Don't save migrated startup-config, fail-secure hardening - #1672
Merged
Merged
Conversation
mattiaswal
reviewed
Sep 29, 2026
mattiaswal
reviewed
Sep 29, 2026
troglobit
force-pushed
the
migrate-to-running
branch
from
September 29, 2026 20:34
340e33e to
726849f
Compare
A startup-config migrated at boot was saved to /cfg. The image on the other partition cannot read the new syntax, so falling back to it after a failed upgrade also ends up in failure-config. Load the migrated config into running-config only, and keep the file in /cfg until the user saves it. The startup datastore keeps the version of the file, so saving over NETCONF/RESTCONF is not an empty diff. Revert to failure-config if the migration fails, instead of loading the file unmigrated. Issue #1637 Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
After a downgrade, startup-config has a newer version than confd. The migrate script refuses such a file, so the unit reverts to failure-config, even though the file often uses no settings unknown to the older image. Load a newer file as-is. The strict parse rejects any setting this version does not know. Issue #1637 Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A startup-config that fails to load may leave parts of it applied, and failure-config is then loaded on top of that. Mark the boot as failed in /mnt/aux and reset. The next boot clears the mark and goes straight to failure-config from a clean state, and a reboot after that tries startup-config again. Failure-config is still applied before the reset, in case the reset does not happen. Issue #1637 Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
After an upgrade, the other partition keeps the old image. A fallback to it boots old software, which may not read a startup-config saved by the new image. Add a note to the login banner when the other partition has a different version. Issue #1637 Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Show the login banner note also in 'show software' and on the WebUI software page, for users who never see the banner. Issue #1637 Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Fixes #1637 Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A plugin callback that never returns while loading startup-config hangs the boot, and the unit never reaches failure-config. Supervise the bootstrap event pump with watchdogd. If it misses its deadline, the supervisor script marks the boot as failed and watchdogd resets the unit, so the next boot goes straight to failure-config. The fail-secure boot itself is not supervised, a hang there would be a reset loop. Issue #1637 Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
troglobit
force-pushed
the
migrate-to-running
branch
from
September 29, 2026 21:22
726849f to
59c3a8d
Compare
mattiaswal
self-requested a review
September 30, 2026 06:43
mattiaswal
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
On upgrade, the migrated
startup-configwas saved to/cfg, so the old image on the other partition could no longer read it and a fallback also ended up infailure-config.running-configonly, the file in/cfgis kept until the user saves it. The startup datastore keeps the old version so a save over NETCONF/RESTCONF is not an empty diff, and the WebUI shows unsaved changesstartup-configis tried as-is instead of going straight tofailure-configstartup-configthat fails to load marks the boot as failed in/mnt/auxand forces a reset, the next boot goes tofailure-configfrom a clean state. Same if loading hangs: the bootstrap event pump is supervised bywatchdogd, which resets after 70 s (sysrepo timeout + margin)show softwareand the WebUI software page remind the user to upgrade the other partition when its version differsTested in QEMU: migration, newer config after downgrade, broken config (reset +
failure-config), hung load (watchdogdsupervisor reset).Checklist
Tick relevant boxes, this PR is-a or has-a: