Repository navigation
Yangerd - #1536
Draft
mattiaswal wants to merge 10 commits into
Draft
Yangerd#1536mattiaswal wants to merge 10 commits into
mattiaswal wants to merge 10 commits into
Conversation
mattiaswal
force-pushed
the
yangerd
branch
3 times, most recently
from
June 19, 2026 09:38
3ec2747 to
71d50ea
Compare
mattiaswal
force-pushed
the
yangerd
branch
3 times, most recently
from
August 17, 2026 11:52
7537929 to
8e6b2a1
Compare
mattiaswal
force-pushed
the
yangerd
branch
4 times, most recently
from
October 5, 2026 11:22
01b4d8f to
ba1a1b3
Compare
mattiaswal
force-pushed
the
yangerd
branch
3 times, most recently
from
October 8, 2026 19:11
4990ef4 to
0f12f38
Compare
A Go daemon replacing the Python yanger scripts that statd forked on
every GET. It keeps operational state in memory, driven by netlink,
nl80211, D-Bus, ZAPI, inotify and the FRR vty sockets, polls only what
has no events, and serves it to statd over a Unix socket as JSON.
Covers interfaces, routing, system, hardware, NTP, LLDP, containers,
firewall, DHCP, TFTP, PTP and WiFi. The RIB comes from zebra when
built with FRR and from the kernel table otherwise.
Interface queries go through a long-lived 'ip -batch' process. A
failing command prints nothing, [] or [{}] before its "Command failed"
line depending on the iproute2 version, and stdout and stderr race on
separate pipes, so the pipes are merged and every command is followed
by one that always fails, whose failure line delimits the answer.
inotify and the wireguard device dump are thin layers over x/sys/unix
and the mdlayher/genetlink stack already used for ethtool and nl80211,
rather than fsnotify and wgctrl, which brought their BSD, Darwin and
Windows backends and x/crypto into vendor. The inotify watcher must
not leave a goroutine blocked in poll(2) per event: each pinned an OS
thread, 1300 of them after an hour of tests on a DUT.
A route change is the one event FRR gives for a neighbor loss, so the
ZAPI watcher pokes the routing collector instead of waiting for the
10 s poll, and the rauc software object is re-read once rauc appears
on the bus, since on the styx boards yangerd came up before it.
Signed-off-by: Mattias Walström <lazzer@gmail.com>
Buildroot builds with -mod=vendor and no network access. Signed-off-by: Mattias Walström <lazzer@gmail.com>
Finit service with readiness notification. Build-time feature flags in /etc/default/yangerd mirror the packages selected, so yangerd only runs the monitors that have something to monitor. GOMEMLIMIT caps the Go heap at 64 MiB. The live tree is under 1 MiB but RSS drifted past 100 MiB, enough for the OOM killer to pick yangerd while rauc held a bundle in tmpfs on a 512 MiB box. Dependabot tracks the Go dependencies on the same weekly schedule as webui and netbrowse, and re-vendors on every bump. Signed-off-by: Mattias Walström <lazzer@gmail.com>
Replaces forking the Python yanger scripts with a query over yangerd's Unix socket. Nested subscriptions graft only the requested node into the parent sysrepo passes, control-plane-protocols is one merged subscription so config-only instances stay, and an empty answer from a yangerd still starting is no data rather than an error. Entries libyang rejects are dropped instead of failing the whole GET. Signed-off-by: Mattias Walström <lazzer@gmail.com>
Nudges yangerd to re-read its polled sources after a configuration change. Best effort, the commit must not fail when yangerd is not installed or not yet running. Signed-off-by: Mattias Walström <lazzer@gmail.com>
Signed-off-by: Mattias Walström <lazzer@gmail.com>
Dynamic entries were baked into the generated ipset XML to survive a firewalld reload, which resurrected entries removed while a reload was in flight. The XML now holds static entries only, and 'firewall reload' re-applies the dynamic ones from confd's shadow files once firewalld is back, dropping any it rejects. Signed-off-by: Mattias Walström <lazzer@gmail.com>
Room for yangerd on the virtual DUTs. Signed-off-by: Mattias Walström <lazzer@gmail.com>
Operational data now comes from yangerd. Interfaces, routes and containers are reactive, the rest is polled, so checks that read a value once right after a change now poll with until(). Also dumps AP and client state when a WiFi check gives up, and updates the generated test specifications. Signed-off-by: Mattias Walström <lazzer@gmail.com>
Loading all modules took ~0.7 s per DUT before a test could even ask has_feature() and skip. The module list is enough for that. Signed-off-by: Mattias Walström <lazzer@gmail.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Checklist
Tick relevant boxes, this PR is-a or has-a: