dan
3f889c7119
default firewall zones in gateway profile
2025-02-10 21:21:08 +00:00
dan
7f17125039
firewall: update zones with interface names as they appear
2025-02-10 21:21:08 +00:00
dan
4bb081ffcf
export anoia.svc:fileno so it can be used with event loops
2025-02-10 21:21:08 +00:00
dan
6587813577
WIP add zones to firewall module
...
- zones are an attrset of name -> [interface-service]
- the firewall will create empty "ifname" sets for each zone name
in each address family (ip, ip6)
- then watch the interface services, and add the "ifname" outputs
to the corresponding sets when they appear
This commit only adds the empty sets
2025-02-10 21:21:08 +00:00
dan
1d780de0f1
add (very basic) set support in firewallgen
...
and add sets for lan/wan/dmz/guest interface names to default
firewall rules
2025-02-10 21:17:43 +00:00
dan
8cf602da91
think
2025-02-10 21:17:43 +00:00
dan
c92aacc6fd
firewall rules: use @lan and @wan sets instead of ifnames
...
we don't have anything yet to create or populate the sets
2025-02-06 09:22:41 +00:00
dan
eff255fe12
boot.expect: sleep more, for gl-ar750
...
the bootloader on gl-ar750 loses characters if we shovel them too fast
2025-02-05 20:35:04 +00:00
dan
453baede61
rt3200: add installer compatibility note
2025-02-05 20:35:04 +00:00
dan
2295ed3110
Merge pull request 'OpenWrt One device support' ( #13 ) from raboof/liminix:openwrt-one into main
...
Reviewed-on: dan/liminix#13
2025-01-08 13:57:39 +00:00
Arnout Engelen
e71d92eb3d
OpenWrt One support
...
https://openwrt.org/toh/openwrt/one
2025-01-07 16:10:04 +01:00
dan
f77da6f14c
remove remaining refs to kexecboot
2025-01-05 17:22:30 +00:00
dan
61eaaa82eb
drivel
2025-01-05 17:17:44 +00:00
dan
95dd1a1fab
add missing code-block
2025-01-05 15:45:04 +00:00
dan
2f9b0f12f9
switch uid
2025-01-05 12:57:51 +00:00
dan
9fd9b8b878
rt3200 kconfig for 6.6.x
...
* DMA stuff needed for wired ethernet
* DSA MDIO _probably_ (based on guessing from openwrt dmesg) needed
for wired ethernet
* some or all of NVMEM so that wireless drivers can read their eeprom
2025-01-05 00:16:03 +00:00
dan
26f206d0e1
phram dtb reserved-memory needs no-map
...
c.f. 69429404ab
Co-authored-by: Arnout Engelen <arnout@bzzt.net >
2025-01-04 23:50:44 +00:00
dan
8cd068ea68
belkin rt3200: set tftp loadAddress to match u-boot
...
the old value of 0x4007ff28 was originally copied from something
upstreamy but I have no record of what. 0x48000000 is $loadaddr
in u-boot so let's use that instead
2025-01-04 23:48:19 +00:00
dan
350ddde260
add pkgs.openwrt_24_10
...
is needed by Belkin RT3200 and might also be handy for OpenWrt One?
this is very copy-pastey, will tidy it up after it
stops being a moving target
2025-01-03 23:52:08 +00:00
dan
13cb8d3692
sort imports
2025-01-03 15:41:22 +00:00
dan
62b7aea8ab
add btrfs.nix to outputs imports
2025-01-03 15:40:33 +00:00
dan
76e3fd9a55
add rt3200 to CI
2025-01-03 15:39:08 +00:00
dan
92284fa9ba
mtdimage can't be a default import
...
it adds kernel config that depend on openwrt patches,
which aren't used/needed on all devices
2025-01-03 00:19:17 +00:00
dan
a2bb55e885
oops fix syntax error
2025-01-03 00:07:00 +00:00
dan
74027b44d7
extract log persistence config from s6 to new module
...
because it frobs kernel config, it breaks levitate
as levitate evalModules doesn't include the kernel
2025-01-02 23:56:49 +00:00
dan
ea5370b3f4
import mtdimage in outputs
2025-01-02 23:37:07 +00:00
dan
55ed365920
turris omnia: default rootfs and bootloader settings
2025-01-02 23:36:15 +00:00
dan
aa2160dd05
logtap: fix indentation
...
spaces not tabs
2025-01-02 22:45:00 +00:00
dan
df414b796f
drivel
2025-01-02 22:19:49 +00:00
dan
7377f7ceb2
implement mechanism for reverting from update.sh
2025-01-02 22:19:49 +00:00
dan
49432aeda5
Merge pull request 'Fix typo: Buildiing -> Building' ( #15 ) from raboof/liminix:typo into main
...
Reviewed-on: dan/liminix#15
Reviewed-by: dan <dan@telent.net >
2025-01-02 14:46:36 +00:00
Arnout Engelen
3caf8a75bb
Fix typo: Buildiing -> Building
2025-01-02 10:53:38 +01:00
dan
cc94ef57fa
in rc.init copy log from previous boot to place of safety
2025-01-01 18:22:45 +00:00
dan
fd28f0ce04
rt3200 needs pmsg-size set in its dts for persistent logging
2025-01-01 14:11:22 +00:00
dan
497307588f
automate ubimage instructions a little
2025-01-01 12:38:08 +00:00
dan
788169586f
/boot is a directory, copy files instead of replacing it with symlink
...
for the record, u-boot doesn't like having /boot/fit -> ../nix/store/..../fit
symlinks so we don't use symlinks inside /boot either
2025-01-01 12:29:25 +00:00
dan
3af9e86624
rt3200: replace bootcmd variable
...
the default is to boot to recovery if there's anything in pstore, but
this doesn't interact well with persstent logging
2025-01-01 11:56:54 +00:00
dan
28d39cd66d
provide etc/kconfig in updater output
...
this is for debugging/documentation purposes and isn't copied to the
device
2025-01-01 11:55:33 +00:00
dan
9dd169d500
add "config" output to kernel derivation
2025-01-01 11:54:46 +00:00
dan
2e513eb4a7
example sni proxy using nginx
2024-12-29 23:34:15 +00:00
dan
f2e4e77d73
firewall: don't use oifname in input rules
...
because it's empty, these are input rules for the local machine
2024-12-29 23:17:31 +00:00
dan
48dfbe0c01
add nginx-small : nginx with finegrained configure options
2024-12-29 20:47:03 +00:00
dan
6f697db57c
remove PSTORE from rt3200 default kconfig
...
we have config.logging.persistent.enable at home
2024-12-29 13:33:55 +00:00
dan
fe1ee12e3d
swap strchr for strchrnul in dropbear authkeyfile patch
...
The strchrnul version was giving weird crashes on aarch64
belkin-rt3200. I haven't figured out why but this one doesn't
2024-12-29 13:30:21 +00:00
dan
4d273a9469
dropbear would like /etc/shells to exist
2024-12-29 13:27:49 +00:00
dan
40db175b41
complain if user attempting to tftpboot a ubifs
2024-12-29 13:26:45 +00:00
dan
ab07212a7e
include jffs2 module per default
...
it has no effect unless enabled
2024-12-29 13:26:06 +00:00
dan
f5e08ac9d9
rt3200 default to loader.fit
2024-12-29 13:25:26 +00:00
dan
0cb18eabcd
boot.expect: improve reliability
...
don't depend on seeing u-boot prompt, it's just too easy to get
out of sync
2024-12-27 18:08:01 +00:00
dan
24151425b8
and fix quoting
2024-12-24 14:29:01 +00:00
dan
e06295ed83
rt3200: add fw_setenv commands to update boot_production
2024-12-24 14:19:29 +00:00
dan
608d3e3abf
proofread
2024-12-24 14:01:30 +00:00
dan
3e19f1b927
Merge branch 'runciter'
2024-12-24 13:47:27 +00:00
dan
3f6e9b6384
rt3200 defaults to ubifs
2024-12-24 13:46:36 +00:00
dan
294492a176
jiggle imports
2024-12-24 13:46:19 +00:00
dan
67a1cd3718
improve install instructions for belkin rt3200
2024-12-24 13:45:11 +00:00
Arnout Engelen
f8a275d1a3
use Linux kernel sources associated with openwrt by default
2024-12-24 12:30:15 +00:00
dan
0ee9c76c33
think
2024-12-24 12:30:15 +00:00
dan
452aaa2f60
Merge pull request 'use Linux kernel sources associated with openwrt by default' ( #12 ) from raboof/liminix:linux-version-with-openwrt into main
...
Reviewed-on: dan/liminix#12
2024-12-24 12:24:31 +00:00
dan
52967f746b
Merge branch 'main' into linux-version-with-openwrt
2024-12-24 12:24:13 +00:00
Arnout Engelen
a89f866bf0
use Linux kernel sources associated with openwrt by default
2024-12-24 12:21:28 +00:00
dan
f3fadd5cd7
think
2024-12-24 12:20:48 +00:00
dan
bc20f4c6b7
rt3200 test install
2024-12-23 23:59:52 +00:00
dan
848214d104
add ubivolume output
2024-12-23 22:37:07 +00:00
dan
ede8f12d2b
declare options.hardware.ubi unconditionally
...
this is so it can be defined in device modules even when
ubifs is not included in the configuration
2024-12-23 22:37:07 +00:00
dan
6cd5b90678
outputs.rootubifs -> ubifs
2024-12-23 22:37:07 +00:00
dan
db4f098c02
add fit bootloader
...
this is for the belkin rt3200, whose uboot doesn't do
extlinux but can load a fit from a ubifs. It adds the
a kernel+dtb as /boot/fit
2024-12-23 11:21:58 +00:00
dan
1347937345
rename file
2024-12-23 10:31:22 +00:00
dan
a7b5f80674
rename extlinux output to bootfiles
...
this is in preparation for introducing other non-extlinux
modules that populate /boot
2024-12-23 00:09:31 +00:00
dan
5c78338d71
make mtdutils use no-systemd util-linux
2024-12-22 23:24:11 +00:00
dan
ed02d02767
bump NEWS
2024-12-22 21:12:36 +00:00
dan
f07a38b0fd
extract uimage output module into own file
2024-12-22 21:10:07 +00:00
dan
ac189f2977
outputs.zimage -> outputs.kernel.zImage
...
remove config option/derivation in favour of accessing
as output of the kernel derivation (matches what we do
with e.g. modulesupport)
2024-12-22 17:27:59 +00:00
dan
ebb4d4a831
think
2024-12-22 16:03:24 +00:00
dan
6bfbdf352d
bordervm: expose ssh on port 2222
2024-12-22 16:01:38 +00:00
dan
4ea1cf7f32
rt3200 better install docs
2024-12-20 22:26:40 +00:00
dan
f60b74f415
add a new updater output
...
this is so that we don't have to obfuscate store paths in
systemConfiguration to avoid dragging in build system
deps.
breaking-ish change to workflows, docs updated
2024-12-20 00:05:07 +00:00
dan
812e35b7b9
systemconfig: improve filenames/pathnames
...
no more make-stuff
2024-12-19 22:28:30 +00:00
dan
172f368633
fix markup
2024-12-19 21:59:04 +00:00
dan
1af9a39db1
omnia: delete pstore config we're probably not using
2024-12-19 20:59:52 +00:00
dan
420552ce98
add omnia to ci
2024-12-19 20:56:05 +00:00
dan
56c667cfd5
extract systemConfiguration into its own output module
2024-12-19 20:55:10 +00:00
dan
f9b4f0bc9c
move modules/squashfs.nix into outputs/
2024-12-19 14:33:50 +00:00
dan
ba5e4704a0
add short note about persistent logs
2024-12-18 23:08:28 +00:00
dan
3357d21d7f
enlarge pmsg buffer to full size of ramoops region
...
4k was a piddly amount and we weren't using the rest of it for
anything else
2024-12-18 21:16:49 +00:00
dan
ffaca615ba
copy logs to /dev/pmsg0 when ogging.persistent.enabled
2024-12-18 21:11:58 +00:00
dan
77cd4492b2
unbreak nix-shell
2024-12-17 23:26:56 +00:00
dan
81f5550bf0
config.logging.persistent enables /dev/pmsg0
...
- whatever's written to /dev/pmsg0 appears as
/sys/fs/pstore/pmsg-ramoops-0 after reboot
- only works on devices with the relevant device tree
support (gl-ar750 and whatever has it by default)
- nothing in the system is actually writing this file yet
- or reading it at boot time, for that matter
2024-12-17 23:24:31 +00:00
dan
b52133a28b
add hardware.dts.includes option
2024-12-17 20:36:14 +00:00
Arnout Engelen
1ff779c1a9
use Linux kernel sources associated with openwrt by default
2024-12-17 20:24:14 +01:00
dan
44caefcd3b
rename config.hardware.dts.includes -> includePaths
...
(1) it's a better name
(2) I want to use `includes` to specify dtsi files
2024-12-17 17:41:53 +00:00
dan
6e6b8790eb
think
2024-12-17 17:24:52 +00:00
dan
2e5a8a572e
tufted: more robust merge-pathname impl
2024-12-17 17:24:40 +00:00
dan
464d046b5a
append-path spec behaviour for repeated /
2024-12-17 17:24:16 +00:00
dan
ac8b971cc0
new fn append-path in anoia
...
complains if you try to ../../../
2024-12-11 17:26:44 +00:00
dan
13087d17e3
use assert macros in anoia/init.fnl
...
there is no circularity (maybe there was once?)
2024-12-11 17:25:39 +00:00
dan
5572c0ecb0
rewrite parts of inout test to be differently wrong
2024-12-09 23:36:22 +00:00
dan
4cbe3ba683
add some debug output in inout test
2024-12-09 21:00:11 +00:00
dan
20f4a12689
inout: improve robustness, maybe?
2024-12-07 16:02:42 +00:00
dan
33e5c436d5
add environment variables that scapy now needs (24.11)
2024-12-04 21:16:36 +00:00
dan
cde30bcd54
in nixos 24.11 chrony no longer expects nss/nspr/readline
2024-12-03 21:39:54 +00:00
dan
1f7d6544e3
provide stdout to ppp callback scripts
...
pppd runs them with 0,1,2 => /dev/null but we actually quite like
seeing errors in the logs
2024-10-17 21:37:08 +01:00
dan
1bca072509
fix chrony pidfile error
2024-10-17 21:35:33 +01:00
dan
7b98724643
turns out we did need usepeerdns
2024-10-17 21:05:16 +01:00
dan
b1625763ee
ppp service signal readiness only when ip-up has run
...
as downstream services need e.g. ifname which is not written by ipv6-up
2024-10-16 22:59:01 +01:00
dan
91bdfc2766
remove apparently obsolete rp-pppoe configure setting
...
this were copied from nixpkgs but perhaps is for an older version of
rp-pppoe because it builds just fine without
2024-10-16 22:56:05 +01:00
dan
14bfebc5c3
enable unloading modules so that scripts work
...
if we can't unload them then the service that loads them will fail
the second time it's run
2024-10-16 22:54:19 +01:00
dan
0447ac0ff9
did we need MODULE_SIG?
...
I think this may be a hangover from using backports modules for wlan
2024-10-16 22:53:16 +01:00
dan
e35a1514ab
send kernel logs to s6
2024-10-16 18:59:42 +01:00
dan
4a0120487c
remove usepeerdns - it causes only errors
...
we handle dns with service outputs anyway
2024-10-16 18:58:34 +01:00
dan
888688ce28
buuld ppp with path to /run
2024-10-16 18:57:26 +01:00
dan
9e3f48768e
think
2024-10-14 18:49:10 +01:00
dan
72171021e3
support finish script in longrun
2024-10-10 18:26:14 +01:00
dan
17517dd34f
remove KEXEC from base kernel config
...
we're not using it any more
2024-10-10 18:23:50 +01:00
dan
5112eab4da
apply incoming-allowed-ip[46] rules to input as well as forward pkts
...
this makes it possible to open ports on the router itself
2024-10-10 18:18:23 +01:00
dan
e383f1b3d3
obfuscate store path for min-copy-closure
...
otherwise the systemconfig closure drags in a bunch of build system
things (bash, etc) which we don't want or need to copy to the device
2024-10-10 16:25:00 +01:00
dan
da1245432e
no more iminix-rebuild
2024-10-09 19:34:55 +01:00
dan
541b1c61c2
ensure $toplevel is path in /nix/store
2024-10-09 18:59:33 +01:00
dan
55c7410a55
add result/install.sh to systemConfiguration output
...
this makes it possible to install a systemconfig instead of
having to use nix-shell (which is very slow)
2024-10-09 13:35:02 +01:00
dan
0f50648157
don't put hostname in levitate logs
...
there might not be one
2024-10-08 22:55:39 +01:00
dan
f1c260d4f7
make ci.ni "all" a derivation
...
this is to stop hydra complaining
2024-10-06 18:04:56 +01:00
dan
3d611d3ba2
fix unstable qemu build?
...
nix-repl> (lib.versionOlder "24.11pre-git" "24.11")
true
nix-repl> (lib.versionOlder "24.11pre-git" "24.10")
false
n
2024-10-06 18:04:48 +01:00
dan
e6b7d86381
sort lines
2024-10-06 17:53:34 +01:00
dan
83fbffb39b
catch another uncaught-logs
2024-10-06 17:53:09 +01:00
dan
f8c579b41e
add CI "all" target
2024-10-06 17:52:59 +01:00
dan
ca9efc4b26
simplify CI
...
* I didn't know what I was doing when I set up Hydra
* it's not certain that I do now either, but hey ho
2024-10-06 15:55:01 +01:00
dan
336fc7e495
think
2024-10-06 14:27:45 +01:00
dan
4cc0add2ad
update refs to uncaught-logs in docs/tests
2024-10-06 13:46:14 +01:00
dan
2d7e6188ac
log shipping service now gets logs on stdin
...
instead of having to open the unix socket
2024-10-06 13:26:58 +01:00
dan
b9999857cb
longrun: don't add logger if producer-for is already set
2024-10-06 13:13:04 +01:00
dan
ba03ddeb38
border-vm: add tang service
2024-10-06 12:38:06 +01:00
dan
493c5f69d7
add module for certifix-client
2024-10-06 11:27:39 +01:00
dan
1a915e91ff
add altname to CSR
2024-10-06 10:13:28 +01:00
dan
197e2eb5b1
new package certifix-client uses certifix to sign ssl client cert
...
this is initially for TLS-enabled logging but would be useful for
anything on a liminix box that wants to talk to a network service in a
"zero trust" setup
2024-10-03 23:00:08 +01:00
dan
7ca822c826
more messing around with lua derivation
2024-10-03 23:00:08 +01:00
dan
e5631783e1
add luaossl package with patch for CSR attributes
2024-10-03 23:00:08 +01:00
dan
635590d37a
implement log shipping config
...
to use this, you need config like for example
+ logging.shipping = {
+ enable = true;
+ service = longrun {
+ name = "ship-logs";
+ run = let path = lib.makeBinPath (with pkgs; [ s6 s6-networking s6 execline ]);
+ in ''
+ PATH=${path}:$PATH
+ s6-ipcserver -1 ${config.logging.shipping.socket} \
+ s6-tcpclient 10.0.2.2 19612 \
+ fdmove -c 1 7 cat
+ '';
+ };
+ };
but I think we can reduce the noise a bit if we use an s6-rc pipeline
with an s6-ipcserver on one side and and a (whatever the user wants)
on the other
2024-09-18 22:14:34 +01:00
dan
17630f2678
rename logtee->logtap
2024-09-18 20:58:02 +01:00
dan
707a471bc2
add logtee to catchall logger
2024-09-16 21:30:06 +01:00
dan
d3fce5edd4
implement error() for musl
2024-09-16 20:35:23 +01:00
dan
5771108fed
improve logtee socket connection warning
...
* print it less often
* to the correct stream (stdout not stderr)
2024-09-16 20:34:26 +01:00
dan
9e5f2d663d
close socket fd if we can't connect it
2024-09-15 22:09:31 +01:00
dan
21eeb1671e
print diagnostic when eof on stderr
2024-09-15 21:59:24 +01:00
dan
44762d38fc
write start cookie when socket connect succeeds
2024-09-15 21:54:21 +01:00
dan
1f6cfc3679
extract method is_connected
2024-09-15 21:40:05 +01:00
dan
8ec00f1710
improve error message
2024-09-15 21:37:04 +01:00
dan
6a6dd32dea
make pollfd array global
2024-09-15 21:32:48 +01:00
dan
9b1fc11a59
logshipper/logtee :copy stdin to stdout & to a unix socket if present
...
first draft
2024-09-15 19:33:21 +01:00
dan
aaa6e353db
incz is a very rudimentary log shipper for zinc search
...
although it probably would work with elasticsearch as well
as zinc is alleged to be ES-compatible
this is just the package and needs hooking into the service/log
infrastructure somehow
2024-09-08 16:38:37 +01:00
dan
69bf6cb5fb
write-fennel quote PATH properly
...
escapeShellArg only quotes if the string contains special
characters, but for a Lua string we must quote unconditionally
2024-09-07 22:31:44 +01:00
dan
9f58e7b926
maybe fix nixpkgs-unstable lua
2024-09-07 00:58:11 +01:00
dan
5a5c27ab9f
think
2024-09-06 22:37:49 +01:00
dan
277c91acdf
Revert "remove luaposix ref in write-fennel"
...
This reverts commit a60c2539a6 .
2024-09-06 00:33:30 +01:00
dan
e0725489ca
unbreak pppoe ci job
2024-09-06 00:33:30 +01:00
dan
cc47515cf8
watch-outputs remove debug code
2024-09-06 00:13:54 +01:00
dan
464913cc8f
tangc use spawn to invoke jose
...
hopefully we are now deadlock-free
2024-09-06 00:12:45 +01:00
dan
e604d628e3
fennel anoia.process.spawn
...
runs a subprocess and invokes a callback whenever its io
descriptors are ready
2024-09-06 00:11:33 +01:00
dan
e2a597589b
anoia.fs.find-executable looks for bin in colon-sep list of directories
2024-09-06 00:08:40 +01:00
Raito Bezarius
a139a262c1
seedrng: init at 2022.04
...
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-09-05 14:18:00 +01:00
dan
6a5fed83dd
conditional fetch in json-to-fstree
2024-09-05 11:14:47 +01:00
dan
bcf5ab24e8
tidy watch-outputs startup message
2024-09-05 10:11:16 +01:00
dan
32bf80c6fa
devout: unlink socket pathname before binding
2024-09-05 10:05:13 +01:00
dan
12275f6896
add more test for table=
2024-09-04 21:21:30 +01:00
dan
a60c2539a6
remove luaposix ref in write-fennel
2024-09-04 21:21:02 +01:00
dan
146a2d9ac0
fix startup race/fencepost in watch-ssh-keys
...
if it starts _after_ the outputs are populated, it should
write the first lot of outputs without waiting for a change
2024-09-04 21:19:51 +01:00
dan
091d863710
extract pppoe/l2tp common code
2024-09-04 12:02:00 +01:00
dan
c7bcfbfa34
make pppoe/l2tp more consistent
2024-09-03 22:57:45 +01:00
dan
500a3c1025
make nodefaultroute explicit in ppp
2024-09-03 22:53:13 +01:00
dan
0c0d0eed8a
make watch-ssh-keys robust against missing key
2024-09-03 22:51:29 +01:00
dan
699cf97206
improve tangc http error messages
2024-09-03 22:50:55 +01:00
dan
cd0093279c
think
2024-09-01 10:14:31 +01:00
dan
034d6aacc4
tangc handle non-zero exit from jwe dec
...
Sometimes it exits non-zero but decrypts the file *anyway*. It only
does this on the device and I haven't been able to reproduce on build,
so this is a workaround until we find the root cause
2024-09-01 09:57:38 +01:00
dan
e590c0ad3f
secrets subscriber: add provider as dep to controlled service
2024-09-01 09:56:59 +01:00
dan
14abdd9998
tang: notify on ready
2024-08-31 23:24:50 +01:00
dan
6287b92000
fix bugs handling base64 padding
2024-08-31 22:43:25 +01:00
dan
d2215d3e56
tangc popen retry on short read
2024-08-31 22:18:23 +01:00
dan
3cf2308bee
tangc: stop printing unexpected blank lines
2024-08-31 15:29:10 +01:00
dan
3913989be3
provide string to perform-encryption
...
instead of letting it read stdin, which I think may have been read
by a subprocess already sometimes?
2024-08-31 15:27:54 +01:00
dan
43e5e6876e
improve tangc error messages
2024-08-31 15:22:26 +01:00
dan
7d6c80570c
refactor all writeFennelScript calls to use writeFennel directly
2024-08-30 20:57:42 +01:00
dan
e745991b9d
restart pppoe/l2tp in secrets changes
2024-08-30 20:49:27 +01:00
dan
defbfce1fb
finish converting outputRef to lambda
2024-08-30 20:46:48 +01:00
dan
0df2c83382
tighten perms on service state directory
2024-08-29 23:56:43 +01:00
dan
01c28de88d
think
2024-08-29 23:56:20 +01:00
dan
2bf197cad8
document outputs and secrets
2024-08-29 23:55:32 +01:00
dan
a8a19977ca
(untested) template service for tang encrypted secrets
2024-08-28 22:32:26 +01:00
dan
8a9284af1e
think
2024-08-28 22:23:00 +01:00
dan
7351e143c5
remove redundant sourcing of ${serviceFns}
...
this is done by the oneshot and longrun functions
2024-08-28 21:28:27 +01:00
dan
283c3154a7
missing file in s6-rc-up-tree test fixture
2024-08-28 21:18:54 +01:00
dan
34f37d60d9
missed adding this
2024-08-28 20:56:52 +01:00
dan
fe7b092075
(untested) http basic auth for outboard secrets
2024-08-28 20:53:59 +01:00
dan
b56f121e04
fetch lua glue: handle missing content-length
2024-08-28 19:52:00 +01:00
dan
d5d621f310
rename http-fstree => json-to-fstree
...
it works for file urls as well, not just http
2024-08-28 16:36:49 +01:00
dan
da95a9fa62
tangc support encryption
2024-08-28 18:55:20 +01:00
dan
85071c88e7
remove argv0 from calls to jose
2024-08-28 11:16:43 +01:00
dan
74093b7ee3
josep! runs jose without json parsing the output
2024-08-28 08:13:50 +01:00
dan
41733e58d6
remove unused code, tidy string parsing
2024-08-28 07:20:07 +01:00
dan
9041d5d63a
add jose! fn to reduce error-checking boilerplate
2024-08-28 07:10:47 +01:00
dan
001ebdc601
remove unused requires
2024-08-28 06:52:04 +01:00
dan
1f97409474
add popen2 to anoia.fs
2024-08-28 06:49:43 +01:00
dan
a41839f3d1
clevis-decrypt-tang in fennel
...
needs a lot of tidying up, but works on my test file
2024-08-28 01:37:44 +01:00
dan
ff76d854fc
extend libfetch lua glue to other HTTP methods
2024-08-28 01:37:02 +01:00
dan
81a6480a4f
anoia add base64 deode
2024-08-27 22:42:03 +01:00
dan
c7164a6f4a
sshd can use outputRef for authorized_keys
2024-08-25 16:35:50 +01:00
dan
83ca86fe42
keys in service output tree are strings
2024-08-25 15:59:24 +01:00
dan
1b4106e2a3
ssh-keys service, draft
2024-08-25 15:09:31 +01:00
dan
89912c766b
nixpkgs 24.11 qemu does not expect texinfo
2024-08-25 14:23:29 +01:00
dan
9828b007ae
watch-ssh-keys turns secrets-service into authorized_keys files
2024-08-24 23:25:32 +01:00
dan
f34abc85ae
add macros param to write-fennel
2024-08-24 23:19:46 +01:00
dan
b475a680fb
define-tests macro, evals body only when inside fennelrepl --test
2024-08-24 22:26:25 +01:00
dan
43612af71a
anoia: %% is alias for string.formt
2024-08-24 13:56:54 +01:00
dan
5695c47496
add dig to anoia
2024-08-23 23:27:29 +01:00
dan
e3ec514710
think
2024-08-23 23:27:17 +01:00
dan
99f68e5421
destructure params in ssh service
2024-08-23 23:13:49 +01:00
dan
9c30b6f882
change output references from attrset to lambda
...
this is so that we can distinguish a ref from a literal parameter that
might be a attrset
2024-08-23 22:25:57 +01:00
dan
dd75322c10
think
2024-08-23 21:45:18 +01:00
dan
869a508c0a
add authorizedKeys option to ssh service
...
this has no apparent use as it stands, but opens the door to
having the keys managed by an external secrets service
2024-08-23 20:35:07 +01:00
dan
e835473945
patch dropbear to add -U option
2024-08-23 19:58:05 +01:00
dan
055268d5d2
upgrade dropbear
2024-08-23 19:57:10 +01:00
dan
ff38bcacbb
improve devout error reporting
2024-08-21 23:24:13 +01:00
dan
a6128955e7
ppp modules: permit (mostly) same params for l2tp as pppoe
...
this also means that l2tp can use secrets for username/password
2024-08-21 23:10:28 +01:00
dan
531cb113be
devout needs a longer startup timeout
...
seems to be taking around 40 seconds now, would be worth digging in to
find out why
2024-08-21 23:09:11 +01:00
dan
daede666cb
in router-with-l2tp use secrets for ppp username/password
2024-08-21 00:17:53 +01:00
dan
2992771c7e
pppoe allow secrets for username/password
2024-08-21 00:17:22 +01:00
dan
4cc82e1502
liminix.types.replacable is a string or ref to an output
2024-08-21 00:16:14 +01:00
dan
21f2320d86
inline method
2024-08-20 23:26:11 +01:00
dan
d40ada4251
use structured ppp params in ppp test
2024-08-20 23:25:31 +01:00
dan
4053ea9481
secrets/subscriber implement different restart types
2024-08-20 22:56:26 +01:00
dan
54d3415885
pppoe convert to using a config file
...
mostly for ease of implementation but does mean we don't
have username/password secrets on the command line
2024-08-20 22:55:30 +01:00
dan
264d83c98d
move some secret-watching stuff from hostapd to secrets
2024-08-20 21:49:11 +01:00
dan
97defc2076
hostapd: get secrets service/path from attrs
2024-08-17 22:25:30 +01:00
dan
ddaa5476d3
override clevis derivation (experimental)
2024-08-15 23:02:54 +01:00
dan
bcd9d56624
start devout after mdevd
...
not 100% sure that there's a dependency but it's plausible, and
would explain the observed occasional failure to start at boot
2024-08-15 23:01:29 +01:00
dan
e2c883356c
add secrets-subscriber service, make hostapd use it
2024-08-15 23:00:41 +01:00
dan
d79a941504
new package watch-outputs and example of its use
2024-08-14 22:58:17 +01:00
dan
2f82e0dab8
hostapd set permissions on dir in /run/
2024-08-14 22:57:02 +01:00
dan
fc03965915
hostapd literal_or_output use an attrset for dispatch
2024-08-14 22:56:01 +01:00
dan
d2d3af2587
outboard secrets: loop in service
...
if we just quit and expect s6 to restart us, the finish script
wipes our outputs and anything with an inotify watch gets confused
2024-08-14 22:41:56 +01:00
dan
310ac30f24
http-fstree needs to write state and .lock for anoia.svc
2024-08-14 22:39:41 +01:00
dan
45a7f96bd4
anoia table= compares tables
2024-08-14 22:36:28 +01:00
dan
79445fd962
support multi-arg assoc
2024-08-14 22:34:37 +01:00
dan
a9ddd78482
think
2024-08-12 22:59:03 +01:00
dan
4fb8253e57
first pass at outboard secrets
...
- a module to fetch them with http(s)
- a service using templating to consume them
- update an example to use it
needs service restarts
needs other services to use the template mechanism
needs tidying up
2024-08-12 22:57:21 +01:00
dan
ff3a1905a5
pass service to output fn in output-template
...
instead of on command line
2024-08-12 22:53:07 +01:00
dan
3c353e4aff
support json quoting in output-template
2024-08-10 23:42:08 +01:00
dan
ba21384fde
new: output-template interpolates output values into config file
2024-08-10 23:06:47 +01:00
dan
2480fdef5b
set up nginx on bordervm for testing outboard secrets
2024-08-10 23:05:50 +01:00
dan
409c1cfb16
think
2024-08-10 23:05:15 +01:00
dan
9767078878
add the example used in the video
2024-08-08 19:24:58 +01:00
dan
d760c2d27b
http-fstree downloads a json file and converts to service outputs
2024-08-08 15:35:11 +01:00
dan
1e139c22fd
think
2024-08-08 15:21:24 +01:00
dan
a1ff07b063
add rxi/json lua module
2024-08-08 15:05:26 +01:00
dan
9550772cec
add lua binding to fetch-freebsd
2024-08-08 15:05:03 +01:00
dan
64cd1626c6
new package fetch-freebsd: small http(s) client library
...
[*] smaller than curl, maybe not maximally small
2024-08-08 11:38:38 +01:00
dan
eb79928b37
anoia.svc allow writing outputs
2024-08-08 11:37:50 +01:00
dan
0a629df48d
anoia.fs: improve error messages
2024-08-08 11:36:47 +01:00
dan
64afd18e2a
why does this fail on hydra?
2024-08-06 23:18:39 +01:00
dan
47e96ddc15
think
2024-08-06 18:43:49 +01:00
dan
5db9d7269e
ppoe structured options are optional
2024-08-06 18:43:27 +01:00
dan
985df8792d
overlay: handle cross-only overrides consistently
2024-08-06 18:42:58 +01:00
dan
528afae8b1
doc: punctuate
2024-08-06 14:15:57 +01:00
dan
384835c89d
admin doc: updte round-robin, explain health check
2024-08-06 14:14:52 +01:00
dan
5051625d31
mention health check in docs
2024-07-30 22:53:21 +01:00
dan
c4d00e062a
add health check service and example that uses it
2024-07-30 22:37:43 +01:00
dan
8fa3443923
Revert "anoia.svc use timeout for inotify"
...
This reverts commit eca8e37e7a .
2024-07-30 17:37:38 +01:00
dan
8091e207b6
some notes on controlled services
2024-07-28 22:57:23 +01:00
dan
39020607ad
rename service-trigger rule to match service name
2024-07-28 22:35:37 +01:00
dan
fe735408a1
v:address is nil if missing, but code expects an array
2024-07-27 17:40:32 +01:00
dan
a9d1582b53
remove unused arg
2024-07-26 23:41:50 +01:00
dan
eca8e37e7a
anoia.svc use timeout for inotify
...
in case we miss a message, check the directory every 5s
anyway
2024-07-26 23:40:40 +01:00
dan
d300373b96
anoia fs.dir use case not match
...
match was accidentally pinning the return from readdir against the
function parameter. Which didn't work.
2024-07-26 23:37:40 +01:00
dan
70ca7fac17
elfutils is reqd by iproute2 (for bpf?), build sans kitchen sink
2024-07-24 22:07:58 +01:00
dan
79a3a45061
build iproute2 without rb to avoid stdatomic
2024-07-24 21:13:55 +01:00
dan
612d6d7a51
build openssl without threads to avoid stdatomic
2024-07-24 21:12:52 +01:00
dan
e1ae986cf6
convert l2tp example to use gateway profile
2024-07-23 09:31:34 +01:00
dan
bce0c7ffb6
rename services.dhcpc in l2tp example
...
it's only used to get the address of the l2tp server, not for
name lookups in general
2024-07-23 09:31:34 +01:00
dan
28ca1e68ab
wwan module needs mdevd
2024-07-23 09:31:34 +01:00
dan
acf33a100f
think
2024-07-23 09:31:34 +01:00
dan
7f9cae9d5c
generalise profile.gateway.wan so not just pppoe
2024-07-23 09:31:34 +01:00
dan
3012c91b47
executive decision: rotuer example should build on gl-ar750
2024-07-23 09:31:34 +01:00
dan
1edf20c08f
fix whitespace
2024-07-23 09:31:34 +01:00
dan
7195cb10ce
add structured config for common pppoe options
2024-07-23 09:31:34 +01:00
dan
135a445672
restore param removed by deadnix
...
dochain is called with `family` even if it never uses it
2024-07-16 20:41:21 +01:00
dan
3899daee56
create a module for round-robin
2024-07-15 22:37:37 +01:00
dan
b17f623d03
need insmod when we habve kmodloader
2024-07-15 22:35:26 +01:00
dan
df395a4d5d
finish moving pkgs.linimix.callService to config.system
2024-07-15 19:00:08 +01:00
dan
75e9f8210c
remove the fixpoint we didn't need
2024-07-15 18:54:04 +01:00
dan
1c3242cab1
doc: swap order of configuration and installation
...
you can get a device up and running using a lightly edited example
config before you need to read all the reference info, so let's
have the documentation in that order.
2024-07-14 12:26:07 +01:00
dan
44ea683391
think
2024-07-14 12:08:02 +01:00
dan
725d8b608f
huawei-cdc-ncm kernel driver -> module
2024-07-14 12:07:28 +01:00
dan
bc9ced5d38
fix doc ref from admin section -> configuration
2024-07-14 11:56:35 +01:00
dan
73ae7788b9
rename wwan-related modules/services
...
we only currently support huawei e3372/cdc ncm so let's make that
explicit in the naming
2024-07-14 11:53:45 +01:00
dan
d34919766a
improve reinstallation docs
2024-07-12 18:38:04 +01:00
dan
2fe0cd2f48
add first draft instructions for using Levitate
2024-07-12 00:17:25 +01:00
dan
241f1013ed
add new Installation guide
...
move the u-boot/serial stuff here from development, as the
reality of Liminix development in 2024 is that serial connection
is still the smoothest installation method
2024-07-11 23:31:00 +01:00
dan
2ce361d4e3
think
2024-07-11 09:39:38 +01:00
dan
3f8cc24dcc
fix most doc warnings
2024-07-10 23:36:24 +01:00
dan
57e3b449f8
proofreading
2024-07-10 21:23:24 +01:00
dan
3964505131
some notes on services
2024-07-10 20:50:08 +01:00
dan
941479b144
use round-robin failiover in l2tp example
2024-07-08 22:01:54 +01:00
dan
ac551536da
set cwd before exec xl2tpd
2024-07-08 21:56:26 +01:00
dan
6f908156af
fix dependency between modem-atz and modeswitch
...
for values of "fix" more than slightly reminiscent of "kludge"
2024-07-08 21:55:05 +01:00
dan
534a49e827
s6-rc-round-robin
...
runs services in order, starting the next one when the previous one
dies or fails to start
2024-07-08 21:53:51 +01:00
dan
07a6eb73cd
set lcp-echo timeout in l2tp
2024-07-08 21:45:54 +01:00
dan
159bfa3057
make xl2tpd quit when the connections close
2024-07-08 21:44:15 +01:00
dan
8f0ab5be40
enable tail -F
2024-07-08 21:37:07 +01:00
dan
7f9971512d
a6-rc-up-tree: handle blocked deps, exit 1 if nothing started
2024-07-08 21:28:31 +01:00
dan
f0f6cc80d7
remove dead code
2024-07-08 21:28:11 +01:00
dan
afcc6a6436
s6-rc-up-tree pass -b to s6-rc command
2024-07-08 21:27:54 +01:00
dan
2e8e05f31a
wip: rewrite s6-rc-up-tree in an actual procgramming language
...
and write some tests for it, too
2024-07-08 21:27:42 +01:00
dan
143137cbc6
pppoe: set lcp echo failure timeout
2024-07-08 21:25:42 +01:00
dan
8d228f2bef
mess with redial
2024-07-08 21:24:44 +01:00
dan
5751058d59
gl-ar750 swap lan and wan
...
I don't know if I just got it wrong the first time or if something
weird is going on
2024-07-08 21:19:30 +01:00
dan
5ac7e1e9b2
write-fennel: set $PATH if lualinux is available
2024-07-08 21:18:02 +01:00
dan
c75452549b
think
2024-07-08 21:17:12 +01:00
dan
2663f58807
disable security for bordervm "liminix" share
...
tftp needs to be able to follow symlinks into the store
2024-07-01 20:53:03 +01:00
dan
9dbc285605
build libusb1 without libatomic
2024-06-30 17:52:17 +01:00
dan
8b6aa2134e
zyxel dual image; restore deleted params
2024-06-30 17:50:45 +01:00
dan
3df1ec76ff
cleanup whitespace and commas
...
* [] is now [ ]
* {} is now { }
* commas in arglists go at end of line not beginning
In short, I ran the whole thing through nixfmt-rfc-style but only
accepted about 30% of its changes. I might grow accustomed to more
of it over time
2024-06-30 17:16:28 +01:00
dan
0d3218127f
remove unused makeWrapper input
2024-06-30 10:46:37 +01:00
dan
e94bf62ec1
remove dead code (run deadnix)
2024-06-29 22:59:27 +01:00
dan
16a2499d74
avoid makeWrapper on host, it requires bash
2024-06-29 22:36:05 +01:00
dan
d4d8093f97
working l2tp-over-wwan stick example
2024-06-20 10:15:54 +01:00
dan
7c9c801afc
rename isTrigger to restart-on-upgrade
...
we're moving away from "trigger" services to "controller" services,
and "restart-on-upgrade" is the name used by s6-rc
2024-06-16 12:58:06 +01:00
dan
c4185617c0
a6-rc-up-tree wait for lock if needed
2024-06-15 15:36:07 +01:00
dan
06d28e9b08
dhcpc handle case when env vars are missing
...
the notify-script should continue and signal readiness even if one or
more of the outputs it writes are mssing in the environment
2024-06-15 15:34:49 +01:00
dan
9540fc2641
add writeAshScriptBin (forgot to add file)
2024-06-15 15:04:56 +01:00
dan
adc84108ad
Revert "wwan gets address from ppp ipcp not dhcp"
...
This reverts commit be13ab23ca .
2024-06-15 15:04:33 +01:00
dan
eae99051fa
exec devout in service definition
...
makes little practical difference but saves a process slot
2024-06-15 15:01:57 +01:00
dan
49d1703428
add s6-rc-up-tree: start reverse deps of controlled service
...
When s6-rc stops a service, it also stops everything that
depends on it. but when it starts a service it starts only
that service, so we have to go through the other services
depending on it and figure out if they should be started too.
2024-06-15 14:59:34 +01:00
dan
1d337588f9
think
2024-06-15 09:04:19 +01:00
dan
29a869b4fa
qemu: use kmodloader for wifi
2024-06-13 10:12:17 +01:00
dan
5ae1b0a193
Revert "bodervm: remove usbutils until we can fix the udev dep"
...
This reverts commit c22e3fb2ef .
2024-06-12 20:58:13 +01:00
dan
473a4947a5
inout test: wait longer for disk to appear
2024-06-12 20:44:03 +01:00
dan
50bad5c604
libusb needs udev on build
...
this is a workaround to make CI work again, but what we really need to
do is completely separate the nixpkgs used for nixos build-system
tools from the nixpkgs we use for liminix host binaries
2024-06-12 18:55:30 +01:00
dan
c22e3fb2ef
bodervm: remove usbutils until we can fix the udev dep
2024-06-12 13:07:29 +01:00
dan
f898e4dca2
remove debug
2024-06-12 13:03:26 +01:00
dan
5121a8563d
callService: dependencies are services not names
2024-06-12 12:58:57 +01:00
dan
78be354b6e
think
2024-06-12 12:52:52 +01:00
dan
be13ab23ca
wwan gets address from ppp ipcp not dhcp
2024-06-12 12:51:07 +01:00
dan
4b30cd7a75
think
2024-06-11 14:05:32 +01:00
dan
b15542b668
start correct services at boot
...
- uncontrolled services that are not dependent on a controlled service
- controllers
- _not_ controlled services or any other service that depends on one
2024-06-11 14:04:14 +01:00
dan
6daeaf29a0
flip controller/controlled relationship for wwan services
2024-06-11 14:02:48 +01:00
dan
e6ca5ea064
store derivations not just names for service deps
...
.. also controllers, contents. This is to make it possible (easier)
to work out transitive dependencies at build time
2024-06-11 14:01:06 +01:00
dan
e6e4665a18
flip dependencies for triggered/controlled services
...
Instead of treating the trigger as the "main" service and the
triggered service as subsidary, now we treat the triggered
service as the service and the trigger as "subsidary". This
needs some special handling when we work out which services
go in the default bundle, but it works better for declaring
dependencies on triggered services because it means the
dependency runs after the triggered service comes up, not
just when the watcher-for-events starts
2024-06-09 22:37:45 +01:00
dan
2c10790a6d
think
2024-06-09 11:19:38 +01:00
dan
571adf84c0
inherit builtins.map
2024-06-07 16:55:45 +01:00
dan
c8c79fd75a
update all calls to uevent-watch
2024-06-02 20:42:09 +01:00
dan
884d8d194e
wrap uevent-watch in a service
2024-06-02 20:42:09 +01:00
dan
f091bbd706
devout: recognise attr,attrs when parsing search term string
2024-06-01 23:48:05 +01:00
dan
37d7e20582
wwan use uevent-watch to find tty for AT commands
2024-06-01 23:47:20 +01:00
dan
04b068f7a3
delete unused code
2024-06-01 22:43:48 +01:00
dan
53f57c1a8c
devout: support sysfs attributes for (grand*)parent device
2024-06-01 22:43:27 +01:00
dan
19aba0d873
devout: support search for sysfs attributes
2024-06-01 21:20:41 +01:00
dan
7d00b39249
rename attributes->properties when referring to uevent fields
...
properties: key-value pairs in the uevent message
attributes: file contents in sysfs
2024-06-01 12:17:49 +01:00
dan
7aa8633cde
think
2024-06-01 12:16:21 +01:00
dan
58bec8a40f
semi-automate tftpbooting with minicom
2024-05-26 18:03:32 +01:00
dan
a3fca5bf05
devout: add functions to read sysfs attributes
2024-05-26 18:03:32 +01:00
dan
e0bd7aec1e
wwan: hook usb-modeswitch to uevent
2024-05-26 18:03:32 +01:00
dan
e815f61bb5
think
2024-05-26 18:00:31 +01:00
dan
af9200a136
skip symlink handing unless linkname was provided
2024-05-26 18:00:31 +01:00
dan
898958fa10
make a serviceDefn for wwan
2024-05-22 18:54:49 +01:00
dan
fa0f262706
commentary
2024-05-22 18:54:49 +01:00
dan
71aeb27b2f
add hacky wwan service with hardcoding all over
2024-05-22 18:54:49 +01:00
dan
530b4080c9
create cdc-ncm module
2024-05-22 18:54:49 +01:00
dan
58cd007ccc
barebones usb_modeswitch package
2024-05-22 18:54:49 +01:00
dan
3a56798eb5
l2tp set default route via tunnel
2024-05-22 18:54:49 +01:00
dan
758c7ef657
exec xl2tpd
...
haven't fully worked out why, but without this s6 is unable to stop it.
2024-05-22 18:54:49 +01:00
dan
73225a70b2
add rudimentary l2tp service module
2024-05-22 18:54:49 +01:00
dan
ab304dd3f1
bordervm enable nat
2024-05-22 18:47:37 +01:00
dan
0d49f0f7a7
gl-ar750 appendDTB
2024-05-22 18:47:16 +01:00
dan
e64390460a
memorable net device names for gl-ar750
...
linux's view of eth1 and eth0 are opposite to that of u-boot
2024-05-22 18:47:08 +01:00
dan
c0ef6ce282
list pkgs we need in bordervm build
...
it's a bit silly trying to build it with the whole liminix overlay
when it's a nixos system not a liminix system
2024-05-22 18:45:35 +01:00
dan
bd6ec5201f
run dhcp server on bordervm
...
this is for testing clients that have dhcp upstream
2024-05-22 18:45:35 +01:00
dan
b4068da9fe
tftp addresses
2024-05-22 18:45:35 +01:00
dan
aa4b09da85
think (foreshadowing)
2024-05-22 18:45:23 +01:00
dan
471c63b399
s6-rc do cleanup in "finish", don't append to "run" script
...
s6-supervise sends signals (e.g. SIGTERM) to the pid of the process
running "run", so how do we know if the ceanup commands are even
getting executed if the shell interpreter that is supposed to do that
got killed already?
2024-05-13 17:53:02 +01:00
dan
782feaeafa
set default for firewall extraRules
2024-05-03 16:28:53 +01:00
dan
ac54c89427
add busybox to bordervm for udhcpd
2024-05-01 23:09:23 +01:00
dan
5a3646cb29
add authorized keys to bordervm
...
You don't often need this because it has autologin, but sometimes
you want to do antics involving sshing through it to the wan port
of a test device.
Note that you probably wanted to start bordervm with funny qemu
options to even make that possible
nix-shell --run "QEMU_NET_OPTS=hostfwd=tcp::10022-:22 run-border-vm"
2024-05-01 23:07:11 +01:00
dan
e249f48cff
add deps on {ins,rm}mod and kconfig for firewall module
2024-05-01 23:06:12 +01:00
dan
6661e42684
mt300a tftpboot needs appendDTB
2024-05-01 23:04:25 +01:00
dan
b9ba9ef835
mt300a remove unneeded service dependencies
2024-05-01 23:03:55 +01:00
dan
8b69dcc209
pass entire config fragment to levitate, not just services
...
to make it useful we need to be able to set packages, passwords, ssh
keys etc
2024-04-29 20:07:01 +01:00
dan
9b3a3b9ff7
add levitate to arhcive
...
this is largely untested
2024-04-28 21:38:13 +01:00
dan
7d08497bcb
arhcive remove coldplug fudge
2024-04-28 21:37:30 +01:00
dan
0e84adaa0e
maybe don't need deps for gl-mt300a vlan devices?
...
will delete them next time I have that device open to test
2024-04-28 21:35:09 +01:00
dan
660ed5df8f
vlan interface services depend on primary
2024-04-28 21:33:36 +01:00
dan
792a11c8c0
gl-mt300n-v2 use full path to swconfig in service stop
2024-04-28 21:32:42 +01:00
dan
7e4a05bbf8
separate kernel and base modules
...
this is needed for levitate
2024-04-28 12:44:27 +01:00
dan
a4ba5c85e1
alphabetize list in all-modules
2024-04-28 12:42:47 +01:00
dan
723ef73d5a
inout: test hotplug and coldplug
2024-04-27 22:41:30 +01:00
dan
3d4e782929
devout: run tests in postBuild
...
because checkPhase is not executed when cross-compiling, and this
package is always only cross-compiled
2024-04-27 21:07:25 +01:00
dan
1b6a05aec5
make uevent-watch use devout instead of direct netlink
2024-04-27 21:07:25 +01:00
dan
80628a3d90
move event matching tests to devout
...
in preparation for future uevent-watch not needing to do
event matching
2024-04-27 21:07:25 +01:00
dan
bf0cafffed
start devout alongside mdevd
...
ensure it starts before mdevd-coldplug so it can populate
its database
2024-04-26 20:52:12 +01:00
dan
e49aba127c
devout: improve socket error handling
2024-04-26 20:49:23 +01:00
dan
324465bc18
devout: write uevent KEY=value format to clients
2024-04-26 17:37:28 +01:00
dan
b33249a050
devout: add readiness notification
2024-04-26 17:23:29 +01:00
dan
b9c084415e
devout: handle readiness on netlink socket but no event
2024-04-26 17:20:33 +01:00
dan
cf9cadd212
devout: replay relevant events to new subscriber
2024-04-26 17:20:33 +01:00
dan
a116fe084a
devout: use socket constants from anoia.net.constants
2024-04-26 16:48:51 +01:00
dan
74cf3e0711
add anoia.net.constants for SOCK_{STREAM,DGRAM} etc
...
we use an ugly bit of C preprocessor to get the values from
header files, because certain constants are different on MIPS
than on other architectures
2024-04-26 16:43:09 +01:00
dan
9795f03da4
think
2024-04-26 16:41:31 +01:00
dan
cdb23b147c
convert anoia.fs to use lualinux
2024-04-25 21:14:37 +01:00
dan
dbd1264352
convert anoia.fs to use lualinux instead of lfs
2024-04-24 20:44:32 +01:00
dan
834858d5bc
think
2024-04-24 18:33:57 +01:00
dan
18335b95e3
devout: strip newlines from client terms
...
this is just to make testing with socat easier
2024-04-24 18:33:02 +01:00
dan
6bee2f67ac
devout: add incoming netlink messages to database
2024-04-24 18:32:27 +01:00
dan
b4ba3eea21
fix revents in unpack-pollfds
2024-04-24 18:31:26 +01:00
dan
16af3984c9
add lualinux to fennelrepl
2024-04-24 18:30:34 +01:00
dan
ce7e395295
devout test: replace minisock with lualinux
2024-04-24 18:29:24 +01:00
dan
7e13e017eb
add readline suport to fennelrepl
2024-04-24 18:28:39 +01:00
dan
bbf2f53c0e
cross-compile lualinux
2024-04-24 18:28:14 +01:00
dan
032d0f8aca
add netlink socket
...
it's not hooked up to anything yet, but it proves we can
do this with lualinux
2024-04-23 23:34:25 +01:00
dan
b8ac9e5279
convert devout from minisock to lualinux
2024-04-23 23:33:11 +01:00
dan
ff2604ca5d
think
2024-04-23 23:30:50 +01:00
dan
72789984ce
add lualinux package
2024-04-23 22:41:38 +01:00
dan
90d9d0e811
update minisock to not scribble on lua strings
2024-04-23 20:19:33 +01:00
dan
97a8ae1c84
devout: add event loop and main run function
2024-04-23 20:15:02 +01:00
dan
52eb283a26
implement unsubscribe
...
and add ids to subscribe so that there's a unique identifier
to pass to unsubscribe
2024-04-23 20:12:46 +01:00
dan
cbb1de804e
switch to minisock fork witj poll() call
...
this is likely to be temporary as minisock is getting
replaced with lualinux
2024-04-23 20:09:41 +01:00
dan
f9c03998b8
implement subscriptions with callback
2024-04-21 13:19:17 +01:00
dan
50de1b090f
add the rest of the test list (all we've thought of)
2024-04-21 11:22:26 +01:00
dan
648382f64a
report bodyless tests as PENDING
2024-04-21 11:19:42 +01:00
dan
e9370358ae
implement "remove" events
2024-04-21 11:19:06 +01:00
dan
762ce7b6b8
cut/paste devout implementation into a real module
2024-04-20 22:48:00 +01:00
dan
b1c0560f4f
implement fetch by path
2024-04-20 22:20:43 +01:00
dan
e34135c41a
improve failed test reporting
2024-04-20 21:46:37 +01:00
dan
712c9b266f
implement find
2024-04-20 18:42:42 +01:00
dan
4df963996c
devout: add device
2024-04-20 18:24:10 +01:00
dan
349bfecbb8
new package "devout", does nothing yet
2024-04-20 17:45:40 +01:00
dan
450d3820b2
clean up uevent-watch test using writeFennel and mainFunction
...
requires less cavorting with globals and stuff
2024-04-20 16:53:43 +01:00
dan
771585546d
import expect= where previously it was copy-pasted
2024-04-20 15:09:50 +01:00
dan
73abf952d5
package minisock, a minimal Lua socket library
2024-04-20 15:09:17 +01:00
dan
8af4e9fd5b
package anoia assert macros and point fennelrepl at them
2024-04-20 14:59:14 +01:00
dan
7e19d80130
anoia: add assert macro module
...
contains expect and expect=
2024-04-20 14:04:32 +01:00
dan
0f0688c802
think
2024-04-20 14:03:48 +01:00
dan
b43f17f655
think
2024-04-20 12:23:04 +01:00
dan
adf62d4483
arhcive: make it work when disk is attached before boot
...
This is a bit of a kludge (a lot of a kludge) but it will
get it running whilt I work on something better
2024-04-17 18:49:30 +01:00
dan
68eb1360f6
use appended dtb in gl-mt300n-v2 tftpboot
...
probably the A variant needs this as well
2024-04-17 18:48:19 +01:00
dan
19ad6cd278
watchdog: put s6 pkg on $PATH for s6-svstat
2024-04-17 13:01:10 +01:00
dan
00076c7b81
mount service: use uevent-watch
2024-04-17 12:59:13 +01:00
dan
721e7499f3
arhcive: use usb module instead of harcoded kconfig
2024-04-17 12:53:43 +01:00
dan
fc723b9a35
think
2024-04-16 18:59:01 +01:00
dan
a5f16dfa81
convert inout test to use uevent-watch
2024-04-15 22:15:27 +01:00
dan
41a4b1f7ef
clean cruft from inout test script
2024-04-15 22:00:44 +01:00
dan
42a5699326
remove unneeded config from inout test
2024-04-15 21:19:18 +01:00
dan
ea2b25168e
add uevent-watch, which toggles services based on uevent msgs
2024-04-15 21:15:07 +01:00
dan
5564cf0554
add nellie.close
2024-04-14 22:45:29 +01:00
dan
f3a13630d3
add multicast groups param to nellie.open
2024-04-14 22:45:29 +01:00
dan
f233acf9ff
netlink uevent hello world
2024-04-14 22:45:29 +01:00
dan
b6a054c588
add mdevd as module
...
following the upstream example, it republishes uevent messages
using multicast group 4 instead of group 2 as used by udev.
2024-04-14 21:59:23 +01:00
dan
b231664a06
anoia: add basename, dirname
2024-04-11 23:11:20 +01:00
dan
f4bf3029fa
anoia: alphabetize exports
2024-04-11 23:11:13 +01:00
dan
05f2c9a2f7
add lua in nix-shell environment
2024-04-11 23:11:06 +01:00
dan
5df5c822ea
convert mount service to trigger
...
Good: this means it's not hanging holding the s6 dataase lock.
Bad: it's the ugliest implementation and doesn't deserve to be preserved
(tbf the ugliness is not new)
2024-04-03 23:17:36 +01:00
dan
4795dd05b7
unconditionally restart trigger services on liminix-rebuild
...
We call s6-rc -u -p default to restart/start the base services
on a rebuild, otherwise services that are only in the new
configuration won't come up. However, this stops any service
started by a trigger. So, workaround is to restart the trigger
service and expect it to restart the services it manages if they're
needed
2024-04-03 23:07:56 +01:00
dan
a192f08881
remove missing module
2024-03-29 17:34:10 +00:00
dan
a873dc6608
Merge commit 'efcfdcc'
2024-03-28 23:47:04 +00:00
dan
2fb4756a7f
add soft restart option to liminix-rebuild
...
instead of doing a full reboot, it runs activate / and uses
s6-rc-update to install the new service database
2024-03-28 23:45:10 +00:00
dan
04f5174425
fix vanilla-configuration defaultroute
2024-03-28 22:13:21 +00:00
dan
dca2e4def1
fix params to s6-rc-init
...
flags must precede scandir otherwise they're ignored
2024-03-28 21:56:28 +00:00
dan
b60126775a
improve liminix-rebuild test
...
* make it executable
* improve robustness
* do't hardcode services.default (why did it do this?)
2024-03-28 21:37:47 +00:00
dan
76f11bcc93
liminix-rebuild: remove -f flag from reboot call
...
now we have timeouts in service definitions, shouldn't need this
any more
2024-03-28 21:37:47 +00:00
dan
efcfdcc21d
think
2024-03-28 20:59:39 +00:00
dan
77f1a78331
ifwait block if s6-rc lock is held
...
otherwise it doesn't trigger the service if something else is
slow to start
2024-03-28 20:59:39 +00:00
dan
28a5dec7dd
implement ifwait trigger service and use in bridge
...
should we convert all ifwait uses to this trigger too? seems
reasonable
2024-03-28 20:59:39 +00:00
dan
fad0a47b75
add config.system.callService
...
this is like pkgs.callService except that it passes
config.system.service as a param so that the service
being defined can invoke other services
if this proves to be a good idea, all uses of
pkgs.callService should be changed to use it instead
2024-03-28 20:59:39 +00:00
dan
af52aafc84
deep thoughts
2024-03-28 20:59:39 +00:00
dan
34442b6069
failing test for ifwait
2024-03-28 20:59:39 +00:00
dan
b8a46fc05e
allow buildInputs param to s6 service
...
this is in preparation for trigger services that need to
close over the triggered service without adding it to
s6-rc dependencies
2024-03-28 20:58:53 +00:00
dan
8ac2c6cec1
support timeouts (default 30s) for starting s6-rc services
2024-03-28 20:58:47 +00:00
dan
8879b2d1ba
fix rt2x00 wifi
2024-03-28 20:58:39 +00:00
dan
83e346d5a0
add deviceName param
2024-03-22 21:55:44 +00:00
dan
156b1fe64a
deep thoughts
2024-03-22 21:54:38 +00:00
dan
1a314e55b7
firewall module: provide default rules and merge extraRules
...
a firewall with no configuration will get a relatively sane ruleset. a
firewall with `extraRules` will get them deep merged into the default
rules. Specifying `rules` will override the defaults
2024-03-21 12:00:34 +00:00
dan
9263b21faa
create gateway profile by extracting from rotuer example
2024-03-21 10:04:42 +00:00
dan
0a820a702a
extneder: delete nftables kernel config
...
don't need nftables on a bridge. (do we? hope not)
2024-03-20 19:05:31 +00:00
dan
4ea518e296
expose modulesPath to ease out-of-tree configuration.nix
2024-03-20 18:58:44 +00:00
dan
98318b450d
deep thoughts
2024-03-16 20:16:49 +00:00
dan
e4ac7f19dc
fix ifwait deps
2024-03-16 20:16:49 +00:00
dan
9c22744850
deep thoughts
2024-03-16 20:16:49 +00:00
dan
c697be8c28
temporary fix for cmake cross-compilation
2024-03-16 20:16:49 +00:00
dan
202a37221a
Merge pull request 'tftpboot: use commandLineDtbNode' ( #11 ) from flokli/liminix:tftpboot-honor-commandLineDtbNode into main
...
Reviewed-on: dan/liminix#11
2024-03-16 18:18:18 +00:00
flokli
436eb03a7b
tftpboot: use commandLineDtbNode
...
config.boot.commandLineDtbNode can be set from `bootargs` to
`bootargs-override` (used for boards where the u-boot on the board does
set `bootargs` on its own).
In that case, the code updating the cmdline for tftpboot purposes also
needs to update this node, not the `bootargs` node.
Otherwise the kernel won't find the phram device, as it never heard
about it, as it didn't get the necessary cmdline options.
2024-03-16 20:06:38 +02:00
dan
e5963ae3f7
deep thoughts
2024-03-06 23:19:47 +00:00
dan
f164f19d95
service starts and stops
2024-03-06 23:19:47 +00:00
dan
dd4ab41f6a
rename run-event
2024-03-06 23:19:47 +00:00
dan
5d5dff6729
WIP add failing test that service starts
2024-03-06 23:19:47 +00:00
dan
570d29c368
pass command line params to run instead of reffing global
2024-03-06 23:19:47 +00:00
dan
725af00dc9
improve test for dummy0 up
...
if we run off the end of the events fixture, it didn't work
2024-03-06 23:19:47 +00:00
dan
e1b932ec27
remove hardcoded filename in test event generator
2024-03-06 23:19:47 +00:00
dan
7173b6fb1c
don't call os.exit
2024-03-06 23:19:47 +00:00
dan
ed9548f21d
pass event producer fn as param
2024-03-06 23:19:47 +00:00
dan
0787807a7f
ifwait: don't run on load if in test harness
2024-03-06 23:19:47 +00:00
dan
38ed91f641
simplify assertion
2024-03-06 23:19:47 +00:00
dan
ffe9603c39
remove file-scoped parameters var
2024-03-06 23:19:47 +00:00
dan
cbd3dfefc5
ifwait fixture/test harness
2024-03-06 23:19:47 +00:00
dan
018c1868b5
ifwait: use anoia.assoc
2024-03-06 23:19:47 +00:00
dan
5184ff63f7
add anoia.nl, a convenience wrapper on netlink
2024-03-06 23:19:47 +00:00
dan
35909c9a23
add netlink to fennelrepl
2024-03-06 23:19:47 +00:00
dan
4383462199
deep thoughts
2024-03-06 23:19:47 +00:00
dan
9730cdd63b
add assoc to anoia
2024-03-06 23:19:47 +00:00
dan
095853214b
Merge pull request 'Fix kernel build on belkin' ( #10 ) from sinavir/liminix:fix_kernel_build_on_belkin into main
...
Reviewed-on: dan/liminix#10
2024-03-06 18:21:13 +00:00
dan
9d6e50cbbc
extract extneder example to a "profile"
...
this is a bit of an experiment to reduce the copy-paste in
examples by turning them into "application" modules.
planning to follow up with another module for "wifi router"
2024-02-27 23:13:12 +00:00
dan
94dbc56595
fix doc
2024-02-27 20:08:30 +00:00
dan
2cd7f932eb
alignment may be null
2024-02-27 19:47:46 +00:00
sinavir
27c7735f02
belkin-RT3200: fix kernel options
2024-02-22 21:57:40 +01:00
sinavir
29c9de248d
fix import of openwrt sources
2024-02-22 21:57:33 +01:00
dan
3ca0d87c27
ci.nix: alphabetise systems
2024-02-21 19:49:14 +00:00
dan
8f30db58ae
New port to Zyxel NWA50AX: update NEWS and ci.nix
2024-02-21 19:32:50 +00:00
dan
f9ab0590a6
Merge remote-tracking branch 'raito/nwa50ax'
2024-02-21 19:27:23 +00:00
dan
84fa8d65f4
fennel: system: verbose log of command that was run
2024-02-21 19:27:14 +00:00
dan
9b0149ecb7
deep thoughts
2024-02-21 19:26:33 +00:00
Raito Bezarius
baf3cf7413
devices/zyxel-nwa50ax: fix dual image mgmt after DTB expansion
...
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-19 03:13:35 +01:00
Raito Bezarius
c5145b5fc9
devices/zyxel-nwa50ax: make zyxel-bootconfig executable
...
Otherwise, it doesn't work well…
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-19 03:13:21 +01:00
Raito Bezarius
628f4dfdbe
devices/zyxel-nwa50ax: developer todo
...
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-19 03:13:21 +01:00
Raito Bezarius
da59e2a349
devices/zyxel-nwa50ax: complete documentation
...
It covers everything I know more or less.
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-19 02:57:34 +01:00
Raito Bezarius
c0a9571a13
devices/zyxel-nwa50ax: upgrade MT7915 firmware from OpenWRT repository
...
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-19 02:57:34 +01:00
Raito Bezarius
d6ffdd7be6
devices/zyxel-nwa50ax: expose primary and secondary images
...
To support A/B a bit better.
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-19 02:57:34 +01:00
Raito Bezarius
985f982435
examples/nwa50ax-ap: support bridge between lan and ethernet
...
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-19 02:48:50 +01:00
Raito Bezarius
a893c0dc4c
devices/zyxel-nwa50ax: use our own more advanced DTB
...
OpenWRT had a DTB for the NWA50AX LEDs that I didn't pick up.
Anyway, we need to include our own special DTB for the NWA platform in general
to support A/B operations, because OpenWRT original one just mark everything else read-only.
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-19 02:48:50 +01:00
Raito Bezarius
3ec29dc1b9
examples/nwa50ax-ap: ensure mtdutils is available for further flashing
...
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-19 02:48:50 +01:00
Raito Bezarius
0e81953b67
devices/zyxel-nwa50ax: cleanup of flash attribute and rootDevice
...
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-19 02:48:50 +01:00
Raito Bezarius
3c70a0d037
devices/zyxel-nwa50ax: ensure bridge is always available
...
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-19 02:48:50 +01:00
Raito Bezarius
422f3edab1
modules/zyxel-dual-image: init
...
This adds a simple boot blessing module, to be used, with the Zyxel NWA50AX.
There's a lot of elephant in the rooms: how do you upgrade kernel, etc.
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-19 02:48:50 +01:00
Raito Bezarius
c14b2f6356
modules/busybox: add dhcprelay
...
This enables to run a DHCP relay from multiple interfaces.
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-19 02:48:50 +01:00
Raito Bezarius
cdafff2095
examples/nwa50ax-ap: init
...
This is a quite comprehensive example using maximally the hardware
available to reach nice performance.
In the future, I will even add RADIUS examples.
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-19 02:48:50 +01:00
Raito Bezarius
13f1bb9f52
devices/zyxel-nwa50ax: init
2024-02-19 02:48:48 +01:00
Raito Bezarius
019fef6929
zyxel-bootconfig: init at no version
...
This tool is useful for manipulating the A/B boot status of the image.
2024-02-18 20:30:41 +01:00
Raito Bezarius
63007859c2
modules/outputs/zyxel-nwa-fit: init
...
Zyxel "firmware" format is just… a FIT with some metadata on the models.
This FIT is like this:
--------------------------
uImage FIT header
--------------------------
Linux kernel
--------------------------
FDT DTB
--------------------------
Padding so that
this makes
8192kb [1]
--------------------------
UBI volume
as a root filesystem
--------------------------
We just reproduce this in a very brutal and naive way.
In the future, this seems worth to generalize and modularize this idea
so that zyxel-nwa-fit is just an instance of a more general output.
[1]: https://git.openwrt.org/?p=openwrt/openwrt.git;a=blob;f=target/linux/ramips/image/mt7621.mk;h=ab1b829ba0086cb9fc9ca8cbbf3cbc14735034d6;hb=refs/heads/main#l3097
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-18 20:30:41 +01:00
Raito Bezarius
e9ab8d7183
modules/outputs/ubivolume: introduce ubinization
...
It creates an UBI image based on an UBI volume configuration.
For now, it creates only an empty rootfs.
2024-02-18 20:30:41 +01:00
Raito Bezarius
3dc58de0eb
modules/outputs: expose commandLineDtbNode option
...
We allow `bootargs` and `bootargs-override` for now only.
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-18 20:30:41 +01:00
Raito Bezarius
dde8386f75
builders/uimage: support aligning the FIT
...
This is necessary when writing to a MTD partition with a certain erasesize.
2024-02-18 20:30:41 +01:00
Raito Bezarius
c59364d623
modules/outputs/ubifs: expose rootubifs rather than rootfs
...
I believe there should be another module exposing `rootubifs` as `rootfs`
or let any other module just subsume that component like `zyxel-nwa-fit` output.
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-18 20:30:41 +01:00
Raito Bezarius
b76c5b4abe
modules/ubifs: revamp to offer directly access to the UBIfs partition
...
Adds the LEB and PEB option and let the user remove the boot image in case
where U-Boot does not support UBI boot.
2024-02-18 20:30:41 +01:00
Raito Bezarius
0a8343be66
pkgs/kernel/uimage: introduce commandLineDtbNode
...
Certain devices like the Zyxel NWA50AX will pass information on the command-line
to explain what is the current image (`bootImage=1` vs. `bootImage=0`).
Unfortunately, if we set the `chosen/bootargs` node, this will be overridden forcibly
by U-Boot.
To avoid this problem, it's easier to simply just use another DTB node like `bootargs-override` which
is what OpenWRT does [1].
[1]: https://git.openwrt.org/?p=openwrt/openwrt.git;a=blob;f=target/linux/ramips/patches-5.15/314-MIPS-add-bootargs-override-property.patch;h=e7dca7af886e8c0b69ba2b23f5855ddfeeb0d4a1;hb=refs/heads/main
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-18 20:30:41 +01:00
Raito Bezarius
d14ee41325
liminix-rebuild: use -f flag to reboot effectively
...
My AP does not reboot upon `reboot` but `reboot -f`… why?
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-17 11:45:17 +00:00
Raito Bezarius
8f814658fe
hostapd: enable 802.11ax
...
For people enjoying WiFi 6 heaven… :>
Signed-off-by: Raito Bezarius <masterancpp@gmail.com >
2024-02-17 11:45:10 +00:00
dan
60508f4d4e
update NEWS
...
* Turris Omnia
* possible wifi regressions
2024-02-16 21:00:59 +00:00
dan
ca64e9035e
gl-ar750 ath9k needs cal data from MTD
2024-02-16 20:44:56 +00:00
dan
4bcc3d5b28
dhcpc6 scripts: simplify (and improve correctness)
2024-02-16 18:47:12 +00:00
dan
28fe37d555
deep thoughts
2024-02-16 18:30:54 +00:00
dan
175db9f604
tail -F for rotuer
2024-02-16 18:30:24 +00:00
dan
b5722a0153
gl-ar750: ath10k wireless depends on firmware
...
so make sure the firmware is present _first_
the ath10k is still broken anyway, looking into why
2024-02-16 00:38:36 +00:00
dan
c373152673
make tftpboot work on devices with old u-boot
...
Some devices have a U-boot variant that does not accept a third
parameter on the "bootm" command, meaning we can't override the dtb
in the bootloader so have to smush it back into the kernel image
This doesn't work in QEMU but I think the problem is with the
U-Boot configuration for QEMU. It does work on at least one
hardware device so I'm pushing it anyway
Based on
https://gti.telent.net/raboof/liminix/src/branch/tftp-old-uboot
Co-authored-by: Arnout Engelen <arnout@bzzt.net >
2024-02-15 23:44:47 +00:00
dan
7e7171556f
subdue dnsmasq logs
...
we need to find a better way of doing this. people might _want_
to have All The Logs from evey dns query
2024-02-15 23:43:54 +00:00
dan
6920ee765d
deep thoughts
2024-02-15 09:11:54 +00:00
dan
71a1ef286e
deep thoughts
2024-02-13 22:32:57 +00:00
dan
ffe0e9d26b
use mkstate for dropbear keys
2024-02-13 22:12:26 +00:00
dan
2b22c7aa91
dnsmasq: store dhcp lease file on /persist
2024-02-13 21:54:45 +00:00
dan
3c950704e1
rename /run/service-state to /run/services/outputs
2024-02-13 21:41:43 +00:00
dan
8578a554c7
deep thoughts
2024-02-13 21:11:30 +00:00
dan
3851698d35
fix tftpboot compressed rootfs
2024-02-13 18:16:17 +00:00
dan
f69ebbb6f5
fix doc CI target
2024-02-13 15:41:45 +00:00
dan
16e4b05653
dhcp6c: set preferred and valid address lifetimes
...
also workaround a bug in rebinding/updates where we get an error
from "ip addr add" trying to add an address that's already present
2024-02-13 13:49:12 +00:00
dan
8ac848b1e6
ath10k_pci: wifi modules must be modules
2024-02-13 12:56:03 +00:00
dan
b7efbd3e21
update NEWS file
2024-02-12 21:10:52 +00:00
dan
a654577ac2
improve port-forwarding comment
2024-02-12 21:05:01 +00:00
dan
c50423f689
turris omnia: upgrade to mainline 6.7.4 kernel
...
On this device we don't need the openwrt kernel or patches. The
newer kernel also fixes the weird one minute pause at boot when
it was doing something with either mmc or switch.
2024-02-12 20:43:01 +00:00
dan
65479e206b
use regular kernel not backports for mac80211
...
the kernel on most devices is now newer than the version that the
backported drivers were backported from
2024-02-12 20:41:10 +00:00
dan
79926c6fe7
remove call to deleted package
2024-02-12 14:56:12 +00:00
dan
ae4856ea7c
improve firewall comment
2024-02-12 13:56:56 +00:00
dan
b9c0d93670
build modules at same time as main kernel vmlinux
...
This changes the practice for building kernel modules: now we expect
that the appropriate Kconfig symbols are set to =m in
config.kernel.config, and then use pkgs.kmodloader to create
a service that loads and unloads all the modules depended on by
a particular requirement.
Note that modules won't be installed on the target device just by
virue of having been built: only the modules that are referenced by a
kmodloader package will be in the closure.
An example may make this clearer: see modules/firewall/default.nix
in this commit.
Why?
If you have a compiled Linux kernel source tree and you change some
symbol from "is not set" to m and then run make modules, you cannot in
general expect that newly compiled module to work. This is because
there are places in the build of the main kernel where it looks to see
which modules _may_ be defined and uses that information to
accommodate them.
For example in an in-kernel build of
https://github.com/torvalds/linux/blob/master/net/netfilter/core.c#L689
some symbols are defined only if CONFIG_NF_CONNTRACK is set, meaning
this code won't work if we have it unset initially then try later to
enable it and build modules only. Or see
https://github.com/torvalds/linux/blob/master/include/linux/netdevice.h#L160
2024-02-11 23:47:11 +00:00
dan
11287a8436
allow lan dns queries (ipv6)
2024-02-11 23:32:46 +00:00
dan
57aece0709
rotuer: don't forward queries for local domain
2024-02-11 23:32:46 +00:00
dan
c1d285a220
rotuer: network debugging tools
2024-02-11 23:32:46 +00:00
dan
dce983ec79
move kernel module to its own subdir
2024-02-11 18:15:55 +00:00
dan
812f497660
add kernel.version param to allow for version-specific patches
...
default to 5.15.137 to avoid breaking the devices that don't declare it
2024-02-11 16:19:52 +00:00
dan
1206d02200
rotuer-secrets: remove root_password, add wifi ssid and domainName
...
this is step one towards getting rid of rotuer-secrets completely and
turning rotuer into a "profile" module that can be less hackily
customised for other people's networks
2024-02-11 15:56:14 +00:00
dan
7c196bf9b4
rotuer: make 5GHz wifi faster
...
VHT doesn't work unless HT is enabled, apparently
2024-02-11 15:38:19 +00:00
dan
86d19c54b3
turris omnia kernel: add RTC, i2c mux, eeprom
2024-02-09 22:34:46 +00:00
dan
aca3e11631
firewall: make ipv4 work
2024-02-08 23:15:48 +00:00
dan
273c66b2d3
Merge pull request 'Add support for TP-Link Archer AX23' ( #6 ) from raboof/liminix:add-archer-ax23-v1-bak into main
...
Reviewed-on: dan/liminix#6
2024-02-08 17:47:46 +00:00
dan
87f6a31a06
improve firewall log format
2024-02-08 17:21:26 +00:00
dan
a9ea01428e
firewall: don't drop in conntrack rule
...
as there are other rules following that might want to accept
2024-02-08 17:20:39 +00:00
dan
92b0bec038
rotuer: add schnapps and the rest of the lan interfaces
2024-02-07 23:48:10 +00:00
dan
82537bbe68
delete commented-out code
2024-02-07 23:47:38 +00:00
dan
efb29c5901
demo-firewall: add some rules for ipv4
2024-02-07 23:47:09 +00:00
dan
29e61be26c
rotuer: get lan rfc1918 prefix from secrets
2024-02-07 23:46:16 +00:00
dan
6f1f9d6f20
firewall: fix module loading
2024-02-07 23:43:41 +00:00
dan
34291292c0
fix dependency on kernel moduels in firewall service
2024-02-07 16:21:14 +00:00
dan
c9e4c1b0da
kernel-modules: use linuxArch instead of case expression
2024-02-07 16:20:34 +00:00
Arnout Engelen
63e3f2aa58
Add support for TP-Link Archer AX23
2024-02-06 18:00:55 +01:00
Arnout Engelen
61494fdc0c
Add tplink module for creating 'safeloader' images
2024-02-06 17:59:38 +01:00
dan
891d6e5f20
thenk
2024-02-05 19:20:13 +00:00
dan
c4041b00f6
Merge pull request 'docs: add hardware recommendation' ( #2 ) from raboof/liminix:hardware-recommendations into main
...
Reviewed-on: dan/liminix#2
2024-02-05 15:56:07 +00:00
dan
f875622100
improve formatting
2024-02-04 18:24:01 +00:00
dan
49ec4a2961
installation instructions for Turris Omnia
...
feels like a milestone, or at least a big step towards one
2024-02-04 18:20:04 +00:00
dan
c8154a2db9
kernel: add "conditional" config
...
imagine: you are using a device that requires
CONFIG_MYDEVICE_FROBOZZ_DRIVER but only if CONFIG_FROBOZZ has been
specified elsewhere. Because we check that every requested config
symbol actually appears in .config then it can't be added
unconditionally or the build will fail if CONFIG_FROBOZZ wasn't asked
for.
I'm not 100% happy about this design but it's the best I've thought of
so far.
2024-02-04 18:12:15 +00:00
dan
02cf2c6b80
add ssh keys in recovry image
2024-02-04 18:10:58 +00:00
dan
b0709a6443
systemconfig: fix missing backslashes on env vars
2024-02-04 17:19:03 +00:00
dan
86f5c9b568
schnapps needs util-linux for mount
...
specifically, it expects mount /dev/foo -o blah /dest to work,
but busybox mount expects options to precede all the other
command line args
2024-02-04 15:50:25 +00:00
dan
ef707de8b1
add extlinux in recovery example
...
this needlessly bloats the TFTP image, which is a shame, but is
needed for installing onto usb stick
2024-02-02 19:51:41 +00:00
dan
89c88dd472
specify type for rootDevice module option
2024-02-02 19:50:13 +00:00
dan
c1ad139310
whitespace
2024-02-02 19:43:34 +00:00
dan
f682b26c29
omnia seems very fussy about tftp load address
...
when loading with 0x1000000 base address, something was getting
corrupted in the uncompressed rootfs
$ head -c $(printf "%d" 0x2be0000) rootfs | sha1sum
142571fe0436c18191727d1d4c2fd32163c1f2e1 -
=> sha1sum 0x1000000 2be0000
sha1 for 01000000 ... 03bdffff ==> 142571fe0436c18191727d1d4c2fd32163c1f2e1
but!
$ head -c $(printf "%d" 0x2bf0000) rootfs | sha1sum
7aa004ba87c6772bade491fbade164e2dfe100f9 -
=> sha1sum 0x1000000 2bf0000
sha1 for 01000000 ... 03beffff ==> 1a0923a94784d0c0b86006c5e6fff1649770dad3
2024-02-02 19:36:11 +00:00
dan
84ce618213
recovery: grow fs to partition size before starting sshd
...
sshd expects there to be space in /persist/secrets that it can
use to write host keys, but when we make ext4fs images we don't
put any free space in them
2024-01-28 11:30:19 +00:00
dan
9e199c6957
tftpboot: compute dtbSize *after* changing dtb
...
Adding the reserved-memory node to the dtb can cause it to grow
by enough that it needs an extra page - this will overlap the start
of the kernel image if we calculate offsets based on the original size
Reported-by: sinavir
Authored-by: sinavir
2024-01-26 22:51:58 +00:00
dan
c8e3d84bf4
think
2024-01-26 22:46:36 +00:00
dan
dd8ec18881
restore boot.tftp.freeSpaceBytes
2024-01-26 22:46:36 +00:00
dan
1730cf07b1
bug workaround
...
If we set squashfs rootfsType, the image doesn't rebuild when
the kernel config is changed. Need to figure out why
2024-01-26 22:46:36 +00:00
dan
de51bfe13d
default root device in recovery to sda1
...
