diff --git a/.github/workflows/trigger_rebuild_packages.yml b/.github/workflows/trigger_rebuild_packages.yml index 4eb740f3d4..32faeb352d 100644 --- a/.github/workflows/trigger_rebuild_packages.yml +++ b/.github/workflows/trigger_rebuild_packages.yml @@ -62,8 +62,6 @@ jobs: - 'scripts/package-build/linux-kernel/**' ndppd: - 'scripts/package-build/ndppd/**' - net-snmp: - - 'scripts/package-build/net-snmp/**' netfilter: - 'scripts/package-build/netfilter/**' node_exporter: @@ -90,6 +88,8 @@ jobs: - 'scripts/package-build/telegraf/**' udp-broadcast-relay: - 'scripts/package-build/udp-broadcast-relay/**' + unionfs-fuse: + - 'scripts/package-build/unionfs-fuse/**' vpp: - 'scripts/package-build/vpp/**' waagent: @@ -191,10 +191,6 @@ jobs: trigger_build "ndppd" fi - if [ "${{ steps.changes.outputs.net-snmp }}" == "true" ]; then - trigger_build "net-snmp" - fi - if [ "${{ steps.changes.outputs.netfilter }}" == "true" ]; then trigger_build "netfilter" fi @@ -247,6 +243,10 @@ jobs: trigger_build "udp-broadcast-relay" fi + if [ "${{ steps.changes.outputs.unionfs-fuse }}" == "true" ]; then + trigger_build "unionfs-fuse" + fi + if [ "${{ steps.changes.outputs.vpp }}" == "true" ]; then trigger_build "vpp" fi diff --git a/data/architectures/amd64.toml b/data/architectures/amd64.toml index 8676ad2f65..5a94e11c78 100644 --- a/data/architectures/amd64.toml +++ b/data/architectures/amd64.toml @@ -14,8 +14,9 @@ packages = [ [additional_repositories.salt] architecture = "amd64" - url = "https://packages.vyos.net/saltproject/debian/11/amd64/3005" - distribution = "bullseye" + url = "https://packages.broadcom.com/artifactory/saltproject-deb" + distribution = "stable" [additional_repositories.zabbix] url = "https://repo.zabbix.com/zabbix/6.0/debian" + distribution = "bookworm" diff --git a/data/architectures/arm64.toml b/data/architectures/arm64.toml index 4d8596c68e..6a183bbe12 100644 --- a/data/architectures/arm64.toml +++ b/data/architectures/arm64.toml @@ -6,8 +6,8 @@ bootloaders = "grub-efi" [additional_repositories.salt] architecture = "arm64" - url = "https://packages.vyos.net/saltproject/debian/11/arm64/3005" - distribution = "bullseye" + url = "https://packages.broadcom.com/artifactory/saltproject-deb" + distribution = "stable" [additional_repositories.zabbix] url = "https://repo.zabbix.com/zabbix/6.0/debian-arm64" diff --git a/data/defaults.toml b/data/defaults.toml index 437cc1cda9..fcba7d7d90 100644 --- a/data/defaults.toml +++ b/data/defaults.toml @@ -2,7 +2,7 @@ build_type = "development" architecture = "amd64" -debian_distribution = "bookworm" +debian_distribution = "trixie" debian_mirror = "http://deb.debian.org/debian" debian_security_mirror = "http://deb.debian.org/debian-security" @@ -14,7 +14,7 @@ vyos_mirror = "https://packages.vyos.net/repositories/current" vyos_branch = "current" release_train = "current" -kernel_version = "6.6.100" +kernel_version = "6.12.40" kernel_flavor = "vyos" bootloaders = "syslinux,grub-efi" diff --git a/data/live-build-config/archives/saltstack.key.chroot b/data/live-build-config/archives/saltstack.key.chroot index 14bd7d98cd..98b895bf35 100644 --- a/data/live-build-config/archives/saltstack.key.chroot +++ b/data/live-build-config/archives/saltstack.key.chroot @@ -1,31 +1,41 @@ -----BEGIN PGP PUBLIC KEY BLOCK----- -Version: GnuPG v2 -mQENBFOpvpgBCADkP656H41i8fpplEEB8IeLhugyC2rTEwwSclb8tQNYtUiGdna9 -m38kb0OS2DDrEdtdQb2hWCnswxaAkUunb2qq18vd3dBvlnI+C4/xu5ksZZkRj+fW -tArNR18V+2jkwcG26m8AxIrT+m4M6/bgnSfHTBtT5adNfVcTHqiT1JtCbQcXmwVw -WbqS6v/LhcsBE//SHne4uBCK/GHxZHhQ5jz5h+3vWeV4gvxS3Xu6v1IlIpLDwUts -kT1DumfynYnnZmWTGc6SYyIFXTPJLtnoWDb9OBdWgZxXfHEcBsKGha+bXO+m2tHA -gNneN9i5f8oNxo5njrL8jkCckOpNpng18BKXABEBAAG0MlNhbHRTdGFjayBQYWNr -YWdpbmcgVGVhbSA8cGFja2FnaW5nQHNhbHRzdGFjay5jb20+iQE4BBMBAgAiBQJT -qb6YAhsDBgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIXgAAKCRAOCKFJ3le/vhkqB/0Q -WzELZf4d87WApzolLG+zpsJKtt/ueXL1W1KA7JILhXB1uyvVORt8uA9FjmE083o1 -yE66wCya7V8hjNn2lkLXboOUd1UTErlRg1GYbIt++VPscTxHxwpjDGxDB1/fiX2o -nK5SEpuj4IeIPJVE/uLNAwZyfX8DArLVJ5h8lknwiHlQLGlnOu9ulEAejwAKt9CU -4oYTszYM4xrbtjB/fR+mPnYh2fBoQO4d/NQiejIEyd9IEEMd/03AJQBuMux62tjA -/NwvQ9eqNgLw9NisFNHRWtP4jhAOsshv1WW+zPzu3ozoO+lLHixUIz7fqRk38q8Q -9oNR31KvrkSNrFbA3D89uQENBFOpvpgBCADJ79iH10AfAfpTBEQwa6vzUI3Eltqb -9aZ0xbZV8V/8pnuU7rqM7Z+nJgldibFk4gFG2bHCG1C5aEH/FmcOMvTKDhJSFQUx -uhgxttMArXm2c22OSy1hpsnVG68G32Nag/QFEJ++3hNnbyGZpHnPiYgej3FrerQJ -zv456wIsxRDMvJ1NZQB3twoCqwapC6FJE2hukSdWB5yCYpWlZJXBKzlYz/gwD/Fr -GL578WrLhKw3UvnJmlpqQaDKwmV2s7MsoZogC6wkHE92kGPG2GmoRD3ALjmCvN1E -PsIsQGnwpcXsRpYVCoW7e2nW4wUf7IkFZ94yOCmUq6WreWI4NggRcFC5ABEBAAGJ -AR8EGAECAAkFAlOpvpgCGwwACgkQDgihSd5Xv74/NggA08kEdBkiWWwJZUZEy7cK -WWcgjnRuOHd4rPeT+vQbOWGu6x4bxuVf9aTiYkf7ZjVF2lPn97EXOEGFWPZeZbH4 -vdRFH9jMtP+rrLt6+3c9j0M8SIJYwBL1+CNpEC/BuHj/Ra/cmnG5ZNhYebm76h5f -T9iPW9fFww36FzFka4VPlvA4oB7ebBtquFg3sdQNU/MmTVV4jPFWXxh4oRDDR+8N -1bcPnbB11b5ary99F/mqr7RgQ+YFF0uKRE3SKa7a+6cIuHEZ7Za+zhPaQlzAOZlx -fuBmScum8uQTrEF5+Um5zkwC7EXTdH1co/+/V/fpOtxIg4XO4kcugZefVm5ERfVS -MA== -=dtMN ------END PGP PUBLIC KEY BLOCK----- +mQGNBGPazmABDAC6qc2st6/Uh/5AL325OB5+Z1XMFM2HhQNjB/VcYbLvcCx9AXsU +eaEmNPm6OY3p5+j8omjpXPYSU7DUQ0lIutuAtwkDMROH7uH/r9IY7iu88S6w3q89 +bgbnqhu4mrSik2RNH2NqEiJkylz5rwj4F387y+UGH3aXIGryr+Lux9WxfqoRRX7J +WCf6KOaduLSp9lF4qdpAb4/Z5yExXtQRA9HULSJZqNVhfhWInTkVPw+vUo/P9AYv +mJVv6HRNlTb4HCnl6AZGcAYv66J7iWukavmYKxuIbdn4gBJwE0shU9SaP70dh/LT +WqIUuGRZBVH/LCuVGzglGYDh2iiOvR7YRMKf26/9xlR0SpeU/B1g6tRu3p+7OgjA +vJFws+bGSPed07asam3mRZ0Y9QLCXMouWhQZQpx7Or1pUl5Wljhe2W84MfW+Ph6T +yUm/j0yRlZJ750rGfDKA5gKIlTUXr+nTvsK3nnRiHGH2zwrC1BkPG8K6MLRluU/J +ChgZo72AOpVNq9MAEQEAAbQ5U2FsdCBQcm9qZWN0IFBhY2thZ2luZyA8c2FsdHBy +b2plY3QtcGFja2FnaW5nQHZtd2FyZS5jb20+iQHSBBMBCAA8FiEEEIV//dP5Hq5X +eiHWZMu8gXPXaz8FAmPazmACGwMFCwkIBwIDIgIBBhUKCQgLAgQWAgMBAh4HAheA +AAoJEGTLvIFz12s/yf0L/jyP/LfduA4DwpjKX9Vpk26tgis9Q0I54UerpD5ibpTA +krzZxK1yFOPddcOjo+Xqg+I8aA+0nJkf+vsfnRgcpLs2qHZkikwZbPduZwkNUHX7 +6YPSXTwyFlzhaRycwPtvBPLFjfmjjjTi/aH4V/frfxfjH/wFvH/xiaiFsYbP3aAP +sJNTLh3im480ugQ7P54ukdte2QHKsjJ3z4tkjnu1ogc1+ZLCSZVDxfR4gLfE6GsN +YFNd+LF7+NtAeJRuJceXIisj8mTQYg+esTF9QtWovdg7vHVPz8mmcsrG9shGr+G9 +iwwtCig+hAGtXFAuODRMur9QfPlP6FhJw0FX/36iJ2p6APZB0EGqn7LJ91EyOnWv +iRimLLvlGFiVB9Xxw1TxnQMNj9jmB1CA4oNqlromO/AA0ryh13TpcIo5gbn6Jcdc +fD4Rbj5k+2HhJTkQ78GpZ0q95P08XD2dlaM2QxxKQGqADJOdV2VgjB2NDXURkInq +6pdkcaRgAKme8b+xjCcVjLkBjQRj2s5gAQwAxmgflHInM8oKQnsXezG5etLmaUsS +EkV5jjQFCShNn9zJEF/PWJk5Df/mbODj02wyc749dSJbRlTY3LgGz1AeywOsM1oQ +XkhfRZZqMwqvfx8IkEPjMvGIv/UI9pqqg/TY7OiYLEDahYXHJDKmlnmCBlnU96cL +yh7a/xY3ZC20/JwbFVAFzD4biWOrAm1YPpdKbqCPclpvRP9N6nb6hxvKKmDo7MqS +uANZMaoqhvnGazt9n435GQkYRvtqmqmOvt8I4oCzV0Y39HfbCHhhy64HSIowKYE7 +YWIujJcfoIDQqq2378T631BxLEUPaoSOV4B8gk/Jbf3KVu4LNqJive7chR8F1C2k +eeAKpaf2CSAe7OrbAfWysHRZ060bSJzRk3COEACk/UURY+RlIwh+LQxEKb1YQueS +YGjxIjV1X7ScyOvam5CmqOd4do9psOS7MHcQNeUbhnjm0TyGT9DF8ELoE0NSYa+J +PvDGHo51M33s31RUO4TtJnU5xSRb2sOKzIuBABEBAAGJAbYEGAEIACAWIQQQhX/9 +0/kerld6IdZky7yBc9drPwUCY9rOYAIbDAAKCRBky7yBc9drP8ctC/9wGi01cBAW +BPEKEnfrKdvlsaLeRxotriupDqGSWxqVxBVd+n0Xs0zPB/kuZFTkHOHpbAWkhPr+ +hP+RJemxCKMCo7kT2FXVR1OYej8Vh+aYWZ5lw6dJGtgo3Ebib2VSKdasmIOI2CY/ +03G46jv05qK3fP6phz+RaX+9hHgh1XW9kKbdkX5lM9RQSZOof3/67IN8w+euy61O +UhNcrsDKrp0kZxw3S+b/02oP1qADXHz2BUerkCZa4RVK1pM0UfRUooOHiEdUxKKM +DE501hwQsMH7WuvlIR8Oc2UGkEtzgukhmhpQPSsVPg54y9US+LkpztM+yq+zRu33 +gAfssli0MvSmkbcTDD22PGbgPMseyYxfw7vuwmjdqvi9Z4jdln2gyZ6sSZdgUMYW +PGEjZDoMzsZx9Zx6SO9XCS7XgYHVc8/B2LGSxj+rpZ6lBbywH88lNnrm/SpQB74U +4QVLffuw76FanTH6advqdWIqtlWPoAQcEkKf5CdmfT2ei2wX1QLatTs= +=ZKPF +-----END PGP PUBLIC KEY BLOCK----- \ No newline at end of file diff --git a/data/live-build-config/archives/saltstack.pref.chroot b/data/live-build-config/archives/saltstack.pref.chroot new file mode 100644 index 0000000000..ab008cb974 --- /dev/null +++ b/data/live-build-config/archives/saltstack.pref.chroot @@ -0,0 +1,3 @@ +Package: salt-* +Pin: version 3006.* +Pin-Priority: 1001 diff --git a/data/live-build-config/hooks/live/18-enable-disable_services.chroot b/data/live-build-config/hooks/live/18-enable-disable_services.chroot index 04ca7f3e12..e442fd71f0 100755 --- a/data/live-build-config/hooks/live/18-enable-disable_services.chroot +++ b/data/live-build-config/hooks/live/18-enable-disable_services.chroot @@ -72,6 +72,10 @@ systemctl disable suricata.service systemctl disable vyconfd.service systemctl disable vpp.service systemctl disable netplug.service +systemctl disable stunnel4.service +systemctl disable igmpproxy.service +systemctl disable wide-dhcpv6-client.service +systemctl disable qat_service.service echo I: Enabling services systemctl enable vyos-hostsd.service diff --git a/docker-vyos/Dockerfile b/docker-vyos/Dockerfile index 3fff371b1f..3b8b0d01d9 100644 --- a/docker-vyos/Dockerfile +++ b/docker-vyos/Dockerfile @@ -19,7 +19,7 @@ ARG VYOS_VERSION ARG BUILD_DATE # Use Debian as base layer -FROM debian:bookworm-slim +FROM debian:trixie-slim LABEL authors="VyOS Maintainers " ENV DEBIAN_FRONTEND noninteractive diff --git a/docker/Dockerfile b/docker/Dockerfile index 2c3891e016..b17fa9170e 100644 --- a/docker/Dockerfile +++ b/docker/Dockerfile @@ -18,7 +18,7 @@ # This Dockerfile is installable on both x86, x86-64, armhf and arm64 systems ARG ARCH= -FROM ${ARCH}debian:bookworm-slim +FROM ${ARCH}debian:trixie-slim RUN grep "VERSION_ID" /etc/os-release || (echo 'VERSION_ID="12"' >> /etc/os-release) @@ -49,7 +49,7 @@ LABEL authors="VyOS Maintainers " \ org.opencontainers.image.licenses="GNU" \ org.opencontainers.image.title="vyos-build" \ org.opencontainers.image.description="Container to build VyOS ISO" \ - org.opencontainers.image.base.name="docker.io/debian/debian:bookworm" + org.opencontainers.image.base.name="docker.io/debian/debian:trixie" ENV DEBIAN_FRONTEND=noninteractive RUN /bin/echo -e 'APT::Install-Recommends "0";\nAPT::Install-Suggests "0";' > /etc/apt/apt.conf.d/01norecommends @@ -106,6 +106,7 @@ RUN apt-get update && apt-get install -y \ python3-pip \ python3-flake8 \ python3-autopep8 \ + python3-toml \ python3-tomli \ python3-tomli-w \ yq \ @@ -171,7 +172,8 @@ RUN wget -O /tmp/open-vmdk-master.zip https://github.com/vmware/open-vmdk/archiv # Packages need for build live-build RUN apt-get update && apt-get install -y \ - cpio + cpio \ + debootstrap COPY patches/live-build/0001-save-package-info.patch /tmp/0001-save-package-info.patch @@ -180,26 +182,7 @@ RUN git clone https://salsa.debian.org/live-team/live-build.git /tmp/live-build patch -p1 < /tmp/0001-save-package-info.patch && \ dch -n "Applying fix for save package info" && \ dpkg-buildpackage -us -uc && \ - dpkg -i ../live-build*.deb && \ - rm -rf /tmp/live-build - -# -# live-build: building in docker fails with mounting /proc | /sys -# -# https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=919659 -# https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=921815 -# https://salsa.debian.org/installer-team/debootstrap/merge_requests/26 -# -RUN wget https://salsa.debian.org/klausenbusk-guest/debootstrap/commit/a9a603b17cadbf52cb98cde0843dc9f23a08b0da.patch \ - -O /tmp/a9a603b17cadbf52cb98cde0843dc9f23a08b0da.patch && \ - git clone https://salsa.debian.org/installer-team/debootstrap /tmp/debootstrap && \ - cd /tmp/debootstrap && git checkout 1.0.114 && \ - patch -p1 < /tmp/a9a603b17cadbf52cb98cde0843dc9f23a08b0da.patch && \ - dch -n "Applying fix for docker image compile" && \ - dpkg-buildpackage -us -uc && \ - sudo dpkg -i ../debootstrap*.deb \ - && rm /tmp/a9a603b17cadbf52cb98cde0843dc9f23a08b0da.patch \ - && rm -rf /tmp/debootstrap + dpkg -i ../live-build*.deb # FPM is used when generation Debian pckages for e.g. Intel QAT drivers RUN gem install --no-document fpm @@ -207,7 +190,6 @@ RUN gem install --no-document fpm # Add vyos package repo COPY vyos-dev.list /etc/apt/sources.list.d/vyos-dev.list COPY vyos-dev.key /usr/share/keyrings/vyos-dev-archive-keyring.gpg -RUN apt-key add /usr/share/keyrings/vyos-dev-archive-keyring.gpg # Packages needed for vyos-1x RUN pip --no-cache --no-cache-dir install --break-system-packages \ @@ -226,7 +208,8 @@ RUN pip --no-cache --no-cache-dir install --break-system-packages \ python3-inotify \ python3-xmltodict \ python3-lxml \ - python3-nose \ + python3-pytest \ + python3-nose2 \ python3-netifaces \ python3-jinja2 \ python3-jmespath \ @@ -290,13 +273,13 @@ RUN apt-get update && apt-get install -y \ python3-jsonpatch \ python3-mock \ python3-oauthlib \ - python3-pep8 \ + # python3-pep8 \ # has no installation candidate (trixie) python3-pyflakes \ python3-serial \ - python3-unittest2 \ + # python3-unittest2 \ # Unable to locate package (trixie) python3-yaml \ python3-jsonschema \ - python3-contextlib2 \ + # python3-contextlib2 \ # has no installation candidate (trixie) python3-pytest-cov \ cloud-utils diff --git a/docker/vyos-dev.list b/docker/vyos-dev.list index 277a86c142..dc38eb0f19 100644 --- a/docker/vyos-dev.list +++ b/docker/vyos-dev.list @@ -1 +1 @@ -deb https://packages.vyos.net/repositories/current current main +deb [signed-by=/usr/share/keyrings/vyos-dev-archive-keyring.gpg] https://packages.vyos.net/repositories/current current main diff --git a/scripts/check-qemu-install b/scripts/check-qemu-install index 91290a3187..feac6b7d2a 100755 --- a/scripts/check-qemu-install +++ b/scripts/check-qemu-install @@ -156,7 +156,7 @@ def get_qemu_cmd(name, enable_uefi, disk_img, raid=None, iso_img=None, tpm=False vnc = '-vnc :0' if enable_uefi: - uefi = '-bios /usr/share/OVMF/OVMF_CODE.fd' + uefi = '-bios /usr/share/ovmf/OVMF.fd' name = f'{name}-UEFI' if secure_boot: diff --git a/scripts/image-build/build-vyos-image b/scripts/image-build/build-vyos-image index 6919b00302..16ba36f0cf 100755 --- a/scripts/image-build/build-vyos-image +++ b/scripts/image-build/build-vyos-image @@ -621,13 +621,13 @@ DOCUMENTATION_URL="{build_config['documentation_url']}" --archive-areas "{{debian_archive_areas}}" \ --backports true \ --binary-image iso-hybrid \ - --bootappend-live "boot=live components hostname=vyos username=live nopersistence noautologin nonetworking union=overlay console=ttyS0,115200 console=tty0 net.ifnames=0 biosdevname=0" \ - --bootappend-live-failsafe "live components memtest noapic noapm nodma nomce nolapic nomodeset nosmp nosplash vga=normal console=ttyS0,115200 console=tty0 net.ifnames=0 biosdevname=0" \ + --bootappend-live "boot=live components hostname=vyos username=live nopersistence noautologin nonetworking union=overlay console=ttyS0,115200 console=tty0 net.ifnames=0 biosdevname=0 systemd.gpt_auto=0" \ + --bootappend-live-failsafe "live components memtest noapic noapm nodma nomce nolapic nomodeset nosmp nosplash vga=normal console=ttyS0,115200 console=tty0 net.ifnames=0 biosdevname=0 systemd.gpt_auto=0" \ --bootloaders "{{bootloaders}}" \ --checksums "sha256" \ --chroot-squashfs-compression-type "{{squashfs_compression_type}}" \ --debian-installer none \ - --debootstrap-options "--variant=minbase --exclude=isc-dhcp-client,isc-dhcp-common,ifupdown --include=apt-utils,ca-certificates,gnupg2,linux-kbuild-6.1" \ + --debootstrap-options "--variant=minbase --exclude=isc-dhcp-client,isc-dhcp-common,ifupdown --include=apt-utils,ca-certificates,gnupg2,linux-kbuild-6.12.38+deb13" \ --distribution "{{debian_distribution}}" \ --firmware-binary false \ --firmware-chroot false \ @@ -681,6 +681,7 @@ Pin-Priority: 600 print("I: Starting image build") if debug: print("D: It's not like I'm building this specially for you or anything!") + cmd("lb build 2>&1") # Copy the image diff --git a/scripts/package-build/linux-kernel/build-intel-qat.sh b/scripts/package-build/linux-kernel/build-intel-qat.sh index c2c364a987..16d8a23641 100755 --- a/scripts/package-build/linux-kernel/build-intel-qat.sh +++ b/scripts/package-build/linux-kernel/build-intel-qat.sh @@ -14,7 +14,7 @@ fi . ${KERNEL_VAR_FILE} -url="https://packages.vyos.net/source-mirror/QAT.L.4.24.0-00005.tar.gz" +url="https://packages.vyos.net/source-mirror/QAT.L.4.28.0-00004.tar.gz" cd ${CWD} @@ -72,7 +72,7 @@ cp quickassist/qat/fw/*.bin ${DEBIAN_DIR}/lib/firmware cp build/*.so ${DEBIAN_DIR}/usr/lib/x86_64-linux-gnu cp build/adf_ctl ${DEBIAN_DIR}/usr/sbin cp quickassist/build_system/build_files/qat_service ${DEBIAN_DIR}/etc/init.d -cp build/usdm_drv.ko ${DEBIAN_DIR}/lib/modules/${KERNEL_VERSION}${KERNEL_SUFFIX}/updates/drivers +#cp build/usdm_drv.ko ${DEBIAN_DIR}/lib/modules/${KERNEL_VERSION}${KERNEL_SUFFIX}/updates/drivers chmod 644 ${DEBIAN_DIR}/lib/firmware/* chmod 755 ${DEBIAN_DIR}/etc/init.d/* ${DEBIAN_DIR}/usr/local/bin/* diff --git a/scripts/package-build/linux-kernel/build-ipt-netflow.sh b/scripts/package-build/linux-kernel/build-ipt-netflow.sh index 9245a4161d..e5f667a924 100755 --- a/scripts/package-build/linux-kernel/build-ipt-netflow.sh +++ b/scripts/package-build/linux-kernel/build-ipt-netflow.sh @@ -19,6 +19,13 @@ if [ -d .git ]; then git clean --force -d -x fi +PATCH_DIR=${CWD}/patches/ipt-netflow +for patch in $(ls ${PATCH_DIR}) +do + echo "I: Apply patch: ${PATCH_DIR}/${patch}" + patch -p1 < ${PATCH_DIR}/${patch} +done + . ${KERNEL_VAR_FILE} DRIVER_VERSION=$(git describe | sed s/^v//) diff --git a/scripts/package-build/linux-kernel/build-jool.py b/scripts/package-build/linux-kernel/build-jool.py index 3d2c3d6a02..80fc23a547 100755 --- a/scripts/package-build/linux-kernel/build-jool.py +++ b/scripts/package-build/linux-kernel/build-jool.py @@ -38,7 +38,7 @@ def add_depends(package_dir: str, package_name: str, PACKAGE_VERSION: str = '4.1.9+bf4c7e3669' PACKAGE_DIR: str = f'{PACKAGE_NAME}-{PACKAGE_VERSION}' SOURCES_ARCHIVE: str = 'jool-4.1.9+bf4c7e3669.tar.gz' -SOURCES_URL: str = f'https://github.com/NICMx/Jool/archive/7f08c42c615ed63cf0fdc1522d91aa0809f6d990.tar.gz' +SOURCES_URL: str = f'https://packages.vyos.net/source-mirror/jool-4.1.9+bf4c7e3669.tar.gz' # download sources sources_archive = Path(SOURCES_ARCHIVE) @@ -46,7 +46,7 @@ def add_depends(package_dir: str, package_name: str, # prepare sources debmake_cmd: list[str] = [ - 'debmake', '-e', 'support@vyos.io', '-f', 'VyOS Support', '-p', + 'debmake', '-z', 'tar.gz', '-e', 'support@vyos.io', '-f', 'VyOS Support', '-p', PACKAGE_NAME, '-u', PACKAGE_VERSION, '-a', SOURCES_ARCHIVE ] run(debmake_cmd) diff --git a/scripts/package-build/linux-kernel/build-linux-firmware.sh b/scripts/package-build/linux-kernel/build-linux-firmware.sh index 2b1fa7b767..d72aacff9e 100755 --- a/scripts/package-build/linux-kernel/build-linux-firmware.sh +++ b/scripts/package-build/linux-kernel/build-linux-firmware.sh @@ -22,7 +22,7 @@ fi result=() # Retrieve firmware blobs from source files -FW_FILES=$(find ${LINUX_SRC}/debian/linux-image/lib/modules/${KERNEL_VERSION}${KERNEL_SUFFIX}/kernel/drivers/net -name *.ko | xargs modinfo | grep "^firmware:" | awk '{print $2}') +FW_FILES=$(find ${LINUX_SRC}/debian/linux-image-${KERNEL_VERSION}${KERNEL_SUFFIX}/lib/modules/${KERNEL_VERSION}${KERNEL_SUFFIX}/kernel/drivers/net -name *.ko | xargs modinfo | grep "^firmware:" | awk '{print $2}') # Debian package will use the descriptive Git commit as version GIT_COMMIT=$(cd ${CWD}/${LINUX_FIRMWARE}; git describe --always) diff --git a/scripts/package-build/linux-kernel/build-realtek-r8152.py b/scripts/package-build/linux-kernel/build-realtek-r8152.py index 0113eafc79..e6cdaaff2a 100755 --- a/scripts/package-build/linux-kernel/build-realtek-r8152.py +++ b/scripts/package-build/linux-kernel/build-realtek-r8152.py @@ -34,8 +34,8 @@ def add_depends(package_dir: str, package_name: str, PACKAGE_NAME: str = 'vyos-drivers-realtek-r8152' PACKAGE_VERSION: str = '2.18.1' PACKAGE_DIR: str = f'{PACKAGE_NAME}-{PACKAGE_VERSION}' -SOURCES_ARCHIVE: str = 'r8152-2.18.1.tar.bz2' -SOURCES_URL: str = f'https://packages.vyos.net/source-mirror/r8152-2.18.1.tar.bz2' +SOURCES_ARCHIVE: str = 'r8152-2.20.1.tar.gz' +SOURCES_URL: str = 'https://packages.vyos.net/source-mirror/r8152-2.20.1.tar.gz' # download sources sources_archive = Path(SOURCES_ARCHIVE) @@ -43,7 +43,7 @@ def add_depends(package_dir: str, package_name: str, # prepare sources debmake_cmd: list[str] = [ - 'debmake', '-e', 'support@vyos.io', '-f', 'VyOS Support', '-p', + 'debmake', '-z', 'tar.gz', '-e', 'support@vyos.io', '-f', 'VyOS Support', '-p', PACKAGE_NAME, '-u', PACKAGE_VERSION, '-a', SOURCES_ARCHIVE ] run(debmake_cmd) diff --git a/scripts/package-build/linux-kernel/package.toml b/scripts/package-build/linux-kernel/package.toml index b98bcd2f52..0c78901a43 100644 --- a/scripts/package-build/linux-kernel/package.toml +++ b/scripts/package-build/linux-kernel/package.toml @@ -12,25 +12,25 @@ build_cmd = "build_kernel" [[packages]] name = "linux-firmware" -commit_id = "20240610" +commit_id = "20250613" scm_url = "https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git" build_cmd = "build_linux_firmware" [[packages]] name = "accel-ppp" -commit_id = "1.13.0" +commit_id = "43f9e5c" scm_url = "https://github.com/accel-ppp/accel-ppp.git" build_cmd = "build_accel_ppp" [[packages]] name = "ovpn-dco" -commit_id = "v0.2.20231117" +commit_id = "v0.2.20241216" scm_url = "https://github.com/OpenVPN/ovpn-dco" build_cmd = "build_openvpn_dco" [[packages]] name = "nat-rtsp" -commit_id = "475af0a" +commit_id = "5aeee02" scm_url = "https://github.com/maru-sama/rtsp-linux.git" build_cmd = "build_nat_rtsp" @@ -42,19 +42,19 @@ build_cmd = "build_intel_qat" [[packages]] name = "igb" -commit_id = "v5.18.7" +commit_id = "v5.19.2.1" scm_url = "https://github.com/intel/ethernet-linux-igb" build_cmd = "build_intel_igb" [[packages]] name = "ixgbe" -commit_id = "v6.0.5" +commit_id = "v6.1.4" scm_url = "https://github.com/intel/ethernet-linux-ixgbe" build_cmd = "build_intel_ixgbe" [[packages]] name = "ixgbevf" -commit_id = "v5.0.2" +commit_id = "v5.1.3" scm_url = "http://github.com/intel/ethernet-linux-ixgbevf" build_cmd = "build_intel_ixgbevf" @@ -78,7 +78,7 @@ build_cmd = "build_realtek_r8152" [[packages]] name = "ipt-netflow" -commit_id = "0eb2092e93" +commit_id = "d46ef26" scm_url = "https://github.com/aabc/ipt-netflow" build_cmd = "build_ipt_netflow" @@ -118,7 +118,6 @@ packages = [ "liblua5.3-dev", "libssl3", "libssl-dev", - "libpcre3-dev", "libnl-genl-3-dev", "libxtables-dev", "asciidoc-base" diff --git a/scripts/package-build/linux-kernel/patches/accel-ppp/0002-Add-vrf-support-for-Framed-Route-and-Framed-IPv6-Rou.patch b/scripts/package-build/linux-kernel/patches/accel-ppp/0002-Add-vrf-support-for-Framed-Route-and-Framed-IPv6-Rou.patch index b963050f7f..cf9557e3ca 100644 --- a/scripts/package-build/linux-kernel/patches/accel-ppp/0002-Add-vrf-support-for-Framed-Route-and-Framed-IPv6-Rou.patch +++ b/scripts/package-build/linux-kernel/patches/accel-ppp/0002-Add-vrf-support-for-Framed-Route-and-Framed-IPv6-Rou.patch @@ -19,10 +19,9 @@ Subject: [PATCH 2/4] Add vrf support for Framed-Route and Framed-IPv6-Route create mode 100644 accel-pppd/libnetlink/rt_names.h diff --git a/accel-pppd/CMakeLists.txt b/accel-pppd/CMakeLists.txt -index ab8a350..c3995ea 100644 --- a/accel-pppd/CMakeLists.txt +++ b/accel-pppd/CMakeLists.txt -@@ -123,6 +123,10 @@ ADD_EXECUTABLE(accel-pppd +@@ -171,4 +171,8 @@ ADD_EXECUTABLE(accel-pppd main.c ) @@ -30,9 +29,7 @@ index ab8a350..c3995ea 100644 + target_sources(accel-pppd PRIVATE libnetlink/rt_names.c) +ENDIF (DEFINED HAVE_VRF) + - TARGET_LINK_LIBRARIES(accel-pppd triton rt pthread ${crypto_lib} pcre) - set_property(TARGET accel-pppd PROPERTY CMAKE_SKIP_BUILD_RPATH FALSE) - set_property(TARGET accel-pppd PROPERTY CMAKE_BUILD_WITH_INSTALL_RPATH FALSE) + # check if we have getcontext/setcontext diff --git a/accel-pppd/ctrl/ipoe/ipoe.c b/accel-pppd/ctrl/ipoe/ipoe.c index 61b7c23..6f23fd6 100644 --- a/accel-pppd/ctrl/ipoe/ipoe.c diff --git a/scripts/package-build/linux-kernel/patches/ipt-netflow/0001-kernel-compatibility.patch b/scripts/package-build/linux-kernel/patches/ipt-netflow/0001-kernel-compatibility.patch new file mode 100644 index 0000000000..fd21f6307f --- /dev/null +++ b/scripts/package-build/linux-kernel/patches/ipt-netflow/0001-kernel-compatibility.patch @@ -0,0 +1,875 @@ +From 0ec2162cf645063b3fe5af6b3b3c482444a9508e Mon Sep 17 00:00:00 2001 +From: Andreas Beckmann +Date: Sat, 20 Jul 2024 02:48:42 +0200 +Subject: [PATCH 01/16] compat: Really fix __has_attribute usage + +Fixes: 40fefb2 ("compat: Fix __has_attribute usage") +Signed-off-by: Andreas Beckmann +--- + compat.h | 9 +++++---- + 1 file changed, 5 insertions(+), 4 deletions(-) + +diff --git a/compat.h b/compat.h +index 8461c3d..6c4984b 100644 +--- a/compat.h ++++ b/compat.h +@@ -773,13 +773,14 @@ struct module *find_module(const char *name) + + /* Copy from 294f69e662d1 ("compiler_attributes.h: Add 'fallthrough' pseudo + * keyword for switch/case use") */ +-#ifndef fallthrough +-# if defined __has_attribute && __has_attribute(__fallthrough__) ++#if !defined(fallthrough) && defined(__has_attribute) ++# if __has_attribute(__fallthrough__) + # define fallthrough __attribute__((__fallthrough__)) +-# else +-# define fallthrough do {} while (0) /* fallthrough */ + # endif + #endif ++#ifndef fallthrough ++# define fallthrough do {} while (0) /* fallthrough */ ++#endif + + #ifndef HAVE_NF_CT_EVENT_NOTIFIER_CT_EVENT + /* + +From e7799319f68f0e8483f8b0cc75f5d0dfcda57777 Mon Sep 17 00:00:00 2001 +From: Andreas Beckmann +Date: Wed, 3 Jul 2024 12:06:55 +0200 +Subject: [PATCH 02/16] Fix dkms status invocation + +and do not query unrelated modules + +Signed-off-by: Andreas Beckmann +--- + configure | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/configure b/configure +index 66ced00..86f9488 100755 +--- a/configure ++++ b/configure +@@ -614,7 +614,7 @@ dkms_check() { + echo Yes. + DKMSINSTALL=dinstall + test "$FROMDKMSCONF" && return +- if dkms status | grep ^ipt-netflow, >/dev/null; then ++ if dkms status ipt-netflow | grep ^ipt-netflow/ >/dev/null; then + echo "! You are already have module installed via DKMS" + echo "! it will be uninstalled on 'make install' and" + echo "! current version of module installed afterwards." + +From 944c81ececb31ffac8fd89d09744fb066fc38308 Mon Sep 17 00:00:00 2001 +From: Andreas Beckmann +Date: Wed, 3 Jul 2024 12:09:45 +0200 +Subject: [PATCH 03/16] Do not check for dkms if called from dkms + +the recursive calls slowed down the configure script significantly + +Signed-off-by: Andreas Beckmann +--- + configure | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/configure b/configure +index 86f9488..f2ec1a9 100755 +--- a/configure ++++ b/configure +@@ -348,7 +348,7 @@ do + --disable-snmp-a*) SKIPSNMP=1 ;; + --disable-net-snmp*) SKIPSNMP=1 ;; + --disable-dkms*) SKIPDKMS=1 ;; +- --from-dkms-conf*) ;; ++ --from-dkms-conf*) SKIPDKMS=1 ;; + --make) echo called from make; CARGS=`echo $CARGS | sed s/--make//g` ;; + -Werror) KOPTS="$KOPTS -Werror" ;; + --help|-h) show_help ;; + +From 51d65f0dffba3b2024586b4fbff579186b089af9 Mon Sep 17 00:00:00 2001 +From: Andreas Beckmann +Date: Wed, 3 Jul 2024 12:12:31 +0200 +Subject: [PATCH 04/16] Set KDIR early if called from dkms and get version from + sources + +Signed-off-by: Andreas Beckmann +--- + configure | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/configure b/configure +index f2ec1a9..ae8a579 100755 +--- a/configure ++++ b/configure +@@ -6,6 +6,7 @@ PATH=$PATH:/bin:/usr/bin:/usr/sbin:/sbin:/usr/local/sbin + case "$1" in + --from-dkms-conf*) + KDKMS=`echo "$1" | sed 's/[^=]*.//'` ++ KDIR="$KDKMS" + # restore options from existing Makefile, if present + if [ -e Makefile ]; then + set -- `sed -n 's/^CARGS = \(.*\)/\1/p' Makefile` + +From 55858baa52c0bb55dcd65522b5ffbd59fd507bf2 Mon Sep 17 00:00:00 2001 +From: Andreas Beckmann +Date: Sat, 1 Mar 2025 14:40:37 +0100 +Subject: [PATCH 05/16] dkms.conf: Declare BUILD_EXCLUSIVE_KERNEL_MIN="3" + +skb_reset_mac_len() was introduced in v3.0-rc3 +and is used unconditionally + +Signed-off-by: Andreas Beckmann +--- + dkms.conf | 4 ++++ + ipt_NETFLOW.c | 1 + + 2 files changed, 5 insertions(+) + +diff --git a/dkms.conf b/dkms.conf +index 808e158..7968b38 100644 +--- a/dkms.conf ++++ b/dkms.conf +@@ -2,6 +2,10 @@ PACKAGE_NAME="ipt-netflow" + pushd `dirname $BASH_SOURCE` + PACKAGE_VERSION=`./version.sh` + popd ++ ++# skb_reset_mac_len() was introduced in v3.0-rc3 ++BUILD_EXCLUSIVE_KERNEL_MIN="3" ++ + BUILT_MODULE_NAME[0]=ipt_NETFLOW + DEST_MODULE_LOCATION[0]=/kernel/extra + STRIP[0]=no +diff --git a/ipt_NETFLOW.c b/ipt_NETFLOW.c +index eee8074..91c8c1e 100644 +--- a/ipt_NETFLOW.c ++++ b/ipt_NETFLOW.c +@@ -74,6 +74,7 @@ + * but centos6 have it backported on its 2.6.32.el6 */ + # include + #endif ++#include + #include "compat.h" + #include "ipt_NETFLOW.h" + #include "murmur3.h" + +From 22c47fc63c1fda10a5a8f8bdf99e5fdd7335f280 Mon Sep 17 00:00:00 2001 +From: Andreas Beckmann +Date: Thu, 18 Jul 2024 00:24:57 +0200 +Subject: [PATCH 06/16] Fix module build for Linux v4.3 + +netif_is_bridge_port() was introduced in v4.4-rc2 by +"vlan: Do not put vlan headers back on bridge and macvlan ports" +(28f9ee22bcdd84726dbf6267d0b58f254166b900) + +Signed-off-by: Andreas Beckmann +--- + ipt_NETFLOW.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/ipt_NETFLOW.c b/ipt_NETFLOW.c +index 91c8c1e..4b7b423 100644 +--- a/ipt_NETFLOW.c ++++ b/ipt_NETFLOW.c +@@ -4882,6 +4882,8 @@ static void parse_l2_header(const struct sk_buff *skb, struct ipt_netflow_tuple + && !(vlan->flags & VLAN_FLAG_REORDER_HDR) + # if LINUX_VERSION_CODE >= KERNEL_VERSION(4,3,0) + && !netif_is_macvlan_port(vlan_dev) ++# endif ++# if LINUX_VERSION_CODE >= KERNEL_VERSION(4,4,0) + && !netif_is_bridge_port(vlan_dev) + # endif + )) + +From c2d6eeb62dbe429f7a08b4ae970339884f5d2765 Mon Sep 17 00:00:00 2001 +From: Andreas Beckmann +Date: Sat, 20 Jul 2024 02:22:01 +0200 +Subject: [PATCH 07/16] Unexporting find_module() has been backported to Linux + v5.10.220 + +Signed-off-by: Andreas Beckmann +--- + compat.h | 5 +++-- + 1 file changed, 3 insertions(+), 2 deletions(-) + +diff --git a/compat.h b/compat.h +index 6c4984b..dffc9e3 100644 +--- a/compat.h ++++ b/compat.h +@@ -746,9 +746,10 @@ unsigned long long strtoul(const char *cp, char **endp, unsigned int base) + return result; + } + +-#if LINUX_VERSION_CODE >= KERNEL_VERSION(5,12,0) ++#if (LINUX_VERSION_CODE >= KERNEL_VERSION(5,12,0)) \ ++ || ((LINUX_VERSION_CODE >= KERNEL_VERSION(5,10,220)) && (LINUX_VERSION_CODE < KERNEL_VERSION(5,11,0))) + /* +- * find_module() is unexported in v5.12: ++ * find_module() is unexported in v5.12 (backported to 5.10.220): + * 089049f6c9956 ("module: unexport find_module and module_mutex") + * and module_mutex is replaced with RCU in + * a006050575745 ("module: use RCU to synchronize find_module") + +From ca9a6ae33874c124f8382e68fc65fdbf08cdd6cd Mon Sep 17 00:00:00 2001 +From: Andreas Beckmann +Date: Fri, 7 Mar 2025 10:03:58 +0100 +Subject: [PATCH 08/16] Fix module build for Linux v6.12 + +adapt to "move asm/unaligned.h to linux/unaligned.h" +(5f60d5f6bbc12e782fac78110b0ee62698f3b576) in v6.12-rc2 + +Fixes: #237 +Signed-off-by: Andreas Beckmann +--- + gen_compat_def | 9 +++++++-- + ipt_NETFLOW.c | 4 ++++ + 2 files changed, 11 insertions(+), 2 deletions(-) + +diff --git a/gen_compat_def b/gen_compat_def +index a9cb95e..e9d4e76 100755 +--- a/gen_compat_def ++++ b/gen_compat_def +@@ -64,7 +64,7 @@ kbuild_test_symbol() { + echo -n "Test function $* " >&2 + kbuild_test_compile ${1^^} $1 ${2-} <<-EOF + #include +- ${2:+#include <$2>} ++ ${3:-${2:+#include <$2>}} + MODULE_LICENSE("GPL"); + void *test = $1; + EOF +@@ -121,7 +121,12 @@ kbuild_test_symbol nf_bridge_info_get linux/netfilter_bridge.h + # Stumbled on 5.9 + kbuild_test_struct vlan_dev_priv linux/if_vlan.h + # Kernel version check broken by centos8 +-kbuild_test_symbol put_unaligned_be24 asm/unaligned.h ++kbuild_test_symbol put_unaligned_be24 '???/unaligned.h' '#include ++#if LINUX_VERSION_CODE >= KERNEL_VERSION(6,12,0) ++#include ++#else ++#include ++#endif' + # totalram_pages changed from atomic to inline function. + kbuild_test_symbol totalram_pages linux/mm.h + kbuild_test_ref totalram_pages linux/mm.h +diff --git a/ipt_NETFLOW.c b/ipt_NETFLOW.c +index 4b7b423..bbd2c9b 100644 +--- a/ipt_NETFLOW.c ++++ b/ipt_NETFLOW.c +@@ -68,7 +68,11 @@ + # include + #endif + #include ++#if LINUX_VERSION_CODE >= KERNEL_VERSION(6,12,0) ++#include ++#else + #include ++#endif + #ifdef HAVE_LLIST + /* llist.h is officially defined since linux 3.1, + * but centos6 have it backported on its 2.6.32.el6 */ + +From c5158c432a06ec1c161f418b6f89c9d9bf26ee4a Mon Sep 17 00:00:00 2001 +From: Jaco Kroon +Date: Sun, 16 Mar 2025 17:12:00 +0200 +Subject: [PATCH 09/16] Less verbose kbuild_test_symbol on third parameter. + +Signed-off-by: Jaco Kroon +--- + gen_compat_def | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/gen_compat_def b/gen_compat_def +index e9d4e76..8a25d41 100755 +--- a/gen_compat_def ++++ b/gen_compat_def +@@ -61,7 +61,7 @@ kbuild_test_compile() { + + # Test that symbol is defined (will catch functions mostly). + kbuild_test_symbol() { +- echo -n "Test function $* " >&2 ++ echo -n "Test function $1 $2" >&2 + kbuild_test_compile ${1^^} $1 ${2-} <<-EOF + #include + ${3:-${2:+#include <$2>}} + +From df33a7d0819e0f2fbd645dedb596b53709f07395 Mon Sep 17 00:00:00 2001 +From: Jaco Kroon +Date: Sun, 16 Mar 2025 17:13:44 +0200 +Subject: [PATCH 10/16] Use strscpy rather than strlcpy (keep as fallback). + +strscpy has been around since 4.3, and strlcpy got removed in 6.8. + +This patch switches to the plainly preferred strscpy whenever it is +available, but will define that to strlcpy if strscpy (sized_strscpy due +to strscpy really being a macro) is not available. + +Ideally we want to compile a test-call, but kbuild_test_symbol() doesn't +work that way. + +We could also simply go "#ifndef strscpy ... # define strscpy strlcpy" +if that would be preferred. + +Signed-off-by: Jaco Kroon +--- + compat.h | 4 ++++ + gen_compat_def | 2 ++ + ipt_NETFLOW.c | 11 ++++++----- + 3 files changed, 12 insertions(+), 5 deletions(-) + +diff --git a/compat.h b/compat.h +index dffc9e3..2e12d18 100644 +--- a/compat.h ++++ b/compat.h +@@ -178,6 +178,10 @@ static int __ethtool_get_settings(struct net_device *dev, struct ethtool_cmd *cm + # define NF_IP_POST_ROUTING NF_INET_POST_ROUTING + #endif + ++#ifndef HAVE_SIZED_STRSCPY ++#define strscpy strlcpy ++#endif ++ + #if LINUX_VERSION_CODE < KERNEL_VERSION(2,6,19) + /* net/netfilter/x_tables.c */ + static void xt_unregister_targets(struct xt_target *target, unsigned int n) +diff --git a/gen_compat_def b/gen_compat_def +index 8a25d41..8643369 100755 +--- a/gen_compat_def ++++ b/gen_compat_def +@@ -134,6 +134,8 @@ kbuild_test_ref totalram_pages linux/mm.h + kbuild_test_member nf_ct_event_notifier.ct_event net/netfilter/nf_conntrack_ecache.h + # 6.4: 0199849acd07 ("sysctl: remove register_sysctl_paths()") + kbuild_test_symbol register_sysctl_paths linux/sysctl.h ++# If we have strscpy, we can use that (more optimal compared to strlcpy). ++kbuild_test_symbol sized_strscpy linux/string.h + + echo "// End of compat_def.h" + +diff --git a/ipt_NETFLOW.c b/ipt_NETFLOW.c +index bbd2c9b..a8455d8 100644 +--- a/ipt_NETFLOW.c ++++ b/ipt_NETFLOW.c +@@ -42,6 +42,7 @@ + #include + #include + #include ++#include + #include + #include + #include +@@ -4092,7 +4093,7 @@ static int ethtool_drvinfo(unsigned char *ptr, size_t size, struct net_device *d + ops->get_drvinfo(dev, &info); + #if LINUX_VERSION_CODE >= KERNEL_VERSION(2,6,37) + else if (dev->dev.parent && dev->dev.parent->driver) { +- strlcpy(info.driver, dev->dev.parent->driver->name, sizeof(info.driver)); ++ strscpy(info.driver, dev->dev.parent->driver->name, sizeof(info.driver)); + } + #endif + n = scnprintf(ptr, len, "%s", info.driver); +@@ -5691,7 +5692,7 @@ static int __init ipt_netflow_init(void) + if (!destination) + destination = destination_buf; + if (destination != destination_buf) { +- strlcpy(destination_buf, destination, sizeof(destination_buf)); ++ strscpy(destination_buf, destination, sizeof(destination_buf)); + destination = destination_buf; + } + if (add_destinations(destination) < 0) +@@ -5701,7 +5702,7 @@ static int __init ipt_netflow_init(void) + if (!aggregation) + aggregation = aggregation_buf; + if (aggregation != aggregation_buf) { +- strlcpy(aggregation_buf, aggregation, sizeof(aggregation_buf)); ++ strscpy(aggregation_buf, aggregation, sizeof(aggregation_buf)); + aggregation = aggregation_buf; + } + add_aggregation(aggregation); +@@ -5711,7 +5712,7 @@ static int __init ipt_netflow_init(void) + if (!sampler) + sampler = sampler_buf; + if (sampler != sampler_buf) { +- strlcpy(sampler_buf, sampler, sizeof(sampler_buf)); ++ strscpy(sampler_buf, sampler, sizeof(sampler_buf)); + sampler = sampler_buf; + } + parse_sampler(sampler); +@@ -5728,7 +5729,7 @@ static int __init ipt_netflow_init(void) + if (!snmp_rules) + snmp_rules = snmp_rules_buf; + if (snmp_rules != snmp_rules_buf) { +- strlcpy(snmp_rules_buf, snmp_rules, sizeof(snmp_rules_buf)); ++ strscpy(snmp_rules_buf, snmp_rules, sizeof(snmp_rules_buf)); + snmp_rules = snmp_rules_buf; + } + add_snmp_rules(snmp_rules); + +From 42382255d39f8a9f0913eba013969d91a278e42c Mon Sep 17 00:00:00 2001 +From: Jaco Kroon +Date: Sun, 16 Mar 2025 18:04:23 +0200 +Subject: [PATCH 11/16] Custom strtoul => simple_strtoul. + +I've verified and traced this back to the initial import into git, +around version 2.6.12 of the kernel. If anybody fails to compile +against older than that I think we can look into this but highly doubt +that'll be an issue. + +Signed-off-by: Jaco Kroon +--- + compat.h | 34 ---------------------------------- + ipt_NETFLOW.c | 4 ++-- + 2 files changed, 2 insertions(+), 36 deletions(-) + +diff --git a/compat.h b/compat.h +index 2e12d18..7447f91 100644 +--- a/compat.h ++++ b/compat.h +@@ -716,40 +716,6 @@ static inline void do_gettimeofday(struct timeval *tv) + } + #endif + +-#define TOLOWER(x) ((x) | 0x20) +-unsigned long long strtoul(const char *cp, char **endp, unsigned int base) +-{ +- unsigned long long result = 0; +- +- if (!base) { +- if (cp[0] == '0') { +- if (TOLOWER(cp[1]) == 'x' && isxdigit(cp[2])) +- base = 16; +- else +- base = 8; +- } else { +- base = 10; +- } +- } +- +- if (base == 16 && cp[0] == '0' && TOLOWER(cp[1]) == 'x') +- cp += 2; +- +- while (isxdigit(*cp)) { +- unsigned int value; +- +- value = isdigit(*cp) ? *cp - '0' : TOLOWER(*cp) - 'a' + 10; +- if (value >= base) +- break; +- result = result * base + value; +- cp++; +- } +- if (endp) +- *endp = (char *)cp; +- +- return result; +-} +- + #if (LINUX_VERSION_CODE >= KERNEL_VERSION(5,12,0)) \ + || ((LINUX_VERSION_CODE >= KERNEL_VERSION(5,10,220)) && (LINUX_VERSION_CODE < KERNEL_VERSION(5,11,0))) + /* +diff --git a/ipt_NETFLOW.c b/ipt_NETFLOW.c +index a8455d8..c305cff 100644 +--- a/ipt_NETFLOW.c ++++ b/ipt_NETFLOW.c +@@ -2402,7 +2402,7 @@ static int add_destinations(const char *ptr) + ++end; + if (succ && + (*end == ':' || *end == '.' || *end == 'p' || *end == '#')) +- sin6->sin6_port = htons(strtoul(++end, (char **)&end, 0)); ++ sin6->sin6_port = htons(simple_strtoul(++end, (char **)&end, 0)); + if (succ && *end == '@') { + ++end; + sout->sin6_family = AF_INET6; +@@ -2417,7 +2417,7 @@ static int add_destinations(const char *ptr) + sin->sin_port = htons(2055); + succ = in4_pton(ptr, len, (u8 *)&sin->sin_addr, -1, &end); + if (succ && *end == ':') +- sin->sin_port = htons(strtoul(++end, (char **)&end, 0)); ++ sin->sin_port = htons(simple_strtoul(++end, (char **)&end, 0)); + if (succ && *end == '@') { + ++end; + sout->sin_family = AF_INET; + +From 87074c132a0db7d8ecde3d1c4194bc8cdcd11e9b Mon Sep 17 00:00:00 2001 +From: Jaco Kroon +Date: Sun, 16 Mar 2025 18:05:33 +0200 +Subject: [PATCH 12/16] static inline functions that's defined in headers. + +Signed-off-by: Jaco Kroon +--- + compat.h | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/compat.h b/compat.h +index 7447f91..8f7df98 100644 +--- a/compat.h ++++ b/compat.h +@@ -220,7 +220,7 @@ struct timeval { + long tv_usec; /* microseconds */ + }; + +-unsigned long timeval_to_jiffies(const struct timeval *tv) ++static inline unsigned long timeval_to_jiffies(const struct timeval *tv) + { + return timespec64_to_jiffies(&(struct timespec64){ + tv->tv_sec, +@@ -387,7 +387,7 @@ static int sockaddr_cmp(const struct sockaddr_storage *sa1, const struct sockadd + #ifndef IN6PTON_XDIGIT + #define hex_to_bin compat_hex_to_bin + /* lib/hexdump.c */ +-int hex_to_bin(char ch) ++static inline int hex_to_bin(char ch) + { + if ((ch >= '0') && (ch <= '9')) + return ch - '0'; + +From 5612f23270dda9db03782f19f8958cc4564357da Mon Sep 17 00:00:00 2001 +From: Jaco Kroon +Date: Sun, 16 Mar 2025 17:22:03 +0200 +Subject: [PATCH 13/16] Add .gitignore file. + +Signed-off-by: Jaco Kroon +--- + .gitignore | 12 ++++++++++++ + 1 file changed, 12 insertions(+) + create mode 100644 .gitignore + +diff --git a/.gitignore b/.gitignore +new file mode 100644 +index 0000000..93ce46a +--- /dev/null ++++ b/.gitignore +@@ -0,0 +1,12 @@ ++.*.cmd ++.*.o.d ++*.ko ++*.o ++*.mod ++*.mod.c ++*.so ++Makefile ++Module.symvers ++compat_def.h ++modules.order ++version.h + +From 2a2c579751013f9db8089fe112f2d820308dc08f Mon Sep 17 00:00:00 2001 +From: Jaco Kroon +Date: Sun, 16 Mar 2025 18:14:33 +0200 +Subject: [PATCH 14/16] Add required const to proc_handler prototypes for + sysfs. + +Signed-off-by: Jaco Kroon +--- + ipt_NETFLOW.c | 22 +++++++++++----------- + 1 file changed, 11 insertions(+), 11 deletions(-) + +diff --git a/ipt_NETFLOW.c b/ipt_NETFLOW.c +index c305cff..8314000 100644 +--- a/ipt_NETFLOW.c ++++ b/ipt_NETFLOW.c +@@ -1525,7 +1525,7 @@ static int switch_promisc(int newpromisc) + + #ifdef CONFIG_SYSCTL + /* sysctl /proc/sys/net/netflow */ +-static int hsize_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *filp,) ++static int hsize_procctl(const ctl_table *ctl, int write, BEFORE2632(struct file *filp,) + void __user *buffer, size_t *lenp, loff_t *fpos) + { + int ret, hsize; +@@ -1542,7 +1542,7 @@ static int hsize_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *filp + return ret; + } + +-static int sndbuf_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *filp,) ++static int sndbuf_procctl(const ctl_table *ctl, int write, BEFORE2632(struct file *filp,) + void __user *buffer, size_t *lenp, loff_t *fpos) + { + int ret; +@@ -1577,7 +1577,7 @@ static int sndbuf_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *fil + } + + static void free_templates(void); +-static int destination_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *filp,) ++static int destination_procctl(const ctl_table *ctl, int write, BEFORE2632(struct file *filp,) + void __user *buffer, size_t *lenp, loff_t *fpos) + { + int ret; +@@ -1594,7 +1594,7 @@ static int destination_procctl(ctl_table *ctl, int write, BEFORE2632(struct file + } + + #ifdef ENABLE_AGGR +-static int aggregation_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *filp,) ++static int aggregation_procctl(const ctl_table *ctl, int write, BEFORE2632(struct file *filp,) + void __user *buffer, size_t *lenp, loff_t *fpos) + { + int ret; +@@ -1609,7 +1609,7 @@ static int aggregation_procctl(ctl_table *ctl, int write, BEFORE2632(struct file + #endif + + #ifdef ENABLE_PROMISC +-static int promisc_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *filp,) ++static int promisc_procctl(const ctl_table *ctl, int write, BEFORE2632(struct file *filp,) + void __user *buffer, size_t *lenp, loff_t *fpos) + { + int newpromisc = promisc; +@@ -1626,7 +1626,7 @@ static int promisc_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *fi + + #ifdef ENABLE_SAMPLER + static int parse_sampler(char *ptr); +-static int sampler_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *filp,) ++static int sampler_procctl(const ctl_table *ctl, int write, BEFORE2632(struct file *filp,) + void __user *buffer, size_t *lenp, loff_t *fpos) + { + int ret; +@@ -1659,7 +1659,7 @@ static int sampler_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *fi + + #ifdef SNMP_RULES + static int add_snmp_rules(char *ptr); +-static int snmp_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *filp,) ++static int snmp_procctl(const ctl_table *ctl, int write, BEFORE2632(struct file *filp,) + void __user *buffer, size_t *lenp, loff_t *fpos) + { + int ret; +@@ -1684,7 +1684,7 @@ static void clear_ipt_netflow_stat(void) + } + } + +-static int flush_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *filp,) ++static int flush_procctl(const ctl_table *ctl, int write, BEFORE2632(struct file *filp,) + void __user *buffer, size_t *lenp, loff_t *fpos) + { + int ret; +@@ -1713,7 +1713,7 @@ static int flush_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *filp + return ret; + } + +-static int protocol_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *filp,) ++static int protocol_procctl(const ctl_table *ctl, int write, BEFORE2632(struct file *filp,) + void __user *buffer, size_t *lenp, loff_t *fpos) + { + int ret; +@@ -1746,7 +1746,7 @@ static int protocol_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *f + #ifdef CONFIG_NF_NAT_NEEDED + static void register_ct_events(void); + static void unregister_ct_events(void); +-static int natevents_procctl(ctl_table *ctl, int write, BEFORE2632(struct file *filp,) ++static int natevents_procctl(const ctl_table *ctl, int write, BEFORE2632(struct file *filp,) + void __user *buffer, size_t *lenp, loff_t *fpos) + { + int ret; +@@ -1772,7 +1772,7 @@ static struct ctl_table_header *netflow_sysctl_header; + + #if LINUX_VERSION_CODE < KERNEL_VERSION(2,6,20) + #define _CTL_NAME(x) .ctl_name = x, +-static void ctl_table_renumber(ctl_table *table) ++static void ctl_table_renumber(const ctl_table *table) + { + int c; + + +From 5fb1aed4c7da1e231d75fbe6dcdd223258306691 Mon Sep 17 00:00:00 2001 +From: Jaco Kroon +Date: Mon, 17 Mar 2025 09:59:17 +0200 +Subject: [PATCH 15/16] Fix printf type warnings. + +Signed-off-by: Jaco Kroon +--- + ipt_NETFLOW.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/ipt_NETFLOW.c b/ipt_NETFLOW.c +index 8314000..2504fbc 100644 +--- a/ipt_NETFLOW.c ++++ b/ipt_NETFLOW.c +@@ -765,11 +765,11 @@ static int nf_seq_show(struct seq_file *seq, void *v) + sampler_mode_string(), + get_sampler_interval()); + if (get_sampler_mode() != SAMPLER_HASH) +- seq_printf(seq, " Flows selected %lu, discarded %lu.", ++ seq_printf(seq, " Flows selected %lld, discarded %llu.", + atomic64_read(&flows_selected), + atomic64_read(&flows_observed) - atomic64_read(&flows_selected)); + else +- seq_printf(seq, " Flows selected %lu.", atomic64_read(&flows_selected)); ++ seq_printf(seq, " Flows selected %llu.", atomic64_read(&flows_selected)); + seq_printf(seq, " Pkts selected %llu, discarded %llu.\n", + t.pkts_selected, + t.pkts_observed - t.pkts_selected); + +From 0c5759d002131ac3ae161713f4ce0d515037c1de Mon Sep 17 00:00:00 2001 +From: Jaco Kroon +Date: Mon, 17 Mar 2025 16:43:30 +0200 +Subject: [PATCH 16/16] Fix prandom_u32{,_max} => get_random_u32{,_below} + +For backwards compatiblity this gets pretty nasty. This should work +fairly well. + +Signed-off-by: Jaco Kroon +--- + compat.h | 33 +++++++++++++++++++++++++-------- + gen_compat_def | 44 ++++++++++++++++++++++++++++++++++++++------ + ipt_NETFLOW.c | 6 +++--- + 3 files changed, 66 insertions(+), 17 deletions(-) + +diff --git a/compat.h b/compat.h +index 8f7df98..2383997 100644 +--- a/compat.h ++++ b/compat.h +@@ -108,17 +108,34 @@ union nf_inet_addr { + # define time_is_after_jiffies(a) time_before(jiffies, a) + #endif + +-#if LINUX_VERSION_CODE < KERNEL_VERSION(3,14,0) +-# if LINUX_VERSION_CODE < KERNEL_VERSION(2,6,19) +-# define prandom_u32 get_random_int +-# elif LINUX_VERSION_CODE < KERNEL_VERSION(3,8,0) +-# define prandom_u32 random32 ++#ifndef HAVE_GET_RANDOM_U32 ++# ifdef HAVE_PRANDOM_U32 ++# ifdef HAVE_PRANDOM_H ++# include ++# endif ++static inline u32 get_random_u32() { ++ return prandom_u32(); ++} ++# else ++# pragma error Need fallback for get_random_u32 ++# endif + #endif +-#define prandom_u32_max compat_prandom_u32_max +-static inline u32 prandom_u32_max(u32 ep_ro) ++ ++#ifndef HAVE_GET_RANDOM_U32_BELOW ++# ifdef HAVE_PRANDOM_U32_MAX ++# ifdef HAVE_PRANDOM_H ++# include ++# endif ++static inline u32 get_random_u32_below(u32 ep_ro) + { +- return (u32)(((u64) prandom_u32() * ep_ro) >> 32); ++ return prandom_u32_max(ep_ro); + } ++# else ++static inline u32 get_random_u32_below(u32 ep_ro) ++{ ++ return (u32)(((u64) get_random_u32() * ep_ro) >> 32); ++} ++# endif + #endif + + #ifndef min_not_zero +diff --git a/gen_compat_def b/gen_compat_def +index 8643369..a26c5c4 100755 +--- a/gen_compat_def ++++ b/gen_compat_def +@@ -1,4 +1,4 @@ +-#!/bin/bash -efu ++#!