2
0
Commit Graph

492 Commits

Author SHA1 Message Date
Peter Collingbourne 83e7c6f2dc Move extraRules to the end of the recursiveUpdate
extraRules is the user-specified ruleset so this allows the
user configuration to override the builtin rules.
2026-05-03 04:02:31 -07:00
Peter Collingbourne 16fb3f5343 Remove iptables modules
With Linux 6.12, some of the iptables modules are no longer directly
selectable, leading to a failure to build the module loader. We don't
need them anyway as we use nftables, so remove them.
2026-04-26 11:58:17 +01:00
dan 0b179a6e04 force create ca-certificate symlink 2026-03-22 15:22:56 +00:00
dan 9f3c8f7cbd treewide: nixfmt and deadnix 2025-11-11 21:49:45 +00:00
dan 9784e90d1f bridge: remove obsolete workaround
we no longer need to remove ipv6 routes from member interfaces when
adding to the bridge, because there will no longer be any ipv6 routes
on the member interfaces
2025-11-11 21:49:01 +00:00
dan 18193bf765 add dhcp6 client to wap profile 2025-11-11 21:49:01 +00:00
dan 9f21c3036f dnsmasq: set ipv6 autoconfig in "router" mode
dnsmasq is configured to send RA, so the interface it's running on
should not also be accepting RA.
2025-11-11 21:49:01 +00:00
dan 40194d5351 enable ipv6 autoconfig when dhcp6c is specified
DHCP6 and autoconfig work in tandem not in opposition! dhcp6 does not
provide a default gateway: it depends on router solicitation/router
adverts for that

Tl;dr the network/site admin will ensure that router adverts are being
sent periodically. The adverts will have either Autonomous or Managed
bits set and that is what tells the host to use SLAAC or to use DHCP6
2025-11-11 21:49:01 +00:00
dan ff7aaec874 disable ipv6 autoconfig when bringing links up 2025-11-11 21:44:38 +00:00
dan 9bb2d4d4fb remove commented code 2025-11-11 21:44:38 +00:00
dan 53ec331e29 attempt disabling ipv6 autoconfiguration at boot
This dosn't work as well as you might think if you didn't know that
the config semantics are weird. By setting 'default' we disable
autoconfig on interfaces that do not yet exist, but setting 'all' here
has no effect.
2025-11-11 21:44:38 +00:00
dan d538e8f6cf add options for setting sysctl parameters at boot time 2025-11-11 21:44:37 +00:00
dan e49f8055f3 add etc/hosts to base module
this is hardcoded to localhost only.  it would be better to have
a config option to allow defining static hosts
2025-11-11 21:44:37 +00:00
dan 7261ef8b21 DHCPNAK means we can't use the requested address
so probably we should flush it
2025-11-11 21:44:37 +00:00
dan 489d1843b5 no action needed for dhcp renewal message
... according to my reading, a renewal is always for the same
address we have already
2025-11-11 21:44:37 +00:00
dan 78e4d30120 dhcp4 client: start controlled service when lease acquired
it is problematic to have dhcp signal readiness when a lease is
acquired, because it holds the s6 service lock while it's waiting
and that can lead to deadlock. Instead, start the dhcp client
"daemon" process and monitor its outputs, bringing up and down
a controlled "dhcp lease acquired" service that other services
(e.g. ntp, or resolvconf, or ...) can declare as a dependency
2025-11-04 00:24:39 +00:00
dan bb2c36a0b4 prefer modules/dhcp4c over system.services.network.dhcp.client 2025-11-03 23:51:52 +00:00
dan c5e0567511 bridge: flush ipv6 routes via member interfaces
Adding an interface as a bridge member does not (by itself) remove the
routes which go via that interface, whioch makes them basically into
null routes. This isn't a problem for IPv4 because there were no
addresses anyway, but interfaces can acquire IPv6 addresses via
autodiscovery before they get added to the bridde

Possibly it would be better to disable autodiscovery on these
interfaces. More thought needed.
2025-11-03 22:01:35 +00:00
dan a3c4ebbe29 dhcpc touch outputs/state
this is important for service subscribers to see the change event
2025-11-03 19:12:58 +00:00
dan 5da61c6d31 bundles depend on controlled services if any of their contents do 2025-11-03 19:12:07 +00:00
dan d3b99aba96 remove unneeded comma 2025-11-01 11:35:55 +00:00
dan 574c95640b remove dhcpc readiness notification
because there's an ugly deadlock. s6-rc won't start anything else
while waiting for int.link.dhcpc to announce it's ready, and the
-running service needs to call s6-rc to launch the scripts that add
members to the bridge. dhcpc won't work until the bridge has a member
2025-10-31 21:46:21 +00:00
dan 19360eca57 remove ifwait service name clash opportunity 2025-10-31 21:45:01 +00:00
dan 5c4004e1b8 add readiness support for ntp 2025-10-29 21:16:49 +00:00
dan 8106389b74 add log backfill services 2025-10-27 21:19:43 +00:00
dan c29416a287 move log fifo away from /run/log which doesn't exist yet 2025-10-27 21:16:17 +00:00
dan 9e042bd385 ppp: ignore error return from writing readiness notification
ip-up and ipv6-up both attempt to write to fd 10, but only the
first writer will succeed because the peer closes the pipe as soon
as it gets anything. I can't see a way to make this race-proof, so
... here we are
2025-10-27 21:12:06 +00:00
dan 6478c56ed1 log.shipping.command is now a command not a string 2025-10-25 17:34:50 +01:00
dan 186543d2de remove option for log shipping socket
* it's a fifo now not a socket
* I think it's an internal detail, not public interface
* backfill will need a second fifo anyway
2025-10-24 23:53:46 +01:00
dan c8b3188bd4 remove unneeded module 2025-10-24 23:46:13 +01:00
dan bfb4799075 certifix-client provice ca-certificate as an output 2025-10-20 23:47:21 +01:00
dan 87c45dec67 switch certifix-client to luahttp 2025-10-19 14:11:51 +01:00
dan a6442c872f change log shipper interface
* it's now a command not a service
* shipper is expected to open() the fifo passed as $LOG_FIFO instead of
  getting logs on stdin

logtap determines that remote logs are getting sent when there's a
reader on the fifo it's writing, but opening the fifo as stdin of
s6-tcpclient is too early as it hasn't even connected to the remote
log server at that time
2025-10-09 21:38:49 +01:00
dan 71aed767f2 switch logtap to use fifo unstead of af_unix 2025-10-08 20:10:11 +01:00
dan a343e63231 rename logshipper -> logtap
- it matches the executable name
- it doesn't ship anything anyway, it's just plumbing
2025-10-08 20:10:11 +01:00
dan cacde953cb don't ask chrony to drop privs, it needs libpcap 2025-10-08 20:10:11 +01:00
dan 7e6a59631a firewall needs the secrets subscriber 2025-08-12 20:07:39 +01:00
dan f728b584a2 add "nobody" user needed by rp-pppoe 2025-04-14 21:27:44 +01:00
dan 210b41efc0 improve robustness of ppp readiness notification
there was a race where ip-up could write ifname and then
ip6-up could write its outputs and then test ifname and
signal ready before ip-up had written the rest of its outputs
2025-03-31 23:17:50 +01:00
dan 53c6d506cf dhcp6c subscribe to ppp ifindex
when the peer bounces ppp, s6 will restart the ppp process but not
restart the dependent services (because the service isn't considered
to have gone down)

so the dependent services need to notice when the outputs from ppp
have changed
2025-03-31 23:15:28 +01:00
dan 01fe2159b4 ppp: write ifindex as output
because what happens if the service is restarted but the new ppp0 is
a different interface than the old one so that services which had
bound to it with the old name are now not getting new data

(I am not 100% that this actually happens but it seems like it would
be good to avoid it if it does)
2025-03-31 23:11:30 +01:00
dan d7d19b5ed0 dhcp6 client: fix service dir in address and prefix acquirers
the scripts now expect the actual service dir instead of the .outputs
subdir
2025-03-31 23:06:40 +01:00
dan ee683f2202 firewall: fix syntax of icmp v4 rule 2025-03-31 23:03:24 +01:00
dan d9723aeb87 secrets subscriber: make restart-all work 2025-03-31 23:01:48 +01:00
dan 46ed8f0199 add bandwidth as a service option for ppp (l2tp, pppoe) 2025-03-27 20:23:26 +00:00
dan dd44fbaec1 rate limit for v4 icmp 2025-03-27 20:21:48 +00:00
dan 89065be6cd bandwidth is bits/second so divide by 8 2025-03-27 20:21:14 +00:00
dan 420320e434 firewall: remove unused args/names/vars 2025-03-27 18:40:07 +00:00
dan 1a6160bcab firewall: show how to ratelimit icmp6 to 5% of available bandwidth
it's a little klunky as yet, requires setting properties.bandwidth on
the interface service
2025-03-25 23:53:02 +00:00
dan e5cfd41013 add nft_limit kmodule for rate limiting in firewall 2025-03-21 21:19:48 +00:00