Commit Graph
100 Commits
Author SHA1 Message Date
Daniel Barlow e4aad311a8 think 2025-04-02 21:09:13 +01:00
Daniel Barlow 6674826990 think 2025-04-02 21:08:49 +01:00
Daniel Barlow 97ff2f3009 think 2025-03-31 23:22:04 +01:00
Daniel Barlow 210b41efc0 improve robustness of ppp readiness notification
there was a race where ip-up could write ifname and then
ip6-up could write its outputs and then test ifname and
signal ready before ip-up had written the rest of its outputs
2025-03-31 23:17:50 +01:00
Daniel Barlow 53c6d506cf dhcp6c subscribe to ppp ifindex
when the peer bounces ppp, s6 will restart the ppp process but not
restart the dependent services (because the service isn't considered
to have gone down)

so the dependent services need to notice when the outputs from ppp
have changed
2025-03-31 23:15:28 +01:00
Daniel Barlow 01fe2159b4 ppp: write ifindex as output
because what happens if the service is restarted but the new ppp0 is
a different interface than the old one so that services which had
bound to it with the old name are now not getting new data

(I am not 100% that this actually happens but it seems like it would
be good to avoid it if it does)
2025-03-31 23:11:30 +01:00
Daniel Barlow d7d19b5ed0 dhcp6 client: fix service dir in address and prefix acquirers
the scripts now expect the actual service dir instead of the .outputs
subdir
2025-03-31 23:06:40 +01:00
Daniel Barlow ee683f2202 firewall: fix syntax of icmp v4 rule 2025-03-31 23:03:24 +01:00
Daniel Barlow d9723aeb87 secrets subscriber: make restart-all work 2025-03-31 23:01:48 +01:00
Daniel Barlow 46ed8f0199 add bandwidth as a service option for ppp (l2tp, pppoe) 2025-03-27 20:23:26 +00:00
Daniel Barlow dd44fbaec1 rate limit for v4 icmp 2025-03-27 20:21:48 +00:00
Daniel Barlow 89065be6cd bandwidth is bits/second so divide by 8 2025-03-27 20:21:14 +00:00
Daniel Barlow 420320e434 firewall: remove unused args/names/vars 2025-03-27 18:40:07 +00:00
Daniel Barlow 9ecd2b4fb4 think 2025-03-25 23:55:00 +00:00
Daniel Barlow 1a6160bcab firewall: show how to ratelimit icmp6 to 5% of available bandwidth
it's a little klunky as yet, requires setting properties.bandwidth on
the interface service
2025-03-25 23:53:02 +00:00
Daniel Barlow b1bf13bb01 add svc:directory, mostly for use in debugging messages 2025-03-25 23:47:01 +00:00
Daniel Barlow c3f550698d watch-outputs fix update logic
it was only working by accident, when it worked, which was by no
means all of the time

note that we unconditionally perform the action (restart or whatever)
once we've started and got the initial state of the outputs. That's
because we have no idea whether the outputs changed in the interval
between the controlled service initially starting and watch-outputs
starting, so updates in that interval could be lost
2025-03-25 23:44:21 +00:00
Daniel Barlow 05991225de anoia.svc allow open of a service that is not yet running
we change the inotify watcher so that it attempts to monitor
/run/service as well as /run/service/foo. If foo doesn't yet exist
then that call to addwatch fails, so we need to be looking at the
parent if we are to be told when foo gets created
2025-03-25 23:37:58 +00:00
Daniel Barlow 7ce1c6bb7d add realpath to lualinux 2025-03-24 22:39:59 +00:00
Daniel Barlow 8440378a39 anoia: make dirname handle tralning / like posix 2025-03-24 22:37:24 +00:00
Daniel Barlow e5cfd41013 add nft_limit kmodule for rate limiting in firewall 2025-03-21 21:19:48 +00:00
Daniel Barlow 0ae5689a40 support maps in firewallgen 2025-03-21 21:19:18 +00:00
Daniel Barlow 45047dc023 squahs falls back 2025-03-21 21:09:05 +00:00
Daniel Barlow 3673804b93 think 2025-03-21 21:08:17 +00:00
Daniel Barlow be03e9e8c8 service outputs falls back to properties (untested) 2025-03-18 18:38:04 +00:00
Daniel Barlow 4e51977ae0 provide properties attr to services
properties are similar to outputs, but are different in that they are
fixed values (do not change) and are present even when the service is
down

if the attribute is present and an attrset, this will write the
equivalent recursive directory structure to $out/.properties/
2025-03-12 23:35:56 +00:00
Daniel Barlow 2b0972ed73 svc.open accepts a /nix/store folder not an outputs folder
this mostly makes things simpler
2025-03-11 00:21:44 +00:00
Daniel Barlow f22237a3b3 doc: filter src attribute to not rebuild as much 2025-03-10 23:08:37 +00:00
Daniel Barlow 9dc0f25587 min-copy-clocure test: ensure sshd up before starting
this test goes wrong intermittently in CI, see if this makes it more
reliable
2025-03-09 21:37:13 +00:00
Daniel Barlow 9ab77a7d7e remove unused function 2025-03-09 20:44:35 +00:00
Daniel Barlow c6918fec00 firewall: use extraText for zone set contents
* the lua necessary is quite wordy, but it's less of a hack than
post-processing the rules file with pseudo-sed to get rid of `elements
= { }` lines

* also switch from stop/starting the firewall service to using a
signal, so that we don't go briefly offline every time a new interface
appears
2025-03-09 20:42:02 +00:00
Daniel Barlow d4e46dbe28 secrets/subscriber don't depend on the services we're watching
this means a watched service can stop and start without killing
the subscriber, and that we can watch for services that don't
yet exist
2025-03-09 20:35:40 +00:00
Daniel Barlow d1f87a56e0 secrets/subscriber: use correct numbers for signals to s6-svc 2025-03-09 20:34:29 +00:00
Daniel Barlow 8c39b47cae output-template: allow splicing statements instead of expression
if the text inside the delimiters begins with ; (a semicolon) then
the rest of it is expected to be one or more Lua statements. It needs
to say `return "foo"` to interpolate anything, as there is no
implicit return of the value of the last statement
2025-03-05 22:38:48 +00:00
Daniel Barlow 2c7a16d792 firewallgen: add extraText param to set
anything in here is added verbatim to the set definition
2025-03-05 22:36:35 +00:00
Daniel Barlow d6b06abb63 delet second copy of output-template 2025-03-02 21:34:02 +00:00
Daniel Barlow 6b32aa569e think 2025-03-02 21:21:45 +00:00
Daniel Barlow 234d1bd87e basic unit tests for output-template 2025-03-02 21:14:46 +00:00
Daniel Barlow c38f180fb7 output-template expose table module 2025-03-02 21:14:16 +00:00
Daniel Barlow 9a8b22997c output-template: pass the tests 2025-03-02 21:09:32 +00:00
Daniel Barlow c32d09bd83 output-template: run the tests 2025-03-02 21:09:11 +00:00
Daniel Barlow 6649ebeccd firewall: use watch-outputs to track changes in zone->interface map
includes a horrible hack to work around (claimed (by me)) deficiencies
in the nftables parser
2025-02-28 00:43:20 +00:00
Daniel Barlow 929226ed9e delete commented code 2025-02-27 20:55:30 +00:00
Daniel Barlow a98f026210 think 2025-02-27 20:54:44 +00:00
Daniel Barlow f4dc001b71 check firewall zones in pppoe test 2025-02-25 23:32:05 +00:00
Daniel Barlow 024c018262 run the output-template test 2025-02-22 00:10:19 +00:00
Daniel Barlow e1293e3778 think 2025-02-21 23:22:39 +00:00
Daniel Barlow 0c406058e9 remove acceotance of udp sport 5 on wan
this was added for replies to dns queries but isn't needed for
that purpose as connection tracking does that anyway
2025-02-12 21:54:01 +00:00
Daniel Barlow 19d441333c remove duplicate rule 2025-02-10 23:50:07 +00:00
Daniel Barlow a726c09ae4 improve explanaton of reverse path filtering rule
thanks RoS for the references :-)
2025-02-10 23:48:29 +00:00
Daniel Barlow 7e2b0068e6 nixfmt-rfc-style
There is nothing in this commit except for the changes made by
nix-shell -p nixfmt-rfc-style --run "nixfmt ."

If this has mucked up your open branches then sorry about that. You
can probably nixfmt them to match before merging
2025-02-10 21:55:08 +00:00
dan 13cc5a8992 Merge pull request 'support firewall zones: don't hardcode interface names in rules' (#16) from firescape into main
Reviewed-on: https://gti.telent.net/dan/liminix/pulls/16
2025-02-10 21:23:15 +00:00
Daniel Barlow 3f889c7119 default firewall zones in gateway profile 2025-02-10 21:21:08 +00:00
Daniel Barlow 7f17125039 firewall: update zones with interface names as they appear 2025-02-10 21:21:08 +00:00
Daniel Barlow 4bb081ffcf export anoia.svc:fileno so it can be used with event loops 2025-02-10 21:21:08 +00:00
Daniel Barlow 6587813577 WIP add zones to firewall module
- zones are an attrset of name -> [interface-service]

- the firewall will create empty "ifname" sets for each zone name
 in each address family (ip, ip6)

- then watch the interface services, and add the "ifname" outputs
to the corresponding sets when they appear

This commit only adds the empty sets
2025-02-10 21:21:08 +00:00
Daniel Barlow 1d780de0f1 add (very basic) set support in firewallgen
and add sets for lan/wan/dmz/guest interface names to default
firewall rules
2025-02-10 21:17:43 +00:00
Daniel Barlow 8cf602da91 think 2025-02-10 21:17:43 +00:00
Daniel Barlow c92aacc6fd firewall rules: use @lan and @wan sets instead of ifnames
we don't have anything yet to create or populate the sets
2025-02-06 09:22:41 +00:00
Daniel Barlow eff255fe12 boot.expect: sleep more, for gl-ar750
the bootloader on gl-ar750 loses characters if we shovel them too fast
2025-02-05 20:35:04 +00:00
Daniel Barlow 453baede61 rt3200: add installer compatibility note 2025-02-05 20:35:04 +00:00
dan 2295ed3110 Merge pull request 'OpenWrt One device support' (#13) from raboof/liminix:openwrt-one into main
Reviewed-on: https://gti.telent.net/dan/liminix/pulls/13
2025-01-08 13:57:39 +00:00
Daniel Barlow f77da6f14c remove remaining refs to kexecboot 2025-01-05 17:22:30 +00:00
Daniel Barlow 61eaaa82eb drivel 2025-01-05 17:17:44 +00:00
Daniel Barlow 95dd1a1fab add missing code-block 2025-01-05 15:45:04 +00:00
Daniel Barlow 2f9b0f12f9 switch uid 2025-01-05 12:57:51 +00:00
Daniel Barlow 9fd9b8b878 rt3200 kconfig for 6.6.x
* DMA stuff needed for wired ethernet

* DSA MDIO _probably_ (based on guessing from openwrt dmesg) needed
for wired ethernet

* some or all of NVMEM so that wireless drivers can read their eeprom
2025-01-05 00:16:03 +00:00
Daniel BarlowandArnout Engelen 26f206d0e1 phram dtb reserved-memory needs no-map
c.f. https://gti.telent.net/dan/liminix/commit/69429404abaf365ed649a2863830c1909f3626b2

Co-authored-by: Arnout Engelen <arnout@bzzt.net>
2025-01-04 23:50:44 +00:00
Daniel Barlow 8cd068ea68 belkin rt3200: set tftp loadAddress to match u-boot
the old value of 0x4007ff28 was originally copied from something
upstreamy but I have no record of what. 0x48000000 is $loadaddr
in u-boot so let's use that instead
2025-01-04 23:48:19 +00:00
Daniel Barlow 350ddde260 add pkgs.openwrt_24_10
is needed by Belkin RT3200 and might also be handy for OpenWrt One?

this is very copy-pastey, will tidy it up after it
stops being a moving target
2025-01-03 23:52:08 +00:00
Daniel Barlow 13cb8d3692 sort imports 2025-01-03 15:41:22 +00:00
Daniel Barlow 62b7aea8ab add btrfs.nix to outputs imports 2025-01-03 15:40:33 +00:00
Daniel Barlow 76e3fd9a55 add rt3200 to CI 2025-01-03 15:39:08 +00:00
Daniel Barlow 92284fa9ba mtdimage can't be a default import
it adds kernel config that depend on openwrt patches,
which aren't used/needed on all devices
2025-01-03 00:19:17 +00:00
Daniel Barlow a2bb55e885 oops fix syntax error 2025-01-03 00:07:00 +00:00
Daniel Barlow 74027b44d7 extract log persistence config from s6 to new module
because it frobs kernel config, it breaks levitate
as levitate evalModules doesn't include the kernel
2025-01-02 23:56:49 +00:00
Daniel Barlow ea5370b3f4 import mtdimage in outputs 2025-01-02 23:37:07 +00:00
Daniel Barlow 55ed365920 turris omnia: default rootfs and bootloader settings 2025-01-02 23:36:15 +00:00
Daniel Barlow aa2160dd05 logtap: fix indentation
spaces not tabs
2025-01-02 22:45:00 +00:00
Daniel Barlow df414b796f drivel 2025-01-02 22:19:49 +00:00
Daniel Barlow 7377f7ceb2 implement mechanism for reverting from update.sh 2025-01-02 22:19:49 +00:00
dan 49432aeda5 Merge pull request 'Fix typo: Buildiing -> Building' (#15) from raboof/liminix:typo into main
Reviewed-on: https://gti.telent.net/dan/liminix/pulls/15
Reviewed-by: dan <dan@telent.net>
2025-01-02 14:46:36 +00:00
Daniel Barlow cc94ef57fa in rc.init copy log from previous boot to place of safety 2025-01-01 18:22:45 +00:00
Daniel Barlow fd28f0ce04 rt3200 needs pmsg-size set in its dts for persistent logging 2025-01-01 14:11:22 +00:00
Daniel Barlow 497307588f automate ubimage instructions a little 2025-01-01 12:38:08 +00:00
Daniel Barlow 788169586f /boot is a directory, copy files instead of replacing it with symlink
for the record, u-boot doesn't like having /boot/fit -> ../nix/store/..../fit
symlinks so we don't use symlinks inside /boot either
2025-01-01 12:29:25 +00:00
Daniel Barlow 3af9e86624 rt3200: replace bootcmd variable
the default is to boot to recovery if there's anything in pstore, but
this doesn't interact well with persstent logging
2025-01-01 11:56:54 +00:00
Daniel Barlow 28d39cd66d provide etc/kconfig in updater output
this is for debugging/documentation purposes and isn't copied to the
device
2025-01-01 11:55:33 +00:00
Daniel Barlow 9dd169d500 add "config" output to kernel derivation 2025-01-01 11:54:46 +00:00
Daniel Barlow 2e513eb4a7 example sni proxy using nginx 2024-12-29 23:34:15 +00:00
Daniel Barlow f2e4e77d73 firewall: don't use oifname in input rules
because it's empty, these are input rules for the local machine
2024-12-29 23:17:31 +00:00
Daniel Barlow 48dfbe0c01 add nginx-small : nginx with finegrained configure options 2024-12-29 20:47:03 +00:00
Daniel Barlow 6f697db57c remove PSTORE from rt3200 default kconfig
we have config.logging.persistent.enable at home
2024-12-29 13:33:55 +00:00
Daniel Barlow fe1ee12e3d swap strchr for strchrnul in dropbear authkeyfile patch
The strchrnul version was giving weird crashes on aarch64
belkin-rt3200. I haven't figured out why but this one doesn't
2024-12-29 13:30:21 +00:00
Daniel Barlow 4d273a9469 dropbear would like /etc/shells to exist 2024-12-29 13:27:49 +00:00
Daniel Barlow 40db175b41 complain if user attempting to tftpboot a ubifs 2024-12-29 13:26:45 +00:00
Daniel Barlow ab07212a7e include jffs2 module per default
it has no effect unless enabled
2024-12-29 13:26:06 +00:00
Daniel Barlow f5e08ac9d9 rt3200 default to loader.fit 2024-12-29 13:25:26 +00:00
Daniel Barlow 0cb18eabcd boot.expect: improve reliability
don't depend on seeing u-boot prompt, it's just too easy to get
out of sync
2024-12-27 18:08:01 +00:00
Daniel Barlow 24151425b8 and fix quoting 2024-12-24 14:29:01 +00:00