/bin/bash -fu + # SPDX-License-Identifier: GPL-2.0-only + # + # Generate defines based on kernel having some symbols declared. +@@ -21,7 +21,7 @@ WD=cc-test-build + mkdir -p $WD + cd ./$WD || fatal "cannot cd to $WD" + +-# args: HAVE_SUMBOL symbol include ++# args: HAVE_SYMBOL symbol [include] [success] [failure] + kbuild_test_compile() { + local cmd + +@@ -30,14 +30,15 @@ kbuild_test_compile() { + cmd="make -s -B -C $KDIR M=$PWD modules" + echo "$cmd" > log + if $cmd >> log 2>&1; then +- echo " declared" >&2 +- [ "$2" ] && echo "// $2 is declared ${3:+in <$3>}" ++ echo " ${4-declared}" >&2 ++ [ "$2" ] && echo "// $2 ${4-is declared}${3:+ in <$3>}" + echo "#define HAVE_$1" + echo ++ return 0 + else +- echo " undeclared" >&2 ++ echo " ${5-undeclared}" >&2 + echo "#undef HAVE_$1" +- echo "// ${2:-symbol} is undeclared${3:+ in <$3>}. Compile:" ++ echo "// ${2:-symbol} ${5-is undeclared}${3:+ in <$3>}. Compile:" + sed "s/^/\/\/ /" test.c + echo "// Output:" + sed "s/^/\/\/ /" log +@@ -56,6 +57,7 @@ kbuild_test_compile() { + echo >&2 + exit 3 + fi ++ return 1 + fi + } + +@@ -105,6 +107,22 @@ kbuild_test_member() { + typeof(((struct $structname*)0)->$member) test; + EOF + } ++ ++# Test that a header is available/exist ++kbuild_test_header() { ++ echo -n "Test header $*" >&2 ++ structname=${1%.*} ++ member=${1#*.} ++ def=${1^^} ++ def=${def##*/} ++ def=${def//./_} ++ kbuild_test_compile $def "header $1" "" "exists" "doesn't exist" <<-EOF ++ #include ++ #include <$1> ++ MODULE_LICENSE("GPL"); ++ EOF ++} ++ + echo "// Autogenerated for $KDIR" + echo + +@@ -136,6 +154,20 @@ kbuild_test_member nf_ct_event_notifier.ct_event net/netfilter/nf_conntrack_ecac + kbuild_test_symbol register_sysctl_paths linux/sysctl.h + # If we have strscpy, we can use that (more optimal compared to strlcpy). + kbuild_test_symbol sized_strscpy linux/string.h ++# Do we have get_random_u32_below ++kbuild_test_symbol get_random_u32_below linux/random.h ++# Do we have get_random_u32 ++kbuild_test_symbol get_random_u32 linux/random.h ++ ++# prandom functions moved from random.h to prandom.h recentish. ++# We use these for fallback for the above only. ++if kbuild_test_header linux/prandom.h; then ++ prand_h=linux/prandom.h ++else ++ prand_h=linux/random.h ++fi ++kbuild_test_symbol prandom_u32 $prand_h ++kbuild_test_symbol prandom_u32_max $prand_h + + echo "// End of compat_def.h" + +diff --git a/ipt_NETFLOW.c b/ipt_NETFLOW.c +index 2504fbc..707dede 100644 +--- a/ipt_NETFLOW.c ++++ b/ipt_NETFLOW.c +@@ -4460,7 +4460,7 @@ static int netflow_scan_and_export(const int flush) + val = nf->sampler_count % interval; + break; + case SAMPLER_RANDOM: +- val = prandom_u32_max(interval); ++ val = get_random_u32_below(interval); + break; + default: /* SAMPLER_HASH */ + val = 0; +@@ -5717,12 +5717,12 @@ static int __init ipt_netflow_init(void) + } + parse_sampler(sampler); + #ifdef SAMPLING_HASH +- hash_seed = prandom_u32(); ++ hash_seed = get_random_u32(); + #endif + #endif + + #ifdef ENABLE_RANDOM_TEMPLATE_IDS +- template_ids = FLOWSET_DATA_FIRST | prandom_u32_max(0x00010000); ++ template_ids = FLOWSET_DATA_FIRST | get_random_u32_below(0x00010000); + #endif + + #ifdef SNMP_RULES diff --git a/scripts/package-build/linux-kernel/patches/kernel/0001-linkstate-ip-device-attribute.patch b/scripts/package-build/linux-kernel/patches/kernel/0001-linkstate-ip-device-attribute.patch index bed612cdf3..187f6cb9e6 100644 --- a/scripts/package-build/linux-kernel/patches/kernel/0001-linkstate-ip-device-attribute.patch +++ b/scripts/package-build/linux-kernel/patches/kernel/0001-linkstate-ip-device-attribute.patch @@ -104,11 +104,11 @@ diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c index 231fa4dc6cde..8d8a8ee9c4fe 100644 --- a/net/ipv6/addrconf.c +++ b/net/ipv6/addrconf.c -@@ -5677,6 +5677,7 @@ static inline void ipv6_store_devconf(struct ipv6_devconf *cnf, - array[DEVCONF_NDISC_EVICT_NOCARRIER] = cnf->ndisc_evict_nocarrier; - array[DEVCONF_ACCEPT_UNTRACKED_NA] = cnf->accept_untracked_na; - array[DEVCONF_ACCEPT_RA_MIN_LFT] = cnf->accept_ra_min_lft; -+ array[DEVCONF_LINK_FILTER] = cnf->link_filter; +@@ -5674,6 +5674,7 @@ static inline void ipv6_store_devconf(struct ipv6_devconf *cnf, + array[DEVCONF_ACCEPT_UNTRACKED_NA] = + READ_ONCE(cnf->accept_untracked_na); + array[DEVCONF_ACCEPT_RA_MIN_LFT] = READ_ONCE(cnf->accept_ra_min_lft); ++ array[DEVCONF_LINK_FILTER] = READ_ONCE(cnf->link_filter); } static inline size_t inet6_ifla6_size(void) diff --git a/scripts/package-build/linux-kernel/patches/kernel/0002-inotify-support-for-stackable-filesystems.patch b/scripts/package-build/linux-kernel/patches/kernel/0002-inotify-support-for-stackable-filesystems.patch index 115f6831f5..01ac50d6bb 100644 --- a/scripts/package-build/linux-kernel/patches/kernel/0002-inotify-support-for-stackable-filesystems.patch +++ b/scripts/package-build/linux-kernel/patches/kernel/0002-inotify-support-for-stackable-filesystems.patch @@ -221,31 +221,25 @@ index 93ee57bc82ad..5f4f886d011e 100644 static int __init ovl_init(void) { int err; -@@ -1548,18 +1561,24 @@ static int __init ovl_init(void) - err = ovl_aio_request_cache_init(); - if (!err) { - err = register_filesystem(&ovl_fs_type); -- if (!err) -- return 0; -+ if (err) -+ goto err; -+ err = inotify_register_stackfs(&ovl_inotify); -+ if (err) -+ goto err; -+ return 0; +@@ -1548,9 +1561,14 @@ static int __init ovl_init(void) + return -ENOMEM; + + err = register_filesystem(&ovl_fs_type); +- if (!err) +- return 0; ++ if (err) ++ goto err; ++ err = inotify_register_stackfs(&ovl_inotify); ++ if (err) ++ goto err; ++ return 0; -- ovl_aio_request_cache_destroy(); - } +err: kmem_cache_destroy(ovl_inode_cachep); - + unregister_filesystem(&ovl_fs_type); -+ ovl_aio_request_cache_destroy(); - return err; - } - - static void __exit ovl_exit(void) - { + return err; +@@ -1554,3 +1554,4 @@ static void __exit ovl_exit(void) + inotify_unregister_stackfs(&ovl_inotify); unregister_filesystem(&ovl_fs_type); diff --git a/scripts/package-build/linux-kernel/patches/kernel/build-linux-perf-package.patch b/scripts/package-build/linux-kernel/patches/kernel/build-linux-perf-package.patch index 082ad58937..49e83c9db1 100644 --- a/scripts/package-build/linux-kernel/patches/kernel/build-linux-perf-package.patch +++ b/scripts/package-build/linux-kernel/patches/kernel/build-linux-perf-package.patch @@ -2,8 +2,8 @@ diff --git c/scripts/package/builddeb i/scripts/package/builddeb index d7dd0d04c70c..6f4a9a7c2c62 100755 --- c/scripts/package/builddeb +++ i/scripts/package/builddeb -@@ -182,6 +182,16 @@ install_libc_headers () { - mv $pdir/usr/include/asm $pdir/usr/include/$host_arch/ +@@ -182,4 +182,14 @@ install_libc_headers () { + mv "$pdir/usr/include/asm" "$pdir/usr/include/${DEB_HOST_MULTIARCH}" } +install_perf () { @@ -16,27 +16,14 @@ index d7dd0d04c70c..6f4a9a7c2c62 100755 + +} + - rm -f debian/files - - packages_enabled=$(dh_listpackages) -@@ -199,6 +209,8 @@ do - install_libc_headers debian/linux-libc-dev;; - linux-headers-*) - install_kernel_headers debian/linux-headers ${package#linux-headers-};; + package=$1 +@@ -167,4 +167,6 @@ case + install_libc_headers "${package}";; + linux-headers-*) + install_kernel_headers "${package}";; + linux-perf-*) + install_perf debian/linux-perf ${package};; - esac - done - -@@ -213,6 +225,8 @@ do - create_package ${package} debian/linux-libc-dev;; - linux-headers-*) - create_package ${package} debian/linux-headers;; -+ linux-perf-*) -+ create_package ${package} debian/linux-perf;; - esac - done - + esac diff --git c/scripts/package/mkdebian i/scripts/package/mkdebian index 5044224cf671..21f98ae50be0 100755 --- c/scripts/package/mkdebian @@ -47,13 +34,13 @@ index 5044224cf671..21f98ae50be0 100755 +cat <> debian/control + -+Package: linux-perf-$version ++Package: linux-perf-${KERNELRELEASE} +Section: devel +Architecture: $debarch +Depends: \${shlibs:Depends} -+Description: Performance analysis tools for Linux $version ++Description: Performance analysis tools for Linux ${KERNELRELEASE} + This package contains the 'perf' performance analysis tools for Linux -+ kernel version $version . ++ kernel version ${KERNELRELEASE} . +Multi-Arch: same +EOF + diff --git a/scripts/package-build/net-snmp/.gitignore b/scripts/package-build/net-snmp/.gitignore deleted file mode 100644 index ce30b515df..0000000000 --- a/scripts/package-build/net-snmp/.gitignore +++ /dev/null @@ -1 +0,0 @@ -/net-snmp/ diff --git a/scripts/package-build/net-snmp/package.toml b/scripts/package-build/net-snmp/package.toml