It will probably work fine for USB-stick boot (except in the case
where there is > 1 usb device plugged in, so maybe don't do that)
It doesn't matter for TFTP boot because boot.scr overrides the root=
param anyway
2024-01-26 22:46:36 +00:00
dan
b09723345c
don't put all of util-linux in recovery
...
it adds ~ 5MB to the image size
2024-01-26 22:46:36 +00:00
dan
1781d4b6e4
add lzma to buildenv
2024-01-26 22:46:36 +00:00
dan
c219350d7c
add usb storage for turris omnia
...
ideally we would make this a module instead of compiling in
directly
2024-01-26 22:46:36 +00:00
dan
6f83282ff5
Merge pull request 'openwrt: update to v23.05.2' ( #4 ) from raboof/liminix:openwrt-update-to-v23.05.2 into main
...
Reviewed-on: dan/liminix#4
2024-01-26 22:39:11 +00:00
Arnout Engelen
04895f9cf6
openwrt: update to v23.05.2
2024-01-25 12:29:03 +01:00
dan
5f2d1660bd
Merge pull request 'belkin-rt3200: Enable watchdog drivers' ( #3 ) from sinavir/liminix:add_belkin_watchdog into main
...
Reviewed-on: dan/liminix#3
2024-01-24 14:36:08 +00:00
sinavir
7642e23c0a
belkin-rt3200: Enable watchdog drivers
2024-01-24 13:38:55 +01:00
dan
83ee488e4c
systemconfig: /boot needs to go inside /persist
2024-01-09 13:10:02 +00:00
dan
f19a937eda
omnia needs MARVELL_PHY for the WAN port to work
...
interestingly, we only see this when it boots from mmc, because
for tftpboot the bootloader has already performed negotiation
and therefore it works despite the missing option.
2024-01-09 13:07:14 +00:00
dan
f0490f37d5
turris omnia: tidy config, remove dead bits
2024-01-08 19:22:42 +00:00
dan
c1101d3af5
make extlinux work with liminix-rebuild
...
add /boot to the systemConfiguration closure
2024-01-08 18:58:07 +00:00
dan
9a3d7a387e
correct turris omnia root device
2024-01-08 18:55:41 +00:00
dan
228c0a1668
pass rootOptions config as rootflags= kernel cmdline opt
2024-01-08 18:54:49 +00:00
dan
63f034e362
preinit: parse rootflags= in kernel command line
2024-01-08 00:35:13 +00:00
dan
6971d03520
preinit: check return from write()
2024-01-07 21:24:16 +00:00
dan
7bc9cb6c55
why is extlink hardcoding root device?
2024-01-07 20:30:23 +00:00
dan
a251ceeb99
omnia releng
2024-01-07 16:54:44 +00:00
dan
38a7f0b03b
turris omnia: add all lan devices
...
I think we might turn "lan" into a bridge, but that's for later
2024-01-07 16:54:44 +00:00
dan
c0c4752350
systemconfig "install" cmd honours prefix on source
2024-01-07 16:54:44 +00:00
dan
3c941b4ce2
partial btrfs support
...
doesn't actually know how to make the filesystem, just
kernel config and accept it as a valid option
2024-01-07 16:43:43 +00:00
dan
243295aab8
recovery config for turris omnia
2024-01-07 14:58:46 +00:00
dan
45e8db09e1
liminix-rebuild: escape brackets in usage message
2024-01-07 14:18:19 +00:00
dan
2a93f24a58
add turris "schnapps" tool
...
in its current state this is useful for turris omnia only, but will
allow us to do installs and rollback to turris os if needed.
2024-01-05 00:07:01 +00:00
dan
64898eada8
mount tmpfs on /tmp
...
too much stuff doesn't work without it and it's not
all worth patching
2024-01-04 23:22:02 +00:00
Arnout Engelen
d5026c2074
docs: add hardware recommendation
...
Also add infrastructure to also generate the supported hardware
page when building the docs locally
2024-01-04 14:35:00 +01:00
dan
136c5e6f32
alphabetize package list
2024-01-04 10:15:23 +00:00
dan
fa9a2c6413
add btrfs-progs
2024-01-04 09:33:44 +00:00
dan
049cdbb610
turris omnia: don't hardcode rootfsType
2024-01-03 20:18:07 +00:00
dan
5ee4adff10
NEWS: we now expect Liminix 23.11
2024-01-03 19:44:49 +00:00
dan
9632a64b47
tftpboot: don't rely on hostname being set
2024-01-03 19:40:00 +00:00
dan
fc5def2e15
don't need ubifs u-boot patch now
...
23.11 has upgraded to a newer u-boot that has ubifs by default
in the qemu-arm config
2024-01-03 19:12:46 +00:00
dan
9369fdf314
use patched qemu only for run-liminix-vm
2024-01-03 17:53:30 +00:00
dan
d2e29543e2
bordervm: build wireshark without qt
...
(we only want tshark anyway)
2024-01-03 17:02:31 +00:00
dan
dad7c2c875
don't overlay util-linux, rename to -small
...
looks like it's used in bootstrapping
2024-01-03 10:45:40 +00:00
dan
3459c04f64
don't need SDL in our custom qemu
2024-01-03 10:09:10 +00:00
dan
ff991508ae
build kernel only once for multiple outputs
...
e.g. vmlinux + zImage
2024-01-02 19:40:57 +00:00
dan
e4ed9dbec9
delete dead comment
2024-01-02 18:10:56 +00:00
dan
9e0ef68c1f
omnia: add MMC block device support
2024-01-02 18:09:44 +00:00
dan
870e4d86cc
omnia: support fw_{print,set}env commands
2024-01-02 18:09:12 +00:00
dan
d6f96c0448
add libubootenv package
2024-01-02 17:44:56 +00:00
dan
e7747832ad
turris-omnia: reindent
2024-01-01 20:24:47 +00:00
dan
921b4f24af
boot.scr: append ; not \n to lzmadec command
...
this is simply to make copy-paste slightly more convenient
2024-01-01 20:21:42 +00:00
dan
e505e37d9a
build util-linux without systemd
...
this didnt work before but it does now, maybe because we
upgraded nixpkgs 23.05->23.11
2023-12-30 22:26:12 +00:00
dan
2152a3f207
a test for liminix-rebuild
...
it's hacky as Selby, but it's better than no test
2023-12-29 22:11:04 +00:00
dan
ec1ff283da
vmdisk output: allow extra params to run.sh
2023-12-29 18:12:57 +00:00
dan
0bf98c5243
add output for u-boot
2023-12-29 17:07:47 +00:00
dan
dc42969ef6
dribble
2023-12-29 16:54:35 +00:00
dan
1a041392aa
liminix-rebuild: add --no-reboot param
2023-12-27 17:47:42 +00:00
dan
6469408d5f
run-liminix-vm: don't reverse order of --flags params
2023-12-26 21:59:00 +00:00
dan
f020d5b25d
qemu mips: enable rebooting
2023-12-26 21:58:18 +00:00
dan
e5cbc2b86b
WIP add systemConfiguration "install" command
...
which copies the init stuff (whatever it is) from store to /persist
instead of making liminix-rebuild have to know what the files are.
This is principally to ease making a system configuration in /mnt or
similar when operating in a rescue/recovery scenario, and we
don't want to liminix-rebuild because it will reboot
2023-12-23 23:53:47 +00:00
dan
29f35cb902
min-copy-closure: add --root to copy to non-standard place
2023-12-23 23:12:40 +00:00
dan
dbf1ecdcb7
swap zimage and dtb in ram
...
kernel uncompression code creates a stack directly
after the compressed payload, which was trashing the dtb
2023-12-23 15:38:32 +00:00
dan
aecc44aaa0
run-liminix-vm: --flag parameter passes arg straight to qemu
2023-12-23 15:32:59 +00:00
dan
1042be912c
turris omnia: switch to regular tftpboot output
...
now it does zimage and rootfs compression
2023-12-23 00:05:34 +00:00
dan
c931d84828
tftproot: put command line in dtb
2023-12-23 00:05:34 +00:00
dan
64a3f50248
tftpboot: support compressed root
2023-12-23 00:05:34 +00:00
dan
c5e9fcecc7
uninit var
2023-12-23 00:05:34 +00:00
dan
f25c41b4d2
tftpboot: move things around in memory
...
new layout has rootfs followed by kernel and dtb, so that we
know the rootfs start and size to embed them into the dtb instead
of having to use dummy values and fill them in afterwards
2023-12-23 00:05:34 +00:00
dan
bfa68d9c55
remove unused variable
2023-12-23 00:05:34 +00:00
dan
ff0ef825a6
tftpboot: add option for kernel image format
2023-12-23 00:05:34 +00:00
dan
44a0cf364b
remove boot-scr output, merge into tftpboot
...
(1) it creates two things (script and dtb); (2) it's a bit pointless
without the tftpboot output it depends on
2023-12-22 21:37:15 +00:00
dan
c7b2733bea
tftpbootlz: put command line in dtb
...
this makes boot.scr substantially shorter, in anticipation of using it
for first boot of the omnia and not wanting to embed an essay in
a setenv value
2023-12-22 20:09:44 +00:00
dan
dfbc72dd51
tftpboot test: fix reserved-memory dt for aarch64
2023-12-22 17:37:53 +00:00
dan
9f851b229c
inadvertently committed, remove
2023-12-22 16:25:54 +00:00
dan
fe2d41a2b1
wlan test: robustify, tail log on failure
2023-12-22 15:49:43 +00:00
dan
9b92bf8447
gazing into the abyss
2023-12-22 15:30:01 +00:00
dan
5f9ffa804f
better detect test succeeded
2023-12-22 15:29:33 +00:00
dan
231c2cef03
make reserved-memory work on mips, and improve test
2023-12-21 22:21:20 +00:00
dan
dbb82339bd
tftpboot test: fail if reserved-memory node is wrong
2023-12-21 21:13:16 +00:00
dan
4a606a4b19
tidy up kernel patch
2023-12-21 21:12:55 +00:00
dan
9c894bdabf
add tftpboot test for mips
2023-12-21 19:25:45 +00:00
dan
a962f18369
run-liminix-vm: map rootfs file iff --phram-address supplied
2023-12-21 19:25:45 +00:00
dan
9a29a042e8
fix tftpboot test on boards without autoboot, swap wan/lan
...
This is for MIPS. I spent a while investigating why the second virtio
net device doesn't function in qemu mips malta u-boot, but with no
success. Use the first one instead.
2023-12-21 19:25:16 +00:00
dan
46926a94db
dont need phram-address param for tftpboot test
...
the phram setup for this test is all passed from
u-boot to the kernel
2023-12-21 19:24:58 +00:00
dan
ab0631c555
qemu mips expects different file size for u-boot
2023-12-19 18:48:28 +00:00
dan
32c13c46bb
support aarch64 in tftpboot test
2023-12-19 12:12:12 +00:00
dan
e5db2691e5
add CI job to test tftpboot
2023-12-18 22:42:29 +00:00
dan
9ca9723c9d
make rootfs work with tftpbootlz
2023-12-17 19:39:26 +00:00
dan
d1e2d525a4
tftpboot omnia using bootz not bootm
...
because kernel size is now beyond the u-boot size
limit for bootm
2023-12-16 23:40:55 +00:00
dan
f4f4387861
well, we're back to where we can boot again
...
so that's good
2023-12-16 23:40:55 +00:00
dan
55fa9992d4
WIP
2023-12-13 21:54:15 +00:00
dan
95d9e014fb
omnia: fix paths
2023-12-13 21:52:28 +00:00
dan
80528376a2
move o.systemConfiguration to initramfs module
...
as far as I can tell, we define it identically in every module
that uses initramfs
2023-12-11 21:47:15 +00:00
dan
d707345891
rename rootfsFiles to rootdir, add bootablerootdir
2023-12-11 21:21:12 +00:00
dan
133b64613d
link to NEWS file
2023-12-11 20:18:28 +00:00
dan
c6c41e331e
let's have a place to document breaking changes
2023-12-11 19:09:56 +00:00
dan
b878d6481a
the first rule of thought club
2023-12-11 19:09:19 +00:00
dan
601bb289ee
rename diskimage to mbrimage
2023-12-11 19:09:19 +00:00
dan
876bd7d8ce
rename flashimage to mtdimage
2023-12-11 19:09:18 +00:00
dan
39c338d710
rm vanilla-configuration-hw.nix, no longer needed
2023-12-11 19:09:18 +00:00
dan
6c8b2bbb83
add retries to wlan test
2023-12-10 18:35:14 +00:00
dan
4ddce6e926
fix the tests we broke
2023-12-10 17:12:57 +00:00
dan
5eeb277564
move output module imports example -> device
...
The outputs available are a characteristic of the device, not
the example.
2023-12-10 16:38:53 +00:00
dan
c81e7c4d35
move all output modules to subdirectory, trash standard.nix
...
standard.nix isn't, is the essence here. Not all devices
support flashimage as it is currently defined - some
have diskimage, some have neither
2023-12-10 15:23:12 +00:00
dan
53fed8839a
fix min-copy-closure for new run-liminix-vm syntax
2023-12-09 17:35:21 +00:00
dan
ebaa7b2bcb
unbreak fennel test
2023-12-09 17:10:41 +00:00
dan
15d570f749
ignore devices/families when extracting docs
2023-12-09 17:10:41 +00:00
Raito Bezarius
aff312bbbe
project: Python 2.7 had an upgrade… !
2023-12-09 17:10:41 +00:00
dan
bb8e974c2b
hard thinking or hardly thinking
2023-12-09 17:10:41 +00:00
dan
317457f582
extract common config for qemu devices into module
2023-12-09 17:10:41 +00:00
dan
07e66c462b
use virtio-bk-pci instead of virtio-bk-device
...
u-boot is happy with either but Linux can autodetect the PCI-based
hardware
2023-12-09 15:53:40 +00:00
dan
4229b42d82
make config.hardware.dts.src nullable
...
This is for QEMU where we won't have to provide a dtb because the
device tree is built by the platform according the (emulated) hardware
present.
Maybe in future there will be other hardware devices where we
don't need to provide a dtb.
2023-12-09 15:51:30 +00:00
dan
03b17fa3ed
add zImage output
2023-12-07 22:31:26 +00:00
dan
a8891461aa
use devtmpfs in initramfs
...
static device nodes don't work with virtio
2023-12-07 20:03:03 +00:00
dan
5adfb0230f
WIP generate bootable disk image with partition table
2023-12-05 23:54:09 +00:00
dan
b519bd15df
pretty-print the qemu command line
...
well, pretty-ish
2023-12-05 17:32:18 +00:00
dan
f2daa0b669
exclude rootfs region from kernel-visible ram
2023-12-05 17:32:18 +00:00
dan
3f74fad966
don't double-json the command line
2023-12-05 17:32:18 +00:00
dan
ed925588f7
extract common code to make root filesystem hierarchy
...
which is then used by the filesystem image creators (ubifs, ext4,
jffs2 etc)
2023-12-05 17:32:18 +00:00
dan
f08c10c8ba
patch u-boot to add ubifs support
...
not that we're using it yet
2023-12-04 23:39:27 +00:00
dan
d25a804f13
test wlan iun armv7
2023-12-04 23:37:39 +00:00
dan
0242cec977
run-liminix-vm: remove unneeded second copy of pad code
2023-12-04 23:37:39 +00:00
dan
5a2963543e
thonk
2023-12-04 23:29:36 +00:00
Raito Bezarius
644f42c35e
kernel: make the build FSAT on FSAT computers
...
I have 128 threads, builds should take only but a moment!
2023-12-03 23:05:12 +00:00
dan
98d3336926
rewrite run-liminix-vm as a fennel program
...
the effect of shell quoting/word splitting rules was reaching
completely unreasonable, insofar as I was unable to reason about it
2023-12-03 22:51:39 +00:00
dan
cb6ebbdc60
alphabetize derivations in overlay
2023-12-02 17:08:59 +00:00
dan
bb335050fd
derivation that produces /boot
2023-12-02 15:31:55 +00:00
dan
395f624338
think
2023-12-02 15:31:09 +00:00
dan
e518ab667b
make job control work in console shell
2023-11-29 19:49:51 +00:00
dan
382128b6cf
omnia: make wan interface work
2023-11-28 21:38:45 +00:00
dan
c803772074
omnia: add hardware ethernet and switch config
2023-11-27 21:37:15 +00:00
dan
32c24f3809
switch pppoe test back to qemu mips
...
while we find out why it fails
2023-11-26 23:18:24 +00:00
dan
cc73a98419
support setting network device names
...
this means that net devices in devices/foo/default.nix can be
specified by their sysfs paths (instead of by "eth0" and "eth1" that
may change from one kernel version to the next) and given mnenomic
names that are helpful for the hardware. Like "wan" and "lan[1..4]"
2023-11-26 23:15:28 +00:00
dan
e2ea145ce5
wip
2023-11-26 22:43:56 +00:00
dan
b036a161f5
thonk
2023-11-26 22:43:31 +00:00
dan
31a2969972
omnia: add support for wifi
...
- ath9k and ath10k, both on PCI bus (which can be enumerated, hence
they don't need to be in device tree)
- need to disable PCIe ASPM for the ath9k to work
- appropriate firmware files added for ath10k
2023-11-26 13:25:01 +00:00
dan
76a370cc92
omnia kernel: add watchdog
...
it's enabled by u-boot so we need at least this minimal capability
otherwise the system reboots after three minutes
2023-11-26 13:07:44 +00:00
dan
bf9f264f0c
update TODO
2023-11-25 18:49:26 +00:00
dan
e35b61b68c
mac80211: support ath9k pci variant
...
if you ask for "ath9k" you get AHB, but if you ask for "atk9k_pci"
now you get PCI. Note that the kernel module name is the same in
both cases.
2023-11-25 18:39:15 +00:00
dan
a8f98ccfe7
use linuxArch instead of case statement
2023-11-25 18:16:20 +00:00
dan
27ce61ae4e
add bootable config for Turris Omnia
2023-11-24 23:29:12 +00:00
dan
3f0f621809
openwrt patches for mvebu (armv7l)
2023-11-24 22:43:58 +00:00
dan
b0ae314df4
stuff
2023-11-24 22:33:42 +00:00
dan
d789a23113
twiddle timeouts
2023-11-24 21:32:53 +00:00
dan
5ba14fd915
add levitate package
...
sets up a chroot system in tmpfs that will be executed on the next
reboot to enable system maintenance without the regular filesystems
mounted
2023-11-23 22:21:03 +00:00
dan
3df34428d6
remove unneeded login and getty applets
2023-11-23 20:01:13 +00:00
dan
62c788eb86
add hook to run maintenance mode instead of rebooting
2023-11-22 00:05:55 +00:00
dan
bab6d346a8
add .../s6/bin to PATH for shutdownd
2023-11-22 00:05:03 +00:00
dan
a202ae476a
extract console redirection stuff from "quit" function
...
so we can use it for scripts that don't reboot at their end
2023-11-21 23:32:37 +00:00
dan
7c9297f91d
use shotdown instead of hpr in .s6-svscan/SIGFOO
...
this is to bring them into line with what more recent
s6-init-linux-maker creates
2023-11-21 23:19:00 +00:00
dan
a0bd250963
switch from getty to root shell on console
...
this just makes things marginally simpler
2023-11-21 23:09:48 +00:00
dan
c8b2d58dd3
exit 0 on service down even if no outputs to delete
2023-11-21 17:25:50 +00:00
dan
e5223f093f
kernel.src may be a path not just a package
...
this makes it easier to hack the kernel locally and test things
2023-11-18 14:21:18 +00:00
dan
c563a6451f
add missing param
2023-11-18 14:20:59 +00:00
dan
f45326b9d3
why we decided not to depend on kexec
2023-11-18 11:51:57 +00:00
dan
f9f4d97bb8
convert flash params to int
2023-11-12 20:39:06 +00:00
dan
abfb35a231
and entryPoint
2023-11-12 18:50:47 +00:00
dan
315907de98
convert hardware loadAddress to int
2023-11-12 18:47:31 +00:00
dan
185117843b
convert tftp.loadAddress from string to int
2023-11-12 18:37:33 +00:00
dan
0131686661
use parseInt for hex values
2023-11-12 18:25:38 +00:00
dan
3da692f7ef
don't import flashimage unconditionally, it breaks qemu
2023-11-12 18:11:13 +00:00
dan
f61e737b54
improve doc for outputs and hardware
...
Changed my mind about "installer" as a first-class concept, at least
in the current implementation. Not every documented output is an
installer
2023-11-12 17:15:58 +00:00
dan
262efaabe6
doc: put all the u-boot/serial stuff in one place to link from
2023-11-12 17:14:33 +00:00
dan
7cfb92e3ce
more doc
2023-11-10 21:17:20 +00:00
dan
22882dabee
think
2023-11-10 21:10:26 +00:00
dan
5e046490de
support links from device pages to their installation methods
2023-11-09 23:02:35 +00:00
dan
a9760d239c
basic doc for flashimage installer
2023-11-09 22:43:50 +00:00
dan
5729cfb4a7
document installation methods (only vmroot yet)
2023-11-09 22:14:31 +00:00
dan
7d5c7b9b44
export evaluation from default.nix and use it for docs
2023-11-09 22:14:31 +00:00
dan
23b3a2baef
extract vmroot output into its own file
2023-11-08 23:19:11 +00:00
dan
4cb4f904f8
delete unused kconfig for arm qemus
2023-11-08 21:28:12 +00:00
dan
a9d847e2c0
add ext4 as rootfsType
2023-11-06 21:52:31 +00:00
dan
6bbff2f5b3
think think
2023-11-05 23:39:50 +00:00
dan
5c1f5fabe2
switch pppoe test to use armv7l
2023-11-05 23:19:40 +00:00
dan
6489a39424
qemu armv7
2023-11-05 23:19:11 +00:00
dan
c94d12934f
remove direct use of run-liminix-vm from tests and doc
2023-11-05 20:37:23 +00:00
dan
c40eef25d6
qemu: use phram instead of block2mtd
2023-11-05 19:13:51 +00:00
dan
46991e2761
aarch64 ram starts at 0x40000000
2023-11-05 15:33:10 +00:00
dan
a135cb1217
introduce lim, the liminix library
...
so far we have lim.parseInt, which parses an integer from a string
with optional base-selecting-prefix (e.g. 0755, 0x12ab)
2023-11-05 15:13:06 +00:00
dan
863045b86b
added hardware.ram.startAddress config
...
it's not 0 on arm32, so this will be useful for qemu
2023-11-05 15:11:58 +00:00
dan
629624bb25
replace multiway if with pkgs.stdenv.hostPlatform.qemuArch
2023-11-05 11:40:26 +00:00
dan
92b9bf959e
options.system.outputs.initramfs -> initramfs module
2023-11-05 11:33:02 +00:00
dan
c5c5f1687a
patch qemu to load uncompressed ARM kernels at correct offset
2023-11-05 11:32:47 +00:00
dan
80793aa694
belkin rt3200 is a ubifs device
2023-11-05 11:32:23 +00:00
dan
824536f9b3
in uimage FIT, honour ${arch}
2023-11-05 11:31:28 +00:00
dan
e6cb5e319b
extract NETDEVICES kconfig to kernel.nix module
2023-11-05 11:31:23 +00:00
dan
c3ccee6506
preinit: print errno (in hex, it's easier) for failures
2023-11-05 11:27:57 +00:00
dan
6db982f25f
preinit: pause before exiting
...
as explained in the comment, this is to give us a
chance to see error messages before the kernel panics
2023-11-05 11:27:57 +00:00
dan
86a5224f3c
preinit: fix compiler warnings
2023-11-05 11:27:43 +00:00
dan
155a29d9b3
preinit: strip trailing newline(s) on /proc/cmdline
2023-11-05 11:27:34 +00:00
dan
e6ef4f78bb
"ubimage" module contains ubifs image + instructions
...
Presently either you run this from U-Boot or you figure out for
yourself how to kexecboot into a recovery system :-)
2023-10-21 23:20:53 +01:00
dan
d2f517a4e9
preinit.c: reindent
2023-10-19 21:02:18 +01:00
dan
0f38ee0e9c
remove PREINIT_USE_LIBC option as it is now the only option
2023-10-19 18:59:02 +01:00
dan
61dc5beca8
preinit: parse rootfstype from kernel command line
2023-10-19 18:56:09 +01:00
dan
f3225c2bd5
delete dup outputs.systemConfiguration
...
perhaps this should go into initramfs.nix not jffs2.nix
2023-10-19 10:09:08 +01:00
dan
8798ee9830
partial fix for timeout handling
...
1) "Unknown transfer id" message was because the local variable "tid"
is not a transfer id, it is a sequence number - so the check was
actually comparing expected vs actual acknowledged sequence number,
not TID. It's still a problem if we get the wrong one, but it
indicates a lost packet (so we should resend) not a packet that was
sent from somewhere else.
2) if the ACK packet has not been received, our retry should involve
_resending_ it, not just trying to wait for it again.
3) I have removed the timeout condition for terminating the resend
loop, because in practice (assuming both ends have the same timeout
setting) all it did was ensure that the loop only ran once. The
timeout is supposed to regulate how long we wait for before retrying
(it doesn't do this, we wait indefinitely), not how long we wait for
before giving up.
2023-10-18 23:35:23 +01:00
dan
629914f65e
initial support for ubifs
2023-10-16 19:55:17 +01:00
dan
0693cf23d8
preinit: improve error logging for fork_exec
2023-10-12 19:00:57 +01:00
dan
c341eb46b6
use hostPlatform.linuxArch in kernel derivation
2023-10-12 18:59:45 +01:00
dan
1a369ff3bf
preinit: remove no-longer-used mips assembly
2023-10-12 18:57:54 +01:00
dan
364c5faf9e
tftpboot: fix errors in phram partition size calc
2023-10-10 20:26:27 +01:00
dan
80a09a9a9b
rt3200: move the entryPoint
2023-10-10 20:25:42 +01:00
dan
3518e2ecca
Merge branch 'hark-how-all-the-belkin-rings'
2023-10-09 19:56:48 +01:00
dan
fc2eb6ee4d
rt3200 mumble
2023-10-09 19:56:22 +01:00
dan
bd20f3e419
uimage: make fit optional
2023-10-09 19:47:57 +01:00
dan
f62ad0e1d7
use "tftpboot" instead of "tftp" in u-boot commands
...
openwrt's u-boot installation doesn't accept the short form
2023-10-09 19:47:57 +01:00
dan
ed792e0dc0
rt3200: swap wireless driver load order
...
mt7515e loads first, so that wlan0 is 2.4GHz
mt7515e loads after, so that 5GHz gets wlan1
2023-10-09 19:47:57 +01:00
dan
d025c33d30
rt3200: enable flash/mtd
2023-10-09 19:47:57 +01:00
dan
a755c9c3c5
delete some inapplicable kconfig
2023-10-09 19:47:57 +01:00
dan
fdf74fa06b
add mt7915, 7615 wifi modules
...
7915 won't work until we have working MTD, because it needs to
read calibration data from flash
2023-10-09 19:47:57 +01:00
dan
b8dea2ed34
rt3200: add DSA
...
this creates a bunch of network interfaces {lan[1234],wan}@eth0
2023-10-09 19:47:57 +01:00
dan
c18f07f02f
aarch64: make tftpboot work
...
- patch dtb to add reserved-memory stanza for the phram device to use
(aarch64 does not accept memmap= command line option)
- patch phram driver to use memremap() instead of ioremap() as
ioremap can't be used for system ram on arm devices
2023-10-09 19:47:57 +01:00
dan
1c4412a1f4
rt3200: enable serial console
2023-10-09 19:47:57 +01:00
dan
dbc16edf96
don't use ttyAMA0 console on all aarch64, just qemu
2023-10-09 19:47:57 +01:00
dan
528d619d76
WIP kernel config for belkin rt3200
2023-10-09 19:47:57 +01:00