN),y)
|
||||
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_YANG_MODULES_CONTAINERS
|
||||
endif
|
||||
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_CLEANUP
|
||||
|
||||
$(eval $(autotools-package))
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
# Create initial /etc/resolv.conf after successful bootstrap, regardless
|
||||
# of startup-config or failure-config. Condition set by confd.
|
||||
task [S12345] <usr/bootstrap> resolvconf -u -- Update DNS configuration
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally calculated
|
||||
sha256 9d9d33b873917ca5d0bdcc47a36d2fd385971ab0c045d1472fcadf95ee5bcf5b LICENCE
|
||||
sha256 f8725f39b9d9d45c8ad6fd2cfc3c1c834a80c32b4217a3d07dd8ed7fe4b6e352 faux-df1d569287bc45d8fd880287c00e3874c5627c19-br1.tar.gz
|
||||
sha256 b385d30b88cab31bf910436ceb1262947bf34a19ca85098c28510e639dc4b37d faux-df1d569287bc45d8fd880287c00e3874c5627c19-git4.tar.gz
|
||||
|
||||
@@ -1,67 +0,0 @@
|
||||
From 46ffa81f5c88ce95db011369d8bfb802313e4217 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Thu, 17 Oct 2024 14:23:24 +0200
|
||||
Subject: [PATCH 1/7] Only mark rdeps dirty if main service is nohup
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
This patch changes a behavior that's been default since Finit 4.0,
|
||||
introduced in 4d05bf9 with 4.0-rc2.
|
||||
|
||||
If service B depends on A and A needs to be reloaded, then B may be
|
||||
affected. If A is declared as NOHUP <!>, then A will be stopped and
|
||||
restarted, during which time the condition it provides is removed,
|
||||
and B will also be stopped.
|
||||
|
||||
However, and as of this patch, if A is declared supporting HUP, then the
|
||||
condition A provides will only go into flux, during which time B will be
|
||||
SIGSTOPed instead of needing to be reloaded.
|
||||
|
||||
Fix #415
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
src/service.c | 8 ++++++++
|
||||
src/svc.h | 1 +
|
||||
2 files changed, 9 insertions(+)
|
||||
|
||||
diff --git a/src/service.c b/src/service.c
|
||||
index 61be85c..b995ff4 100644
|
||||
--- a/src/service.c
|
||||
+++ b/src/service.c
|
||||
@@ -2001,6 +2001,10 @@ static void svc_mark_affected(char *cond)
|
||||
* Called on conf_reload() to update service reverse dependencies.
|
||||
* E.g., if ospfd depends on zebra and the zebra Finit conf has
|
||||
* changed, we need to mark the ospfd Finit conf as changed too.
|
||||
+ *
|
||||
+ * However, a daemon that depends on syslogd (sysklogd project), need
|
||||
+ * not be reloeaded (SIGHUP'ed or stop/started) because syslogd support
|
||||
+ * reloading its configuration file on SIGHUP.
|
||||
*/
|
||||
void service_update_rdeps(void)
|
||||
{
|
||||
@@ -2012,6 +2016,10 @@ void service_update_rdeps(void)
|
||||
if (!svc_is_changed(svc))
|
||||
continue;
|
||||
|
||||
+ /* Service supports reloading conf without stop/start */
|
||||
+ if (!svc_is_nohup(svc))
|
||||
+ continue; /* Yup, no need to stop start rdeps */
|
||||
+
|
||||
svc_mark_affected(mkcond(svc, cond, sizeof(cond)));
|
||||
}
|
||||
}
|
||||
diff --git a/src/svc.h b/src/svc.h
|
||||
index d00ac14..e2f6bd8 100644
|
||||
--- a/src/svc.h
|
||||
+++ b/src/svc.h
|
||||
@@ -259,6 +259,7 @@ static inline int svc_is_tty (svc_t *svc) { return svc && SVC_TYPE_TTY
|
||||
static inline int svc_is_runtask (svc_t *svc) { return svc && (SVC_TYPE_RUNTASK & svc->type);}
|
||||
static inline int svc_is_forking (svc_t *svc) { return svc && svc->forking; }
|
||||
static inline int svc_is_manual (svc_t *svc) { return svc && svc->manual; }
|
||||
+static inline int svc_is_nohup (svc_t *svc) { return svc && (0 == svc->sighup); }
|
||||
|
||||
static inline int svc_in_runlevel (svc_t *svc, int runlevel) { return svc && ISSET(svc->runlevels, runlevel); }
|
||||
static inline int svc_nohup (svc_t *svc) { return svc && (0 == svc->sighup || 0 != svc->args_dirty); }
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,33 +0,0 @@
|
||||
From 119e66a7e9c95283918639b51dd03a3d666955f8 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Mon, 28 Oct 2024 10:58:04 +0100
|
||||
Subject: [PATCH 2/7] Reset color attributes and clear screen when starting up
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Some boot loaders, like GRUB, leave background color artifacts from
|
||||
their boot menu. This patch resets the foreground and background
|
||||
color attributes, and then clears the screen, without clearing the
|
||||
scrollback buffer.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
src/helpers.c | 3 +++
|
||||
1 file changed, 3 insertions(+)
|
||||
|
||||
diff --git a/src/helpers.c b/src/helpers.c
|
||||
index 8768de8..99c4557 100644
|
||||
--- a/src/helpers.c
|
||||
+++ b/src/helpers.c
|
||||
@@ -87,6 +87,9 @@ void console_init(void)
|
||||
/* Enable line wrap, if disabled previously, e.g., qemu */
|
||||
dprint(STDOUT_FILENO, "\033[?7h", 5);
|
||||
|
||||
+ /* Reset atttributes, background and foreground color */
|
||||
+ dprint(STDOUT_FILENO, "\033[49m\033[39m\e[2J", 14);
|
||||
+
|
||||
log_init();
|
||||
}
|
||||
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,196 +0,0 @@
|
||||
From 0c0e880f3fdd38f7bbde618408378dc0a19ff005 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Sun, 3 Nov 2024 09:39:46 +0100
|
||||
Subject: [PATCH 3/7] plugins: refactor rtc.so
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Factor out time_set() and time_get() for readability and reuse.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
plugins/rtc.c | 116 +++++++++++++++++++++++++++++---------------------
|
||||
1 file changed, 68 insertions(+), 48 deletions(-)
|
||||
|
||||
diff --git a/plugins/rtc.c b/plugins/rtc.c
|
||||
index 238791f..9520c7d 100644
|
||||
--- a/plugins/rtc.c
|
||||
+++ b/plugins/rtc.c
|
||||
@@ -68,6 +68,60 @@ static void tz_restore(char *tz)
|
||||
tzset();
|
||||
}
|
||||
|
||||
+static int time_set(struct tm *tm)
|
||||
+{
|
||||
+ struct tm fallback = { 0 };
|
||||
+ struct timeval tv = { 0 };
|
||||
+ char tz[128];
|
||||
+ int rc = 0;
|
||||
+
|
||||
+ tz_set(tz, sizeof(tz));
|
||||
+
|
||||
+ if (!tm) {
|
||||
+ logit(LOG_NOTICE, "Resetting system clock to kernel default, %s.", rtc_timestamp);
|
||||
+ tm = &fallback;
|
||||
+
|
||||
+ /* Attempt to set RTC to a sane value ... */
|
||||
+ tv.tv_sec = rtc_date_fallback;
|
||||
+ if (!gmtime_r(&tv.tv_sec, tm)) {
|
||||
+ rc = 1;
|
||||
+ goto out;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ tm->tm_isdst = -1; /* Use tzdata to figure it out, please. */
|
||||
+ tv.tv_sec = mktime(tm);
|
||||
+ if (tv.tv_sec == (time_t)-1 || tv.tv_sec < rtc_date_fallback) {
|
||||
+ errno = EINVAL;
|
||||
+ rc = 2;
|
||||
+ } else {
|
||||
+ if (settimeofday(&tv, NULL) == -1)
|
||||
+ rc = 1;
|
||||
+ }
|
||||
+out:
|
||||
+ tz_restore(tz);
|
||||
+ return rc;
|
||||
+}
|
||||
+
|
||||
+static int time_get(struct tm *tm)
|
||||
+{
|
||||
+ struct timeval tv = { 0 };
|
||||
+ char tz[128];
|
||||
+ int rc = 0;
|
||||
+
|
||||
+ tz_set(tz, sizeof(tz));
|
||||
+
|
||||
+ rc = gettimeofday(&tv, NULL);
|
||||
+ if (rc < 0 || tv.tv_sec < rtc_date_fallback)
|
||||
+ rc = 2;
|
||||
+ else
|
||||
+ gmtime_r(&tv.tv_sec, tm);
|
||||
+
|
||||
+ tz_restore(tz);
|
||||
+
|
||||
+ return rc;
|
||||
+}
|
||||
+
|
||||
static int rtc_open(void)
|
||||
{
|
||||
char *alt[] = {
|
||||
@@ -91,10 +145,8 @@ static int rtc_open(void)
|
||||
|
||||
static void rtc_save(void *arg)
|
||||
{
|
||||
- struct timeval tv = { 0 };
|
||||
struct tm tm = { 0 };
|
||||
int fd, rc = 0;
|
||||
- char tz[128];
|
||||
|
||||
if (rescue) {
|
||||
dbg("Skipping %s plugin in rescue mode.", __FILE__);
|
||||
@@ -105,38 +157,26 @@ static void rtc_save(void *arg)
|
||||
if (fd < 0)
|
||||
return;
|
||||
|
||||
- tz_set(tz, sizeof(tz));
|
||||
- rc = gettimeofday(&tv, NULL);
|
||||
- if (rc < 0 || tv.tv_sec < rtc_date_fallback) {
|
||||
+ if ((rc = time_get(&tm))) {
|
||||
print_desc(NULL, "System clock invalid, not saving to RTC");
|
||||
- invalid:
|
||||
- logit(LOG_ERR, "System clock invalid, before %s, not saving to RTC", rtc_timestamp);
|
||||
- rc = 2;
|
||||
- goto out;
|
||||
+ } else {
|
||||
+ print_desc(NULL, "Saving system clock (UTC) to RTC");
|
||||
+ rc = ioctl(fd, RTC_SET_TIME, &tm);
|
||||
}
|
||||
|
||||
- print_desc(NULL, "Saving system time (UTC) to RTC");
|
||||
-
|
||||
- gmtime_r(&tv.tv_sec, &tm);
|
||||
- if (ioctl(fd, RTC_SET_TIME, &tm) < 0) {
|
||||
- if (EINVAL == errno)
|
||||
- goto invalid;
|
||||
- rc = 1;
|
||||
- goto out;
|
||||
+ if (rc && errno == EINVAL) {
|
||||
+ logit(LOG_ERR, "System clock invalid, before %s, not saving to RTC", rtc_timestamp);
|
||||
+ rc = 2;
|
||||
}
|
||||
|
||||
-out:
|
||||
- tz_restore(tz);
|
||||
print(rc, NULL);
|
||||
close(fd);
|
||||
}
|
||||
|
||||
static void rtc_restore(void *arg)
|
||||
{
|
||||
- struct timeval tv = { 0 };
|
||||
struct tm tm = { 0 };
|
||||
int fd, rc = 0;
|
||||
- char tz[128];
|
||||
|
||||
if (rescue) {
|
||||
dbg("Skipping %s plugin in rescue mode.", __FILE__);
|
||||
@@ -149,16 +189,19 @@ static void rtc_restore(void *arg)
|
||||
return;
|
||||
}
|
||||
|
||||
- tz_set(tz, sizeof(tz));
|
||||
- if (ioctl(fd, RTC_RD_TIME, &tm) < 0) {
|
||||
+ if ((rc = ioctl(fd, RTC_RD_TIME, &tm)) < 0) {
|
||||
char msg[120];
|
||||
|
||||
snprintf(msg, sizeof(msg), "Failed restoring system clock, %s",
|
||||
EINVAL == errno ? "RTC time is too old" :
|
||||
ENOENT == errno ? "RTC has no saved time" : "see log for details");
|
||||
print_desc(NULL, msg);
|
||||
+ } else {
|
||||
+ print_desc(NULL, "Restoring system clock (UTC) from RTC");
|
||||
+ rc = time_set(&tm);
|
||||
+ }
|
||||
|
||||
- invalid:
|
||||
+ if (rc) {
|
||||
logit(LOG_ERR, "Failed restoring system clock from RTC.");
|
||||
if (EINVAL == errno)
|
||||
logit(LOG_ERR, "RTC time is too old (before %s)", rtc_timestamp);
|
||||
@@ -167,33 +210,10 @@ static void rtc_restore(void *arg)
|
||||
else
|
||||
logit(LOG_ERR, "RTC error code %d: %s", errno, strerror(errno));
|
||||
|
||||
- /* Been here already? */
|
||||
- if (rc)
|
||||
- goto out;
|
||||
-
|
||||
- /* Attempt to set RTC to a sane value ... */
|
||||
- tv.tv_sec = rtc_date_fallback;
|
||||
- if (!gmtime_r(&tv.tv_sec, &tm))
|
||||
- goto out;
|
||||
-
|
||||
- logit(LOG_NOTICE, "Resetting RTC to kernel default, %s.", rtc_timestamp);
|
||||
+ time_set(NULL);
|
||||
rc = 2;
|
||||
}
|
||||
|
||||
- if (!rc)
|
||||
- print_desc(NULL, "Restoring system clock (UTC) from RTC");
|
||||
- tm.tm_isdst = -1; /* Use tzdata to figure it out, please. */
|
||||
- tv.tv_sec = mktime(&tm);
|
||||
- if (tv.tv_sec == (time_t)-1 || tv.tv_sec < rtc_date_fallback) {
|
||||
- errno = EINVAL;
|
||||
- goto invalid;
|
||||
- }
|
||||
-
|
||||
- if (settimeofday(&tv, NULL) == -1)
|
||||
- rc = 1;
|
||||
-
|
||||
-out:
|
||||
- tz_restore(tz);
|
||||
print(rc, NULL);
|
||||
close(fd);
|
||||
}
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,239 +0,0 @@
|
||||
From bc8118d515839dc598f437aa01f07a771646968d Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Sun, 3 Nov 2024 09:47:16 +0100
|
||||
Subject: [PATCH 4/7] Fix #418: support systems with a broken RTC
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
This patch introduces a new configure option --with-rtc-file=FILE. When
|
||||
enabled the RTC plugin detects missing RTC device and falls back to save
|
||||
and restore system time from a file instead. When --with-rtc-file is
|
||||
used without an argument the default file is /var/lib/misc/rtc, but the
|
||||
feature itself is disabled by default.
|
||||
|
||||
The usefulness of this feature may not be obvious at first, but some
|
||||
systems are equipped with an RTC that resets to a random date at power
|
||||
on. This can be really bad in the case the date is far in the future,
|
||||
because an NTP sync would then cause time skips backwards, which shows
|
||||
up in logs and causes a whole lot of pain in alarm systems.
|
||||
|
||||
The solution is to disable the RTC driver or device tree node, and when
|
||||
Finit starts up, the RTC plugin detects a the device node and instead
|
||||
restores time from the last save game. Meaning time will always only
|
||||
move forwards.
|
||||
|
||||
NOTE: when Finit is built --with-rtc-file we always save to disk, but
|
||||
only restore from the "save game" if restoring from RTC fails.
|
||||
If the system has no RTC we always restore from disk.
|
||||
|
||||
As an added bonus, this change also makes sure to periodically
|
||||
sync also the RTC with the system clock. Useful for systems
|
||||
that do not run an NTP client.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
configure.ac | 12 ++++++
|
||||
plugins/rtc.c | 105 ++++++++++++++++++++++++++++++++++++++++++++++----
|
||||
2 files changed, 110 insertions(+), 7 deletions(-)
|
||||
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index 483457f..ae7cd23 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -180,6 +180,10 @@ AC_ARG_WITH(rtc-date,
|
||||
AS_HELP_STRING([--with-rtc-date=DATE], [If RTC date/time is too old, restore to DATE, format "YYYY-MM-DD HH:MM", default "2000-01-01 00:00"]),
|
||||
[rtc_date=$withval], [rtc_date=no])
|
||||
|
||||
+AC_ARG_WITH(rtc-file,
|
||||
+ AS_HELP_STRING([--with-rtc-file=FILE], [If RTC is missing, save and restore system clock from this file, default: no]),
|
||||
+ [rtc_file=$withval], [rtc_file=no])
|
||||
+
|
||||
### Enable features ###########################################################################
|
||||
|
||||
# Create config.h from selected features and fallback defaults
|
||||
@@ -281,6 +285,13 @@ AS_IF([test "x$rtc_date" != "xno"], [
|
||||
AC_DEFINE(RTC_TIMESTAMP_CUSTOM, "$rtc_date", [Custom RTC restore date, default: 2000-01-01 00:00])], [
|
||||
rtc_date=""])
|
||||
|
||||
+AS_IF([test "x$rtc_file" != "xno"], [
|
||||
+ AS_IF([test "x$rtc_file" = "xyes"], [
|
||||
+ rtc_file=/var/lib/misc/rtc])
|
||||
+ AC_EXPAND_DIR(rtcfile_path, "$rtc_file")
|
||||
+ AC_DEFINE_UNQUOTED(RTC_FILE, "$rtcfile_path", [Save and restore system time from this file if /dev/rtc is missing.])],[
|
||||
+ AC_DEFINE_UNQUOTED(RTC_FILE, NULL)])
|
||||
+
|
||||
AS_IF([test "x$with_keventd" != "xno"], [with_keventd=yes])
|
||||
|
||||
AS_IF([test "x$with_sulogin" != "xno"], [
|
||||
@@ -387,6 +398,7 @@ Behavior:
|
||||
Boot heading..........: $heading
|
||||
Plugins...............: $plugins
|
||||
RTC restore date......: $RTC_DATE
|
||||
+ RTC fallback file.....: $rtc_file
|
||||
|
||||
Optional features:
|
||||
Install doc/..........: $enable_doc
|
||||
diff --git a/plugins/rtc.c b/plugins/rtc.c
|
||||
index 9520c7d..9b4eeae 100644
|
||||
--- a/plugins/rtc.c
|
||||
+++ b/plugins/rtc.c
|
||||
@@ -36,8 +36,15 @@
|
||||
#include "helpers.h"
|
||||
#include "plugin.h"
|
||||
|
||||
-/* Kernel RTC driver validates against this date for sanity check */
|
||||
+/*
|
||||
+ * Kernel RTC driver validates against this date for sanity check. The
|
||||
+ * on NTP sync the driver can also update the RTC every 11 mins. We use
|
||||
+ * the same update interval to handle manual time set and file save.
|
||||
+ */
|
||||
#define RTC_TIMESTAMP_BEGIN_2000 "2000-01-01 00:00:00"
|
||||
+#define RTC_FMT "%Y-%m-%d %H:%M:%S"
|
||||
+#define RTC_PERIOD (11 * 60 * 1000)
|
||||
+
|
||||
#ifdef RTC_TIMESTAMP_CUSTOM
|
||||
static char *rtc_timestamp = RTC_TIMESTAMP_CUSTOM;
|
||||
#else
|
||||
@@ -45,6 +52,10 @@ static char *rtc_timestamp = RTC_TIMESTAMP_BEGIN_2000;
|
||||
#endif
|
||||
static time_t rtc_date_fallback = 946684800LL;
|
||||
|
||||
+static char *rtc_file = RTC_FILE;
|
||||
+static uev_t rtc_timer;
|
||||
+
|
||||
+
|
||||
static void tz_set(char *tz, size_t len)
|
||||
{
|
||||
char *ptr;
|
||||
@@ -122,6 +133,68 @@ static int time_get(struct tm *tm)
|
||||
return rc;
|
||||
}
|
||||
|
||||
+static void file_save(void *arg)
|
||||
+{
|
||||
+ struct tm tm = { 0 };
|
||||
+ int rc = 0;
|
||||
+ FILE *fp;
|
||||
+
|
||||
+ fp = fopen(rtc_file, "w");
|
||||
+ if (!fp) {
|
||||
+ logit(LOG_WARNING, "Failed saving system clock to %s, code %d: %s",
|
||||
+ rtc_file, errno, strerror(errno));
|
||||
+ return;
|
||||
+ }
|
||||
+
|
||||
+ if ((rc = time_get(&tm))) {
|
||||
+ logit(LOG_ERR, "System clock invalid, before %s, not saving", rtc_timestamp);
|
||||
+ print_desc(NULL, "System clock invalid, skipping");
|
||||
+ } else {
|
||||
+ char buf[32] = { 0 };
|
||||
+
|
||||
+ print_desc(NULL, "Saving system clock to file");
|
||||
+ strftime(buf, sizeof(buf), RTC_FMT, &tm);
|
||||
+ fprintf(fp, "%s\n", buf);
|
||||
+ }
|
||||
+
|
||||
+ print(rc, NULL);
|
||||
+ fclose(fp);
|
||||
+}
|
||||
+
|
||||
+static void file_restore(void *arg)
|
||||
+{
|
||||
+ struct tm tm = { 0 };
|
||||
+ int rc = 1;
|
||||
+ FILE *fp;
|
||||
+
|
||||
+ if (!rtc_file) {
|
||||
+ logit(LOG_NOTICE, "System has no RTC (missing driver?), skipping restore.");
|
||||
+ return;
|
||||
+ }
|
||||
+
|
||||
+ print_desc(NULL, "Restoring system clock from backup");
|
||||
+
|
||||
+ fp = fopen(rtc_file, "r");
|
||||
+ if (fp) {
|
||||
+ char buf[32];
|
||||
+
|
||||
+ if (fgets(buf, sizeof(buf), fp)) {
|
||||
+ chomp(buf);
|
||||
+ strptime(buf, RTC_FMT, &tm);
|
||||
+ rc = time_set(&tm);
|
||||
+ }
|
||||
+ fclose(fp);
|
||||
+ } else
|
||||
+ logit(LOG_WARNING, "Missing %s", rtc_file);
|
||||
+
|
||||
+ if (rc) {
|
||||
+ time_set(NULL);
|
||||
+ rc = 2;
|
||||
+ }
|
||||
+
|
||||
+ print(rc, NULL);
|
||||
+}
|
||||
+
|
||||
static int rtc_open(void)
|
||||
{
|
||||
char *alt[] = {
|
||||
@@ -185,7 +258,7 @@ static void rtc_restore(void *arg)
|
||||
|
||||
fd = rtc_open();
|
||||
if (fd < 0) {
|
||||
- logit(LOG_NOTICE, "System has no RTC (missing driver?), skipping restore.");
|
||||
+ file_restore(arg);
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -210,21 +283,37 @@ static void rtc_restore(void *arg)
|
||||
else
|
||||
logit(LOG_ERR, "RTC error code %d: %s", errno, strerror(errno));
|
||||
|
||||
- time_set(NULL);
|
||||
- rc = 2;
|
||||
- }
|
||||
+ print(2, NULL);
|
||||
+
|
||||
+ /* Try restoring from last save game */
|
||||
+ if (rtc_file)
|
||||
+ file_restore(arg);
|
||||
+ } else
|
||||
+ print(0, NULL);
|
||||
|
||||
- print(rc, NULL);
|
||||
close(fd);
|
||||
}
|
||||
|
||||
+
|
||||
+static void save(void *arg)
|
||||
+{
|
||||
+ rtc_save(arg);
|
||||
+ file_save(arg);
|
||||
+}
|
||||
+
|
||||
+static void update(uev_t *w, void *arg, int events)
|
||||
+{
|
||||
+ save(arg);
|
||||
+}
|
||||
+
|
||||
+
|
||||
static plugin_t plugin = {
|
||||
.name = __FILE__,
|
||||
.hook[HOOK_BASEFS_UP] = {
|
||||
.cb = rtc_restore
|
||||
},
|
||||
.hook[HOOK_SHUTDOWN] = {
|
||||
- .cb = rtc_save
|
||||
+ .cb = save
|
||||
}
|
||||
};
|
||||
|
||||
@@ -237,6 +326,8 @@ PLUGIN_INIT(plugin_init)
|
||||
else
|
||||
rtc_timestamp = RTC_TIMESTAMP_BEGIN_2000;
|
||||
|
||||
+ uev_timer_init(ctx, &rtc_timer, update, NULL, RTC_PERIOD, RTC_PERIOD);
|
||||
+
|
||||
plugin_register(&plugin);
|
||||
}
|
||||
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,73 +0,0 @@
|
||||
From 6be16f2f6d093ef495d0fe4313f7b05b4ba3e08f Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Sun, 3 Nov 2024 10:38:38 +0100
|
||||
Subject: [PATCH 5/7] Fix buggy --with-rtc-date=DATE, introduced in Finit v4.4
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
In 42ef3d3c, for v4.4-rc1, support for setting a custom RTC restore date
|
||||
was introduced. Unfortunately the configure script was wrong and caused
|
||||
config.h to contain
|
||||
|
||||
#define RTC_TIMESTAMP_CUSTOM "$rtc_date"
|
||||
|
||||
instead of
|
||||
|
||||
#define RTC_TIMESTAMP_CUSTOM "2023-04-10 14:35:42"
|
||||
|
||||
Furthermore, the error handling for strptime() was wrong, so the restore
|
||||
date was always reverted to the default.
|
||||
|
||||
This patch fixes both issues and extends the DATE of --with-rtc-date to
|
||||
also include seconds.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
configure.ac | 4 ++--
|
||||
plugins/rtc.c | 8 +++++---
|
||||
2 files changed, 7 insertions(+), 5 deletions(-)
|
||||
|
||||
diff --git a/configure.ac b/configure.ac
|
||||
index ae7cd23..58b78ac 100644
|
||||
--- a/configure.ac
|
||||
+++ b/configure.ac
|
||||
@@ -177,7 +177,7 @@ AC_ARG_WITH(plugin-path,
|
||||
[plugin_path=$withval], [plugin_path=yes])
|
||||
|
||||
AC_ARG_WITH(rtc-date,
|
||||
- AS_HELP_STRING([--with-rtc-date=DATE], [If RTC date/time is too old, restore to DATE, format "YYYY-MM-DD HH:MM", default "2000-01-01 00:00"]),
|
||||
+ AS_HELP_STRING([--with-rtc-date=DATE], [If RTC date/time is too old, restore to DATE, format "YYYY-MM-DD HH:MM:SS", default "2000-01-01 00:00:00"]),
|
||||
[rtc_date=$withval], [rtc_date=no])
|
||||
|
||||
AC_ARG_WITH(rtc-file,
|
||||
@@ -282,7 +282,7 @@ AS_IF([test "x$with_random_seed" != "xno"], [
|
||||
AC_DEFINE_UNQUOTED(RANDOMSEED, "$random_path", [Improve random at boot by seeding it with sth from before.])])
|
||||
|
||||
AS_IF([test "x$rtc_date" != "xno"], [
|
||||
- AC_DEFINE(RTC_TIMESTAMP_CUSTOM, "$rtc_date", [Custom RTC restore date, default: 2000-01-01 00:00])], [
|
||||
+ AC_DEFINE_UNQUOTED(RTC_TIMESTAMP_CUSTOM, "$rtc_date", [Custom RTC restore date, default: 2000-01-01 00:00])], [
|
||||
rtc_date=""])
|
||||
|
||||
AS_IF([test "x$rtc_file" != "xno"], [
|
||||
diff --git a/plugins/rtc.c b/plugins/rtc.c
|
||||
index 9b4eeae..a733f75 100644
|
||||
--- a/plugins/rtc.c
|
||||
+++ b/plugins/rtc.c
|
||||
@@ -321,10 +321,12 @@ PLUGIN_INIT(plugin_init)
|
||||
{
|
||||
struct tm tm = { 0 };
|
||||
|
||||
- if (!strptime(rtc_timestamp, "%Y-%m-%d %H:%M", &tm))
|
||||
- rtc_date_fallback = mktime(&tm);
|
||||
- else
|
||||
+ if (!strptime(rtc_timestamp, RTC_FMT, &tm)) {
|
||||
+ logit(LOG_ERR, "Invalid restore date '%s', reverting to '%s'",
|
||||
+ rtc_timestamp, RTC_TIMESTAMP_BEGIN_2000);
|
||||
rtc_timestamp = RTC_TIMESTAMP_BEGIN_2000;
|
||||
+ } else
|
||||
+ rtc_date_fallback = mktime(&tm);
|
||||
|
||||
uev_timer_init(ctx, &rtc_timer, update, NULL, RTC_PERIOD, RTC_PERIOD);
|
||||
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,85 +0,0 @@
|
||||
From 49c0557cedd8d3c1a2f74d27fa7db83dd529914a Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Sun, 3 Nov 2024 20:49:04 +0100
|
||||
Subject: [PATCH 6/7] plugins: reduce log level LOG_ERR -> LOG_WARNING
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
These plugins signal success and failure directly to the console, the
|
||||
user should inspect syslog for more information.
|
||||
|
||||
This change is a follow-up to 340cae4, where kernel logs of LOG_ERR and
|
||||
higher are allowed to log directly to the console. Since syslogd has
|
||||
not been started before these plugins, the log messages would otherwise
|
||||
leak to the console.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
plugins/rtc.c | 14 +++++++-------
|
||||
plugins/urandom.c | 2 +-
|
||||
2 files changed, 8 insertions(+), 8 deletions(-)
|
||||
|
||||
diff --git a/plugins/rtc.c b/plugins/rtc.c
|
||||
index a733f75..96203a0 100644
|
||||
--- a/plugins/rtc.c
|
||||
+++ b/plugins/rtc.c
|
||||
@@ -147,7 +147,7 @@ static void file_save(void *arg)
|
||||
}
|
||||
|
||||
if ((rc = time_get(&tm))) {
|
||||
- logit(LOG_ERR, "System clock invalid, before %s, not saving", rtc_timestamp);
|
||||
+ logit(LOG_WARNING, "System clock invalid, before %s, not saving", rtc_timestamp);
|
||||
print_desc(NULL, "System clock invalid, skipping");
|
||||
} else {
|
||||
char buf[32] = { 0 };
|
||||
@@ -238,7 +238,7 @@ static void rtc_save(void *arg)
|
||||
}
|
||||
|
||||
if (rc && errno == EINVAL) {
|
||||
- logit(LOG_ERR, "System clock invalid, before %s, not saving to RTC", rtc_timestamp);
|
||||
+ logit(LOG_WARNING, "System clock invalid, before %s, not saving to RTC", rtc_timestamp);
|
||||
rc = 2;
|
||||
}
|
||||
|
||||
@@ -275,13 +275,13 @@ static void rtc_restore(void *arg)
|
||||
}
|
||||
|
||||
if (rc) {
|
||||
- logit(LOG_ERR, "Failed restoring system clock from RTC.");
|
||||
+ logit(LOG_WARNING, "Failed restoring system clock from RTC.");
|
||||
if (EINVAL == errno)
|
||||
- logit(LOG_ERR, "RTC time is too old (before %s)", rtc_timestamp);
|
||||
+ logit(LOG_WARNING, "RTC time is too old (before %s)", rtc_timestamp);
|
||||
else if (ENOENT == errno)
|
||||
- logit(LOG_ERR, "RTC has no previously saved (valid) time.");
|
||||
+ logit(LOG_WARNING, "RTC has no previously saved (valid) time.");
|
||||
else
|
||||
- logit(LOG_ERR, "RTC error code %d: %s", errno, strerror(errno));
|
||||
+ logit(LOG_WARNING, "RTC error code %d: %s", errno, strerror(errno));
|
||||
|
||||
print(2, NULL);
|
||||
|
||||
@@ -322,7 +322,7 @@ PLUGIN_INIT(plugin_init)
|
||||
struct tm tm = { 0 };
|
||||
|
||||
if (!strptime(rtc_timestamp, RTC_FMT, &tm)) {
|
||||
- logit(LOG_ERR, "Invalid restore date '%s', reverting to '%s'",
|
||||
+ logit(LOG_WARNING, "Invalid restore date '%s', reverting to '%s'",
|
||||
rtc_timestamp, RTC_TIMESTAMP_BEGIN_2000);
|
||||
rtc_timestamp = RTC_TIMESTAMP_BEGIN_2000;
|
||||
} else
|
||||
diff --git a/plugins/urandom.c b/plugins/urandom.c
|
||||
index b9f6039..6f82779 100644
|
||||
--- a/plugins/urandom.c
|
||||
+++ b/plugins/urandom.c
|
||||
@@ -154,7 +154,7 @@ static void setup(void *arg)
|
||||
close(fd);
|
||||
free(rpi);
|
||||
if (rc < 0)
|
||||
- logit(LOG_ERR, "Failed adding entropy to kernel random pool: %s", strerror(err));
|
||||
+ logit(LOG_WARNING, "Failed adding entropy to kernel random pool: %s", strerror(err));
|
||||
print_result(rc < 0);
|
||||
return;
|
||||
fallback:
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,57 +0,0 @@
|
||||
From 465bc17ca4b131f8c1ef27ff8279f4ea13745a78 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Thu, 28 Nov 2024 11:06:57 +0100
|
||||
Subject: [PATCH 7/7] Fix unintended restart of template siblings
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Consider the case where container@.conf is an available template. When
|
||||
creating a container@foo.conf it will share the same base .conf as an
|
||||
existing container@bar.conf, but we do not expect to restart bar just
|
||||
because foo is instantiated.
|
||||
|
||||
Up until this change, all template siblings were considered "dirty" if a
|
||||
new one was created or updated. Skipping realpath() for all files that
|
||||
have a '@' works around the problem.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
src/conf.c | 20 +++++++++++++-------
|
||||
1 file changed, 13 insertions(+), 7 deletions(-)
|
||||
|
||||
diff --git a/src/conf.c b/src/conf.c
|
||||
index 1cfcd87..531923c 100644
|
||||
--- a/src/conf.c
|
||||
+++ b/src/conf.c
|
||||
@@ -1432,16 +1432,22 @@ static int conf_change_act(char *dir, char *name, uint32_t mask)
|
||||
strlcpy(fn, dir, sizeof(fn));
|
||||
dbg("path: %s mask: %08x", fn, mask);
|
||||
|
||||
- /* Handle disabling/removal of service */
|
||||
- rp = realpath(fn, NULL);
|
||||
- if (!rp) {
|
||||
- if (errno != ENOENT)
|
||||
- goto fail;
|
||||
+ if (strchr(name, '@')) {
|
||||
+ /* Skip realpath for templates */
|
||||
rp = strdup(fn);
|
||||
- if (!rp)
|
||||
- goto fail;
|
||||
+ } else {
|
||||
+ /* Handle disabling/removal of service */
|
||||
+ rp = realpath(fn, NULL);
|
||||
+ if (!rp) {
|
||||
+ if (errno != ENOENT)
|
||||
+ goto fail;
|
||||
+ rp = strdup(fn);
|
||||
+ }
|
||||
}
|
||||
|
||||
+ if (!rp)
|
||||
+ goto fail;
|
||||
+
|
||||
node = conf_find(rp);
|
||||
if (node) {
|
||||
dbg("event already registered for %s ...", name);
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
# From https://github.com/troglobit/finit/releases/
|
||||
sha256 5026965e33f31b8fa4e2e465b9521e805fa01c31cade884c07d0fcff97cd0ddf finit-4.8.tar.gz
|
||||
sha256 7e49a3df58c5aedfff9537b7ff34b9238fc28b523d4dbacc316d606c7af5e335 finit-4.11.tar.gz
|
||||
|
||||
# Locally calculated
|
||||
sha256 2fd62c0fe6ea6d1861669f4c87bda83a0b5ceca64f4baa4d16dd078fbd218c14 LICENSE
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
FINIT_VERSION = 4.8
|
||||
FINIT_VERSION = 4.11
|
||||
FINIT_SITE = https://github.com/troglobit/finit/releases/download/$(FINIT_VERSION)
|
||||
FINIT_LICENSE = MIT
|
||||
FINIT_LICENSE_FILES = LICENSE
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally calculated
|
||||
sha256 9d9d33b873917ca5d0bdcc47a36d2fd385971ab0c045d1472fcadf95ee5bcf5b LICENCE
|
||||
sha256 b579d0028c8c88ddea27282f03c8c23fa9a758ad47918aeffb048456cf204375 klish-plugin-sysrepo-b693714a1ff5f8021651d7619556afb19945e5e6-br1.tar.gz
|
||||
sha256 598089ad964594bbbaf2b7d7214d8761c828174eef53b7cfb1cd98517f407d01 klish-plugin-sysrepo-b693714a1ff5f8021651d7619556afb19945e5e6-git4.tar.gz
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally calculated
|
||||
sha256 9d9d33b873917ca5d0bdcc47a36d2fd385971ab0c045d1472fcadf95ee5bcf5b LICENCE
|
||||
sha256 0305355dd29dc276f7957d51e2406907e0c862dfd46f496c8a921df4f3d72a8d klish-019ebd2704e322b5d500f5687d526431e535eec8-br1.tar.gz
|
||||
sha256 79c9b16b227320fea358114738933ea25be33f8f263d3eec1f83fb603c0c0b22 klish-019ebd2704e322b5d500f5687d526431e535eec8-git4.tar.gz
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# Locally calculated
|
||||
sha256 6b94f3abc1aabd0c72a7c7d92a77f79dda7c8a0cb3df839a97890b4116a2de2a COPYING
|
||||
sha256 6bd96a33f41f73d6ca524efa946b5e592227a5dd6dd21f193fadf4be3583552d nghttp2-asio-e877868abe06a83ed0a6ac6e245c07f6f20866b5-br1.tar.gz
|
||||
sha256 d971c538a31eae5714d2434d90f86794f267615e85e8d2bb0c383e83c300e1ce nghttp2-asio-e877868abe06a83ed0a6ac6e245c07f6f20866b5-git4.tar.gz
|
||||
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
# Locally computed
|
||||
sha256 830a633630bf6e61f2b8d4ca00efdd9a173ef25cdd49d4a4364c293e088561df podman-4.5.0.tar.gz
|
||||
sha256 830a633630bf6e61f2b8d4ca00efdd9a173ef25cdd49d4a4364c293e088561df podman-4.5.0-go2.tar.gz
|
||||
sha256 62fb8a3a9621dc2388174caaabe9c2317b694bb9a1d46c98bcf5655b68f51be3 LICENSE
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
From 74ec0f8335f811e4f5becc8bbea4a52af4d3e749 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Tue, 17 Sep 2024 04:08:12 +0200
|
||||
Subject: [PATCH 1/2] On SIGTERM, allow dispatcher to process event before
|
||||
Subject: [PATCH 1/3] On SIGTERM, allow dispatcher to process event before
|
||||
exiting
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
From bceb724d328f156efa4ad18f26f1760504bd093d Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Wed, 27 Nov 2024 08:44:57 +0100
|
||||
Subject: [PATCH 2/2] avahi-daemon: allow adjusting log level
|
||||
Subject: [PATCH 2/3] avahi-daemon: allow adjusting log level
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
|
||||
@@ -0,0 +1,60 @@
|
||||
From 50ddfbefe5ac4d87040cb177e7cf432d4da04e97 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Wed, 26 Feb 2025 17:42:08 +0100
|
||||
Subject: [PATCH 3/3] avahi-daemon: improve error reporting in chroot
|
||||
communication
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Improve logging of error in chroot communication by including the
|
||||
filename in the log message. Instead of this:
|
||||
|
||||
avahi-daemon[3590]: chroot.c: open() failed: No such file or directory
|
||||
|
||||
log this:
|
||||
|
||||
avahi-daemon[3590]: chroot.c: open(/etc/resolv.conf) failed: No such file or directory
|
||||
|
||||
Which on a system with resolvconf would make the sysadmin a lot calmer,
|
||||
since the file had not yet been created at boot.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
avahi-daemon/chroot.c | 9 ++++++---
|
||||
1 file changed, 6 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/avahi-daemon/chroot.c b/avahi-daemon/chroot.c
|
||||
index ccd56be..fbaad69 100644
|
||||
--- a/avahi-daemon/chroot.c
|
||||
+++ b/avahi-daemon/chroot.c
|
||||
@@ -237,12 +237,13 @@ static int helper_main(int fd) {
|
||||
case AVAHI_CHROOT_GET_RECORD_BROWSER_INTROSPECT:
|
||||
#endif
|
||||
case AVAHI_CHROOT_GET_RESOLV_CONF: {
|
||||
+ const char *fn = get_file_name_table[(int) command];
|
||||
int payload;
|
||||
|
||||
- if ((payload = open(get_file_name_table[(int) command], O_RDONLY)) < 0) {
|
||||
+ if ((payload = open(fn, O_RDONLY)) < 0) {
|
||||
uint8_t c = AVAHI_CHROOT_FAILURE;
|
||||
|
||||
- avahi_log_error(__FILE__": open() failed: %s", strerror(errno));
|
||||
+ avahi_log_error(__FILE__": open(%s) failed: %s", fn, strerror(errno));
|
||||
|
||||
if (write(fd, &c, sizeof(c)) != sizeof(c)) {
|
||||
avahi_log_error(__FILE__": write() failed: %s\n", strerror(errno));
|
||||
@@ -262,9 +263,11 @@ static int helper_main(int fd) {
|
||||
|
||||
case AVAHI_CHROOT_UNLINK_SOCKET:
|
||||
case AVAHI_CHROOT_UNLINK_PID: {
|
||||
+ const char *fn = unlink_file_name_table[(int) command];
|
||||
uint8_t c = AVAHI_CHROOT_SUCCESS;
|
||||
|
||||
- unlink(unlink_file_name_table[(int) command]);
|
||||
+ if (unlink(fn) && errno != ENOENT)
|
||||
+ avahi_log_error(__FILE__": unlink(%s) failed: %s", fn, strerror(errno));
|
||||
|
||||
if (write(fd, &c, sizeof(c)) != sizeof(c)) {
|
||||
avahi_log_error(__FILE__": write() failed: %s\n", strerror(errno));
|
||||
--
|
||||
2.43.0
|
||||
|
||||
+97
@@ -0,0 +1,97 @@
|
||||
From 7e93dca4dab6bdbb39fd7f7c0f436839a1eb626e Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Wed, 5 Jul 2023 22:38:56 +0200
|
||||
Subject: [PATCH 1/2] adduser: clarify adduser -D behavior and add -d for SSH
|
||||
key login
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Clarify that -D locks the account (!), then add -d to create an account
|
||||
for which password login is disabled (*) but the user can log in with
|
||||
SSH keys.
|
||||
|
||||
This also adjusts the long option --disabled-password, which was mapped
|
||||
to -D, probably mistakenly. With this change BusyBox adduser behaves
|
||||
the same as Debian's --disabled-login and --disabled-password.
|
||||
|
||||
Fixes #10981
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
loginutils/adduser.c | 24 ++++++++++++++----------
|
||||
1 file changed, 14 insertions(+), 10 deletions(-)
|
||||
|
||||
diff --git a/loginutils/adduser.c b/loginutils/adduser.c
|
||||
index d3c795afa..cf6a0264a 100644
|
||||
--- a/loginutils/adduser.c
|
||||
+++ b/loginutils/adduser.c
|
||||
@@ -62,7 +62,8 @@
|
||||
//usage: "\n -s SHELL Login shell"
|
||||
//usage: "\n -G GRP Group"
|
||||
//usage: "\n -S Create a system user"
|
||||
-//usage: "\n -D Don't assign a password"
|
||||
+//usage: "\n -D Don't assign a password (locked account)"
|
||||
+//usage: "\n -d Like -D but allow login using SSH keys"
|
||||
//usage: "\n -H Don't create home directory"
|
||||
//usage: "\n -u UID User id"
|
||||
//usage: "\n -k SKEL Skeleton directory (/etc/skel)"
|
||||
@@ -82,10 +83,11 @@
|
||||
#define OPT_SHELL (1 << 2)
|
||||
#define OPT_GID (1 << 3)
|
||||
#define OPT_DONT_SET_PASS (1 << 4)
|
||||
-#define OPT_SYSTEM_ACCOUNT (1 << 5)
|
||||
-#define OPT_DONT_MAKE_HOME (1 << 6)
|
||||
-#define OPT_UID (1 << 7)
|
||||
-#define OPT_SKEL (1 << 8)
|
||||
+#define OPT_DISABLED_PASS (1 << 5)
|
||||
+#define OPT_SYSTEM_ACCOUNT (1 << 6)
|
||||
+#define OPT_DONT_MAKE_HOME (1 << 7)
|
||||
+#define OPT_UID (1 << 8)
|
||||
+#define OPT_SKEL (1 << 9)
|
||||
|
||||
/* remix */
|
||||
/* recoded such that the uid may be passed in *p */
|
||||
@@ -168,7 +170,8 @@ static const char adduser_longopts[] ALIGN1 =
|
||||
"gecos\0" Required_argument "g"
|
||||
"shell\0" Required_argument "s"
|
||||
"ingroup\0" Required_argument "G"
|
||||
- "disabled-password\0" No_argument "D"
|
||||
+ "disabled-password\0" No_argument "d"
|
||||
+ "disabled-login\0" No_argument "D"
|
||||
"empty-password\0" No_argument "D"
|
||||
"system\0" No_argument "S"
|
||||
"no-create-home\0" No_argument "H"
|
||||
@@ -202,10 +205,10 @@ int adduser_main(int argc UNUSED_PARAM, char **argv)
|
||||
pw.pw_dir = NULL;
|
||||
|
||||
opts = getopt32long(argv, "^"
|
||||
- "h:g:s:G:DSHu:k:"
|
||||
+ "h:g:s:G:DdSHu:k:"
|
||||
/* at least one and at most two non-option args */
|
||||
/* disable interactive passwd for system accounts */
|
||||
- "\0" "-1:?2:SD",
|
||||
+ "\0" "-1:?2:SDd",
|
||||
adduser_longopts,
|
||||
&pw.pw_dir, &pw.pw_gecos, &pw.pw_shell,
|
||||
&usegroup, &uid, &skel
|
||||
@@ -263,7 +266,8 @@ int adduser_main(int argc UNUSED_PARAM, char **argv)
|
||||
* 8. unix date when login expires (i.e. when it may no longer be used)
|
||||
*/
|
||||
/* fields: 2 3 4 5 6 78 */
|
||||
- p = xasprintf("!:%u:0:99999:7:::", (unsigned)(time(NULL)) / (24*60*60));
|
||||
+ p = xasprintf("%c:%u:0:99999:7:::", (opts & OPT_DISABLED_PASS) ? '*' : '!',
|
||||
+ (unsigned)(time(NULL)) / (24*60*60));
|
||||
/* ignore errors: if file is missing we suppose admin doesn't want it */
|
||||
update_passwd(bb_path_shadow_file, pw.pw_name, p, NULL);
|
||||
if (ENABLE_FEATURE_CLEAN_UP)
|
||||
@@ -305,7 +309,7 @@ int adduser_main(int argc UNUSED_PARAM, char **argv)
|
||||
}
|
||||
}
|
||||
|
||||
- if (!(opts & OPT_DONT_SET_PASS)) {
|
||||
+ if (!(opts & (OPT_DONT_SET_PASS | OPT_DISABLED_PASS))) {
|
||||
/* interactively set passwd */
|
||||
passwd_wrapper(pw.pw_name);
|
||||
}
|
||||
--
|
||||
2.34.1
|
||||
|
||||
@@ -0,0 +1,55 @@
|
||||
From 2a1462d9f6a117cf1a5ae531d36143bd0a55d533 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Wed, 5 Jul 2023 23:48:14 +0200
|
||||
Subject: [PATCH 2/2] login: add support for shadow passwords
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
login, on fallback from PAM, or when PAM support is not enabled, checks
|
||||
pw->pw_passwd for locked ("!") or passwordless ("*") accounts. However,
|
||||
on systems with shadow passwords the first character will always be "x".
|
||||
|
||||
This patch adds shadow password support from the passwd tool, letting
|
||||
the user end up in "Login incorrect" rather than the "login: bad salt"
|
||||
case, which could be used by an attacker to guess the state of accounts.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
loginutils/login.c | 15 +++++++++++++++
|
||||
1 file changed, 15 insertions(+)
|
||||
|
||||
diff --git a/loginutils/login.c b/loginutils/login.c
|
||||
index b02be2176..0e7f20844 100644
|
||||
--- a/loginutils/login.c
|
||||
+++ b/loginutils/login.c
|
||||
@@ -345,6 +345,11 @@ int login_main(int argc UNUSED_PARAM, char **argv)
|
||||
#endif
|
||||
#if ENABLE_LOGIN_SESSION_AS_CHILD
|
||||
pid_t child_pid;
|
||||
+#endif
|
||||
+#if ENABLE_FEATURE_SHADOWPASSWDS
|
||||
+ /* Using _r function to avoid pulling in static buffers */
|
||||
+ struct spwd spw, *result = NULL;
|
||||
+ char buffer[256];
|
||||
#endif
|
||||
IF_FEATURE_UTMP(pid_t my_pid;)
|
||||
|
||||
@@ -493,6 +498,16 @@ int login_main(int argc UNUSED_PARAM, char **argv)
|
||||
goto fake_it;
|
||||
}
|
||||
|
||||
+#if ENABLE_FEATURE_SHADOWPASSWDS
|
||||
+ if (getspnam_r(pw->pw_name, &spw, buffer, sizeof(buffer), &result)
|
||||
+ || !result || strcmp(result->sp_namp, pw->pw_name)) {
|
||||
+ strcpy(username, "UNKNOWN");
|
||||
+ goto fake_it;
|
||||
+ } else {
|
||||
+ pw->pw_passwd = result->sp_pwdp;
|
||||
+ }
|
||||
+#endif
|
||||
+
|
||||
if (pw->pw_passwd[0] == '!' || pw->pw_passwd[0] == '*')
|
||||
goto auth_failed;
|
||||
|
||||
--
|
||||
2.34.1
|
||||
|
||||
@@ -1,190 +0,0 @@
|
||||
commit 9ae2b2a466871d936ab79b15c95ba85cbc7d5cd6
|
||||
Author: Stefan Schlosser <sgs@grmmbl.org>
|
||||
Date: Fri Aug 23 10:52:17 2024 +0200
|
||||
|
||||
dnsmasq: add support for option 82
|
||||
|
||||
This patch adds support to insert Option 82 Relay Agent Information (see RFC3046)
|
||||
into relayed DHCP requests.
|
||||
|
||||
When relay has been turned on with --dhcp-relay, the suboptions circuit-id and remote-id
|
||||
can be configured using directives --dhcp-circuitid and --dhcp-remoteid with a maximum of
|
||||
4 bytes denoted in hex format:
|
||||
|
||||
dhcp-circuitid=set:enterprise,00:11:22:33
|
||||
dhcp-remoteid=set:enterprise,cc:dd:ee:ff
|
||||
|
||||
If circuit-id is not set, dnsmasq will use the interface index instead.
|
||||
|
||||
These options usually provide a way to map requests to --dhcp-host and --dhcp-range directives
|
||||
but dhcp-proxy function uses them already for similar purposes.
|
||||
|
||||
The existing option space will be used (no re-negotiation). If it doesn't fit to a packet a warning
|
||||
|
||||
"Not enough space to add relay agent information"
|
||||
|
||||
will be dropped.
|
||||
|
||||
Signed-off-by: Stefan Schlosser <sgs@grmmbl.org>
|
||||
|
||||
diff --git dnsmasq-2.90/src/dhcp.c dnsmasq-2.90/src/dhcp.c
|
||||
index b65facd..4c399eb 100644
|
||||
--- dnsmasq-2.90/src/dhcp.c
|
||||
+++ dnsmasq-2.90/src/dhcp.c
|
||||
@@ -1117,7 +1117,10 @@ static int relay_upstream4(int iface_index, struct dhcp_packet *mess, size_t sz)
|
||||
/* plug in our address */
|
||||
mess->giaddr.s_addr = relay->local.addr4.s_addr;
|
||||
}
|
||||
-
|
||||
+
|
||||
+ /* add relay agent information */
|
||||
+ add_relay_agent_info(relay, mess, sz);
|
||||
+
|
||||
to.sa.sa_family = AF_INET;
|
||||
to.in.sin_addr = relay->server.addr4;
|
||||
to.in.sin_port = htons(relay->port);
|
||||
diff --git dnsmasq-2.90/src/dnsmasq.h dnsmasq-2.90/src/dnsmasq.h
|
||||
index e455c3f..73cb94e 100644
|
||||
--- dnsmasq-2.90/src/dnsmasq.h
|
||||
+++ dnsmasq-2.90/src/dnsmasq.h
|
||||
@@ -1902,3 +1902,6 @@ int add_update_server(int flags,
|
||||
const char *interface,
|
||||
const char *domain,
|
||||
union all_addr *local_addr);
|
||||
+
|
||||
+
|
||||
+int add_relay_agent_info(struct dhcp_relay *relay, struct dhcp_packet *mess, size_t sz);
|
||||
diff --git dnsmasq-2.90/src/rfc2131.c dnsmasq-2.90/src/rfc2131.c
|
||||
index 68834ea..05a4faa 100644
|
||||
--- dnsmasq-2.90/src/rfc2131.c
|
||||
+++ dnsmasq-2.90/src/rfc2131.c
|
||||
@@ -2812,4 +2812,129 @@ static void apply_delay(u32 xid, time_t recvtime, struct dhcp_netid *netid)
|
||||
}
|
||||
}
|
||||
|
||||
+struct relay_info {
|
||||
+ struct {
|
||||
+ unsigned char *data;
|
||||
+ int len;
|
||||
+ } circuit;
|
||||
+ struct {
|
||||
+ unsigned char *data;
|
||||
+ int len;
|
||||
+ } remote;
|
||||
+};
|
||||
+
|
||||
+static inline int subopt_add(unsigned char *ptr, size_t size,
|
||||
+ int subopt, unsigned char *buf, int len)
|
||||
+{
|
||||
+ if ((len + 2) > size)
|
||||
+ {
|
||||
+ my_syslog(MS_DHCP | LOG_WARNING, "No space for relay sub option %d", subopt);
|
||||
+ return 0;
|
||||
+ }
|
||||
+
|
||||
+ *(ptr++) = subopt;
|
||||
+ *(ptr++) = len;
|
||||
+ memcpy(ptr, buf, len);
|
||||
+
|
||||
+ return (len + 2);
|
||||
+}
|
||||
+
|
||||
+static int option_add(struct dhcp_packet *mess, size_t sz,
|
||||
+ struct relay_info *info)
|
||||
+{
|
||||
+ unsigned char *start = &mess->options[0] + sizeof(u32);
|
||||
+ unsigned char *end = (unsigned char *)mess + sz;
|
||||
+ unsigned char *optend = NULL;
|
||||
+ unsigned char opt[64], *sub, *p;
|
||||
+ int size, len = 0;
|
||||
+ int ret = -1;
|
||||
+
|
||||
+ sub = &opt[2];
|
||||
+ size = sizeof(opt) - 2;
|
||||
+
|
||||
+ if (info->circuit.len > 0)
|
||||
+ len += subopt_add(sub+len, size-len,
|
||||
+ SUBOPT_CIRCUIT_ID,
|
||||
+ info->circuit.data,
|
||||
+ info->circuit.len);
|
||||
+
|
||||
+ if (info->remote.len > 0)
|
||||
+ len += subopt_add(sub+len, size-len,
|
||||
+ SUBOPT_REMOTE_ID,
|
||||
+ info->remote.data,
|
||||
+ info->remote.len);
|
||||
+
|
||||
+ if (len == 0)
|
||||
+ return 0; /* Nothing to add */
|
||||
+
|
||||
+ opt[0] = OPTION_AGENT_ID;
|
||||
+ opt[1] = len;
|
||||
+ len += 2;
|
||||
+
|
||||
+ /* find option end */
|
||||
+ optend = option_find1(start, end, OPTION_END, 1);
|
||||
+ if (!optend)
|
||||
+ return -1;
|
||||
+
|
||||
+ *optend = 0;
|
||||
+
|
||||
+ p = dhcp_skip_opts(start);
|
||||
+ if ((p + len + 1) >= end)
|
||||
+ {
|
||||
+ my_syslog(MS_DHCP | LOG_WARNING, "Not enough space to add relay agent information");
|
||||
+ goto out;
|
||||
+ }
|
||||
+
|
||||
+ memcpy(p, opt, len);
|
||||
+ optend = p + len;
|
||||
+
|
||||
+ ret = 0;
|
||||
+out:
|
||||
+ *optend = OPTION_END;
|
||||
+ return ret;
|
||||
+}
|
||||
+
|
||||
+int add_relay_agent_info(struct dhcp_relay *relay, struct dhcp_packet *mess, size_t sz)
|
||||
+{
|
||||
+ struct dhcp_vendor *vendor;
|
||||
+ struct relay_info info;
|
||||
+ int ifindex;
|
||||
+
|
||||
+ if (option_find(mess, sz, OPTION_AGENT_ID, 1))
|
||||
+ return 0; /* don't alter any existing relay agent info */
|
||||
+
|
||||
+ /* lookup circuit-id and remote-id */
|
||||
+ info.circuit.len = info.remote.len = 0;
|
||||
+
|
||||
+ for (vendor = daemon->dhcp_vendors; vendor; vendor = vendor->next)
|
||||
+ {
|
||||
+ if (vendor->match_type == MATCH_CIRCUIT)
|
||||
+ {
|
||||
+ if (info.circuit.len == 0)
|
||||
+ {
|
||||
+ info.circuit.data = vendor->data;
|
||||
+ info.circuit.len = vendor->len;
|
||||
+ }
|
||||
+ }
|
||||
+ else if (vendor->match_type == MATCH_REMOTE)
|
||||
+ {
|
||||
+ if (info.remote.len == 0)
|
||||
+ {
|
||||
+ info.remote.data = vendor->data;
|
||||
+ info.remote.len = vendor->len;
|
||||
+ }
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ /* use interface index as circuit-id if not specified */
|
||||
+ if (info.circuit.len == 0)
|
||||
+ {
|
||||
+ ifindex = htonl(relay->iface_index);
|
||||
+ info.circuit.data = &ifindex;
|
||||
+ info.circuit.len = sizeof(ifindex);
|
||||
+ }
|
||||
+
|
||||
+ return option_add(mess, sz, &info);
|
||||
+}
|
||||
+
|
||||
#endif /* HAVE_DHCP */
|
||||
@@ -1,22 +0,0 @@
|
||||
diff --git a/lib/yang.c b/lib/yang.c
|
||||
index ef1cf898a..c780b8e8c 100644
|
||||
--- a/lib/yang.c
|
||||
+++ b/lib/yang.c
|
||||
@@ -647,7 +647,7 @@ struct yang_data *yang_data_list_find(const struct list *list,
|
||||
}
|
||||
|
||||
/* Make libyang log its errors using FRR logging infrastructure. */
|
||||
-static void ly_log_cb(LY_LOG_LEVEL level, const char *msg, const char *path)
|
||||
+static void ly_log_cb(LY_LOG_LEVEL level, const char *msg, const char *path, uint64_t line)
|
||||
{
|
||||
int priority = LOG_ERR;
|
||||
|
||||
@@ -742,7 +742,7 @@ struct ly_ctx *yang_ctx_new_setup(bool embedded_modules, bool explicit_compile)
|
||||
void yang_init(bool embedded_modules, bool defer_compile)
|
||||
{
|
||||
/* Initialize libyang global parameters that affect all containers. */
|
||||
- ly_set_log_clb(ly_log_cb, 1);
|
||||
+ ly_set_log_clb(ly_log_cb);
|
||||
ly_log_options(LY_LOLOG | LY_LOSTORE);
|
||||
|
||||
/* Initialize libyang container for native models. */
|
||||
@@ -0,0 +1,67 @@
|
||||
diff -urN frr-9.1.3.orig/lib/yang.c frr-9.1.3/lib/yang.c
|
||||
--- frr-9.1.3.orig/lib/yang.c 2024-12-27 22:06:42.000000000 +0100
|
||||
+++ frr-9.1.3/lib/yang.c 2025-03-04 12:23:06.723640114 +0100
|
||||
@@ -10,11 +10,23 @@
|
||||
#include "lib_errors.h"
|
||||
#include "yang.h"
|
||||
#include "yang_translator.h"
|
||||
+#include <libyang/version.h>
|
||||
#include "northbound.h"
|
||||
|
||||
DEFINE_MTYPE_STATIC(LIB, YANG_MODULE, "YANG module");
|
||||
DEFINE_MTYPE_STATIC(LIB, YANG_DATA, "YANG data structure");
|
||||
|
||||
+/* Safe to remove after libyang 2.2.8 */
|
||||
+#if (LY_VERSION_MAJOR < 3)
|
||||
+#define yang_lyd_find_xpath3(ctx_node, tree, xpath, format, prefix_data, vars, \
|
||||
+ set) \
|
||||
+ lyd_find_xpath3(ctx_node, tree, xpath, vars, set)
|
||||
+#else
|
||||
+#define yang_lyd_find_xpath3(ctx_node, tree, xpath, format, prefix_data, vars, \
|
||||
+ set) \
|
||||
+ lyd_find_xpath3(ctx_node, tree, xpath, LY_VALUE_JSON, NULL, vars, set)
|
||||
+#endif
|
||||
+
|
||||
/* libyang container. */
|
||||
struct ly_ctx *ly_native_ctx;
|
||||
|
||||
@@ -657,7 +669,12 @@
|
||||
}
|
||||
|
||||
/* Make libyang log its errors using FRR logging infrastructure. */
|
||||
-static void ly_log_cb(LY_LOG_LEVEL level, const char *msg, const char *path)
|
||||
+static void ly_zlog_cb(LY_LOG_LEVEL level, const char *msg, const char *data_path
|
||||
+#if !(LY_VERSION_MAJOR < 3)
|
||||
+ ,
|
||||
+ const char *schema_path, uint64_t line
|
||||
+#endif
|
||||
+)
|
||||
{
|
||||
int priority = LOG_ERR;
|
||||
|
||||
@@ -674,8 +691,14 @@
|
||||
break;
|
||||
}
|
||||
|
||||
- if (path)
|
||||
- zlog(priority, "libyang: %s (%s)", msg, path);
|
||||
+ if (data_path)
|
||||
+ zlog(priority, "libyang: %s (%s)", msg, data_path);
|
||||
+#if !(LY_VERSION_MAJOR < 3)
|
||||
+ else if (schema_path)
|
||||
+ zlog(priority, "libyang %s (%s)\n", msg, schema_path);
|
||||
+ else if (line)
|
||||
+ zlog(priority, "libyang %s (line %" PRIu64 ")\n", msg, line);
|
||||
+#endif
|
||||
else
|
||||
zlog(priority, "libyang: %s", msg);
|
||||
}
|
||||
@@ -752,7 +775,7 @@
|
||||
void yang_init(bool embedded_modules, bool defer_compile)
|
||||
{
|
||||
/* Initialize libyang global parameters that affect all containers. */
|
||||
- ly_set_log_clb(ly_log_cb, 1);
|
||||
+ ly_set_log_clb(ly_zlog_cb);
|
||||
ly_log_options(LY_LOLOG | LY_LOSTORE);
|
||||
|
||||
/* Initialize libyang container for native models. */
|
||||
@@ -0,0 +1,30 @@
|
||||
From 5f37809521acda432d77aa4028b74c5713c2d988 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Wed, 20 Nov 2024 15:53:21 +0100
|
||||
Subject: [PATCH 2/2] staticd: Re-enable split config support
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Because we can.
|
||||
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
staticd/static_main.c | 3 +--
|
||||
1 file changed, 1 insertion(+), 2 deletions(-)
|
||||
|
||||
diff --git a/staticd/static_main.c b/staticd/static_main.c
|
||||
index 165fb4d65..59e924c83 100644
|
||||
--- a/staticd/static_main.c
|
||||
+++ b/staticd/static_main.c
|
||||
@@ -128,8 +128,7 @@ FRR_DAEMON_INFO(staticd, STATIC, .vty_port = STATIC_VTY_PORT,
|
||||
|
||||
.privs = &static_privs, .yang_modules = staticd_yang_modules,
|
||||
.n_yang_modules = array_size(staticd_yang_modules),
|
||||
-
|
||||
- .flags = FRR_NO_SPLIT_CONFIG);
|
||||
+ );
|
||||
|
||||
int main(int argc, char **argv, char **envp)
|
||||
{
|
||||
--
|
||||
2.43.0
|
||||
|
||||
+5
-8
@@ -1,24 +1,21 @@
|
||||
From 998f0e99f2bd7ab54e1d25acac4227335c8caaec Mon Sep 17 00:00:00 2001
|
||||
From 774cf1d3f5b9cfac247c3efcf4eed39d06c675dc Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 12 Mar 2024 10:27:24 +0100
|
||||
Subject: [PATCH 01/25] [FIX] net: dsa: mv88e6xxx: Fix timeout on waiting for
|
||||
Subject: [PATCH 01/27] [FIX] net: dsa: mv88e6xxx: Fix timeout on waiting for
|
||||
PPU on 6393X
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
In a multi-chip setup, delays of up to 750ms are observed before the
|
||||
device (6393X) signals completion of PPU initialization (Global 1,
|
||||
register 0, bit 15). Therefore, increase the timeout threshold to 1s.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/dsa/mv88e6xxx/chip.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
index 284270a4ade1..1f0b0c07ed9d 100644
|
||||
index 5aeecfab9630..2565277582c5 100644
|
||||
--- a/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
@@ -86,7 +86,7 @@ int mv88e6xxx_write(struct mv88e6xxx_chip *chip, int addr, int reg, u16 val)
|
||||
+6
-9
@@ -1,12 +1,9 @@
|
||||
From 3002b9e08272f3d740c2b582cf9b01fa1fde46b8 Mon Sep 17 00:00:00 2001
|
||||
From 6bd6c3c49c438e35d61669879b64b6c4a00d1a19 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Wed, 27 Mar 2024 15:52:43 +0100
|
||||
Subject: [PATCH 02/25] net: dsa: mv88e6xxx: Improve indirect register access
|
||||
Subject: [PATCH 02/27] net: dsa: mv88e6xxx: Improve indirect register access
|
||||
perf on 6393
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
When operating in multi-chip mode, the 6393 family maps a subset of
|
||||
commonly used global registers to the outermost address space (in
|
||||
@@ -17,7 +14,7 @@ Therefore, add a new set of SMI operations which remaps accesses to
|
||||
such registers to the corresponding directly addressable register. All
|
||||
other accesses use the regular indirect interface.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/dsa/mv88e6xxx/chip.c | 7 +++
|
||||
drivers/net/dsa/mv88e6xxx/global1.h | 3 ++
|
||||
@@ -27,10 +24,10 @@ Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
5 files changed, 119 insertions(+)
|
||||
|
||||
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
index 1f0b0c07ed9d..f9d892d036be 100644
|
||||
index 2565277582c5..7ba492ee5c86 100644
|
||||
--- a/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
@@ -6472,6 +6472,13 @@ static int mv88e6xxx_detect(struct mv88e6xxx_chip *chip)
|
||||
@@ -6502,6 +6502,13 @@ static int mv88e6xxx_detect(struct mv88e6xxx_chip *chip)
|
||||
/* Update the compatible info with the probed one */
|
||||
chip->info = info;
|
||||
|
||||
+5
-8
@@ -1,12 +1,9 @@
|
||||
From 6bad36ecd3bb8f9b97c51f8ee2409f250344c1fc Mon Sep 17 00:00:00 2001
|
||||
From 02bb753cee9b24a3a1bcbcd15c3729144200eafc Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Mon, 22 Apr 2024 23:18:01 +0200
|
||||
Subject: [PATCH 03/25] net: dsa: mv88e6xxx: Honor ports being managed via
|
||||
Subject: [PATCH 03/27] net: dsa: mv88e6xxx: Honor ports being managed via
|
||||
in-band-status
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
Keep all link parameters in their unforced states when the port is
|
||||
declared as being managed via in-band-status, and let the MAC
|
||||
@@ -17,13 +14,13 @@ This state is the default set up by mv88e6xxx_port_setup_mac(), so all
|
||||
we have to do is to make the phylink MAC callbacks no-ops in cases
|
||||
when in-band-status is being used.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/dsa/mv88e6xxx/chip.c | 6 ++++++
|
||||
1 file changed, 6 insertions(+)
|
||||
|
||||
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
index f9d892d036be..98bd635b0ba9 100644
|
||||
index 7ba492ee5c86..cdf48fae0623 100644
|
||||
--- a/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
@@ -964,6 +964,9 @@ static void mv88e6xxx_mac_link_down(struct phylink_config *config,
|
||||
+4
-7
@@ -1,12 +1,9 @@
|
||||
From 980366a1f8709fdfe643edb666c86a916c681a6c Mon Sep 17 00:00:00 2001
|
||||
From 6cbb6a0a54d81ff5b117b023ac7e251ab1e9c556 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Wed, 24 Apr 2024 22:41:04 +0200
|
||||
Subject: [PATCH 04/25] net: dsa: mv88e6xxx: Limit rsvd2cpu policy to user
|
||||
Subject: [PATCH 04/27] net: dsa: mv88e6xxx: Limit rsvd2cpu policy to user
|
||||
ports on 6393X
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
For packets with a DA in the IEEE reserved L2 group range, originating
|
||||
from a CPU, forward it as normal, rather than classifying it as
|
||||
@@ -33,7 +30,7 @@ switch would try to trap it back to the CPU. Given that the CPU is
|
||||
trusted, instead assume that it indeed meant for the packet to be
|
||||
forwarded like any other.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/dsa/mv88e6xxx/port.c | 31 +++++++++++++++++++++++++------
|
||||
1 file changed, 25 insertions(+), 6 deletions(-)
|
||||
+6
-9
@@ -1,16 +1,13 @@
|
||||
From cfc55d98057160753158b7c5357c94ac24d918fe Mon Sep 17 00:00:00 2001
|
||||
From 86b1608084c6e9676db0641f31203d8067893470 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Thu, 16 Nov 2023 19:44:32 +0100
|
||||
Subject: [PATCH 05/25] net: dsa: mv88e6xxx: Add LED infrastructure
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Subject: [PATCH 05/27] net: dsa: mv88e6xxx: Add LED infrastructure
|
||||
Organization: Wires
|
||||
|
||||
Parse DT for LEDs and register them for devices that support it,
|
||||
though no actual implementations exist yet.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/dsa/mv88e6xxx/Makefile | 1 +
|
||||
drivers/net/dsa/mv88e6xxx/chip.c | 5 +-
|
||||
@@ -34,7 +31,7 @@ index a9a9651187db..6720d9303914 100644
|
||||
mv88e6xxx-objs += pcs-6352.o
|
||||
mv88e6xxx-objs += pcs-639x.o
|
||||
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
index 98bd635b0ba9..97cebc490fac 100644
|
||||
index cdf48fae0623..0a7858280903 100644
|
||||
--- a/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
@@ -37,6 +37,7 @@
|
||||
@@ -45,7 +42,7 @@ index 98bd635b0ba9..97cebc490fac 100644
|
||||
#include "phy.h"
|
||||
#include "port.h"
|
||||
#include "ptp.h"
|
||||
@@ -4115,7 +4116,9 @@ static int mv88e6xxx_port_setup(struct dsa_switch *ds, int port)
|
||||
@@ -4145,7 +4146,9 @@ static int mv88e6xxx_port_setup(struct dsa_switch *ds, int port)
|
||||
return err;
|
||||
}
|
||||
|
||||
+6
-9
@@ -1,18 +1,15 @@
|
||||
From 180f2b90c73bc9fdfb27335327571daf8507f9c8 Mon Sep 17 00:00:00 2001
|
||||
From 5496a27ee644f72b721eba0e8c057efb65ee445f Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Thu, 16 Nov 2023 21:59:35 +0100
|
||||
Subject: [PATCH 06/25] net: dsa: mv88e6xxx: Add LED support for 6393X
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Subject: [PATCH 06/27] net: dsa: mv88e6xxx: Add LED support for 6393X
|
||||
Organization: Wires
|
||||
|
||||
Trigger support:
|
||||
- "none"
|
||||
- "timer"
|
||||
- "netdev"
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/dsa/mv88e6xxx/chip.c | 1 +
|
||||
drivers/net/dsa/mv88e6xxx/leds.c | 229 +++++++++++++++++++++++++++++++
|
||||
@@ -22,10 +19,10 @@ Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
5 files changed, 272 insertions(+)
|
||||
|
||||
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
index 97cebc490fac..e8edf3970940 100644
|
||||
index 0a7858280903..cd746bea31be 100644
|
||||
--- a/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
@@ -5627,6 +5627,7 @@ static const struct mv88e6xxx_ops mv88e6393x_ops = {
|
||||
@@ -5657,6 +5657,7 @@ static const struct mv88e6xxx_ops mv88e6393x_ops = {
|
||||
.gpio_ops = &mv88e6352_gpio_ops,
|
||||
.avb_ops = &mv88e6390_avb_ops,
|
||||
.ptp_ops = &mv88e6352_ptp_ops,
|
||||
+4
-7
@@ -1,12 +1,9 @@
|
||||
From 2e42839d4edb250b298f7683975382e9ec97c9a9 Mon Sep 17 00:00:00 2001
|
||||
From a0e2ebe61422d5e0e330022a2a38a31c049a4407 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 28 May 2024 10:38:42 +0200
|
||||
Subject: [PATCH 07/25] net: dsa: tag_dsa: Use tag priority as initial
|
||||
Subject: [PATCH 07/27] net: dsa: tag_dsa: Use tag priority as initial
|
||||
skb->priority
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
Use the 3-bit priority field from the DSA tag as the initial packet
|
||||
priority on ingress to the CPU.
|
||||
@@ -23,7 +20,7 @@ can do with an "ingress-qos-map" on VLAN interfaces. Until that is
|
||||
implemented, support the setup that is likely to be the most common; a
|
||||
1:1 mapping from FPri to skb->priority.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
net/dsa/tag_dsa.c | 7 +++++++
|
||||
1 file changed, 7 insertions(+)
|
||||
+4
-7
@@ -1,12 +1,9 @@
|
||||
From 681fc63548bae02cd286042a3470011617ff78fd Mon Sep 17 00:00:00 2001
|
||||
From a88679c946d5163eb0e30718109c18ddbbd8cfc6 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 16 Jan 2024 16:00:55 +0100
|
||||
Subject: [PATCH 08/25] net: dsa: Support MDB memberships whose L2 addresses
|
||||
Subject: [PATCH 08/27] net: dsa: Support MDB memberships whose L2 addresses
|
||||
overlap
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
Multiple IP multicast groups (32 for v4, 2^80 for v6) map to the same
|
||||
L2 address. This means that switchdev drivers may receive multiple MDB
|
||||
@@ -33,7 +30,7 @@ needed to do this is already in place, since it is also needed on CPU
|
||||
and DSA ports. Thus, "implement" this by simply removing the guards
|
||||
which previously skipped reference countung on user ports.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
net/dsa/switch.c | 16 ----------------
|
||||
1 file changed, 16 deletions(-)
|
||||
+4
-7
@@ -1,13 +1,10 @@
|
||||
From d1c7aeac75ffe6e1350d8a08ee9ba99209636df5 Mon Sep 17 00:00:00 2001
|
||||
From c6528f18fbafef721c18e546aa0b60c1b1d772c6 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Thu, 21 Mar 2024 19:12:15 +0100
|
||||
Subject: [PATCH 09/25] net: dsa: Support EtherType based priority overrides
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Subject: [PATCH 09/27] net: dsa: Support EtherType based priority overrides
|
||||
Organization: Wires
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
include/net/dsa.h | 4 ++++
|
||||
net/dsa/user.c | 56 +++++++++++++++++++++++++++++++++++++++++++++--
|
||||
+9
-12
@@ -1,14 +1,11 @@
|
||||
From 79d68d69f6cd6cf57ef5ed4bcba45134ff8ba174 Mon Sep 17 00:00:00 2001
|
||||
From bc41b93b365694ac36a19565270b8deda3b8cb79 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Fri, 22 Mar 2024 16:15:43 +0100
|
||||
Subject: [PATCH 10/25] net: dsa: mv88e6xxx: Support EtherType based priority
|
||||
Subject: [PATCH 10/27] net: dsa: mv88e6xxx: Support EtherType based priority
|
||||
overrides
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/dsa/mv88e6xxx/chip.c | 64 +++++++++++++++++++++++++++++
|
||||
drivers/net/dsa/mv88e6xxx/chip.h | 21 ++++++++++
|
||||
@@ -19,7 +16,7 @@ Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
6 files changed, 207 insertions(+), 4 deletions(-)
|
||||
|
||||
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
index e8edf3970940..3151df2a27c7 100644
|
||||
index cd746bea31be..e05caeabdc85 100644
|
||||
--- a/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
@@ -1715,6 +1715,11 @@ static int mv88e6xxx_rmu_setup(struct mv88e6xxx_chip *chip)
|
||||
@@ -34,7 +31,7 @@ index e8edf3970940..3151df2a27c7 100644
|
||||
if (chip->info->ops->pot_clear)
|
||||
return chip->info->ops->pot_clear(chip);
|
||||
|
||||
@@ -3386,6 +3391,7 @@ static int mv88e6xxx_setup_port(struct mv88e6xxx_chip *chip, int port)
|
||||
@@ -3416,6 +3421,7 @@ static int mv88e6xxx_setup_port(struct mv88e6xxx_chip *chip, int port)
|
||||
|
||||
chip->ports[port].chip = chip;
|
||||
chip->ports[port].port = port;
|
||||
@@ -42,7 +39,7 @@ index e8edf3970940..3151df2a27c7 100644
|
||||
|
||||
err = mv88e6xxx_port_setup_mac(chip, port, LINK_UNFORCED,
|
||||
SPEED_UNFORCED, DUPLEX_UNFORCED,
|
||||
@@ -6532,6 +6538,7 @@ static struct mv88e6xxx_chip *mv88e6xxx_alloc_chip(struct device *dev)
|
||||
@@ -6562,6 +6568,7 @@ static struct mv88e6xxx_chip *mv88e6xxx_alloc_chip(struct device *dev)
|
||||
chip->dev = dev;
|
||||
|
||||
mutex_init(&chip->reg_lock);
|
||||
@@ -50,7 +47,7 @@ index e8edf3970940..3151df2a27c7 100644
|
||||
INIT_LIST_HEAD(&chip->mdios);
|
||||
idr_init(&chip->policies);
|
||||
INIT_LIST_HEAD(&chip->msts);
|
||||
@@ -7064,6 +7071,61 @@ static int mv88e6xxx_crosschip_lag_leave(struct dsa_switch *ds, int sw_index,
|
||||
@@ -7101,6 +7108,61 @@ static int mv88e6xxx_crosschip_lag_leave(struct dsa_switch *ds, int sw_index,
|
||||
return err_sync ? : err_pvt;
|
||||
}
|
||||
|
||||
@@ -112,7 +109,7 @@ index e8edf3970940..3151df2a27c7 100644
|
||||
static const struct phylink_mac_ops mv88e6xxx_phylink_mac_ops = {
|
||||
.mac_select_pcs = mv88e6xxx_mac_select_pcs,
|
||||
.mac_prepare = mv88e6xxx_mac_prepare,
|
||||
@@ -7133,6 +7195,8 @@ static const struct dsa_switch_ops mv88e6xxx_switch_ops = {
|
||||
@@ -7170,6 +7232,8 @@ static const struct dsa_switch_ops mv88e6xxx_switch_ops = {
|
||||
.crosschip_lag_change = mv88e6xxx_crosschip_lag_change,
|
||||
.crosschip_lag_join = mv88e6xxx_crosschip_lag_join,
|
||||
.crosschip_lag_leave = mv88e6xxx_crosschip_lag_leave,
|
||||
+8
-11
@@ -1,11 +1,8 @@
|
||||
From 57eabbff1169a5641c59fc698d7b122d17733d49 Mon Sep 17 00:00:00 2001
|
||||
From 70c1d59448db0ec88c07fa4ff5748b0df740a8d2 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 28 May 2024 11:04:22 +0200
|
||||
Subject: [PATCH 11/25] net: dsa: mv88e6xxx: Add mqprio qdisc support
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Subject: [PATCH 11/27] net: dsa: mv88e6xxx: Add mqprio qdisc support
|
||||
Organization: Wires
|
||||
|
||||
Add support for attaching mqprio qdisc's to mv88e6xxx ports and use
|
||||
the packet's traffic class as the outgoing priority when no PCP bits
|
||||
@@ -28,14 +25,14 @@ Since FPri is always a 3-bit field, even on older chips with only 4
|
||||
physical queues, always report 8 queues and let the chip's policy
|
||||
handle the mapping down to the "real" number.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/dsa/mv88e6xxx/chip.c | 70 ++++++++++++++++++++++++++++++++
|
||||
net/dsa/tag_dsa.c | 4 +-
|
||||
2 files changed, 73 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
index 3151df2a27c7..f50ad71bb28b 100644
|
||||
index e05caeabdc85..ad997818047e 100644
|
||||
--- a/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
@@ -31,6 +31,7 @@
|
||||
@@ -46,7 +43,7 @@ index 3151df2a27c7..f50ad71bb28b 100644
|
||||
|
||||
#include "chip.h"
|
||||
#include "devlink.h"
|
||||
@@ -7126,6 +7127,68 @@ static int mv88e6xxx_port_del_etype_prio(struct dsa_switch *ds, int port,
|
||||
@@ -7163,6 +7164,68 @@ static int mv88e6xxx_port_del_etype_prio(struct dsa_switch *ds, int port,
|
||||
return err;
|
||||
}
|
||||
|
||||
@@ -115,7 +112,7 @@ index 3151df2a27c7..f50ad71bb28b 100644
|
||||
static const struct phylink_mac_ops mv88e6xxx_phylink_mac_ops = {
|
||||
.mac_select_pcs = mv88e6xxx_mac_select_pcs,
|
||||
.mac_prepare = mv88e6xxx_mac_prepare,
|
||||
@@ -7197,6 +7260,7 @@ static const struct dsa_switch_ops mv88e6xxx_switch_ops = {
|
||||
@@ -7234,6 +7297,7 @@ static const struct dsa_switch_ops mv88e6xxx_switch_ops = {
|
||||
.crosschip_lag_leave = mv88e6xxx_crosschip_lag_leave,
|
||||
.port_add_etype_prio = mv88e6xxx_port_add_etype_prio,
|
||||
.port_del_etype_prio = mv88e6xxx_port_del_etype_prio,
|
||||
@@ -123,7 +120,7 @@ index 3151df2a27c7..f50ad71bb28b 100644
|
||||
};
|
||||
|
||||
static int mv88e6xxx_register_switch(struct mv88e6xxx_chip *chip)
|
||||
@@ -7223,6 +7287,12 @@ static int mv88e6xxx_register_switch(struct mv88e6xxx_chip *chip)
|
||||
@@ -7260,6 +7324,12 @@ static int mv88e6xxx_register_switch(struct mv88e6xxx_chip *chip)
|
||||
*/
|
||||
ds->num_lag_ids = mv88e6xxx_has_lag(chip) ? 16 : 0;
|
||||
|
||||
+7
-10
@@ -1,12 +1,9 @@
|
||||
From 752cce791dfe31525e3974d6f6419e4be0535343 Mon Sep 17 00:00:00 2001
|
||||
From c3721cb1cccf3c8fe18bea05c9ad20e7082291bd Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Wed, 29 May 2024 13:20:41 +0200
|
||||
Subject: [PATCH 12/25] net: dsa: mv88e6xxx: Use VLAN prio over IP when both
|
||||
Subject: [PATCH 12/27] net: dsa: mv88e6xxx: Use VLAN prio over IP when both
|
||||
are available
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
Switch the priority sourcing precdence to prefer VLAN PCP over IP
|
||||
DSCP, when both are available.
|
||||
@@ -26,16 +23,16 @@ main reasons for choosing the new default:
|
||||
core over trusted VLAN trunks, the packet should keep its original
|
||||
priority, independent of what inner protocol fields may indicate.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/dsa/mv88e6xxx/chip.c | 11 ++++++++---
|
||||
1 file changed, 8 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
index f50ad71bb28b..2a46bf5f3da8 100644
|
||||
index ad997818047e..40e8d2018fee 100644
|
||||
--- a/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
@@ -3402,9 +3402,13 @@ static int mv88e6xxx_setup_port(struct mv88e6xxx_chip *chip, int port)
|
||||
@@ -3432,9 +3432,13 @@ static int mv88e6xxx_setup_port(struct mv88e6xxx_chip *chip, int port)
|
||||
|
||||
/* Port Control: disable Drop-on-Unlock, disable Drop-on-Lock,
|
||||
* disable Header mode, enable IGMP/MLD snooping, disable VLAN
|
||||
@@ -52,7 +49,7 @@ index f50ad71bb28b..2a46bf5f3da8 100644
|
||||
*
|
||||
* If this is the CPU link, use DSA or EDSA tagging depending
|
||||
* on which tagging mode was configured.
|
||||
@@ -3415,6 +3419,7 @@ static int mv88e6xxx_setup_port(struct mv88e6xxx_chip *chip, int port)
|
||||
@@ -3445,6 +3449,7 @@ static int mv88e6xxx_setup_port(struct mv88e6xxx_chip *chip, int port)
|
||||
* forwarding of unknown unicasts and multicasts.
|
||||
*/
|
||||
reg = MV88E6185_PORT_CTL0_USE_TAG | MV88E6185_PORT_CTL0_USE_IP |
|
||||
+12
-15
@@ -1,12 +1,9 @@
|
||||
From b3b9b97cbe4eebd6cd3d68744e11a1bde5b98a47 Mon Sep 17 00:00:00 2001
|
||||
From 373d60426de6d19fd668e1e0b599ca430f351a18 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 26 Nov 2024 19:45:59 +0100
|
||||
Subject: [PATCH 13/25] [FIX] net: dsa: mv88e6xxx: Trap locally terminated
|
||||
Subject: [PATCH 13/27] [FIX] net: dsa: mv88e6xxx: Trap locally terminated
|
||||
VLANs
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
Before this change, in a setup like the following, packets assigned to
|
||||
VLAN 10 were forwarded between the switch ports, even though the
|
||||
@@ -28,7 +25,7 @@ marked as policy entries. As the VTU policy of user ports is already
|
||||
set to TRAP (to ensure proper standalone port operation), this will
|
||||
cause all packets assigned to these VLANs to properly terminated.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/dsa/mv88e6xxx/chip.c | 33 ++++++++++++++++++--------------
|
||||
include/net/switchdev.h | 4 ++++
|
||||
@@ -36,10 +33,10 @@ Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
3 files changed, 27 insertions(+), 14 deletions(-)
|
||||
|
||||
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
index 2a46bf5f3da8..785cd3d0e2b1 100644
|
||||
index 40e8d2018fee..30f8a5388733 100644
|
||||
--- a/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
@@ -2631,7 +2631,7 @@ static int mv88e6xxx_port_broadcast_sync(struct mv88e6xxx_chip *chip, int port,
|
||||
@@ -2654,7 +2654,7 @@ static int mv88e6xxx_port_broadcast_sync(struct mv88e6xxx_chip *chip, int port,
|
||||
}
|
||||
|
||||
static int mv88e6xxx_port_vlan_join(struct mv88e6xxx_chip *chip, int port,
|
||||
@@ -48,7 +45,7 @@ index 2a46bf5f3da8..785cd3d0e2b1 100644
|
||||
{
|
||||
const u8 non_member = MV88E6XXX_G1_VTU_DATA_MEMBER_TAG_NON_MEMBER;
|
||||
struct mv88e6xxx_vtu_entry vlan;
|
||||
@@ -2643,9 +2643,7 @@ static int mv88e6xxx_port_vlan_join(struct mv88e6xxx_chip *chip, int port,
|
||||
@@ -2666,9 +2666,7 @@ static int mv88e6xxx_port_vlan_join(struct mv88e6xxx_chip *chip, int port,
|
||||
|
||||
if (!vlan.valid) {
|
||||
memset(&vlan, 0, sizeof(vlan));
|
||||
@@ -59,7 +56,7 @@ index 2a46bf5f3da8..785cd3d0e2b1 100644
|
||||
|
||||
err = mv88e6xxx_atu_new(chip, &vlan.fid);
|
||||
if (err)
|
||||
@@ -2668,6 +2666,9 @@ static int mv88e6xxx_port_vlan_join(struct mv88e6xxx_chip *chip, int port,
|
||||
@@ -2691,6 +2689,9 @@ static int mv88e6xxx_port_vlan_join(struct mv88e6xxx_chip *chip, int port,
|
||||
if (err)
|
||||
return err;
|
||||
} else if (vlan.member[port] != member) {
|
||||
@@ -69,7 +66,7 @@ index 2a46bf5f3da8..785cd3d0e2b1 100644
|
||||
vlan.member[port] = member;
|
||||
|
||||
err = mv88e6xxx_vtu_loadpurge(chip, &vlan);
|
||||
@@ -2714,7 +2715,8 @@ static int mv88e6xxx_port_vlan_add(struct dsa_switch *ds, int port,
|
||||
@@ -2737,7 +2738,8 @@ static int mv88e6xxx_port_vlan_add(struct dsa_switch *ds, int port,
|
||||
|
||||
mv88e6xxx_reg_lock(chip);
|
||||
|
||||
@@ -79,7 +76,7 @@ index 2a46bf5f3da8..785cd3d0e2b1 100644
|
||||
if (err) {
|
||||
dev_err(ds->dev, "p%d: failed to add VLAN %d%c\n", port,
|
||||
vlan->vid, untagged ? 'u' : 't');
|
||||
@@ -3454,14 +3456,17 @@ static int mv88e6xxx_setup_port(struct mv88e6xxx_chip *chip, int port)
|
||||
@@ -3484,14 +3486,17 @@ static int mv88e6xxx_setup_port(struct mv88e6xxx_chip *chip, int port)
|
||||
if (err)
|
||||
return err;
|
||||
|
||||
@@ -104,7 +101,7 @@ index 2a46bf5f3da8..785cd3d0e2b1 100644
|
||||
chip->info->ops->port_set_policy) {
|
||||
err = chip->info->ops->port_set_policy(chip, port,
|
||||
MV88E6XXX_POLICY_MAPPING_VTU,
|
||||
@@ -3491,7 +3496,7 @@ static int mv88e6xxx_setup_port(struct mv88e6xxx_chip *chip, int port)
|
||||
@@ -3521,7 +3526,7 @@ static int mv88e6xxx_setup_port(struct mv88e6xxx_chip *chip, int port)
|
||||
*/
|
||||
err = mv88e6xxx_port_vlan_join(chip, port, MV88E6XXX_VID_STANDALONE,
|
||||
MV88E6XXX_G1_VTU_DATA_MEMBER_TAG_UNMODIFIED,
|
||||
@@ -113,7 +110,7 @@ index 2a46bf5f3da8..785cd3d0e2b1 100644
|
||||
if (err)
|
||||
return err;
|
||||
|
||||
@@ -3505,7 +3510,7 @@ static int mv88e6xxx_setup_port(struct mv88e6xxx_chip *chip, int port)
|
||||
@@ -3535,7 +3540,7 @@ static int mv88e6xxx_setup_port(struct mv88e6xxx_chip *chip, int port)
|
||||
*/
|
||||
err = mv88e6xxx_port_vlan_join(chip, port, MV88E6XXX_VID_BRIDGED,
|
||||
MV88E6XXX_G1_VTU_DATA_MEMBER_TAG_UNMODIFIED,
|
||||
+4
-7
@@ -1,12 +1,9 @@
|
||||
From 1e19f28f4f44973f349ad8bbb2fe0f4624e3c0f3 Mon Sep 17 00:00:00 2001
|
||||
From a6368c60ac6ae2e0d97ac571b6506aa09becbb71 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 19 Sep 2023 18:38:10 +0200
|
||||
Subject: [PATCH 14/25] net: phy: marvell10g: Support firmware loading on
|
||||
Subject: [PATCH 14/27] net: phy: marvell10g: Support firmware loading on
|
||||
88X3310
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
When probing, if a device is waiting for firmware to be loaded into
|
||||
its RAM, ask userspace for the binary and load it over XMDIO.
|
||||
@@ -15,7 +12,7 @@ We have no choice but to bail out of the probe if firmware is not
|
||||
available, as the device does not have any built-in image on which to
|
||||
fall back.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/phy/marvell10g.c | 161 +++++++++++++++++++++++++++++++++++
|
||||
1 file changed, 161 insertions(+)
|
||||
+4
-7
@@ -1,18 +1,15 @@
|
||||
From 95ff23729224c6c08801c2dba8830b18c177431b Mon Sep 17 00:00:00 2001
|
||||
From 550dd1b443cf9d054f2a523088fbe22b215e07cb Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 21 Nov 2023 20:15:24 +0100
|
||||
Subject: [PATCH 15/25] net: phy: marvell10g: Fix power-up when strapped to
|
||||
Subject: [PATCH 15/27] net: phy: marvell10g: Fix power-up when strapped to
|
||||
start powered down
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
On devices which are hardware strapped to start powered down (PDSTATE
|
||||
== 1), make sure that we clear the power-down bit on all units
|
||||
affected by this setting.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/phy/marvell10g.c | 18 +++++++++++++++---
|
||||
1 file changed, 15 insertions(+), 3 deletions(-)
|
||||
+4
-7
@@ -1,11 +1,8 @@
|
||||
From ecdfc7324dd50d79c81af453699467023d72e2bf Mon Sep 17 00:00:00 2001
|
||||
From 9ca4c28ccf7857a36db8dd3c37dcd005222bdb78 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Wed, 15 Nov 2023 20:58:42 +0100
|
||||
Subject: [PATCH 16/25] net: phy: marvell10g: Add LED support for 88X3310
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Subject: [PATCH 16/27] net: phy: marvell10g: Add LED support for 88X3310
|
||||
Organization: Wires
|
||||
|
||||
Pickup the LEDs from the state in which the hardware reset or
|
||||
bootloader left them, but also support further configuration via
|
||||
@@ -21,7 +18,7 @@ Trigger support:
|
||||
- "netdev": Offload link or duplex information to the solid behavior;
|
||||
tx and/or rx activity to blink behavior.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/phy/marvell10g.c | 422 +++++++++++++++++++++++++++++++++++
|
||||
1 file changed, 422 insertions(+)
|
||||
+4
-7
@@ -1,12 +1,9 @@
|
||||
From df3d8aede0c04a0ae93e0dc02ba6b471e3791500 Mon Sep 17 00:00:00 2001
|
||||
From 69f9bda6cab34556e67a096c282eee7337f97f26 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 12 Dec 2023 09:51:05 +0100
|
||||
Subject: [PATCH 17/25] net: phy: marvell10g: Support LEDs tied to a single
|
||||
Subject: [PATCH 17/27] net: phy: marvell10g: Support LEDs tied to a single
|
||||
media side
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
In a combo-port setup, i.e. where both the copper and fiber interface
|
||||
are available to the user, the LEDs may be physically located either
|
||||
@@ -18,7 +15,7 @@ the offloading of the "netdev" trigger, such that LEDs attached to the
|
||||
RJ45 jack only lights up when a copper link is established, and vice
|
||||
versa for the SFP cage.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/phy/marvell10g.c | 23 ++++++++++++++++++++++-
|
||||
1 file changed, 22 insertions(+), 1 deletion(-)
|
||||
+5
-8
@@ -1,11 +1,8 @@
|
||||
From f76443118313f681a62cf34a6f8b38f743832dff Mon Sep 17 00:00:00 2001
|
||||
From f70be42f0ee50cda8c1cde14442ea8285c01834b Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Wed, 27 Mar 2024 10:10:19 +0100
|
||||
Subject: [PATCH 18/25] net: phy: Do not resume PHY when attaching
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Subject: [PATCH 18/27] net: phy: Do not resume PHY when attaching
|
||||
Organization: Wires
|
||||
|
||||
The PHY should not start negotiating with its link-partner until
|
||||
explicitly instructed to do so.
|
||||
@@ -19,13 +16,13 @@ probing (e.g. DSA) would end up with a physical link being
|
||||
established, even though the corresponding interface was still
|
||||
administratively down.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/phy/phy_device.c | 1 -
|
||||
1 file changed, 1 deletion(-)
|
||||
|
||||
diff --git a/drivers/net/phy/phy_device.c b/drivers/net/phy/phy_device.c
|
||||
index 499797646580..0acfef4fe43e 100644
|
||||
index 119dfa2d6643..7c7cc6edf314 100644
|
||||
--- a/drivers/net/phy/phy_device.c
|
||||
+++ b/drivers/net/phy/phy_device.c
|
||||
@@ -1634,7 +1634,6 @@ int phy_attach_direct(struct net_device *dev, struct phy_device *phydev,
|
||||
+4
-7
@@ -1,12 +1,9 @@
|
||||
From cd73e20a5c51dc26ab6a768a813ab805ad8b0689 Mon Sep 17 00:00:00 2001
|
||||
From 17d6f3f6a7429ae635d0359b39da2e173c403fdf Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Mon, 4 Mar 2024 16:47:28 +0100
|
||||
Subject: [PATCH 19/25] net: bridge: avoid classifying unknown multicast as
|
||||
Subject: [PATCH 19/27] net: bridge: avoid classifying unknown multicast as
|
||||
mrouters_only
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
Unknown multicast, MAC/IPv4/IPv6, should always be flooded according to
|
||||
the per-port mcast_flood setting, as well as to detected and configured
|
||||
@@ -19,7 +16,7 @@ Because a multicast router should always receive both known and unknown
|
||||
multicast.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
include/uapi/linux/if_bridge.h | 1 +
|
||||
net/bridge/br.c | 5 +++++
|
||||
+3
-7
@@ -1,12 +1,9 @@
|
||||
From ed61171f9f5d42000b7315d8af12691bb02dac35 Mon Sep 17 00:00:00 2001
|
||||
From 27ca82c96a6bcd560e908eed17fc24126e8051a6 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Tue, 5 Mar 2024 06:44:41 +0100
|
||||
Subject: [PATCH 20/25] net: bridge: Ignore router ports when forwarding L2
|
||||
Subject: [PATCH 20/27] net: bridge: Ignore router ports when forwarding L2
|
||||
multicast
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
Multicast router ports are either statically configured or learned from
|
||||
control protocol traffic (IGMP/MLD/PIM). These protocols regulate IP
|
||||
@@ -15,7 +12,6 @@ of unknown multicast or using permanent MDB entries.
|
||||
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
---
|
||||
net/bridge/br_private.h | 5 ++++-
|
||||
1 file changed, 4 insertions(+), 1 deletion(-)
|
||||
+4
-7
@@ -1,12 +1,9 @@
|
||||
From 73702e1c0331ef8644f326f2dc155a73749cb1c5 Mon Sep 17 00:00:00 2001
|
||||
From bbbb4f7460efeaf057d37d837cae79a565a6d406 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Thu, 4 Apr 2024 16:36:30 +0200
|
||||
Subject: [PATCH 21/25] net: bridge: drop delay for applying strict multicast
|
||||
Subject: [PATCH 21/27] net: bridge: drop delay for applying strict multicast
|
||||
filtering
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
This *local* patch drops the initial delay before applying strict multicast
|
||||
filtering, introduced in [1] and recently updated in [2].
|
||||
@@ -22,7 +19,7 @@ A proper fix for upstreaming could be to add a knob to disable the delay.
|
||||
[2]: https://lore.kernel.org/netdev/20240127175033.9640-1-linus.luessing@c0d3.blue/
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
net/bridge/br_multicast.c | 42 +++++++--------------------------------
|
||||
net/bridge/br_private.h | 4 +---
|
||||
+4
-7
@@ -1,12 +1,9 @@
|
||||
From a48795ef7dbcfd7f1921753ad943144b933020b0 Mon Sep 17 00:00:00 2001
|
||||
From 7c751c24428060c3e87f164eb2a054db410f4b0d Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Thu, 16 May 2024 14:51:54 +0200
|
||||
Subject: [PATCH 22/25] net: bridge: Differentiate MDB additions from
|
||||
Subject: [PATCH 22/27] net: bridge: Differentiate MDB additions from
|
||||
modifications
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
Before this change, the reception of an IGMPv3 report (and analogously
|
||||
for MLDv2) that adds a new group, would trigger two MDB RTM_NEWMDB
|
||||
@@ -25,7 +22,7 @@ generated.
|
||||
Therefore, discriminate new groups from changes to existing groups by
|
||||
introducing a RTM_SETMDB events to be used in the latter scenario.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
include/uapi/linux/rtnetlink.h | 2 ++
|
||||
net/bridge/br_mdb.c | 4 ++--
|
||||
+4
-7
@@ -1,12 +1,9 @@
|
||||
From f0bbef0a94ed2e00475036b25dac8746e061c114 Mon Sep 17 00:00:00 2001
|
||||
From db0d727f6cc90ccea2378d876329c151db1670dc Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Fri, 24 Nov 2023 23:29:55 +0100
|
||||
Subject: [PATCH 23/25] nvmem: layouts: onie-tlv: Let device probe even when
|
||||
Subject: [PATCH 23/27] nvmem: layouts: onie-tlv: Let device probe even when
|
||||
TLV is invalid
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
Before this change, probing an NVMEM device, expected to contain a
|
||||
valid TLV, would fail if it had not been provisioned yet. But an
|
||||
@@ -17,7 +14,7 @@ be successfully probed.
|
||||
Therefore, settle for reporting data corruption issues in the log, and
|
||||
simply refrain from registering any cells in those cases.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/nvmem/layouts/onie-tlv.c | 6 +++---
|
||||
1 file changed, 3 insertions(+), 3 deletions(-)
|
||||
+4
-7
@@ -1,18 +1,15 @@
|
||||
From 7135f0ab4f04b5cea7a0b67df0fe91f925ef19df Mon Sep 17 00:00:00 2001
|
||||
From ed58f4b6e7344bdefceb7ac31d1c769a6d127827 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Mon, 29 Apr 2024 15:14:51 +0200
|
||||
Subject: [PATCH 24/25] usb: core: adjust log level for unauthorized devices
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Subject: [PATCH 24/27] usb: core: adjust log level for unauthorized devices
|
||||
Organization: Wires
|
||||
|
||||
The fact that a USB device currently is not authorized is not an error,
|
||||
so let's adjust the log level so these messages slip below radar for the
|
||||
commonly used 'quiet' log level.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/usb/core/driver.c | 4 ++--
|
||||
drivers/usb/core/generic.c | 2 +-
|
||||
+4
-7
@@ -1,12 +1,9 @@
|
||||
From 733067c41391c3b9f10d0bf62b1097dce9996df1 Mon Sep 17 00:00:00 2001
|
||||
From e7f7ae788680b4ec73af736453ec4afeb34d9842 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Thu, 16 Jan 2025 12:35:12 +0100
|
||||
Subject: [PATCH 25/25] net: dsa: mv88e6xxx: collapse disabled state into
|
||||
Subject: [PATCH 25/27] net: dsa: mv88e6xxx: collapse disabled state into
|
||||
blocking
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
This patch changes the behavior of switchcore ports wrt. the port state.
|
||||
Instead of disabling the port, the driver now treats the disabled state
|
||||
@@ -21,7 +18,7 @@ each member port, preventing LACPDUs from passing through to qualify the
|
||||
link and become active.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/dsa/mv88e6xxx/port.c | 2 --
|
||||
1 file changed, 2 deletions(-)
|
||||
+147
@@ -0,0 +1,147 @@
|
||||
From 823687aa03d866f3b76b5e40e35fa56c7f6f4492 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Wed, 12 Feb 2025 22:03:14 +0100
|
||||
Subject: [PATCH 26/27] net: dsa: mv88e6xxx: Only activate LAG offloading when
|
||||
bridged
|
||||
Organization: Wires
|
||||
|
||||
The current port isolation scheme for mv88e6xxx is detailed here:
|
||||
https://lore.kernel.org/netdev/20220203101657.990241-1-tobias@waldekranz.com/
|
||||
|
||||
As it turns out, this is not compatible with LAGs. Consider the
|
||||
following setup:
|
||||
|
||||
.-----.
|
||||
| CPU |
|
||||
'--+--'
|
||||
|
|
||||
.--0--. .-----.
|
||||
| sw1 9---0 sw2 |
|
||||
'-----' '-4-5-'
|
||||
|
||||
A LAG is created from sw2p{4,5}, using ID 0, but it is not attached
|
||||
to any bridge - so port isolation is active. Let's walk through a
|
||||
packet's journey to the CPU:
|
||||
|
||||
1. Packet ingresses sw2p4, the MapDA bit is not set, so it is flooded
|
||||
according to the PVT, which only contains sw2p0
|
||||
2. Packet egresses sw2p0 with FORWARD vid:0 dev:2 port:0(lag)
|
||||
3. Packet ingresses sw1p9, the VTU policy bit is set for VLAN 0, thus
|
||||
the packet is classified as MGMT and trapped to the CPU
|
||||
4. Packet egresses sw1p0 with TO_CPU vid:0 dev:2 port:0
|
||||
5. Packet ingresses CPU, since no user port is mapped to sw2p0 the
|
||||
packet is dropped
|
||||
|
||||
The problem is that in step 2, the original source port information is
|
||||
lost (replaced with "lag 0"), and then sw1 rewrites the ingressing
|
||||
FORWARD to a TO_CPU, which does not have a LAG bit. As a result, after
|
||||
the translation between steps 3 and 4, it now looks as if the packet
|
||||
originally ingressed on sw2p0.
|
||||
|
||||
Therefore, defer enabling the LAG offload until it joins a bridge. In
|
||||
the example above, it means that the original source port (sw2p4)
|
||||
information will be in the FORWARD sent in step 2, which allows the
|
||||
existing port isolation to work as intended.
|
||||
|
||||
Before joining a bridge, the offload does not offer any performance
|
||||
benefit anyway. All ingressing packet will always have to go to the
|
||||
CPU; egress traffic always relies on software hashing.
|
||||
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/dsa/mv88e6xxx/chip.c | 42 +++++++++++++++-----------------
|
||||
1 file changed, 20 insertions(+), 22 deletions(-)
|
||||
|
||||
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
index 30f8a5388733..c1f8adaa008a 100644
|
||||
--- a/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
|
||||
@@ -3095,6 +3095,7 @@ static int mv88e6xxx_port_bridge_join(struct dsa_switch *ds, int port,
|
||||
struct netlink_ext_ack *extack)
|
||||
{
|
||||
struct mv88e6xxx_chip *chip = ds->priv;
|
||||
+ unsigned int lagid;
|
||||
int err;
|
||||
|
||||
mv88e6xxx_reg_lock(chip);
|
||||
@@ -3103,6 +3104,13 @@ static int mv88e6xxx_port_bridge_join(struct dsa_switch *ds, int port,
|
||||
if (err)
|
||||
goto unlock;
|
||||
|
||||
+ if ((lagid = dsa_port_lag_id_get(dsa_to_port(ds, port)))) {
|
||||
+ /* DSA LAG IDs are one-based */
|
||||
+ err = mv88e6xxx_port_set_trunk(chip, port, true, lagid - 1);
|
||||
+ if (err)
|
||||
+ goto unlock;
|
||||
+ }
|
||||
+
|
||||
err = mv88e6xxx_port_set_map_da(chip, port, true);
|
||||
if (err)
|
||||
goto unlock;
|
||||
@@ -3147,6 +3155,14 @@ static void mv88e6xxx_port_bridge_leave(struct dsa_switch *ds, int port,
|
||||
"port %d failed to restore map-DA: %pe\n",
|
||||
port, ERR_PTR(err));
|
||||
|
||||
+ if (dsa_port_lag_id_get(dsa_to_port(ds, port))) {
|
||||
+ err = mv88e6xxx_port_set_trunk(chip, port, false, 0);
|
||||
+ if (err)
|
||||
+ dev_err(ds->dev,
|
||||
+ "port %d failed to disable trunking: %pe\n",
|
||||
+ port, ERR_PTR(err));
|
||||
+ }
|
||||
+
|
||||
err = mv88e6xxx_port_commit_pvid(chip, port);
|
||||
if (err)
|
||||
dev_err(ds->dev,
|
||||
@@ -7029,30 +7045,13 @@ static int mv88e6xxx_port_lag_join(struct dsa_switch *ds, int port,
|
||||
struct netlink_ext_ack *extack)
|
||||
{
|
||||
struct mv88e6xxx_chip *chip = ds->priv;
|
||||
- int err, id;
|
||||
+ int err;
|
||||
|
||||
if (!mv88e6xxx_lag_can_offload(ds, lag, info, extack))
|
||||
return -EOPNOTSUPP;
|
||||
|
||||
- /* DSA LAG IDs are one-based */
|
||||
- id = lag.id - 1;
|
||||
-
|
||||
mv88e6xxx_reg_lock(chip);
|
||||
-
|
||||
- err = mv88e6xxx_port_set_trunk(chip, port, true, id);
|
||||
- if (err)
|
||||
- goto err_unlock;
|
||||
-
|
||||
err = mv88e6xxx_lag_sync_masks_map(ds, lag);
|
||||
- if (err)
|
||||
- goto err_clear_trunk;
|
||||
-
|
||||
- mv88e6xxx_reg_unlock(chip);
|
||||
- return 0;
|
||||
-
|
||||
-err_clear_trunk:
|
||||
- mv88e6xxx_port_set_trunk(chip, port, false, 0);
|
||||
-err_unlock:
|
||||
mv88e6xxx_reg_unlock(chip);
|
||||
return err;
|
||||
}
|
||||
@@ -7061,13 +7060,12 @@ static int mv88e6xxx_port_lag_leave(struct dsa_switch *ds, int port,
|
||||
struct dsa_lag lag)
|
||||
{
|
||||
struct mv88e6xxx_chip *chip = ds->priv;
|
||||
- int err_sync, err_trunk;
|
||||
+ int err;
|
||||
|
||||
mv88e6xxx_reg_lock(chip);
|
||||
- err_sync = mv88e6xxx_lag_sync_masks_map(ds, lag);
|
||||
- err_trunk = mv88e6xxx_port_set_trunk(chip, port, false, 0);
|
||||
+ err = mv88e6xxx_lag_sync_masks_map(ds, lag);
|
||||
mv88e6xxx_reg_unlock(chip);
|
||||
- return err_sync ? : err_trunk;
|
||||
+ return err;
|
||||
}
|
||||
|
||||
static int mv88e6xxx_crosschip_lag_change(struct dsa_switch *ds, int sw_index,
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -0,0 +1,651 @@
|
||||
From f33dc6fb8cd78eb3b1b2ea3de68b8a54efabdac2 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
Date: Tue, 18 Mar 2025 10:55:09 +0100
|
||||
Subject: [PATCH 27/27] net: mvpp2: Prevent parser TCAM memory corruption
|
||||
Organization: Wires
|
||||
|
||||
Protect the parser TCAM/SRAM memory, and the cached (shadow) SRAM
|
||||
information, from concurrent modifications.
|
||||
|
||||
Both the TCAM and SRAM tables are indirectly accessed by configuring
|
||||
an index register that selects the row to read or write to. This means
|
||||
that operations must be atomic in order to, e.g., avoid spreading
|
||||
writes across multiple rows. Since the shadow SRAM array is used to
|
||||
find free rows in the hardware table, it must also be protected in
|
||||
order to avoid TOCTOU errors where multiple cores allocate the same
|
||||
row.
|
||||
|
||||
This issue was detected in a situation where `mvpp2_set_rx_mode()` ran
|
||||
concurrently on two CPUs. In this particular case the
|
||||
MVPP2_PE_MAC_UC_PROMISCUOUS entry was corrupted, causing the
|
||||
classifier unit to drop all incoming unicast - indicated by the
|
||||
`rx_classifier_drops` counter.
|
||||
|
||||
Fixes: 3f518509dedc ("ethernet: Add new driver for Marvell Armada 375 network unit")
|
||||
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
|
||||
---
|
||||
drivers/net/ethernet/marvell/mvpp2/mvpp2.h | 3 +
|
||||
.../net/ethernet/marvell/mvpp2/mvpp2_main.c | 3 +-
|
||||
.../net/ethernet/marvell/mvpp2/mvpp2_prs.c | 201 ++++++++++++------
|
||||
3 files changed, 140 insertions(+), 67 deletions(-)
|
||||
|
||||
diff --git a/drivers/net/ethernet/marvell/mvpp2/mvpp2.h b/drivers/net/ethernet/marvell/mvpp2/mvpp2.h
|
||||
index 9e02e4367bec..9bd3d76b5fe2 100644
|
||||
--- a/drivers/net/ethernet/marvell/mvpp2/mvpp2.h
|
||||
+++ b/drivers/net/ethernet/marvell/mvpp2/mvpp2.h
|
||||
@@ -1108,6 +1108,9 @@ struct mvpp2 {
|
||||
|
||||
/* Spinlocks for CM3 shared memory configuration */
|
||||
spinlock_t mss_spinlock;
|
||||
+
|
||||
+ /* Spinlock for shared PRS parser memory and shadow table */
|
||||
+ spinlock_t prs_spinlock;
|
||||
};
|
||||
|
||||
struct mvpp2_pcpu_stats {
|
||||
diff --git a/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c b/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
|
||||
index 3880dcc0418b..66b5a80c9c28 100644
|
||||
--- a/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
|
||||
+++ b/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
|
||||
@@ -7640,8 +7640,9 @@ static int mvpp2_probe(struct platform_device *pdev)
|
||||
if (mvpp2_read(priv, MVPP2_VER_ID_REG) == MVPP2_VER_PP23)
|
||||
priv->hw_version = MVPP23;
|
||||
|
||||
- /* Init mss lock */
|
||||
+ /* Init locks for shared packet processor resources */
|
||||
spin_lock_init(&priv->mss_spinlock);
|
||||
+ spin_lock_init(&priv->prs_spinlock);
|
||||
|
||||
/* Initialize network controller */
|
||||
err = mvpp2_init(pdev, priv);
|
||||
diff --git a/drivers/net/ethernet/marvell/mvpp2/mvpp2_prs.c b/drivers/net/ethernet/marvell/mvpp2/mvpp2_prs.c
|
||||
index 9af22f497a40..a96edc7dc0de 100644
|
||||
--- a/drivers/net/ethernet/marvell/mvpp2/mvpp2_prs.c
|
||||
+++ b/drivers/net/ethernet/marvell/mvpp2/mvpp2_prs.c
|
||||
@@ -23,6 +23,8 @@ static int mvpp2_prs_hw_write(struct mvpp2 *priv, struct mvpp2_prs_entry *pe)
|
||||
{
|
||||
int i;
|
||||
|
||||
+ lockdep_assert_held(&priv->prs_spinlock);
|
||||
+
|
||||
if (pe->index > MVPP2_PRS_TCAM_SRAM_SIZE - 1)
|
||||
return -EINVAL;
|
||||
|
||||
@@ -43,11 +45,13 @@ static int mvpp2_prs_hw_write(struct mvpp2 *priv, struct mvpp2_prs_entry *pe)
|
||||
}
|
||||
|
||||
/* Initialize tcam entry from hw */
|
||||
-int mvpp2_prs_init_from_hw(struct mvpp2 *priv, struct mvpp2_prs_entry *pe,
|
||||
- int tid)
|
||||
+static int mvpp2_prs_init_from_hw_unlocked(struct mvpp2 *priv,
|
||||
+ struct mvpp2_prs_entry *pe, int tid)
|
||||
{
|
||||
int i;
|
||||
|
||||
+ lockdep_assert_held(&priv->prs_spinlock);
|
||||
+
|
||||
if (tid > MVPP2_PRS_TCAM_SRAM_SIZE - 1)
|
||||
return -EINVAL;
|
||||
|
||||
@@ -73,6 +77,18 @@ int mvpp2_prs_init_from_hw(struct mvpp2 *priv, struct mvpp2_prs_entry *pe,
|
||||
return 0;
|
||||
}
|
||||
|
||||
+int mvpp2_prs_init_from_hw(struct mvpp2 *priv, struct mvpp2_prs_entry *pe,
|
||||
+ int tid)
|
||||
+{
|
||||
+ int err;
|
||||
+
|
||||
+ spin_lock_bh(&priv->prs_spinlock);
|
||||
+ err = mvpp2_prs_init_from_hw_unlocked(priv, pe, tid);
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
+
|
||||
+ return err;
|
||||
+}
|
||||
+
|
||||
/* Invalidate tcam hw entry */
|
||||
static void mvpp2_prs_hw_inv(struct mvpp2 *priv, int index)
|
||||
{
|
||||
@@ -374,7 +390,7 @@ static int mvpp2_prs_flow_find(struct mvpp2 *priv, int flow)
|
||||
priv->prs_shadow[tid].lu != MVPP2_PRS_LU_FLOWS)
|
||||
continue;
|
||||
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, tid);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
|
||||
bits = mvpp2_prs_sram_ai_get(&pe);
|
||||
|
||||
/* Sram store classification lookup ID in AI bits [5:0] */
|
||||
@@ -441,7 +457,7 @@ static void mvpp2_prs_mac_drop_all_set(struct mvpp2 *priv, int port, bool add)
|
||||
|
||||
if (priv->prs_shadow[MVPP2_PE_DROP_ALL].valid) {
|
||||
/* Entry exist - update port only */
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, MVPP2_PE_DROP_ALL);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, MVPP2_PE_DROP_ALL);
|
||||
} else {
|
||||
/* Entry doesn't exist - create new */
|
||||
memset(&pe, 0, sizeof(pe));
|
||||
@@ -469,14 +485,17 @@ static void mvpp2_prs_mac_drop_all_set(struct mvpp2 *priv, int port, bool add)
|
||||
}
|
||||
|
||||
/* Set port to unicast or multicast promiscuous mode */
|
||||
-void mvpp2_prs_mac_promisc_set(struct mvpp2 *priv, int port,
|
||||
- enum mvpp2_prs_l2_cast l2_cast, bool add)
|
||||
+static void mvpp2_prs_mac_promisc_set_unlocked(struct mvpp2 *priv, int port,
|
||||
+ enum mvpp2_prs_l2_cast l2_cast,
|
||||
+ bool add)
|
||||
{
|
||||
struct mvpp2_prs_entry pe;
|
||||
unsigned char cast_match;
|
||||
unsigned int ri;
|
||||
int tid;
|
||||
|
||||
+ lockdep_assert_held(&priv->prs_spinlock);
|
||||
+
|
||||
if (l2_cast == MVPP2_PRS_L2_UNI_CAST) {
|
||||
cast_match = MVPP2_PRS_UCAST_VAL;
|
||||
tid = MVPP2_PE_MAC_UC_PROMISCUOUS;
|
||||
@@ -489,7 +508,7 @@ void mvpp2_prs_mac_promisc_set(struct mvpp2 *priv, int port,
|
||||
|
||||
/* promiscuous mode - Accept unknown unicast or multicast packets */
|
||||
if (priv->prs_shadow[tid].valid) {
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, tid);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
|
||||
} else {
|
||||
memset(&pe, 0, sizeof(pe));
|
||||
mvpp2_prs_tcam_lu_set(&pe, MVPP2_PRS_LU_MAC);
|
||||
@@ -522,6 +541,14 @@ void mvpp2_prs_mac_promisc_set(struct mvpp2 *priv, int port,
|
||||
mvpp2_prs_hw_write(priv, &pe);
|
||||
}
|
||||
|
||||
+void mvpp2_prs_mac_promisc_set(struct mvpp2 *priv, int port,
|
||||
+ enum mvpp2_prs_l2_cast l2_cast, bool add)
|
||||
+{
|
||||
+ spin_lock_bh(&priv->prs_spinlock);
|
||||
+ mvpp2_prs_mac_promisc_set_unlocked(priv, port, l2_cast, add);
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
+}
|
||||
+
|
||||
/* Set entry for dsa packets */
|
||||
static void mvpp2_prs_dsa_tag_set(struct mvpp2 *priv, int port, bool add,
|
||||
bool tagged, bool extend)
|
||||
@@ -539,7 +566,7 @@ static void mvpp2_prs_dsa_tag_set(struct mvpp2 *priv, int port, bool add,
|
||||
|
||||
if (priv->prs_shadow[tid].valid) {
|
||||
/* Entry exist - update port only */
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, tid);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
|
||||
} else {
|
||||
/* Entry doesn't exist - create new */
|
||||
memset(&pe, 0, sizeof(pe));
|
||||
@@ -610,7 +637,7 @@ static void mvpp2_prs_dsa_tag_ethertype_set(struct mvpp2 *priv, int port,
|
||||
|
||||
if (priv->prs_shadow[tid].valid) {
|
||||
/* Entry exist - update port only */
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, tid);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
|
||||
} else {
|
||||
/* Entry doesn't exist - create new */
|
||||
memset(&pe, 0, sizeof(pe));
|
||||
@@ -673,7 +700,7 @@ static int mvpp2_prs_vlan_find(struct mvpp2 *priv, unsigned short tpid, int ai)
|
||||
priv->prs_shadow[tid].lu != MVPP2_PRS_LU_VLAN)
|
||||
continue;
|
||||
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, tid);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
|
||||
match = mvpp2_prs_tcam_data_cmp(&pe, 0, tpid);
|
||||
if (!match)
|
||||
continue;
|
||||
@@ -726,7 +753,7 @@ static int mvpp2_prs_vlan_add(struct mvpp2 *priv, unsigned short tpid, int ai,
|
||||
priv->prs_shadow[tid_aux].lu != MVPP2_PRS_LU_VLAN)
|
||||
continue;
|
||||
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, tid_aux);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid_aux);
|
||||
ri_bits = mvpp2_prs_sram_ri_get(&pe);
|
||||
if ((ri_bits & MVPP2_PRS_RI_VLAN_MASK) ==
|
||||
MVPP2_PRS_RI_VLAN_DOUBLE)
|
||||
@@ -760,7 +787,7 @@ static int mvpp2_prs_vlan_add(struct mvpp2 *priv, unsigned short tpid, int ai,
|
||||
|
||||
mvpp2_prs_shadow_set(priv, pe.index, MVPP2_PRS_LU_VLAN);
|
||||
} else {
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, tid);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
|
||||
}
|
||||
/* Update ports' mask */
|
||||
mvpp2_prs_tcam_port_map_set(&pe, port_map);
|
||||
@@ -800,7 +827,7 @@ static int mvpp2_prs_double_vlan_find(struct mvpp2 *priv, unsigned short tpid1,
|
||||
priv->prs_shadow[tid].lu != MVPP2_PRS_LU_VLAN)
|
||||
continue;
|
||||
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, tid);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
|
||||
|
||||
match = mvpp2_prs_tcam_data_cmp(&pe, 0, tpid1) &&
|
||||
mvpp2_prs_tcam_data_cmp(&pe, 4, tpid2);
|
||||
@@ -849,7 +876,7 @@ static int mvpp2_prs_double_vlan_add(struct mvpp2 *priv, unsigned short tpid1,
|
||||
priv->prs_shadow[tid_aux].lu != MVPP2_PRS_LU_VLAN)
|
||||
continue;
|
||||
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, tid_aux);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid_aux);
|
||||
ri_bits = mvpp2_prs_sram_ri_get(&pe);
|
||||
ri_bits &= MVPP2_PRS_RI_VLAN_MASK;
|
||||
if (ri_bits == MVPP2_PRS_RI_VLAN_SINGLE ||
|
||||
@@ -880,7 +907,7 @@ static int mvpp2_prs_double_vlan_add(struct mvpp2 *priv, unsigned short tpid1,
|
||||
|
||||
mvpp2_prs_shadow_set(priv, pe.index, MVPP2_PRS_LU_VLAN);
|
||||
} else {
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, tid);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
|
||||
}
|
||||
|
||||
/* Update ports' mask */
|
||||
@@ -1213,8 +1240,8 @@ static void mvpp2_prs_mac_init(struct mvpp2 *priv)
|
||||
/* Create dummy entries for drop all and promiscuous modes */
|
||||
mvpp2_prs_drop_fc(priv);
|
||||
mvpp2_prs_mac_drop_all_set(priv, 0, false);
|
||||
- mvpp2_prs_mac_promisc_set(priv, 0, MVPP2_PRS_L2_UNI_CAST, false);
|
||||
- mvpp2_prs_mac_promisc_set(priv, 0, MVPP2_PRS_L2_MULTI_CAST, false);
|
||||
+ mvpp2_prs_mac_promisc_set_unlocked(priv, 0, MVPP2_PRS_L2_UNI_CAST, false);
|
||||
+ mvpp2_prs_mac_promisc_set_unlocked(priv, 0, MVPP2_PRS_L2_MULTI_CAST, false);
|
||||
}
|
||||
|
||||
/* Set default entries for various types of dsa packets */
|
||||
@@ -1533,12 +1560,6 @@ static int mvpp2_prs_vlan_init(struct platform_device *pdev, struct mvpp2 *priv)
|
||||
struct mvpp2_prs_entry pe;
|
||||
int err;
|
||||
|
||||
- priv->prs_double_vlans = devm_kcalloc(&pdev->dev, sizeof(bool),
|
||||
- MVPP2_PRS_DBL_VLANS_MAX,
|
||||
- GFP_KERNEL);
|
||||
- if (!priv->prs_double_vlans)
|
||||
- return -ENOMEM;
|
||||
-
|
||||
/* Double VLAN: 0x88A8, 0x8100 */
|
||||
err = mvpp2_prs_double_vlan_add(priv, ETH_P_8021AD, ETH_P_8021Q,
|
||||
MVPP2_PRS_PORT_MASK);
|
||||
@@ -1941,7 +1962,7 @@ static int mvpp2_prs_vid_range_find(struct mvpp2_port *port, u16 vid, u16 mask)
|
||||
port->priv->prs_shadow[tid].lu != MVPP2_PRS_LU_VID)
|
||||
continue;
|
||||
|
||||
- mvpp2_prs_init_from_hw(port->priv, &pe, tid);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(port->priv, &pe, tid);
|
||||
|
||||
mvpp2_prs_tcam_data_byte_get(&pe, 2, &byte[0], &enable[0]);
|
||||
mvpp2_prs_tcam_data_byte_get(&pe, 3, &byte[1], &enable[1]);
|
||||
@@ -1970,6 +1991,8 @@ int mvpp2_prs_vid_entry_add(struct mvpp2_port *port, u16 vid)
|
||||
|
||||
memset(&pe, 0, sizeof(pe));
|
||||
|
||||
+ spin_lock_bh(&priv->prs_spinlock);
|
||||
+
|
||||
/* Scan TCAM and see if entry with this <vid,port> already exist */
|
||||
tid = mvpp2_prs_vid_range_find(port, vid, mask);
|
||||
|
||||
@@ -1988,8 +2011,10 @@ int mvpp2_prs_vid_entry_add(struct mvpp2_port *port, u16 vid)
|
||||
MVPP2_PRS_VLAN_FILT_MAX_ENTRY);
|
||||
|
||||
/* There isn't room for a new VID filter */
|
||||
- if (tid < 0)
|
||||
+ if (tid < 0) {
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
return tid;
|
||||
+ }
|
||||
|
||||
mvpp2_prs_tcam_lu_set(&pe, MVPP2_PRS_LU_VID);
|
||||
pe.index = tid;
|
||||
@@ -1997,7 +2022,7 @@ int mvpp2_prs_vid_entry_add(struct mvpp2_port *port, u16 vid)
|
||||
/* Mask all ports */
|
||||
mvpp2_prs_tcam_port_map_set(&pe, 0);
|
||||
} else {
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, tid);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
|
||||
}
|
||||
|
||||
/* Enable the current port */
|
||||
@@ -2019,6 +2044,7 @@ int mvpp2_prs_vid_entry_add(struct mvpp2_port *port, u16 vid)
|
||||
mvpp2_prs_shadow_set(priv, pe.index, MVPP2_PRS_LU_VID);
|
||||
mvpp2_prs_hw_write(priv, &pe);
|
||||
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -2028,15 +2054,16 @@ void mvpp2_prs_vid_entry_remove(struct mvpp2_port *port, u16 vid)
|
||||
struct mvpp2 *priv = port->priv;
|
||||
int tid;
|
||||
|
||||
- /* Scan TCAM and see if entry with this <vid,port> already exist */
|
||||
- tid = mvpp2_prs_vid_range_find(port, vid, 0xfff);
|
||||
+ spin_lock_bh(&priv->prs_spinlock);
|
||||
|
||||
- /* No such entry */
|
||||
- if (tid < 0)
|
||||
- return;
|
||||
+ /* Invalidate TCAM entry with this <vid,port>, if it exists */
|
||||
+ tid = mvpp2_prs_vid_range_find(port, vid, 0xfff);
|
||||
+ if (tid >= 0) {
|
||||
+ mvpp2_prs_hw_inv(priv, tid);
|
||||
+ priv->prs_shadow[tid].valid = false;
|
||||
+ }
|
||||
|
||||
- mvpp2_prs_hw_inv(priv, tid);
|
||||
- priv->prs_shadow[tid].valid = false;
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
}
|
||||
|
||||
/* Remove all existing VID filters on this port */
|
||||
@@ -2045,6 +2072,8 @@ void mvpp2_prs_vid_remove_all(struct mvpp2_port *port)
|
||||
struct mvpp2 *priv = port->priv;
|
||||
int tid;
|
||||
|
||||
+ spin_lock_bh(&priv->prs_spinlock);
|
||||
+
|
||||
for (tid = MVPP2_PRS_VID_PORT_FIRST(port->id);
|
||||
tid <= MVPP2_PRS_VID_PORT_LAST(port->id); tid++) {
|
||||
if (priv->prs_shadow[tid].valid) {
|
||||
@@ -2052,6 +2081,8 @@ void mvpp2_prs_vid_remove_all(struct mvpp2_port *port)
|
||||
priv->prs_shadow[tid].valid = false;
|
||||
}
|
||||
}
|
||||
+
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
}
|
||||
|
||||
/* Remove VID filering entry for this port */
|
||||
@@ -2060,10 +2091,14 @@ void mvpp2_prs_vid_disable_filtering(struct mvpp2_port *port)
|
||||
unsigned int tid = MVPP2_PRS_VID_PORT_DFLT(port->id);
|
||||
struct mvpp2 *priv = port->priv;
|
||||
|
||||
+ spin_lock_bh(&priv->prs_spinlock);
|
||||
+
|
||||
/* Invalidate the guard entry */
|
||||
mvpp2_prs_hw_inv(priv, tid);
|
||||
|
||||
priv->prs_shadow[tid].valid = false;
|
||||
+
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
}
|
||||
|
||||
/* Add guard entry that drops packets when no VID is matched on this port */
|
||||
@@ -2079,6 +2114,8 @@ void mvpp2_prs_vid_enable_filtering(struct mvpp2_port *port)
|
||||
|
||||
memset(&pe, 0, sizeof(pe));
|
||||
|
||||
+ spin_lock_bh(&priv->prs_spinlock);
|
||||
+
|
||||
pe.index = tid;
|
||||
|
||||
reg_val = mvpp2_read(priv, MVPP2_MH_REG(port->id));
|
||||
@@ -2111,6 +2148,8 @@ void mvpp2_prs_vid_enable_filtering(struct mvpp2_port *port)
|
||||
/* Update shadow table */
|
||||
mvpp2_prs_shadow_set(priv, pe.index, MVPP2_PRS_LU_VID);
|
||||
mvpp2_prs_hw_write(priv, &pe);
|
||||
+
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
}
|
||||
|
||||
/* Parser default initialization */
|
||||
@@ -2118,6 +2157,20 @@ int mvpp2_prs_default_init(struct platform_device *pdev, struct mvpp2 *priv)
|
||||
{
|
||||
int err, index, i;
|
||||
|
||||
+ priv->prs_shadow = devm_kcalloc(&pdev->dev, MVPP2_PRS_TCAM_SRAM_SIZE,
|
||||
+ sizeof(*priv->prs_shadow),
|
||||
+ GFP_KERNEL);
|
||||
+ if (!priv->prs_shadow)
|
||||
+ return -ENOMEM;
|
||||
+
|
||||
+ priv->prs_double_vlans = devm_kcalloc(&pdev->dev, sizeof(bool),
|
||||
+ MVPP2_PRS_DBL_VLANS_MAX,
|
||||
+ GFP_KERNEL);
|
||||
+ if (!priv->prs_double_vlans)
|
||||
+ return -ENOMEM;
|
||||
+
|
||||
+ spin_lock_bh(&priv->prs_spinlock);
|
||||
+
|
||||
/* Enable tcam table */
|
||||
mvpp2_write(priv, MVPP2_PRS_TCAM_CTRL_REG, MVPP2_PRS_TCAM_EN_MASK);
|
||||
|
||||
@@ -2136,12 +2189,6 @@ int mvpp2_prs_default_init(struct platform_device *pdev, struct mvpp2 *priv)
|
||||
for (index = 0; index < MVPP2_PRS_TCAM_SRAM_SIZE; index++)
|
||||
mvpp2_prs_hw_inv(priv, index);
|
||||
|
||||
- priv->prs_shadow = devm_kcalloc(&pdev->dev, MVPP2_PRS_TCAM_SRAM_SIZE,
|
||||
- sizeof(*priv->prs_shadow),
|
||||
- GFP_KERNEL);
|
||||
- if (!priv->prs_shadow)
|
||||
- return -ENOMEM;
|
||||
-
|
||||
/* Always start from lookup = 0 */
|
||||
for (index = 0; index < MVPP2_MAX_PORTS; index++)
|
||||
mvpp2_prs_hw_port_init(priv, index, MVPP2_PRS_LU_MH,
|
||||
@@ -2158,26 +2205,13 @@ int mvpp2_prs_default_init(struct platform_device *pdev, struct mvpp2 *priv)
|
||||
mvpp2_prs_vid_init(priv);
|
||||
|
||||
err = mvpp2_prs_etype_init(priv);
|
||||
- if (err)
|
||||
- return err;
|
||||
-
|
||||
- err = mvpp2_prs_vlan_init(pdev, priv);
|
||||
- if (err)
|
||||
- return err;
|
||||
-
|
||||
- err = mvpp2_prs_pppoe_init(priv);
|
||||
- if (err)
|
||||
- return err;
|
||||
-
|
||||
- err = mvpp2_prs_ip6_init(priv);
|
||||
- if (err)
|
||||
- return err;
|
||||
-
|
||||
- err = mvpp2_prs_ip4_init(priv);
|
||||
- if (err)
|
||||
- return err;
|
||||
+ err = err ? : mvpp2_prs_vlan_init(pdev, priv);
|
||||
+ err = err ? : mvpp2_prs_pppoe_init(priv);
|
||||
+ err = err ? : mvpp2_prs_ip6_init(priv);
|
||||
+ err = err ? : mvpp2_prs_ip4_init(priv);
|
||||
|
||||
- return 0;
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
+ return err;
|
||||
}
|
||||
|
||||
/* Compare MAC DA with tcam entry data */
|
||||
@@ -2217,7 +2251,7 @@ mvpp2_prs_mac_da_range_find(struct mvpp2 *priv, int pmap, const u8 *da,
|
||||
(priv->prs_shadow[tid].udf != udf_type))
|
||||
continue;
|
||||
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, tid);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
|
||||
entry_pmap = mvpp2_prs_tcam_port_map_get(&pe);
|
||||
|
||||
if (mvpp2_prs_mac_range_equals(&pe, da, mask) &&
|
||||
@@ -2229,7 +2263,8 @@ mvpp2_prs_mac_da_range_find(struct mvpp2 *priv, int pmap, const u8 *da,
|
||||
}
|
||||
|
||||
/* Update parser's mac da entry */
|
||||
-int mvpp2_prs_mac_da_accept(struct mvpp2_port *port, const u8 *da, bool add)
|
||||
+static int mvpp2_prs_mac_da_accept_unlocked(struct mvpp2_port *port,
|
||||
+ const u8 *da, bool add)
|
||||
{
|
||||
unsigned char mask[ETH_ALEN] = { 0xff, 0xff, 0xff, 0xff, 0xff, 0xff };
|
||||
struct mvpp2 *priv = port->priv;
|
||||
@@ -2261,7 +2296,7 @@ int mvpp2_prs_mac_da_accept(struct mvpp2_port *port, const u8 *da, bool add)
|
||||
/* Mask all ports */
|
||||
mvpp2_prs_tcam_port_map_set(&pe, 0);
|
||||
} else {
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, tid);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
|
||||
}
|
||||
|
||||
mvpp2_prs_tcam_lu_set(&pe, MVPP2_PRS_LU_MAC);
|
||||
@@ -2317,6 +2352,17 @@ int mvpp2_prs_mac_da_accept(struct mvpp2_port *port, const u8 *da, bool add)
|
||||
return 0;
|
||||
}
|
||||
|
||||
+int mvpp2_prs_mac_da_accept(struct mvpp2_port *port, const u8 *da, bool add)
|
||||
+{
|
||||
+ int err;
|
||||
+
|
||||
+ spin_lock_bh(&port->priv->prs_spinlock);
|
||||
+ err = mvpp2_prs_mac_da_accept_unlocked(port, da, add);
|
||||
+ spin_unlock_bh(&port->priv->prs_spinlock);
|
||||
+
|
||||
+ return err;
|
||||
+}
|
||||
+
|
||||
int mvpp2_prs_update_mac_da(struct net_device *dev, const u8 *da)
|
||||
{
|
||||
struct mvpp2_port *port = netdev_priv(dev);
|
||||
@@ -2345,6 +2391,8 @@ void mvpp2_prs_mac_del_all(struct mvpp2_port *port)
|
||||
unsigned long pmap;
|
||||
int index, tid;
|
||||
|
||||
+ spin_lock_bh(&priv->prs_spinlock);
|
||||
+
|
||||
for (tid = MVPP2_PE_MAC_RANGE_START;
|
||||
tid <= MVPP2_PE_MAC_RANGE_END; tid++) {
|
||||
unsigned char da[ETH_ALEN], da_mask[ETH_ALEN];
|
||||
@@ -2354,7 +2402,7 @@ void mvpp2_prs_mac_del_all(struct mvpp2_port *port)
|
||||
(priv->prs_shadow[tid].udf != MVPP2_PRS_UDF_MAC_DEF))
|
||||
continue;
|
||||
|
||||
- mvpp2_prs_init_from_hw(priv, &pe, tid);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
|
||||
|
||||
pmap = mvpp2_prs_tcam_port_map_get(&pe);
|
||||
|
||||
@@ -2375,14 +2423,17 @@ void mvpp2_prs_mac_del_all(struct mvpp2_port *port)
|
||||
continue;
|
||||
|
||||
/* Remove entry from TCAM */
|
||||
- mvpp2_prs_mac_da_accept(port, da, false);
|
||||
+ mvpp2_prs_mac_da_accept_unlocked(port, da, false);
|
||||
}
|
||||
+
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
}
|
||||
|
||||
int mvpp2_prs_tag_mode_set(struct mvpp2 *priv, int port, int type)
|
||||
{
|
||||
switch (type) {
|
||||
case MVPP2_TAG_TYPE_EDSA:
|
||||
+ spin_lock_bh(&priv->prs_spinlock);
|
||||
/* Add port to EDSA entries */
|
||||
mvpp2_prs_dsa_tag_set(priv, port, true,
|
||||
MVPP2_PRS_TAGGED, MVPP2_PRS_EDSA);
|
||||
@@ -2393,9 +2444,11 @@ int mvpp2_prs_tag_mode_set(struct mvpp2 *priv, int port, int type)
|
||||
MVPP2_PRS_TAGGED, MVPP2_PRS_DSA);
|
||||
mvpp2_prs_dsa_tag_set(priv, port, false,
|
||||
MVPP2_PRS_UNTAGGED, MVPP2_PRS_DSA);
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
break;
|
||||
|
||||
case MVPP2_TAG_TYPE_DSA:
|
||||
+ spin_lock_bh(&priv->prs_spinlock);
|
||||
/* Add port to DSA entries */
|
||||
mvpp2_prs_dsa_tag_set(priv, port, true,
|
||||
MVPP2_PRS_TAGGED, MVPP2_PRS_DSA);
|
||||
@@ -2406,10 +2459,12 @@ int mvpp2_prs_tag_mode_set(struct mvpp2 *priv, int port, int type)
|
||||
MVPP2_PRS_TAGGED, MVPP2_PRS_EDSA);
|
||||
mvpp2_prs_dsa_tag_set(priv, port, false,
|
||||
MVPP2_PRS_UNTAGGED, MVPP2_PRS_EDSA);
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
break;
|
||||
|
||||
case MVPP2_TAG_TYPE_MH:
|
||||
case MVPP2_TAG_TYPE_NONE:
|
||||
+ spin_lock_bh(&priv->prs_spinlock);
|
||||
/* Remove port form EDSA and DSA entries */
|
||||
mvpp2_prs_dsa_tag_set(priv, port, false,
|
||||
MVPP2_PRS_TAGGED, MVPP2_PRS_DSA);
|
||||
@@ -2419,6 +2474,7 @@ int mvpp2_prs_tag_mode_set(struct mvpp2 *priv, int port, int type)
|
||||
MVPP2_PRS_TAGGED, MVPP2_PRS_EDSA);
|
||||
mvpp2_prs_dsa_tag_set(priv, port, false,
|
||||
MVPP2_PRS_UNTAGGED, MVPP2_PRS_EDSA);
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
break;
|
||||
|
||||
default:
|
||||
@@ -2437,11 +2493,15 @@ int mvpp2_prs_add_flow(struct mvpp2 *priv, int flow, u32 ri, u32 ri_mask)
|
||||
|
||||
memset(&pe, 0, sizeof(pe));
|
||||
|
||||
+ spin_lock_bh(&priv->prs_spinlock);
|
||||
+
|
||||
tid = mvpp2_prs_tcam_first_free(priv,
|
||||
MVPP2_PE_LAST_FREE_TID,
|
||||
MVPP2_PE_FIRST_FREE_TID);
|
||||
- if (tid < 0)
|
||||
+ if (tid < 0) {
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
return tid;
|
||||
+ }
|
||||
|
||||
pe.index = tid;
|
||||
|
||||
@@ -2461,6 +2521,7 @@ int mvpp2_prs_add_flow(struct mvpp2 *priv, int flow, u32 ri, u32 ri_mask)
|
||||
mvpp2_prs_tcam_port_map_set(&pe, MVPP2_PRS_PORT_MASK);
|
||||
mvpp2_prs_hw_write(priv, &pe);
|
||||
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -2472,6 +2533,8 @@ int mvpp2_prs_def_flow(struct mvpp2_port *port)
|
||||
|
||||
memset(&pe, 0, sizeof(pe));
|
||||
|
||||
+ spin_lock_bh(&port->priv->prs_spinlock);
|
||||
+
|
||||
tid = mvpp2_prs_flow_find(port->priv, port->id);
|
||||
|
||||
/* Such entry not exist */
|
||||
@@ -2480,8 +2543,10 @@ int mvpp2_prs_def_flow(struct mvpp2_port *port)
|
||||
tid = mvpp2_prs_tcam_first_free(port->priv,
|
||||
MVPP2_PE_LAST_FREE_TID,
|
||||
MVPP2_PE_FIRST_FREE_TID);
|
||||
- if (tid < 0)
|
||||
+ if (tid < 0) {
|
||||
+ spin_unlock_bh(&port->priv->prs_spinlock);
|
||||
return tid;
|
||||
+ }
|
||||
|
||||
pe.index = tid;
|
||||
|
||||
@@ -2492,13 +2557,14 @@ int mvpp2_prs_def_flow(struct mvpp2_port *port)
|
||||
/* Update shadow table */
|
||||
mvpp2_prs_shadow_set(port->priv, pe.index, MVPP2_PRS_LU_FLOWS);
|
||||
} else {
|
||||
- mvpp2_prs_init_from_hw(port->priv, &pe, tid);
|
||||
+ mvpp2_prs_init_from_hw_unlocked(port->priv, &pe, tid);
|
||||
}
|
||||
|
||||
mvpp2_prs_tcam_lu_set(&pe, MVPP2_PRS_LU_FLOWS);
|
||||
mvpp2_prs_tcam_port_map_set(&pe, (1 << port->id));
|
||||
mvpp2_prs_hw_write(port->priv, &pe);
|
||||
|
||||
+ spin_unlock_bh(&port->priv->prs_spinlock);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -2509,11 +2575,14 @@ int mvpp2_prs_hits(struct mvpp2 *priv, int index)
|
||||
if (index > MVPP2_PRS_TCAM_SRAM_SIZE)
|
||||
return -EINVAL;
|
||||
|
||||
+ spin_lock_bh(&priv->prs_spinlock);
|
||||
+
|
||||
mvpp2_write(priv, MVPP2_PRS_TCAM_HIT_IDX_REG, index);
|
||||
|
||||
val = mvpp2_read(priv, MVPP2_PRS_TCAM_HIT_CNT_REG);
|
||||
|
||||
val &= MVPP2_PRS_TCAM_HIT_CNT_MASK;
|
||||
|
||||
+ spin_unlock_bh(&priv->prs_spinlock);
|
||||
return val;
|
||||
}
|
||||
--
|
||||
2.43.0
|
||||
|
||||
+2
-2
@@ -1,11 +1,11 @@
|
||||
From 2950046cd17bf9296a0b70b8f6b38114f6985864 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Thu, 22 Jun 2023 10:24:57 +0200
|
||||
Subject: [PATCH 1/3] Allow 'factory' as copy-from (only) in rpc copy-config
|
||||
Subject: [PATCH 1/4] Allow 'factory' as copy-from (only) in rpc copy-config
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
|
||||
+2
-2
@@ -1,11 +1,11 @@
|
||||
From d2e4e60838761e2bdd02d651b8e0bea47cc2dcb5 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Mattias=20Walstr=C3=B6m?= <lazzer@gmail.com>
|
||||
Date: Tue, 2 Jul 2024 14:56:15 +0200
|
||||
Subject: [PATCH 2/3] Disable local users (backwards compat with older model)
|
||||
Subject: [PATCH 2/4] Disable local users (backwards compat with older model)
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Addiva Elektronik
|
||||
Organization: Wires
|
||||
|
||||
Drop local-users, because if enabled netopeer require all users that
|
||||
should be allowed to use NETCONF to also be configured in the updated
|
||||
|
||||
@@ -0,0 +1,72 @@
|
||||
From 2f09813c91def7672c036c7f713302cb3a12cf18 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Mattias=20Walstr=C3=B6m?= <lazzer@gmail.com>
|
||||
Date: Tue, 4 Feb 2025 20:14:50 +0100
|
||||
Subject: [PATCH 4/4] Do not generate data in sysrepo
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Wires
|
||||
|
||||
We generate the host keys and configuration for netconf on boot, do not generate anything when
|
||||
building/installing netopeer2
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
---
|
||||
CMakeLists.txt | 40 ----------------------------------------
|
||||
1 file changed, 40 deletions(-)
|
||||
|
||||
diff --git a/CMakeLists.txt b/CMakeLists.txt
|
||||
index 4341be1..f1c4ae8 100644
|
||||
--- a/CMakeLists.txt
|
||||
+++ b/CMakeLists.txt
|
||||
@@ -383,47 +383,7 @@ if(SYSREPO_SETUP)
|
||||
message(FATAL_ERROR \" OUTPUT:\\n \${CMD_OUT_F}\\n ERROR:\\n \${CMD_ERR_F}\")
|
||||
endif()
|
||||
")
|
||||
-
|
||||
- # generate hostkey
|
||||
- install(CODE "
|
||||
- message(STATUS \"Generating a new RSA host key \\\"genkey\\\" if not already added (merge_hostkey.sh)...\")
|
||||
- set(ENV{SYSREPOCTL_EXECUTABLE} \"${SYSREPOCTL_EXECUTABLE}\")
|
||||
- set(ENV{SYSREPOCFG_EXECUTABLE} \"${SYSREPOCFG_EXECUTABLE}\")
|
||||
- execute_process(COMMAND \"\$ENV{DESTDIR}${DATA_DIR}/scripts/merge_hostkey.sh\"
|
||||
- RESULT_VARIABLE CMD_RES
|
||||
- OUTPUT_VARIABLE CMD_OUT
|
||||
- ERROR_VARIABLE CMD_ERR
|
||||
- OUTPUT_STRIP_TRAILING_WHITESPACE
|
||||
- ERROR_STRIP_TRAILING_WHITESPACE)
|
||||
- if(NOT CMD_RES EQUAL 0)
|
||||
- string(REPLACE \"\\n\" \"\\n \" CMD_OUT_F \"\${CMD_OUT}\")
|
||||
- string(REPLACE \"\\n\" \"\\n \" CMD_ERR_F \"\${CMD_ERR}\")
|
||||
- message(FATAL_ERROR \" OUTPUT:\\n \${CMD_OUT_F}\\n ERROR:\\n \${CMD_ERR_F}\")
|
||||
- endif()
|
||||
- ")
|
||||
-
|
||||
- # merge listen config
|
||||
- install(CODE "
|
||||
- message(STATUS \"Merging default server listen configuration if there is none (merge_config.sh)...\")
|
||||
- set(ENV{SYSREPOCTL_EXECUTABLE} \"${SYSREPOCTL_EXECUTABLE}\")
|
||||
- set(ENV{SYSREPOCFG_EXECUTABLE} \"${SYSREPOCFG_EXECUTABLE}\")
|
||||
- set(ENV{NP2_VERSION} \"${NP2SRV_VERSION}\")
|
||||
- execute_process(COMMAND \"\$ENV{DESTDIR}${DATA_DIR}/scripts/merge_config.sh\"
|
||||
- RESULT_VARIABLE CMD_RES
|
||||
- OUTPUT_VARIABLE CMD_OUT
|
||||
- ERROR_VARIABLE CMD_ERR
|
||||
- OUTPUT_STRIP_TRAILING_WHITESPACE
|
||||
- ERROR_STRIP_TRAILING_WHITESPACE)
|
||||
- if(NOT CMD_RES EQUAL 0)
|
||||
- string(REPLACE \"\\n\" \"\\n \" CMD_OUT_F \"\${CMD_OUT}\")
|
||||
- string(REPLACE \"\\n\" \"\\n \" CMD_ERR_F \"\${CMD_ERR}\")
|
||||
- message(FATAL_ERROR \" OUTPUT:\\n \${CMD_OUT_F}\\n ERROR:\\n \${CMD_ERR_F}\")
|
||||
- endif()
|
||||
- ")
|
||||
-else()
|
||||
- message(WARNING "Server will refuse to start if the modules are not installed!")
|
||||
endif()
|
||||
-
|
||||
# tests
|
||||
if(ENABLE_TESTS OR (BUILD_NETOPEER2_LIB AND NETOPEER2_LIB_TESTS))
|
||||
if(ENABLE_TESTS)
|
||||
--
|
||||
2.43.0
|
||||
|
||||
@@ -1,5 +1,15 @@
|
||||
--- a/agent/snmpd.c 2023-11-10 08:51:59.539942616 +0100
|
||||
+++ b/agent/snmpd.c 2023-11-10 08:56:27.719112830 +0100
|
||||
diff -urN netsnmp-5.9.3.orig/agent/snmpd.c netsnmp-5.9.3/agent/snmpd.c
|
||||
--- netsnmp-5.9.3.orig/agent/snmpd.c 2025-03-04 18:09:48.420162455 +0100
|
||||
+++ netsnmp-5.9.3/agent/snmpd.c 2025-03-04 18:13:48.149281606 +0100
|
||||
@@ -123,7 +123,7 @@
|
||||
# define PATH_MAX 255
|
||||
# endif
|
||||
#endif
|
||||
-
|
||||
+#include <sys/stat.h>
|
||||
#include <net-snmp/net-snmp-includes.h>
|
||||
#include <net-snmp/agent/net-snmp-agent-includes.h>
|
||||
#include "agent_global_vars.h"
|
||||
@@ -179,6 +179,7 @@
|
||||
#define TIMETICK 500000L
|
||||
|
||||
|
||||
@@ -1,12 +0,0 @@
|
||||
diff -ru openresolv-3.12.0.orig/resolvconf.in openresolv-3.12.0/resolvconf.in
|
||||
--- openresolv-3.12.0.orig/resolvconf.in 2020-12-27 19:05:10.000000000 +0100
|
||||
+++ openresolv-3.12.0/resolvconf.in 2023-03-27 00:19:03.365164029 +0200
|
||||
@@ -315,6 +315,8 @@
|
||||
then
|
||||
/usr/bin/systemctl restart $1.service
|
||||
fi'
|
||||
+ elif [ -x /sbin/initctl ]; then
|
||||
+ RESTARTCMD="/sbin/initctl -bnq restart \$1"
|
||||
elif [ -x /sbin/rc-service ] &&
|
||||
{ [ -s /libexec/rc/init.d/softlevel ] ||
|
||||
[ -s /run/openrc/softlevel ]; }
|
||||
@@ -1,16 +0,0 @@
|
||||
diff -ru openresolv-3.12.0.orig/resolvconf.in openresolv-3.12.0/resolvconf.in
|
||||
--- openresolv-3.12.0.orig/resolvconf.in 2020-12-27 19:05:10.000000000 +0100
|
||||
+++ openresolv-3.12.0/resolvconf.in 2023-03-27 00:19:03.365164029 +0200
|
||||
@@ -315,6 +315,12 @@
|
||||
then
|
||||
/usr/bin/systemctl restart $1.service
|
||||
fi'
|
||||
+ elif [ -x /sbin/initctl ]; then
|
||||
+ # Finit
|
||||
+ RESTARTCMD='
|
||||
+ if /sbin/initctl -bq status $1; then
|
||||
+ /sbin/initctl -bnq restart $1
|
||||
+ fi'
|
||||
elif [ -x /sbin/rc-service ] &&
|
||||
{ [ -s /libexec/rc/init.d/softlevel ] ||
|
||||
[ -s /run/openrc/softlevel ]; }
|
||||
@@ -0,0 +1,30 @@
|
||||
From 1aed761c6e4148d2800b73500df769dfee4fea6e Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Mattias=20Walstr=C3=B6m?= <lazzer@gmail.com>
|
||||
Date: Wed, 5 Mar 2025 08:38:22 +0100
|
||||
Subject: [PATCH] Remove pip-tools as a requirement
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
Organization: Wires
|
||||
|
||||
It is not used.
|
||||
|
||||
Signed-off-by: Mattias Walström <lazzer@gmail.com>
|
||||
---
|
||||
pyproject.toml | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/pyproject.toml b/pyproject.toml
|
||||
index 5b4eb3e..66b735b 100644
|
||||
--- a/pyproject.toml
|
||||
+++ b/pyproject.toml
|
||||
@@ -1,5 +1,5 @@
|
||||
[build-system]
|
||||
-requires = ["setuptools", "wheel", "pip-tools"]
|
||||
+requires = ["setuptools", "wheel"]
|
||||
build-backend = "setuptools.build_meta"
|
||||
|
||||
[project]
|
||||
--
|
||||
2.43.0
|
||||
|
||||
+13
-16
@@ -17,11 +17,11 @@ Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
src/main.c | 45 ++++++++++++++++++++++++++++++++++++++++++++-
|
||||
1 file changed, 44 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/main.c b/src/main.c
|
||||
index 70bb7b5..cfc8607 100644
|
||||
--- a/src/main.c
|
||||
+++ b/src/main.c
|
||||
@@ -9,6 +9,7 @@
|
||||
|
||||
diff -urN rauc-1.13.orig/src/main.c rauc-1.13/src/main.c
|
||||
--- rauc-1.13.orig/src/main.c 2025-03-04 14:55:59.671534612 +0100
|
||||
+++ rauc-1.13/src/main.c 2025-03-04 14:57:13.022772424 +0100
|
||||
@@ -10,6 +10,7 @@
|
||||
#include <locale.h>
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
@@ -29,7 +29,7 @@ index 70bb7b5..cfc8607 100644
|
||||
#include <sys/ioctl.h>
|
||||
#include <unistd.h>
|
||||
|
||||
@@ -1961,6 +1962,38 @@ static gboolean unknown_start(int argc, char **argv)
|
||||
@@ -2460,6 +2461,38 @@
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
@@ -68,25 +68,25 @@ index 70bb7b5..cfc8607 100644
|
||||
typedef enum {
|
||||
UNKNOWN = 0,
|
||||
INSTALL,
|
||||
@@ -2142,7 +2175,7 @@ static void create_option_groups(void)
|
||||
@@ -2676,7 +2709,7 @@
|
||||
|
||||
static void cmdline_handler(int argc, char **argv)
|
||||
{
|
||||
- gboolean help = FALSE, debug = FALSE, version = FALSE;
|
||||
+ gboolean help = FALSE, debug = FALSE, use_syslog = FALSE, version = FALSE;
|
||||
gchar *confpath = NULL, *keyring = NULL, **intermediate = NULL, *mount = NULL;
|
||||
g_autofree gchar *confpath = NULL, *keyring = NULL, *mount = NULL;
|
||||
char *cmdarg = NULL;
|
||||
g_autoptr(GOptionContext) context = NULL;
|
||||
@@ -2155,6 +2188,7 @@ static void cmdline_handler(int argc, char **argv)
|
||||
{"intermediate", '\0', 0, G_OPTION_ARG_FILENAME_ARRAY, &intermediate, "intermediate CA file name", "PEMFILE"},
|
||||
@@ -2690,6 +2723,7 @@
|
||||
{"intermediate", '\0', G_OPTION_FLAG_HIDDEN, G_OPTION_ARG_FILENAME_ARRAY, &intermediate, "intermediate CA file or PKCS#11 URL", "PEMFILE|PKCS11-URL"},
|
||||
{"mount", '\0', 0, G_OPTION_ARG_FILENAME, &mount, "mount prefix", "PATH"},
|
||||
{"debug", 'd', 0, G_OPTION_ARG_NONE, &debug, "enable debug output", NULL},
|
||||
+ {"syslog", 's', 0, G_OPTION_ARG_NONE, &use_syslog, "use syslog instead of stdout", NULL},
|
||||
{"version", '\0', 0, G_OPTION_ARG_NONE, &version, "display version", NULL},
|
||||
{"help", 'h', 0, G_OPTION_ARG_NONE, &help, NULL, NULL},
|
||||
{"help", 'h', 0, G_OPTION_ARG_NONE, &help, "display help and exit", NULL},
|
||||
{0}
|
||||
@@ -2269,6 +2303,15 @@ static void cmdline_handler(int argc, char **argv)
|
||||
g_message("Debug log domains: '%s'", domains);
|
||||
@@ -2816,6 +2850,15 @@
|
||||
);
|
||||
}
|
||||
|
||||
+ if (use_syslog) {
|
||||
@@ -101,6 +101,3 @@ index 70bb7b5..cfc8607 100644
|
||||
/* get first parameter without dashes */
|
||||
for (gint i = 1; i <= argc; i++) {
|
||||
if (argv[i] && !g_str_has_prefix(argv[i], "-")) {
|
||||
--
|
||||
2.34.1
|
||||
|
||||
@@ -1,29 +0,0 @@
|
||||
From 6d1d38458c911b281fa7da59ce01cec590bc1c64 Mon Sep 17 00:00:00 2001
|
||||
From: Joachim Wiberg <troglobit@gmail.com>
|
||||
Date: Thu, 23 Nov 2023 17:16:16 +0100
|
||||
Subject: [PATCH 1/2] src/bundle: enable tftp protocol
|
||||
Organization: Addiva Elektronik
|
||||
|
||||
Despite its age, TFTP still reigns strong in some sectors. Enable it
|
||||
for KernelKit//Infix.
|
||||
|
||||
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
|
||||
---
|
||||
src/bundle.c | 1 +
|
||||
1 file changed, 1 insertion(+)
|
||||
|
||||
diff --git a/src/bundle.c b/src/bundle.c
|
||||
index 05d4e72..b70e191 100644
|
||||
--- a/src/bundle.c
|
||||
+++ b/src/bundle.c
|
||||
@@ -1322,6 +1322,7 @@ static gboolean is_remote_scheme(const gchar *scheme)
|
||||
{
|
||||
return (g_strcmp0(scheme, "http") == 0) ||
|
||||
(g_strcmp0(scheme, "https") == 0) ||
|
||||
+ (g_strcmp0(scheme, "tftp") == 0) ||
|
||||
(g_strcmp0(scheme, "sftp") == 0) ||
|
||||
(g_strcmp0(scheme, "ftp") == 0);
|
||||
}
|
||||
--
|
||||
2.34.1
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user