deleted file mode 100644 index 414f5e2435..0000000000 --- a/scripts/package-build/net-snmp/package.toml +++ /dev/null @@ -1,5 +0,0 @@ -[[packages]] -name = "net-snmp" -commit_id = "debian/5.9.4+dfsg-1" -scm_url = "https://salsa.debian.org/debian/net-snmp" -build_cmd = "dpkg-buildpackage -us -uc -tc -b || true" diff --git a/scripts/package-build/net-snmp/patches/net-snmp/add-linux-6.7-compatibility-parsing.patch b/scripts/package-build/net-snmp/patches/net-snmp/add-linux-6.7-compatibility-parsing.patch deleted file mode 100644 index b6dcd77ae8..0000000000 --- a/scripts/package-build/net-snmp/patches/net-snmp/add-linux-6.7-compatibility-parsing.patch +++ /dev/null @@ -1,119 +0,0 @@ -From f5ae6baf0018abda9dedc368fe6d52c0d7a8ab8f Mon Sep 17 00:00:00 2001 -From: Philippe Troin -Date: Sat, 3 Feb 2024 10:30:30 -0800 -Subject: [PATCH] Add Linux 6.7 compatibility parsing /proc/net/snmp - -Linux 6.7 adds a new OutTransmits field to Ip in /proc/net/snmp. -This breaks the hard-coded assumptions about the Ip line length. -Add compatibility to parse Linux 6.7 Ip header while keep support -for previous versions. ---- - .../ip-mib/data_access/systemstats_linux.c | 46 +++++++++++++++---- - 1 file changed, 37 insertions(+), 9 deletions(-) - -diff --git a/agent/mibgroup/ip-mib/data_access/systemstats_linux.c b/agent/mibgroup/ip-mib/data_access/systemstats_linux.c -index 49e0a34d5c..f04e828a94 100644 ---- a/agent/mibgroup/ip-mib/data_access/systemstats_linux.c -+++ b/agent/mibgroup/ip-mib/data_access/systemstats_linux.c -@@ -36,7 +36,7 @@ netsnmp_access_systemstats_arch_init(void) - } - - /* -- /proc/net/snmp -+ /proc/net/snmp - Linux 6.6 and lower - - Ip: Forwarding DefaultTTL InReceives InHdrErrors InAddrErrors ForwDatagrams InUnknownProtos InDiscards InDelivers OutRequests OutDiscards OutNoRoutes ReasmTimeout ReasmReqds ReasmOKs ReasmFails FragOKs FragFails FragCreates - Ip: 2 64 7083534 0 0 0 0 0 6860233 6548963 0 0 1 286623 63322 1 259920 0 0 -@@ -49,6 +49,26 @@ netsnmp_access_systemstats_arch_init(void) - - Udp: InDatagrams NoPorts InErrors OutDatagrams - Udp: 1491094 122 0 1466178 -+* -+ /proc/net/snmp - Linux 6.7 and higher -+ -+ Ip: Forwarding DefaultTTL InReceives InHdrErrors InAddrErrors ForwDatagrams InUnknownProtos InDiscards InDelivers OutRequests OutDiscards OutNoRoutes ReasmTimeout ReasmReqds ReasmOKs ReasmFails FragOKs FragFails FragCreates OutTransmits -+ Ip: 1 64 50859058 496 0 37470604 0 0 20472980 7515791 1756 0 0 7264 3632 0 3548 0 7096 44961424 -+ -+ Icmp: InMsgs InErrors InCsumErrors InDestUnreachs InTimeExcds InParmProbs InSrcQuenchs InRedirects InEchos InEchoReps InTimestamps InTimestampReps InAddrMasks InAddrMaskReps OutMsgs OutErrors OutRateLimitGlobal OutRateLimitHost OutDestUnreachs OutTimeExcds OutParmProbs OutSrcQuenchs OutRedirects OutEchos OutEchoReps OutTimestamps OutTimestampReps OutAddrMasks OutAddrMaskReps -+ Icmp: 114447 2655 0 17589 0 0 0 0 66905 29953 0 0 0 0 143956 0 0 572 16610 484 0 0 0 59957 66905 0 0 0 0 -+ -+ IcmpMsg: InType0 InType3 InType8 OutType0 OutType3 OutType8 OutType11 -+ IcmpMsg: 29953 17589 66905 66905 16610 59957 484 -+ -+ Tcp: RtoAlgorithm RtoMin RtoMax MaxConn ActiveOpens PassiveOpens AttemptFails EstabResets CurrEstab InSegs OutSegs RetransSegs InErrs OutRsts InCsumErrors -+ Tcp: 1 200 120000 -1 17744 13525 307 3783 6 18093137 9277788 3499 8 7442 0 -+ -+ Udp: InDatagrams NoPorts InErrors OutDatagrams RcvbufErrors SndbufErrors InCsumErrors IgnoredMulti MemErrors -+ Udp: 2257832 1422 0 2252835 0 0 0 84 0 -+ -+ UdpLite: InDatagrams NoPorts InErrors OutDatagrams RcvbufErrors SndbufErrors InCsumErrors IgnoredMulti MemErrors -+ UdpLite: 0 0 0 0 0 0 0 0 0 - */ - - -@@ -101,10 +121,10 @@ _systemstats_v4(netsnmp_container* container, u_int load_flags) - FILE *devin; - char line[1024]; - netsnmp_systemstats_entry *entry = NULL; -- int scan_count; -+ int scan_count, expected_scan_count; - char *stats, *start = line; - int len; -- unsigned long long scan_vals[19]; -+ unsigned long long scan_vals[20]; - - DEBUGMSGTL(("access:systemstats:container:arch", "load v4 (flags %x)\n", - load_flags)); -@@ -126,10 +146,17 @@ _systemstats_v4(netsnmp_container* container, u_int load_flags) - */ - NETSNMP_IGNORE_RESULT(fgets(line, sizeof(line), devin)); - len = strlen(line); -- if (224 != len) { -+ switch (len) { -+ case 224: -+ expected_scan_count = 19; -+ break; -+ case 237: -+ expected_scan_count = 20; -+ break; -+ default: - fclose(devin); - snmp_log(LOG_ERR, "systemstats_linux: unexpected header length in /proc/net/snmp." -- " %d != 224\n", len); -+ " %d not in { 224, 237 } \n", len); - return -4; - } - -@@ -178,20 +205,20 @@ _systemstats_v4(netsnmp_container* container, u_int load_flags) - memset(scan_vals, 0x0, sizeof(scan_vals)); - scan_count = sscanf(stats, - "%llu %llu %llu %llu %llu %llu %llu %llu %llu %llu" -- "%llu %llu %llu %llu %llu %llu %llu %llu %llu", -+ "%llu %llu %llu %llu %llu %llu %llu %llu %llu %llu", - &scan_vals[0],&scan_vals[1],&scan_vals[2], - &scan_vals[3],&scan_vals[4],&scan_vals[5], - &scan_vals[6],&scan_vals[7],&scan_vals[8], - &scan_vals[9],&scan_vals[10],&scan_vals[11], - &scan_vals[12],&scan_vals[13],&scan_vals[14], - &scan_vals[15],&scan_vals[16],&scan_vals[17], -- &scan_vals[18]); -+ &scan_vals[18],&scan_vals[19]); - DEBUGMSGTL(("access:systemstats", " read %d values\n", scan_count)); - -- if(scan_count != 19) { -+ if(scan_count != expected_scan_count) { - snmp_log(LOG_ERR, - "error scanning systemstats data (expected %d, got %d)\n", -- 19, scan_count); -+ expected_scan_count, scan_count); - netsnmp_access_systemstats_entry_free(entry); - return -4; - } -@@ -223,6 +250,7 @@ _systemstats_v4(netsnmp_container* container, u_int load_flags) - entry->stats.HCOutFragFails.high = scan_vals[17] >> 32; - entry->stats.HCOutFragCreates.low = scan_vals[18] & 0xffffffff; - entry->stats.HCOutFragCreates.high = scan_vals[18] >> 32; -+ /* entry->stats. = scan_vals[19]; / * OutTransmits */ - - entry->stats.columnAvail[IPSYSTEMSTATSTABLE_HCINRECEIVES] = 1; - entry->stats.columnAvail[IPSYSTEMSTATSTABLE_INHDRERRORS] = 1; diff --git a/scripts/package-build/podman/package.toml b/scripts/package-build/podman/package.toml index 707f3d7ecd..3ba3345af1 100644 --- a/scripts/package-build/podman/package.toml +++ b/scripts/package-build/podman/package.toml @@ -1,12 +1,12 @@ [[packages]] name = "podman" -commit_id = "v4.9.5" +commit_id = "v5.5.2" scm_url = "https://github.com/containers/podman" #build_cmd = "cd ..; ./build.sh" build_cmd = """ make install.tools -make podman-release +BINDIR=/usr/bin make podman-release tar xf podman-release-$(dpkg --print-architecture).tar.gz VERSION=$(ls -d podman-v* | cut -c9-) diff --git a/scripts/package-build/unionfs-fuse/.gitignore b/scripts/package-build/unionfs-fuse/.gitignore new file mode 100644 index 0000000000..12982e780c --- /dev/null +++ b/scripts/package-build/unionfs-fuse/.gitignore @@ -0,0 +1 @@ +unionfs-fuse/ \ No newline at end of file diff --git a/scripts/package-build/net-snmp/build.py b/scripts/package-build/unionfs-fuse/build.py similarity index 100% rename from scripts/package-build/net-snmp/build.py rename to scripts/package-build/unionfs-fuse/build.py diff --git a/scripts/package-build/unionfs-fuse/package.toml b/scripts/package-build/unionfs-fuse/package.toml new file mode 100644 index 0000000000..5e9d728f6b --- /dev/null +++ b/scripts/package-build/unionfs-fuse/package.toml @@ -0,0 +1,31 @@ +[[packages]] +name = "unionfs-fuse" +commit_id = "v3.6" +scm_url = "https://github.com/rpodgorny/unionfs-fuse" + +build_cmd = """ +mkdir build +cd build + +cmake .. -DWITH_LIBFUSE3=TRUE \ + -DCMAKE_SKIP_RPATH=TRUE \ + -DCMAKE_INSTALL_PREFIX=/usr +make +make DESTDIR=. install + +VERSION=$(git describe --tags --exact-match 2>/dev/null || git rev-parse --short HEAD) + +fpm --input-type dir --output-type deb --name unionfs-fuse \ + --version $VERSION --deb-compression gz \ + --maintainer "VyOS Package Maintainers " \ + --description "Fuse implementation of unionfs" \ + --depends libfuse3-dev \ + --license "BSD" --package ../.. usr + +""" + +[dependencies] +packages = [ + "cmake", + "libfuse3-dev" +]