Skip to content

Don't save migrated startup-config, fail-secure hardening - #1672

Merged
mattiaswal merged 7 commits into
mainfrom
migrate-to-running
Sep 30, 2026
Merged

mattiaswal merged 7 commits into
mainfrom
migrate-to-running

Conversation

@troglobit

Copy link
Copy Markdown
Contributor

Description

On upgrade, the migrated startup-config was saved to /cfg, so the old image on the other partition could no longer read it and a fallback also ended up in failure-config.

  • Migrate into running-config only, the file in /cfg is kept until the user saves it. The startup datastore keeps the old version so a save over NETCONF/RESTCONF is not an empty diff, and the WebUI shows unsaved changes
  • After a downgrade, a newer startup-config is tried as-is instead of going straight to failure-config
  • A startup-config that fails to load marks the boot as failed in /mnt/aux and forces a reset, the next boot goes to failure-config from a clean state. Same if loading hangs: the bootstrap event pump is supervised by watchdogd, which resets after 70 s (sysrepo timeout + margin)
  • Login banner, show software and the WebUI software page remind the user to upgrade the other partition when its version differs

Tested in QEMU: migration, newer config after downgrade, broken config (reset + failure-config), hung load (watchdogd supervisor reset).

Checklist

Tick relevant boxes, this PR is-a or has-a:

  • Bugfix
    • Regression tests
    • ChangeLog updates (for next release)
  • Feature
    • YANG model change => revision updated?
    • Regression tests added?
    • ChangeLog updates (for next release)
    • Documentation added?
  • Test changes
    • Checked in changed Readme.adoc (make test-spec)
    • Added new test to group Readme.adoc and yaml file
  • Code style update (formatting, renaming)
  • Refactoring (please detail in commit messages)
  • Build related changes
  • Documentation content changes
    • ChangeLog updated (for major changes)
  • Other (please describe):

@troglobit troglobit linked an issue Sep 29, 2026 that may be closed by this pull request
Comment thread board/common/rootfs/usr/libexec/infix/supervisor
Comment thread src/confd/src/core.c Outdated
A startup-config migrated at boot was saved to /cfg.  The image on the
other partition cannot read the new syntax, so falling back to it after
a failed upgrade also ends up in failure-config.

Load the migrated config into running-config only, and keep the file in
/cfg until the user saves it.  The startup datastore keeps the version
of the file, so saving over NETCONF/RESTCONF is not an empty diff.

Revert to failure-config if the migration fails, instead of loading the
file unmigrated.

Issue #1637

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
After a downgrade, startup-config has a newer version than confd.  The
migrate script refuses such a file, so the unit reverts to
failure-config, even though the file often uses no settings unknown to
the older image.

Load a newer file as-is.  The strict parse rejects any setting this
version does not know.

Issue #1637

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A startup-config that fails to load may leave parts of it applied, and
failure-config is then loaded on top of that.

Mark the boot as failed in /mnt/aux and reset.  The next boot clears the
mark and goes straight to failure-config from a clean state, and a
reboot after that tries startup-config again.  Failure-config is still
applied before the reset, in case the reset does not happen.

Issue #1637

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
After an upgrade, the other partition keeps the old image.  A fallback
to it boots old software, which may not read a startup-config saved by
the new image.

Add a note to the login banner when the other partition has a different
version.

Issue #1637

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Show the login banner note also in 'show software' and on the WebUI
software page, for users who never see the banner.

Issue #1637

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Fixes #1637

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A plugin callback that never returns while loading startup-config hangs
the boot, and the unit never reaches failure-config.

Supervise the bootstrap event pump with watchdogd.  If it misses its
deadline, the supervisor script marks the boot as failed and watchdogd
resets the unit, so the next boot goes straight to failure-config.  The
fail-secure boot itself is not supervised, a hang there would be a reset
loop.

Issue #1637

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
@mattiaswal
mattiaswal self-requested a review September 30, 2026 06:43
@mattiaswal
mattiaswal merged commit 946b1a8 into main Sep 30, 2026
11 checks passed
@mattiaswal
mattiaswal deleted the migrate-to-running branch September 30, 2026 06:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Don't save migrated startup-config

2 participants