Important
This release includes breaking changes. Several configuration
strings are now limited to a safe character set, and a startup-config
with a value outside these limits fails validation on boot, leaving the
system in failure-config. Read Limitations before upgrading.
Changes
-
Upgrade Linux kernel to 6.18.54 (LTS)
-
Upgrade Buildroot to 2025.02.18 (LTS)
-
Upgrade FRR to 10.5.5
-
Support bundle changes: - The shell command
support collectnow redacts private keys, password hashes and other secrets from configuration files in the archive by default, use--no-redactto keep them. - The environment dump is no longer collected - A new/infix-system:support-collectRPC, for collecting support data over NETCONF or RESTCONF. The archive is returned base64 encoded, up to 16 MiB, larger ones are left on the device for out-of-band fetching. Access is limited to users in the NACMadmingroup - WebUI: the support bundle is collected with the new RPC, as the logged-in user -
Add support for unattended software updates, letting a unit track an RSS/Atom release feed on a schedule and install a newer release to the inactive partition on its own, then either reboot to activate it or leave it staged for the next reboot, see Unattended Software Updates
-
The factory configuration now provides two schedules,
nightlyandweekly, ready to be referenced by any scheduled feature -
Features that run on a schedule are now active as soon as they reference one, see Scheduling for details
-
Add Novarq Tactical-1000 support: LAN9696 (Laguna) switch with 24 GbE copper ports, four SFP+ cages, and a management port, booting Infix from eMMC with the usual A/B slots, see the board README for details
-
CLI changes: - The
configurecommand takes an optional path to start in a sub-context directly, e.g.,configure system authentication- Partial commands can now be entered as long as they are unambiguous, e.g.,sh intforshow interface- CIDR notation for IP addresses, e.g.set ipv4 address 192.168.1.1/24. An address without prefix length gets a classful default: /8, /16, or /24 - Thedircommand lists directories as the logged-in user, so it shows only what that user may read - Theeditcommand now also edits settings interactively: passwords and keys are prompted for,binarysettings open in the text editor, andstringsettings are edited on a line prefilled with the current value - Thetext-editorandchangecommands are removed, seeeditabove - Addeditandclearverbs to admin-exec:edit datetimeandedit boot-orderprompt with the current value,clear dhcp-server statisticsreplacesdhcp-server clear-statistics.set datetimenow also accepts free-form input, e.g.,14:05, and echoes the ISO-8601 value it sets, see https://xkcd.com/1179/ for details - Addlogcommand to admin-exec, for logging a message to the system log, e.g.,log severity warning Kilroy was here- Theremovecommand now offers the startup-config as a possible alternative, and warns about the consequences (factory reset) - Addrenamecommand, for renaming or moving a file without copying it, e.g.rename startup-config backup- File system completion with Tab, forcopy,rename,remove, anddir, limited to the directories those commands accept - Thecopyandremovecommands now also accept files in/var/lib,/var/tmp, and/tmp. Files written there are world-readable, and the.cfgextension is only added for files in/cfg -
Add an
/infix-syslog:logRPC, for injecting messages in the system log over NETCONF/RESTCONF, issue #1639. The operation is restricted to users in theadmingroup by default -
Add
/system/advancedfor low-level system customization, available in the WebUI from the Configure > Advanced page, issue #463:rc.d: user scripts stored in the configuration, run once at boot after the startup configuration has been applied, in the order listed -default: daemon environment files written to/etc/default, e.g., extraptp4lcommand line options
Note: these settings are restricted to
admingroup users by default -
/bin/shis now provided by Busybox ash instead of Bash, speeding up boot and configuration changes, issue #961. Same rationale as Debian's dash-as-/bin/sh. Bash remains available for interactive use and for scripts using#!/bin/bash -
Add per-server
minpollandmaxpolloptions to the NTP client -
Add an SNMP v1/v2c agent for read-only monitoring from existing management systems. Disabled by default, see SNMP for details
-
Add support for network boot and device provisioning, issue #1542: - Add TFTP server, read-only, serving
/var/lib/tftpbootor a directory on USB media, with optional per-client subdirectories, see TFTP - Add network boot parameters to the DHCP server:boot file,server-address, andserver-nameat global, subnet, or host scope, sent in the BOOTP header fields and as options 66/67 -
Document the release and maintenance policy: which versions receive updates, what may go into a patch release, and the levels of long-term maintenance available, see Releases & Support
-
WebUI changes: - Add 802.11s WiFi mesh point support and access point roaming (802.11k/r/v, band steering, OKC), both configuration (incl. wizard) and status - Key Vitals on the Overview page are named by the component they measure
-
Interface operational status additions, issue #514: -
higher-layer-ifandlower-layer-if, the interfaces stacked directly on top of or beneath each one, e.g., a VLAN interface and its parent -last-change, the time the interface entered its current state -
Optional
boot.itbimage, a FIT with kernel, rootfs, and device trees that a vendor U-Boot can start during board bring-up, see Netboot HowTo for details -
Add
make migrate-configsto bring static configurations, e.g., the per-productfactory-config.cfgin Infix and in spins, up to date with the current confd version -
NETCONF management is now served by the OpenSSH daemon, meaning the standard
ietf-netconf-server.yangmodel is no longer used. NETCONF is enabled withssh netconf enabled, existing configurations are migrated. NETCONF call-home, NETCONF over TLS, and the on-devicenetopeer2-clitool require the built-in SSH server of netopeer2 and are therefore no longer available in default builds
Fixes
- Restrict several configuration strings to a safe character set, issues #1655 and #1657, see Limitations for the affected settings
- Fix #1637: a startup-config migrated on upgrade was saved to disk at boot, so the image on the other partition could no longer read it. The migrated configuration now stays in running-config until saved, see Configuration Migration
- A startup-config that fails to load, or hangs, now resets the unit and the next boot goes straight to failure-config, see Broken startup-config
- Fix Wi-Fi access point failing to start on radios without 802.11ax or 802.11ac, e.g. the BPi-R64, the hostapd modes now follow what the radio supports
- First boot after a factory reset: - Fix status LED still blinking after the first boot - Fix resize looping forever on a disk with a
varpartition but noauxfilesystem, the system now boots without/varinstead - Give
/var120 MiB in the 512 MiB QEMU image, room for a support archive - Apply syslog configuration changes at runtime, not only after reboot
- Fix removing an
enumerationorbooleanleaf in a RESTCONF YANG Patch - Fix OSPF sometimes learning no routes over a link that flapped while a routing change was being applied
- Wi-Fi fixes: - Fix #1619: Raspberry Pi kernel panic when configuring Wi-Fi - Mesh point interfaces showed an empty
mesh-idin operational status - Radio hardware components showed up asradio0-1in operational status, the temperature sensor is now a child of the radio,radio0-temp - WebUI fixes: - Saving a Wi-Fi or WireGuard interface did nothing, a hidden "+ New" form blocked the submit - The mode of a Wi-Fi interface, station, access point, or mesh point, can now be changed after it has been created - Reject malformed RESTCONF paths, link only
httpandhttpsURLs from mDNS records, and sendCache-Control: no-store
Tip
Try Infix in GNS3! See the blog post for details https://www.kernelkit.org/posts/infix-in-gns3/