| Age | Commit message (Collapse) | Author | Files | Lines |
|
Only persist the primary bridge IP to /var/google/gbmc-br-ip if
gbmc_rwfs_purge_done succeeds.
If an RWFS purge is pending for the active trip ID or has not yet
completed, attempting to write the IP to RWFS can fail due to ENOSPC or
corrupt flash, or store state that will be immediately wiped on the
pending reboot.
Change-Id: I4a98d14edf2489a7970bc594693969bb3ac5e45d
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
gbmc_rwfs_purge_done
When verifying whether the RWFS purge has completed for a given
GBMC_TRIP_ID, also check /run/initramfs/rwfs-purged.
Initramfs and clean-rwfs write the purge flag/trip ID to
/run/initramfs/rwfs-purged during early boot purge handling. Checking
both paths allows gbmc_rwfs_purge_done to recognize a completed purge
even if the persistent /var overlay is not mounted or if running in
tmpfs fallback mode.
Change-Id: I2ca09e9463f7a07339cd5c37cd73aebc75244990
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Call gbmc_br_dhcp_rwfs_sync_ro prior to requesting powercycle in
50-gbmc-psu-hardreset.sh.in and prior to reboot -f in 51-gbmc-reboot.sh
to ensure filesystems are flushed and clean before the reset occurs.
Change-Id: Ic6776afb6459eafbd61b83cdbceb11026f488ed3
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
completion
Avoid writing /var/google/gbmc-br-ip during the initial DHCP bound phase
to prevent ENOSPC failures when RWFS is full.
Persist the primary IP to RWFS via gbmc_net_unmask_and_write once all
dhcp step hooks and RWFS purge have run.
Change-Id: Icaf470d8e92970337ebc4e9d249e8d8a953454ae
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Add gbmc_fetch_trip_id and gbmc_rwfs_purge_done to gbmc-br-dhcp-lib.sh
to parse the netboot trip ID into a global variable GBMC_TRIP_ID and
verify against /var/google/rwfs-purged (or /run/initramfs/rwfs-purged
when trip ID is absent).
Change-Id: I63b3e60fea07c9c8f689b9497b983769f5e4a613
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Add gbmc-br-dhcp-lib.sh to host DHCP netboot helpers for RWFS management:
- gbmc_br_dhcp_rwfs_sync_ro: flushes pending writes and remounts / and
the underlying RWFS read-only prior to reset or powercycle.
Change-Id: I3e27d437c04f3f5cb140c188be7230b3ced0125c
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Add gbmc_net_unmask_and_write to gbmc-net-lib.sh to safely unmask any
bind-mounts over a persistent target file, touch the file to verify write
capability, and write content to RWFS.
Use gbmc_net_unmask_and_write in gbmc_br_set_ip to replace inline
unmount and file creation logic.
Change-Id: I9b0263595fe80c1cccfa34ac239b505793bb5224
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
When systemd-networkd reloads or reconfigures an interface, it parses
RoutingPolicyRule entries and installs them into the kernel with
protocol 'static'. When out-of-band scripts configure the same rules
without proto static, the kernel treats them as distinct rules and
creates duplicate entries.
Specify 'proto static' when adding IPv6 routing policy rules in
gbmc-nic-neigh and gbmc-ncsi-br-deprecated-ips to ensure rule deduplication
and idempotence.
Change-Id: Ic82c81358db41122a61358d7c22998a4f9441113
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
management
Set ManageForeignRoutingPolicyRules=no in networkd.conf to prevent
systemd-networkd from dropping routing policy rules managed out-of-band
by iproute2 when interfaces are reconfigured.
Change-Id: I226b9f71c35a6435cfa69f36f332306263889154
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
When gbmc-br-dhcp-term stops DHCP after the 10-minute wait without
/run/netboot_done being present, emit update_netboot_status "netboot"
"DHCP is not running" "FAIL" so dhcp-done (port 23) and gbmc-netboot
report an explicit failure instead of remaining at "Waiting on dhcp
process".
Break rather than exiting early if the DHCP slice is already inactive,
and stop gbmc-br-dhcp@'*' synchronously before writing the final
status.
Change-Id: Ie7ae3c516cfce2994e7cf04f8c8383fc214a2595
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Extract NETBOOT_STATUS_START and update_netboot_status from
gbmc-br-dhcp.sh into gbmc-br-lib.sh so other gbmc-bridge scripts
(such as gbmc-br-dhcp-term.sh) can emit structured netboot status
updates to gbmc-netboot and dhcp-done.
Change-Id: Iebacc119bd4f8dcb5799065d2f9e46ecb1b95b4e
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Stop gbmc-br-dhcp-term before stopping gbmc-br-dhcp and restarting
dhcp-done so the terminator cannot race with dhcp-done restart and
overwrite its status.
Remove any stale /run/netboot_done and /run/gbmc-br-dhcp.pid files
before starting a fresh DHCP session.
Change-Id: I42d4f6347f41dc50baef2131c9c5b1f8835be402
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Remove /run/gbmc-br-dhcp.pid when gbmc_br_exit exits with a non-zero
status so a failed bound run does not leave a stale PID behind that
blocks gbmc-br-dhcp-term from completing.
Move touch /run/netboot_done into the ret == 0 branch of gbmc_br_exit
so hooks that exit 0 early (such as 50-gbmc-psu-hardreset on coordinated
powercycle or 51-gbmc-reboot) also mark netboot_done.
Change-Id: I0fe1f54b4cf48601eeb16456aa53202759b399c5
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Instead of triggering a systemd-networkd reload whenever a bridge IP
address is added or removed, configure the kernel proxy NDP entries
and routing policy rules directly via ip -6 neigh and ip -6 rule.
If direct manipulation fails, fall back to triggering a systemd-networkd
reload for the affected interfaces.
The network drop-in file is still updated so networkd retains state
across any future reload.
Change-Id: Ic64262850e123f17995698872919552926fe3954
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Coalesce bridge RA /124 route changes via gbmc_ip_monitor_defer so that
routine Router Advertisement refreshes (where the kernel deletes and
re-adds the route 2.6 ms apart) become a no-op instead of triggering
repeated remove and add route update churn.
Change-Id: Ifb3f7abae166fecc71db996014a9722034628ed1
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Apply label 99 via 'ip addrlabel add prefix <pfx>/80 label 99' when
configuring SLAAC addresses generated from bridge Router Advertisements,
and remove the label when the SLAAC address is deleted.
Under RFC 6724 Rule 6 (prefer matching label), this ensures that manual
addresses (e.g. fd02::, 212c::) with default label 2 are natively
preferred over SLAAC-generated addresses without requiring route-table
source overrides.
Change-Id: I14612a34b8c1d4f26df5bd06b20e3f5291fad3ee
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Currently, gbmc-br-ra overrides update_rtr as a no-op, forcing bridge
interfaces to rely exclusively on kernel-generated RA routes with
routine expiration lifetimes. This causes repeated route add/delete
churn as the kernel refreshes the ephemeral default route.
Update update_rtr to use default_update_rtr from gbmc-ra.sh, following
the static gateway pattern used by front and NCSI without using
phosphor-networkd. ROUTE_METRIC remains 1000, which is greater than
front (800) and NCSI (900), but less than the kernel RA metric (1056).
Set UseGateway=false under [IPv6AcceptRA] in -bmc-gbmcbr.network.in
to prevent systemd-networkd from installing the kernel default route,
while keeping RIO, PIO, and SLAAC route handling intact.
Change-Id: Ia770c3c072d0e582f1f0051be4eba1215cc42e39
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Add documentation comments describing add_rtr, default_update_rtr, and
default_update_fqdn behaviors and parameters.
Change-Id: I47f1549421cb8b7ae29cfbb72a76f238d33d94b0
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Add documentation comment describing the behavior, arguments, and return
value of gbmc_net_route_table_for_intf.
Change-Id: I2ebba161fc0f40d1ae0ca51d1f04dbf556d10db8
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
When GBMC_AVOID_RWFS is set, avoid writing mutable networking state to /var
by keeping dynamic state in /run and bind-mounting empty configs over /etc
via gbmc_net_mask_or_rm instead of modifying persistent storage directly.
Change-Id: Ie1f5996e575b51e471d89ab7afd70abb13d7b8a0
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
gbmc-br-dhcp-term
Document that the 10-minute wait in gbmc-br-dhcp-term is intentional because
gBMC uses DHCP to trigger reinstall operations, and DHCP servers only respond
when a reinstall is queued rather than during normal operation and bootup.
Change-Id: I2bf486329761a23310d5a24bcf11c6782378e755
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
deletion
Debounce ULA additions and removals using gbmc_ip_monitor_defer so rapid
interface oscillations do not cause churn. Silence expected errors during
stale address deletion when addresses are already gone.
Change-Id: I706f296adab58ae3569cd941c1cd05410b3fb6c8
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Read the hostname from /proc/sys/kernel/hostname instead of /etc/hostname, and
skip the update when it is empty. The kernel copy is always readable and is
what hostnamectl updates, so the hostname is still detected when /etc/hostname
is unpopulated, as happens on read-only and volatile root filesystems.
Change-Id: I46809ae14c3a50cbd8e89ad0e877540dc79613f5
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Introduce generic service reload coalescing mechanism (_gbmc_net_service_reload)
in gbmc-net-lib.sh for systemd-networkd and nftables reloads across concurrent
processes.
Integrate reload queuing into gbmc-ip-monitor during initial sweep ([INIT]) and
defer live event bursts by 1 second ([DEFER]). Because every hook invocation is
wrapped in a reload queue in gbmc_ip_monitor_run_hooks, individual hooks do not
need to open the queue system directly.
Update callers across bridge, NCSI, and NIC configurations to use
gbmc_net_networkd_reload and gbmc_net_nftables_reload, and add comprehensive
unit tests in gbmc-ip-monitor-test.sh and gbmc-net-lib-test.sh.
Change-Id: I2fd89dbe4e8446ecaf5b9c910cc1abb7b6887279
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
gbmc-br-dhcp
When gbmc-br-dhcp exits unexpectedly with an error, reporting failure
against NETBOOT_STATUS_STATE could overwrite a state that had already
reported SUCCESS, while leaving the umbrella netboot state incomplete.
Report failure against the top-level "netboot" state instead, and retain
the explanatory comment on why sleep infinity is held on successful
termination.
Change-Id: I058ca04c96f7a6ae02062b9d3a8de49b6b6082d8
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
The idea here is useful, but this implementation conflicts with hooks we
have downstream that do reloads before set_ip finishes.
Change-Id: Iac22b1d7c80b7dad94df4cb6cdda52d681386f21
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
This change was bad, it deletes all statuses including errors when the
process terminates. We want to keep those statuses around to be queried.
Change-Id: Ide2579e7bc5f048f4bd7ceff1faca468603dc8ef
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Add hwclock-save.service to gbmc-psu-hardreset.target and shutdown.target
to ensure the system time is flushed to the hardware RTC prior to
cutting power on PSU hard resets, reboots, and shutdowns.
Change-Id: I6181568db400f344a71bcffcc436dfe33474dfa9
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Nancy, Benjamin, and Brandon no longer work on the google side of
openbmc. Yuxiao has a long history here so add him as a maintainer.
Change-Id: I2898d9113e0552e5229e760098560187829d05ad
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
When reboot.target or other shutdown targets time out waiting for
services to terminate, ensure that systemd takes the appropriate forced
action (e.g. reboot-force, poweroff-force, halt-force, kexec-force)
rather than timing out and leaving the system hung.
Tested: Verified on physical BMC (lcatlc-ep2) with an ephemeral service
configured with a 180s stop timeout; reboot.target timed out after 30s
and properly forced the reboot into systemd-shutdown and the initrd
/shutdown script.
Change-Id: Icffe076305d3e1f31f23f0d202327ccba3454c85
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
We don't ever want the script terminating with writing a status update.
This guarantees we write a failure status when we exit with an error.
Change-Id: Ib2223a9867f0ef0b0b2357007726a918e671066b
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Configure runtime IPv6 in /run/systemd/network/ and run
GBMC_BR_LIB_SET_IP_HOOKS before persisting /var/google/gbmc-br-ip to
RWFS. This ensures runtime network configuration and hooks complete
before touching RWFS.
Change-Id: Ie3fa2eafb63532d488ce5308f269f1089767dccf
Signed-off-by: Mo Elbadry <elbadrym@google.com>
|
|
We don't want stale ongoing flags left in the filesystem and reported to
the installer, if we terminate we should delete the status file
entirely to convey DHCP is stopped.
Tested: Verified that stopping the service deletes the file
Change-Id: I98a4a9e7a35c2235ab02db9af39a99b4d4bfb701
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Ana Mendes (1):
handler: remove IPMI filtering logic
Change-Id: Id64c31cf01e946c7ba314f2b8f18007b49657d2a
Signed-off-by: Andrew Geissler <openbmcbump-github@yahoo.com>
|
|
Patrick Williams (2):
build: add meson subproject wrap files
build: fix missing ipmid header
Change-Id: Ib7abe7eb777d47539aed79ad0ce994d9ff5ad443
Signed-off-by: Andrew Geissler <openbmcbump-github@yahoo.com>
|
|
Jasmine Cha (1):
Added IPMI handler to support memory capacity gib
Change-Id: Ifda284450447ee51a044766b66437b0acda6643a
Signed-off-by: Andrew Geissler <openbmcbump-github@yahoo.com>
|
|
Change-Id: Idcacbf5d6db384d3540f9af8d66ff5c09381b4e9
Signed-off-by: Yuxiao Zhang <yuxiaozhang@google.com>
|
|
Patrick Williams (1):
OWNERS: prune inactive members
Change-Id: I57384fdc157a3d656b4b87dfe668707ce1d3da5f
Signed-off-by: Andrew Geissler <openbmcbump-github@yahoo.com>
|
|
Ana Mendes (1):
handler: enable IPMI filtering for Attestable BM
Change-Id: I4ddda7c1d25ccaa5dccaea489ff85a9e73c05c60
Signed-off-by: Andrew Geissler <openbmcbump-github@yahoo.com>
|
|
Patrick Williams (1):
sdbusplus: use shorter type aliases
Change-Id: Ic85fc2d1ef8ed464cd4a87f7a55d54f78cb47eed
Signed-off-by: Andrew Geissler <openbmcbump-github@yahoo.com>
|
|
Create a flag to indicate that the current boot is netboot.
Change-Id: I127fbfc5e4a68c4de13ab3c34d2a6c500c0320ce
Signed-off-by: Yuxiao Zhang <yuxiaozhang@google.com>
|
|
Add options to disable always_available for gbmcbr and configure channel
15 to the right KCS bridge.
Tested:
- channel_access.json doesn't have gbmcbr
```
$ cat ./tmp/work/all-openbmc-linux/phosphor-ipmi-config/1.0/packages-split/phosphor-ipmi-config/usr/share/ipmi-providers/channel_config.json | jq '."15"'
{
"name": "ipmi_kcs1",
"is_valid": true,
"active_sessions": 0,
"channel_info": {
"medium_type": "system-interface",
"protocol_type": "kcs",
"session_supported": "session-less",
"is_ipmi": true
}
}
// On ALWAYS_AVAILABLE_ON_GBMCBR_IPMI_CHANNEL=0
$ cat ./tmp/work/all-openbmc-linux/phosphor-ipmi-config/1.0/package/usr/share/ipmi-providers/channel_access.json
{
"1": {
"access_mode": "always_available",
"user_auth_disabled": false,
"per_msg_auth_disabled": false,
"alerting_disabled": false,
"priv_limit": "priv-admin"
},
"2": {
"access_mode": "always_available",
"user_auth_disabled": false,
"per_msg_auth_disabled": false,
"alerting_disabled": false,
"priv_limit": "priv-admin"
}
}
```
Change-Id: Idecd7337c29685faea2a648ab8246e79e1588ace
Signed-off-by: Willy Tu <wltu@google.com>
|
|
Patrick Williams (1):
sdbusplus: rename SdBusError
Change-Id: Ia8d444f0ecc7c9800cf3ac138ecd5b19450fd54d
Signed-off-by: Andrew Geissler <openbmcbump-github@yahoo.com>
|
|
Tested: regular image with mfg type has no l2br variation
Change-Id: Icec9bad9e3d8f73daa911190dc0594d665752fb8
Signed-off-by: Yuxiao Zhang <yuxiaozhang@google.com>
|
|
Added an nftables forwarding rule for non-primary NCSI
interfaces to permit inbound traffic across the gbmcbr.
Tested: Verified rules are correctly applied on a real machine.
Change-Id: Ifa6a8f360efeb0afe93daaf767ce0870bbdebba0
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Stored complex regexes in variables to prevent Word Splitting on unquoted
spaces inside conditional expression regex operators.
Tested: Manually verified script syntax.
Change-Id: I32a4ded1530754fc8213e49c483c53f857c8e3b7
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Tested: together with https://gbmc-review.git.corp.google.com/c/meta-gbmc-staging/+/90919
Reboot is delayed
Change-Id: Ibf315a47e879df10df4a7ea2ca06cb61b6730c26
Signed-off-by: Yuxiao Zhang <yuxiaozhang@google.com>
|
|
The linux kernel removes source addresses from routes silently when all
addresses matching the source are deleted. We need to make sure we
follow this pattern and delete them so we can replace them if the
address gets re-added.
Change-Id: I4825f60c1c8b237eb05b52e4d2fa0a7b7b9f9297
Signed-off-by: William A. Kennington III <wak@google.com>
|
|
Not all dead route end with linkdown/dead, make sure that we skip them
when the dead/linkdown is in the middle of the route
Change-Id: I5b41068a47f75215eab29b54b9afc3324825a231
Signed-off-by: Yuxiao Zhang <yuxiaozhang@google.com>
|
|
Patrick Williams (1):
meson: use non-deprecated systemd packageconfig
Change-Id: I8c43098942f27754c8c0bacc21814d45a1ecc9a2
Signed-off-by: Andrew Geissler <openbmcbump-github@yahoo.com>
|