Skip to content

Yangerd - #1536

Draft
mattiaswal wants to merge 23 commits into
mainfrom
yangerd
Draft

Yangerd#1536
mattiaswal wants to merge 23 commits into
mainfrom
yangerd

Conversation

@mattiaswal

Copy link
Copy Markdown
Contributor

Description

Checklist

Tick relevant boxes, this PR is-a or has-a:

  • Bugfix
    • Regression tests
    • ChangeLog updates (for next release)
  • Feature
    • YANG model change => revision updated?
    • Regression tests added?
    • ChangeLog updates (for next release)
    • Documentation added?
  • Test changes
    • Checked in changed Readme.adoc (make test-spec)
    • Added new test to group Readme.adoc and yaml file
  • Code style update (formatting, renaming)
  • Refactoring (please detail in commit messages)
  • Build related changes
  • Documentation content changes
    • ChangeLog updated (for major changes)
  • Other (please describe):

@mattiaswal mattiaswal added the ci:main Build default defconfig, not minimal label Jun 12, 2026
@mattiaswal
mattiaswal force-pushed the yangerd branch 3 times, most recently from 3ec2747 to 71d50ea Compare June 19, 2026 09:38
@mattiaswal
mattiaswal force-pushed the yangerd branch 3 times, most recently from 7537929 to 8e6b2a1 Compare August 17, 2026 11:52
@mattiaswal
mattiaswal force-pushed the yangerd branch 4 times, most recently from 01b4d8f to ba1a1b3 Compare October 5, 2026 11:22
@mattiaswal
mattiaswal force-pushed the yangerd branch 2 times, most recently from 4a681f0 to 1af1d8e Compare October 7, 2026 12:47
A Go daemon replacing the Python yanger scripts that statd forked on
every GET.  It keeps operational state in memory, driven by netlink,
nl80211, D-Bus, ZAPI, inotify and the FRR vty sockets, polls only what
has no events, and serves it to statd over a Unix socket as JSON.
Covers interfaces, routing, system, hardware, NTP, LLDP, containers,
firewall, DHCP, TFTP, PTP and WiFi.  The RIB comes from zebra when
built with FRR and from the kernel table otherwise.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
Buildroot builds with -mod=vendor and no network access.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
Finit service with readiness notification.  Build-time feature flags
in /etc/default/yangerd mirror the packages selected, so yangerd only
runs the monitors that have something to monitor.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
Replaces forking the Python yanger scripts with a query over yangerd's
Unix socket.  Nested subscriptions graft only the requested node into
the parent sysrepo passes, control-plane-protocols is one merged
subscription so config-only instances stay, and an empty answer from a
yangerd still starting is no data rather than an error.  Entries
libyang rejects are dropped instead of failing the whole GET.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
Nudges yangerd to re-read its polled sources after a configuration
change.  Best effort, the commit must not fail when yangerd is not
installed or not yet running.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
Signed-off-by: Mattias Walström <lazzer@gmail.com>
Dynamic entries were baked into the generated ipset XML to survive a
firewalld reload, which resurrected entries removed while a reload was
in flight.  The XML now holds static entries only, and 'firewall
reload' re-applies the dynamic ones from confd's shadow files once
firewalld is back, dropping any it rejects.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
Room for yangerd on the virtual DUTs.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
Operational data now comes from yangerd.  Interfaces, routes and
containers are reactive, the rest is polled, so checks that read a
value once right after a change now poll with until().  Also dumps AP
and client state when a WiFi check gives up, and updates the generated
test specifications.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
Both are drafts from the start of the work, kept for reference.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
Same weekly gomod schedule as webui and netbrowse.  Dependabot detects
the vendor directory itself and re-vendors on every bump.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
Replaces wgctrl, which pulled in the whole wireguard module, x/crypto
and the Windows syscall tables for one device dump.  The query is the
same WG_CMD_GET_DEVICE the wg tool makes, on the mdlayher/genetlink
stack already used for ethtool and nl80211.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
The two users only need Add, Remove and Create, Write and Remove
events, which is a thin layer over the inotify calls in x/sys/unix.
fsnotify brought its BSD, Darwin and Windows backends and with them
the x/sys/windows tables into vendor.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
Loading all modules took ~0.7 s per DUT before a test could even ask
has_feature() and skip.  The module list is enough for that.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
Signed-off-by: Mattias Walström <lazzer@gmail.com>
The collector only asked ospfd and ripd, so the ospfv3 and ripng
protocols had no operational state at all.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
Without them a RIPng or OSPFv3 route add never triggers a RIB
re-read, so IPv6 routes only showed up when something else changed.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
The live tree is under 1 MiB but RSS drifted past 100 MiB, enough for
the OOM killer to pick yangerd while rauc held a bundle in tmpfs on a
512 MiB box.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
The installer status is empty while yangerd restarts; poll instead of
crashing on None.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
Depending on the iproute2 version a failing command prints nothing,
[] or [{}] before its "Command failed" line, and with stdout and
stderr on separate pipes the two race, so the stray line became the
next query's answer and an interface's addresses were replaced with
another command's output.  Merge the pipes and follow every command
with one that always fails, so its failure line delimits the answer.

Also serialize Refresh with the restart loop, which killed whichever
process was current after its backoff sleep, and stop readers of a
replaced process instead of leaking them.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
closed() started a goroutine blocked in poll(2) for every delivered
event, and they only ended when the watcher closed, which for fswatcher
is never.  Each pinned an OS thread: 1300 threads and 66 MB of heap on
a DUT after an hour of tests.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
The routing collector polled FRR every 10 s, so an OSPF neighbor loss
took up to that long to show.  A route change is the one event FRR
gives for it, so poke the collector from the ZAPI watcher.

Signed-off-by: Mattias Walström <lazzer@gmail.com>
The software object was read once at start, and when rauc was not up
yet it stayed without booted and the slots for the life of the
process.  Finit's own slot check waits for rauc; yangerd did not, and
on the styx boards it lost the race.

Signed-off-by: Mattias Walström <lazzer@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci:main Build default defconfig, not minimal

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant