Skip to content
Draft

Yangerd #1536

Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
153 commits
Select commit Hold shift + click to select a range
9bc656c
TEMP: WiP document
mattiaswal Mar 27, 2026
8cbe3b1
TEMP: Update yanger spec
mattiaswal Mar 28, 2026
3a235e6
firewall: simplify
mattiaswal Mar 31, 2026
b33f834
test: system: Make tests more robust
mattiaswal Mar 31, 2026
1d19272
test: firewall: Make tests more robust
mattiaswal Mar 31, 2026
3ded7fb
yangerd: Initial
mattiaswal Mar 31, 2026
5b3f688
move yanger
mattiaswal Mar 31, 2026
964224f
statd: Include new yangerd backend for operational
mattiaswal Mar 31, 2026
35b8603
update doc
mattiaswal Mar 31, 2026
e4b569b
Fix routing and ip addresses
mattiaswal Mar 31, 2026
12a7fc4
yangerd: Continues
mattiaswal Mar 31, 2026
be8525b
zapi: Fix deletion of routes
mattiaswal Apr 24, 2026
a997f18
Fix interface and bridge race conditions
mattiaswal Apr 27, 2026
3cd1738
FRR does not send delete on OSPF route change
mattiaswal Apr 28, 2026
eeed083
Fix ntp and dns status
mattiaswal Apr 28, 2026
271f186
test: dhcp: server_subnets: Add longer timeout for polling
mattiaswal Apr 28, 2026
ce7c922
test: case: ntp: Adapt tests for polled yangerd
mattiaswal Apr 28, 2026
04f227d
Fix containers, reactive now.
mattiaswal Apr 29, 2026
d4e4947
test: containers: host_commands/test.py: Adapt to new yangerd
mattiaswal Apr 29, 2026
f2d3039
test: usb: adapt to new yangerd
mattiaswal Apr 29, 2026
c2cf586
yangerd: Send sighup to yangerd on config change
mattiaswal Apr 29, 2026
8a19e6c
yangerd: fix stp status
mattiaswal Apr 29, 2026
ef02a6f
yangerd: Add wireguard support
mattiaswal Apr 29, 2026
9f5ce5b
test: wireguard_roadwarrior: Adapt to the new polled world in yangerd
mattiaswal Apr 29, 2026
1f9709a
test: iface_enable_disable: Simplify test
mattiaswal Apr 29, 2026
26f841c
yangerd: Do not start in runlevel S
mattiaswal Apr 30, 2026
0328ad6
yangerd: Add backoff if ip batch work have crashed
mattiaswal Apr 30, 2026
89e3f5d
yangerd: Add WiFi implementation
mattiaswal May 2, 2026
6637956
yanger: Remove code duplication and fix upgrade
mattiaswal May 20, 2026
5af7ea1
statd: Remove old code
mattiaswal May 20, 2026
9335b20
test: upgrade: Add adaptions needed for yangerd
mattiaswal May 22, 2026
bc6f455
test: upgrade: Add adaptions needed for yangerd
mattiaswal May 22, 2026
95046d0
test: syslog: property_filter: Adapt to changes required by yangerd
mattiaswal May 22, 2026
e30df18
yangerd: Add support for getting ARP neighbors
mattiaswal May 22, 2026
f9deb33
tests: Adapt to new yangerd
mattiaswal May 22, 2026
a9534e4
test: stp_basic: Stabilize test
mattiaswal Jun 5, 2026
e607b8a
test: ntp_client: Adapt to new yangerd daemon
mattiaswal Jun 5, 2026
57170dc
test: veth_delete: Adapt to new yangerd
mattiaswal Jun 10, 2026
3b10ffe
test: ospf_unnumbered_interface: Adapt to new yangerd
mattiaswal Jun 10, 2026
d8c50a4
test: route_pref_ospf: Adapt to yangerd
mattiaswal Jun 10, 2026
65a2a40
test: upgrade: Adapt to yangerd
mattiaswal Jun 10, 2026
147aa25
yangerd: Add missing files
mattiaswal Jun 10, 2026
1f2506c
test: upgrade: add missing readme
mattiaswal Jun 11, 2026
9adde12
test: ospf_point_to_multipoint: Adapt to yanger
mattiaswal Jun 11, 2026
5e48775
test: hostname: adapt to yanger
mattiaswal Jun 11, 2026
1cba966
test: ntp_client: Update test spec
mattiaswal Jun 11, 2026
0367912
test: route_pref_ospf: Update test spec
mattiaswal Jun 11, 2026
33f2734
test: ospf_default_route_advertise: Make test more robust
mattiaswal Jun 11, 2026
ad4c08f
statd: Adapt to yanger keys on module:container path
mattiaswal Jun 12, 2026
e801938
yangerd: Return {} instead of 404 if no match
mattiaswal Jun 12, 2026
9c4fc4e
yangerd: Fix ntp and lldp status
mattiaswal Jun 12, 2026
99717eb
test: ntp: client_stratum_selection: Adapt to yangerd behaviour
mattiaswal Jun 12, 2026
c1159b8
test: rip_multihop: Adapt to yangerd changes
mattiaswal Jun 12, 2026
83eedb2
test: firewall: ipv6-zone-migration: Adapt to yanger behaviour changes
mattiaswal Jun 12, 2026
937764e
dhcp: server_subnets: Adapt to yanger behaviour changes
mattiaswal Jun 12, 2026
5f2bb4e
test: mdns_allow_deny: Adapt to yangerd behaviour changes
mattiaswal Jun 12, 2026
ab7398d
yangerd: add missing files
mattiaswal Jun 12, 2026
32584b4
yangerd: Add arm 32bit support
mattiaswal Jun 12, 2026
f1728d7
test: speed_duplex_coppar: Adapt to yangerd
mattiaswal Jun 12, 2026
1e9d086
test: upgrade: Make more robust using yangerd
mattiaswal Jun 14, 2026
2eb3580
test: dhcp: client_basic: Adapt to changes by yangerd
mattiaswal Jun 14, 2026
80bb10c
yangerd: Fix bugs with containers and boot order in CI
mattiaswal Jun 14, 2026
36fc951
yangerd: Change containers from polled to reactive
mattiaswal Jun 17, 2026
b1ab2f2
yangerd: Fix containers
mattiaswal Jun 18, 2026
bac59c2
yangerd: containers: widen event debounce to avoid podman contention
mattiaswal Jun 20, 2026
53b8497
yangerd: firewall: Add support for IPsets
mattiaswal Aug 14, 2026
bdd24fd
test: virt: Increase RAM per virtual DUT
mattiaswal Aug 14, 2026
c71048b
yangerd: Remove mdlayher/ethtool, not used anymore
mattiaswal Aug 14, 2026
4c6bfb9
yangerd: ntp: Query chronyd over cmdmon instead of chronyc
mattiaswal Aug 14, 2026
2bb2ca3
yangerd: Add ieee1588-ptp-tt operational monitor
mattiaswal Aug 17, 2026
f864d23
confd: firewall: Re-apply dynamic address-set entries after reload
mattiaswal Aug 17, 2026
92b3fd1
test: routing: ospf_basic: Poll for OSPF neighbors in operational
mattiaswal Aug 18, 2026
b97917c
yangerd: add TFTP served-files monitor
mattiaswal Sep 28, 2026
8b4e304
yangerd: iface: add higher-layer-if and lower-layer-if
mattiaswal Sep 28, 2026
02d8e30
yangerd: lldp: ensure unique remote-systems-data keys
mattiaswal Sep 28, 2026
8b7efaf
yangerd: hardware: find sensors by class, not by name
mattiaswal Sep 28, 2026
ace5ebc
yangerd: hardware: read sensors on GET instead of polling
mattiaswal Sep 28, 2026
68391c4
yangerd: wifi: add mesh-point operational data
mattiaswal Sep 28, 2026
3d91905
yangerd: wifi: report the BSSID a station is connected to
mattiaswal Sep 28, 2026
b003159
yangerd: backoff: add Retry, the restart loop every monitor hand-rolls
mattiaswal Sep 28, 2026
6df257a
yangerd: tree: export ShallowMerge
mattiaswal Sep 28, 2026
18a1e54
yangerd: tree: call providers unlocked, create entries under the writ…
mattiaswal Sep 28, 2026
3075b4c
yangerd: main: one spawn helper for the monitor goroutines
mattiaswal Sep 28, 2026
d1828ad
yangerd: ethmonitor: listen on the right message types, off the event…
mattiaswal Sep 29, 2026
65000b6
yangerd: iface: keep counter64 exact, drop dedup and the stats copy
mattiaswal Sep 29, 2026
55ae6c5
yangerd: ipbatch: one batch runner for ip and bridge, fail fast
mattiaswal Sep 29, 2026
8171d9a
yangerd: monitor: key staging by ifindex, coalesce rebuilds
mattiaswal Sep 29, 2026
6dcb142
yangerd: stpquery: keep topology-change time stable between polls
mattiaswal Sep 29, 2026
a23df32
yangerd: collector: one poke channel per collector
mattiaswal Sep 29, 2026
6c749d9
yangerd: main: reuse tree.ShallowMerge, read boot order from the cache
mattiaswal Sep 29, 2026
5401817
yangerd: monitor: ask ethtool for every port after the initial dump
mattiaswal Sep 29, 2026
799720d
yangerd: routing: clear protocols that stop running
mattiaswal Sep 29, 2026
30b1b58
yangerd: routing: parse RIP versions by column
mattiaswal Sep 29, 2026
639c6c5
yangerd: zapi: cancellable reads, bounded vty queries
mattiaswal Sep 29, 2026
ee5506a
yangerd: dbus: use backoff.Retry for the reconnect loop
mattiaswal Sep 29, 2026
4bdbc29
yangerd: software: re-read slots when a RAUC install completes
mattiaswal Sep 29, 2026
0ab16a2
yangerd: firewall: only ask nft about timeout sets
mattiaswal Sep 29, 2026
cc680b3
yangerd: system: reuse the shared bus for RAUC installer status
mattiaswal Sep 29, 2026
65b7fc7
yangerd: routing: query ospfd, ripd and bfdd over vty in-process
mattiaswal Sep 29, 2026
af4f7a9
yangerd: containers: bound collection time, drop the unused collector
mattiaswal Sep 29, 2026
3f44380
yangerd: dhcp: keep leases when the lease file read is torn
mattiaswal Sep 29, 2026
96bdc1e
yangerd: dns: report resolver origin and interface again
mattiaswal Sep 29, 2026
59220e5
yangerd: firewall: list every firewalld service
mattiaswal Sep 29, 2026
b20eeea
yangerd: system: report /run and /tmp usage again
mattiaswal Sep 29, 2026
293d927
yangerd: zapi: drop the unused route decoder
mattiaswal Sep 29, 2026
6021049
yangerd: numconv: one number converter instead of five
mattiaswal Sep 29, 2026
aa24679
yangerd: firewall: share the port range parser
mattiaswal Sep 29, 2026
f291c15
yangerd: collector: share run-and-decode, report initctl failures
mattiaswal Sep 29, 2026
4215546
yangerd: system: skip the installer overlay on a decode error
mattiaswal Sep 29, 2026
f251c37
yangerd: dbus: delete the subtree when dnsmasq or firewalld exits
mattiaswal Sep 29, 2026
d53d726
yangerd: ipc: send data in its own frame, bound every connection
mattiaswal Sep 29, 2026
5394306
statd: fold routing callbacks into the generic one, stop leaking parents
mattiaswal Sep 29, 2026
1e44df7
confd: do not fail the commit when yangerd cannot be reloaded
mattiaswal Sep 29, 2026
c8a5294
confd: firewall: stop resurrecting dynamic entries that cannot stay
mattiaswal Sep 29, 2026
3e40262
yangerd: fswatcher: follow files that come and go
mattiaswal Sep 29, 2026
7571ab5
yangerd: add unixgram, use it for wpactrl client sockets
mattiaswal Sep 29, 2026
a2f8513
yangerd: ptp: fix instance stop race and per-session goroutine leak
mattiaswal Sep 29, 2026
5e8e0db
yangerd: lldp: frame watch events with a JSON decoder
mattiaswal Sep 29, 2026
7376e6c
yangerd: containers: use backoff.Retry for the events subprocess
mattiaswal Sep 29, 2026
4270e5d
package/yangerd: fix log level, gate monitors, declare readiness
mattiaswal Sep 29, 2026
748defc
yangerd: hardware: list sysfs and /dev with Glob instead of forking ls
mattiaswal Sep 29, 2026
f9437d8
yangerd: hardware: keep fans off the CPU, warn once per duplicate name
mattiaswal Sep 29, 2026
d08d7a0
yangerd: hardware: use Go names for the functions ported from Python
mattiaswal Sep 29, 2026
981dd40
yangerd: tftp: re-add watches on every scan, watch the nearest ancestor
mattiaswal Sep 29, 2026
61db2d0
yangerd: tftp: rescan when the mount table changes
mattiaswal Sep 29, 2026
c7a3493
yangerd: wifi: keep mesh-point on disconnect, skip nl80211 for hostapd
mattiaswal Sep 29, 2026
65f45dc
yangerd: forwarding: follow interfaces that come and go
mattiaswal Sep 29, 2026
98fbf25
yangerd: write a pidfile once the interfaces are known
mattiaswal Sep 29, 2026
bc88d69
yangerd: routing: drop the unused command runner
mattiaswal Sep 29, 2026
4bcd0cd
statd: routing: one merged subscription for control-plane-protocols
mattiaswal Sep 29, 2026
03d9825
statd: an empty yangerd answer is no data, not an error
mattiaswal Sep 29, 2026
83d78b0
yangerd: frrvty: enter the enable node before each command
mattiaswal Sep 29, 2026
2dd5f7a
statd: iface: keep last-change stamps in nanoseconds
mattiaswal Sep 29, 2026
d1d0c60
yangerd: monitor: a late delete must not wipe a reused interface name
mattiaswal Sep 29, 2026
d913cb3
yangerd: monitor: name devices by index in batch queries
mattiaswal Sep 29, 2026
db9a7a3
yangerd: wifi: detach from the old daemon when its interface goes
mattiaswal Sep 29, 2026
cd88c4b
statd: drop entries libyang rejects instead of failing the whole GET
mattiaswal Sep 29, 2026
5ab410b
yangerd: monitor: refresh ip when a link query hits a stale name
mattiaswal Sep 29, 2026
39c7197
test: ifalias: poll for the description in operational
mattiaswal Sep 29, 2026
5c54a74
yangerd: monitor: refuse a link answer without the interface in it
mattiaswal Sep 29, 2026
3e673f8
test: iface_phys_address: poll for the static MAC like the other steps
mattiaswal Sep 29, 2026
e53a0dc
yangerd: monitor: one re-dump per burst, once the batches are back
mattiaswal Sep 29, 2026
afc51b7
yangerd: take over interface last-change from statd
mattiaswal Sep 29, 2026
d7ce9c9
yangerd: hardware: radios on nl80211 events, the rest on demand
mattiaswal Sep 30, 2026
d4f2669
yangerd: add README on design and data sources
mattiaswal Sep 30, 2026
eee7ad2
yangerd: wpactrl: notice when an attached daemon goes away
mattiaswal Sep 30, 2026
631e99f
yangerd: firewall: do not let a reloading firewalld stall the GET
mattiaswal Sep 30, 2026
ffcf9ad
test: firewall: address-set: poll for the dynamic entry after reload
mattiaswal Sep 30, 2026
a1b96f2
yangerd: wifi: report only 2.4/5/6 GHz bands, name hwsim radios
mattiaswal Sep 30, 2026
706af8c
yangerd: ntp: read chronyd at GET time, map chrony 4 source states
mattiaswal Sep 30, 2026
97c13dd
yangerd: README: NTP is read on demand
mattiaswal Sep 30, 2026
46357e2
test: wifi_mesh_roaming: read each BSSID once, allow the mesh time to…
mattiaswal Sep 30, 2026
c005895
test: wifi: dump AP and client state when a WiFi check gives up
mattiaswal Sep 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion board/common/rootfs/etc/finit.d/available/firewalld.conf
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
service [2345] <!pid/syslogd> reload:'firewall-cmd -q --reload' \
service [2345] <!pid/syslogd> reload:'firewall reload' \
firewalld --nofork --log-target syslog \
-- Firewall daemon
1 change: 1 addition & 0 deletions configs/aarch64_defconfig
Original file line number Diff line number Diff line change
Expand Up @@ -166,6 +166,7 @@ BR2_PACKAGE_CURIOS_NFTABLES=y
BR2_PACKAGE_GENCERT=y
BR2_PACKAGE_STATD=y
BR2_PACKAGE_SUPPORT_ENCRYPT=y
BR2_PACKAGE_YANGERD=y
BR2_PACKAGE_FACTORY=y
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
Expand Down
1 change: 1 addition & 0 deletions configs/aarch64_minimal_defconfig
Original file line number Diff line number Diff line change
Expand Up @@ -132,6 +132,7 @@ BR2_PACKAGE_CONFD_TEST_MODE=y
BR2_PACKAGE_GENCERT=y
BR2_PACKAGE_STATD=y
BR2_PACKAGE_SUPPORT=y
BR2_PACKAGE_YANGERD=y
BR2_PACKAGE_FACTORY=y
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
Expand Down
1 change: 1 addition & 0 deletions configs/arm_defconfig
Original file line number Diff line number Diff line change
Expand Up @@ -153,6 +153,7 @@ BR2_PACKAGE_CONFD_TEST_MODE=y
BR2_PACKAGE_GENCERT=y
BR2_PACKAGE_STATD=y
BR2_PACKAGE_SUPPORT_ENCRYPT=y
BR2_PACKAGE_YANGERD=y
BR2_PACKAGE_FACTORY=y
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
Expand Down
1 change: 1 addition & 0 deletions configs/arm_minimal_defconfig
Original file line number Diff line number Diff line change
Expand Up @@ -130,6 +130,7 @@ BR2_PACKAGE_CONFD_TEST_MODE=y
BR2_PACKAGE_GENCERT=y
BR2_PACKAGE_STATD=y
BR2_PACKAGE_SUPPORT=y
BR2_PACKAGE_YANGERD=y
BR2_PACKAGE_FACTORY=y
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
Expand Down
1 change: 1 addition & 0 deletions configs/riscv64_defconfig
Original file line number Diff line number Diff line change
Expand Up @@ -184,6 +184,7 @@ BR2_PACKAGE_NETD=y
BR2_PACKAGE_GENCERT=y
BR2_PACKAGE_STATD=y
BR2_PACKAGE_SUPPORT_ENCRYPT=y
BR2_PACKAGE_YANGERD=y
BR2_PACKAGE_FACTORY=y
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
Expand Down
1 change: 1 addition & 0 deletions configs/x86_64_defconfig
Original file line number Diff line number Diff line change
Expand Up @@ -159,6 +159,7 @@ BR2_PACKAGE_CURIOS_NFTABLES=y
BR2_PACKAGE_GENCERT=y
BR2_PACKAGE_STATD=y
BR2_PACKAGE_SUPPORT_ENCRYPT=y
BR2_PACKAGE_YANGERD=y
BR2_PACKAGE_FACTORY=y
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
Expand Down
1 change: 1 addition & 0 deletions configs/x86_64_minimal_defconfig
Original file line number Diff line number Diff line change
Expand Up @@ -129,6 +129,7 @@ BR2_PACKAGE_CONFD_TEST_MODE=y
BR2_PACKAGE_GENCERT=y
BR2_PACKAGE_STATD=y
BR2_PACKAGE_SUPPORT=y
BR2_PACKAGE_YANGERD=y
BR2_PACKAGE_FACTORY=y
BR2_PACKAGE_FINIT_PLUGIN_HOTPLUG=y
BR2_PACKAGE_FINIT_PLUGIN_HOOK_SCRIPTS=y
Expand Down
1 change: 1 addition & 0 deletions package/Config.in
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ source "$BR2_EXTERNAL_INFIX_PATH/package/curios-nftables/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/gencert/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/statd/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/support/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/yangerd/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/factory/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/faux/Config.in"
source "$BR2_EXTERNAL_INFIX_PATH/package/finit/Config.in"
Expand Down
2 changes: 2 additions & 0 deletions package/statd/Config.in
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
config BR2_PACKAGE_STATD
bool "statd"
depends on BR2_PACKAGE_HOST_GO_TARGET_ARCH_SUPPORTS # yangerd
select BR2_PACKAGE_YANGERD
select BR2_PACKAGE_JANSSON
select BR2_PACKAGE_LIBEV
select BR2_PACKAGE_SYSREPO
Expand Down
7 changes: 7 additions & 0 deletions package/yangerd/Config.in
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
config BR2_PACKAGE_YANGERD
bool "yangerd"
depends on BR2_PACKAGE_HOST_GO_TARGET_ARCH_SUPPORTS
help
Operational data daemon for YANG/NETCONF/RESTCONF.
Replaces Python yanger scripts with a persistent Go daemon
serving operational data over a Unix socket IPC protocol.
3 changes: 3 additions & 0 deletions package/yangerd/yangerd.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
service <> name:yangerd notify:pid log:prio:daemon.notice,tag:yangerd \
env:-/etc/default/yangerd \
[2345] yangerd -- Operational data daemon
41 changes: 41 additions & 0 deletions package/yangerd/yangerd.mk
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
################################################################################
#
# yangerd
#
################################################################################

YANGERD_VERSION = 1.0.0
YANGERD_SITE = $(BR2_EXTERNAL_INFIX_PATH)/src/yangerd
YANGERD_SITE_METHOD = local
YANGERD_GOMOD = github.com/kernelkit/infix/src/yangerd
YANGERD_LICENSE = BSD-2-Clause
YANGERD_LICENSE_FILES = LICENSE
YANGERD_REDISTRIBUTE = NO

YANGERD_BUILD_TARGETS = cmd/yangerd cmd/yangerctl
YANGERD_INSTALL_BINS = yangerd yangerctl

define YANGERD_INSTALL_EXTRA
$(INSTALL) -D -m 0644 $(YANGERD_PKGDIR)/yangerd.conf \
$(FINIT_D)/available/yangerd.conf
ln -sf ../available/yangerd.conf $(FINIT_D)/enabled/yangerd.conf
$(INSTALL) -d $(TARGET_DIR)/etc/default
echo '# yangerd build-time feature flags (generated by yangerd.mk)' \
> $(TARGET_DIR)/etc/default/yangerd
echo 'YANGERD_ENABLE_WIFI=$(if $(BR2_PACKAGE_IW),true,false)' \
>> $(TARGET_DIR)/etc/default/yangerd
echo 'YANGERD_ENABLE_CONTAINERS=$(if $(BR2_PACKAGE_PODMAN),true,false)' \
>> $(TARGET_DIR)/etc/default/yangerd
echo 'YANGERD_ENABLE_GPS=$(if $(BR2_PACKAGE_GPSD),true,false)' \
>> $(TARGET_DIR)/etc/default/yangerd
echo 'YANGERD_ENABLE_LLDP=$(if $(BR2_PACKAGE_LLDPD),true,false)' \
>> $(TARGET_DIR)/etc/default/yangerd
echo 'YANGERD_ENABLE_FIREWALL=$(if $(BR2_PACKAGE_FIREWALLD),true,false)' \
>> $(TARGET_DIR)/etc/default/yangerd
echo 'YANGERD_ENABLE_DHCP=$(if $(BR2_PACKAGE_DNSMASQ),true,false)' \
>> $(TARGET_DIR)/etc/default/yangerd
echo 'YANGERD_LOG_LEVEL=info' >> $(TARGET_DIR)/etc/default/yangerd
endef
YANGERD_POST_INSTALL_TARGET_HOOKS += YANGERD_INSTALL_EXTRA

$(eval $(golang-package))
39 changes: 39 additions & 0 deletions src/confd/bin/firewall
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@
DEST="org.fedoraproject.FirewallD1"
OBJECT="/org/fedoraproject/FirewallD1"
INTERFACE="org.fedoraproject.FirewallD1"
ADDRSET_DIR="/run/confd/address-sets"
VERBOSE=0

print() {
Expand Down Expand Up @@ -117,6 +118,42 @@ ipset_call()
fi
}

# Dynamic address-set entries only exist in the runtime config; a reload
# rebuilds the sets from the generated ipset XML, which holds static
# entries only. Re-apply the dynamic entries tracked by confd's
# add/remove action handlers, so they survive the reload without being
# baked into the XML (which would resurrect entries removed while the
# reload was in flight).
#
# An entry firewalld rejects as invalid, e.g., one now overlapping a
# static entry, is dropped from the shadow file, or it could never be
# removed with the remove action again.
addrset_resync()
{
for file in "$ADDRSET_DIR"/*; do
case "$file" in *.resync) continue ;; esac
[ -f "$file" ] || continue
name=$(basename "$file")
keep="$file.resync"
: > "$keep"

while IFS= read -r entry; do
[ -n "$entry" ] || continue
if ! ipset_call addEntry "$name" "$entry"; then
case "$output" in
*INVALID_ENTRY*)
logger -t firewall -p daemon.warn "ipset $name: dropping rejected dynamic entry $entry"
continue
;;
esac
fi
printf '%s\n' "$entry" >> "$keep"
done < "$file"

mv "$keep" "$file"
done
}

panic_status()
{
if is_panic_enabled; then
Expand Down Expand Up @@ -377,6 +414,8 @@ main()
exit 1
fi
fi

addrset_resync
;;
panic)
if ! check_firewalld; then
Expand Down
4 changes: 4 additions & 0 deletions src/confd/src/core.c
Original file line number Diff line number Diff line change
Expand Up @@ -787,6 +787,10 @@ static int change_cb(sr_session_ctx_t *session, uint32_t sub_id, const char *mod
return SR_ERR_SYS;
}

/* Nudge yangerd to re-poll, best effort: it may not be installed */
if (systemf("initctl -bq reload yangerd"))
DEBUG("yangerd not reloaded, not running?");

AUDIT("The new configuration has been applied.");
}

Expand Down
84 changes: 15 additions & 69 deletions src/confd/src/firewall.c
Original file line number Diff line number Diff line change
Expand Up @@ -106,29 +106,6 @@ static int prefix_parse(const char *str, struct prefix *p)
return -1;
}

static bool prefix_overlap(const char *a, const char *b)
{
struct prefix pa, pb;
int len, i;

if (prefix_parse(a, &pa) || prefix_parse(b, &pb) || pa.af != pb.af)
return false;

len = pa.len < pb.len ? pa.len : pb.len;
for (i = 0; i < len / 8; i++) {
if (pa.addr[i] != pb.addr[i])
return false;
}
if (len % 8) {
uint8_t mask = 0xff << (8 - len % 8);

if ((pa.addr[i] & mask) != (pb.addr[i] & mask))
return false;
}

return true;
}

static bool shadow_has(const char *name, const char *entry)
{
char line[ENTRY_STRLEN];
Expand Down Expand Up @@ -371,47 +348,12 @@ static int generate_zone(struct lyd_node *cfg, const char *name, char **ifaces)
}

/*
* Dynamic entries, added at runtime with the add action, are folded
* into the generated ipset as regular entries so they survive the
* firewalld reload triggered by configuration changes. Entries that
* overlap new static configuration are dropped -- config wins, and
* nftables refuses overlapping elements in interval sets.
* Only static entries go into the generated ipset. Dynamic entries,
* added at runtime with the add action, are re-applied from the shadow
* files by 'firewall reload' after firewalld has reloaded. Baking them
* into the XML would resurrect entries removed while a reload was in
* flight -- the reload is asynchronous to the action handlers.
*/
static void merge_dynamic(FILE *fp, struct lyd_node *cfg, const char *name)
{
char line[ENTRY_STRLEN];
FILE *sf;

sf = fopenf("r", ADDRSET_RUNDIR "/%s", name);
if (!sf)
return;

while (fgets(line, sizeof(line), sf)) {
struct lyd_node *node;
bool skip = false;

chomp(line);
if (!line[0])
continue;

LYX_LIST_FOR_EACH(lyd_child(cfg), node, "entry") {
if (prefix_overlap(line, lyd_get_value(node))) {
skip = true;
break;
}
}

if (skip) {
NOTE("address-set %s: dropping dynamic entry %s, overlaps static entry",
name, line);
continue;
}

fprintf(fp, " <entry>%s</entry>\n", line);
}
fclose(sf);
}

static int generate_ipset(struct lyd_node *cfg, const char *name)
{
const char *family, *timeout, *desc;
Expand Down Expand Up @@ -441,9 +383,6 @@ static int generate_ipset(struct lyd_node *cfg, const char *name)
LYX_LIST_FOR_EACH(lyd_child(cfg), node, "entry")
fprintf(fp, " <entry>%s</entry>\n", lyd_get_value(node));

if (!timeout)
merge_dynamic(fp, cfg, name);

fprintf(fp, "</ipset>\n");

return close_file(fp);
Expand Down Expand Up @@ -745,10 +684,17 @@ int firewall_change(sr_session_ctx_t *session, struct lyd_node *config, struct l
return SR_ERR_OK;
}

/* Drop dynamic state of deleted address-sets */
/*
* Drop dynamic state of deleted address-sets, and of sets
* that got a timeout: their entries expire on their own and
* must not be re-applied on reload.
*/
clist = lydx_get_descendant(diff, "firewall", "address-set", NULL);
LYX_LIST_FOR_EACH(clist, cnode, "address-set") {
if (lydx_get_op(cnode) == LYDX_OP_DELETE)
struct lyd_node *timeout = lydx_get_child(cnode, "timeout");

if (lydx_get_op(cnode) == LYDX_OP_DELETE ||
(timeout && lydx_get_op(timeout) != LYDX_OP_DELETE))
erasef(ADDRSET_RUNDIR "/%s", lydx_get_cattr(cnode, "name"));
}

Expand Down Expand Up @@ -861,7 +807,7 @@ int firewall_change(sr_session_ctx_t *session, struct lyd_node *config, struct l
LYX_LIST_FOR_EACH(clist, cnode, "service")
generate_service(cnode, lydx_get_cattr(cnode, "name"));

/* Regenerate all address-sets, incl. dynamic entries */
/* Regenerate all address-sets (static entries only) */
clist = lydx_get_descendant(tree, "firewall", "address-set", NULL);
LYX_LIST_FOR_EACH(clist, cnode, "address-set")
generate_ipset(cnode, lydx_get_cattr(cnode, "name"));
Expand Down
2 changes: 1 addition & 1 deletion src/statd/Makefile.am
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ DISTCLEANFILES = *~ *.d
ACLOCAL_AMFLAGS = -I m4

sbin_PROGRAMS = statd
statd_SOURCES = statd.c shared.c shared.h journal.c journal_retention.c journal.h avahi.c avahi.h iface.c iface.h
statd_SOURCES = statd.c shared.c shared.h journal.c journal_retention.c journal.h avahi.c avahi.h iface.c iface.h yangerd.c yangerd.h
statd_CPPFLAGS = -D_DEFAULT_SOURCE -D_GNU_SOURCE
statd_CPPFLAGS += -DSTATD_VERSION=\"$(PACKAGE_VERSION)\"
statd_CFLAGS = -W -Wall -Wextra
Expand Down
Loading
Loading