Compare commits

...
Author SHA1 Message Date
Mattias Walström 52735154ad statd: yanger: Do not fail if rauc or /run/system.json is not found
This to be able to run statd outside infix.
2025-04-13 15:28:13 +02:00
Mattias WalströmandGitHub cc03a59725 Merge pull request #1013 from kernelkit/move-yang-models-to-confd
Move yang models to confd
2025-04-11 13:45:26 +02:00
Mattias Walström 092964a10b confd: Install *all* YANG modules from confd
Sysrepo, netopeer etc are still responsible to install the modules in
target directory, this will make that we will discover quickly if something
is updated.

Also this enables rm -rf output/target/etc/sysrepo/data/* && make confd-rebuild
This will reinstall all modules again.
2025-04-11 08:21:51 +02:00
Mattias Walström d0277de958 srload: Add support for multiple search directories 2025-04-11 08:21:50 +02:00
Mattias WalströmandGitHub 2df84e20af Merge pull request #1016 from kernelkit/fix-ssh-migrate
Fix migration when SSH server settings exist
2025-04-11 08:20:34 +02:00
Mattias WalströmandGitHub 9de4633c13 Merge pull request #1017 from kernelkit/update-kernel
Upgrade linux kernel to 6.12.23 (LTS)
2025-04-10 19:50:39 +02:00
Mattias Walström 50f955c242 Upgrade linux kernel to 6.12.23 (LTS) 2025-04-10 15:21:36 +02:00
Mattias Walström f2f539b492 Fix migration when SSH server settings exist
This fix #1015
2025-04-10 14:29:56 +02:00
Joachim WibergandGitHub 2b439298fb Merge pull request #1014 from kernelkit/fix-migrate-version 2025-04-09 17:04:06 +02:00
Richard Alpe 2ef759a9d8 confd: remove prefix from version leaf in migrate
Signed-off-by: Richard Alpe <richard@bit42.se>
2025-04-09 15:51:11 +02:00
Mattias WalströmandGitHub 6fe4db8431 Merge pull request #1011 from kernelkit/update-kernel
Update kernel to 6.12.22 (LTS)
2025-04-07 18:44:55 +02:00
Mattias Walström b2525e29e1 Upgrade linux kernel to 6.12.22 (LTS) 2025-04-07 18:26:07 +02:00
Joachim WibergandGitHub 7ef5223fca Merge pull request #1010 from kernelkit/netboot-doc
Netboot HowTo

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-04-07 17:57:56 +02:00
Joachim Wiberg 323bfc9d66 doc: add netboot howto, for developers
[skip ci]

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-04-07 17:56:59 +02:00
Mattias WalströmandGitHub d6be23fa6b Merge pull request #1012 from kernelkit/run-migrate-script-locally
Run migrate script locally
2025-04-07 17:07:21 +02:00
Mattias Walström c7c2998e33 Require a valid sha256 checksum for all package downloaded 2025-04-07 16:57:17 +02:00
Mattias Walström 184ed470d7 kernel-refresh.sh: Update linux hash on update 2025-04-07 16:57:17 +02:00
Richard Alpe 75352a9f77 confd: add no log option (-e) to migrate script
Write logs to stderr instead of syslog. Useful when running on a
non-target system.

Signed-off-by: Richard Alpe <richard@bit42.se>
2025-04-07 15:20:54 +02:00
Richard Alpe e3c601f2fd confd: add script path option (-s) to migrate script
This allows a user to run in on any system which has the Infix source
code that contains the modification scripts.

Signed-off-by: Richard Alpe <richard@bit42.se>
2025-04-07 15:09:36 +02:00
Richard Alpe 0ab9e2a36a confd: fix indentation of bin/migrate
Don't mix tabs and spaces.

Signed-off-by: Richard Alpe <richard@bit42.se>
2025-04-07 14:57:17 +02:00
Joachim WibergandGitHub 7b20665cf9 Merge pull request #1004 from kernelkit/new-show-command
Add new show command

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-04-07 14:34:35 +02:00
Mattias WalströmandGitHub 3d86ecd2ee Merge pull request #1005 from kernelkit/fix-images
Change type of disk image
2025-04-07 09:41:01 +02:00
Richard Alpe 403b79d370 test: update unit test data (cli/show-software)
The software list from sysrepo is no longer reversed, the reverse now
happens in cli-pretty. This commit reflects that.

Signed-off-by: Richard Alpe <richard@bit42.se>
2025-04-07 09:06:29 +02:00
Richard Alpe 740ecbcc43 cli: integrate (use) new show command in cli 2025-04-07 09:06:28 +02:00
Richard Alpe 42af6eec30 show: add bash tab-completions
Signed-off-by: Richard Alpe <richard@bit42.se>
2025-04-07 09:06:27 +02:00
Richard Alpe c584af356b show: add new show tool written in python3
The reason for this is:
1) We want to use the same fetch tool for all operational data, to
   avoid having duplicated xpaths scattered across the repo.
2) We want to call this directly from the CLI, which means it need to
   be escape safe. A unprivileged user shall be able to use it but not
   escape into a shell or do other malicious stuff.

Signed-off-by: Richard Alpe <richard@bit42.se>
2025-04-07 09:06:26 +02:00
Richard Alpe 827dc098e4 board/common: deprecate existing show command
There's several reasons for this. The main reason is that it was
developed as an intermediate way of getting system information when
the operational datastore was almost empty. There's not a lot of data
available in the operational datastore and we shall rely on that data
primarily. This command isn't safe to run from a jailed CLI as i
doesn't validate input and run commands directly in the shell, making
it hard to protect against a CLI jail break.

In upcoming patches we will introduce a new show tool that relies
solely on operational data and which sanitize the user input.

Signed-off-by: Richard Alpe <richard@bit42.se>
2025-04-07 09:06:25 +02:00
Richard Alpe bc5dd949d7 cli: fix indentation of infix.xml 2025-04-07 09:06:20 +02:00
Mattias Walström 4a932dec11 Update changelog for 2025.04 2025-04-07 08:20:21 +02:00
Mattias Walström d5c5e38604 CI: Store qcow2 disk images as release artififacts
This to make it easier to use  GNS3 appliance file from
GNS3 marketplace.
2025-04-07 08:16:34 +02:00
Mattias Walström 02080bfb6c qeneth: Move Infix test templates from qeneth to Infix 2025-04-07 08:16:33 +02:00
Mattias Walström d3fa51e4fa Use qcow2 for disk image instead of raw image
This make the release bundle much smaller, the disk image size
change from 512M to 2xsizeof(squashimage)
2025-04-07 08:16:33 +02:00
Mattias Walström 6cfe5f8c58 Fix symlink in release packages
Fix #1002
2025-04-07 08:16:33 +02:00
Mattias Walström b4f3e4eab8 migrate: Fix typo resulting in not logging correctly 2025-04-07 08:16:32 +02:00
Joachim WibergandGitHub b188e781ee Merge pull request #1007 from kernelkit/r2s-fixes
Fix NanoPi R2S Regression

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-04-07 08:16:09 +02:00
Joachim Wiberg 8156179f1b doc: update ChangeLog for v25.04 release cycle
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-04-07 06:22:19 +02:00
Joachim Wiberg 55632eebaa utils: update usage text with example, add -f
- Update usage text for readability, add example
 - Reindent getopts case and add -h
 - Allow 'git rm -f' to remove already staged patches

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-04-07 06:06:42 +02:00
Joachim Wiberg 71b11026bb configs/r2s_defconfig: bump kernel to 6.12.21 (LTS)
- Bump kernel to 6.12.21, same as other tier one boards
 - Fix #1006 byt enabling netlink for ethtool (now works!)
 - Sync defconfigs:
   - LIBXCRYPT now in an rdep of another package
   - Disable FORCE check hashes for now
 - Drop patches for 6.10 tree (r2s kernel)
 - Port RTL8153b patch for R2S LAN LED support

Fixes #1006

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-04-07 05:54:54 +02:00
Joachim Wiberg 2b28733fda confd: set correct file version of migrated files in backup
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-04-07 05:32:05 +02:00
Joachim Wiberg 8c115e17c4 board/common: set wheel group on /cfg/backup dir
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-04-07 05:32:05 +02:00
Mattias WalströmandGitHub 10f62f679b Merge pull request #1000 from kernelkit/logging-fixes
Misc. fixes related to logging found in -rc1
2025-03-31 15:08:10 +02:00
Joachim Wiberg fa4f7c6532 doc: update ChangeLog with fixes for -rc1 issues
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-31 13:49:34 +02:00
Joachim Wiberg 0647541988 patches/sysklogd: sync with latest version in Buildroot 2025.02
Buildroot 2025.02 currently has sysklogd v2.7.0, which has new features,
but also a few bugs.  This commit drops all patches for v2.5.2 and adds
all patches for sysklogd v2.7.2

For more information, see:

 - https://github.com/troglobit/sysklogd/releases/tag/v2.7.1
 - https://github.com/troglobit/sysklogd/releases/tag/v2.7.2

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-31 13:43:19 +02:00
Joachim Wiberg 2602ddc0b8 board/common: skip product init if no product specific dir
This silences a bogus warning in the log when runparts is called with no
argument.  I.e., when there is no product specific init files available.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-31 13:35:44 +02:00
Joachim Wiberg 3886b284d3 confd: fix invalid priority argument to logger
There is no such loglevel 'critical', only 'crit' is defined.

For some reason this issue has not been spotted until the upgrade to
Buildroot 2025.02, which includes sysklogd v2.7.0, and Finit v4.11.

Introduced in 3e48af6, when the concept of failure-config was added.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-31 13:14:34 +02:00
Joachim Wiberg 22a9405d1e confd: shellcheck fixes to load script
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-03-31 13:13:43 +02:00
218 changed files with 2004 additions and 5637 deletions
+11 -1
View File
@@ -95,6 +95,11 @@ jobs:
name: artifact-${{ matrix.target }}
path: output/*.tar.gz
- uses: actions/upload-artifact@v4
with:
name: artifact-disk-image-${{ matrix.target }}
path: output/images/*.qcow2
release:
name: Release Infix ${{ github.ref_name }}
needs: build
@@ -141,6 +146,11 @@ jobs:
for file in *.tar.gz; do
sha256sum $file > $file.sha256
done
if ls *.qcow2 &>/dev/null; then
for file in *.qcow2; do
sha256sum "$file" > "$file.sha256"
done
fi
- name: Extract ChangeLog entry ...
run: |
@@ -155,7 +165,7 @@ jobs:
makeLatest: ${{ steps.rel.outputs.latest }}
discussionCategory: ${{ steps.rel.outputs.cat }}
bodyFile: release.md
artifacts: "*.tar.gz*"
artifacts: "*.tar.gz*,*.qcow2*"
- name: Summary
run: |
-2
View File
@@ -230,7 +230,6 @@ CONFIG_MAC80211_LEDS=y
CONFIG_RFKILL=y
CONFIG_NET_9P=y
CONFIG_NET_9P_VIRTIO=y
# CONFIG_ETHTOOL_NETLINK is not set
CONFIG_PCI=y
CONFIG_PCIEPORTBUS=y
CONFIG_PCI_IOV=y
@@ -481,7 +480,6 @@ CONFIG_I2C=y
CONFIG_I2C_CHARDEV=y
CONFIG_I2C_MUX=y
CONFIG_I2C_MUX_PCA954x=y
CONFIG_I2C_DESIGNWARE_PLATFORM=y
CONFIG_I2C_GPIO=m
CONFIG_I2C_RK3X=y
CONFIG_I2C_SLAVE=y
+5 -3
View File
@@ -127,7 +127,7 @@ bootdata=
diskimg=disk.img
bootimg=
bootpart=
tmpimage=$(mktemp)
while getopts "a:b:B:n:s:" opt; do
case ${opt} in
a)
@@ -166,7 +166,7 @@ awk \
-vimgsize=$imgsize \
-vcfgsize=$cfgsize \
-vvarsize=$varsize \
-vdiskimg=$diskimg \
-vdiskimg=$tmpimage \
-vbootimg="$bootimg" -vbootpart="$bootpart" \
'{
sub(/@TOTALSIZE@/, total);
@@ -211,5 +211,7 @@ genimage \
--rootpath "$root" \
--tmppath "$tmp" \
--inputpath "$BINARIES_DIR" \
--outputpath "$BINARIES_DIR" \
--config "$root/genimage.cfg"
qemu-img convert -c -O qcow2 "$tmpimage" "$BINARIES_DIR/$diskimg"
rm "$tmpimage"
+3 -3
View File
@@ -23,7 +23,7 @@ if [ -n "$IMAGE_ID" ]; then
else
NAME="$INFIX_ID"-$(echo "$BR2_ARCH" | tr _ - | sed 's/x86-64/x86_64/')
fi
diskimg=disk.img
diskimg=disk.qcow2
ver()
{
@@ -48,7 +48,7 @@ fi
load_cfg DISK_IMAGE
if [ "$DISK_IMAGE" = "y" ]; then
ixmsg "Creating Disk Image"
diskimg="${NAME}-disk$(ver).img"
diskimg="${NAME}-disk$(ver).qcow2"
bootcfg=
if [ "$DISK_IMAGE_BOOT_DATA" ]; then
bootcfg="-b $DISK_IMAGE_BOOT_DATA -B $DISK_IMAGE_BOOT_OFFSET"
@@ -90,7 +90,7 @@ if [ "$BR2_TARGET_ROOTFS_SQUASHFS" = "y" ]; then
rel=$(ver)
ln -sf rootfs.squashfs "$BINARIES_DIR/${NAME}${rel}.img"
if [ -n "$rel" ]; then
ln -sf "$BINARIES_DIR/${NAME}${rel}.img" "$BINARIES_DIR/${NAME}.img"
ln -sf "${NAME}${rel}.img" "$BINARIES_DIR/${NAME}.img"
fi
fi
+5 -5
View File
@@ -120,7 +120,7 @@ rootfs_args()
echo -n "-device sd-card,drive=mmc "
echo -n "-drive id=mmc,file=$CONFIG_QEMU_ROOTFS,if=none,format=raw "
elif [ "$CONFIG_QEMU_ROOTFS_VSCSI" = "y" ]; then
echo -n "-drive file=$CONFIG_QEMU_ROOTFS.qcow2,if=virtio,format=qcow2,bus=0,unit=0 "
echo -n "-drive file=qemu.qcow2,if=virtio,format=qcow2,bus=0,unit=0 "
fi
}
@@ -316,13 +316,13 @@ gdb_args()
run_qemu()
{
if [ "$CONFIG_QEMU_ROOTFS_VSCSI" = "y" ]; then
if ! qemu-img check "${CONFIG_QEMU_ROOTFS}.qcow2"; then
rm -f "${CONFIG_QEMU_ROOTFS}.qcow2"
if ! qemu-img check "qemu.qcow2"; then
rm -f "qemu.qcow2"
fi
if [ ! -f "${CONFIG_QEMU_ROOTFS}.qcow2" ]; then
if [ ! -f "qemu.qcow2" ]; then
echo "Creating qcow2 disk image for Qemu ..."
qemu-img create -f qcow2 -o backing_file="$CONFIG_QEMU_ROOTFS" \
-F raw "${CONFIG_QEMU_ROOTFS}.qcow2" > /dev/null
-F qcow2 "qemu.qcow2" > /dev/null
fi
fi
@@ -39,8 +39,10 @@ fi
# init scripts to prevent select services from starting.
initctl -nbq cond set led
note "Calling runparts $PRODUCT_INIT/S[0-9]+.* start"
/usr/libexec/finit/runparts -bsp "$PRODUCT_INIT"
if [ -d "$PRODUCT_INIT" ]; then
note "Calling runparts $PRODUCT_INIT/S[0-9]+.* start"
/usr/libexec/finit/runparts -bsp "$PRODUCT_INIT"
fi
# Product specific init done.
initctl -nbq cond set product
@@ -4,10 +4,14 @@
# the migrate tool inserts old version in name before .cfg extension.
CONFIG_FILE="/cfg/startup-config.cfg"
BACKUP_FILE="/cfg/backup/startup-config.cfg"
mkdir -p "$(dirname "$BACKUP_FILE")"
BACKUP_DIR="$(dirname "$BACKUP_FILE")"
mkdir -p "$BACKUP_DIR"
chown root:wheel "$BACKUP_DIR"
chmod 0770 "$BACKUP_DIR"
if [ ! -f "$CONFIG_FILE" ]; then
note "No $(basename "$CONFIG_FILE" .cfg) yet, likely factory reset."
logger -I $$ -k -p user.notice -t $(basename "$0") "No $(basename "$CONFIG_FILE" .cfg) yet, likely factory reset."
exit 0
elif migrate -cq "$CONFIG_FILE"; then
exit 0
+3 -1
View File
@@ -27,7 +27,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.21"
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.23"
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
BR2_LINUX_KERNEL_INSTALL_TARGET=y
@@ -139,6 +139,7 @@ BR2_PACKAGE_CURIOS_HTTPD=y
BR2_PACKAGE_CURIOS_NFTABLES=y
BR2_PACKAGE_GENCERT=y
BR2_PACKAGE_STATD=y
BR2_PACKAGE_SHOW=y
BR2_PACKAGE_FACTORY=y
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
@@ -164,6 +165,7 @@ BR2_PACKAGE_TETRIS=y
BR2_PACKAGE_ROUSETTE=y
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
TRUSTED_KEYS=y
TRUSTED_KEYS_DEVELOPMENT=y
DISK_IMAGE_BOOT_BIN=y
+3 -1
View File
@@ -27,7 +27,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-build
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.21"
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.23"
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/linux_defconfig"
BR2_LINUX_KERNEL_INSTALL_TARGET=y
@@ -119,6 +119,7 @@ BR2_PACKAGE_CONFD=y
BR2_PACKAGE_CONFD_TEST_MODE=y
BR2_PACKAGE_GENCERT=y
BR2_PACKAGE_STATD=y
BR2_PACKAGE_SHOW=y
BR2_PACKAGE_FACTORY=y
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
@@ -137,6 +138,7 @@ BR2_PACKAGE_MDNS_ALIAS=y
BR2_PACKAGE_LIBINPUT=y
BR2_PACKAGE_ROUSETTE=y
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
DISK_IMAGE_BOOT_BIN=y
TRUSTED_KEYS=y
TRUSTED_KEYS_DEVELOPMENT=y
+4 -4
View File
@@ -8,7 +8,6 @@ BR2_CCACHE=y
BR2_CCACHE_DIR="${BR2_EXTERNAL_INFIX_PATH}/.ccache"
BR2_ENABLE_DEBUG=y
BR2_GLOBAL_PATCH_DIR="${BR2_EXTERNAL_INFIX_PATH}/patches"
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
BR2_TARGET_GENERIC_HOSTNAME="infix"
BR2_TARGET_GENERIC_ISSUE="Infix by KernelKit"
BR2_INIT_FINIT=y
@@ -30,7 +29,7 @@ BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image
BR2_ROOTFS_POST_SCRIPT_ARGS="-c $(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/r2s/genimage.cfg"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.10.3"
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.23"
BR2_LINUX_KERNEL_PATCH="$(BR2_EXTERNAL_INFIX_PATH)/board/aarch64/r2s/rk3328-nanopi-r2s-dts.patch"
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/aarch64/r2s/linux_defconfig"
@@ -74,7 +73,6 @@ BR2_PACKAGE_PYTHON_GUNICORN=y
BR2_PACKAGE_LIBSSH_OPENSSL=y
BR2_PACKAGE_LIBSSH2=y
BR2_PACKAGE_LIBSSH2_OPENSSL=y
BR2_PACKAGE_LIBXCRYPT=y
BR2_PACKAGE_LIBOPENSSL_BIN=y
BR2_PACKAGE_LIBINPUT=y
BR2_PACKAGE_LIBCURL_CURL=y
@@ -178,6 +176,7 @@ INFIX_SUPPORT="mailto:kernelkit@googlegroups.com"
BR2_PACKAGE_CONFD=y
BR2_PACKAGE_GENCERT=y
BR2_PACKAGE_STATD=y
BR2_PACKAGE_SHOW=y
BR2_PACKAGE_FACTORY=y
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
@@ -201,8 +200,9 @@ BR2_PACKAGE_PODMAN_DRIVER_DEVICEMAPPER=y
BR2_PACKAGE_PODMAN_DRIVER_VFS=y
BR2_PACKAGE_TETRIS=y
BR2_PACKAGE_ROUSETTE=y
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
TRUSTED_KEYS=y
TRUSTED_KEYS_DEVELOPMENT=y
# GNS3_APPLIANCE is not set
+2
View File
@@ -169,6 +169,7 @@ BR2_PACKAGE_CONFD=y
# BR2_PACKAGE_CONFD_TEST_MODE is not set
BR2_PACKAGE_GENCERT=y
BR2_PACKAGE_STATD=y
BR2_PACKAGE_SHOW=y
BR2_PACKAGE_FACTORY=y
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
@@ -194,6 +195,7 @@ BR2_PACKAGE_TETRIS=y
BR2_PACKAGE_ROUSETTE=y
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
TRUSTED_KEYS=y
TRUSTED_KEYS_DEVELOPMENT=y
# GNS3_APPLIANCE is not set
+3 -1
View File
@@ -26,7 +26,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INF
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.21"
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.23"
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
BR2_LINUX_KERNEL_INSTALL_TARGET=y
@@ -141,6 +141,7 @@ BR2_PACKAGE_CURIOS_HTTPD=y
BR2_PACKAGE_CURIOS_NFTABLES=y
BR2_PACKAGE_GENCERT=y
BR2_PACKAGE_STATD=y
BR2_PACKAGE_SHOW=y
BR2_PACKAGE_FACTORY=y
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
@@ -166,6 +167,7 @@ BR2_PACKAGE_TETRIS=y
BR2_PACKAGE_ROUSETTE=y
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
BR2_PACKAGE_HOST_PYTHON_YANGDOC=y
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
TRUSTED_KEYS=y
TRUSTED_KEYS_DEVELOPMENT=y
GNS3_APPLIANCE_RAM=512
+3 -1
View File
@@ -26,7 +26,7 @@ BR2_ROOTFS_POST_BUILD_SCRIPT="board/qemu/x86_64/post-build.sh ${BR2_EXTERNAL_INF
BR2_ROOTFS_POST_IMAGE_SCRIPT="${BR2_EXTERNAL_INFIX_PATH}/board/common/post-image.sh"
BR2_LINUX_KERNEL=y
BR2_LINUX_KERNEL_CUSTOM_VERSION=y
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.21"
BR2_LINUX_KERNEL_CUSTOM_VERSION_VALUE="6.12.23"
BR2_LINUX_KERNEL_USE_CUSTOM_CONFIG=y
BR2_LINUX_KERNEL_CUSTOM_CONFIG_FILE="${BR2_EXTERNAL_INFIX_PATH}/board/x86_64/linux_defconfig"
BR2_LINUX_KERNEL_INSTALL_TARGET=y
@@ -123,6 +123,7 @@ BR2_PACKAGE_CONFD=y
BR2_PACKAGE_CONFD_TEST_MODE=y
BR2_PACKAGE_GENCERT=y
BR2_PACKAGE_STATD=y
BR2_PACKAGE_SHOW=y
BR2_PACKAGE_FACTORY=y
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
@@ -140,6 +141,7 @@ BR2_PACKAGE_MCD=y
BR2_PACKAGE_MDNS_ALIAS=y
BR2_PACKAGE_ROUSETTE=y
BR2_PACKAGE_RAUC_INSTALLATION_STATUS=y
BR2_DOWNLOAD_FORCE_CHECK_HASHES=y
TRUSTED_KEYS=y
TRUSTED_KEYS_DEVELOPMENT=y
GNS3_APPLIANCE_RAM=512
+22
View File
@@ -4,6 +4,21 @@ Change Log
All notable changes to the project are documented in this file.
[v25.04.0][UNRELEASED]
-------------------------
### Changes
- Upgrade Linux kernel to 6.12.23 (LTS)
- Format for disk image (for QEMU) has changed to `qcow2`
### Fixes
- Fix #1002: Broken symlink in release package
- Fix #1006: NanoPi R2S corrupt startup, regression in Infix v25.02.0
- Bump R2S kernel, now same as tier one boards
- Fix #1015: Not possible to save custom SSH settings in startup-config
- Fix group owner and permissions of `/cfg/backup` directory
- Fix extraction of old version for `/cfg/backup/` files
[v25.03.0][] - 2025-03-31
-------------------------
@@ -21,6 +36,12 @@ All notable changes to the project are documented in this file.
- Fix #990: web console, ttyd service, stopped working after upgrade to
Buildroot 2025.02, caused by new (missing) option `--writable`
- Fix TCAM memory corruption in `mvpp2` Ethernet controller
- Fix annoying (but harmless) usage message from the logger tool when
`startup-config` fails to load and the system reverts to failure mode
- Fix harmless log warning for product specific init when no product
specific init scripts are found
- Backport fixes for sysklogd, affecting hostname filtering and periods
in TAG names, pending official backport in Buildroot
[v25.02.0][] - 2025-03-04
@@ -1524,6 +1545,7 @@ Supported YANG models in addition to those used by sysrepo and netopeer:
[buildroot]: https://buildroot.org/
[UNRELEASED]: https://github.com/kernelkit/infix/compare/v25.03.0...HEAD
[v25.04.0]: https://github.com/kernelkit/infix/compare/v25.03.0...v25.04.0
[v25.03.0]: https://github.com/kernelkit/infix/compare/v25.02.0...v25.03.0
[v25.02.0]: https://github.com/kernelkit/infix/compare/v25.01.0...v25.02.0
[v25.01.0]: https://github.com/kernelkit/infix/compare/v24.11.0...v25.01.0
+10 -5
View File
@@ -131,6 +131,8 @@ This rebuilds (and installs) `foo` and `bar`, the `all` target calls
on Buildroot to finalize the target filesystem and generate the images.
The final `run` argument is explained below.
### `confd`
The Infix `src/confd/` is the engine of the system. Currently it is a
@@ -217,21 +219,24 @@ structure of an existing one. However, before making any changes, **always discu
them with the Infix core team**. This helps avoid issues later in development and
makes pull request reviews smoother.
Testing
-------
Manual testing can be done using Qemu by calling <kbd>make run</kbd>,
see also [Infix in Virtual Environments](virtual.md).
see also [Infix in Virtual Environments](virtual.md), or on a physical
device by upgrading to the latest build or "[netbooting](netboot.md)"
and running the image from RAM. The latter is how most board porting
work is done -- **much quicker** change-load-test cycles.
The Infix automated test suite is built around Qemu and [Qeneth][2], see:
* [Testing](testing.md)
* [Docker Image](../test/docker/README.md)
With any new feature added to Infix, it is essential to include a
relevant test case. See the
[Test Development](testing.md#test-development) section for guidance
on adding test cases.
With any new feature added to Infix, it is essential to include relevant
test case(s). See the [Test Development](testing.md#test-development)
section for guidance on adding test cases.
Reviewing
+130
View File
@@ -0,0 +1,130 @@
Netboot HowTo
=============
This document describes how to set up network booting U-Boot devices on
a LAN, e.g., when working with an evaluation board or other embedded
system. The most secure way to do this is with a local LAN between a PC
and the device.
Instead of setting up everything in U-Boot to download the Linux Image,
device tree, and initramfs, we will let U-Boot download a script with
instructions to run. When you have multiple systems (boards) this
quickly becomes a lot easier to manage.
> [!NOTE]
> Instructions in this HowTo assume a Debian based development system,
> e.g., Ubuntu or Linux Mint.
## Network Interface Setup
For two dedicated network interfaces, here `eth2` and `eth3` (ymmv), we
create an old-style interfaces config[^1] with the following content:
```
# /etc/network/interfaces.d/gimli
auto eth2
iface eth2 inet static
address 192.168.0.1
netmask 255.255.255.0
auto eth3
iface eth3 inet manual
```
> [!TIP]
> Use configuration file names in `.d/` directories that make sense and
> can easily be remembered. Here we use the hostname of the PC.
## DHCP/TFTP Server Setup
The examples given here use `dnsmasq`, which provides both DHCP and TFTP
server support. The same can be achieved with other implementations.
Similar to `interfaces.d`, dnsmasq has an `/etc/dnsmasq.d` directory so
we can use "snippets" instead of modifying `/etc/dnsmasq.conf` directly.
Add a file called `/etc/dnsmasq.d/gimli`.
Initial content:
```
# Remember IP address handed out to BOOTP clients
bootp-dynamic
# Disable check-if-ip-address-is-already-used
no-ping
# Enable TFTP server, use /srv/ftp, same as any FTP server, useful
# when using the same images for system upgrade as for netbooting.
enable-tftp
tftp-root=/srv/ftp
```
> [!CAUTION]
> First of all, make sure you DO NOT accidentally set up dnsmasq so that
> it starts acting as a DHCP server also on your office LAN! Follow the
> instructions below for more details.
If you have many interfaces used for lab equipment and only one office
LAN interface, then use something like this:
```
# Disable DHCP server on loopback and office LAN (eth0)
except-interface=lo
except-interface=eth0
```
To further lock this down, we only run the DHCP server on each of the
interfaces used for lab equipment, with a dedicated IP range as well:
```
# Currently I have an imx8mp-evk on eth2, so on my system I have a
# symlink bootfile-eth2 -> netboot.scr
interface=eth2
dhcp-range=192.168.0.100,192.168.0.199,1h
dhcp-boot=tag:eth2,bootfile-eth2
```
## Bootfile netboot.scr
The bootfile U-Boot retrieves from the TFTP server is a script that
looks like this, `netboot.sh`:
```sh
setenv ramdisk_addr_r 0x58000000
setenv fdt_addr_r 0x50400000
setenv autoboot off
tftp ${fdt_addr_r} imx8mp-evk/imx8mp-evk.dtb
tftp ${kernel_addr_r} imx8mp-evk/Image
tftp ${ramdisk_addr_r} imx8mp-evk/rootfs.squashfs
setenv bootargs console=ttymxc1,115200 root=/dev/ram0 brd.rd_size=500000 rauc.slot=net
booti ${kernel_addr_r} ${ramdisk_addr_r}:${filesize} ${fdt_addr_r}
```
U-Boot cannot read script files directly, so we need to wrap it with a
FIT format header, this is done by first converting it on the PC:
```
$ mkimage -T script -d netboot.sh netboot.scr
```
The output is `netboot.scr` which we symlink to above in the dnsmasq
setup step.
## U-Boot Commands
U-Boot is a maze of environment variables, some with values, some wrap
commands, and most are undocumented. We will use a prefix for our
variables to ensure we do not overwrite anything you may want to use
later.
```sh
==> setenv ixboot 'dhcp && source \${fileaddr}'
==> saveenv
```
[^1]: To prevent NetworkManager from automatically managing the interfaces.
+1
View File
@@ -34,6 +34,7 @@ source "$BR2_EXTERNAL_INFIX_PATH/package/python-libyang/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/python-statd/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/python-yangdoc/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/skeleton-init-finit/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/show/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/tetris/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/libyang-cpp/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/sysrepo-cpp/Config.in"
+1 -1
View File
@@ -17,7 +17,7 @@ run name:startup log:prio:user.notice norestart <pid/confd> env:/etc/default/con
-- Loading startup-config
# Run if loading startup-config fails for some reason
run name:failure log:prio:user.critical norestart env:/etc/default/confd \
run name:failure log:prio:user.crit norestart env:/etc/default/confd \
if:<run/startup/failure> \
[S] <pid/confd> /usr/libexec/confd/load -t $CONFD_TIMEOUT failure-config \
-- Loading failure-config
+22 -3
View File
@@ -35,13 +35,30 @@ define CONFD_INSTALL_EXTRA
cp $(CONFD_PKGDIR)/avahi.service $(TARGET_DIR)/etc/avahi/services/netconf.service
endef
NETOPEER2_SEARCHPATH=$(TARGET_DIR)/usr/share/yang/modules/netopeer2/
SYSREPO_SEARCHPATH=$(TARGET_DIR)/usr/share/yang/modules/sysrepo/
LIBNETCONF2_SEARCHPATH=$(TARGET_DIR)/usr/share/yang/modules/libnetconf2/
CONFD_SEARCHPATH=$(TARGET_DIR)/usr/share/yang/modules/confd/
TEST_MODE_SEARCHPATH=$(TARGET_DIR)/usr/share/yang/modules/test-mode/
ROUSETTE_SEARCHPATH=$(TARGET_DIR)/usr/share/yang/modules/rousette/
COMMON_SYSREPO_ENV = \
SYSREPO_SHM_PREFIX=$(CONFD_SYSREPO_SHM_PREFIX) \
SYSREPOCTL_EXECUTABLE="$(HOST_DIR)/bin/sysrepoctl" \
SYSREPOCFG_EXECUTABLE="$(HOST_DIR)/bin/sysrepocfg" \
SEARCH_PATH="$(TARGET_DIR)/usr/share/yang/modules/confd/"
SEARCH_PATH="$(NETOPEER2_SEARCHPATH) $(SYSREPO_SEARCHPATH) $(LIBNETCONF2_SEARCHPATH) $(TEST_MODE_SEARCHPATH) $(CONFD_SEARCHPATH) $(ROUSETTE_SEARCHPATH)"
define CONFD_INSTALL_YANG_MODULES
$(COMMON_SYSREPO_ENV) \
$(BR2_EXTERNAL_INFIX_PATH)/utils/srload $(@D)/yang/sysrepo.inc
$(COMMON_SYSREPO_ENV) \
$(BR2_EXTERNAL_INFIX_PATH)/utils/srload $(@D)/yang/libnetconf2.inc
$(COMMON_SYSREPO_ENV) \
$(BR2_EXTERNAL_INFIX_PATH)/utils/srload $(@D)/yang/netopeer2.inc
$(COMMON_SYSREPO_ENV) \
$(BR2_EXTERNAL_INFIX_PATH)/utils/srload $(@D)/yang/rousette.inc
$(COMMON_SYSREPO_ENV) \
$(BR2_EXTERNAL_INFIX_PATH)/utils/srload $(@D)/yang/test-mode.inc
$(COMMON_SYSREPO_ENV) \
$(BR2_EXTERNAL_INFIX_PATH)/utils/srload $(@D)/yang/confd.inc
endef
@@ -57,11 +74,13 @@ define CONFD_PERMISSIONS
/etc/sysrepo/data/ r 660 root wheel - - - - -
/etc/sysrepo/data d 770 root wheel - - - - -
endef
define CONFD_EMPTY_SYSREPO
rm -rf $(TARGET_DIR)/etc/sysrepo/data/
endef
define CONFD_CLEANUP
rm -f /dev/shm/$(CONFD_SYSREPO_SHM_PREFIX)*
endef
CONFD_PRE_INSTALL_TARGET_HOOKS += CONFD_EMPTY_SYSREPO
CONFD_PRE_INSTALL_TARGET_HOOKS += CONFD_CLEANUP
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_EXTRA
CONFD_POST_INSTALL_TARGET_HOOKS += CONFD_INSTALL_YANG_MODULES
+6
View File
@@ -0,0 +1,6 @@
config BR2_PACKAGE_SHOW
bool "show"
help
Tool to retrieve and present operational data from sysrepo.
https://github.com/kernelkit/infix
+19
View File
@@ -0,0 +1,19 @@
################################################################################
#
# show
#
################################################################################
SHOW_VERSION = 1.0
SHOW_LICENSE = MIT
SHOW_LICENSE_FILES = LICENSE
SHOW_SITE_METHOD = local
SHOW_SITE = $(BR2_EXTERNAL_INFIX_PATH)/src/show
SHOW_REDISTRIBUTE = NO
define SHOW_INSTALL_TARGET_CMDS
$(TARGET_MAKE_ENV) $(TARGET_CONFIGURE_OPTS) $(MAKE) -C $(@D) \
DESTDIR="$(TARGET_DIR)" install
endef
$(eval $(generic-package))
@@ -1,236 +0,0 @@
From c2251e09714b9715ee5ece18aa1096bc08cb8f6d Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 4 Mar 2024 16:47:28 +0100
Subject: [PATCH 1/5] net: bridge: avoid classifying unknown multicast as
mrouters_only
Organization: Addiva Elektronik
Unknown multicast, MAC/IPv4/IPv6, should always be flooded according to
the per-port mcast_flood setting, as well as to detected and configured
mcast_router ports.
This patch drops the mrouters_only classifier of unknown IP multicast
and moves the flow handling from br_multicast_flood() to br_flood().
This in turn means br_flood() must know about multicast router ports.
Because a multicast router should always receive both known and unknown
multicast.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
include/uapi/linux/if_bridge.h | 1 +
net/bridge/br.c | 5 +++++
net/bridge/br_device.c | 10 ++++++----
net/bridge/br_forward.c | 14 ++++++++++++--
net/bridge/br_input.c | 2 +-
net/bridge/br_multicast.c | 11 +++++++++--
net/bridge/br_private.h | 18 ++++++++++++++++--
7 files changed, 50 insertions(+), 11 deletions(-)
diff --git a/include/uapi/linux/if_bridge.h b/include/uapi/linux/if_bridge.h
index a5b743a2f775..3bffc39d7800 100644
--- a/include/uapi/linux/if_bridge.h
+++ b/include/uapi/linux/if_bridge.h
@@ -830,6 +830,7 @@ enum br_boolopt_id {
BR_BOOLOPT_NO_LL_LEARN,
BR_BOOLOPT_MCAST_VLAN_SNOOPING,
BR_BOOLOPT_MST_ENABLE,
+ BR_BOOLOPT_MCAST_FLOOD_ALWAYS,
BR_BOOLOPT_MAX
};
diff --git a/net/bridge/br.c b/net/bridge/br.c
index 2cab878e0a39..006fb2e5eafb 100644
--- a/net/bridge/br.c
+++ b/net/bridge/br.c
@@ -277,6 +277,9 @@ int br_boolopt_toggle(struct net_bridge *br, enum br_boolopt_id opt, bool on,
case BR_BOOLOPT_MST_ENABLE:
err = br_mst_set_enabled(br, on, extack);
break;
+ case BR_BOOLOPT_MCAST_FLOOD_ALWAYS:
+ br_opt_toggle(br, BROPT_MCAST_FLOOD_ALWAYS, on);
+ break;
default:
/* shouldn't be called with unsupported options */
WARN_ON(1);
@@ -295,6 +298,8 @@ int br_boolopt_get(const struct net_bridge *br, enum br_boolopt_id opt)
return br_opt_get(br, BROPT_MCAST_VLAN_SNOOPING_ENABLED);
case BR_BOOLOPT_MST_ENABLE:
return br_opt_get(br, BROPT_MST_ENABLED);
+ case BR_BOOLOPT_MCAST_FLOOD_ALWAYS:
+ return br_opt_get(br, BROPT_MCAST_FLOOD_ALWAYS);
default:
/* shouldn't be called with unsupported options */
WARN_ON(1);
diff --git a/net/bridge/br_device.c b/net/bridge/br_device.c
index fb1115857e49..6aac21d86d37 100644
--- a/net/bridge/br_device.c
+++ b/net/bridge/br_device.c
@@ -87,10 +87,10 @@ netdev_tx_t br_dev_xmit(struct sk_buff *skb, struct net_device *dev)
dest = eth_hdr(skb)->h_dest;
if (is_broadcast_ether_addr(dest)) {
- br_flood(br, skb, BR_PKT_BROADCAST, false, true, vid);
+ br_flood(br, skb, NULL, BR_PKT_BROADCAST, false, true, vid);
} else if (is_multicast_ether_addr(dest)) {
if (unlikely(netpoll_tx_running(dev))) {
- br_flood(br, skb, BR_PKT_MULTICAST, false, true, vid);
+ br_flood(br, skb, brmctx, BR_PKT_MULTICAST, false, true, vid);
goto out;
}
if (br_multicast_rcv(&brmctx, &pmctx_null, vlan, skb, vid)) {
@@ -103,11 +103,11 @@ netdev_tx_t br_dev_xmit(struct sk_buff *skb, struct net_device *dev)
br_multicast_querier_exists(brmctx, eth_hdr(skb), mdst))
br_multicast_flood(mdst, skb, brmctx, false, true);
else
- br_flood(br, skb, BR_PKT_MULTICAST, false, true, vid);
+ br_flood(br, skb, brmctx, BR_PKT_MULTICAST, false, true, vid);
} else if ((dst = br_fdb_find_rcu(br, dest, vid)) != NULL) {
br_forward(dst->dst, skb, false, true);
} else {
- br_flood(br, skb, BR_PKT_UNICAST, false, true, vid);
+ br_flood(br, skb, NULL, BR_PKT_UNICAST, false, true, vid);
}
out:
rcu_read_unlock();
@@ -524,6 +524,8 @@ void br_dev_setup(struct net_device *dev)
br->bridge_ageing_time = br->ageing_time = BR_DEFAULT_AGEING_TIME;
dev->max_mtu = ETH_MAX_MTU;
+ br_opt_toggle(br, BROPT_MCAST_FLOOD_ALWAYS, false);
+
br_netfilter_rtable_init(br);
br_stp_timer_init(br);
br_multicast_init(br);
diff --git a/net/bridge/br_forward.c b/net/bridge/br_forward.c
index e19b583ff2c6..1094364d96e0 100644
--- a/net/bridge/br_forward.c
+++ b/net/bridge/br_forward.c
@@ -198,14 +198,19 @@ static struct net_bridge_port *maybe_deliver(
/* called under rcu_read_lock */
void br_flood(struct net_bridge *br, struct sk_buff *skb,
- enum br_pkt_type pkt_type, bool local_rcv, bool local_orig,
- u16 vid)
+ struct net_bridge_mcast *brmctx, enum br_pkt_type pkt_type,
+ bool local_rcv, bool local_orig, u16 vid)
{
+ struct net_bridge_port *rport = NULL;
struct net_bridge_port *prev = NULL;
+ struct hlist_node *rp = NULL;
struct net_bridge_port *p;
br_tc_skb_miss_set(skb, pkt_type != BR_PKT_BROADCAST);
+ if (pkt_type == BR_PKT_MULTICAST)
+ rp = br_multicast_get_first_rport_node(brmctx, skb);
+
list_for_each_entry_rcu(p, &br->port_list, list) {
/* Do not flood unicast traffic to ports that turn it off, nor
* other traffic if flood off, except for traffic we originate
@@ -216,6 +221,11 @@ void br_flood(struct net_bridge *br, struct sk_buff *skb,
continue;
break;
case BR_PKT_MULTICAST:
+ rport = br_multicast_rport_from_node_skb(rp, skb);
+ if (rport == p) {
+ rp = rcu_dereference(hlist_next_rcu(rp));
+ break;
+ }
if (!(p->flags & BR_MCAST_FLOOD) && skb->dev != br->dev)
continue;
break;
diff --git a/net/bridge/br_input.c b/net/bridge/br_input.c
index ceaa5a89b947..e54d648db7de 100644
--- a/net/bridge/br_input.c
+++ b/net/bridge/br_input.c
@@ -212,7 +212,7 @@ int br_handle_frame_finish(struct net *net, struct sock *sk, struct sk_buff *skb
br_forward(dst->dst, skb, local_rcv, false);
} else {
if (!mcast_hit)
- br_flood(br, skb, pkt_type, local_rcv, false, vid);
+ br_flood(br, skb, brmctx, pkt_type, local_rcv, false, vid);
else
br_multicast_flood(mdst, skb, brmctx, local_rcv, false);
}
diff --git a/net/bridge/br_multicast.c b/net/bridge/br_multicast.c
index 9a1cb5079a7a..dc49df4f92a8 100644
--- a/net/bridge/br_multicast.c
+++ b/net/bridge/br_multicast.c
@@ -3776,6 +3776,11 @@ static void br_multicast_err_count(const struct net_bridge *br,
u64_stats_update_end(&pstats->syncp);
}
+static bool br_flood_mrouters(const struct net_bridge *br)
+{
+ return br_opt_get(br, BROPT_MCAST_FLOOD_ALWAYS) ? false : true;
+}
+
static void br_multicast_pim(struct net_bridge_mcast *brmctx,
struct net_bridge_mcast_port *pmctx,
const struct sk_buff *skb)
@@ -3822,7 +3827,8 @@ static int br_multicast_ipv4_rcv(struct net_bridge_mcast *brmctx,
if (err == -ENOMSG) {
if (!ipv4_is_local_multicast(ip_hdr(skb)->daddr)) {
- BR_INPUT_SKB_CB(skb)->mrouters_only = 1;
+ BR_INPUT_SKB_CB(skb)->mrouters_only =
+ br_flood_mrouters(brmctx->br);
} else if (pim_ipv4_all_pim_routers(ip_hdr(skb)->daddr)) {
if (ip_hdr(skb)->protocol == IPPROTO_PIM)
br_multicast_pim(brmctx, pmctx, skb);
@@ -3891,7 +3897,8 @@ static int br_multicast_ipv6_rcv(struct net_bridge_mcast *brmctx,
if (err == -ENOMSG || err == -ENODATA) {
if (!ipv6_addr_is_ll_all_nodes(&ipv6_hdr(skb)->daddr))
- BR_INPUT_SKB_CB(skb)->mrouters_only = 1;
+ BR_INPUT_SKB_CB(skb)->mrouters_only =
+ br_flood_mrouters(brmctx->br);
if (err == -ENODATA &&
ipv6_addr_is_all_snoopers(&ipv6_hdr(skb)->daddr))
br_ip6_multicast_mrd_rcv(brmctx, pmctx, skb);
diff --git a/net/bridge/br_private.h b/net/bridge/br_private.h
index d4bedc87b1d8..dfd6e2cdd13e 100644
--- a/net/bridge/br_private.h
+++ b/net/bridge/br_private.h
@@ -483,6 +483,7 @@ enum net_bridge_opts {
BROPT_VLAN_BRIDGE_BINDING,
BROPT_MCAST_VLAN_SNOOPING_ENABLED,
BROPT_MST_ENABLED,
+ BROPT_MCAST_FLOOD_ALWAYS,
};
struct net_bridge {
@@ -886,8 +887,8 @@ void br_forward(const struct net_bridge_port *to, struct sk_buff *skb,
bool local_rcv, bool local_orig);
int br_forward_finish(struct net *net, struct sock *sk, struct sk_buff *skb);
void br_flood(struct net_bridge *br, struct sk_buff *skb,
- enum br_pkt_type pkt_type, bool local_rcv, bool local_orig,
- u16 vid);
+ struct net_bridge_mcast *brmctx, enum br_pkt_type pkt_type,
+ bool local_rcv, bool local_orig, u16 vid);
/* return true if both source port and dest port are isolated */
static inline bool br_skb_isolated(const struct net_bridge_port *to,
@@ -1408,6 +1409,19 @@ static inline void br_multicast_flood(struct net_bridge_mdb_entry *mdst,
{
}
+static inline struct hlist_node *
+br_multicast_get_first_rport_node(struct net_bridge_mcast *brmctx,
+ struct sk_buff *skb)
+{
+ return NULL;
+}
+
+static inline struct net_bridge_port *
+br_multicast_rport_from_node_skb(struct hlist_node *rp, struct sk_buff *skb)
+{
+ return NULL;
+}
+
static inline bool br_multicast_is_router(struct net_bridge_mcast *brmctx,
struct sk_buff *skb)
{
--
2.43.0
@@ -1,37 +0,0 @@
From 75edfa9b690b65423aa3e63ed5870d565950d9bb Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Tue, 5 Mar 2024 06:44:41 +0100
Subject: [PATCH 2/5] net: bridge: Ignore router ports when forwarding L2
multicast
Organization: Addiva Elektronik
Multicast router ports are either statically configured or learned from
control protocol traffic (IGMP/MLD/PIM). These protocols regulate IP
multicast -- MAC multicast should always be forwarded through flooding
of unknown multicast or using permanent MDB entries.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
net/bridge/br_private.h | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/net/bridge/br_private.h b/net/bridge/br_private.h
index dfd6e2cdd13e..7aabf8bd7da2 100644
--- a/net/bridge/br_private.h
+++ b/net/bridge/br_private.h
@@ -1086,7 +1086,10 @@ br_multicast_get_first_rport_node(struct net_bridge_mcast *brmctx,
if (skb->protocol == htons(ETH_P_IPV6))
return rcu_dereference(hlist_first_rcu(&brmctx->ip6_mc_router_list));
#endif
- return rcu_dereference(hlist_first_rcu(&brmctx->ip4_mc_router_list));
+ if (skb->protocol == htons(ETH_P_IP))
+ return rcu_dereference(hlist_first_rcu(&brmctx->ip4_mc_router_list));
+
+ return NULL;
}
static inline struct net_bridge_port *
--
2.43.0
@@ -1,190 +0,0 @@
From 2d2ac57a7d9354c2c1fa796659e33496fc8e918d Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Thu, 4 Apr 2024 16:36:30 +0200
Subject: [PATCH 3/5] net: bridge: drop delay for applying strict multicast
filtering
Organization: Addiva Elektronik
This *local* patch drops the initial delay before applying strict multicast
filtering, introduced in [1] and recently updated in [2].
The main reason for this patch is RFC conformance and customer expectations.
At power on we assume the querier role by default and are expected to stop
unknown flooding as soon as we have a membership report in place, not after
10 seconds.
A proper fix for upstreaming could be to add a knob to disable the delay.
[1]: https://lore.kernel.org/netdev/1375311980-25575-1-git-send-email-linus.luessing@web.de/
[2]: https://lore.kernel.org/netdev/20240127175033.9640-1-linus.luessing@c0d3.blue/
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
net/bridge/br_multicast.c | 42 +++++++--------------------------------
net/bridge/br_private.h | 4 +---
2 files changed, 8 insertions(+), 38 deletions(-)
diff --git a/net/bridge/br_multicast.c b/net/bridge/br_multicast.c
index dc49df4f92a8..47c0625c5553 100644
--- a/net/bridge/br_multicast.c
+++ b/net/bridge/br_multicast.c
@@ -1762,10 +1762,6 @@ static void br_ip6_multicast_querier_expired(struct timer_list *t)
}
#endif
-static void br_multicast_query_delay_expired(struct timer_list *t)
-{
-}
-
static void br_multicast_select_own_querier(struct net_bridge_mcast *brmctx,
struct br_ip *ip,
struct sk_buff *skb)
@@ -3198,12 +3194,8 @@ int br_multicast_dump_querier_state(struct sk_buff *skb,
static void
br_multicast_update_query_timer(struct net_bridge_mcast *brmctx,
- struct bridge_mcast_other_query *query,
- unsigned long max_delay)
+ struct bridge_mcast_other_query *query)
{
- if (!timer_pending(&query->timer))
- mod_timer(&query->delay_timer, jiffies + max_delay);
-
mod_timer(&query->timer, jiffies + brmctx->multicast_querier_interval);
}
@@ -3394,13 +3386,12 @@ static void
br_ip4_multicast_query_received(struct net_bridge_mcast *brmctx,
struct net_bridge_mcast_port *pmctx,
struct bridge_mcast_other_query *query,
- struct br_ip *saddr,
- unsigned long max_delay)
+ struct br_ip *saddr)
{
if (!br_multicast_select_querier(brmctx, pmctx, saddr))
return;
- br_multicast_update_query_timer(brmctx, query, max_delay);
+ br_multicast_update_query_timer(brmctx, query);
br_ip4_multicast_mark_router(brmctx, pmctx);
}
@@ -3409,13 +3400,12 @@ static void
br_ip6_multicast_query_received(struct net_bridge_mcast *brmctx,
struct net_bridge_mcast_port *pmctx,
struct bridge_mcast_other_query *query,
- struct br_ip *saddr,
- unsigned long max_delay)
+ struct br_ip *saddr)
{
if (!br_multicast_select_querier(brmctx, pmctx, saddr))
return;
- br_multicast_update_query_timer(brmctx, query, max_delay);
+ br_multicast_update_query_timer(brmctx, query);
br_ip6_multicast_mark_router(brmctx, pmctx);
}
#endif
@@ -3469,7 +3459,7 @@ static void br_ip4_multicast_query(struct net_bridge_mcast *brmctx,
br_ip4_multicast_query_received(brmctx, pmctx,
&brmctx->ip4_other_query,
- &saddr, max_delay);
+ &saddr);
goto out;
}
@@ -3557,7 +3547,7 @@ static int br_ip6_multicast_query(struct net_bridge_mcast *brmctx,
br_ip6_multicast_query_received(brmctx, pmctx,
&brmctx->ip6_other_query,
- &saddr, max_delay);
+ &saddr);
goto out;
} else if (!group) {
goto out;
@@ -4065,8 +4055,6 @@ void br_multicast_ctx_init(struct net_bridge *br,
br_ip4_multicast_local_router_expired, 0);
timer_setup(&brmctx->ip4_other_query.timer,
br_ip4_multicast_querier_expired, 0);
- timer_setup(&brmctx->ip4_other_query.delay_timer,
- br_multicast_query_delay_expired, 0);
timer_setup(&brmctx->ip4_own_query.timer,
br_ip4_multicast_query_expired, 0);
#if IS_ENABLED(CONFIG_IPV6)
@@ -4074,8 +4062,6 @@ void br_multicast_ctx_init(struct net_bridge *br,
br_ip6_multicast_local_router_expired, 0);
timer_setup(&brmctx->ip6_other_query.timer,
br_ip6_multicast_querier_expired, 0);
- timer_setup(&brmctx->ip6_other_query.delay_timer,
- br_multicast_query_delay_expired, 0);
timer_setup(&brmctx->ip6_own_query.timer,
br_ip6_multicast_query_expired, 0);
#endif
@@ -4210,12 +4196,10 @@ static void __br_multicast_stop(struct net_bridge_mcast *brmctx)
{
del_timer_sync(&brmctx->ip4_mc_router_timer);
del_timer_sync(&brmctx->ip4_other_query.timer);
- del_timer_sync(&brmctx->ip4_other_query.delay_timer);
del_timer_sync(&brmctx->ip4_own_query.timer);
#if IS_ENABLED(CONFIG_IPV6)
del_timer_sync(&brmctx->ip6_mc_router_timer);
del_timer_sync(&brmctx->ip6_other_query.timer);
- del_timer_sync(&brmctx->ip6_other_query.delay_timer);
del_timer_sync(&brmctx->ip6_own_query.timer);
#endif
}
@@ -4643,8 +4627,6 @@ EXPORT_SYMBOL_GPL(br_multicast_router);
int br_multicast_set_querier(struct net_bridge_mcast *brmctx, unsigned long val)
{
- unsigned long max_delay;
-
val = !!val;
spin_lock_bh(&brmctx->br->multicast_lock);
@@ -4655,19 +4637,9 @@ int br_multicast_set_querier(struct net_bridge_mcast *brmctx, unsigned long val)
if (!val)
goto unlock;
- max_delay = brmctx->multicast_query_response_interval;
-
- if (!timer_pending(&brmctx->ip4_other_query.timer))
- mod_timer(&brmctx->ip4_other_query.delay_timer,
- jiffies + max_delay);
-
br_multicast_start_querier(brmctx, &brmctx->ip4_own_query);
#if IS_ENABLED(CONFIG_IPV6)
- if (!timer_pending(&brmctx->ip6_other_query.timer))
- mod_timer(&brmctx->ip6_other_query.delay_timer,
- jiffies + max_delay);
-
br_multicast_start_querier(brmctx, &brmctx->ip6_own_query);
#endif
diff --git a/net/bridge/br_private.h b/net/bridge/br_private.h
index 7aabf8bd7da2..43fff09dfb71 100644
--- a/net/bridge/br_private.h
+++ b/net/bridge/br_private.h
@@ -78,7 +78,6 @@ struct bridge_mcast_own_query {
/* other querier */
struct bridge_mcast_other_query {
struct timer_list timer;
- struct timer_list delay_timer;
};
/* selected querier */
@@ -1164,8 +1163,7 @@ __br_multicast_querier_exists(struct net_bridge_mcast *brmctx,
own_querier_enabled = false;
}
- return !timer_pending(&querier->delay_timer) &&
- (own_querier_enabled || timer_pending(&querier->timer));
+ return own_querier_enabled || timer_pending(&querier->timer);
}
static inline bool br_multicast_querier_exists(struct net_bridge_mcast *brmctx,
--
2.43.0
@@ -1,49 +0,0 @@
From c7818c4273ef1705d6e153f5e4eda683d68f59be Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 29 Apr 2024 15:14:51 +0200
Subject: [PATCH 4/5] usb: core: adjust log level for unauthorized devices
Organization: Addiva Elektronik
The fact that a USB device currently is not authorized is not an error,
so let's adjust the log level so these messages slip below radar for the
commonly used 'quiet' log level.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
drivers/usb/core/driver.c | 4 ++--
drivers/usb/core/generic.c | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/usb/core/driver.c b/drivers/usb/core/driver.c
index e02ba15f6e34..3fe4d15cd6db 100644
--- a/drivers/usb/core/driver.c
+++ b/drivers/usb/core/driver.c
@@ -335,10 +335,10 @@ static int usb_probe_interface(struct device *dev)
return error;
if (udev->authorized == 0) {
- dev_err(&intf->dev, "Device is not authorized for usage\n");
+ dev_warn(&intf->dev, "Device is not authorized for usage\n");
return error;
} else if (intf->authorized == 0) {
- dev_err(&intf->dev, "Interface %d is not authorized for usage\n",
+ dev_warn(&intf->dev, "Interface %d is not authorized for usage\n",
intf->altsetting->desc.bInterfaceNumber);
return error;
}
diff --git a/drivers/usb/core/generic.c b/drivers/usb/core/generic.c
index b134bff5c3fe..60575a01a810 100644
--- a/drivers/usb/core/generic.c
+++ b/drivers/usb/core/generic.c
@@ -247,7 +247,7 @@ int usb_generic_driver_probe(struct usb_device *udev)
* with the driver core and lets interface drivers bind to them.
*/
if (udev->authorized == 0)
- dev_err(&udev->dev, "Device is not authorized for usage\n");
+ dev_warn(&udev->dev, "Device is not authorized for usage\n");
else {
c = usb_choose_configuration(udev);
if (c >= 0) {
--
2.43.0
@@ -1,651 +0,0 @@
From f33dc6fb8cd78eb3b1b2ea3de68b8a54efabdac2 Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Tue, 18 Mar 2025 10:55:09 +0100
Subject: [PATCH 27/27] net: mvpp2: Prevent parser TCAM memory corruption
Organization: Wires
Protect the parser TCAM/SRAM memory, and the cached (shadow) SRAM
information, from concurrent modifications.
Both the TCAM and SRAM tables are indirectly accessed by configuring
an index register that selects the row to read or write to. This means
that operations must be atomic in order to, e.g., avoid spreading
writes across multiple rows. Since the shadow SRAM array is used to
find free rows in the hardware table, it must also be protected in
order to avoid TOCTOU errors where multiple cores allocate the same
row.
This issue was detected in a situation where `mvpp2_set_rx_mode()` ran
concurrently on two CPUs. In this particular case the
MVPP2_PE_MAC_UC_PROMISCUOUS entry was corrupted, causing the
classifier unit to drop all incoming unicast - indicated by the
`rx_classifier_drops` counter.
Fixes: 3f518509dedc ("ethernet: Add new driver for Marvell Armada 375 network unit")
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/ethernet/marvell/mvpp2/mvpp2.h | 3 +
.../net/ethernet/marvell/mvpp2/mvpp2_main.c | 3 +-
.../net/ethernet/marvell/mvpp2/mvpp2_prs.c | 201 ++++++++++++------
3 files changed, 140 insertions(+), 67 deletions(-)
diff --git a/drivers/net/ethernet/marvell/mvpp2/mvpp2.h b/drivers/net/ethernet/marvell/mvpp2/mvpp2.h
index 9e02e4367bec..9bd3d76b5fe2 100644
--- a/drivers/net/ethernet/marvell/mvpp2/mvpp2.h
+++ b/drivers/net/ethernet/marvell/mvpp2/mvpp2.h
@@ -1108,6 +1108,9 @@ struct mvpp2 {
/* Spinlocks for CM3 shared memory configuration */
spinlock_t mss_spinlock;
+
+ /* Spinlock for shared PRS parser memory and shadow table */
+ spinlock_t prs_spinlock;
};
struct mvpp2_pcpu_stats {
diff --git a/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c b/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
index 3880dcc0418b..66b5a80c9c28 100644
--- a/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
+++ b/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
@@ -7640,8 +7640,9 @@ static int mvpp2_probe(struct platform_device *pdev)
if (mvpp2_read(priv, MVPP2_VER_ID_REG) == MVPP2_VER_PP23)
priv->hw_version = MVPP23;
- /* Init mss lock */
+ /* Init locks for shared packet processor resources */
spin_lock_init(&priv->mss_spinlock);
+ spin_lock_init(&priv->prs_spinlock);
/* Initialize network controller */
err = mvpp2_init(pdev, priv);
diff --git a/drivers/net/ethernet/marvell/mvpp2/mvpp2_prs.c b/drivers/net/ethernet/marvell/mvpp2/mvpp2_prs.c
index 9af22f497a40..a96edc7dc0de 100644
--- a/drivers/net/ethernet/marvell/mvpp2/mvpp2_prs.c
+++ b/drivers/net/ethernet/marvell/mvpp2/mvpp2_prs.c
@@ -23,6 +23,8 @@ static int mvpp2_prs_hw_write(struct mvpp2 *priv, struct mvpp2_prs_entry *pe)
{
int i;
+ lockdep_assert_held(&priv->prs_spinlock);
+
if (pe->index > MVPP2_PRS_TCAM_SRAM_SIZE - 1)
return -EINVAL;
@@ -43,11 +45,13 @@ static int mvpp2_prs_hw_write(struct mvpp2 *priv, struct mvpp2_prs_entry *pe)
}
/* Initialize tcam entry from hw */
-int mvpp2_prs_init_from_hw(struct mvpp2 *priv, struct mvpp2_prs_entry *pe,
- int tid)
+static int mvpp2_prs_init_from_hw_unlocked(struct mvpp2 *priv,
+ struct mvpp2_prs_entry *pe, int tid)
{
int i;
+ lockdep_assert_held(&priv->prs_spinlock);
+
if (tid > MVPP2_PRS_TCAM_SRAM_SIZE - 1)
return -EINVAL;
@@ -73,6 +77,18 @@ int mvpp2_prs_init_from_hw(struct mvpp2 *priv, struct mvpp2_prs_entry *pe,
return 0;
}
+int mvpp2_prs_init_from_hw(struct mvpp2 *priv, struct mvpp2_prs_entry *pe,
+ int tid)
+{
+ int err;
+
+ spin_lock_bh(&priv->prs_spinlock);
+ err = mvpp2_prs_init_from_hw_unlocked(priv, pe, tid);
+ spin_unlock_bh(&priv->prs_spinlock);
+
+ return err;
+}
+
/* Invalidate tcam hw entry */
static void mvpp2_prs_hw_inv(struct mvpp2 *priv, int index)
{
@@ -374,7 +390,7 @@ static int mvpp2_prs_flow_find(struct mvpp2 *priv, int flow)
priv->prs_shadow[tid].lu != MVPP2_PRS_LU_FLOWS)
continue;
- mvpp2_prs_init_from_hw(priv, &pe, tid);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
bits = mvpp2_prs_sram_ai_get(&pe);
/* Sram store classification lookup ID in AI bits [5:0] */
@@ -441,7 +457,7 @@ static void mvpp2_prs_mac_drop_all_set(struct mvpp2 *priv, int port, bool add)
if (priv->prs_shadow[MVPP2_PE_DROP_ALL].valid) {
/* Entry exist - update port only */
- mvpp2_prs_init_from_hw(priv, &pe, MVPP2_PE_DROP_ALL);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, MVPP2_PE_DROP_ALL);
} else {
/* Entry doesn't exist - create new */
memset(&pe, 0, sizeof(pe));
@@ -469,14 +485,17 @@ static void mvpp2_prs_mac_drop_all_set(struct mvpp2 *priv, int port, bool add)
}
/* Set port to unicast or multicast promiscuous mode */
-void mvpp2_prs_mac_promisc_set(struct mvpp2 *priv, int port,
- enum mvpp2_prs_l2_cast l2_cast, bool add)
+static void mvpp2_prs_mac_promisc_set_unlocked(struct mvpp2 *priv, int port,
+ enum mvpp2_prs_l2_cast l2_cast,
+ bool add)
{
struct mvpp2_prs_entry pe;
unsigned char cast_match;
unsigned int ri;
int tid;
+ lockdep_assert_held(&priv->prs_spinlock);
+
if (l2_cast == MVPP2_PRS_L2_UNI_CAST) {
cast_match = MVPP2_PRS_UCAST_VAL;
tid = MVPP2_PE_MAC_UC_PROMISCUOUS;
@@ -489,7 +508,7 @@ void mvpp2_prs_mac_promisc_set(struct mvpp2 *priv, int port,
/* promiscuous mode - Accept unknown unicast or multicast packets */
if (priv->prs_shadow[tid].valid) {
- mvpp2_prs_init_from_hw(priv, &pe, tid);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
} else {
memset(&pe, 0, sizeof(pe));
mvpp2_prs_tcam_lu_set(&pe, MVPP2_PRS_LU_MAC);
@@ -522,6 +541,14 @@ void mvpp2_prs_mac_promisc_set(struct mvpp2 *priv, int port,
mvpp2_prs_hw_write(priv, &pe);
}
+void mvpp2_prs_mac_promisc_set(struct mvpp2 *priv, int port,
+ enum mvpp2_prs_l2_cast l2_cast, bool add)
+{
+ spin_lock_bh(&priv->prs_spinlock);
+ mvpp2_prs_mac_promisc_set_unlocked(priv, port, l2_cast, add);
+ spin_unlock_bh(&priv->prs_spinlock);
+}
+
/* Set entry for dsa packets */
static void mvpp2_prs_dsa_tag_set(struct mvpp2 *priv, int port, bool add,
bool tagged, bool extend)
@@ -539,7 +566,7 @@ static void mvpp2_prs_dsa_tag_set(struct mvpp2 *priv, int port, bool add,
if (priv->prs_shadow[tid].valid) {
/* Entry exist - update port only */
- mvpp2_prs_init_from_hw(priv, &pe, tid);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
} else {
/* Entry doesn't exist - create new */
memset(&pe, 0, sizeof(pe));
@@ -610,7 +637,7 @@ static void mvpp2_prs_dsa_tag_ethertype_set(struct mvpp2 *priv, int port,
if (priv->prs_shadow[tid].valid) {
/* Entry exist - update port only */
- mvpp2_prs_init_from_hw(priv, &pe, tid);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
} else {
/* Entry doesn't exist - create new */
memset(&pe, 0, sizeof(pe));
@@ -673,7 +700,7 @@ static int mvpp2_prs_vlan_find(struct mvpp2 *priv, unsigned short tpid, int ai)
priv->prs_shadow[tid].lu != MVPP2_PRS_LU_VLAN)
continue;
- mvpp2_prs_init_from_hw(priv, &pe, tid);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
match = mvpp2_prs_tcam_data_cmp(&pe, 0, tpid);
if (!match)
continue;
@@ -726,7 +753,7 @@ static int mvpp2_prs_vlan_add(struct mvpp2 *priv, unsigned short tpid, int ai,
priv->prs_shadow[tid_aux].lu != MVPP2_PRS_LU_VLAN)
continue;
- mvpp2_prs_init_from_hw(priv, &pe, tid_aux);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid_aux);
ri_bits = mvpp2_prs_sram_ri_get(&pe);
if ((ri_bits & MVPP2_PRS_RI_VLAN_MASK) ==
MVPP2_PRS_RI_VLAN_DOUBLE)
@@ -760,7 +787,7 @@ static int mvpp2_prs_vlan_add(struct mvpp2 *priv, unsigned short tpid, int ai,
mvpp2_prs_shadow_set(priv, pe.index, MVPP2_PRS_LU_VLAN);
} else {
- mvpp2_prs_init_from_hw(priv, &pe, tid);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
}
/* Update ports' mask */
mvpp2_prs_tcam_port_map_set(&pe, port_map);
@@ -800,7 +827,7 @@ static int mvpp2_prs_double_vlan_find(struct mvpp2 *priv, unsigned short tpid1,
priv->prs_shadow[tid].lu != MVPP2_PRS_LU_VLAN)
continue;
- mvpp2_prs_init_from_hw(priv, &pe, tid);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
match = mvpp2_prs_tcam_data_cmp(&pe, 0, tpid1) &&
mvpp2_prs_tcam_data_cmp(&pe, 4, tpid2);
@@ -849,7 +876,7 @@ static int mvpp2_prs_double_vlan_add(struct mvpp2 *priv, unsigned short tpid1,
priv->prs_shadow[tid_aux].lu != MVPP2_PRS_LU_VLAN)
continue;
- mvpp2_prs_init_from_hw(priv, &pe, tid_aux);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid_aux);
ri_bits = mvpp2_prs_sram_ri_get(&pe);
ri_bits &= MVPP2_PRS_RI_VLAN_MASK;
if (ri_bits == MVPP2_PRS_RI_VLAN_SINGLE ||
@@ -880,7 +907,7 @@ static int mvpp2_prs_double_vlan_add(struct mvpp2 *priv, unsigned short tpid1,
mvpp2_prs_shadow_set(priv, pe.index, MVPP2_PRS_LU_VLAN);
} else {
- mvpp2_prs_init_from_hw(priv, &pe, tid);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
}
/* Update ports' mask */
@@ -1213,8 +1240,8 @@ static void mvpp2_prs_mac_init(struct mvpp2 *priv)
/* Create dummy entries for drop all and promiscuous modes */
mvpp2_prs_drop_fc(priv);
mvpp2_prs_mac_drop_all_set(priv, 0, false);
- mvpp2_prs_mac_promisc_set(priv, 0, MVPP2_PRS_L2_UNI_CAST, false);
- mvpp2_prs_mac_promisc_set(priv, 0, MVPP2_PRS_L2_MULTI_CAST, false);
+ mvpp2_prs_mac_promisc_set_unlocked(priv, 0, MVPP2_PRS_L2_UNI_CAST, false);
+ mvpp2_prs_mac_promisc_set_unlocked(priv, 0, MVPP2_PRS_L2_MULTI_CAST, false);
}
/* Set default entries for various types of dsa packets */
@@ -1533,12 +1560,6 @@ static int mvpp2_prs_vlan_init(struct platform_device *pdev, struct mvpp2 *priv)
struct mvpp2_prs_entry pe;
int err;
- priv->prs_double_vlans = devm_kcalloc(&pdev->dev, sizeof(bool),
- MVPP2_PRS_DBL_VLANS_MAX,
- GFP_KERNEL);
- if (!priv->prs_double_vlans)
- return -ENOMEM;
-
/* Double VLAN: 0x88A8, 0x8100 */
err = mvpp2_prs_double_vlan_add(priv, ETH_P_8021AD, ETH_P_8021Q,
MVPP2_PRS_PORT_MASK);
@@ -1941,7 +1962,7 @@ static int mvpp2_prs_vid_range_find(struct mvpp2_port *port, u16 vid, u16 mask)
port->priv->prs_shadow[tid].lu != MVPP2_PRS_LU_VID)
continue;
- mvpp2_prs_init_from_hw(port->priv, &pe, tid);
+ mvpp2_prs_init_from_hw_unlocked(port->priv, &pe, tid);
mvpp2_prs_tcam_data_byte_get(&pe, 2, &byte[0], &enable[0]);
mvpp2_prs_tcam_data_byte_get(&pe, 3, &byte[1], &enable[1]);
@@ -1970,6 +1991,8 @@ int mvpp2_prs_vid_entry_add(struct mvpp2_port *port, u16 vid)
memset(&pe, 0, sizeof(pe));
+ spin_lock_bh(&priv->prs_spinlock);
+
/* Scan TCAM and see if entry with this <vid,port> already exist */
tid = mvpp2_prs_vid_range_find(port, vid, mask);
@@ -1988,8 +2011,10 @@ int mvpp2_prs_vid_entry_add(struct mvpp2_port *port, u16 vid)
MVPP2_PRS_VLAN_FILT_MAX_ENTRY);
/* There isn't room for a new VID filter */
- if (tid < 0)
+ if (tid < 0) {
+ spin_unlock_bh(&priv->prs_spinlock);
return tid;
+ }
mvpp2_prs_tcam_lu_set(&pe, MVPP2_PRS_LU_VID);
pe.index = tid;
@@ -1997,7 +2022,7 @@ int mvpp2_prs_vid_entry_add(struct mvpp2_port *port, u16 vid)
/* Mask all ports */
mvpp2_prs_tcam_port_map_set(&pe, 0);
} else {
- mvpp2_prs_init_from_hw(priv, &pe, tid);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
}
/* Enable the current port */
@@ -2019,6 +2044,7 @@ int mvpp2_prs_vid_entry_add(struct mvpp2_port *port, u16 vid)
mvpp2_prs_shadow_set(priv, pe.index, MVPP2_PRS_LU_VID);
mvpp2_prs_hw_write(priv, &pe);
+ spin_unlock_bh(&priv->prs_spinlock);
return 0;
}
@@ -2028,15 +2054,16 @@ void mvpp2_prs_vid_entry_remove(struct mvpp2_port *port, u16 vid)
struct mvpp2 *priv = port->priv;
int tid;
- /* Scan TCAM and see if entry with this <vid,port> already exist */
- tid = mvpp2_prs_vid_range_find(port, vid, 0xfff);
+ spin_lock_bh(&priv->prs_spinlock);
- /* No such entry */
- if (tid < 0)
- return;
+ /* Invalidate TCAM entry with this <vid,port>, if it exists */
+ tid = mvpp2_prs_vid_range_find(port, vid, 0xfff);
+ if (tid >= 0) {
+ mvpp2_prs_hw_inv(priv, tid);
+ priv->prs_shadow[tid].valid = false;
+ }
- mvpp2_prs_hw_inv(priv, tid);
- priv->prs_shadow[tid].valid = false;
+ spin_unlock_bh(&priv->prs_spinlock);
}
/* Remove all existing VID filters on this port */
@@ -2045,6 +2072,8 @@ void mvpp2_prs_vid_remove_all(struct mvpp2_port *port)
struct mvpp2 *priv = port->priv;
int tid;
+ spin_lock_bh(&priv->prs_spinlock);
+
for (tid = MVPP2_PRS_VID_PORT_FIRST(port->id);
tid <= MVPP2_PRS_VID_PORT_LAST(port->id); tid++) {
if (priv->prs_shadow[tid].valid) {
@@ -2052,6 +2081,8 @@ void mvpp2_prs_vid_remove_all(struct mvpp2_port *port)
priv->prs_shadow[tid].valid = false;
}
}
+
+ spin_unlock_bh(&priv->prs_spinlock);
}
/* Remove VID filering entry for this port */
@@ -2060,10 +2091,14 @@ void mvpp2_prs_vid_disable_filtering(struct mvpp2_port *port)
unsigned int tid = MVPP2_PRS_VID_PORT_DFLT(port->id);
struct mvpp2 *priv = port->priv;
+ spin_lock_bh(&priv->prs_spinlock);
+
/* Invalidate the guard entry */
mvpp2_prs_hw_inv(priv, tid);
priv->prs_shadow[tid].valid = false;
+
+ spin_unlock_bh(&priv->prs_spinlock);
}
/* Add guard entry that drops packets when no VID is matched on this port */
@@ -2079,6 +2114,8 @@ void mvpp2_prs_vid_enable_filtering(struct mvpp2_port *port)
memset(&pe, 0, sizeof(pe));
+ spin_lock_bh(&priv->prs_spinlock);
+
pe.index = tid;
reg_val = mvpp2_read(priv, MVPP2_MH_REG(port->id));
@@ -2111,6 +2148,8 @@ void mvpp2_prs_vid_enable_filtering(struct mvpp2_port *port)
/* Update shadow table */
mvpp2_prs_shadow_set(priv, pe.index, MVPP2_PRS_LU_VID);
mvpp2_prs_hw_write(priv, &pe);
+
+ spin_unlock_bh(&priv->prs_spinlock);
}
/* Parser default initialization */
@@ -2118,6 +2157,20 @@ int mvpp2_prs_default_init(struct platform_device *pdev, struct mvpp2 *priv)
{
int err, index, i;
+ priv->prs_shadow = devm_kcalloc(&pdev->dev, MVPP2_PRS_TCAM_SRAM_SIZE,
+ sizeof(*priv->prs_shadow),
+ GFP_KERNEL);
+ if (!priv->prs_shadow)
+ return -ENOMEM;
+
+ priv->prs_double_vlans = devm_kcalloc(&pdev->dev, sizeof(bool),
+ MVPP2_PRS_DBL_VLANS_MAX,
+ GFP_KERNEL);
+ if (!priv->prs_double_vlans)
+ return -ENOMEM;
+
+ spin_lock_bh(&priv->prs_spinlock);
+
/* Enable tcam table */
mvpp2_write(priv, MVPP2_PRS_TCAM_CTRL_REG, MVPP2_PRS_TCAM_EN_MASK);
@@ -2136,12 +2189,6 @@ int mvpp2_prs_default_init(struct platform_device *pdev, struct mvpp2 *priv)
for (index = 0; index < MVPP2_PRS_TCAM_SRAM_SIZE; index++)
mvpp2_prs_hw_inv(priv, index);
- priv->prs_shadow = devm_kcalloc(&pdev->dev, MVPP2_PRS_TCAM_SRAM_SIZE,
- sizeof(*priv->prs_shadow),
- GFP_KERNEL);
- if (!priv->prs_shadow)
- return -ENOMEM;
-
/* Always start from lookup = 0 */
for (index = 0; index < MVPP2_MAX_PORTS; index++)
mvpp2_prs_hw_port_init(priv, index, MVPP2_PRS_LU_MH,
@@ -2158,26 +2205,13 @@ int mvpp2_prs_default_init(struct platform_device *pdev, struct mvpp2 *priv)
mvpp2_prs_vid_init(priv);
err = mvpp2_prs_etype_init(priv);
- if (err)
- return err;
-
- err = mvpp2_prs_vlan_init(pdev, priv);
- if (err)
- return err;
-
- err = mvpp2_prs_pppoe_init(priv);
- if (err)
- return err;
-
- err = mvpp2_prs_ip6_init(priv);
- if (err)
- return err;
-
- err = mvpp2_prs_ip4_init(priv);
- if (err)
- return err;
+ err = err ? : mvpp2_prs_vlan_init(pdev, priv);
+ err = err ? : mvpp2_prs_pppoe_init(priv);
+ err = err ? : mvpp2_prs_ip6_init(priv);
+ err = err ? : mvpp2_prs_ip4_init(priv);
- return 0;
+ spin_unlock_bh(&priv->prs_spinlock);
+ return err;
}
/* Compare MAC DA with tcam entry data */
@@ -2217,7 +2251,7 @@ mvpp2_prs_mac_da_range_find(struct mvpp2 *priv, int pmap, const u8 *da,
(priv->prs_shadow[tid].udf != udf_type))
continue;
- mvpp2_prs_init_from_hw(priv, &pe, tid);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
entry_pmap = mvpp2_prs_tcam_port_map_get(&pe);
if (mvpp2_prs_mac_range_equals(&pe, da, mask) &&
@@ -2229,7 +2263,8 @@ mvpp2_prs_mac_da_range_find(struct mvpp2 *priv, int pmap, const u8 *da,
}
/* Update parser's mac da entry */
-int mvpp2_prs_mac_da_accept(struct mvpp2_port *port, const u8 *da, bool add)
+static int mvpp2_prs_mac_da_accept_unlocked(struct mvpp2_port *port,
+ const u8 *da, bool add)
{
unsigned char mask[ETH_ALEN] = { 0xff, 0xff, 0xff, 0xff, 0xff, 0xff };
struct mvpp2 *priv = port->priv;
@@ -2261,7 +2296,7 @@ int mvpp2_prs_mac_da_accept(struct mvpp2_port *port, const u8 *da, bool add)
/* Mask all ports */
mvpp2_prs_tcam_port_map_set(&pe, 0);
} else {
- mvpp2_prs_init_from_hw(priv, &pe, tid);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
}
mvpp2_prs_tcam_lu_set(&pe, MVPP2_PRS_LU_MAC);
@@ -2317,6 +2352,17 @@ int mvpp2_prs_mac_da_accept(struct mvpp2_port *port, const u8 *da, bool add)
return 0;
}
+int mvpp2_prs_mac_da_accept(struct mvpp2_port *port, const u8 *da, bool add)
+{
+ int err;
+
+ spin_lock_bh(&port->priv->prs_spinlock);
+ err = mvpp2_prs_mac_da_accept_unlocked(port, da, add);
+ spin_unlock_bh(&port->priv->prs_spinlock);
+
+ return err;
+}
+
int mvpp2_prs_update_mac_da(struct net_device *dev, const u8 *da)
{
struct mvpp2_port *port = netdev_priv(dev);
@@ -2345,6 +2391,8 @@ void mvpp2_prs_mac_del_all(struct mvpp2_port *port)
unsigned long pmap;
int index, tid;
+ spin_lock_bh(&priv->prs_spinlock);
+
for (tid = MVPP2_PE_MAC_RANGE_START;
tid <= MVPP2_PE_MAC_RANGE_END; tid++) {
unsigned char da[ETH_ALEN], da_mask[ETH_ALEN];
@@ -2354,7 +2402,7 @@ void mvpp2_prs_mac_del_all(struct mvpp2_port *port)
(priv->prs_shadow[tid].udf != MVPP2_PRS_UDF_MAC_DEF))
continue;
- mvpp2_prs_init_from_hw(priv, &pe, tid);
+ mvpp2_prs_init_from_hw_unlocked(priv, &pe, tid);
pmap = mvpp2_prs_tcam_port_map_get(&pe);
@@ -2375,14 +2423,17 @@ void mvpp2_prs_mac_del_all(struct mvpp2_port *port)
continue;
/* Remove entry from TCAM */
- mvpp2_prs_mac_da_accept(port, da, false);
+ mvpp2_prs_mac_da_accept_unlocked(port, da, false);
}
+
+ spin_unlock_bh(&priv->prs_spinlock);
}
int mvpp2_prs_tag_mode_set(struct mvpp2 *priv, int port, int type)
{
switch (type) {
case MVPP2_TAG_TYPE_EDSA:
+ spin_lock_bh(&priv->prs_spinlock);
/* Add port to EDSA entries */
mvpp2_prs_dsa_tag_set(priv, port, true,
MVPP2_PRS_TAGGED, MVPP2_PRS_EDSA);
@@ -2393,9 +2444,11 @@ int mvpp2_prs_tag_mode_set(struct mvpp2 *priv, int port, int type)
MVPP2_PRS_TAGGED, MVPP2_PRS_DSA);
mvpp2_prs_dsa_tag_set(priv, port, false,
MVPP2_PRS_UNTAGGED, MVPP2_PRS_DSA);
+ spin_unlock_bh(&priv->prs_spinlock);
break;
case MVPP2_TAG_TYPE_DSA:
+ spin_lock_bh(&priv->prs_spinlock);
/* Add port to DSA entries */
mvpp2_prs_dsa_tag_set(priv, port, true,
MVPP2_PRS_TAGGED, MVPP2_PRS_DSA);
@@ -2406,10 +2459,12 @@ int mvpp2_prs_tag_mode_set(struct mvpp2 *priv, int port, int type)
MVPP2_PRS_TAGGED, MVPP2_PRS_EDSA);
mvpp2_prs_dsa_tag_set(priv, port, false,
MVPP2_PRS_UNTAGGED, MVPP2_PRS_EDSA);
+ spin_unlock_bh(&priv->prs_spinlock);
break;
case MVPP2_TAG_TYPE_MH:
case MVPP2_TAG_TYPE_NONE:
+ spin_lock_bh(&priv->prs_spinlock);
/* Remove port form EDSA and DSA entries */
mvpp2_prs_dsa_tag_set(priv, port, false,
MVPP2_PRS_TAGGED, MVPP2_PRS_DSA);
@@ -2419,6 +2474,7 @@ int mvpp2_prs_tag_mode_set(struct mvpp2 *priv, int port, int type)
MVPP2_PRS_TAGGED, MVPP2_PRS_EDSA);
mvpp2_prs_dsa_tag_set(priv, port, false,
MVPP2_PRS_UNTAGGED, MVPP2_PRS_EDSA);
+ spin_unlock_bh(&priv->prs_spinlock);
break;
default:
@@ -2437,11 +2493,15 @@ int mvpp2_prs_add_flow(struct mvpp2 *priv, int flow, u32 ri, u32 ri_mask)
memset(&pe, 0, sizeof(pe));
+ spin_lock_bh(&priv->prs_spinlock);
+
tid = mvpp2_prs_tcam_first_free(priv,
MVPP2_PE_LAST_FREE_TID,
MVPP2_PE_FIRST_FREE_TID);
- if (tid < 0)
+ if (tid < 0) {
+ spin_unlock_bh(&priv->prs_spinlock);
return tid;
+ }
pe.index = tid;
@@ -2461,6 +2521,7 @@ int mvpp2_prs_add_flow(struct mvpp2 *priv, int flow, u32 ri, u32 ri_mask)
mvpp2_prs_tcam_port_map_set(&pe, MVPP2_PRS_PORT_MASK);
mvpp2_prs_hw_write(priv, &pe);
+ spin_unlock_bh(&priv->prs_spinlock);
return 0;
}
@@ -2472,6 +2533,8 @@ int mvpp2_prs_def_flow(struct mvpp2_port *port)
memset(&pe, 0, sizeof(pe));
+ spin_lock_bh(&port->priv->prs_spinlock);
+
tid = mvpp2_prs_flow_find(port->priv, port->id);
/* Such entry not exist */
@@ -2480,8 +2543,10 @@ int mvpp2_prs_def_flow(struct mvpp2_port *port)
tid = mvpp2_prs_tcam_first_free(port->priv,
MVPP2_PE_LAST_FREE_TID,
MVPP2_PE_FIRST_FREE_TID);
- if (tid < 0)
+ if (tid < 0) {
+ spin_unlock_bh(&port->priv->prs_spinlock);
return tid;
+ }
pe.index = tid;
@@ -2492,13 +2557,14 @@ int mvpp2_prs_def_flow(struct mvpp2_port *port)
/* Update shadow table */
mvpp2_prs_shadow_set(port->priv, pe.index, MVPP2_PRS_LU_FLOWS);
} else {
- mvpp2_prs_init_from_hw(port->priv, &pe, tid);
+ mvpp2_prs_init_from_hw_unlocked(port->priv, &pe, tid);
}
mvpp2_prs_tcam_lu_set(&pe, MVPP2_PRS_LU_FLOWS);
mvpp2_prs_tcam_port_map_set(&pe, (1 << port->id));
mvpp2_prs_hw_write(port->priv, &pe);
+ spin_unlock_bh(&port->priv->prs_spinlock);
return 0;
}
@@ -2509,11 +2575,14 @@ int mvpp2_prs_hits(struct mvpp2 *priv, int index)
if (index > MVPP2_PRS_TCAM_SRAM_SIZE)
return -EINVAL;
+ spin_lock_bh(&priv->prs_spinlock);
+
mvpp2_write(priv, MVPP2_PRS_TCAM_HIT_IDX_REG, index);
val = mvpp2_read(priv, MVPP2_PRS_TCAM_HIT_CNT_REG);
val &= MVPP2_PRS_TCAM_HIT_CNT_MASK;
+ spin_unlock_bh(&priv->prs_spinlock);
return val;
}
--
2.43.0
@@ -1,4 +1,4 @@
From 774cf1d3f5b9cfac247c3efcf4eed39d06c675dc Mon Sep 17 00:00:00 2001
From aa7cb68028d74ca604e29af1e0291041593aed6b Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Tue, 12 Mar 2024 10:27:24 +0100
Subject: [PATCH 01/27] [FIX] net: dsa: mv88e6xxx: Fix timeout on waiting for
@@ -8,14 +8,12 @@ Organization: Wires
In a multi-chip setup, delays of up to 750ms are observed before the
device (6393X) signals completion of PPU initialization (Global 1,
register 0, bit 15). Therefore, increase the timeout threshold to 1s.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/dsa/mv88e6xxx/chip.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index 5aeecfab9630..2565277582c5 100644
index 5935100e7d65..378b6714dcf9 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -86,7 +86,7 @@ int mv88e6xxx_write(struct mv88e6xxx_chip *chip, int addr, int reg, u16 val)
@@ -27,6 +25,3 @@ index 5aeecfab9630..2565277582c5 100644
u16 data;
int err;
int i;
--
2.43.0
@@ -1,4 +1,4 @@
From 6bd6c3c49c438e35d61669879b64b6c4a00d1a19 Mon Sep 17 00:00:00 2001
From de553470d110f8a685f084e095cabe70f6e034e7 Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Wed, 27 Mar 2024 15:52:43 +0100
Subject: [PATCH 02/27] net: dsa: mv88e6xxx: Improve indirect register access
@@ -13,8 +13,6 @@ previous families).
Therefore, add a new set of SMI operations which remaps accesses to
such registers to the corresponding directly addressable register. All
other accesses use the regular indirect interface.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/dsa/mv88e6xxx/chip.c | 7 +++
drivers/net/dsa/mv88e6xxx/global1.h | 3 ++
@@ -24,7 +22,7 @@ Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
5 files changed, 119 insertions(+)
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index 2565277582c5..7ba492ee5c86 100644
index 378b6714dcf9..e3da229cc309 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -6502,6 +6502,13 @@ static int mv88e6xxx_detect(struct mv88e6xxx_chip *chip)
@@ -211,6 +209,3 @@ index c6c71d5757f5..788cf68b7b33 100644
int mv88e6xxx_smi_init(struct mv88e6xxx_chip *chip,
struct mii_bus *bus, int sw_addr);
--
2.43.0
@@ -1,4 +1,4 @@
From 02bb753cee9b24a3a1bcbcd15c3729144200eafc Mon Sep 17 00:00:00 2001
From 3071af4b67233b72e4861c9cddf86861c39e969a Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Mon, 22 Apr 2024 23:18:01 +0200
Subject: [PATCH 03/27] net: dsa: mv88e6xxx: Honor ports being managed via
@@ -13,14 +13,12 @@ USXGMII autoneg)
This state is the default set up by mv88e6xxx_port_setup_mac(), so all
we have to do is to make the phylink MAC callbacks no-ops in cases
when in-band-status is being used.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/dsa/mv88e6xxx/chip.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index 7ba492ee5c86..cdf48fae0623 100644
index e3da229cc309..1273d936177c 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -964,6 +964,9 @@ static void mv88e6xxx_mac_link_down(struct phylink_config *config,
@@ -43,6 +41,3 @@ index 7ba492ee5c86..cdf48fae0623 100644
ops = chip->info->ops;
mv88e6xxx_reg_lock(chip);
--
2.43.0
@@ -1,4 +1,4 @@
From 6cbb6a0a54d81ff5b117b023ac7e251ab1e9c556 Mon Sep 17 00:00:00 2001
From f832e39dec010abcab657040a2fc7eb39593a49c Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Wed, 24 Apr 2024 22:41:04 +0200
Subject: [PATCH 04/27] net: dsa: mv88e6xxx: Limit rsvd2cpu policy to user
@@ -29,8 +29,6 @@ Before this change, due to rsvd2cpu being enabled on the CPU port, the
switch would try to trap it back to the CPU. Given that the CPU is
trusted, instead assume that it indeed meant for the packet to be
forwarded like any other.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/dsa/mv88e6xxx/port.c | 31 +++++++++++++++++++++++++------
1 file changed, 25 insertions(+), 6 deletions(-)
@@ -98,6 +96,3 @@ index 04053fdc6489..f25fb3214acb 100644
if (err)
return err;
--
2.43.0
@@ -1,4 +1,4 @@
From 86b1608084c6e9676db0641f31203d8067893470 Mon Sep 17 00:00:00 2001
From 28f28edf9eb603fb25dea6f73f5292b195b8f9b5 Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Thu, 16 Nov 2023 19:44:32 +0100
Subject: [PATCH 05/27] net: dsa: mv88e6xxx: Add LED infrastructure
@@ -6,8 +6,6 @@ Organization: Wires
Parse DT for LEDs and register them for devices that support it,
though no actual implementations exist yet.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/dsa/mv88e6xxx/Makefile | 1 +
drivers/net/dsa/mv88e6xxx/chip.c | 5 +-
@@ -31,7 +29,7 @@ index a9a9651187db..6720d9303914 100644
mv88e6xxx-objs += pcs-6352.o
mv88e6xxx-objs += pcs-639x.o
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index cdf48fae0623..0a7858280903 100644
index 1273d936177c..e1224c3d217a 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -37,6 +37,7 @@
@@ -311,6 +309,3 @@ index 000000000000..8afa2a0c0527
+int mv88e6xxx_port_setup_leds(struct dsa_switch *ds, int port);
+
+#endif /* _MV88E6XXX_LEDS_H */
--
2.43.0
@@ -1,4 +1,4 @@
From 5496a27ee644f72b721eba0e8c057efb65ee445f Mon Sep 17 00:00:00 2001
From 511ad81be48ff78279864de5ca9154ae12a2361b Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Thu, 16 Nov 2023 21:59:35 +0100
Subject: [PATCH 06/27] net: dsa: mv88e6xxx: Add LED support for 6393X
@@ -8,8 +8,6 @@ Trigger support:
- "none"
- "timer"
- "netdev"
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/dsa/mv88e6xxx/chip.c | 1 +
drivers/net/dsa/mv88e6xxx/leds.c | 229 +++++++++++++++++++++++++++++++
@@ -19,7 +17,7 @@ Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
5 files changed, 272 insertions(+)
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index 0a7858280903..cd746bea31be 100644
index e1224c3d217a..8c7b8673b694 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -5657,6 +5657,7 @@ static const struct mv88e6xxx_ops mv88e6393x_ops = {
@@ -359,6 +357,3 @@ index ddadeb9bfdae..7157864dc20f 100644
int mv88e6393x_set_egress_port(struct mv88e6xxx_chip *chip,
enum mv88e6xxx_egress_direction direction,
int port);
--
2.43.0
@@ -1,4 +1,4 @@
From a0e2ebe61422d5e0e330022a2a38a31c049a4407 Mon Sep 17 00:00:00 2001
From 7ae7d5ff2239d9d99e0fc769a07bcdcb3edfde94 Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Tue, 28 May 2024 10:38:42 +0200
Subject: [PATCH 07/27] net: dsa: tag_dsa: Use tag priority as initial
@@ -19,8 +19,6 @@ Ideally we could then map this priority to an internal one, like we
can do with an "ingress-qos-map" on VLAN interfaces. Until that is
implemented, support the setup that is likely to be the most common; a
1:1 mapping from FPri to skb->priority.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
net/dsa/tag_dsa.c | 7 +++++++
1 file changed, 7 insertions(+)
@@ -43,6 +41,3 @@ index 2a2c4fb61a65..a00ae6bf2971 100644
return skb;
}
--
2.43.0
@@ -1,4 +1,4 @@
From a88679c946d5163eb0e30718109c18ddbbd8cfc6 Mon Sep 17 00:00:00 2001
From 4a8b7416746d92a0307b113aebcb9b8c429f031a Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Tue, 16 Jan 2024 16:00:55 +0100
Subject: [PATCH 08/27] net: dsa: Support MDB memberships whose L2 addresses
@@ -29,8 +29,6 @@ as long as the count is positive. Fortunately, all the infrastructure
needed to do this is already in place, since it is also needed on CPU
and DSA ports. Thus, "implement" this by simply removing the guards
which previously skipped reference countung on user ports.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
net/dsa/switch.c | 16 ----------------
1 file changed, 16 deletions(-)
@@ -69,6 +67,3 @@ index 3d2feeea897b..628e8a884dde 100644
mutex_lock(&dp->addr_lists_lock);
a = dsa_mac_addr_find(&dp->mdbs, mdb->addr, mdb->vid, db);
--
2.43.0
@@ -1,10 +1,9 @@
From c6528f18fbafef721c18e546aa0b60c1b1d772c6 Mon Sep 17 00:00:00 2001
From 180ecf6cdc045f0bc661551e3f7b0b46c4a6e490 Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Thu, 21 Mar 2024 19:12:15 +0100
Subject: [PATCH 09/27] net: dsa: Support EtherType based priority overrides
Organization: Wires
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
include/net/dsa.h | 4 ++++
net/dsa/user.c | 56 +++++++++++++++++++++++++++++++++++++++++++++--
@@ -113,6 +112,3 @@ index 64f660d2334b..e13fb22e2c2b 100644
}
break;
case IEEE_8021QAZ_APP_SEL_DSCP:
--
2.43.0
@@ -1,11 +1,10 @@
From bc41b93b365694ac36a19565270b8deda3b8cb79 Mon Sep 17 00:00:00 2001
From 6c90dd976e8ecb860533a0d1c07620bbb3401d28 Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Fri, 22 Mar 2024 16:15:43 +0100
Subject: [PATCH 10/27] net: dsa: mv88e6xxx: Support EtherType based priority
overrides
Organization: Wires
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/dsa/mv88e6xxx/chip.c | 64 +++++++++++++++++++++++++++++
drivers/net/dsa/mv88e6xxx/chip.h | 21 ++++++++++
@@ -16,7 +15,7 @@ Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
6 files changed, 207 insertions(+), 4 deletions(-)
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index cd746bea31be..e05caeabdc85 100644
index 8c7b8673b694..97b4e3770994 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -1715,6 +1715,11 @@ static int mv88e6xxx_rmu_setup(struct mv88e6xxx_chip *chip)
@@ -371,6 +370,3 @@ index 7157864dc20f..7edb04c41ac8 100644
int mv88e6xxx_port_set_message_port(struct mv88e6xxx_chip *chip, int port,
bool message_port);
int mv88e6xxx_port_set_trunk(struct mv88e6xxx_chip *chip, int port,
--
2.43.0
@@ -1,4 +1,4 @@
From 70c1d59448db0ec88c07fa4ff5748b0df740a8d2 Mon Sep 17 00:00:00 2001
From d253013e702aca0e4f91bea6f88a9442e25a8384 Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Tue, 28 May 2024 11:04:22 +0200
Subject: [PATCH 11/27] net: dsa: mv88e6xxx: Add mqprio qdisc support
@@ -24,15 +24,13 @@ are effectively only specifying the QPri.
Since FPri is always a 3-bit field, even on older chips with only 4
physical queues, always report 8 queues and let the chip's policy
handle the mapping down to the "real" number.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/dsa/mv88e6xxx/chip.c | 70 ++++++++++++++++++++++++++++++++
net/dsa/tag_dsa.c | 4 +-
2 files changed, 73 insertions(+), 1 deletion(-)
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index e05caeabdc85..ad997818047e 100644
index 97b4e3770994..d2404e9431b1 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -31,6 +31,7 @@
@@ -157,6 +155,3 @@ index a00ae6bf2971..55c296e0b5b0 100644
dsa_header[3] = vid & 0xff;
}
--
2.43.0
@@ -1,4 +1,4 @@
From c3721cb1cccf3c8fe18bea05c9ad20e7082291bd Mon Sep 17 00:00:00 2001
From b4fe1543b6186642024d3600b47f093504ed10cc Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Wed, 29 May 2024 13:20:41 +0200
Subject: [PATCH 12/27] net: dsa: mv88e6xxx: Use VLAN prio over IP when both
@@ -22,14 +22,12 @@ main reasons for choosing the new default:
packet's priority. As the packet then moves through the network
core over trusted VLAN trunks, the packet should keep its original
priority, independent of what inner protocol fields may indicate.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/dsa/mv88e6xxx/chip.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index ad997818047e..40e8d2018fee 100644
index d2404e9431b1..2477d201b2cf 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -3432,9 +3432,13 @@ static int mv88e6xxx_setup_port(struct mv88e6xxx_chip *chip, int port)
@@ -57,6 +55,3 @@ index ad997818047e..40e8d2018fee 100644
MV88E6XXX_PORT_CTL0_STATE_FORWARDING;
/* Forward any IPv4 IGMP or IPv6 MLD frames received
* by a USER port to the CPU port to allow snooping.
--
2.43.0
@@ -1,4 +1,4 @@
From 373d60426de6d19fd668e1e0b599ca430f351a18 Mon Sep 17 00:00:00 2001
From a9b8b2431a73995041df5f89e5c79af49e006729 Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Tue, 26 Nov 2024 19:45:59 +0100
Subject: [PATCH 13/27] [FIX] net: dsa: mv88e6xxx: Trap locally terminated
@@ -24,8 +24,6 @@ a VLAN upper interface, rather than to offload bridge VLANs, are
marked as policy entries. As the VTU policy of user ports is already
set to TRAP (to ensure proper standalone port operation), this will
cause all packets assigned to these VLANs to properly terminated.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/dsa/mv88e6xxx/chip.c | 33 ++++++++++++++++++--------------
include/net/switchdev.h | 4 ++++
@@ -33,7 +31,7 @@ Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
3 files changed, 27 insertions(+), 14 deletions(-)
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index 40e8d2018fee..30f8a5388733 100644
index 2477d201b2cf..41f3223313d0 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -2654,7 +2654,7 @@ static int mv88e6xxx_port_broadcast_sync(struct mv88e6xxx_chip *chip, int port,
@@ -156,6 +154,3 @@ index e13fb22e2c2b..f45e313f1dd0 100644
};
struct dsa_switch *ds = dp->ds;
struct netdev_hw_addr *ha;
--
2.43.0
@@ -1,4 +1,4 @@
From a6368c60ac6ae2e0d97ac571b6506aa09becbb71 Mon Sep 17 00:00:00 2001
From 82d6ed51bb597cd1f79e74b1263c3492738b3c71 Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Tue, 19 Sep 2023 18:38:10 +0200
Subject: [PATCH 14/27] net: phy: marvell10g: Support firmware loading on
@@ -11,8 +11,6 @@ its RAM, ask userspace for the binary and load it over XMDIO.
We have no choice but to bail out of the probe if firmware is not
available, as the device does not have any built-in image on which to
fall back.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/phy/marvell10g.c | 161 +++++++++++++++++++++++++++++++++++
1 file changed, 161 insertions(+)
@@ -236,6 +234,3 @@ index 6642eb642d4b..79d9483419c0 100644
MODULE_DESCRIPTION("Marvell Alaska X/M multi-gigabit Ethernet PHY driver");
+MODULE_FIRMWARE("mrvl/x3310fw.hdr");
MODULE_LICENSE("GPL");
--
2.43.0
@@ -1,4 +1,4 @@
From 550dd1b443cf9d054f2a523088fbe22b215e07cb Mon Sep 17 00:00:00 2001
From 384a0171443f0136f626ca2aff94f393837bcb2c Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Tue, 21 Nov 2023 20:15:24 +0100
Subject: [PATCH 15/27] net: phy: marvell10g: Fix power-up when strapped to
@@ -8,8 +8,6 @@ Organization: Wires
On devices which are hardware strapped to start powered down (PDSTATE
== 1), make sure that we clear the power-down bit on all units
affected by this setting.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/phy/marvell10g.c | 18 +++++++++++++++---
1 file changed, 15 insertions(+), 3 deletions(-)
@@ -45,6 +43,3 @@ index 79d9483419c0..268484092776 100644
/* Sometimes, the power down bit doesn't clear immediately, and
* a read of this register causes the bit not to clear. Delay
--
2.43.0
@@ -1,4 +1,4 @@
From 9ca4c28ccf7857a36db8dd3c37dcd005222bdb78 Mon Sep 17 00:00:00 2001
From ee93f4ed2fbd7595622ecf0ed3fa9e2803662ae9 Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Wed, 15 Nov 2023 20:58:42 +0100
Subject: [PATCH 16/27] net: phy: marvell10g: Add LED support for 88X3310
@@ -17,8 +17,6 @@ Trigger support:
software blinking
- "netdev": Offload link or duplex information to the solid behavior;
tx and/or rx activity to blink behavior.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/phy/marvell10g.c | 422 +++++++++++++++++++++++++++++++++++
1 file changed, 422 insertions(+)
@@ -512,6 +510,3 @@ index 268484092776..9f8475b67ef7 100644
},
{
.phy_id = MARVELL_PHY_ID_88X3310,
--
2.43.0
@@ -1,4 +1,4 @@
From 69f9bda6cab34556e67a096c282eee7337f97f26 Mon Sep 17 00:00:00 2001
From a37059a58453694376e6e5df700d6d4c51703b13 Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Tue, 12 Dec 2023 09:51:05 +0100
Subject: [PATCH 17/27] net: phy: marvell10g: Support LEDs tied to a single
@@ -14,8 +14,6 @@ tied to a particular media side, and use that information to refine
the offloading of the "netdev" trigger, such that LEDs attached to the
RJ45 jack only lights up when a copper link is established, and vice
versa for the SFP cage.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/phy/marvell10g.c | 23 ++++++++++++++++++++++-
1 file changed, 22 insertions(+), 1 deletion(-)
@@ -75,6 +73,3 @@ index 9f8475b67ef7..82b2e9b55b67 100644
/* mv3310_led_polarity_set() will not be called unless the
* device tree specifies a mode that of_phy_led() considers to
* be a non-default configuration. I.e., something other than
--
2.43.0
@@ -1,4 +1,4 @@
From f70be42f0ee50cda8c1cde14442ea8285c01834b Mon Sep 17 00:00:00 2001
From 0fabf9cc0ddb17ed1d88212edcb41600444c51e3 Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Wed, 27 Mar 2024 10:10:19 +0100
Subject: [PATCH 18/27] net: phy: Do not resume PHY when attaching
@@ -15,8 +15,6 @@ Otherwise, drivers that attached to their PHYs during
probing (e.g. DSA) would end up with a physical link being
established, even though the corresponding interface was still
administratively down.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/phy/phy_device.c | 1 -
1 file changed, 1 deletion(-)
@@ -33,6 +31,3 @@ index 119dfa2d6643..7c7cc6edf314 100644
if (!phydev->is_on_sfp_module)
phy_led_triggers_register(phydev);
--
2.43.0
@@ -1,4 +1,4 @@
From 17d6f3f6a7429ae635d0359b39da2e173c403fdf Mon Sep 17 00:00:00 2001
From 60514772701b8335077c9bbd7107786d2a7a3ed4 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 4 Mar 2024 16:47:28 +0100
Subject: [PATCH 19/27] net: bridge: avoid classifying unknown multicast as
@@ -16,7 +16,6 @@ Because a multicast router should always receive both known and unknown
multicast.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
include/uapi/linux/if_bridge.h | 1 +
net/bridge/br.c | 5 +++++
@@ -232,6 +231,3 @@ index 041f6e571a20..40651b07df94 100644
static inline bool br_multicast_is_router(struct net_bridge_mcast *brmctx,
struct sk_buff *skb)
{
--
2.43.0
@@ -1,4 +1,4 @@
From 27ca82c96a6bcd560e908eed17fc24126e8051a6 Mon Sep 17 00:00:00 2001
From 91d101863365ef759c6101674881c7d21130b24b Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Tue, 5 Mar 2024 06:44:41 +0100
Subject: [PATCH 20/27] net: bridge: Ignore router ports when forwarding L2
@@ -32,6 +32,3 @@ index 40651b07df94..e90b4f5cab76 100644
}
static inline struct net_bridge_port *
--
2.43.0
@@ -1,4 +1,4 @@
From bbbb4f7460efeaf057d37d837cae79a565a6d406 Mon Sep 17 00:00:00 2001
From e22d99445476933f9a2da0e825d8a0da62af0c20 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Thu, 4 Apr 2024 16:36:30 +0200
Subject: [PATCH 21/27] net: bridge: drop delay for applying strict multicast
@@ -19,7 +19,6 @@ A proper fix for upstreaming could be to add a knob to disable the delay.
[2]: https://lore.kernel.org/netdev/20240127175033.9640-1-linus.luessing@c0d3.blue/
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
net/bridge/br_multicast.c | 42 +++++++--------------------------------
net/bridge/br_private.h | 4 +---
@@ -186,6 +185,3 @@ index e90b4f5cab76..73b78c594564 100644
}
static inline bool br_multicast_querier_exists(struct net_bridge_mcast *brmctx,
--
2.43.0
@@ -1,4 +1,4 @@
From 7c751c24428060c3e87f164eb2a054db410f4b0d Mon Sep 17 00:00:00 2001
From 69a5b99e93002daa2a65574677c9ab595f3c8b8d Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Thu, 16 May 2024 14:51:54 +0200
Subject: [PATCH 22/27] net: bridge: Differentiate MDB additions from
@@ -21,8 +21,6 @@ generated.
Therefore, discriminate new groups from changes to existing groups by
introducing a RTM_SETMDB events to be used in the latter scenario.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
include/uapi/linux/rtnetlink.h | 2 ++
net/bridge/br_mdb.c | 4 ++--
@@ -104,6 +102,3 @@ index 34be07a1fd00..9c8bf38e0079 100644
unlock_continue:
spin_unlock(&brmctx->br->multicast_lock);
}
--
2.43.0
@@ -1,4 +1,4 @@
From db0d727f6cc90ccea2378d876329c151db1670dc Mon Sep 17 00:00:00 2001
From 55ff4511898852f9408c5ccab8082f1b03f697a4 Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Fri, 24 Nov 2023 23:29:55 +0100
Subject: [PATCH 23/27] nvmem: layouts: onie-tlv: Let device probe even when
@@ -13,8 +13,6 @@ be successfully probed.
Therefore, settle for reporting data corruption issues in the log, and
simply refrain from registering any cells in those cases.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/nvmem/layouts/onie-tlv.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
@@ -50,6 +48,3 @@ index 0967a32319a2..48547d5bb502 100644
data = table + hdr_len;
ret = onie_tlv_add_cells(dev, nvmem, data_len, data);
--
2.43.0
@@ -1,4 +1,4 @@
From ed58f4b6e7344bdefceb7ac31d1c769a6d127827 Mon Sep 17 00:00:00 2001
From 950e326ed789709260dbe9f139ebcec264889048 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 29 Apr 2024 15:14:51 +0200
Subject: [PATCH 24/27] usb: core: adjust log level for unauthorized devices
@@ -9,7 +9,6 @@ so let's adjust the log level so these messages slip below radar for the
commonly used 'quiet' log level.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/usb/core/driver.c | 4 ++--
drivers/usb/core/generic.c | 2 +-
@@ -45,6 +44,3 @@ index b134bff5c3fe..60575a01a810 100644
else {
c = usb_choose_configuration(udev);
if (c >= 0) {
--
2.43.0
@@ -1,4 +1,4 @@
From e7f7ae788680b4ec73af736453ec4afeb34d9842 Mon Sep 17 00:00:00 2001
From 6229922ab3d1a414dfbbc8b3d13eaf10136b9e68 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Thu, 16 Jan 2025 12:35:12 +0100
Subject: [PATCH 25/27] net: dsa: mv88e6xxx: collapse disabled state into
@@ -18,7 +18,6 @@ each member port, preventing LACPDUs from passing through to qualify the
link and become active.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/dsa/mv88e6xxx/port.c | 2 --
1 file changed, 2 deletions(-)
@@ -36,6 +35,3 @@ index 84900814c456..91e58297594c 100644
case BR_STATE_BLOCKING:
case BR_STATE_LISTENING:
state = MV88E6XXX_PORT_CTL0_STATE_BLOCKING;
--
2.43.0
@@ -1,4 +1,4 @@
From 823687aa03d866f3b76b5e40e35fa56c7f6f4492 Mon Sep 17 00:00:00 2001
From fff392ae3166cc2afa80f3eca6066fa21eb6e28e Mon Sep 17 00:00:00 2001
From: Tobias Waldekranz <tobias@waldekranz.com>
Date: Wed, 12 Feb 2025 22:03:14 +0100
Subject: [PATCH 26/27] net: dsa: mv88e6xxx: Only activate LAG offloading when
@@ -46,14 +46,12 @@ existing port isolation to work as intended.
Before joining a bridge, the offload does not offer any performance
benefit anyway. All ingressing packet will always have to go to the
CPU; egress traffic always relies on software hashing.
Signed-off-by: Tobias Waldekranz <tobias@waldekranz.com>
---
drivers/net/dsa/mv88e6xxx/chip.c | 42 +++++++++++++++-----------------
1 file changed, 20 insertions(+), 22 deletions(-)
diff --git a/drivers/net/dsa/mv88e6xxx/chip.c b/drivers/net/dsa/mv88e6xxx/chip.c
index 30f8a5388733..c1f8adaa008a 100644
index 41f3223313d0..7bee935fd40f 100644
--- a/drivers/net/dsa/mv88e6xxx/chip.c
+++ b/drivers/net/dsa/mv88e6xxx/chip.c
@@ -3095,6 +3095,7 @@ static int mv88e6xxx_port_bridge_join(struct dsa_switch *ds, int port,
@@ -142,6 +140,3 @@ index 30f8a5388733..c1f8adaa008a 100644
}
static int mv88e6xxx_crosschip_lag_change(struct dsa_switch *ds, int sw_index,
--
2.43.0
@@ -1,9 +1,9 @@
From daba70e7782b704224396f0d86dcd91b4713e064 Mon Sep 17 00:00:00 2001
From 2eb2c9c7eaca24788cf448b151424a347c8ddf98 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Sun, 11 Aug 2024 11:27:35 +0200
Subject: [PATCH 5/5] net: usb: r8152: add r8153b support for link/activity
Subject: [PATCH 27/27] net: usb: r8152: add r8153b support for link/activity
LEDs
Organization: Addiva Elektronik
Organization: Wires
This patch adds support for the link/activity LEDs on the NanoPi R2S
and OrangePi R1 Plus.
@@ -19,7 +19,7 @@ Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
1 file changed, 8 insertions(+)
diff --git a/drivers/net/usb/r8152.c b/drivers/net/usb/r8152.c
index 19df1cd9f072..810477991810 100644
index 468c73974046..7e4089f10fde 100644
--- a/drivers/net/usb/r8152.c
+++ b/drivers/net/usb/r8152.c
@@ -41,6 +41,11 @@
@@ -34,7 +34,7 @@ index 19df1cd9f072..810477991810 100644
#define R8152_PHY_ID 32
#define PLA_IDR 0xc000
@@ -7296,6 +7301,9 @@ static void r8153b_init(struct r8152 *tp)
@@ -7306,6 +7311,9 @@ static void r8153b_init(struct r8152 *tp)
ocp_data &= ~(RX_AGG_DISABLE | RX_ZERO_EN);
ocp_write_word(tp, MCU_TYPE_USB, USB_USB_CTRL, ocp_data);
@@ -44,6 +44,3 @@ index 19df1cd9f072..810477991810 100644
rtl_tally_reset(tp);
tp->coalesce = 15000; /* 15 us */
--
2.43.0
+2 -3
View File
@@ -1,3 +1,2 @@
# Locally calculated
sha256 9ac322d85bcf98a04667d929f5c2666b15bd58c6c2d68dd512c72acbced07d04 linux-6.8.2.tar.xz
sha256 fa5f22fd67dd05812d39dca579320c493048e26c4a556048a12385e7ae6fc698 linux-6.10.3.tar.xz
# Calculated with ../utils/kernel-refresh.sh
sha256 d8d95404f8deeb7ff6992c0df855025062e9e8182bca6daa27ef2e9275d27749 linux-6.12.23.tar.xz
@@ -1,117 +0,0 @@
From ad9a464806fe27fe65d403f56f1dc701f7d0a10a Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Wed, 24 Apr 2024 13:19:09 +0200
Subject: [PATCH 01/17] Fix #72: loss of raw kernel log messages to console
Organization: Addiva Elektronik
This patch adds a command line flag `-l` to keep kernel logs to console.
A feature requested by embedded Linux users which often navigate issues
by console output.
With properly configured kernel logging, e.g., `quiet`, only error and
above in severity is logged by the kernel directly to the console. So
for most users this would be a useful behavior.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
man/syslogd.8 | 18 +++++++++++++++++-
src/syslogd.c | 10 +++++++++-
src/syslogd.h | 4 ++--
3 files changed, 28 insertions(+), 4 deletions(-)
diff --git a/man/syslogd.8 b/man/syslogd.8
index dcfb564..70f1b8b 100644
--- a/man/syslogd.8
+++ b/man/syslogd.8
@@ -38,7 +38,7 @@
.Nd log systems messages
.Sh SYNOPSIS
.Nm
-.Op Fl ?468AcdFHKknsTtv
+.Op Fl ?468AcdFHKklnsTtv
.Op Fl a Ar addr[/len][:port]
.Op Fl a Ar name[:port]
.Op Fl b Ar addr[:port]
@@ -292,6 +292,22 @@ Usually the
.Dq kern
facility is reserved for messages read directly from
.Pa /dev/kmsg .
+.It Fl l
+Keep kernel console logging. By default
+.Nm
+call
+.Xr klogctl 2
+to disable the kernel's logging to console after having opened
+.Pa /dev/kmsg .
+With this option the kernel's log level can be adjusted using
+.Xr sysctl 8 ,
+or the kernel command line, to suit your logging needs to the console.
+.Pp
+Please note, this does not affect logging of kernel messages, see
+.Fl K ,
+only what the kernel logs to
+.Pa /dev/console .
+Also, this is only applicable to Linux.
.It Fl m Ar interval
Select the number of minutes between
.Dq mark
diff --git a/src/syslogd.c b/src/syslogd.c
index c02d064..c9ea7fd 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -154,6 +154,7 @@ static int RemoteHostname; /* Log remote hostname from the message */
static int KernLog = 1; /* Track kernel logs by default */
static int KeepKernFac; /* Keep remotely logged kernel facility */
static int KeepKernTime; /* Keep kernel timestamp, evern after initial read */
+static int KeepKernConsole; /* Keep kernel logging to console */
static off_t RotateSz = 0; /* Max file size (bytes) before rotating, disabled by default */
static int RotateCnt = 5; /* Max number (count) of log files to keep, set with -c <NUM> */
@@ -363,6 +364,9 @@ int usage(int code)
" -H Use hostname from message instead of address for remote messages\n"
" -K Disable kernel logging, useful in container use-cases\n"
" -k Allow logging with facility 'kernel', otherwise remapped to 'user'\n"
+#ifdef __linux__
+ " -l Keep kernel logging to console, use sysctl to adjust kernel.printk\n"
+#endif
" -m MINS Interval between MARK messages, 0 to disable, default: 20 min\n"
" -n Disable DNS query for every request\n"
" -P FILE File to store the process ID, default: %s\n"
@@ -397,7 +401,7 @@ int main(int argc, char *argv[])
char *ptr;
int ch;
- while ((ch = getopt(argc, argv, "468Aa:b:C:cdHFf:Kkm:nP:p:r:sTtv?")) != EOF) {
+ while ((ch = getopt(argc, argv, "468Aa:b:C:cdHFf:Kklm:nP:p:r:sTtv?")) != EOF) {
switch ((char)ch) {
case '4':
family = PF_INET;
@@ -464,6 +468,10 @@ int main(int argc, char *argv[])
KeepKernFac = 1;
break;
+ case 'l':
+ KeepKernConsole = 1;
+ break;
+
case 'm': /* mark interval */
MarkInterval = atoi(optarg) * 60;
break;
diff --git a/src/syslogd.h b/src/syslogd.h
index 68ceafb..1703df2 100644
--- a/src/syslogd.h
+++ b/src/syslogd.h
@@ -169,8 +169,8 @@
#define SYSLOG_ACTION_CONSOLE_ON 7
#ifdef __linux__
-#define kern_console_off() klogctl(SYSLOG_ACTION_CONSOLE_OFF, NULL, 0)
-#define kern_console_on() klogctl(SYSLOG_ACTION_CONSOLE_ON, NULL, 0)
+#define kern_console_off() if (!KeepKernConsole) klogctl(SYSLOG_ACTION_CONSOLE_OFF, NULL, 0)
+#define kern_console_on() if (!KeepKernConsole) klogctl(SYSLOG_ACTION_CONSOLE_ON, NULL, 0)
#else
#define kern_console_off() do { } while (0)
#define kern_console_on() do { } while (0)
--
2.43.0
@@ -1,177 +0,0 @@
From 7e0882688b0ea459c850e6e0ace66cca7100fd0a Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Fri, 12 Jul 2024 22:54:51 +0200
Subject: [PATCH 02/17] Fix #80: add global log rotation options to .conf file
Organization: Addiva Elektronik
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
man/syslog.conf.5 | 20 ++++++++++++++++----
src/syslogd.c | 36 ++++++++++++++++++++++++++++++++++--
syslog.conf | 14 +++++++++++---
3 files changed, 61 insertions(+), 9 deletions(-)
diff --git a/man/syslog.conf.5 b/man/syslog.conf.5
index 73c11e1..030c377 100644
--- a/man/syslog.conf.5
+++ b/man/syslog.conf.5
@@ -71,6 +71,9 @@ OPTION := [OPTION,]
secure_mode [0,1,2]
+rotate_size SIZE
+rotate_count NUMBER
+
include /etc/syslog.d/*.conf
notify /path/to/script-on-rotate
.Ed
@@ -107,6 +110,15 @@ a file can reach before it is rotated, and later compressed. This
feature is mostly intended for embedded systems that do not want to have
cron or a separate log rotate daemon.
.Pp
+The
+.Ql rotate_size SIZE
+and
+.Ql rotate_count COUNT
+are the same as the
+.Nm syslogd Fl r Ar SIZE:COUNT
+command line option. Remember, command line options take precedence
+over .conf file settings.
+.Pp
.Sy Note:
the permissions of the rotated files are kept. Meaning the
administrator can create all log files, before starting
@@ -120,13 +132,13 @@ permissions.
Comments, lines starting with a hash mark ('#'), and empty lines are
ignored. If an error occurs during parsing the whole line is ignored.
.Pp
-Additional options include
+The
.Ql secure_mode <0-2>
-which is the same as the
+option is the same as the
.Nm syslogd Fl s
-commandline option.
+command line option.
.Sy Note:
-command line option always wins, so you need to drop
+again, command line option always wins, so you need to drop
.Fl s
from the command line to use this .conf file option instead.
.Pp
diff --git a/src/syslogd.c b/src/syslogd.c
index c9ea7fd..5061376 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -156,6 +156,7 @@ static int KeepKernFac; /* Keep remotely logged kernel facility */
static int KeepKernTime; /* Keep kernel timestamp, evern after initial read */
static int KeepKernConsole; /* Keep kernel logging to console */
+static int rotate_opt; /* Set if command line option has been given (wins) */
static off_t RotateSz = 0; /* Max file size (bytes) before rotating, disabled by default */
static int RotateCnt = 5; /* Max number (count) of log files to keep, set with -c <NUM> */
@@ -180,13 +181,17 @@ static SIMPLEQ_HEAD(, allowedpeer) aphead = SIMPLEQ_HEAD_INITIALIZER(aphead);
* parser moves the argument to the beginning of the parsed line.
*/
char *secure_str; /* string value of secure_mode */
+char *rotate_sz_str; /* string value of RotateSz */
+char *rotate_cnt_str; /* string value of RotateCnt */
const struct cfkey {
const char *key;
char **var;
} cfkey[] = {
- { "notify", NULL },
- { "secure_mode", &secure_str },
+ { "notify", NULL },
+ { "secure_mode", &secure_str },
+ { "rotate_size", &rotate_sz_str },
+ { "rotate_count", &rotate_cnt_str },
};
/* Function prototypes. */
@@ -499,6 +504,7 @@ int main(int argc, char *argv[])
case 'r':
parse_rotation(optarg, &RotateSz, &RotateCnt);
+ rotate_opt++;
break;
case 's':
@@ -3296,6 +3302,32 @@ static int cfparse(FILE *fp, struct files *newf, struct notifiers *newn)
secure_str = NULL;
}
+ if (rotate_sz_str) {
+ if (rotate_opt) {
+ logit("Skipping 'rotate_size', already set on command line.");
+ } else {
+ int val = strtobytes(rotate_sz_str);
+ if (val > 0)
+ RotateSz = val;
+ }
+
+ free(rotate_sz_str);
+ rotate_sz_str = NULL;
+ }
+
+ if (rotate_cnt_str) {
+ if (rotate_opt) {
+ logit("Skipping 'rotate_count', already set on command line.");
+ } else {
+ int val = atoi(rotate_cnt_str);
+ if (val > 0)
+ RotateCnt = val;
+ }
+
+ free(rotate_cnt_str);
+ rotate_cnt_str = NULL;
+ }
+
return 0;
}
diff --git a/syslog.conf b/syslog.conf
index c4c7525..52161a1 100644
--- a/syslog.conf
+++ b/syslog.conf
@@ -42,9 +42,11 @@ mail.err /var/log/mail.err
cron,daemon.none;\
mail,news.none -/var/log/messages
-# Store all critical eventes, except kernel logs in critical
#
-#*.=crit;kern.none /var/log/critical
+# Store all critical events, except kernel logs, in critical RFC5424 format.
+# Overide global log rotation settings, rotate every 10MiB, keep 5 old logs,
+#
+#*.=crit;kern.none /var/log/critical ;rotate=10M:5,RFC5424
# Example of sending events to remote syslog server.
# All events from notice and above, except auth, authpriv
@@ -60,7 +62,7 @@ mail.err /var/log/mail.err
# Priority alert and above are sent to the operator
#
-#*.alert root,joey
+#*.alert root,joey
#
# Secure mode, same as -s, none(0), on(1), full(2). When enabled
@@ -70,6 +72,12 @@ mail.err /var/log/mail.err
#
secure_mode 1
+#
+# Global log rotation, same as -r SIZE:COUNT, command line wins.
+#
+#rotate_size 1M
+#rotate_count 5
+
#
# Include all config files in /etc/syslog.d/
#
--
2.43.0
@@ -1,102 +0,0 @@
From a2c47f81bf3d358dddb475cbaa8125f2cb776587 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Sun, 14 Jul 2024 09:19:01 +0200
Subject: [PATCH 03/17] Refactor, rely on global file rotation if not set
per-file
Organization: Addiva Elektronik
Instead of initializing per-file rotation with global values, leave them
unset to allow global settings to be changed from config file.
This changes the semantics so that it is no longer possible to disable
log rotation on a per-file basis.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 37 +++++++++++++++++++++++++------------
1 file changed, 25 insertions(+), 12 deletions(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index 5061376..fa8964b 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -1732,21 +1732,34 @@ static void logmsg(struct buf_msg *buffer)
static void logrotate(struct filed *f)
{
struct stat statf;
+ off_t sz;
- if (!f->f_rotatesz)
+ if (!f->f_rotatesz && !RotateSz)
return;
+ if (f->f_rotatesz)
+ sz = f->f_rotatesz;
+ else
+ sz = RotateSz;
+
if (fstat(f->f_file, &statf))
return;
/* bug (mostly harmless): can wrap around if file > 4gb */
- if (S_ISREG(statf.st_mode) && statf.st_size > f->f_rotatesz)
+ if (S_ISREG(statf.st_mode) && statf.st_size > sz)
rotate_file(f, &statf);
}
static void rotate_file(struct filed *f, struct stat *stp_or_null)
{
- if (f->f_rotatecount > 0) { /* always 0..999 */
+ int cnt;
+
+ if (f->f_rotatecount)
+ cnt = f->f_rotatecount;
+ else
+ cnt = RotateCnt;
+
+ if (cnt > 0) { /* always 0..999 */
struct stat st_stack;
int len = strlen(f->f_un.f_fname) + 10 + 5;
int i;
@@ -1754,7 +1767,7 @@ static void rotate_file(struct filed *f, struct stat *stp_or_null)
char newFile[len];
/* First age zipped log files */
- for (i = f->f_rotatecount; i > 1; i--) {
+ for (i = cnt; i > 1; i--) {
snprintf(oldFile, len, "%s.%d.gz", f->f_un.f_fname, i - 1);
snprintf(newFile, len, "%s.%d.gz", f->f_un.f_fname, i);
@@ -1808,7 +1821,14 @@ static void rotate_all_files(void)
struct filed *f;
SIMPLEQ_FOREACH(f, &fhead, f_link) {
- if (f->f_type == F_FILE && f->f_rotatesz)
+ off_t sz;
+
+ if (f->f_rotatesz)
+ sz = f->f_rotatesz;
+ else
+ sz = RotateSz;
+
+ if (f->f_type == F_FILE && sz)
rotate_file(f, NULL);
}
}
@@ -3140,13 +3160,6 @@ static struct filed *cfline(char *line)
break;
case F_FILE:
- /* default rotate from command line */
- if (f->f_rotatesz == 0) {
- f->f_rotatecount = RotateCnt;
- f->f_rotatesz = RotateSz;
- }
- /* fallthrough */
-
default:
/* All other targets default to RFC3164 */
if (f->f_flags & (RFC3164 | RFC5424))
--
2.43.0
@@ -1,67 +0,0 @@
From 0366909927cebecdf6c35b83a976a25c529043e1 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Sun, 14 Jul 2024 09:26:50 +0200
Subject: [PATCH 04/17] Allow per-file rotation settings to set only one value
Organization: Addiva Elektronik
This change makes it possible to set rotate=2M, or rotate=:5, and then
rely on the global settings for the other.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
man/syslog.conf.5 | 10 ++++++++--
src/syslogd.c | 7 +++----
2 files changed, 11 insertions(+), 6 deletions(-)
diff --git a/man/syslog.conf.5 b/man/syslog.conf.5
index 030c377..f436dc3 100644
--- a/man/syslog.conf.5
+++ b/man/syslog.conf.5
@@ -67,7 +67,10 @@ ACTION := /path/to/file
OPTION := [OPTION,]
|= RFC3164
|= RFC5424
- |= rotate=SIZE:COUNT
+ |= rotate=ROT
+ROT := SIZE:COUNT
+ |= SIZE
+ |= :COUNT
secure_mode [0,1,2]
@@ -108,7 +111,10 @@ The log rotation, which is only relevant for files, details the max
.Ar SIZE:COUNT
a file can reach before it is rotated, and later compressed. This
feature is mostly intended for embedded systems that do not want to have
-cron or a separate log rotate daemon.
+cron or a separate log rotate daemon. It is possible to specify only
+size or count, in which case the global setting covers the other. E.g.,
+to set only the rotation count, use:
+.Ar rotate=:COUNT .
.Pp
The
.Ql rotate_size SIZE
diff --git a/src/syslogd.c b/src/syslogd.c
index fa8964b..2264a75 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -2876,13 +2876,12 @@ static void cfrot(char *ptr, struct filed *f)
*c++ = 0;
cnt = atoi(c);
}
+ if (cnt > 0)
+ f->f_rotatecount = cnt;
sz = strtobytes(ptr);
- if (sz > 0 && cnt > 0) {
- logit("Set rotate size %d bytes, %d rotations\n", sz, cnt);
- f->f_rotatecount = cnt;
+ if (sz > 0)
f->f_rotatesz = sz;
- }
}
static int cfopt(char **ptr, const char *opt)
--
2.43.0
@@ -1,150 +0,0 @@
From a1dc835fd5d11ce0dd6d9983c1aa2ca188460ac9 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Sun, 14 Jul 2024 17:46:41 +0200
Subject: [PATCH 05/17] Fix #81: blocking delay for unreachable remote
Organization: Addiva Elektronik
This patch fixes a blocking delay when a named remote action is set up.
On GLIBC systems, with the default resolver setup, this may be as long
as 10 seconds, meaning syslogd retried nslookup() every log message,
which in turn lead to snail speed on logging to other targets.
Additionally it re-enables the warning for failure to resolve the DNS
name -- a user is likely very interested in why they are not seeing any
logs on their remote server. Logs age out, so logging in to a device
which may have logged this once is not very useful.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
configure.ac | 12 ++++++++++++
src/syslogd.c | 27 ++++++++++++++++-----------
src/syslogd.h | 5 ++++-
3 files changed, 32 insertions(+), 12 deletions(-)
diff --git a/configure.ac b/configure.ac
index c370877..cf2488a 100644
--- a/configure.ac
+++ b/configure.ac
@@ -67,6 +67,10 @@ AC_CHECK_FUNCS([setsid])
AC_CHECK_FUNCS([getprogname strtobytes])
# Command line options
+AC_ARG_WITH(dns-delay,
+ AS_HELP_STRING([--with-dns-delay=SEC], [Retry delay resolving DNS names, default: 60]),
+ [dns_delay=$withval], [dns_delay='no'])
+
AC_ARG_WITH(suspend-time,
AS_HELP_STRING([--with-suspend-time=SEC], [Retry delay for sending to remote, default: 180]),
[suspend_time=$withval], [suspend_time='no'])
@@ -82,6 +86,13 @@ AC_ARG_WITH(logger,
AS_IF([test "x$logger" != "xno"], with_logger="yes", with_logger="no")
AM_CONDITIONAL([ENABLE_LOGGER], [test "x$with_logger" != "xno"])
+AS_IF([test "x$dns_delay" != "xno"],[
+ AS_IF([test "x$dns_delay" = "xyes"],[
+ AC_MSG_ERROR([Must supply argument])])
+ ]
+ AC_DEFINE_UNQUOTED(INET_DNS_DELAY, $dns_delay, [Retry delay for resolving DNS names, default: 60]),
+ dns_delay=60)
+
AS_IF([test "x$suspend_time" != "xno"],[
AS_IF([test "x$suspend_time" = "xyes"],[
AC_MSG_ERROR([Must supply argument])])
@@ -134,6 +145,7 @@ cat <<EOF
Optional features:
logger.........: $with_logger
+ dns retry delay: $dns_delay sec
suspend time...: $suspend_time sec
systemd........: $with_systemd
diff --git a/src/syslogd.c b/src/syslogd.c
index 2264a75..c838c36 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -837,6 +837,11 @@ static void inet_cb(int sd, void *arg)
parsemsg(hname, msg);
}
+/*
+ * Depending on the setup of /etc/resolv.conf, and the system resolver,
+ * a call to this function may be blocked for 10 seconds, or even more,
+ * waiting for a response. See https://serverfault.com/a/562108/122484
+ */
static int nslookup(const char *host, const char *service, struct addrinfo **ai)
{
struct addrinfo hints;
@@ -2405,8 +2410,8 @@ static void forw_lookup(struct filed *f)
char *host = f->f_un.f_forw.f_hname;
char *serv = f->f_un.f_forw.f_serv;
struct addrinfo *ai;
+ time_t now, diff;
int err, first;
- time_t diff;
if (SecureMode > 1) {
if (f->f_un.f_forw.f_addr)
@@ -2419,27 +2424,27 @@ static void forw_lookup(struct filed *f)
/* Called from cfline() for initial lookup? */
first = f->f_type == F_UNUSED ? 1 : 0;
+ now = timer_now();
+ diff = now - f->f_time;
+
/*
- * Not INET_SUSPEND_TIME, but back off a few seconds at least
- * to prevent syslogd from hammering the resolver for every
- * little message that is logged. E.g., at boot when we read
- * the kernel ring buffer.
+ * Back off a minute to prevent unnecessary delays on other log
+ * targets due to being blockd in nslookup(). This means bootup
+ * log messages may not be logged for named remote targets since
+ * networking may not be available until later.
*/
- diff = timer_now() - f->f_time;
- if (!first && diff < 5)
+ if (!first && diff < INET_DNS_DELAY)
return;
err = nslookup(host, serv, &ai);
if (err) {
f->f_type = F_FORW_UNKN;
- f->f_time = timer_now();
- if (!first && !(f->f_flags & SUSP_RETR))
+ f->f_time = now;
+ if (!first)
WARN("Failed resolving '%s:%s': %s", host, serv, gai_strerror(err));
- f->f_flags |= SUSP_RETR; /* Retry silently */
return;
}
- f->f_flags &= ~SUSP_RETR;
f->f_type = F_FORW;
f->f_un.f_forw.f_addr = ai;
f->f_prevcount = 0;
diff --git a/src/syslogd.h b/src/syslogd.h
index 1703df2..a14b6a0 100644
--- a/src/syslogd.h
+++ b/src/syslogd.h
@@ -119,6 +119,10 @@
#define MAXUNAMES 20 /* maximum number of user names */
#define MAXFNAME 200 /* max file pathname length */
+#ifndef INET_DNS_DELAY
+#define INET_DNS_DELAY 60
+#endif
+
#ifndef INET_SUSPEND_TIME
#define INET_SUSPEND_TIME 180 /* equal to 3 minutes */
#endif
@@ -185,7 +189,6 @@
#define MARK 0x008 /* this message is a mark */
#define RFC3164 0x010 /* format log message according to RFC 3164 */
#define RFC5424 0x020 /* format log message according to RFC 5424 */
-#define SUSP_RETR 0x040 /* suspend/forw_unkn, retrying nslookup */
/* Syslog timestamp formats. */
#define BSDFMT_DATELEN 0
--
2.43.0
@@ -1,40 +0,0 @@
From 2d626af27e8f3115175749d183a8b7f91849bf10 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Sun, 14 Jul 2024 17:43:39 +0200
Subject: [PATCH 06/17] Fix annoying gcc warning in rotate_file()
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Organization: Addiva Elektronik
syslogd.c: In function rotate_file:
syslogd.c:1787:69: warning: %s directive output between 0 and 2147483646 bytes may cause result to exceed INT_MAX [-Wformat-truncation=]
1787 | snprintf(cmd, sizeof(cmd), "gzip -f %s", newFile);
| ^~
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index c838c36..461bbb1 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -1786,10 +1786,11 @@ static void rotate_file(struct filed *f, struct stat *stp_or_null)
snprintf(newFile, len, "%s.%d", f->f_un.f_fname, i);
if (!rename(oldFile, newFile) && i > 0) {
- size_t clen = 18 + strlen(newFile) + 1;
+ const char *gzip = "gzip -f";
+ size_t clen = strlen(gzip) + len + 1;
char cmd[clen];
- snprintf(cmd, sizeof(cmd), "gzip -f %s", newFile);
+ snprintf(cmd, clen, "%s %s", gzip, newFile);
system(cmd);
}
}
--
2.43.0
@@ -1,239 +0,0 @@
From 2aa73f85580614b9162aaaa74b2a9e817c6396bd Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 15 Jul 2024 10:46:50 +0200
Subject: [PATCH 07/17] Refactor cfparse() to add a per-keyword parser
Organization: Addiva Elektronik
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 74 +++++++++++++++++++++++++++------------------------
src/syslogd.h | 2 +-
2 files changed, 40 insertions(+), 36 deletions(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index 461bbb1..452513f 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -163,7 +163,7 @@ static int RotateCnt = 5; /* Max number (count) of log files to keep, set wi
/*
* List of notifiers
*/
-static SIMPLEQ_HEAD(notifiers, notifier) nothead = SIMPLEQ_HEAD_INITIALIZER(nothead);
+static TAILQ_HEAD(notifiers, notifier) nothead = TAILQ_HEAD_INITIALIZER(nothead);
/*
* List of peers and sockets for binding.
@@ -184,16 +184,6 @@ char *secure_str; /* string value of secure_mode */
char *rotate_sz_str; /* string value of RotateSz */
char *rotate_cnt_str; /* string value of RotateCnt */
-const struct cfkey {
- const char *key;
- char **var;
-} cfkey[] = {
- { "notify", NULL },
- { "secure_mode", &secure_str },
- { "rotate_size", &rotate_sz_str },
- { "rotate_count", &rotate_cnt_str },
-};
-
/* Function prototypes. */
static int allowaddr(char *s);
void untty(void);
@@ -221,10 +211,10 @@ static void signal_init(void);
static void boot_time_init(void);
static void init(void);
static int strtobytes(char *arg);
-static int cfparse(FILE *fp, struct files *newf, struct notifiers *newn);
+static int cfparse(FILE *fp, struct files *newf);
int decode(char *name, struct _code *codetab);
static void logit(char *, ...);
-static void notifier_add(struct notifiers *newn, const char *program);
+static void notifier_add(char *program, void *arg);
static void notifier_invoke(const char *logfile);
static void notifier_free_all(void);
void reload(int);
@@ -233,6 +223,20 @@ static int validate(struct sockaddr *sa, const char *hname);
static int waitdaemon(int);
static void timedout(int);
+/*
+ * Configuration file keywords, variables, and optional callbacks
+ */
+const struct cfkey {
+ const char *key;
+ char **var;
+ void (*cb)(char *, void *);
+ void *arg;
+} cfkey[] = {
+ { "notify", NULL, notifier_add, &nothead },
+ { "rotate_size", &rotate_sz_str, NULL, NULL },
+ { "rotate_count", &rotate_cnt_str, NULL, NULL },
+ { "secure_mode", &secure_str, NULL, NULL },
+};
/*
* Very basic, and incomplete, check if we're running in a container.
@@ -1816,7 +1820,7 @@ static void rotate_file(struct filed *f, struct stat *stp_or_null)
return;
}
- if (!SIMPLEQ_EMPTY(&nothead))
+ if (!TAILQ_EMPTY(&nothead))
notifier_invoke(f->f_un.f_fname);
}
ftruncate(f->f_file, 0);
@@ -2708,7 +2712,6 @@ static void boot_time_init(void)
*/
static void init(void)
{
- struct notifiers newn = SIMPLEQ_HEAD_INITIALIZER(newn);
struct files newf = SIMPLEQ_HEAD_INITIALIZER(newf);
struct filed *f;
struct peer *pe;
@@ -2762,6 +2765,11 @@ static void init(void)
*/
tzset();
+ /*
+ * Free all notifiers
+ */
+ notifier_free_all();
+
/*
* Read configuration file(s)
*/
@@ -2776,7 +2784,7 @@ static void init(void)
}
}
- if (cfparse(fp, &newf, &newn)) {
+ if (cfparse(fp, &newf)) {
fclose(fp);
return;
}
@@ -2789,13 +2797,6 @@ static void init(void)
fhead = newf;
- /*
- * Free all notifiers
- */
- notifier_free_all();
-
- nothead = newn;
-
/*
* Open or close sockets for local and remote communication
*/
@@ -2815,11 +2816,12 @@ static void init(void)
Initialized = 1;
if (Debug) {
- if (!SIMPLEQ_EMPTY(&nothead)) {
+ if (!TAILQ_EMPTY(&nothead)) {
struct notifier *np;
- SIMPLEQ_FOREACH(np, &nothead, n_link)
+ TAILQ_FOREACH(np, &nothead, n_link) {
printf("notify %s\n", np->n_program);
+ }
printf("\n");
}
@@ -3208,6 +3210,8 @@ const struct cfkey *cfkey_match(char *cline)
if (cfk->var)
*cfk->var = strdup(p);
+ else if (cfk->cb)
+ cfk->cb(p, cfk->arg);
else
memmove(cline, p, strlen(p) + 1);
@@ -3220,7 +3224,7 @@ const struct cfkey *cfkey_match(char *cline)
/*
* Parse .conf file and append to list
*/
-static int cfparse(FILE *fp, struct files *newf, struct notifiers *newn)
+static int cfparse(FILE *fp, struct files *newf)
{
const struct cfkey *cfk;
struct filed *f;
@@ -3286,7 +3290,7 @@ static int cfparse(FILE *fp, struct files *newf, struct notifiers *newn)
}
logit("Parsing %s ...\n", gl.gl_pathv[i]);
- cfparse(fpi, newf, newn);
+ cfparse(fpi, newf);
fclose(fpi);
}
globfree(&gl);
@@ -3294,11 +3298,8 @@ static int cfparse(FILE *fp, struct files *newf, struct notifiers *newn)
}
cfk = cfkey_match(cline);
- if (cfk) {
- if (!strcmp(cfk->key, "notify"))
- notifier_add(newn, cline);
+ if (cfk)
continue;
- }
f = cfline(cline);
if (!f)
@@ -3681,8 +3682,10 @@ static void logit(char *fmt, ...)
fflush(stdout);
}
-static void notifier_add(struct notifiers *newn, const char *program)
+static void notifier_add(char *program, void *arg)
{
+ struct notifiers *newn = (struct notifiers *)arg;
+
while (*program && isspace(*program))
++program;
@@ -3701,7 +3704,7 @@ static void notifier_add(struct notifiers *newn, const char *program)
ERR("Cannot allocate memory for a notify program");
return;
}
- SIMPLEQ_INSERT_TAIL(newn, np, n_link);
+ TAILQ_INSERT_TAIL(newn, np, n_link);
} else
logit("notify: non-existing, or not executable program\n");
}
@@ -3714,7 +3717,7 @@ static void notifier_invoke(const char *logfile)
logit("notify: rotated %s, invoking hooks\n", logfile);
- SIMPLEQ_FOREACH(np, &nothead, n_link) {
+ TAILQ_FOREACH(np, &nothead, n_link) {
childpid = fork();
switch (childpid) {
@@ -3739,7 +3742,8 @@ static void notifier_free_all(void)
{
struct notifier *np, *npnext;
- SIMPLEQ_FOREACH_SAFE(np, &nothead, n_link, npnext) {
+ TAILQ_FOREACH_SAFE(np, &nothead, n_link, npnext) {
+ TAILQ_REMOVE(&nothead, np, n_link);
free(np->n_program);
free(np);
}
diff --git a/src/syslogd.h b/src/syslogd.h
index a14b6a0..14c66a7 100644
--- a/src/syslogd.h
+++ b/src/syslogd.h
@@ -314,7 +314,7 @@ struct filed {
* Log rotation notifiers
*/
struct notifier {
- SIMPLEQ_ENTRY(notifier) n_link;
+ TAILQ_ENTRY(notifier) n_link;
char *n_program;
};
--
2.43.0
@@ -1,42 +0,0 @@
From c15bb6208cdd0e0629a28c10cb448a11aa7a1624 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 15 Jul 2024 14:24:08 +0200
Subject: [PATCH 08/17] Fix gcc warning in vsyslogp_r()
Organization: Addiva Elektronik
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslog.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/src/syslog.c b/src/syslog.c
index 1510258..fbbdfdf 100644
--- a/src/syslog.c
+++ b/src/syslog.c
@@ -267,7 +267,7 @@ vsyslogp_r(int pri, struct syslog_data *data, const char *msgid,
/* Default log format is RFC5424, continues below BSD format */
if (data->log_stat & LOG_RFC3164) {
const char *tag = data->log_tag;
- char tmp[33];
+ char tmp[256];
if (!(data->log_stat & LOG_NLOG)) {
prlen = snprintf(p, tbuf_left, "<%d>", pri);
@@ -303,12 +303,12 @@ vsyslogp_r(int pri, struct syslog_data *data, const char *msgid,
/*
* When sending remote we MUST follow RFC3164 sec 4.1.3,
- * otherwise we "cheat" and allow max lenght hostname,
+ * otherwise we "cheat" and allow max length hostname,
* for either log file or local syslogd -- it is up to
* the local syslogd then to fulfill RFC req. on output
*/
if (data->log_host) {
- strlcpy(tmp, data->log_tag, sizeof(tbuf));
+ strlcpy(tmp, data->log_tag, sizeof(tmp));
tag = tmp;
}
--
2.43.0
@@ -1,285 +0,0 @@
From f5fae387b92e81cc1f1f9e8f6656b20bb9e2e929 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 15 Jul 2024 14:57:54 +0200
Subject: [PATCH 09/17] Fix #83: add support for listen addr:port to .conf file
Organization: Addiva Elektronik
This complements the command line '-b addr:port' support with a 'listen'
directive in the .conf file. The command line listen directives are in
this implementation treated as "static" and cannot be removed using the
.conf file.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 104 +++++++++++++++++++++++++++++++++++++++++---------
src/syslogd.h | 3 +-
2 files changed, 88 insertions(+), 19 deletions(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index 452513f..8ad5109 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -168,12 +168,12 @@ static TAILQ_HEAD(notifiers, notifier) nothead = TAILQ_HEAD_INITIALIZER(nothead)
/*
* List of peers and sockets for binding.
*/
-static SIMPLEQ_HEAD(, peer) pqueue = SIMPLEQ_HEAD_INITIALIZER(pqueue);
+static TAILQ_HEAD(peers, peer) pqueue = TAILQ_HEAD_INITIALIZER(pqueue);
/*
* List fo peers allowed to log to us.
*/
-static SIMPLEQ_HEAD(, allowedpeer) aphead = SIMPLEQ_HEAD_INITIALIZER(aphead);
+static SIMPLEQ_HEAD(allowed, allowedpeer) aphead = SIMPLEQ_HEAD_INITIALIZER(aphead);
/*
* central list of recognized configuration keywords with an optional
@@ -211,6 +211,7 @@ static void signal_init(void);
static void boot_time_init(void);
static void init(void);
static int strtobytes(char *arg);
+static void cflisten(char *ptr, void *arg);
static int cfparse(FILE *fp, struct files *newf);
int decode(char *name, struct _code *codetab);
static void logit(char *, ...);
@@ -232,6 +233,7 @@ const struct cfkey {
void (*cb)(char *, void *);
void *arg;
} cfkey[] = {
+ { "listen", NULL, cflisten, NULL },
{ "notify", NULL, notifier_add, &nothead },
{ "rotate_size", &rotate_sz_str, NULL, NULL },
{ "rotate_count", &rotate_cnt_str, NULL, NULL },
@@ -276,11 +278,24 @@ static int addpeer(struct peer *pe0)
{
struct peer *pe;
+ TAILQ_FOREACH(pe, &pqueue, pe_link) {
+ if (((pe->pe_name == NULL && pe0->pe_name == NULL) ||
+ (pe->pe_name != NULL && pe0->pe_name != NULL && strcmp(pe->pe_name, pe0->pe_name) == 0)) &&
+ ((pe->pe_serv == NULL && pe0->pe_serv == NULL) ||
+ (pe->pe_serv != NULL && pe0->pe_serv != NULL && strcmp(pe->pe_serv, pe0->pe_serv) == 0))) {
+ /* update flags */
+ pe->pe_mark = pe0->pe_mark;
+ pe->pe_mode = pe0->pe_mode;
+
+ return 0;
+ }
+ }
+
pe = calloc(1, sizeof(*pe));
if (pe == NULL)
err(1, "malloc failed");
*pe = *pe0;
- SIMPLEQ_INSERT_TAIL(&pqueue, pe, pe_link);
+ TAILQ_INSERT_TAIL(&pqueue, pe, pe_link);
return 0;
}
@@ -406,7 +421,6 @@ int main(int argc, char *argv[])
pid_t ppid = 1;
int no_sys = 0;
int pflag = 0;
- int bflag = 0;
char *ptr;
int ch;
@@ -434,13 +448,13 @@ int main(int argc, char *argv[])
break;
case 'b':
- bflag = 1;
ptr = strchr(optarg, ':');
if (ptr)
*ptr++ = 0;
addpeer(&(struct peer) {
.pe_name = optarg,
.pe_serv = ptr,
+ .pe_mark = -1,
});
break;
@@ -503,6 +517,7 @@ int main(int argc, char *argv[])
addpeer(&(struct peer) {
.pe_name = optarg,
.pe_mode = 0666,
+ .pe_mark = -1,
});
break;
@@ -538,13 +553,6 @@ int main(int argc, char *argv[])
if ((argc -= optind))
return usage(1);
- /* Default to listen to :514 (syslog/udp) */
- if (!bflag)
- addpeer(&(struct peer) {
- .pe_name = NULL,
- .pe_serv = "syslog",
- });
-
/* Figure out where to read system log messages from */
if (!pflag) {
/* Do we run under systemd-journald (Requires=syslog.socket)? */
@@ -556,6 +564,7 @@ int main(int argc, char *argv[])
addpeer(&(struct peer) {
.pe_name = _PATH_LOG,
.pe_mode = 0666,
+ .pe_mark = -1,
});
}
}
@@ -2545,7 +2554,9 @@ void die(int signo)
/*
* Close all UNIX and inet sockets
*/
- SIMPLEQ_FOREACH_SAFE(pe, &pqueue, pe_link, next) {
+ TAILQ_FOREACH_SAFE(pe, &pqueue, pe_link, next) {
+ TAILQ_REMOVE(&pqueue, pe, pe_link);
+
for (size_t i = 0; i < pe->pe_socknum; i++) {
logit("Closing socket %d ...\n", pe->pe_sock[i]);
socket_close(pe->pe_sock[i]);
@@ -2713,8 +2724,9 @@ static void boot_time_init(void)
static void init(void)
{
struct files newf = SIMPLEQ_HEAD_INITIALIZER(newf);
+ struct peer *pe, *penext;
struct filed *f;
- struct peer *pe;
+ int bflag = 0;
FILE *fp;
char *p;
@@ -2765,6 +2777,16 @@ static void init(void)
*/
tzset();
+ /*
+ * mark
+ */
+ TAILQ_FOREACH(pe, &pqueue, pe_link) {
+ if (pe->pe_mark == -1)
+ continue;
+
+ pe->pe_mark = 1;
+ }
+
/*
* Free all notifiers
*/
@@ -2797,10 +2819,31 @@ static void init(void)
fhead = newf;
+ /*
+ * Ensure a default listen *:514 exists (compat)
+ */
+ TAILQ_FOREACH(pe, &pqueue, pe_link) {
+ if (pe->pe_mark == 1)
+ continue; /* marked for deletion */
+ if (pe->pe_name && pe->pe_name[0] == '/')
+ continue; /* named pipe */
+ if (pe->pe_name || pe->pe_serv) {
+ bflag = 1;
+ break; /* static or from .conf */
+ }
+ }
+ if (!bflag) {
+ /* Default to listen to :514 (syslog/udp) */
+ addpeer(&(struct peer) {
+ .pe_name = NULL,
+ .pe_serv = "514",
+ });
+ }
+
/*
* Open or close sockets for local and remote communication
*/
- SIMPLEQ_FOREACH(pe, &pqueue, pe_link) {
+ TAILQ_FOREACH(pe, &pqueue, pe_link) {
if (pe->pe_name && pe->pe_name[0] == '/') {
create_unix_socket(pe);
} else {
@@ -2808,11 +2851,23 @@ static void init(void)
socket_close(pe->pe_sock[i]);
pe->pe_socknum = 0;
- if (SecureMode < 2)
+ /* skip any marked for deletion */
+ if (SecureMode < 2 && pe->pe_mark <= 0)
create_inet_socket(pe);
}
}
+ /*
+ * Sweep
+ */
+ TAILQ_FOREACH_SAFE(pe, &pqueue, pe_link, penext) {
+ if (pe->pe_mark <= 0)
+ continue;
+
+ TAILQ_REMOVE(&pqueue, pe, pe_link);
+ free(pe);
+ }
+
Initialized = 1;
if (Debug) {
@@ -2874,6 +2929,19 @@ static void init(void)
logit("syslogd: restarted.\n");
}
+static void cflisten(char *ptr, void *arg)
+{
+ char *peer = ptr;
+
+ ptr = strchr(peer, ':');
+ if (ptr)
+ *ptr++ = 0;
+ addpeer(&(struct peer) {
+ .pe_name = peer,
+ .pe_serv = ptr,
+ });
+}
+
static void cfrot(char *ptr, struct filed *f)
{
char *c;
@@ -3096,7 +3164,7 @@ static struct filed *cfline(char *line)
if (bp)
*bp++ = 0;
else
- bp = "syslog"; /* default: 514/udp */
+ bp = "514"; /* default: 514/udp */
strlcpy(f->f_un.f_forw.f_hname, p, sizeof(f->f_un.f_forw.f_hname));
strlcpy(f->f_un.f_forw.f_serv, bp, sizeof(f->f_un.f_forw.f_serv));
@@ -3426,7 +3494,7 @@ static int allowaddr(char *s)
goto err;
}
} else {
- if ((se = getservbyname("syslog", "udp")))
+ if ((se = getservbyname("514", "udp")))
ap->port = ntohs(se->s_port);
else
/* sanity, should not happen */
diff --git a/src/syslogd.h b/src/syslogd.h
index 14c66a7..d74c0ed 100644
--- a/src/syslogd.h
+++ b/src/syslogd.h
@@ -225,9 +225,10 @@
* Struct to hold records of peers and sockets
*/
struct peer {
- SIMPLEQ_ENTRY(peer) pe_link;
+ TAILQ_ENTRY(peer) pe_link;
const char *pe_name;
const char *pe_serv;
+ int pe_mark;
mode_t pe_mode;
int pe_sock[16];
size_t pe_socknum;
--
2.43.0
@@ -1,346 +0,0 @@
From ad8dedd04a979279d245b53a60311ad91acaaf14 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 15 Jul 2024 15:02:32 +0200
Subject: [PATCH 10/17] Fix #82: retry creating UNIX and network sockets on
failure
Organization: Addiva Elektronik
When starting up, or on SIGHUP, syslogd may fail to create a UNIX socket
or (bind) an Internet socket. The latter may be because the system is
in bootstrap and the interface and/or address syslogd tries to bind() to
does not yet exist.
This commit adds a very basic retry loop every five seconds.
Also, with the new retry logic it was deemed worth it to increase the
logging from syslogd itself. I.e., when failing to create a socket,
or when retrying and succeeding, as well as when closing sockets. In
particular when opening and closing Internet facing ports.
Since startup, or reconfiguration, is not failure to send() the we do
not want to inadvertedly trigger F_FORW_SUSP for remote log actions.
This is the reason for the ENONET error code from socket_ffs(), to
ensure we retry sending to remote on the next log message instead of
waiting 180 sec. Ordering at boot, or reconf, is also the reason for
setting Initialized earlier -- this prevents inadvertedly logging to the
console instead of to a file that actually is open. We can usually log
to file but maybe not yet to a remote.
To not terrify casual readers of the logs, messages for opening and
closing Inet (Internet) sockets are tracked from what context they were
opened in. Context, in this context, is the secure_mode switch in which
syslogd only opens UDP sockets for sending messages to other syslog
servers, i.e., without binding to a server port.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/socket.c | 1 +
src/syslogd.c | 145 +++++++++++++++++++++++++++++++++++---------------
2 files changed, 102 insertions(+), 44 deletions(-)
diff --git a/src/socket.c b/src/socket.c
index 4b64888..8c32dac 100644
--- a/src/socket.c
+++ b/src/socket.c
@@ -217,6 +217,7 @@ int socket_ffs(int family)
return entry->sd;
}
+ errno = ENONET;
return -1;
}
diff --git a/src/syslogd.c b/src/syslogd.c
index 8ad5109..402a85e 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -160,6 +160,9 @@ static int rotate_opt; /* Set if command line option has been given
static off_t RotateSz = 0; /* Max file size (bytes) before rotating, disabled by default */
static int RotateCnt = 5; /* Max number (count) of log files to keep, set with -c <NUM> */
+struct timeval *retry = NULL; /* Set by init() to &init_tv whenever retry jobs exist */
+struct timeval init_tv = { 5, 0 }; /* Retry every 5 seconds. */
+
/*
* List of notifiers
*/
@@ -209,6 +212,7 @@ void debug_switch();
void die(int sig);
static void signal_init(void);
static void boot_time_init(void);
+static void retry_init(void);
static void init(void);
static int strtobytes(char *arg);
static void cflisten(char *ptr, void *arg);
@@ -642,7 +646,7 @@ no_klogd:
for (;;) {
int rc;
- rc = socket_poll(NULL);
+ rc = socket_poll(retry);
if (restart > 0) {
restart--;
logit("\nReceived SIGHUP, reloading syslogd.\n");
@@ -660,8 +664,11 @@ no_klogd:
rotate_all_files();
}
- if (rc < 0 && errno != EINTR)
- ERR("select()");
+ if (rc < 0) {
+ if (errno != EINTR)
+ ERR("select()");
+ } else if (rc == 0)
+ retry_init();
if (KernLog)
sys_seqno_save();
@@ -769,14 +776,14 @@ static void unix_cb(int sd, void *arg)
parsemsg(LocalHostName, msg);
}
-static void create_unix_socket(struct peer *pe)
+static int create_unix_socket(struct peer *pe)
{
struct sockaddr_un sun;
struct addrinfo ai;
int sd = -1;
if (pe->pe_socknum)
- return; /* Already set up */
+ return 0; /* Already set up */
memset(&ai, 0, sizeof(ai));
ai.ai_addr = (struct sockaddr *)&sun;
@@ -790,11 +797,12 @@ static void create_unix_socket(struct peer *pe)
if (sd < 0)
goto err;
- logit("Created UNIX socket %d ...\n", sd);
+ NOTE("Created UNIX socket %s", sun.sun_path);
pe->pe_sock[pe->pe_socknum++] = sd;
- return;
+ return 0;
err:
ERR("cannot create %s", pe->pe_name);
+ return 1;
}
static void unmapped(struct sockaddr *sa)
@@ -866,7 +874,7 @@ static int nslookup(const char *host, const char *service, struct addrinfo **ai)
/* Reset resolver cache and retry name lookup */
res_init();
- logit("nslookup '%s:%s'\n", node ?: "none", service);
+ logit("nslookup '%s:%s'\n", node ?: "*", service);
memset(&hints, 0, sizeof(hints));
hints.ai_flags = !node ? AI_PASSIVE : 0;
hints.ai_family = family;
@@ -875,22 +883,25 @@ static int nslookup(const char *host, const char *service, struct addrinfo **ai)
return getaddrinfo(node, service, &hints, ai);
}
-static void create_inet_socket(struct peer *pe)
+static int create_inet_socket(struct peer *pe)
{
struct addrinfo *ai, *res;
- int sd, err;
+ int err, rc = 0;
+
+ if (pe->pe_socknum)
+ return 0; /* Already set up */
err = nslookup(pe->pe_name, pe->pe_serv, &res);
if (err) {
- ERRX("%s/udp service unknown: %s", pe->pe_serv,
- gai_strerror(err));
- return;
+ ERRX("%s:%s/udp service unknown: %s", pe->pe_name ?: "*", pe->pe_serv, gai_strerror(err));
+ return 1;
}
for (ai = res; ai; ai = ai->ai_next) {
+ int sd;
+
if (pe->pe_socknum + 1 >= NELEMS(pe->pe_sock)) {
- WARN("Only %zd IP addresses per socket supported.",
- NELEMS(pe->pe_sock));
+ WARN("Only %zd IP addresses per socket supported.", NELEMS(pe->pe_sock));
break;
}
@@ -900,15 +911,35 @@ static void create_inet_socket(struct peer *pe)
ai->ai_flags &= ~AI_SECURE;
sd = socket_create(ai, inet_cb, NULL);
- if (sd < 0)
+ if (sd < 0) {
+ WARN("Failed creating socket for %s:%s: %s", pe->pe_name ?: "*",
+ pe->pe_serv, strerror(errno));
+ rc = 1;
continue;
+ }
- logit("Created inet socket %d for %s:%s ...\n", sd,
- pe->pe_name, pe->pe_serv);
+ if (!SecureMode) {
+ pe->pe_mode |= 01000;
+ NOTE("Opened inet socket %s:%s", pe->pe_name ?: "*", pe->pe_serv);
+ }
pe->pe_sock[pe->pe_socknum++] = sd;
}
freeaddrinfo(res);
+ if (rc && pe->pe_socknum == 0)
+ return rc;
+
+ return 0;
+}
+
+static void close_socket(struct peer *pe)
+{
+ for (size_t i = 0; i < pe->pe_socknum; i++) {
+ if (pe->pe_mode & 01000)
+ NOTE("Closing inet socket %s:%s", pe->pe_name ?: "*", pe->pe_serv);
+ socket_close(pe->pe_sock[i]);
+ }
+ pe->pe_socknum = 0;
}
void untty(void)
@@ -1947,6 +1978,7 @@ void fprintlog_write(struct filed *f, struct iovec *iov, int iovcnt, int flags)
if (lsent != len) {
switch (errno) {
case ENOBUFS:
+ case ENONET: /* returned by socket_ffs() */
case ENETDOWN:
case ENETUNREACH:
case EHOSTUNREACH:
@@ -2556,11 +2588,7 @@ void die(int signo)
*/
TAILQ_FOREACH_SAFE(pe, &pqueue, pe_link, next) {
TAILQ_REMOVE(&pqueue, pe, pe_link);
-
- for (size_t i = 0; i < pe->pe_socknum; i++) {
- logit("Closing socket %d ...\n", pe->pe_sock[i]);
- socket_close(pe->pe_sock[i]);
- }
+ close_socket(pe);
free(pe);
}
@@ -2718,6 +2746,31 @@ static void boot_time_init(void)
#endif
}
+/*
+ * Used by init() to trigger retries of, e.g., binding to interfaces.
+ */
+static void retry_init(void)
+{
+ struct peer *pe;
+ int fail = 0;
+
+ logit("Retrying socket init ...\n");
+ TAILQ_FOREACH(pe, &pqueue, pe_link) {
+ if (pe->pe_name && pe->pe_name[0] == '/') {
+ fail |= create_unix_socket(pe);
+ } else {
+ /* skip any marked for deletion */
+ if (SecureMode < 2)
+ fail |= create_inet_socket(pe);
+ }
+ }
+
+ if (!fail) {
+ logit("Socket re-init done.\n");
+ retry = NULL;
+ }
+}
+
/*
* INIT -- Initialize syslogd from configuration table
*/
@@ -2725,8 +2778,8 @@ static void init(void)
{
struct files newf = SIMPLEQ_HEAD_INITIALIZER(newf);
struct peer *pe, *penext;
+ int bflag = 0, fail = 0;
struct filed *f;
- int bflag = 0;
FILE *fp;
char *p;
@@ -2840,23 +2893,6 @@ static void init(void)
});
}
- /*
- * Open or close sockets for local and remote communication
- */
- TAILQ_FOREACH(pe, &pqueue, pe_link) {
- if (pe->pe_name && pe->pe_name[0] == '/') {
- create_unix_socket(pe);
- } else {
- for (size_t i = 0; i < pe->pe_socknum; i++)
- socket_close(pe->pe_sock[i]);
- pe->pe_socknum = 0;
-
- /* skip any marked for deletion */
- if (SecureMode < 2 && pe->pe_mark <= 0)
- create_inet_socket(pe);
- }
- }
-
/*
* Sweep
*/
@@ -2865,11 +2901,35 @@ static void init(void)
continue;
TAILQ_REMOVE(&pqueue, pe, pe_link);
+ close_socket(pe);
free(pe);
}
Initialized = 1;
+ flog(LOG_SYSLOG | LOG_INFO, "syslogd v" VERSION ": restart.");
+ logit("syslogd: restarted.\n");
+
+ /*
+ * Open or close sockets for local and remote communication
+ * These may be delayed, so start local logging first.
+ */
+ TAILQ_FOREACH(pe, &pqueue, pe_link) {
+ if (pe->pe_name && pe->pe_name[0] == '/') {
+ fail |= create_unix_socket(pe);
+ } else {
+ close_socket(pe);
+
+ if (SecureMode < 2)
+ fail |= create_inet_socket(pe);
+ }
+ }
+
+ if (fail)
+ retry = &init_tv;
+ else
+ retry = NULL;
+
if (Debug) {
if (!TAILQ_EMPTY(&nothead)) {
struct notifier *np;
@@ -2924,9 +2984,6 @@ static void init(void)
printf("\n");
}
}
-
- flog(LOG_SYSLOG | LOG_INFO, "syslogd v" VERSION ": restart.");
- logit("syslogd: restarted.\n");
}
static void cflisten(char *ptr, void *arg)
--
2.43.0
@@ -1,30 +0,0 @@
From 87ccd3eb37087ffb4b5f5b0322a558522a705215 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Thu, 18 Jul 2024 11:42:36 +0200
Subject: [PATCH 11/17] Read *.conf files from include/ directories sorted
Organization: Addiva Elektronik
No point in "saving time" on this operation. It is more important to
users that we read the files in a predefined order, alphabetically.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index 402a85e..87da475 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -3400,7 +3400,7 @@ static int cfparse(FILE *fp, struct files *newf)
p++;
logit("Searching for %s ...\n", p);
- if (glob(p, GLOB_NOSORT, NULL, &gl))
+ if (glob(p, 0, NULL, &gl))
logit("No files match %s\n", p);
for (size_t i = 0; i < gl.gl_pathc; i++) {
--
2.43.0
@@ -1,44 +0,0 @@
From 035dccad53efcd4237f040dc702ab435212ecf03 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Sun, 21 Jul 2024 19:15:48 +0200
Subject: [PATCH 12/17] Fix #87: segfault on shutdown
Organization: Addiva Elektronik
Regression introduced in in 36295e3, for issue #82.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index 87da475..64da821 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -2578,11 +2578,6 @@ void die(int signo)
*/
timer_exit();
- /*
- * Close all open log files.
- */
- close_open_log_files();
-
/*
* Close all UNIX and inet sockets
*/
@@ -2592,6 +2587,11 @@ void die(int signo)
free(pe);
}
+ /*
+ * Close all open log files.
+ */
+ close_open_log_files();
+
kern_console_on();
exit(0);
--
2.43.0
@@ -1,62 +0,0 @@
From c7267011224ebd28d8a9daccd589109288fbde11 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 26 Aug 2024 11:47:10 +0200
Subject: [PATCH 13/17] Fix #85: logging to remote IPv6 address does not work
Organization: Addiva Elektronik
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 13 ++++++++++++-
test/fwd.sh | 4 ++--
2 files changed, 14 insertions(+), 3 deletions(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index 64da821..a2502c9 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -3216,8 +3216,19 @@ static struct filed *cfline(char *line)
switch (*p) {
case '@':
cfopts(p, f);
+ p++;
+ if (*p == '[') {
+ p++;
- bp = strchr(++p, ':');
+ q = strchr(p, ']');
+ if (!q) {
+ ERR("Invalid IPv6 address in remote target, missing ']'");
+ break;
+ }
+ *q++ = 0;
+ bp = strchr(q, ':');
+ } else
+ bp = strchr(p, ':');
if (bp)
*bp++ = 0;
else
diff --git a/test/fwd.sh b/test/fwd.sh
index 70fba5b..e37dc1f 100755
--- a/test/fwd.sh
+++ b/test/fwd.sh
@@ -13,7 +13,7 @@ MSG="fwd and allow"
cat <<EOF >"${CONFD}/fwd.conf"
kern.* /dev/null
-ntp.* @127.0.0.2:${PORT2} ;RFC5424
+ntp.* @[::1]:${PORT2} ;RFC5424
EOF
reload
@@ -23,7 +23,7 @@ kern.* /dev/null
*.*;kern.none ${LOG2} ;RFC5424
EOF
-setup2 -m0 -a 127.0.0.2:* -b ":${PORT2}"
+setup2 -m0 -a "[::1]:*" -b ":${PORT2}"
print "TEST: Starting"
--
2.43.0
@@ -1,45 +0,0 @@
From 1a2e13cb3f3e4fb9f33a56cc87fb96ebc3bb45c7 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 26 Aug 2024 11:49:27 +0200
Subject: [PATCH 14/17] Fix #86: adapt facilities for RFC5424 compliance
Organization: Addiva Elektronik
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslog.h | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/src/syslog.h b/src/syslog.h
index 873e7f8..0a9c31b 100644
--- a/src/syslog.h
+++ b/src/syslog.h
@@ -118,8 +118,10 @@ CODE prioritynames[] = {
#define LOG_FTP (11<<3) /* ftp daemon */
#define LOG_NTP (12<<3) /* NTP subsystem */
#define LOG_SECURITY (13<<3) /* Log audit, for audit trails */
+#define LOG_AUDIT LOG_SECURITY /* Alias for RFC5424 compat. */
#define LOG_CONSOLE (14<<3) /* Log alert */
#define LOG_CRON_SOL (15<<3) /* clock daemon (Solaris) */
+#define LOG_CRON2 LOG_CRON_SOL /* Alias for RFC5424 compat. */
#define LOG_LOCAL0 (16<<3) /* reserved for local use */
#define LOG_LOCAL1 (17<<3) /* reserved for local use */
#define LOG_LOCAL2 (18<<3) /* reserved for local use */
@@ -141,6 +143,7 @@ CODE facilitynames[] = {
{ "console", LOG_CONSOLE },
{ "cron", LOG_CRON },
{ "cron_sol", LOG_CRON_SOL }, /* Solaris cron */
+ { "cron2", LOG_CRON2 },
{ "daemon", LOG_DAEMON },
{ "ftp", LOG_FTP },
{ "kern", LOG_KERN },
@@ -150,6 +153,7 @@ CODE facilitynames[] = {
{ "news", LOG_NEWS },
{ "ntp", LOG_NTP },
{ "security", LOG_SECURITY },
+ { "audit", LOG_AUDIT },
{ "syslog", LOG_SYSLOG },
{ "user", LOG_USER },
{ "uucp", LOG_UUCP },
--
2.43.0
@@ -1,34 +0,0 @@
From d6e7d2c6ee36cfc67eeef643d4a6c69dfbbd36ab Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 26 Aug 2024 11:50:13 +0200
Subject: [PATCH 15/17] Fix #88: initial delay for unresolvable remote target
Organization: Addiva Elektronik
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index a2502c9..fecf281 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -871,8 +871,14 @@ static int nslookup(const char *host, const char *service, struct addrinfo **ai)
if (!node || !node[0])
node = NULL;
- /* Reset resolver cache and retry name lookup */
+ /*
+ * Reset resolver cache and retry name lookup. The use of
+ * `_res` here seems to be the most portable way to adjust
+ * the per-process timeout and retry.
+ */
res_init();
+ _res.retrans = 1;
+ _res.retry = 1;
logit("nslookup '%s:%s'\n", node ?: "*", service);
memset(&hints, 0, sizeof(hints));
--
2.43.0
@@ -1,123 +0,0 @@
From fbded7ec91a0747b4d9c9059ef48aebb5d5fc4e8 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Tue, 27 Aug 2024 13:32:18 +0200
Subject: [PATCH 16/17] Fix #89: data corruption using .conf file listen
directive
Organization: Addiva Elektronik
The addpeer() function must save a copy of the name:service argument,
otherwise, when called from cfparse(), the contents of the string will
be corrupted.
Also, add a delpeer() function to wrap the logic for when closing and
deleting peers when stopping or reloading syslogd.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 47 +++++++++++++++++++++++++++++++++--------------
src/syslogd.h | 4 ++--
2 files changed, 35 insertions(+), 16 deletions(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index fecf281..9b8dc24 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -298,12 +298,43 @@ static int addpeer(struct peer *pe0)
pe = calloc(1, sizeof(*pe));
if (pe == NULL)
err(1, "malloc failed");
+
*pe = *pe0;
+ if (pe0->pe_name)
+ pe->pe_name = strdup(pe0->pe_name);
+ if (pe0->pe_serv)
+ pe->pe_serv = strdup(pe0->pe_serv);
+
TAILQ_INSERT_TAIL(&pqueue, pe, pe_link);
return 0;
}
+static void close_socket(struct peer *pe)
+{
+ for (size_t i = 0; i < pe->pe_socknum; i++) {
+ if (pe->pe_mode & 01000)
+ NOTE("Closing inet socket %s:%s", pe->pe_name ?: "*", pe->pe_serv);
+ socket_close(pe->pe_sock[i]);
+ }
+ pe->pe_socknum = 0;
+}
+
+static void delpeer(struct peer *pe)
+{
+ if (!pe)
+ return;
+
+ close_socket(pe);
+
+ if (pe->pe_name)
+ free(pe->pe_name);
+ if (pe->pe_serv)
+ free(pe->pe_serv);
+
+ free(pe);
+}
+
static void sys_seqno_load(void)
{
char buf[32], *str;
@@ -938,16 +969,6 @@ static int create_inet_socket(struct peer *pe)
return 0;
}
-static void close_socket(struct peer *pe)
-{
- for (size_t i = 0; i < pe->pe_socknum; i++) {
- if (pe->pe_mode & 01000)
- NOTE("Closing inet socket %s:%s", pe->pe_name ?: "*", pe->pe_serv);
- socket_close(pe->pe_sock[i]);
- }
- pe->pe_socknum = 0;
-}
-
void untty(void)
{
#ifdef HAVE_SETSID
@@ -2589,8 +2610,7 @@ void die(int signo)
*/
TAILQ_FOREACH_SAFE(pe, &pqueue, pe_link, next) {
TAILQ_REMOVE(&pqueue, pe, pe_link);
- close_socket(pe);
- free(pe);
+ delpeer(pe);
}
/*
@@ -2907,8 +2927,7 @@ static void init(void)
continue;
TAILQ_REMOVE(&pqueue, pe, pe_link);
- close_socket(pe);
- free(pe);
+ delpeer(pe);
}
Initialized = 1;
diff --git a/src/syslogd.h b/src/syslogd.h
index d74c0ed..0dce0ed 100644
--- a/src/syslogd.h
+++ b/src/syslogd.h
@@ -226,8 +226,8 @@
*/
struct peer {
TAILQ_ENTRY(peer) pe_link;
- const char *pe_name;
- const char *pe_serv;
+ char *pe_name;
+ char *pe_serv;
int pe_mark;
mode_t pe_mode;
int pe_sock[16];
--
2.43.0
@@ -1,47 +0,0 @@
From 691aea6cbe27134d4d4106bb0bca396aff2802f9 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Tue, 27 Aug 2024 13:35:03 +0200
Subject: [PATCH 17/17] Fix #90: add support for IPv6 addresses in listen
directive
Organization: Addiva Elektronik
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 20 +++++++++++++++++++-
1 file changed, 19 insertions(+), 1 deletion(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index 9b8dc24..033be84 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -3014,8 +3014,26 @@ static void init(void)
static void cflisten(char *ptr, void *arg)
{
char *peer = ptr;
+ char *p;
+
+ while (*peer && isspace(*peer))
+ ++peer;
+
+ logit("cflisten[%s]\n", peer);
+
+ p = peer;
+ if (*p == '[') {
+ p++;
+
+ p = strchr(p, ']');
+ if (!p) {
+ ERR("Invalid IPv6 address in listen '%s', missing ']'", peer);
+ return;
+ }
+ *p++ = 0;
+ }
- ptr = strchr(peer, ':');
+ ptr = strchr(p, ':');
if (ptr)
*ptr++ = 0;
addpeer(&(struct peer) {
--
2.43.0
@@ -0,0 +1,28 @@
From 8e230d3f2e1e33691998862e99ab4e13410527b9 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Wed, 8 Jan 2025 07:49:06 +0100
Subject: [PATCH 01/16] Drop redundant initial call to localtime_r()
Organization: Wires
Fixes #94
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index 17115fc..5ad4dbc 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -1508,7 +1508,6 @@ void printsys(char *msg)
*/
if (KeepKernTime || !sys_seqno_init) {
now = boot_time + ustime / 1000000;
- localtime_r(&now, &buffer.timestamp.tm);
} else {
struct timeval tv;
--
2.43.0
@@ -0,0 +1,28 @@
From 13c8071821ad27247061dbf4efe5a34505520bc1 Mon Sep 17 00:00:00 2001
From: Patrick Oppenlander <patrick.oppenlander@gmail.com>
Date: Thu, 23 Jan 2025 15:22:57 +1100
Subject: [PATCH 02/16] fix local hostname '+@', '-@' support
Organization: Wires
Signed-off-by: Patrick Oppenlander <patrick.oppenlander@gmail.com>
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index 5ad4dbc..c07e143 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -3895,7 +3895,7 @@ static int cfparse(FILE *fp, struct files *newf)
char *local = LocalHostName;
while (i < sizeof(host) - 1 && *local)
- host[i++] = *local;
+ host[i++] = *local++;
p++;
} else if (!isprint(*p) || isblank(*p))
break;
--
2.43.0
@@ -0,0 +1,31 @@
From 979edb2515d24174fe9a3e2d6402d62172028c52 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Sat, 1 Feb 2025 20:33:19 +0100
Subject: [PATCH 03/16] Fix #95: printsys(), minor code simplification
Organization: Wires
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index c07e143..f812d9e 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -1511,11 +1511,11 @@ void printsys(char *msg)
} else {
struct timeval tv;
- now = time(NULL);
if (gettimeofday(&tv, NULL) == -1) {
tv.tv_sec = time(NULL);
tv.tv_usec = 0;
}
+ now = tv.tv_sec;
ustime = tv.tv_usec;
}
--
2.43.0
@@ -0,0 +1,31 @@
From 360dfe4b6b17378990daef797a7e6a551c799b98 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Sun, 2 Feb 2025 06:34:16 +0100
Subject: [PATCH 04/16] Fix #98: fprintlog_first(), drop superfluous call
Organization: Wires
The call to check_timestamp() is not needed (anymore) already called in
logmsg(), which is the only way of entering this function (today).
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 3 ---
1 file changed, 3 deletions(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index f812d9e..6748cc6 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -2424,9 +2424,6 @@ static void fprintlog_first(struct filed *f, struct buf_msg *buffer)
logit("Called fprintlog_first(), ");
- /* Messages generated by syslogd itself may not have a timestamp */
- check_timestamp(buffer);
-
if (f->f_type != F_FORW_SUSP && f->f_type != F_FORW_UNKN) {
f->f_time = timer_now();
f->f_prevcount = 0;
--
2.43.0
@@ -0,0 +1,118 @@
From 472c3d6a24e43f8186ce069da267e9ae52c18699 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Thu, 27 Feb 2025 19:07:11 +0100
Subject: [PATCH 05/16] Fix #100: parsing of userspace messages in /dev/kmsg
Organization: Wires
Some applications that inject log messages to /dev/kmsg do not use a
space separating the APP_NAME (and optional PID), while some do. So we
need to support the following variants for the human readable payload,
as defined in [1]:
1. APP: MESG
2. APP:MESG
3. APP MESG
4. APP[PID]: MESG
5. APP[PID]:MESG
6. APP[PID] MESG
Prior to this change, 4 & 5 were treated the same, causing #100, and the
other alternatives were not supported at all. This patch drops the bad
local implementation in printsys() in favor of the generic parsemsg()
helper function for RFC3164 messages, which properly extracts both the
application name and PID if present.
This helper's ': ' separator check is relaxed since some clients only
send ':' (no space) before the message. The RFC can be interpreted
either way, so we now allow either/or or no separator.
[1]: https://www.kernel.org/doc/Documentation/ABI/testing/dev-kmsg
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 55 +++++++++++++++++++++++++++------------------------
1 file changed, 29 insertions(+), 26 deletions(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index 6748cc6..b52af73 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -1242,16 +1242,38 @@ parsemsg_rfc3164_app_name_procid(char **msg, char **app_name, char **procid)
procid_length = 0;
}
- /* Separator. */
- if (m[0] != ':' || m[1] != ' ')
- goto bad;
+ /*
+ * Relaxed separator check. This function is used both for
+ * incoming remote/local syslog messages, and the /dev/kmsg
+ * printsys() function.
+ *
+ * RFC3164 sec. 4.1.3 states that: "the conclusion of the TAG
+ * field has been seen to be the left square bracket character
+ * ('['), a colon character (':'), or a space character". This
+ * uncertainty continues in sec. 5.3: "a colon and a space
+ * character *usually* follow the TAG" (emphasis added).
+ *
+ * Hence, we should be prepared for any of:
+ * - APP: msg
+ * - APP:msg
+ * - APP msg
+ * - APP[PID]: msg
+ * - APP[PID]:msg
+ * - APP[PID] msg
+ */
+ if (*m == ':') {
+ m++;
+ if (isblank(*m))
+ m++;
+ } else if (isblank(*m))
+ m++;
/* Split strings from input. */
app_name_begin[app_name_length] = '\0';
if (procid_begin != 0)
procid_begin[procid_length] = '\0';
- *msg = m + 2;
+ *msg = m;
*app_name = app_name_begin;
*procid = procid_begin;
return;
@@ -1630,29 +1652,10 @@ void printsys(char *msg)
/*
* Check for user writing to /dev/kmsg before /dev/log
* is up. Syntax to write: <PRI>APP_NAME[PROC_ID]:msg
+ * Kernel facility is 0, anything != 0 is userspace.
*/
- if (buffer.pri & LOG_FACMASK) {
- for (q = p; *q && !isspace(*q) && *q != '['; q++)
- ;
-
- if (*q == '[') {
- char *ptr = &q[1];
-
- while (*ptr && isdigit(*ptr))
- ptr++;
-
- if (ptr[0] == ']' && ptr[1] == ':') {
- *ptr++ = 0;
- *q++ = 0;
-
- buffer.app_name = p;
- buffer.proc_id = q;
-
- /* user log message cont. here */
- p = &ptr[1];
- }
- }
- }
+ if (buffer.pri & LOG_FACMASK)
+ parsemsg_rfc3164_app_name_procid(&p, &buffer.app_name, &buffer.proc_id);
q = lp;
while (*p != '\0' && (c = *p++) != '\n' && q < &line[MAXLINE])
--
2.43.0
@@ -0,0 +1,99 @@
From 8cdf4b0c4b9914b8b7aa1c1c1d76dad0fa429115 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Sat, 1 Mar 2025 09:23:01 +0100
Subject: [PATCH 06/16] Fix #93: update documentation on behavior of -T flag
Organization: Wires
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
man/syslogd.8 | 17 ++++++++++-------
src/syslogd.c | 10 +++++-----
2 files changed, 15 insertions(+), 12 deletions(-)
diff --git a/man/syslogd.8 b/man/syslogd.8
index f3e6ad2..7534529 100644
--- a/man/syslogd.8
+++ b/man/syslogd.8
@@ -411,10 +411,13 @@ the command line option always wins, so it must be removed for
.Nm
to consider the .conf file option instead.
.It Fl T
-Always use the local time and date for messages received from the network,
-instead of the timestamp field supplied in the message by the remote host.
-This is useful if some of the originating hosts cannot keep time properly
-or are unable to generate a correct timestamp.
+Always use the local time and date for messages instead of the timestamp
+field in the log message. This applies to both messages received from a
+remote syslog server and locally originated. Useful if the originating
+hosts cannot keep time properly or are unable to generate a correct
+timestamp. See
+.Fl t
+for details on the timestamp of (local) kernel messages.
.It Fl t
Keep (trust) kernel timestamp.
.Pp
@@ -472,9 +475,9 @@ API included with the
.Nm sysklogd
project.
.Pp
-The date and time are taken from the received message. If the format of
-the timestamp field is incorrect, time obtained from the local host is
-used instead. This can be overridden by the
+The date and time for a log message are by default read from the
+received message. If the format of the timestamp field is incorrect,
+the time of reception is used instead. See also the
.Fl T
flag.
.Sh SECURITY
diff --git a/src/syslogd.c b/src/syslogd.c
index b52af73..5a40732 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -148,7 +148,7 @@ static int no_compress; /* don't compress messages (1=pipes, 2=all) */
static int secure_opt; /* sink for others, log to remote, or only unix domain socks */
static int secure_mode; /* same as above but from syslog.conf, only if cmdline unset */
-static int RemoteAddDate; /* Always set the date on remote messages */
+static int AlwaysAddDate; /* Always use our timestamp for log messages */
static int RemoteHostname; /* Log remote hostname from the message */
static int KernLog = 1; /* Track kernel logs by default */
@@ -458,7 +458,7 @@ int usage(int code)
" If specified twice, no socket at all will be opened, which also\n"
" disables support for logging to remote machines.\n"
" -t Keep kernel timestamp, even after initial ring buffer emptying\n"
- " -T Use local time and date for messages received from remote hosts\n"
+ " -T Use local time and date for log messages (both local and remote)\n"
" -? Show this help text\n"
" -v Show program version and exit\n"
"\n"
@@ -585,7 +585,7 @@ int main(int argc, char *argv[])
break;
case 'T':
- RemoteAddDate = 1;
+ AlwaysAddDate = 1;
break;
case 't': /* keep/trust kernel timestamp always */
@@ -1129,7 +1129,7 @@ parsemsg_rfc5424(const char *from, int pri, char *msg)
}
#undef PARSE_NUMBER
PARSE_CHAR("TIMESTAMP", ' ');
- if (!RemoteAddDate)
+ if (!AlwaysAddDate)
timestamp = &timestamp_remote;
}
@@ -1311,7 +1311,7 @@ parsemsg_rfc3164(const char *from, int pri, char *msg)
msg += RFC3164_DATELEN + 1;
- if (!RemoteAddDate) {
+ if (!AlwaysAddDate) {
struct timeval tv;
time_t t_remote;
struct tm tm_now;
--
2.43.0
@@ -0,0 +1,44 @@
From b5b4a4ecb893dd643fb25763fb9c6f6ca972725e Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Sun, 2 Mar 2025 13:56:46 +0100
Subject: [PATCH 07/16] Update internal timer consistently
Organization: Wires
Timer is already updated by parsemsg() before calling logmsg(). For
consistency, add explicit update also to printsys() (kernel) and
flog() (internally originated) messages.
Issue #70
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/src/syslogd.c b/src/syslogd.c
index 5a40732..1737f7c 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -1467,6 +1467,9 @@ void printsys(char *msg)
char *lp, *p, *q;
int c;
+ /* Update current time before logging */
+ timer_update();
+
lp = line;
for (p = msg; *p != '\0';) {
memset(&buffer, 0, sizeof(buffer));
@@ -2669,6 +2672,9 @@ void flog(int pri, char *fmt, ...)
char proc_id[10];
va_list ap;
+ /* Update current time before logging */
+ timer_update();
+
va_start(ap, fmt);
(void)vsnprintf(buf, sizeof(buf), fmt, ap);
va_end(ap);
--
2.43.0
@@ -0,0 +1,61 @@
From d3362a104b414af2b352a15a6d1e92f823bdb9b6 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Sun, 2 Mar 2025 14:06:37 +0100
Subject: [PATCH 08/16] Update ChangeLog and bump version for upcoming v2.7.1
release
Organization: Wires
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
ChangeLog.md | 14 ++++++++++++++
configure.ac | 2 +-
2 files changed, 15 insertions(+), 1 deletion(-)
diff --git a/ChangeLog.md b/ChangeLog.md
index b96857f..aa3e793 100644
--- a/ChangeLog.md
+++ b/ChangeLog.md
@@ -4,6 +4,19 @@ Change Log
All relevant changes to the project are documented in this file.
+[v2.7.1][UNRELEASED] - 2025-03-xx
+-----------------------
+
+### Changes
+- Update `syslogd -T` documentation, it applies to messages originating
+ both locally and from both remote syslog servers, issue #93
+
+### Fixes
+- Fix #99: hostname filtering support, introduced in v2.7.0, broken
+- Fix #100: parsing of userspace messages in `/dev/kmsg` inserted an
+ extra space before the message payload
+
+
[v2.7.0][] - 2025-01-06
-----------------------
@@ -667,6 +680,7 @@ and a replacement for `syslog.h` to enable new features in RFC5424.
[UNRELEASED]: https://github.com/troglobit/sysklogd/compare/v2.7.0...HEAD
+[v2.7.1]: https://github.com/troglobit/sysklogd/compare/v2.7.0...v2.7.1
[v2.7.0]: https://github.com/troglobit/sysklogd/compare/v2.6.2...v2.7.0
[v2.6.2]: https://github.com/troglobit/sysklogd/compare/v2.6.1...v2.6.2
[v2.6.1]: https://github.com/troglobit/sysklogd/compare/v2.6.0...v2.6.1
diff --git a/configure.ac b/configure.ac
index f387800..64de416 100644
--- a/configure.ac
+++ b/configure.ac
@@ -25,7 +25,7 @@
# OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
# SUCH DAMAGE.
-AC_INIT([sysklogd], [2.7.0],
+AC_INIT([sysklogd], [2.7.1-rc1],
[https://github.com/troglobit/sysklogd/issues],,
[https://github.com/troglobit/sysklogd])
AC_CONFIG_AUX_DIR(aux)
--
2.43.0
@@ -0,0 +1,47 @@
From 5552a3ea0d025573a5e212d62ee3e04bd376c7c4 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 3 Mar 2025 03:17:39 +0100
Subject: [PATCH 09/16] Bump version and update ChangeLog for v2.7.1 release
Organization: Wires
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
ChangeLog.md | 4 ++--
configure.ac | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/ChangeLog.md b/ChangeLog.md
index aa3e793..12829c0 100644
--- a/ChangeLog.md
+++ b/ChangeLog.md
@@ -4,12 +4,12 @@ Change Log
All relevant changes to the project are documented in this file.
-[v2.7.1][UNRELEASED] - 2025-03-xx
+[v2.7.1][] - 2025-03-03
-----------------------
### Changes
- Update `syslogd -T` documentation, it applies to messages originating
- both locally and from both remote syslog servers, issue #93
+ both locally and from remote syslog servers, issue #93
### Fixes
- Fix #99: hostname filtering support, introduced in v2.7.0, broken
diff --git a/configure.ac b/configure.ac
index 64de416..a2cf9be 100644
--- a/configure.ac
+++ b/configure.ac
@@ -25,7 +25,7 @@
# OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
# SUCH DAMAGE.
-AC_INIT([sysklogd], [2.7.1-rc1],
+AC_INIT([sysklogd], [2.7.1],
[https://github.com/troglobit/sysklogd/issues],,
[https://github.com/troglobit/sysklogd])
AC_CONFIG_AUX_DIR(aux)
--
2.43.0
@@ -0,0 +1,162 @@
From 64cd26232e598f902cf93b540152df5f7d8991e8 Mon Sep 17 00:00:00 2001
From: Luz Paz <luzpaz@pm.me>
Date: Mon, 3 Mar 2025 07:16:35 -0500
Subject: [PATCH 10/16] Fix various typos Fixes user-facing and non-user-facing
typos Found via `codespell -q 3 -L bootup,clen,nd,servent,siz,tast,unx`
Organization: Wires
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
ChangeLog.md | 2 +-
README.md | 2 +-
man/syslog.conf.5 | 2 +-
src/logger.c | 2 +-
src/syslog.h | 2 +-
src/syslogd.c | 4 ++--
src/syslogd.h | 2 +-
syslog.conf | 4 ++--
test/listen.sh | 4 ++--
9 files changed, 12 insertions(+), 12 deletions(-)
diff --git a/ChangeLog.md b/ChangeLog.md
index 12829c0..da44e01 100644
--- a/ChangeLog.md
+++ b/ChangeLog.md
@@ -508,7 +508,7 @@ and a replacement for `syslog.h` to enable new features in RFC5424.
- New `syslogp()` API from NetBSD, for applications wanting to use
RFC5424 features like MsgID or structured data
- Many *incompatible changes* to command line options in `syslogd` and
- `klogd` for compatiblity with FreeBSD and NetBSD syslogd. Examples:
+ `klogd` for compatibility with FreeBSD and NetBSD syslogd. Examples:
- In syslogd: `-b` and `-c` have been replaced with `-r` for global
log rotation, `-a` has been replaced with the new `-p` support. The
`-r` flag and `-s HOST` has also been dropped in favor of the BSD
diff --git a/README.md b/README.md
index eff6b03..12ce92c 100644
--- a/README.md
+++ b/README.md
@@ -63,7 +63,7 @@ Main differences from the original sysklogd package are:
- The separate `klogd` daemon is no longer part of the sysklogd project,
syslogd now natively supports logging kernel messages as well
-- *Major* command line changes to `syslogd`, for compatibilty with *BSD
+- *Major* command line changes to `syslogd`, for compatibility with *BSD
- Supports `include /etc/syslog.d/*.conf` directive, see example .conf
- Built-in log-rotation support, with compression by default, useful for
embedded systems. No need for cron and/or a separate log rotate daemon
diff --git a/man/syslog.conf.5 b/man/syslog.conf.5
index f7d9ea1..64a7260 100644
--- a/man/syslog.conf.5
+++ b/man/syslog.conf.5
@@ -704,7 +704,7 @@ This example shows one combination of program and hostname filters.
!-ppp
*.* /var/log/syslog
-# Local pppd messages of severity info, or higer, go to its own log file
+# Local pppd messages of severity info, or higher, go to its own log file
!+ppp
*.info /var/log/ppp.log
diff --git a/src/logger.c b/src/logger.c
index ffdb9e1..8fcb42a 100644
--- a/src/logger.c
+++ b/src/logger.c
@@ -286,7 +286,7 @@ static int usage(int code)
" -h HOST Send (UDP) message to this remote syslog server (IP or DNS name)\n"
" -H NAME Use NAME instead of system hostname in message header\n"
" -i Log process ID of the logger process with each line (LOG_PID)\n"
- " -I PID Log process ID using PID, recommed using PID $$ for shell scripts\n"
+ " -I PID Log process ID using PID, recommend using PID $$ for shell scripts\n"
#ifdef __linux__
" -k Log to kernel /dev/kmsg if /dev/log doesn't exist yet\n"
#endif
diff --git a/src/syslog.h b/src/syslog.h
index 9c33967..4f35ad0 100644
--- a/src/syslog.h
+++ b/src/syslog.h
@@ -191,7 +191,7 @@ CODE facilitynames[] = {
#define LOG_NDELAY 0x008 /* don't delay open */
#define LOG_NOWAIT 0x010 /* don't wait for console forks: DEPRECATED */
#define LOG_PERROR 0x020 /* log to stderr as well */
-#define LOG_PTRIM 0x040 /* trim anything syslog addded when writing to stderr */
+#define LOG_PTRIM 0x040 /* trim anything syslog added when writing to stderr */
#define LOG_NLOG 0x080 /* don't write to the system log */
#define LOG_STDOUT 0x100 /* like nlog, for debugging syslogp() API */
#define LOG_RFC3164 0x200 /* Log to remote/ipc socket in old BSD format */
diff --git a/src/syslogd.c b/src/syslogd.c
index 1737f7c..9128e7f 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -177,7 +177,7 @@ static TAILQ_HEAD(notifiers, notifier) nothead = TAILQ_HEAD_INITIALIZER(nothead)
static TAILQ_HEAD(peers, peer) pqueue = TAILQ_HEAD_INITIALIZER(pqueue);
/*
- * List fo peers allowed to log to us.
+ * List of peers allowed to log to us.
*/
static SIMPLEQ_HEAD(allowed, allowedpeer) aphead = SIMPLEQ_HEAD_INITIALIZER(aphead);
@@ -4456,7 +4456,7 @@ static void notifier_free_all(void)
}
/*
- * The following function is resposible for handling a SIGHUP signal. Since
+ * The following function is responsible for handling a SIGHUP signal. Since
* we are now doing mallocs/free as part of init we had better not being
* doing this during a signal handler. Instead this function simply sets
* a flag variable which will tell the main loop to go through a restart.
diff --git a/src/syslogd.h b/src/syslogd.h
index ff97a0a..511e3e8 100644
--- a/src/syslogd.h
+++ b/src/syslogd.h
@@ -224,7 +224,7 @@
#define F_PIPE 9 /* named pipe */
/*
- * Stuct to hold property-based filters
+ * Struct to hold property-based filters
*/
struct prop_filter {
uint8_t prop_type;
diff --git a/syslog.conf b/syslog.conf
index 581fc32..3426c25 100644
--- a/syslog.conf
+++ b/syslog.conf
@@ -44,7 +44,7 @@ mail.err /var/log/mail.err
#
# Store all critical events, except kernel logs, in critical RFC5424 format.
-# Overide global log rotation settings, rotate every 10MiB, keep 5 old logs,
+# Override global log rotation settings, rotate every 10MiB, keep 5 old logs,
#
#*.=crit;kern.none /var/log/critical ;rotate=10M:5,RFC5424
@@ -68,7 +68,7 @@ mail.err /var/log/mail.err
# Secure mode, same as -s, none(0), on(1), full(2). When enabled
# only logging to remote syslog server possible, with full secure
# mode, not even that is possible. We default to prevent syslogd
-# from opening UDP/514 and receving messages from other systems.
+# from opening UDP/514 and receiving messages from other systems.
#
secure_mode 1
diff --git a/test/listen.sh b/test/listen.sh
index 1b706e8..7665261 100755
--- a/test/listen.sh
+++ b/test/listen.sh
@@ -99,10 +99,10 @@ run_step "Verify listen off - no remote no ports" verify_secure_daem
run_step "Verify listen off - only send to remote, no ports" verify_safe_daemon
run_step "Verify listen on, default" verify_default_daemon
-run_step "Verfiy listen on 127.0.0.1:510" verify_local_daemon
+run_step "Verify listen on 127.0.0.1:510" verify_local_daemon
run_step "Verify port 514 is closed" check_not_open 514
-run_step "Verfiy listen on 10.0.0.1:512" verify_bind
+run_step "Verify listen on 10.0.0.1:512" verify_bind
run_step "Verify port 510 is closed" check_not_open 510
run_step "Verify delayed bind to new address 10.0.0.2:513" verify_delayed_bind
--
2.43.0
@@ -0,0 +1,70 @@
From 2fbac9e54b60e813a5ecfb4ff4177b6351bfbffd Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Tue, 18 Mar 2025 06:32:27 +0100
Subject: [PATCH 11/16] test: update tag.sh, include dots in name and verify
tag in logfile
Organization: Wires
Issue #102
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
test/tag.sh | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/test/tag.sh b/test/tag.sh
index 3e1c598..bfc409a 100755
--- a/test/tag.sh
+++ b/test/tag.sh
@@ -1,16 +1,20 @@
#!/bin/sh
# Verify log filtering based on ident/tag.
+#DEBUG=true
. "${srcdir:-.}/lib.sh"
TG1=pimd
TG2=mrouted
+TG3=in.tftpd
MSG="Multicast, a perfect weapon for an imperfect time."
UNX="In UNIX we trust"
+DOT="We bring 512 byte block gifts"
LOGDIR="$DIR/log"
SYSLOG="${LOGDIR}/syslog"
TG1LOG="${LOGDIR}/$TG1.log"
TG2LOG="${LOGDIR}/$TG2.log"
+TG3LOG="${LOGDIR}/$TG3.log"
setup_syslogd()
{
@@ -22,6 +26,8 @@ setup_syslogd()
*.* $TG1LOG
#!$TG2
*.* $TG2LOG
+ #!$TG3
+ *.* $TG3LOG
EOF
setup -m0
}
@@ -32,8 +38,8 @@ verify_tag()
log="$1"; shift
msg="$*"
- logger -t "$tag" "$msg"
- grep "$msg" "$log"
+ logger -ip user.debug -t "$tag" "$msg"
+ grep "$msg" "$log" |grep "$tag"
}
verify_log()
@@ -52,6 +58,7 @@ verify_not()
run_step "Set up property based filtering syslogd" setup_syslogd
run_step "Verify basic tag based filtering (1)" verify_tag "$TG1" "$TG1LOG" "$MSG"
run_step "Verify basic tag based filtering (2)" verify_tag "$TG2" "$TG2LOG" "$MSG"
+run_step "Verify basic tag based filtering (3)" verify_tag "$TG3" "$TG3LOG" "$DOT"
run_step "Verify not in syslog" verify_not "$SYSLOG" "$MSG"
run_step "Verify unfiltered tag logging" verify_tag "foo" "$SYSLOG" "$UNX"
--
2.43.0
@@ -0,0 +1,72 @@
From ff09758a63f100d5e611d28b1f219ea10f2ca996 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Wed, 19 Mar 2025 06:08:45 +0100
Subject: [PATCH 12/16] test: further extend tag test to check RFC3164 code
path as well
Organization: Wires
Reproduces issue #102
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
test/tag.sh | 33 +++++++++++++++++++++++++++++----
1 file changed, 29 insertions(+), 4 deletions(-)
diff --git a/test/tag.sh b/test/tag.sh
index bfc409a..53aa745 100755
--- a/test/tag.sh
+++ b/test/tag.sh
@@ -1,6 +1,11 @@
#!/bin/sh
-# Verify log filtering based on ident/tag.
-#DEBUG=true
+# Verify log filtering based on ident/tag for both RFC3154 (BSD)
+# and RFC5424 formatted log messages sent to syslogd. A logged
+# message can also contain a [PID], so the combinations of various
+# tags + pid are also covered.
+#
+# Regression test for issue #102.
+#
. "${srcdir:-.}/lib.sh"
TG1=pimd
@@ -32,14 +37,34 @@ setup_syslogd()
setup -m0
}
+# Verify both RFC3164 (BSD) log format and RFC5424, because
+# they have different format parsers in syslogd. Generates
+# three additional variants of the given log message: rev,
+# rot13, and alphabetically sorted.
verify_tag()
{
tag="$1"; shift
log="$1"; shift
msg="$*"
+ rev=$(echo "$msg" | rev)
+ rot=$(echo "$msg" | tr 'a-zA-Z' 'n-za-mN-ZA-M')
+ bin=$(echo "$msg" | sed 's/./&\n/g' | sort | tr -d '\n')
- logger -ip user.debug -t "$tag" "$msg"
- grep "$msg" "$log" |grep "$tag"
+ # BSD log format (with -b)
+ logger -b -ip user.debug -t "$tag" "$msg"
+ verify_log "$log" "$msg" | grep "$tag" || return 1
+
+ # RFC5424 (default)
+ logger -ip user.debug -t "$tag" "$rev"
+ verify_log "$log" "$rev" | grep "$tag" || return 1
+
+ # BSD without -p flag
+ logger -b -i -t "$tag" "$rot"
+ verify_log "$log" "$rot" | grep "$tag" || return 1
+
+ # RFC5424 without -p flag
+ logger -i -t "$tag" "$bin"
+ verify_log "$log" "$bin" | grep "$tag" || return 1
}
verify_log()
--
2.43.0
@@ -0,0 +1,40 @@
From c0622119d6baf45dcaef01897f6c686f2eb92ee4 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Wed, 19 Mar 2025 06:35:39 +0100
Subject: [PATCH 13/16] Fix #102: allow '.' in tag names, regression in v2.7.1
Organization: Wires
RFC3164 specifies; "The TAG is a string of ABNF alphanumeric characters
that MUST NOT exceed 32 characters. Any non-alphanumeric character
will terminate the TAG field and will be assumed to be the starting
character of the CONTENT field."
Strictly speaking, ABNF (Augmented Backus-Naur Form) only includes the
alphanumeric characters, meaning just be letters and digits.
However, in real-life scenarios, and per previous behavior, we should
definitely allow '.' as well. The existing argument to `strspn()` is
from FreeBSD, which for some reason do *not* allow '.', but they do
also allow '_-/' ... '/' seems like the real outlier here.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/syslogd.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/syslogd.c b/src/syslogd.c
index 9128e7f..07abdf9 100644
--- a/src/syslogd.c
+++ b/src/syslogd.c
@@ -1223,7 +1223,7 @@ parsemsg_rfc3164_app_name_procid(char **msg, char **app_name, char **procid)
"abcdefghijklmnopqrstuvwxyz"
"ABCDEFGHIJKLMNOPQRSTUVWXYZ"
"0123456789"
- "_-/");
+ "._-/");
if (app_name_length == 0)
goto bad;
m += app_name_length;
--
2.43.0
@@ -0,0 +1,60 @@
From 93f9cd74856be4b9a77c72b8e4c55a49c32ce26e Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 24 Mar 2025 06:01:46 +0100
Subject: [PATCH 14/16] Prepare for upcoming v2.7.2
Organization: Wires
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
ChangeLog.md | 14 +++++++++++++-
configure.ac | 2 +-
2 files changed, 14 insertions(+), 2 deletions(-)
diff --git a/ChangeLog.md b/ChangeLog.md
index da44e01..140cfc4 100644
--- a/ChangeLog.md
+++ b/ChangeLog.md
@@ -4,6 +4,17 @@ Change Log
All relevant changes to the project are documented in this file.
+[v2.7.2][UNRELEASED]
+-----------------------
+
+### Changes
+- Increased code coverage testing of tag parser
+
+### Fixes
+- Fix #102: allow `.` in tag names, regression in v2.7.1
+- Fix various typos in documentation, by Luz Paz
+
+
[v2.7.1][] - 2025-03-03
-----------------------
@@ -679,7 +690,8 @@ and a replacement for `syslog.h` to enable new features in RFC5424.
- Several bugfixes and improvements, please refer to the .c files
-[UNRELEASED]: https://github.com/troglobit/sysklogd/compare/v2.7.0...HEAD
+[UNRELEASED]: https://github.com/troglobit/sysklogd/compare/v2.7.1...HEAD
+[v2.7.2]: https://github.com/troglobit/sysklogd/compare/v2.7.1...v2.7.2
[v2.7.1]: https://github.com/troglobit/sysklogd/compare/v2.7.0...v2.7.1
[v2.7.0]: https://github.com/troglobit/sysklogd/compare/v2.6.2...v2.7.0
[v2.6.2]: https://github.com/troglobit/sysklogd/compare/v2.6.1...v2.6.2
diff --git a/configure.ac b/configure.ac
index a2cf9be..13dadfa 100644
--- a/configure.ac
+++ b/configure.ac
@@ -25,7 +25,7 @@
# OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
# SUCH DAMAGE.
-AC_INIT([sysklogd], [2.7.1],
+AC_INIT([sysklogd], [2.7.2-beta1],
[https://github.com/troglobit/sysklogd/issues],,
[https://github.com/troglobit/sysklogd])
AC_CONFIG_AUX_DIR(aux)
--
2.43.0
@@ -0,0 +1,57 @@
From debc8c337b3e7d8c76701991a4566714b78c1846 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 31 Mar 2025 13:22:47 +0200
Subject: [PATCH 15/16] logger: show invalid option arguments if -p and -o
parsing fail
Organization: Wires
Instead of just showing the usage instructions, include information
about the option and its argument failing. Useful when debugging
faulty calls to the logger program deep in an operating system.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
src/logger.c | 14 +++++++++++---
1 file changed, 11 insertions(+), 3 deletions(-)
diff --git a/src/logger.c b/src/logger.c
index 8fcb42a..5bf263f 100644
--- a/src/logger.c
+++ b/src/logger.c
@@ -393,13 +393,17 @@ int main(int argc, char *argv[])
break;
case 'o':
- if (parse_opts(optarg, &iface, &ttl))
+ if (parse_opts(optarg, &iface, &ttl)) {
+ printf("Invalid option argument '-%c %s'\n", c, optarg);
return usage(1);
+ }
break;
case 'p':
- if (parse_prio(optarg, &facility, &severity))
+ if (parse_prio(optarg, &facility, &severity)) {
+ printf("Invalid option argument '-%c %s'\n", c, optarg);
return usage(1);
+ }
break;
case 'P':
@@ -428,8 +432,12 @@ int main(int argc, char *argv[])
printf("%s\n", version_info);
return 0;
- default:
+ case '?':
return usage(0);
+
+ default:
+ printf("Unsupported option '-%c'\n", c);
+ return usage(1);
}
}
--
2.43.0
@@ -0,0 +1,47 @@
From 5fb314cb9060afa3bd4eed2f0be3200f02f729e9 Mon Sep 17 00:00:00 2001
From: Joachim Wiberg <troglobit@gmail.com>
Date: Mon, 31 Mar 2025 13:26:13 +0200
Subject: [PATCH 16/16] Update ChangeLog and bump version for v2.7.2 release
Organization: Wires
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
---
ChangeLog.md | 4 +++-
configure.ac | 2 +-
2 files changed, 4 insertions(+), 2 deletions(-)
diff --git a/ChangeLog.md b/ChangeLog.md
index 140cfc4..8d8bb43 100644
--- a/ChangeLog.md
+++ b/ChangeLog.md
@@ -4,11 +4,13 @@ Change Log
All relevant changes to the project are documented in this file.
-[v2.7.2][UNRELEASED]
+[v2.7.2][] - 2025-03-31
-----------------------
### Changes
- Increased code coverage testing of tag parser
+- Improved error handling in `logger` when invalid arguments to
+ `-p` and `-o` are encountered
### Fixes
- Fix #102: allow `.` in tag names, regression in v2.7.1
diff --git a/configure.ac b/configure.ac
index 13dadfa..fe79595 100644
--- a/configure.ac
+++ b/configure.ac
@@ -25,7 +25,7 @@
# OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
# SUCH DAMAGE.
-AC_INIT([sysklogd], [2.7.2-beta1],
+AC_INIT([sysklogd], [2.7.2],
[https://github.com/troglobit/sysklogd/issues],,
[https://github.com/troglobit/sysklogd])
AC_CONFIG_AUX_DIR(aux)
--
2.43.0
+10 -3
View File
@@ -10,7 +10,7 @@
banner_append()
{
printf "\n$@\n" | tee -a \
printf "\n%s\n" "$*" | tee -a \
/etc/banner \
/etc/issue \
/etc/issue.net \
@@ -28,12 +28,14 @@ perms()
note()
{
logger -I $$ -p user.notice -t load "$*"
msg="$*"
logger -I $$ -p user.notice -t load -- "$msg"
}
err()
{
logger -I $$ -p user.error -t load "$*"
msg="$*"
logger -I $$ -p user.error -t load -- "$msg"
}
@@ -46,6 +48,8 @@ while getopts "t:" opt; do
t)
sysrepocfg="$sysrepocfg -t $OPTARG"
;;
*)
;;
esac
done
shift $((OPTIND - 1))
@@ -123,6 +127,9 @@ if ! $sysrepocfg -v2 -I"$fn" -f json; then
banner_append "CRITICAL ERROR: Logins are disabled, no credentials available"
initctl -nbq runlevel 9
;;
*)
err "Unknown config $config, aborting!"
;;
esac
exit 1
+91 -73
View File
@@ -9,10 +9,12 @@ usage()
echo
echo "options:"
echo " -b FILE Create backup FILE, appends detected version before .ext"
echo " -e Print all messages on stderr instead of syslog"
echo " -c Check only, returns false when migration is not needed"
echo " -h This help text"
echo " -i Edit file in-place instead of sending to stdout, like sed"
echo " -q Quiet, skip normal log messages, only errors are logged"
echo " -s PATH Specify custom script path"
echo
echo "By default, this script reads a .cfg file on stdin, or as the first"
echo "non-option argument, then migrates it to a new syntax on stdout."
@@ -27,14 +29,23 @@ cleanup()
note()
{
if [ -n "$quiet" ]; then
return
return
fi
if [ -n "$nolog" ]; then
echo "$1" >&2
else
logger -I $$ -k -p user.notice -t "$ident" "$1"
fi
logger -I $$ -k -p user.notice -t "$ident" "$1"
}
err()
{
logger -I $$ -k -p user.err -t "$ident" "$1"
if [ -n "$nolog" ]; then
echo "Error: $1" >&2
else
logger -I $$ -k -p user.err -t "$ident" "$1"
fi
}
# Convert human-readable version to integer level
@@ -46,11 +57,11 @@ atoi()
file_version()
{
jq -r '
if .["infix-meta:meta"] | has("infix-meta:version") then
.["infix-meta:meta"]["infix-meta:version"]
else
"0.0"
end
if .["infix-meta:meta"] | has("version") then
.["infix-meta:meta"]["version"]
else
"0.0"
end
' "$1"
}
@@ -58,16 +69,16 @@ file_version()
confd_version()
{
find "$scripts" -mindepth 1 -maxdepth 1 -type d \
| sort -V | tail -n1 | xargs -n1 basename
}
| sort -V | tail -n1 | xargs -n1 basename
}
# Update meta data with the latest version
meta_version()
{
if jq --arg version "$sys_version" '.["infix-meta:meta"] = {"infix-meta:version": $version}' "$2" \
> "${2}.tmp" && mv "${2}.tmp" "$2"; then
note "$1: configuration updated to version $sys_version."
return 0
if jq --arg version "$sys_version" '.["infix-meta:meta"] = {"version": $version}' "$2" \
> "${2}.tmp" && mv "${2}.tmp" "$2"; then
note "$1: configuration updated to version $sys_version."
return 0
fi
err "$1: failed updating configuration to version $sys_version!"
@@ -80,23 +91,23 @@ migrate()
note "$1: migrating from version $cfg_version"
for version_dir in $(find "$scripts" -mindepth 1 -maxdepth 1 -type d | sort -V); do
dir=$(basename "$version_dir")
version=$(atoi "$dir")
dir=$(basename "$version_dir")
version=$(atoi "$dir")
# Step by step upgrade file to latest version
if [ "$cfg_level" -lt "$version" ]; then
note "Applying migrations for version $dir ..."
# Step by step upgrade file to latest version
if [ "$cfg_level" -lt "$version" ]; then
note "Applying migrations for version $dir ..."
# Apply all scripts in the version directory in order
for script in $(find "$version_dir" -type f -name '*.sh' | sort -V); do
note "$1: calling $script ..."
sh "$script" "$2"
done
# Apply all scripts in the version directory in order
for script in $(find "$version_dir" -type f -name '*.sh' | sort -V); do
note "$1: calling $script ..."
sh "$script" "$2"
done
# File now at $version ...
cfg_level="$version"
fi
done
# File now at $version ...
cfg_level="$version"
fi
done
}
# Try migrating a copy, then diff the files, for factory-config check
@@ -121,36 +132,43 @@ chmod 600 "$tmp"
trap cleanup INT HUP TERM EXIT
OPTS=$(getopt -o b:chiq -- "$@")
OPTS=$(getopt -o b:echiqs: -- "$@")
eval set -- "$OPTS"
while [ -n "$1" ]; do
case $1 in
-b)
bak=$2
shift
;;
-c)
check=1
;;
-h)
usage
exit 0
;;
-i)
inplace=1
;;
-q)
quiet=1
;;
--)
shift
break
;;
*)
# Likely file argument
break
;;
-b)
bak=$2
shift
;;
-e)
nolog=1
;;
-c)
check=1
;;
-h)
usage
exit 0
;;
-i)
inplace=1
;;
-q)
quiet=1
;;
-s)
scripts=$2
shift
;;
--)
shift
break
;;
*)
# Likely file argument
break
;;
esac
shift
done
@@ -190,22 +208,22 @@ if [ "$cfg_level" -eq "$sys_level" ]; then
exit 0
else
if [ -n "$check" ]; then
# We may be called to check a file without meta:version (factory)
if [ "$cfg_version" = "0.0" ]; then
if diff "$tmp"; then
# File is OK, despite lacking meta:version
exit 0
fi
msg="$orig: has syntax error, requires migrating."
else
msg="$orig: version $cfg_version, requires migrating."
fi
if [ -t 0 ]; then
echo "$msg"
else
note "$msg"
fi
exit 1
# We may be called to check a file without meta:version (factory)
if [ "$cfg_version" = "0.0" ]; then
if diff "$tmp"; then
# File is OK, despite lacking meta:version
exit 0
fi
msg="$orig: has syntax error, requires migrating."
else
msg="$orig: version $cfg_version, requires migrating."
fi
if [ -t 0 ]; then
echo "$msg"
else
note "$msg"
fi
exit 1
fi
fi
@@ -214,10 +232,10 @@ if [ -n "$bak" ]; then
ext="${bak##*.}"
bak="${fil}-${cfg_version}.${ext}"
if cp -p "$tmp" "$bak" 2>/dev/null; then
note "$orig: backup created: $bak"
note "$orig: backup created: $bak"
else
err "$orig: failed creating backup: $bak"
exit 1
err "$orig: failed creating backup: $bak"
exit 1
fi
fi
+5 -2
View File
@@ -19,8 +19,11 @@ AC_CONFIG_FILES([
share/migrate/1.3/Makefile
share/migrate/1.4/Makefile
share/migrate/1.5/Makefile
src/Makefile
yang/Makefile
yang/confd/Makefile
yang/test-mode/Makefile
yang/rousette/Makefile
src/Makefile
])
AC_PROG_CC
@@ -83,7 +86,7 @@ DATAROOTDIR=`eval echo $datarootdir`
DATAROOTDIR=`eval echo $DATAROOTDIR`
AC_SUBST(DATAROOTDIR)
YANGDIR=`eval echo $datarootdir/yang/modules/confd`
YANGDIR=`eval echo $datarootdir/yang/modules`
AC_SUBST(YANGDIR)
LIBDIR=`eval echo $libdir`
+14 -11
View File
@@ -3,14 +3,17 @@
file=$1
temp=${file}.tmp
jq '.["infix-services:ssh"] = {
"enabled": true,
"hostkey": ["genkey"],
"listen": [
{"name": "ipv4", "address": "0.0.0.0", "port": 22},
{"name": "ipv6", "address": "::", "port": 22}
]
}' "$file" > "$temp"
mv "$temp" "$file"
jq '
if has("infix-services:ssh") then
.
else
.["infix-services:ssh"] = {
"enabled": true,
"hostkey": ["genkey"],
"listen": [
{"name": "ipv4", "address": "0.0.0.0", "port": 22},
{"name": "ipv6", "address": "::", "port": 22}
]
}
end' $file > temp.json
mv temp.json $file
+1 -2
View File
@@ -1,2 +1 @@
yangdir = $(YANGDIR)
yang_DATA = $(wildcard *@*.yang) ieee802-types.yang ieee802-dot1ab-types.yang
SUBDIRS = confd test-mode rousette
+3 -26
View File
@@ -1,25 +1,20 @@
# -*- sh -*-
# REMEMBER TO UPDATE infix-interfaces ALSO IN containers.inc
#FORCE_UPDATE="infix-interfaces"
MODULES=(
"ietf-system@2014-08-06.yang -e authentication -e local-users -e ntp -e ntp-udp-port -e timezone-name"
"iana-timezones@2013-11-19.yang"
"notifications@2008-07-14.yang"
"ietf-tcp-common@2023-12-28.yang -e keepalives-supported"
"ietf-interfaces@2018-02-20.yang -e if-mib"
"ietf-ip@2018-02-22.yang -e ipv6-privacy-autoconf"
"ietf-network-instance@2019-01-21.yang"
"ietf-netconf-monitoring@2010-10-04.yang"
"ietf-netconf-nmda@2019-01-07.yang -e origin -e with-defaults"
"ietf-subscribed-notifications@2019-09-09.yang -e encode-xml -e replay -e subtree -e xpath"
"ietf-yang-push@2019-09-09.yang -e on-change"
"ietf-routing@2018-03-13.yang"
"ietf-ipv6-unicast-routing@2018-03-13.yang"
"ietf-ipv4-unicast-routing@2018-03-13.yang"
"ietf-ospf@2022-10-19.yang -e bfd -e explicit-router-id"
"iana-if-type@2023-01-26.yang"
# NOTE: ietf-tls-client must be version matched with ietf-tls-server, used by netopeer2!
"ietf-tls-client@2023-12-28.yang" # used by ietf-syslog (remote)
# NOTE: ietf-tls-client must be version matched with ietf-tls-server, used by netopeer2!
"ietf-tls-client@2023-12-28.yang"
"ietf-syslog@2024-03-21.yang -e file-action -e file-limit-size -e remote-action"
"infix-syslog@2024-07-19.yang"
"iana-hardware@2018-03-13.yang"
@@ -43,22 +38,4 @@ MODULES=(
"infix-interfaces@2025-01-09.yang -e vlan-filtering"
"infix-crypto-types@2025-02-04.yang"
"infix-keystore@2025-02-04.yang"
# from rousette
"ietf-restconf@2017-01-26.yang"
"ietf-yang-patch@2017-02-22.yang"
"ietf-restconf-monitoring@2017-01-26.yang"
# from sysrepo
"sysrepo-plugind@2022-08-26.yang"
# from netopeer
"nc-notifications@2008-07-14.yang"
"ietf-crypto-types@2023-12-28.yang -e encrypted-private-keys"
"ietf-netconf-server@2023-12-28.yang -e ssh-listen -e tls-listen -e ssh-call-home -e tls-call-home"
"ietf-netconf-acm@2018-02-14.yang"
"ietf-netconf@2013-09-29.yang -e writable-running -e candidate -e rollback-on-error -e validate -e startup -e url -e xpath -e confirmed-commit"
"ietf-truststore@2023-12-28.yang -e central-truststore-supported -e certificates"
"ietf-keystore@2023-12-28.yang -e central-keystore-supported -e asymmetric-keys -e symmetric-keys"
"ietf-tls-server@2023-12-28.yang -e server-ident-raw-public-key -e server-ident-x509-cert"
)
+2
View File
@@ -0,0 +1,2 @@
yangdir = $(YANGDIR)/confd
yang_DATA = $(wildcard *@*.yang) ieee802-types.yang ieee802-dot1ab-types.yang

Some files were not shown because too many files have changed in this diff Show More