2
0
Commit Graph

1674 Commits

Author SHA1 Message Date
Peter Collingbourne 83e7c6f2dc Move extraRules to the end of the recursiveUpdate
extraRules is the user-specified ruleset so this allows the
user configuration to override the builtin rules.
2026-05-03 04:02:31 -07:00
dan d0376d4101 add configuration for gateway test
it can't share the rotuer example as rotuer's secrets aren't
checked into git
2026-04-29 13:23:18 +01:00
dan 5f2abc0d2b test that rotuer example builds
there is no test in CI that builds the firewall or any of those
modules, so this is temporary-ish to increase coverage
2026-04-26 18:10:56 +01:00
Peter Collingbourne c03d50235a Move openwrt-one TFTP load address after reserved-memory regions
I was seeing random filesystem corruption when booting larger images
over TFTP, and it turned out to be caused by the image being loaded
on top of some reserved-memory regions (see link below).

https://github.com/torvalds/linux/blob/897d54018cc9aa97fd1529ca08a53b429d05a566/arch/arm64/boot/dts/mediatek/mt7981b.dtsi#L72
2026-04-26 12:57:53 +01:00
dan f1277b0564 make elfutils build 2026-04-26 12:33:32 +01:00
Peter Collingbourne 16fb3f5343 Remove iptables modules
With Linux 6.12, some of the iptables modules are no longer directly
selectable, leading to a failure to build the module loader. We don't
need them anyway as we use nftables, so remove them.
2026-04-26 11:58:17 +01:00
dan 9c62e8333d think 2026-04-26 11:57:06 +01:00
dan dc62a8b75f disaable util-linux lastlog support as it depends on PAM 2026-03-30 14:03:02 +01:00
dan 7f6b05ef96 switch from mainline ag71xx driver to openwrt version 2026-03-30 13:35:19 +01:00
dan 4299293cc5 backport OF "compatible" changes for ath79 2026-03-28 21:17:55 +00:00
dan b6b420bc5b gl-ar750 upgrade ath10k firmware 2026-03-28 21:17:08 +00:00
dan 5af28615f1 gl-ar750: update to newer kernel + openwrt
this device is not (yet?) in mainline, but openwrt 25.12 has
the right patches to make it work with linux 6.12
2026-03-28 21:15:51 +00:00
dan e8a60d2860 bordervm switch usb passthru from ehci to xhci
this was to fix a bug that turned out to be something else,
but the qemu docs say it's better anyway
2026-03-22 15:23:50 +00:00
dan 82164d3968 think 2026-03-22 15:23:19 +00:00
dan 0b179a6e04 force create ca-certificate symlink 2026-03-22 15:22:56 +00:00
dan 29d51396f5 s6-rc-up-tree doesn't need runtime fennel 2026-03-18 21:09:55 +00:00
dan 5f92529f4f odhcp6c: upgrade to newer (but not new) upstream
* we need new enough for cmake 3
* but not so new it depends on libubox

This is a "get it working again" patch, not a long-term solution.
Either we should add libubox to liminix or we should find another
dhcp6 client
2026-03-18 21:07:49 +00:00
dan a1d7c49e22 luaossl: remove .orig file after patching
*something* tries to patch src/openssl.c again in the install phase
(I haven't figured out what) and dies because it can't make
src/openssl.c.orig if it exists already.
2026-03-18 21:06:19 +00:00
dan 7f23c5dc0f update dropbear, simplify authorized_keys patch 2026-03-11 18:22:39 +00:00
dan c364095c44 build our own fennel
final.lua53Packages.fennel seems somehow to drag in glibc
2026-03-11 07:45:00 +00:00
dan ef07dcc10a bump ubifs max leb count 2026-03-11 07:38:00 +00:00
dan 4b40e51a1d run-liminix-vm tell qemu not to reboot when guest terminates 2026-03-11 07:30:00 +00:00
dan 9fef673ca0 remove ci.nix "all" attribute
use ci-all.nix instead if you want to do all the jobs
2026-03-09 12:01:19 +00:00
dan 7b1324208b note nixpkgs version reqt 2026-03-09 11:42:38 +00:00
dan cab0d7a805 update ppp package 2026-03-09 11:12:40 +00:00
dan 41375681dd hash for firmwre-utils 2026-03-09 11:12:27 +00:00
dan dd3629ae8e update firmware-utils for compatibility with newer cmake 2026-03-08 01:08:50 +00:00
dan 3026eaf879 copy airoha firmware recursively 2026-03-08 00:28:45 +00:00
dan 48022da733 nixpkgs fennel moved into luaPackages 2026-03-07 23:03:43 +00:00
dan 9596a7eccf chrony doesn't use texinfo any loger 2026-03-07 22:28:33 +00:00
dan f15ffaeac2 kludge: force gcc 13 for kernel builds
we can get rid of this when we upgrade devices from kernel 5.x to 6.x
(which clearly we also need to do)
2026-03-07 22:27:12 +00:00
dan 9f3c8f7cbd treewide: nixfmt and deadnix 2025-11-11 21:49:45 +00:00
dan 9784e90d1f bridge: remove obsolete workaround
we no longer need to remove ipv6 routes from member interfaces when
adding to the bridge, because there will no longer be any ipv6 routes
on the member interfaces
2025-11-11 21:49:01 +00:00
dan 18193bf765 add dhcp6 client to wap profile 2025-11-11 21:49:01 +00:00
dan 9f21c3036f dnsmasq: set ipv6 autoconfig in "router" mode
dnsmasq is configured to send RA, so the interface it's running on
should not also be accepting RA.
2025-11-11 21:49:01 +00:00
dan 40194d5351 enable ipv6 autoconfig when dhcp6c is specified
DHCP6 and autoconfig work in tandem not in opposition! dhcp6 does not
provide a default gateway: it depends on router solicitation/router
adverts for that

Tl;dr the network/site admin will ensure that router adverts are being
sent periodically. The adverts will have either Autonomous or Managed
bits set and that is what tells the host to use SLAAC or to use DHCP6
2025-11-11 21:49:01 +00:00
dan ff7aaec874 disable ipv6 autoconfig when bringing links up 2025-11-11 21:44:38 +00:00
dan 9bb2d4d4fb remove commented code 2025-11-11 21:44:38 +00:00
dan 53ec331e29 attempt disabling ipv6 autoconfiguration at boot
This dosn't work as well as you might think if you didn't know that
the config semantics are weird. By setting 'default' we disable
autoconfig on interfaces that do not yet exist, but setting 'all' here
has no effect.
2025-11-11 21:44:38 +00:00
dan d538e8f6cf add options for setting sysctl parameters at boot time 2025-11-11 21:44:37 +00:00
dan 8646677ead think 2025-11-11 21:44:37 +00:00
dan bedc1009f8 whitespace 2025-11-11 21:44:37 +00:00
dan 4abdbeb1ea fix reference to dhcp client in tutorial 2025-11-11 21:44:37 +00:00
dan e5c036f100 fix bad relative path 2025-11-11 21:44:37 +00:00
dan e49f8055f3 add etc/hosts to base module
this is hardcoded to localhost only.  it would be better to have
a config option to allow defining static hosts
2025-11-11 21:44:37 +00:00
dan 7261ef8b21 DHCPNAK means we can't use the requested address
so probably we should flush it
2025-11-11 21:44:37 +00:00
dan 489d1843b5 no action needed for dhcp renewal message
... according to my reading, a renewal is always for the same
address we have already
2025-11-11 21:44:37 +00:00
dan bf7d02ae85 note dhcp client rename 2025-11-11 21:44:37 +00:00
dan d9f91e4820 update examples for dhcp4c rename 2025-11-11 21:44:37 +00:00
dan 46dcf71e16 fix swconfig build
missing ctype.h
2025-11-04 18:53:38 +00:00