Wrap wpa_cli operations in try-except blocks to ensure WiFi errors don't
cause sysrepocfg to fail. Interface queries now return data for working
interfaces even when WiFi has issues.
Fixes:
admin@rpi-79-41-1d:/> show interfaces
Error running sysrepocfg: Command '['sysrepocfg', '-f', 'json', '-X', '-d', 'operational', '-x', '/ietf-interfaces:interfaces']' returned non-zero exit status 1.
No interface data retrieved.
admin@rpi-79-41-1d:/>
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit consolidates mkimage.sh scripts into a unified SD card image
creation tool that works for all boards. It needs a bootloader an $ARCH
rootfs.squashfs image and a genimage.cfg.in template.
- Detects build directories from `O=` environment variable or `output/`
- Sources `.config` to discover Buildroot paths
- Uses Buildroot's `support/scripts/genimage.sh` when available
- Automatically generates `.bmap` files if `bmaptool` is available
- Fallback to direct `genimage` invocation if wrapper not found
See the online instructions for usage.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add new interface quirk to allow skipping disabling of flow control on
all RPi 3B/4B devices that have the smsc95xx driver.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The xPi's usually don't have a VPD so the chassis mac-address probed at
boot is usually null in /run/system.json. This commit adds a fallbkack
mechanism to populate this field so it can be used for unique hostnames
even on these boards.
Ths ietf-hardware.yang model does not have a notion of physical address,
so we augment one tht is generic enought to be used for other hardware
components than Ethernet, similar to what ietf-interfaces.yang use.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Enable bridging of LAN ports in br0, default IP: 192.168.0.1/24
- Enable firewall with two zones: 'wan' and 'lan', policy: lan-to-wan
- Enable DHCP server on br0
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit drops the board specific defconfig in favor of proper BSP
support for the FriendlyARM NanoPi R2S to Infix as part of the default
Aarch64 build.
The name FriendlyARM was elected over FriendlyELEC ("new" name) to be
consistent with both kernel and Buildroot naming standards.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit consolidates all BSP support files into the Buildroot standard
board/ directory. The concept of selectable boards in menuconfig remains
as-is but now lives in board/ instead.
Drop support for board-specific post-build.sh scripts, not needed atm. and
we should really use Buildroot _POST_INSTALL_HOOKS in the board .mk files
instead.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
With the additional support for RPi3, including Zero 2W, this commit renames
all relevant directories and Config.In options to match.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
For more advanced hardware with multiple sensor types per device
(e.g., SFP modules with temperature, voltage, current, and power
sensors), use the YANG parent/child relationship to group related
sensors together for better presentation.
Changes:
- Remove parent/parent-rel-pos deviations from infix-hardware.yang
- Create parent components (class: module) for multi-sensor devices
- Add parent references to child sensor components
- Add human-readable descriptions from hwmon labels
- Extend hwmon discovery to support voltage, current, and power
- Normalize sensor names: strip vendor prefixes (mt7915_phy0 -> phy0)
- Remove redundant TYPE column, clarify units (V -> VDC, add spaces)
- Simplify child sensor display by stripping parent prefix
- Fix "show system" to only show CPU temperature and fan speed
Example output from "show hardware":
NAME VALUE STATUS
===================================================
sfp1:
Rx Power 0.000 W ok
Tx Power 0.001 W ok
Vcc 3.35 VDC ok
Bias 0.006 A ok
Temperature 30.3 °C ok
sfp2:
Rx Power 0.000 W ok
Tx Power 0.001 W ok
Vcc 3.34 VDC ok
Bias 0.006 A ok
Temperature 32.0 °C ok
cpu 42.8 °C ok
phy0 47.0 °C ok
phy1 53.0 °C ok
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit adds resource usage: memory, loadavg, and filesystem usage
by augmenting ietf-system:/system-state.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Remove class deviation to allow iana-hardware:sensor
- Populate sensor operational data from /sys/class/thermal
- Extend 'show hardware'
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Usually, when upgrading a system, you want to reboot it so the upgrade
takes effect. This commit adds a 'reboot' option/flag, alongside the
'force' option, to facilitate this.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The DWC2 controller is a very common IP block in ARM and RiscV SoCs. With the
USB subsystem back to a built-in we can now enable host mode for the DWC2 (USB
2.0) ports on RPi. It also opens up for merging the NanoPi R2S into the
generic aarch64 build.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
On some boards, and in particular with a hybrid mbr/gpt partition table,
like on the RPi64, we must resize ext *after* reboot.
Also, do some cleanup and consolidation of error handling to prevent us
from entering an endless boot loop.
Follow-up to 391e9715
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit refactors USB port probing to:
- Eliminate duplicates: previously, 'authorized' and 'authorized_default'
were listed as separate USB port entries (confusing). Now each USB
port is represented once, with the path pointing to the USB device
directory, confd appends the appropriate attribute file as needed
- Add support for Raspberry Pi 4B and CM4 USB port(s) using a generic
discovery function that scans /sys/bus/usb/devices for USB root hubs.
This should work seamlessly across all platforms
- For backwards compatibility and better UX:
- Single USB port systems: Named "USB" (no number)
- Multi-port systems: Named "USB1", "USB2", etc.
- Device tree-based discovery is tried first (for boards like Alder with
explicit DT USB port definitions), with fallback to generic discovery
for boards without DT
Fixes: #315
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit adds support for the Raspberry Pi CM4 based mini DFRobot IoT
Router board, SKU:DFR0767. It comes with an additional RTL8111 PCIe NIC
hence the addidtional kernel module and firmware. The latter fixes:
r8169 0000:01:00.0: Direct firmware load for rtl_nic/rtl8168h-2.fw failed with error -2
r8169 0000:01:00.0: Unable to load firmware rtl_nic/rtl8168h-2.fw (-2)
Please note, the change in BCMGENET from module to built-in is to ensure
it is probed before any PCIe NIC, both this board and the CM4-based NVME
NAS base board enumerate the built-in MAC as eth0.
Also, unlike the RPi 3B/4B, it is not a given fact that a CM4 based board
comes with WiFi onboard, and since most compute module setups are DYI, we
take the easy way out and leave it as an exercise to the user to add WiFi
interface to the config.
https://wiki.dfrobot.com/Compute_Module_4_IoT_Router_Board_Mini_SKU_DFR0767
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The BCM2837 core is used not just in the RPi 3B but also in the Zero 2W,
both device trees have been added to the board config.
The BCM2711 support has been extended to include RPi 400 and CM4 I/O.
To support the BCM2837 family more firmware options habe been enabled,
since the RPi3 does not have bootcode.bin flashed in the SoC. The SD
card image now uses a hybrid GPT/MBR format so the RPi3 bootcode.bin
can read all files from the first VFAT partition.
The default device tree for Linux is now chosen by the U-Boot probe and
the only exception is the "laundry room" detector that looks for a RPi4
with a 7" touch screen, which then selects the DSI enabled RPi4 variant.
This is enough to properly load an RPi 3B and a CM4 based router board.
The BCM2837 does not have PCI/PCIe or a built-in MAC so it relies on the
USB to Ethernet LAN78xx which does not support disabling pause frames.
I have opted for checking for EOPNOTSUPP instead of adding yet another
quirk, because it is likely to be a common limitation of more drivers
and chipsets, and this code is best-effort anyway.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Use kernel cmdline option 'usbcore.authorized_default=2' to lock all
external/user-visible USB ports by default.
The kernel distinguishes internal vs external USB ports using ACPI
methods (_UPC and _PLD) on x86/x86_64 systems. On ACPI systems, ports
marked as non-visible but connectable are considered internal (e.g.,
hard-wired USB-to-Ethernet adapters) and are automatically authorized,
while user-visible external ports require manual authorization.
However, on device tree systems the kernel lacks a standard mechanism
for identifying internal ports. The 'authorized_default=2' setting falls
back to requiring authorization for all devices on these platforms,
We list user-accessible USB ports in the device tree ('usb-ports' and
'usb-port-names'), with unlisted ports being implicitly internal and
managed separately.
Fixes#1065
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This will make sure to apply NACM rules for all the data. It also
makes it possible for a luser access a subset of the data, even if
they to do not have read access to /cfg/startup-config.cfg.
This will fix#1106, in time, but only allows manual trigger for now,
needs more test and verification
utils/kernel-upgrade.sh at least automate all the manual manual processes
for upgrading the kernel.
Bridge ports should not have IP addresses configured. The IP address
should be configured on the bridge interface itself, not its member ports.
Add YANG must expression to enforce this rule at configuration time.
Fixes#1122
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A valid DHCP server setup for a subnet is one of pool and/or at least one
static host entry/lease. If pool is enabled the pool must have a start
and an end address.
To allow setting up a DHCP server with no pool and at least one static host
entry/lease, we make the pool a presence container, otherwise the pool will
always be set and trigger the below inference.
When an interactive CLI/Web user enables the address pool we infer a default
range .100-.250, but only for /24, C-class networks. This is what most users
know and expect.
The YANG model now validates that:
- If an address pool is created, both start-address and end-address must be set
- Each subnet must have either a pool or at least one static host entry
- The pool container is now a presence container, so "no pool" fully deletes it
Fixes#1121
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Addresses disk space issues in GitHub Actions for generic x86_64 builds
by removing unused tools (Android SDK, .NET, Docker images, etc.) before
the build starts. This frees up ~30GB of space.
Fixes#1210
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Multiple services can have PID 0 when stopped/done, making PID
unsuitable as a unique key. There could also be multiple services with
the same name (I would assume?).
Signed-off-by: Richard Alpe <richard@bit42.se>
This patch adds operational data support for system services. The
data is in a generic format but is intended to be able to represent
finit information (initctl) nicely.
The reason for augmenting this to ietf-system and not to
infix-services is that we consider this generic system information
which is totally disconnected from what ever services infix might
provide.
In this first state we only support pid, name, description and state.
Making the data look something like:
"infix-system:services": {
"service": [
{
"pid": 1185,
"name": "udevd",
"status": "running",
"description": "Device event daemon (udev)"
}]
Signed-off-by: Richard Alpe <richard@bit42.se>
Address two issues identified by Coverity Scan:
1. CID 550484 (TOCTOU): Remove access() check before realpath()
- realpath() already fails if file doesn't exist, making the
access() check redundant and introducing a TOCTOU race
- Simplifies code while improving security
2. CID 550483 (CHECKED_RETURN): Mark unchecked remove() calls
- Add (void) cast to two remove() calls to explicitly indicate
we don't care about the return value
- These are cleanup operations for temp files where failure
is acceptable, even expected
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Much of the content was made obsolete by recent changes, we now optimize
the experience for users, avoiding recreate at boot unless checksums for
configuration or base image have changed.
This was also a good time to explain the difference between mutable and
immutable tags, which sometimes is a cause for great confusion.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Since there is no safe way (unique hash/id) to identify unused named
volumes, we cannot automate removal of them. Since volume data, when
compared to a container image, is quite small, it was decided that we
document this instead.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add bash completion for the common datastores, like we already do in the
CLI, and update the usage text accordingly.
Also, make sure to install to /usr/bin, not /bin since we've now merged
the hierarchies since a while back.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The regular file-to-file copy, was missing calls to cfg_adjust(), this
commit fixes that and adds some helpful comments for each use-case.
Also, drop insecure mktemp() in favor of our own version which uses the
basename of the remote source file.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This is a follow-up to PR #717 where path traversal protection was
discussed. A year later and it's clear that having a user-friendly
copy tool in the shell is a good thing, but that we proably want to
restrict what it can do when called from the CLI.
A sanitize flag (-s) is added to control the behavior, when used in the
shell without -s, both commands act like traditional UNIX tools and do
assume . for relative paths, and allow ../, whereas when running from
the CLI only /media/ is allowed and otherwise files are assumed to be
in $HOME or /cfg
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit adds config file validation to the copy command, discussed
in #373. Allowing users to test their config files before restoring a
backup. The feature could also be used for the automatic rollback when
downgrading to an earlier version of the OS.
Fixes#373
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When copying to the running datastore we cannot use sr_copy_config(),
instead we must use sr_replace_config(). This fix covers both the case
of 'copy startup-config running-config' and 'copy FILE running-config'.
Fixes#1203
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Rename test directories in infix_containers/ to remove the redundant
'container_' prefix since they already live under infix_containers/:
container_basic -> basic
container_bridge -> bridge
container_enabled -> enabled
container_environment -> environment
container_firewall_basic -> firewall_basic
container_host_commands -> host_commands
container_phys -> phys
container_veth -> veth
container_volume -> volume
Also update references in all.yaml and Readme.adoc files.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit adds four (small) container images to the Infamy test container
which are used in the new container upgrade test. The test verifies that a
mutable container can be upgraded and that old images are properly cleaned
up from the container store.
Fixes#624
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Already supported in the CLI. This makes it official, and quite handy
for users that run mutable containers.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Shell script:
- Factor out big portions of code into more logical helper functions
- Simplify calling setup script by checking for remote image first
- Simplify meta/sha up-to-date handling and clarify terminology
- Consistent use of -f instead of -e in file-exists checks
- Fix unsafe use of 'mktemp -u'
C code:
- Clarify meta/sha terminology: rename meta-sha256 -> meta-image-sha256
- Refactor weird archive_offset() function to local_path() helper
- Factor out helper function calc_sha()
- Check len of sha256 >= 64
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
One unique feature of Infix OS is that you can embed your OCI archive in
the rootfs.squashfs. This way your container instance does not need to
download anything from the network. To upgrade you drop in a new image
and rebuild Infix, when the new Infix boots the container script 'setup'
command will recognize that the OCI archive has changed and will reload
it into the container store.
This patch is an improvement of the way too generic 'podman image prune'
command used previously. Instead of looking for any dangling image, we
now surgically remove the old image.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Container instances that run with mutable images, e.g., tagged with `:latest`
or similar non-versioned tags, can be upgraded without changing the config.
This commit fixes two issues found with this support:
- force container image re-fetch on upgrade, even if the file exists locally
- surgically remove old image from container store after upgrade
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Usually, when your system is up and running properly, you want to clean
up anything unused from your previous experiments. This change alllows
that by calling the interactive 'podman image prune -a -f' command from
the CLI command 'container remove all'
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When loading big OCI images at boot the `podman load` process completely
monopolizes all cores of an Arm Cortex-A72. It blocks on I/O, sure, but
with 'nice' we can get some attention at least to more critical services
at boot.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit reverts 477f7ae and bb19d06, which intended to fix an issue
with lingering old images, see #1098. However, as detailed in #1147,
this caused severe side effects while working with multiple larger
containers. Basically, the prune operation of one container removed
images of other containers that are just being created in parallel.
Instead of using the podman prune command we can use the meta datain the
start script to pinpoint exactly which image(s) to remove, including any
downloaded OCI archives when the container instance is removed.
Fixes#1147
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit adds metadata to track loaded OCI archives to allow skipping
'delete + load' of OCI images when restarting either the container or the
system as a whole. The sha256 of all loaded OCI archives is stored in a
sidecar file in our downloads directory. Then we verify the checksum of
the OCI archives against their same-named sidecar to determine if the OCI
archive is already loaded or not.
Additionally, the instance using the image is labled with metadata to detect
changes in the container configuration. This in turn allow skipping the
delete + create phase also of the instance.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The default timeout for 'podman stop foo' is 10 seconds, which for
heavily loaded systems with intricate shutdown process is *waaaay*
too short. Increase it to the container script default 30s, which
coincidentally is also the container@.conf template's kill delay.
Fixes#1149
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Not only great for debugging, but also allows users to start their
containers manually in another way. But yeah, mostly for debug.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This rectifies an omission from the initial yang model. Not all
charachters are supported in container and volume names. E.g.,
simply attempting to create a volume or container with a space
in the name causes this error message from podman:
podman: Error: running volume create option: names must match [a-zA-Z0-9][a-zA-Z0-9_.-]*: invalid argument
In addition to the regexp, the new 'ident' type also enforces a
minimum and maximum length. Sure, technically a single char is
allowed, but let's be reasonable, and who in their right mind
wants an identifier > 64 chars? We have description for that.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Slight refactor of page, adding another badge for the latest release,
and restructuring the Technical Details section a bit.
[skip ci]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The curl.sh wrapper script had several issues:
- Used 'shift 2' incorrectly without proper argument validation
- Required hostname as enviroment variable instead of option
- Lacked proper option parsing, should behave like a cross between
curl and sysrepocfg
All examples have been updated to match the refactored script, and
a local copy in utils/curl.sh has been added.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Fixes a minor regression after merge of BPi-R3. The RPi4 device tree,
specifically regulator-sd-io-1v8 in bcm2711-rpi-4-b.dts, requires the
GPIO voltage regulator be built-in for the SD card controller.
Fixes#1197
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Coverity scan detected a memory leak in the new firewall change() cb
where allocated memory from ietf_interfaces_get_all_l3() was not freed
on error paths when srx_get_diff() failed or returned NULL.
This commit consolidates all cleanup paths to use the 'done:' label,
ensuring ifaces, diff, and cfg are properly freed in all exit scenarios.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add supoprt for infix-firewall.yang, modeled on the zone-based firewalld
The terminology is a mix of firewalld, classic netfilter and inspired by
Ubiquity. E.g., zone 'policy' -> 'action', and the zone matrix overview.
- Port forwarding allows forwarding a range of ports
- Operational data comes from firewalld active rules
- Firewall logging goes to /var/log/firewall.log
- Show implicit/built-in rules and zones (HOST) in firewall matrix,
includes "locked" policy for the default-drop behavior
- The zone services field in admin-exec 'show firewall' shows ANY when
the zone default action is set to 'accept'
- Zone 'forwarding' and 'masquerade' settings live in Infix in the
policys instead, meaning users need to explicitly add a policy
to allow both intra-zone and inter-zone forwarding
- Support for emergency lockdown (kill switch)
- Pre-defined services (xml+enums) are filtered and included as a
separate YANG model, extensions added for netconf and restconf
- Includes initial support for firewalld rich rules
firewalld policy rules, including rich rules, have an obnoxious priority
field which is extremely hard to get right, so in Infix we use the far
superior YANG construct 'ordered-by user;'. This ensure all rules are
generated in that order by setting the priority field, on read-back from
firewalld (operational) the priority field is used to sort the output
of rules in the CLI.
Fixes#448
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Used by infix-firewall.c when figuring out interfaces that are not
explicitly assigned to any zone. Placing them in the default zone
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The 'brief' keyword has been gone for a while now. Also, update the
ouput to match the "new" cli-pretty formatting.
Fixes#1174
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
With all jobs now depending on check-trigger we can do the evaluations
there and set some variables that can be reused later.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Here we use a check-trigger job that all the others depend on, which
should prevent duplicate workflows starting a bit more elegantly than
killing one of them with the concurrency checker.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
In setups like this...
CPU
eth0
|
.----0----.
| dst0sw0 |
'-1-2-3-4-'
|
.----0----.
| dst1sw0 |
'-1-2-3-4-'
...both eth0 and dst0sw0p4 are DSA ports. But the latter is _also_ a
physical port as far as devlink is concerned. As a result, it would
first be marked as "internal" and is then instantly reclassified as a
"port".
Catch this condition and stick with the initial "internal"
classification.
In addition to matching on interface names, add support for matching
on ethtool information.
Example:
{
"@ethtool:driver=st_gmac": {
"broken-mqprio": true
}
}
This would mark any interface using the "st_gmac" driver as having a
broken mqprio implementation. Whereas this:
{
"@ethtool:driver=st_gmac;bus-info:30bf0000.ethernet": {
"broken-mqprio": true
}
}
Only matches an st_gmac-backed interface at the specified location.
As matching becomes more complicated, use the shell implementation
from confd as well, to make sure that they are always in agreement.
Fix a bug where systems with OSPF enabled on some, but not all,
interfaces would cause the OSPF iterator to fail when accessing
iface['area'], which was missing. This caused the ospf_status.py
tool to return {}, resulting in empty OSPF data in sysrepo.
Fixes#1169 Expected neighbors not shown in sysrepocfg
Signed-off-by: Richard Alpe <richard@bit42.se>
The xpath_to_uri() method only processed the first predicate in XPath
expressions with multiple [key='value'] patterns. Each re.sub() call
was performed on the original xpath instead of the result the previous
substitutions, causing subsequent predicates to be ignored.
Example XPath that would fail:
/infix-firewall:firewall/zone[name='untrusted']/interface[.='e2']
Would incorrectly convert to:
/infix-firewall:firewall/zone[name='untrusted']/interface=e2
Instead of the correct RESTCONF URL:
/infix-firewall:firewall/zone=untrusted/interface=e2
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Before this change:
ok 2 - Configure basic end-device firewall
not ok 3 - Verify unused interface assigned to default zone
# Exiting (2025-09-25 11:33:00)
# Traceback (most recent call last):
# File "/home/jocke/src/x-misc/test/./case/infix_firewall/basic/test.py", line 127, in <module>
# assert unused_if not in public_zone["interface"], \
# ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
# AssertionError: Unused interface e4 should be in default zone 'public', got interfaces: ['e2', 'e3', 'e5', 'e7', 'e8']
After this change:
ok 2 - Configure basic end-device firewall
not ok 3 - Verify unused interface assigned to default zone
# Exiting (2025-09-25 11:35:00)
# File "/home/jocke/src/x-misc/test/./case/infix_firewall/basic/test.py", line 127, in <module>
# assert unused_if not in public_zone["interface"], \
# ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
# Unused interface e4 should be in default zone 'public', got interfaces: ['e2', 'e3', 'e5', 'e7', 'e8']
Slightly shorter and arguably easier to read for a non-pythonic human.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A very common pattern in our tests is:
if (condition):
print(f"the condition failed with {output}")
test.fail()
This change allows us to write:
if (condition):
test.fail(f"the condition failed with {output}")
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The rauc event logger is a separate glib logger that by default logs to
the system console, with annoying ANSI escape sequences. This commit
drops the default stdout/stderr redirect of these log messages and adds
a more exhaustive bundle install and event log, in json format, instead.
For more information about event logging, see the rauc documentation:
https://rauc.readthedocs.io/en/latest/advanced.html
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Drop 'local', not available in POSIX shell scripts
- Check for an assortment of backup file combos
- Simplify nested if-statements, skip whitelist first
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The default 'trace' log level is quite verbose for our production systems.
This commit changes the default to 'info' and adds a command line option
to control the log level if needed.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
To be able to maintain our own set of patches on top rousette, a kkit
branch have been set up with a reduced set of backported fixes.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- cli: add '-r' to log/pager/follow for "raw" control chars, including unicode
- sysklogd: backport unicode fix for em-dash character (—) in slogan
- sysklogd: drop old patches
- sysklogd: run in 8-bit safe mode
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This is currently a standalone workflow that needs manual trigger via
workflow_dispatch, but the end goal here is to chain it to the release
job.
Signed-off-by: Richard Alpe <richard@bit42.se>
Add concurrency control to trigger workflow to cancel in-progress builds
when new events (like adding ci:main label) occur on the same PR. This
prevents resource waste from duplicate builds and handles the common
workflow where developers add the ci:main label after PR creation.
Fixes#1154
Adjust DHCP client retry behavior:
-t 3 (was -t 10) : Maximum discovery attempts per cycle
-T 5 (was -T 3) : Seconds to wait between attempts
-A 30 (was -A 10) : Seconds to wait after all attempts fail
Before: 10 attempts × 3 seconds = 30 seconds of rapid trying, then 10
second pause = 40 second total cycle
After: 3 attempts × 5 seconds = 15 seconds of trying, then 30 second
pause = 45 second total cycle
=> 70% fewer log messages during active attempts, with longer quiet
periods between cycles.
Fixes#1100
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Add HISTCONTROL=ignoreboth to ignore duplicate commands and those
starting with space, enable histappend, and improve tab completion
behavior. Also add /etc/inputrc for better readline key bindings.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
To reduce the duplication of effort between 9pm and the Infamy framework
this change consolidates the move from local 'infamy: title:' extension
to 9pm 'name:'.
For the parameterized tunnel tests we leverage the 9pm dynamic test-spec
variable, which looks for a correspodning <case>.adoc instead of static
Readme.adoc, when generating the test report.
Each test documentation should cover all aspects of the test, much like
the usage text of a UNIX program. To this end, the tunnel test docs are
now more spelled out, including all invariants.
Some refactoring of these tests were also necessary, e.g., replacing any
reserved Python keywords like 'type', and other PEP-8 fixes.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Import new 9pm version for improved test report generation. With this
in place we can take the opportunity to also refactor and simplify the
test spec. generation.
Fixes#1129
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit greatly simplifies AsciiDoc image references in generated
Readme.adoc files. The two focused use-cases that remain after this
change are working references in:
- Generated output/images/test-report.pdf
- Viewing test's Readme.adoc from GitHub
Previously we aimed to have working images also when the test's Readme
was included in the parent directory's Readme.adoc. This, however, is
not supported as of this commit. It seems unlikely also to ever be a
supported feature of AsciiDoc on GitHub, for details, see the following
issue: <https://github.com/github/markup/issues/1095>
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
It should be possible to create test reports manually, so logically
the GitHub workflow should call a make rule in test.mk
Untested: branding, or any case where Infix is used as a BR2_EXTERNAL
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The Banana Pi R3 is a high-performance networking board featuring:
- MediaTek MT7986 ARM Cortex-A53 quad-core processor
- 4x Gigabit LAN ports (lan1-lan4)
- 1x Gigabit WAN port
- 2x SFP ports (sfp1, sfp2) for fiber connectivity
- Dual WiFi interfaces (wifi0 for 2.4GHz, wifi1 for 5GHz)
- USB support
- SD card boot support
The motd-banner was behind on the new slogan:
.-------.
| . . | Infix OS — Immutable.Friendly.Secure
|-. v .-| https://kernelkit.org
'-'---'-'
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit completes the collection. We now have small, medium, and
large sizes. Useful for easy conversion to other formats, e.g., bmp.
[skip ci]
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
You need first to clone gns3-registry from https://github.com/GNS3/gns3-registry
Follow this steps:
1. ./utils/bump-gns3.py 25.08.0 ../../gns3/gns3-registry/appliances/infix.gns3a
2. TEST in gns3, just add the new version, start it.
3. run python3 check.py inside gns3-registry, verify infix is ok.
4. Create a pull request to gns3-registry
This fix#1107
This branch can be used to test push events which is especially
useful when working on the CI infrastructure.
Signed-off-by: Richard Alpe <richard@bit42.se>
For a heavily loaded system, 10 seconds/retries is not enough time to
expect containers to have started up. Particularly after the changes
done recently to do prune before and after a container is started.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Usually the CNI bridge plugin "takes care" of enabling IPv4 forwarding
on all interfaces, see issue #1125, but when the container tests are run
in a different order from the infix_containers.yaml, Infix may reset the
IPv4 forwarding on this critical interface.
This change is both future proof and also ensures the test works as it
was intended even if tests are run out-of-order.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- the port-mapping plugin supports iptables or nftables
- the firewall plugin support only iptables or firewalld
Enforce use of iptables wrapper for nftables, for now, in both plugins.
This all needs to be refactored to run podman with "unmanaged" networks
in the future.
Related to issue #1125
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
When a container's image is on an inaccessible remote server, the
container wrapper script waits in the background for any netowrk
changes to retry download of the image.
This change avoids the dangerous previous construct, and is also
easier to read: timeuot after 60 seconds unless ip monitor reads
at least one event before that.
Fixes#1124
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The extended kill delay (10 sec) is sometimes not enough for complex
system containers. Also, podman sometimes take the opportunity to do
housekeeping tasks when stopping a container. So, allow for up to 30
sec. grace period before we send SIGKILL.
With the latest image prune extension, set a 60 sec. timeout for the
cleanup task, in case podman gets stuck. This to prevent any future
mishaps.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Highlights:
- fixes to systemd and s6 type services
- bare-bones libsystemd replacement with #include <systemd/sd-daemon.h>
- new reload:script mimicking systemd ExecReload, and
- new stop:script mimicking systemd ExecStop
- exit status/signal info when a process dies
- service kill:SEC now support up to 300 sec.
- the /tmp/norespawn trick now also covers service_retry()
- the sysv 'stop' command process environment is now same as 'start'
- State machine ordering issue: enter new config generation after
services disabled in previous generation have been stopped
Full changelog at:
- <https://github.com/troglobit/finit/releases/tag/4.13>
- <https://github.com/troglobit/finit/releases/tag/4.14>
Fixes#1123
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
As Infix matures as an operating system it is quickly becoming more and
more useful also for end-device use-cases. The README should reflect
this change in focus.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
From the documentation:
> 'podman image prune' removes all dangling images from local storage.
> With the all option, all unused images are deleted (i.e., images not
> in use by any container).
>
> The image prune command does not prune cache images that only use
> layers that are necessary for other images.
So, when the container script is called in the cleanup phase of the
lifetime of a container, we can use the '--all' option to ensure we also
remove this container's loaded image. In the case this happens before
a reboot of the system, there will be no old version of the image loaded
to /var/lib/containers after boot.
Issue #1098
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
There are 2 main reasons for this:
1) It's almost impossible to write complex logical expressions in GH
workflows. I wanted to pass "" as flavor when not building _minimal.
So that the end target string would become TARGET + FLAVOR where
FLAVOR is empty, making it x86_64 for example.
As it turns out "" is false in GH workflow logical expressions, this
in conjunction with the limitations the interpreter has made it hard
to actually write sane expressions in the "with:" variables when
calling downstream jobs via workflow calls.
Here's an example of what I was trying to do and could not:
with:
flavor: ${{ (
github.event_name == 'pull_request' &&
contains(github.event.pull_request.labels.*.name, 'ci:main')
) && '' || '_minimal' }}
As '' is false, the first sets of expressions always evaluates to
false making the string "_minimal". I tried bracing this in various
ways and to use "null" or various JSON objects, all in vain.
2) It reduces complexity instead of adding additional.
Signed-off-by: Richard Alpe <richard@bit42.se>
Previously, upgrading Podman containers with the same tag left
behind dangling images, causing overlay storage to grow and fill
disk space.
This change ensures dangling images are cleaned up using
podman image prune. The command is run without -a, so only
unreferenced images are removed. This provides safe cleanup while
preventing unnecessary overlay growth.
Fixes#1098
Signed-off-by: Richard Alpe <richard@bit42.se>
The defconfigs for all architectures other than x86_64 has this
enabled, so align it with the rest.
This has no on-target impact, but it enables us to attach to a live VM
instance and debug it, or do offline debugging like resolving stack
trace lines from oops messages to source locations.
The board/common/uboot/extras.config was updated with CONFIG_MMC_PCI
*after* we last built the SparX5i bootloader, and this was really only
needed for the Qemu build, so let's move the requirement there.
Also, we now (Buildroot 2025.02) need to update the dependencies for the
Fireant bootloader with libbsd (for some reason) and dtc, of course.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commit migrates the bootloader build from Raspberry Pi 4 board
package to a dedicated bootloader defconfig. The idea is to set up
dedicated wokflows for building bootloaders, which change rarely,
streamlining the Infix image builds.
A dedicated workflow, or job in an existing workflow, can then do
the composition to minimal SD-card images useful for starting up
Infix on boards where SD-card is the primary boot source.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Prior to this commit yanger looked at the running system using
os.path..., this meant that the static reply / capture data wasn't
used properly. This resulted in strange behavior during unit testing
on GitHub runners where USB ports are missing.
Signed-off-by: Richard Alpe <richard@bit42.se>
The execd runner has not been used since Nov, 2024, ca0e54b. This
weekend it started triggering a warning from Coverity Scan, so let
us drop it for good this time.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This commits tweaks the material orange theme to use the exact color hue
of Jackys footies. To match this and give a slightly better contrast we
also change Jacksy border and logo text color to a slightly darker tone.
The original logo.svg is retained for reference, the new logo is logo2,
which all the .png variants have now been updated to.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
In the spirit of my uni English teacher; "simplify, Simplify, SIMPLIFY!"
This commit collapses the About and Introduction into a single document,
doc/index.md.
Also, relocate the System Boot section to doc/boot.md, which we alrady
have and covers the initial bootloader part of it.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Lot of work still remains, but this new disposition should serve as a
more representative template.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Files in doc/cli/*.md are used in and displayed as help text in the CLI
admin-exec level. So we cannot use standard admonitions (yet) since the
terminal markdown converter (lowdown) doesn't support the syntax.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
We want to discourage people to use sysrepocfg and instead move to use
NETCONF, or even better, RESTCONF. When something's missing we should
add it to these two official, and standardized, interfaces.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
And make the ASCII image more generic to ease any branding work we may
need to do for certain customers later on.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- custom cover page for pdf
- Center and resize logo
- Place slogan just below logo
- Ensure all text on cover page is in matching grey
Please note, the mkdocs-to-pdf plugin works, but it has a bug in the
enumeration of sections. We may need to fork it to make it work the
way users expect.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Way too long. By splitting it in multiple files we can also user
simpler (shorter) headings, which makes navigation easier.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The Python tool 'mike'[1] helps manage multiple versions of MkDocs-powered
documentation. Only required when building the kernelkit.org site docs!
For each new tag, that steps year or month, a new version of is created of
the documentation, in a separate sub-directory on the gh-pages branch.
Strategy - Version Grouping with Early Publishing:
- Extract YEAR.MONTH from tag
E.g., v25.06.0-beta1, v25.06.0-rc1, v25.06.0, v25.06.1 → become version 25.06
- From first pre-release onwards:
- v25.06.0-beta1 → creates docs version 25.06
- v25.06.0-rc1 → updates docs version 25.06
- v25.06.0 (GA) → updates docs version 25.06
- v25.06.1 (patch) → updates docs version 25.06
- New major/minor series:
- v25.07.0-beta1 → creates new docs version 25.07
Benefits:
- Users get docs as soon as beta/rc is available
- Patches update existing docs (logical since patches rarely change docs significantly)
- Clean version grouping by YEAR.MONTH
- Mike handles create vs update automatically
[1]: https://github.com/jimporter/mike
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Major overhaul and simplification of both language and structure to
improve accessibility and UX in new documentation framework.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Note, this change breaks some links on GitHub due to the difference in
how MkDocs and GitHub implement "autolinking" and anchors. Since the
idea is to make MkDocs our primary documentation framework, breaking
links on GitHub in favor of MkDocs is the best compromise.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This makes it a lot easier to find relevant information on how to
perform a system upgrade. Further consolidation may come later.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Redesign how GH actions are triggered. This new design uses a
self-trigger to start jobs which are only started via workflow_calls.
The main benefit of this is to be able to start workflows from various
Infix Spins without needing to duplicate the workflow files in them.
Upcoming patches are intended to parameterize to allow Spins to pass
different architectures, brand names and such.
Signed-off-by: Richard Alpe <richard@bit42.se>
We was missing the firmware required for this, and for this to work
cfg80211 needs to be as module since the rootfs is not loaded when it
is loaded if compiled in kernel.
And add iw since it very useful for debugging.
Add test to verify a container on Infix can execute commands on the
host by mounting a script to `/etc/rc.local` with proper permissions.
The test confirms host hostname change using `nsenter` from inside
a privileged container.
Resolves#1024
- Fix by-word movement, detect word barrier using non-alphanum chars
- Fix delete word left/right, make sure to save word in kill buffer
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
- Buildroot updated to v25.02.3
- Tefactor of nftables container
The nftables container now includes BusyBox, a shell with vi and some
basic filesystem tools, as well as nsenter and unshare, suitable for
testing and other more advanced tasks.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Support implemented:
* WPA2/3 support
* scanning (in background, results in operational)
* Unencrypted networks
No certificate support, only PSK
*only* client so far, no AP
If a extra infix feature require features to be added to an already
loaded module. Instead of have the exact module definition in multiple
places (with date), this will allow a much more flexible sytax:
MODULES=(
"infix-interfaces -e containers"
)
This require that the infix-interfaces is loaded *before* this file
is run.
This since the feature is called 'wifi' in Infix, this makes the naming
consistent over the system.
Also trigger start of a wpa_supplicant, for scanning in the background.
The scanning results is available operational.
Some CLI commands where inadvertently moved from the global CLI
context into the show context.
For example the upgrade command.
As a result, commands like upgrade were unavailable at the top-level
prompt:admin@ix-00-00-00:/> upgrade ?
Error: Command not found, or incomplete.
However, these commands remained accessible under the "show" context
as a temporary workaround:
admin@ix-00-00-00:/> show upgrade ?
URI [(ftp|tftp|http|https|ftp)://(dns.name | ip.address)/path/to/]upgrade-bundle.pkg
This patch restores the affected commands to the global CLI context so
that commands like upgrade function as intended at the root prompt.
Fixes: 9c0a8e39 klish-plugin-infix: fix indentation in infix.xml
Signed-off-by: Richard Alpe <richard@bit42.se>
title: `Upgrade to kernel ${{ steps.check.outputs.current_version }}`,
head: 'kernel-upgrade',
base: 'main',
body: `Automated kernel upgrade to version ${{ steps.check.outputs.current_version }}.\n\n**Previous version:** ${{ steps.check.outputs.latest_tag }}\n**New version:** ${{ steps.check.outputs.current_version }}\n**Source:** https://www.kernel.org/\n\nThis PR was automatically created by the kernel release monitoring workflow.`
echo "> **Try Infix in GNS3!** Download the appliance from the [GNS3 Marketplace](https://gns3.com/marketplace/appliances/infix) to test Infix in a virtual network environment without hardware." >> release.md
Full support for base board but not any extension board on the GPIOs.
Other RPi boards of the same generation may work as well, but may need
some additional testing/work. A few CM4 variants have been tested and
seem to work as expected, but YMMV as always.
### Touch screen
The [Raspberry Pi touch display v1][0] is supported on the 4B, including
touch functionality. There are multiple touchscreens on the market for
Raspberry Pi, but currently only the official first version with 800x480
resolution is supported. Infix supplies all drivers required to utilize
the hardware, but you need to add the actual graphical application in a
container.
There are some important considerations you need to know about when
using Infix for graphical applications. The container needs access to
`/dev/dri/` to be able to access the graphics card, it also need access
to `/run/udev` to be able to find the input devices.
Example of running Doom in Infix:
```
admin@example:/> configure
admin@example:/config/> edit container doom
admin@example:/config/container/doom/> set image docker://mattiaswal/alpine-doom:latest
admin@example:/config/container/doom/> set privileged
admin@example:/config/container/doom/> edit mount udev
admin@example:/config/container/doom/mount/udev/> set type bind
admin@example:/config/container/doom/mount/udev/> set target /run/udev/
admin@example:/config/container/doom/mount/udev/> set source /run/udev/
admin@example:/config/container/doom/mount/udev/> end
admin@example:/config/container/doom/mount/xorg.conf/> set content U2VjdGlvbiAiT3V0cHV0Q2xhc3MiCiAgSWRlbnRpZmllciAidmM0IgogIE1hdGNoRHJpdmVyICJ2YzQiCiAgRHJpdmVyICJtb2Rlc2V0dGluZyIKICBPcHRpb24gIlByaW1hcnlHUFUiICJ0cnVlIgpFbmRTZWN0aW9uCg==
admin@example:/config/container/doom/mount/xorg.conf/> set target /etc/X11/xorg.conf
admin@example:/config/container/doom/mount/xorg.conf/> end
admin@example:/config/container/doom/> edit volume var
admin@example:/config/container/doom/volume/var/> set target /var
Some files were not shown because too many files have changed in this diff
Show More
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.