Skip to content

Infix v26.09.0

Latest

Choose a tag to compare

@github-actions github-actions released this 01 Oct 19:58
v26.09.0
f7dc450

Important

This release includes breaking changes. Several configuration
strings are now limited to a safe character set, and a startup-config
with a value outside these limits fails validation on boot, leaving the
system in failure-config. Read Limitations before upgrading.

Changes

  • Upgrade Linux kernel to 6.18.54 (LTS)

  • Upgrade Buildroot to 2025.02.18 (LTS)

  • Upgrade FRR to 10.5.5

  • Support bundle changes: - The shell command support collect now redacts private keys, password hashes and other secrets from configuration files in the archive by default, use --no-redact to keep them. - The environment dump is no longer collected - A new /infix-system:support-collect RPC, for collecting support data over NETCONF or RESTCONF. The archive is returned base64 encoded, up to 16 MiB, larger ones are left on the device for out-of-band fetching. Access is limited to users in the NACM admin group - WebUI: the support bundle is collected with the new RPC, as the logged-in user

  • Add support for unattended software updates, letting a unit track an RSS/Atom release feed on a schedule and install a newer release to the inactive partition on its own, then either reboot to activate it or leave it staged for the next reboot, see Unattended Software Updates

  • The factory configuration now provides two schedules, nightly and weekly, ready to be referenced by any scheduled feature

  • Features that run on a schedule are now active as soon as they reference one, see Scheduling for details

  • Add Novarq Tactical-1000 support: LAN9696 (Laguna) switch with 24 GbE copper ports, four SFP+ cages, and a management port, booting Infix from eMMC with the usual A/B slots, see the board README for details

  • CLI changes: - The configure command takes an optional path to start in a sub-context directly, e.g., configure system authentication - Partial commands can now be entered as long as they are unambiguous, e.g., sh int for show interface - CIDR notation for IP addresses, e.g. set ipv4 address 192.168.1.1/24. An address without prefix length gets a classful default: /8, /16, or /24 - The dir command lists directories as the logged-in user, so it shows only what that user may read - The edit command now also edits settings interactively: passwords and keys are prompted for, binary settings open in the text editor, and string settings are edited on a line prefilled with the current value - The text-editor and change commands are removed, see edit above - Add edit and clear verbs to admin-exec: edit datetime and edit boot-order prompt with the current value, clear dhcp-server statistics replaces dhcp-server clear-statistics. set datetime now also accepts free-form input, e.g., 14:05, and echoes the ISO-8601 value it sets, see https://xkcd.com/1179/ for details - Add log command to admin-exec, for logging a message to the system log, e.g., log severity warning Kilroy was here - The remove command now offers the startup-config as a possible alternative, and warns about the consequences (factory reset) - Add rename command, for renaming or moving a file without copying it, e.g. rename startup-config backup - File system completion with Tab, for copy, rename, remove, and dir, limited to the directories those commands accept - The copy and remove commands now also accept files in /var/lib, /var/tmp, and /tmp. Files written there are world-readable, and the .cfg extension is only added for files in /cfg

  • Add an /infix-syslog:log RPC, for injecting messages in the system log over NETCONF/RESTCONF, issue #1639. The operation is restricted to users in the admin group by default

  • Add /system/advanced for low-level system customization, available in the WebUI from the Configure > Advanced page, issue #463:

    • rc.d: user scripts stored in the configuration, run once at boot after the startup configuration has been applied, in the order listed - default: daemon environment files written to /etc/default, e.g., extra ptp4l command line options

    Note: these settings are restricted to admin group users by default

  • /bin/sh is now provided by Busybox ash instead of Bash, speeding up boot and configuration changes, issue #961. Same rationale as Debian's dash-as-/bin/sh. Bash remains available for interactive use and for scripts using #!/bin/bash

  • Add per-server minpoll and maxpoll options to the NTP client

  • Add an SNMP v1/v2c agent for read-only monitoring from existing management systems. Disabled by default, see SNMP for details

  • Add support for network boot and device provisioning, issue #1542: - Add TFTP server, read-only, serving /var/lib/tftpboot or a directory on USB media, with optional per-client subdirectories, see TFTP - Add network boot parameters to the DHCP server: boot file, server-address, and server-name at global, subnet, or host scope, sent in the BOOTP header fields and as options 66/67

  • Document the release and maintenance policy: which versions receive updates, what may go into a patch release, and the levels of long-term maintenance available, see Releases & Support

  • WebUI changes: - Add 802.11s WiFi mesh point support and access point roaming (802.11k/r/v, band steering, OKC), both configuration (incl. wizard) and status - Key Vitals on the Overview page are named by the component they measure

  • Interface operational status additions, issue #514: - higher-layer-if and lower-layer-if, the interfaces stacked directly on top of or beneath each one, e.g., a VLAN interface and its parent - last-change, the time the interface entered its current state

  • Optional boot.itb image, a FIT with kernel, rootfs, and device trees that a vendor U-Boot can start during board bring-up, see Netboot HowTo for details

  • Add make migrate-configs to bring static configurations, e.g., the per-product factory-config.cfg in Infix and in spins, up to date with the current confd version

  • NETCONF management is now served by the OpenSSH daemon, meaning the standard ietf-netconf-server.yang model is no longer used. NETCONF is enabled with ssh netconf enabled, existing configurations are migrated. NETCONF call-home, NETCONF over TLS, and the on-device netopeer2-cli tool require the built-in SSH server of netopeer2 and are therefore no longer available in default builds

Fixes

  • Restrict several configuration strings to a safe character set, issues #1655 and #1657, see Limitations for the affected settings
  • Fix #1637: a startup-config migrated on upgrade was saved to disk at boot, so the image on the other partition could no longer read it. The migrated configuration now stays in running-config until saved, see Configuration Migration
  • A startup-config that fails to load, or hangs, now resets the unit and the next boot goes straight to failure-config, see Broken startup-config
  • Fix Wi-Fi access point failing to start on radios without 802.11ax or 802.11ac, e.g. the BPi-R64, the hostapd modes now follow what the radio supports
  • First boot after a factory reset: - Fix status LED still blinking after the first boot - Fix resize looping forever on a disk with a var partition but no aux filesystem, the system now boots without /var instead
  • Give /var 120 MiB in the 512 MiB QEMU image, room for a support archive
  • Apply syslog configuration changes at runtime, not only after reboot
  • Fix removing an enumeration or boolean leaf in a RESTCONF YANG Patch
  • Fix OSPF sometimes learning no routes over a link that flapped while a routing change was being applied
  • Wi-Fi fixes: - Fix #1619: Raspberry Pi kernel panic when configuring Wi-Fi - Mesh point interfaces showed an empty mesh-id in operational status - Radio hardware components showed up as radio0-1 in operational status, the temperature sensor is now a child of the radio, radio0-temp
  • WebUI fixes: - Saving a Wi-Fi or WireGuard interface did nothing, a hidden "+ New" form blocked the submit - The mode of a Wi-Fi interface, station, access point, or mesh point, can now be changed after it has been created - Reject malformed RESTCONF paths, link only http and https URLs from mDNS records, and send Cache-Control: no-store

Tip

Try Infix in GNS3! See the blog post for details https://www.kernelkit.org/posts/infix-in-gns3/