diff options
Diffstat (limited to 'scripts')
13 files changed, 173 insertions, 42 deletions
diff --git a/scripts/check-qemu-install b/scripts/check-qemu-install index 0929ea02..62896266 100755 --- a/scripts/check-qemu-install +++ b/scripts/check-qemu-install @@ -599,11 +599,19 @@ def BOOTLOADERchooseSerialConsole(child, live: bool) -> None: time.sleep(BOOTLOADER_SLEEP) child.send(KEY_RETURN) time.sleep(BOOTLOADER_SLEEP) + # GRUB submenus never time out on their own, so confirm we actually + # landed on this submenu before navigating further - otherwise a + # dropped keypress leaves the VM stuck here until the login wait + # elsewhere expires + child.expect('Select console type', timeout=BOOTLOADER_TMO) + # Select console type child.send(KEY_DOWN) time.sleep(BOOTLOADER_SLEEP) child.send(KEY_RETURN) time.sleep(BOOTLOADER_SLEEP) + child.expect(r'ttyS \(serial\)', timeout=BOOTLOADER_TMO) + # *ttyS (serial) child.send(KEY_DOWN) time.sleep(BOOTLOADER_SLEEP) @@ -723,6 +731,7 @@ def _image_update_cli_sequence(c, log, new_image_name, server_bind_host='127.0.0 'Would you like to set the new image as the default one for boot', 'An active configuration was found. Would you like to copy it to the new image', 'Would you like to copy SSH host keys', + 'Would you like to copy Bash history', 'Would you like to save the SSH known hosts (fingerprints)', 'Signature is not available. Do you want to continue with installation', 'There are unsaved changes to the configuration', @@ -747,9 +756,11 @@ def _image_update_cli_sequence(c, log, new_image_name, server_bind_host='127.0.0 c.sendline('y') elif i == 7: c.sendline('y') - elif i == 8 or i == 9: + elif i == 8: + c.sendline('y') + elif i == 9 or i == 10: raise Exception('add system image reported an error') - elif i == 10: + elif i == 11: log.info('add system image completed') break @@ -1356,18 +1367,17 @@ try: log.info('Smoketests will be run using vyconfd/vyos-commitd') log.info('Executing VyOS smoketests') + c.sendline('ls /usr/bin/vyos-smoketest 2>/dev/null') + c.expect('/usr/bin/vyos-smoketest') + c.expect(op_mode_prompt) c.sendline('/usr/bin/vyos-smoketest') i = c.expect(['\n +Invalid command:', '\n +Set failed', - 'No such file or directory', r'\n\S+@\S+[$#]'], timeout=test_timeout) + r'\n\S+@\S+[$#]'], timeout=test_timeout) if i == 0: raise Exception('Invalid command detected') if i == 1: raise Exception('Set syntax failed :/') - if i == 2: - tmp = '(W)hy (T)he (F)ace? VyOS smoketest not found!' - log.error(tmp) - raise Exception(tmp) c.sendline('echo EXITCODE:$\x16?') i = c.expect(['EXITCODE:0', 'EXITCODE:\d+']) diff --git a/scripts/image-build/build-vyos-image b/scripts/image-build/build-vyos-image index b181a6e4..a1458d99 100755 --- a/scripts/image-build/build-vyos-image +++ b/scripts/image-build/build-vyos-image @@ -31,6 +31,7 @@ import datetime import functools import string import subprocess +import tempfile class ImageBuildError(Exception): pass @@ -156,6 +157,7 @@ def build(): 'qemu-utils', 'gdisk', 'kpartx', + 'squashfs-tools', 'dosfstools' ], 'binaries': [] @@ -727,26 +729,37 @@ Pin-Priority: 600 manifest['artifacts'].append(iso_file) # Now create SBOM - syft_target_dir = 'chroot' - syft_base_path = os.getcwd() + f'/{syft_target_dir}' base_filename = iso_file.rstrip('.iso') - syft_cmd = [['syft', syft_target_dir, - '--source-name', 'VyOS', '--source-version', version, - '-o', f'cyclonedx-json={base_filename}.cdx.json', - '-o', f'spdx-json={base_filename}.spdx.json']] - - # syft bug for CycloneDX https://github.com/anchore/syft/issues/4592#issuecomment-4567247328 - syft_cmd.append(['sed', '-i', '-e', f's@{syft_base_path}@@g', f'{base_filename}.cdx.json']) - syft_cmd.append(['sed', '-i', '-e', f's@{syft_base_path}@//@g', f'{base_filename}.spdx.json']) - - for c in syft_cmd: - with subprocess.Popen(c, stdout=subprocess.PIPE, stderr=subprocess.STDOUT, - text=True, bufsize=1) as p: - for line in p.stdout: - sys.stdout.write(line) - sys.stdout.flush() - p.wait() - print("I: Finished SBOM generation") + syft_target_dir = tempfile.mkdtemp(prefix='unsquashfs_rootfs-', dir=os.getcwd()) + syft_base_path = syft_target_dir + try: + # lb config builds the amd64 squashfs as xz with -Xbcj x86 (a BCJ pre-filter + # chained with LZMA2. Real unsquashfs/mksquashfs fully support multi-filter + # xz streams; syft's own Go-based squashfs/xz decoder apparently only handles + # plain single-filter. Extract squashfs first + print("I: Unpack squashfs for SBOM generation") + syft_cmd = [['unsquashfs', '-quiet', '-no-progress', '-force', '-dest', syft_target_dir, 'binary/live/filesystem.squashfs']] + # run syft on extracted content + syft_cmd.append(['syft', syft_target_dir, + '--source-name', 'VyOS', '--source-version', version, + '-o', f'cyclonedx-json={base_filename}.cdx.json', + '-o', f'spdx-json={base_filename}.spdx.json']) + + # syft bug for CycloneDX https://github.com/anchore/syft/issues/4592#issuecomment-4567247328 + syft_cmd.append(['sed', '-i', '-e', f's@{syft_base_path}@@g', f'{base_filename}.cdx.json']) + syft_cmd.append(['sed', '-i', '-e', f's@{syft_base_path}@//@g', f'{base_filename}.spdx.json']) + + for c in syft_cmd: + with subprocess.Popen(c, stdout=subprocess.PIPE, stderr=subprocess.STDOUT, + text=True, bufsize=1) as p: + for line in p.stdout: + sys.stdout.write(line) + sys.stdout.flush() + p.wait() + print("I: Finished SBOM generation") + finally: + # remove temporary unpacked squashfs, even on failure/interruption + shutil.rmtree(syft_target_dir, ignore_errors=True) # If the flavor has `image_format = "iso"`, then the work is done. diff --git a/scripts/package-build/iproute2/.gitignore b/scripts/package-build/iproute2/.gitignore new file mode 100644 index 00000000..393b9da9 --- /dev/null +++ b/scripts/package-build/iproute2/.gitignore @@ -0,0 +1 @@ +/iproute2/ diff --git a/scripts/package-build/iproute2/build.py b/scripts/package-build/iproute2/build.py new file mode 120000 index 00000000..3c76af73 --- /dev/null +++ b/scripts/package-build/iproute2/build.py @@ -0,0 +1 @@ +../build.py
\ No newline at end of file diff --git a/scripts/package-build/iproute2/package.toml b/scripts/package-build/iproute2/package.toml new file mode 100644 index 00000000..363cbd31 --- /dev/null +++ b/scripts/package-build/iproute2/package.toml @@ -0,0 +1,5 @@ +[[packages]] +name = "iproute2" +commit_id = "debian/6.18.0-1" +scm_url = "https://salsa.debian.org/kernel-team/iproute2.git" +pre_build_hook = "sudo apt-get install -y -t bookworm-backports debhelper" diff --git a/scripts/package-build/linux-kernel/config/90-debug.config b/scripts/package-build/linux-kernel/config/90-debug.config index 28ffe431..9eb5d016 100644 --- a/scripts/package-build/linux-kernel/config/90-debug.config +++ b/scripts/package-build/linux-kernel/config/90-debug.config @@ -180,3 +180,10 @@ CONFIG_IO_STRICT_DEVMEM=y # CONFIG_KCOV is not set # CONFIG_RUNTIME_TESTING_MENU is not set # CONFIG_MEMTEST is not set + +# +# Kdump tool support +# +CONFIG_CRASH_DUMP=y +CONFIG_DEBUG_INFO=y +CONFIG_PROC_VMCORE=y diff --git a/scripts/package-build/linux-kernel/config/x86/vyos_defconfig b/scripts/package-build/linux-kernel/config/x86/vyos_defconfig index 3ce5b449..87c8bc3b 100644 --- a/scripts/package-build/linux-kernel/config/x86/vyos_defconfig +++ b/scripts/package-build/linux-kernel/config/x86/vyos_defconfig @@ -1040,6 +1040,7 @@ CONFIG_PCI_IOV=y CONFIG_PCI_PRI=y CONFIG_PCI_PASID=y CONFIG_PCI_LABEL=y +CONFIG_PCI_HYPERV=m # CONFIG_PCIE_BUS_TUNE_OFF is not set CONFIG_PCIE_BUS_DEFAULT=y # CONFIG_PCIE_BUS_SAFE is not set @@ -1058,6 +1059,7 @@ CONFIG_HOTPLUG_PCI_SHPC=y # PCI controller drivers # CONFIG_VMD=m +CONFIG_PCI_HYPERV_INTERFACE=m # # DesignWare-based PCIe controllers @@ -1762,6 +1764,7 @@ CONFIG_NET_VENDOR_MICROCHIP=y # CONFIG_VCAP is not set CONFIG_NET_VENDOR_MICROSEMI=y CONFIG_NET_VENDOR_MICROSOFT=y +CONFIG_MICROSOFT_MANA=m CONFIG_NET_VENDOR_MYRI=y CONFIG_MYRI10GE=m CONFIG_MYRI10GE_DCA=y @@ -4099,7 +4102,7 @@ CONFIG_VHOST_VDPA=m # Microsoft Hyper-V guest support # CONFIG_HYPERV=y -CONFIG_HYPERV_VTL_MODE=y +# CONFIG_HYPERV_VTL_MODE is not set CONFIG_HYPERV_TIMER=y CONFIG_HYPERV_UTILS=m CONFIG_HYPERV_BALLOON=m diff --git a/scripts/package-build/linux-kernel/patches/kernel/0004-l2tp-defer-route-at-tunnel-create.patch b/scripts/package-build/linux-kernel/patches/kernel/0004-l2tp-defer-route-at-tunnel-create.patch index b19a57e8..1020869e 100644 --- a/scripts/package-build/linux-kernel/patches/kernel/0004-l2tp-defer-route-at-tunnel-create.patch +++ b/scripts/package-build/linux-kernel/patches/kernel/0004-l2tp-defer-route-at-tunnel-create.patch @@ -30,10 +30,15 @@ Assisted-by: Cursor:claude-4.8-opus Signed-off-by: Christian Breunig <christian@breunig.cc> --- -diff --git i/net/l2tp/l2tp_core.c w/net/l2tp/l2tp_core.c -index 9156a937334a..6fd9c1d89533 100644 ---- i/net/l2tp/l2tp_core.c -+++ w/net/l2tp/l2tp_core.c + net/l2tp/l2tp_core.c | 65 +++++++++++++++++++++++- + net/l2tp/l2tp_ip.c | 37 ++++++++++++++ + net/l2tp/l2tp_ip6.c | 117 +++++++++++++++++++++++++++++++++++++++++++ + 3 files changed, 218 insertions(+), 1 deletion(-) + +diff --git a/net/l2tp/l2tp_core.c b/net/l2tp/l2tp_core.c +index fd78928e9be2..0be01b28b7a8 100644 +--- a/net/l2tp/l2tp_core.c ++++ b/net/l2tp/l2tp_core.c @@ -55,6 +55,8 @@ #include <net/inet_ecn.h> #include <net/ip6_route.h> @@ -43,7 +48,7 @@ index 9156a937334a..6fd9c1d89533 100644 #include <asm/byteorder.h> #include <linux/atomic.h> -@@ -1453,6 +1455,67 @@ static void l2tp_tunnel_del_work(struct work_struct *work) +@@ -1454,6 +1456,67 @@ static void l2tp_tunnel_del_work(struct work_struct *work) * These sockets are freed when the namespace exits using the pernet * exit hook. */ @@ -111,7 +116,7 @@ index 9156a937334a..6fd9c1d89533 100644 static int l2tp_tunnel_sock_create(struct net *net, u32 tunnel_id, u32 peer_tunnel_id, -@@ -1490,7 +1553,7 @@ static int l2tp_tunnel_sock_create(struct net *net, +@@ -1491,7 +1554,7 @@ static int l2tp_tunnel_sock_create(struct net *net, udp_conf.local_udp_port = htons(cfg->local_udp_port); udp_conf.peer_udp_port = htons(cfg->peer_udp_port); @@ -120,10 +125,10 @@ index 9156a937334a..6fd9c1d89533 100644 if (err < 0) goto out; -diff --git i/net/l2tp/l2tp_ip.c w/net/l2tp/l2tp_ip.c -index 29795d2839e8..d63b00f09421 100644 ---- i/net/l2tp/l2tp_ip.c -+++ w/net/l2tp/l2tp_ip.c +diff --git a/net/l2tp/l2tp_ip.c b/net/l2tp/l2tp_ip.c +index 29795d2839e8..0d904a50b9a3 100644 +--- a/net/l2tp/l2tp_ip.c ++++ b/net/l2tp/l2tp_ip.c @@ -24,6 +24,7 @@ #include <net/xfrm.h> #include <net/net_namespace.h> @@ -182,10 +187,10 @@ index 29795d2839e8..d63b00f09421 100644 if (rc < 0) goto out_sk; -diff --git i/net/l2tp/l2tp_ip6.c w/net/l2tp/l2tp_ip6.c -index ea232f338dcb..610e666c0a58 100644 ---- i/net/l2tp/l2tp_ip6.c -+++ w/net/l2tp/l2tp_ip6.c +diff --git a/net/l2tp/l2tp_ip6.c b/net/l2tp/l2tp_ip6.c +index ea232f338dcb..e4e34db4c37f 100644 +--- a/net/l2tp/l2tp_ip6.c ++++ b/net/l2tp/l2tp_ip6.c @@ -28,6 +28,8 @@ #include <net/transp_v6.h> #include <net/addrconf.h> @@ -324,3 +329,6 @@ index ea232f338dcb..610e666c0a58 100644 if (rc < 0) goto out_sk; +-- +2.39.5 + diff --git a/scripts/package-build/linux-kernel/patches/kernel/0005-arm64-fix-relative-syscalltbl-path-in-Makefile.sysc.patch b/scripts/package-build/linux-kernel/patches/kernel/0005-arm64-fix-relative-syscalltbl-path-in-Makefile.sysc.patch new file mode 100644 index 00000000..8bccf3b2 --- /dev/null +++ b/scripts/package-build/linux-kernel/patches/kernel/0005-arm64-fix-relative-syscalltbl-path-in-Makefile.sysc.patch @@ -0,0 +1,57 @@ +From: Christian Breunig <christian@breunig.cc> +Date: Sat, 18 Jul 2026 18:30:00 +0000 +Subject: [PATCH] arm64: fix relative syscalltbl path in Makefile.syscalls + +Building the "linux-perf" Debian package (added by +0002-build-linux-perf-package.patch, via install_perf() invoking +"make -C tools/perf ... install") reproducibly fails on an arm64 build +host with: + + make[9]: *** No rule to make target + '.../tools/perf/libperf/arch/arm64/include/generated/uapi/asm/unistd_64.h'. + Stop. + +Root cause: tools/lib/perf/Makefile's "uapi-asm-generic:" recipe invokes +scripts/Makefile.asm-headers without "-C $(srctree)", so it inherits +whatever working directory tools/lib/perf/Makefile itself was invoked +with - which is tools/lib/perf/, not the kernel source root. This is +harmless for the generic default: + + syscalltbl := $(srctree)/scripts/syscall.tbl + +...which is absolute and thus resolves correctly regardless of the +working directory. arch/arm64/kernel/Makefile.syscalls, however, +overrides this with a relative path: + + syscalltbl = arch/arm64/tools/syscall_%.tbl + +When SRCARCH=arm64 (true both for the target kernel and, on a native +arm64 build host, for tools/perf's own build), this relative path is +looked up relative to tools/lib/perf/ instead of the kernel root, does +not exist there, and the "unistd_%.h" pattern rule that depends on it +can no longer be matched - so make reports no rule for the target at +all, rather than a missing-prerequisite error. + +This only surfaces on a native arm64 build host: on x86_64 hosts (the +common case for cross-building arm64 kernels) tools/perf builds for the +x86_64 host architecture, which has no such override and always uses +the safe, absolute default path. + +Fix by making arm64's override absolute too, matching the default and +every other reference in this file's callers. +--- + arch/arm64/kernel/Makefile.syscalls | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/arch/arm64/kernel/Makefile.syscalls b/arch/arm64/kernel/Makefile.syscalls +index 0542a718871a..958f2335ec1b 100644 +--- a/arch/arm64/kernel/Makefile.syscalls ++++ b/arch/arm64/kernel/Makefile.syscalls +@@ -3,4 +3,4 @@ + syscall_abis_32 += + syscall_abis_64 += renameat rlimit memfd_secret + +-syscalltbl = arch/arm64/tools/syscall_%.tbl ++syscalltbl = $(srctree)/arch/arm64/tools/syscall_%.tbl +-- +2.39.5 diff --git a/scripts/package-build/openssl/package.toml b/scripts/package-build/openssl/package.toml index 6dfd32e0..b38022ca 100644 --- a/scripts/package-build/openssl/package.toml +++ b/scripts/package-build/openssl/package.toml @@ -2,4 +2,5 @@ name = "openssl" commit_id = "debian/openssl-3.0.20-1_deb12u2" scm_url = "https://salsa.debian.org/debian/openssl.git" -build_cmd = "dpkg-buildpackage -us -uc -tc -b" +pre_build_hook = "git reset --hard HEAD && git clean -ffdx" +build_cmd = "sed -i '1s/)/+vyos1)/' debian/changelog && dpkg-buildpackage -us -uc -tc -b" diff --git a/scripts/package-build/squid/.gitignore b/scripts/package-build/squid/.gitignore new file mode 100644 index 00000000..0b00d9fb --- /dev/null +++ b/scripts/package-build/squid/.gitignore @@ -0,0 +1 @@ +/squid/ diff --git a/scripts/package-build/squid/build.py b/scripts/package-build/squid/build.py new file mode 120000 index 00000000..3c76af73 --- /dev/null +++ b/scripts/package-build/squid/build.py @@ -0,0 +1 @@ +../build.py
\ No newline at end of file diff --git a/scripts/package-build/squid/package.toml b/scripts/package-build/squid/package.toml new file mode 100644 index 00000000..fc693be0 --- /dev/null +++ b/scripts/package-build/squid/package.toml @@ -0,0 +1,23 @@ +[[packages]] +name = "squid" +commit_id = "debian/7.6-2" +scm_url = "https://salsa.debian.org/squid-team/squid" + +[dependencies] + packages = [ + "libltdl-dev", + "dh-apparmor", + "libcppunit-dev", + "libcap2-dev", + "libecap3-dev", + "libgnutls28-dev", + "libldap2-dev", + "libnetfilter-conntrack-dev", + "libpam0g-dev", + "libsasl2-dev", + "libsystemd-dev", + "libtdb-dev", + "nettle-dev", + "libssl-dev" + ] + |
