Support building Infix without Frr - #1681
Merged
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
A Bash-only command remains in minimal images, and the basic OSPF test can incorrectly skip on a non-routing endpoint.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Implements issue #1670 by supporting minimal Infix builds without FRR or Bash while retaining static routing.
Changes:
- Adds Linux-kernel static routing and operational route reporting.
- Feature-gates FRR services, YANG capabilities, and dynamic-routing tests.
- Adds POSIX shell fallbacks and updates minimal build configurations.
| File | Description |
|---|---|
test/infamy/route.py |
Adds routing-feature skip helper. |
test/case/use_case/ospf_container/test.py |
Skips OSPF container test when unsupported. |
test/case/statd/containers/system/rootfs/usr/bin/vtysh |
Adjusts statd FRR fixture marker. |
test/case/routing/route_pref_ospf/test.py |
Feature-gates OSPF preference test. |
test/case/routing/rip_redistribute/test.py |
Feature-gates RIP/OSPF redistribution test. |
test/case/routing/rip_passive_interface/test.py |
Feature-gates RIP test. |
test/case/routing/rip_multihop/test.py |
Feature-gates RIP test. |
test/case/routing/rip_basic/test.py |
Feature-gates RIP test. |
test/case/routing/ospf_unnumbered_interface/test.py |
Feature-gates OSPF test. |
test/case/routing/ospf_point_to_multipoint/test.py |
Feature-gates OSPF test. |
test/case/routing/ospf_point_to_multipoint_hybrid/test.py |
Feature-gates OSPF test. |
test/case/routing/ospf_multiarea/test.py |
Feature-gates OSPF test. |
test/case/routing/ospf_default_route_advertise/test.py |
Feature-gates OSPF test. |
test/case/routing/ospf_debug/test.py |
Feature-gates OSPF debug test. |
test/case/routing/ospf_bfd/test.py |
Feature-gates OSPF and BFD test. |
test/case/routing/ospf_basic/test.py |
Feature-gates basic OSPF test. |
src/statd/statd.c |
Conditionally compiles FRR status subscriptions. |
src/statd/python/yanger/ietf_routing.py |
Reports routes directly from the kernel. |
src/statd/configure.ac |
Adds FRR build option. |
src/netd/src/linux_backend.c |
Improves kernel static-route reconciliation. |
src/confd/yang/frr.inc |
Enables FRR-related YANG features. |
src/confd/yang/confd/infix-routing@2026-09-28.yang |
Adds revisioned feature-gated routing model. |
src/confd/yang/confd/infix-routing.yang |
Defines OSPF, RIP, and BFD features. |
src/confd/yang/confd.inc |
Selects the new routing revision. |
src/confd/src/system.c |
Handles missing FRR group and Bash fallback. |
src/confd/src/routing.c |
Separates FRR-specific routing handling. |
src/confd/configure.ac |
Adds FRR feature configuration. |
package/statd/statd.mk |
Passes statd’s FRR build option. |
package/skeleton-init-finit/skeleton/usr/lib/tmpfiles.d/frr.conf |
Defines FRR runtime directories. |
package/skeleton-init-finit/skeleton-init-finit.mk |
Removes FRR artifacts from minimal images. |
package/netd/netd.mk |
Installs backend-specific Finit dependencies. |
package/netd/netd.conf |
Simplifies the netd service definition. |
package/confd/confd.mk |
Configures FRR support and YANG features. |
doc/routing.md |
Documents static-only builds. |
doc/ChangeLog.md |
Records FRR-free minimal build support. |
configs/x86_64_minimal_defconfig |
Removes FRR and Bash. |
configs/arm_minimal_defconfig |
Removes FRR and Bash. |
configs/aarch64_minimal_defconfig |
Removes FRR and Bash. |
board/common/rootfs/usr/bin/clish |
Falls back to BusyBox shell. |
board/common/rootfs/usr/bin/askline |
Adds a POSIX-shell input fallback. |
board/common/rootfs/etc/finit.d/available/netd.conf |
Removes the obsolete overlay service file. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
saba8814
reviewed
Oct 3, 2026
saba8814
left a comment
Collaborator
There was a problem hiding this comment.
LGTM, only doc clarification.
The kernel backend left the control fields of the route dump message uninitialized, so whether the dump worked depended on what was on the stack. When it failed, with ENOBUFS, netd saw none of the routes it had installed and never removed or replaced any of them. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Without FRR the kernel backend is what installs static and DHCP routes, and it got three things wrong. A gateway route read back from the kernel also carries an interface, so it never matched the config and was deleted and re-added on every reload. A changed route preference was not seen as a change. And a route with preference 255, which FRR keeps out of the FIB, was installed. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The service waited for staticd, which a build without FRR does not have, so netd never started and no static routes were set. The package now installs the service itself and adds the staticd condition only with an FRR backend. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The skeleton is copied wholesale, so a build without FRR shipped FRR's config files, daemon defaults, and a tmpfiles rule for an frr user that does not exist. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Without bash, users with the bash login shell, admin included, got /bin/false, and clish runs the CLI through bash. Let BusyBox answer to bash there instead. A build with bash keeps the real one, BusyBox installs after it and does not overwrite it. askline needs bash's line editing to edit the value in place, with ash it offers the current value as the default instead. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The helper and its service template went into every image from the board's rootfs overlay. Without Podman nothing calls them, and on a build where bash is BusyBox ash the helper would start and then break on its bash features. confd already enables container support only with Podman, so it installs them alongside. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A build without FRR would still accept OSPF, RIP and BFD configuration with nothing to run it. The three protocols are now YANG features, enabled only when FRR is built, so the device accepts and advertises only what it can do. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The routing table came from vtysh only, so a build without FRR showed no routes at all. Without vtysh the kernel table is read instead: every route there is installed, the lowest metric per prefix is the active one, and netd sets the route preference as metric. The OSPF, RIP and BFD status providers are left out. The container replay test gets an empty vtysh so it keeps replaying the FRR path. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A build without FRR has static routing only. The OSPF, RIP and BFD tests check the routing features the device advertises and skip rather than fail. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
For small switch-only deployments FRR is dead weight, and it drags in bash and its dependencies. The minimal builds drop both. BUSYBOX_SHOW_OTHERS was selected only through bash, and without it sysklogd, less, whois and kmod-tools silently disappear, so it is now set explicitly. Fixes #1670 Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Contributor
Author
Thank you, and the regression tests all pass now. @saba8814 could you mark the PR as approved, please? 🙏 |
saba8814
approved these changes
Oct 3, 2026
requests has no default timeout, so a request or reply lost on the way to a DUT left the test waiting until CI cancelled the job six hours later. The reachability probe in attach() is polled in a retry loop, but a probe that never returns is never retried. nginx replies 504 when rousette takes more than 60 s, so the 90 s read timeout only fires when traffic is lost. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The subscription from sr_nacm_init() was never unsubscribed, so its listener thread outlived the session and connection it refers to. A NACM change arriving during teardown, e.g., from a full config replace, could leave copy waiting forever on freed memory. statd runs copy on every ietf-system operational read, so one stuck copy stalled every operational read served by statd. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
statd waits for yanger inside its sysrepo callbacks, and yanger waited for its commands with no timeout. One stuck helper, e.g., a copy deadlocked in sysrepo, stalled every operational read served by statd. A command that times out is killed and treated as failed: the caller's default is returned, or the error is logged and raised. The limit is generous so a slow command on a loaded single-core target is not cut off, yet below the 60 s rousette waits for operational data. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Description
*_minimal_defconfigstatdnetdFirst build will be minimal, second will be with
ci:mainlabel to verify full builds.Checklist
Tick relevant boxes, this PR is-a or has-a: