Add TFTP server and DHCP bootfile support - #1647
Conversation
8472f53 to
629fa87
Compare
629fa87 to
b88ccde
Compare
Security auditAudited head b88ccde against main. Two findings should be fixed before merge, one deserves a doc note, the rest is minor. Privilege modelAdmins are in
Findings
1. TFTP
|
Agreed, thanks for the awesome review! 🙇♂️ |
|
One correction to the privilege model, since it changes how we fix finding 2.
So For that reason The same reasoning applies to finding 6, which is in this round as well: Findings 1-5 are folded into their respective commits, 6 is a separate one. For finding 5 I kept the field check rather than NUL separated records, busybox |
b88ccde to
1755ec3
Compare
|
@mattiaswal fixed, all of them, with the previously noted exceptions. |
Adding a label fires a second pull_request event in the same concurrency group, cancelling the run from 'opened'. Only ci:main is meant to start a run, so the PR ends up with no CI at all. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Changes that cannot affect the image, e.g. a ChangeLog fixup after another branch landed, should not spend an hour of CI. Adding the label to an open PR also stops a build already running. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Staging a file for another service, or copying a log off the system, was not possible from the CLI. Only /cfg, /media and the user's home were accepted, a directory destination was refused, and the refusal said "no such file" about a file that was there. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
copy ended a completed directory with a space, so the path could not be typed further, show offered six of its twenty subcommands, and neither erase nor rpc had any. The files also sat in two places, installed two ways. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Completing a directory or a URI scheme ended the word with a space, so the path could not be typed any further. Also brings unambiguous command-name prefixes. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Tab on "copy /", "remove /" or "dir /" gave nothing, the CLI has no shell to do it. Limited to the directories copy and erase accept. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
There was no way to set a configuration aside from the CLI, only copy and remove, so the way to start from a clean slate was to remove the one file that holds the system's configuration. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
It is the one file most likely to be removed, and the only one whose removal changes what the system boots. Offer it, and say so before asking. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Devices that netboot from the system, or fetch their configuration over TFTP, need a local server. Read-only, serving /var/lib/tftpboot by default, or a directory on USB media. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Operators need to see what the server hands out, in particular when a device fails to boot from it. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Devices that netboot as a fallback read the boot file and server address from the BOOTP header fields, which the option list cannot set. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
dir listed three of the places copy accepts, and with no argument it stopped after the first one. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The key becomes one path segment, so a prefix like 10.0.0.0/24 splits the path and the server answers 400. Only a test addressing a list entry by such a key hits it, and only when the pseudo-random transport picks RESTCONF, which is why it passes on one rig and fails on another. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Cover the TFTP server end to end, and the BOOTP header fields a netbooting client sees, including which scope wins. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Where files live, how to get them there, per-client directories, and the scope precedence for boot parameters. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Regression introduced in 0b026fa Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
klishd runs as root and dir is a script action, so any CLI user could list directories they cannot read themselves, e.g. dir /etc/ssh. Make it a plugin action, dropping privileges like copy and remove do. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
1755ec3 to
71142d9
Compare
Description
Add support for acting as a TFTP server so an Infix unit can hand out boot images, configs, and firmware to downstream devices on an isolated or provisioning network
Checklist
Tick relevant boxes, this PR is-a or has-a: