From 537bfce2bda471c92caabd388589230200891509 Mon Sep 17 00:00:00 2001 From: Michael Biebl Date: Fri, 3 Jul 2026 19:53:18 +0200 Subject: New upstream version 1.58~rc1 --- .gitignore | 4 - .gitlab-ci.yml | 22 +- .gitlab-ci/ci.template | 12 + .gitlab-ci/debian-install.sh | 7 + .gitlab/merge_request_templates/Default.md | 12 +- .pre-commit-config.yaml | 28 + CONTRIBUTING.md | 22 + NEWS | 119 +- config.h.meson | 9 +- contrib/alpine/REQUIRED_PACKAGES | 3 +- contrib/debian/REQUIRED_PACKAGES | 11 + contrib/fedora/REQUIRED_PACKAGES | 3 +- contrib/fedora/rpm/24-clat-auto.conf | 32 + contrib/fedora/rpm/NetworkManager.spec | 67 +- contrib/fedora/rpm/build.sh | 2 + contrib/fedora/rpm/build_clean.sh | 1 - contrib/fedora/rpm/configure-for-system.sh | 24 +- contrib/scripts/nm-ci-run.sh | 12 +- contrib/scripts/nm-copr-build.sh | 10 +- data/NetworkManager-config-initrd.service.in | 5 +- data/NetworkManager-initrd.service.in | 10 +- data/NetworkManager-wait-online-initrd.service.in | 5 +- data/NetworkManager.service.in | 10 +- data/meson.build | 10 +- data/org.freedesktop.NetworkManager.policy.in | 174 + data/org.freedesktop.NetworkManager.policy.in.in | 174 - docs/libnm/libnm.svg | 2 +- ...rg.freedesktop.NetworkManager.Device.Geneve.xml | 12 +- .../org.freedesktop.NetworkManager.Device.xml | 4 +- ...edesktop.NetworkManager.Settings.Connection.xml | 2 +- man/NetworkManager.conf.xml | 66 +- man/nm-cloud-setup.xml | 4 +- man/nmcli.xml | 7 +- man/nmtui.xml | 5 + meson.build | 57 +- meson_options.txt | 11 +- po/LINGUAS | 1 + po/POTFILES.in | 6 +- po/bg.po | 9892 ++++++----- po/kk.po | 16300 +++++++++++++++++++ po/pt_BR.po | 9602 ++++++----- po/sl.po | 6855 ++++---- po/sr.po | 16019 ++++++++---------- po/sr@latin.po | 16014 ++++++++---------- po/sv.po | 10220 ++++++------ po/tr.po | 5382 +++--- src/c-list/.github/workflows/ci.yml | 32 +- src/c-rbtree/.github/workflows/ci.yml | 13 +- src/c-rbtree/.readthedocs.yaml | 23 - src/c-rbtree/NEWS.md | 14 + src/c-rbtree/meson.build | 4 +- src/c-rbtree/src/c-rbtree.h | 4 +- src/c-rbtree/src/docs/.readthedocs.yaml | 24 + src/c-rbtree/src/docs/conf.py | 13 +- src/c-rbtree/src/docs/requirements.txt | 6 +- src/c-rbtree/src/meson.build | 2 +- src/c-siphash/.github/workflows/ci.yml | 13 +- src/c-siphash/NEWS.md | 14 + src/c-siphash/meson.build | 4 +- src/c-siphash/src/meson.build | 2 +- src/c-stdaux/.github/workflows/ci.yml | 32 +- src/c-stdaux/.readthedocs.yaml | 20 - src/c-stdaux/AUTHORS | 5 +- src/c-stdaux/NEWS.md | 22 + src/c-stdaux/meson.build | 2 +- src/c-stdaux/src/docs/.readthedocs.yaml | 22 + src/c-stdaux/src/docs/conf.py | 13 +- src/c-stdaux/src/docs/requirements.txt | 6 +- src/c-stdaux/src/meson.build | 2 + src/c-stdaux/src/test-basic.c | 4 +- src/core/bpf/clat.bpf.c | 1203 ++ src/core/bpf/clat.h | 30 + src/core/bpf/meson.build | 239 + src/core/devices/nm-device-bond.c | 13 +- src/core/devices/nm-device-ethernet.c | 12 +- src/core/devices/nm-device-macvlan.c | 7 +- src/core/devices/nm-device-veth.c | 2 +- src/core/devices/nm-device-vxlan.c | 4 +- src/core/devices/nm-device.c | 671 +- src/core/devices/nm-device.h | 1 + src/core/devices/wifi/nm-device-iwd.c | 33 + src/core/devices/wifi/nm-device-wifi.c | 174 +- src/core/devices/wifi/nm-wifi-ap.c | 18 +- src/core/devices/wifi/nm-wifi-utils.c | 40 +- src/core/devices/wifi/nm-wifi-utils.h | 4 + src/core/devices/wifi/tests/test-devices-wifi.c | 46 + src/core/devices/wwan/nm-modem-manager.c | 11 +- src/core/dhcp/README.next.md | 10 +- src/core/dhcp/nm-dhcp-client.c | 45 +- src/core/dhcp/nm-dhcp-client.h | 5 +- src/core/dhcp/nm-dhcp-dhclient-utils.c | 763 - src/core/dhcp/nm-dhcp-dhclient-utils.h | 38 - src/core/dhcp/nm-dhcp-dhclient.c | 741 - src/core/dhcp/nm-dhcp-helper.c | 3 +- src/core/dhcp/nm-dhcp-listener.c | 3 - src/core/dhcp/nm-dhcp-manager.c | 35 +- src/core/dhcp/nm-dhcp-nettools.c | 28 +- src/core/dhcp/nm-dhcp-systemd.c | 48 +- src/core/dhcp/nm-dhcp-utils.c | 58 - src/core/dhcp/nm-dhcp-utils.h | 6 - src/core/dhcp/tests/meson.build | 1 - .../dhcp/tests/test-dhclient-commented-duid.leases | 2 - src/core/dhcp/tests/test-dhclient-duid.leases | 2 - src/core/dhcp/tests/test-dhcp-dhclient.c | 1478 -- src/core/dns/nm-dns-manager.c | 2 +- src/core/main.c | 22 +- src/core/meson.build | 17 +- src/core/ndisc/nm-lndp-ndisc.c | 35 +- src/core/ndisc/nm-ndisc-private.h | 2 + src/core/ndisc/nm-ndisc.c | 152 +- src/core/ndisc/nm-ndisc.h | 27 +- src/core/nm-config.c | 35 +- src/core/nm-core-utils.c | 470 + src/core/nm-core-utils.h | 16 + src/core/nm-ip-config.c | 111 +- src/core/nm-l3-config-data.c | 297 +- src/core/nm-l3-config-data.h | 44 +- src/core/nm-l3cfg.c | 593 + src/core/nm-manager.c | 85 +- src/core/nm-netns.c | 44 +- src/core/nm-netns.h | 1 + src/core/nm-pacrunner-manager.c | 54 - src/core/nm-policy.c | 14 +- src/core/ppp/nm-pppd-plugin.c | 2 +- src/core/settings/nm-settings-connection.c | 2 + src/core/settings/nm-settings.c | 2 + .../plugins/ifcfg-rh/nms-ifcfg-rh-reader.c | 51 +- .../plugins/ifcfg-rh/nms-ifcfg-rh-writer.c | 19 +- .../ifcfg-Test_Write_WiFi_AP_Mode.cexpected | 3 +- .../ifcfg-Test_Write_WiFi_Band_6ghz.cexpected | 18 + .../ifcfg-Test_Write_WiFi_Band_A.cexpected | 18 - .../ifcfg-Test_Write_WiFi_Band_a.cexpected | 18 + .../network-scripts/ifcfg-test-wifi-band-6ghz | 13 + .../ifcfg-test-wifi-band-6ghz-channel-mismatch | 9 + .../plugins/ifcfg-rh/tests/test-ifcfg-rh.c | 93 +- .../settings/plugins/keyfile/nms-keyfile-writer.c | 4 +- src/core/supplicant/nm-supplicant-config.c | 98 +- src/core/supplicant/nm-supplicant-interface.c | 15 + src/core/supplicant/nm-supplicant-interface.h | 1 + .../supplicant/nm-supplicant-settings-verify.c | 3 +- src/core/tests/config/NetworkManager-warn.conf | 2 +- src/core/tests/config/NetworkManager.conf | 2 +- src/core/tests/config/test-config.c | 4 +- src/core/tests/test-core.c | 105 + src/core/tests/test-netns.c | 39 + src/core/tests/test-systemd.c | 37 + src/core/vpn/nm-vpn-connection.c | 8 +- src/core/vpn/nm-vpn-manager.c | 35 +- src/libnm-base/nm-base.h | 1 + src/libnm-base/nm-config-base.h | 1 + src/libnm-client-impl/libnm.ver | 9 +- src/libnm-client-impl/meson.build | 4 +- src/libnm-client-impl/nm-access-point.c | 12 +- src/libnm-client-impl/nm-active-connection.c | 4 +- src/libnm-client-impl/nm-device-geneve.c | 24 +- src/libnm-client-impl/nm-device.c | 4 +- src/libnm-client-impl/nm-ip-config.c | 90 +- src/libnm-client-impl/nm-libnm-utils.c | 7 + src/libnm-client-impl/nm-object.c | 2 +- src/libnm-client-impl/tests/test-libnm.c | 32 + src/libnm-client-impl/tests/test-nm-client.c | 2 +- src/libnm-client-public/nm-device-geneve.h | 16 +- src/libnm-client-public/nm-device.h | 4 +- src/libnm-client-public/nm-ip-config.h | 10 +- src/libnm-core-aux-intern/nm-libnm-core-utils.c | 193 + src/libnm-core-aux-intern/nm-libnm-core-utils.h | 25 + .../gen-metadata-nm-settings-libnm-core.xml.in | 4 + src/libnm-core-impl/nm-connection.c | 2 +- src/libnm-core-impl/nm-setting-8021x.c | 9 +- src/libnm-core-impl/nm-setting-bond.c | 16 +- src/libnm-core-impl/nm-setting-connection.c | 5 +- src/libnm-core-impl/nm-setting-geneve.c | 26 +- src/libnm-core-impl/nm-setting-ip-config.c | 9 +- src/libnm-core-impl/nm-setting-ip4-config.c | 90 +- src/libnm-core-impl/nm-setting-ip6-config.c | 8 +- src/libnm-core-impl/nm-setting-private.h | 3 +- src/libnm-core-impl/nm-setting-wireless.c | 23 +- src/libnm-core-impl/nm-utils.c | 267 +- src/libnm-core-impl/tests/test-general.c | 327 +- src/libnm-core-impl/tests/test-setting.c | 15 +- src/libnm-core-intern/nm-core-internal.h | 2 - src/libnm-core-public/nm-connection.h | 2 +- src/libnm-core-public/nm-dbus-interface.h | 6 +- src/libnm-core-public/nm-setting-geneve.h | 18 +- src/libnm-core-public/nm-setting-ip4-config.h | 30 + src/libnm-core-public/nm-utils.h | 30 +- src/libnm-core-public/nm-version-macros.h.in | 2 +- src/libnm-core-public/nm-version.h | 14 +- src/libnm-glib-aux/nm-inet-utils.c | 86 + src/libnm-glib-aux/nm-inet-utils.h | 4 + src/libnm-glib-aux/tests/test-shared-general.c | 55 + src/libnm-platform/nm-linux-platform.c | 10 +- src/libnm-platform/nm-platform.c | 34 +- src/libnm-platform/nm-platform.h | 1 + src/libnm-platform/nmp-ethtool-ioctl.c | 27 - src/libnm-platform/nmp-ethtool-ioctl.h | 2 - src/libnm-systemd-shared/nm-sd-utils-shared.c | 23 +- src/libnmc-base/nm-client-utils.c | 152 +- src/libnmc-base/nm-client-utils.h | 12 + src/libnmc-base/tests/meson.build | 26 + src/libnmc-base/tests/test-client-utils.c | 126 + src/libnmc-setting/nm-meta-setting-access.c | 25 +- src/libnmc-setting/nm-meta-setting-access.h | 1 + src/libnmc-setting/nm-meta-setting-desc.c | 12 +- src/libnmc-setting/nm-meta-setting-desc.h | 1 + src/libnmc-setting/settings-docs.h.in | 23 +- src/libnmt-newt/meson.build | 1 + src/libnmt-newt/nmt-newt-form.c | 182 +- src/libnmt-newt/nmt-newt-form.h | 5 + src/libnmt-newt/nmt-newt-textbox.c | 2 +- src/libnmt-newt/nmt-newt-utils.c | 39 + src/libnmt-newt/nmt-newt-utils.h | 2 + src/meson.build | 1 + src/n-acd/src/n-acd.c | 9 +- src/n-dhcp4/src/n-dhcp4-c-connection.c | 48 +- src/n-dhcp4/src/util/packet.c | 8 +- src/n-dhcp4/src/util/test-packet.c | 115 + src/nm-initrd-generator/meson.build | 7 + src/nm-initrd-generator/nm-initrd-generator.sh | 50 + src/nm-initrd-generator/nmi-cmdline-reader.c | 2 +- src/nmcli/common.c | 18 + src/nmcli/connections.c | 17 +- src/nmcli/devices.c | 167 +- src/nmcli/gen-metadata-nm-settings-nmcli.xml.in | 28 +- src/nmcli/general.c | 18 + src/nmcli/utils.c | 14 +- src/nmcli/utils.h | 5 + src/nmtui/meson.build | 4 +- src/nmtui/nm-editor-bindings.c | 4 +- src/nmtui/nmt-address-list.c | 267 - src/nmtui/nmt-address-list.h | 43 - src/nmtui/nmt-connect-connection-list.c | 56 +- src/nmtui/nmt-connect-connection-list.h | 4 + src/nmtui/nmt-device-entry.c | 173 +- src/nmtui/nmt-device-entry.h | 5 +- src/nmtui/nmt-edit-connection-list.c | 129 +- src/nmtui/nmt-edit-connection-list.h | 3 + src/nmtui/nmt-editor-grid.c | 6 +- src/nmtui/nmt-editor.c | 45 +- src/nmtui/nmt-list.c | 277 + src/nmtui/nmt-list.h | 41 + src/nmtui/nmt-page-bond.c | 112 +- src/nmtui/nmt-page-bridge.c | 2 +- src/nmtui/nmt-page-ip-tunnel.c | 2 +- src/nmtui/nmt-page-ip4.c | 8 +- src/nmtui/nmt-page-ip6.c | 8 +- src/nmtui/nmt-page-macsec.c | 2 +- src/nmtui/nmt-page-vlan.c | 2 +- src/nmtui/nmt-page-wifi.c | 7 +- src/nmtui/nmt-password-dialog.c | 33 +- src/nmtui/nmt-utils.c | 209 + src/nmtui/nmt-utils.h | 35 + src/nmtui/nmt-widget-list.c | 2 +- src/nmtui/nmt-wifi-qr-dialog.c | 165 + src/nmtui/nmt-wifi-qr-dialog.h | 13 + src/nmtui/nmt-wireguard-peer-list.c | 1 + src/nmtui/nmtui-connect.c | 305 +- src/nmtui/nmtui-connect.h | 2 + src/nmtui/nmtui-edit.c | 16 +- src/nmtui/nmtui.c | 18 +- .../test-client.check-on-disk/test_002.expected | 186 +- .../test-client.check-on-disk/test_003.expected | 2876 ++-- .../test-client.check-on-disk/test_004.expected | 5408 +++--- .../test-client.check-on-disk/test_005.expected | 15 + src/tests/client/test-client.py | 41 +- tools/nm-guest-data/systemd-dhcp-host.service.in | 14 - tools/nm-in-container | 1 - tools/nm-in-vm | 5 +- tools/test-networkmanager-service.py | 24 +- 269 files changed, 66677 insertions(+), 46539 deletions(-) create mode 100644 .pre-commit-config.yaml create mode 100644 contrib/fedora/rpm/24-clat-auto.conf create mode 100644 data/org.freedesktop.NetworkManager.policy.in delete mode 100644 data/org.freedesktop.NetworkManager.policy.in.in create mode 100644 po/kk.po delete mode 100644 src/c-rbtree/.readthedocs.yaml create mode 100644 src/c-rbtree/src/docs/.readthedocs.yaml delete mode 100644 src/c-stdaux/.readthedocs.yaml create mode 100644 src/c-stdaux/src/docs/.readthedocs.yaml create mode 100644 src/core/bpf/clat.bpf.c create mode 100644 src/core/bpf/clat.h create mode 100644 src/core/bpf/meson.build delete mode 100644 src/core/dhcp/nm-dhcp-dhclient-utils.c delete mode 100644 src/core/dhcp/nm-dhcp-dhclient-utils.h delete mode 100644 src/core/dhcp/nm-dhcp-dhclient.c delete mode 100644 src/core/dhcp/tests/test-dhclient-commented-duid.leases delete mode 100644 src/core/dhcp/tests/test-dhclient-duid.leases delete mode 100644 src/core/dhcp/tests/test-dhcp-dhclient.c create mode 100644 src/core/settings/plugins/ifcfg-rh/tests/network-scripts/ifcfg-Test_Write_WiFi_Band_6ghz.cexpected delete mode 100644 src/core/settings/plugins/ifcfg-rh/tests/network-scripts/ifcfg-Test_Write_WiFi_Band_A.cexpected create mode 100644 src/core/settings/plugins/ifcfg-rh/tests/network-scripts/ifcfg-Test_Write_WiFi_Band_a.cexpected create mode 100644 src/core/settings/plugins/ifcfg-rh/tests/network-scripts/ifcfg-test-wifi-band-6ghz create mode 100644 src/core/settings/plugins/ifcfg-rh/tests/network-scripts/ifcfg-test-wifi-band-6ghz-channel-mismatch create mode 100644 src/libnmc-base/tests/meson.build create mode 100644 src/libnmc-base/tests/test-client-utils.c create mode 100755 src/nm-initrd-generator/nm-initrd-generator.sh delete mode 100644 src/nmtui/nmt-address-list.c delete mode 100644 src/nmtui/nmt-address-list.h create mode 100644 src/nmtui/nmt-list.c create mode 100644 src/nmtui/nmt-list.h create mode 100644 src/nmtui/nmt-wifi-qr-dialog.c create mode 100644 src/nmtui/nmt-wifi-qr-dialog.h create mode 100644 src/tests/client/test-client.check-on-disk/test_005.expected delete mode 100644 tools/nm-guest-data/systemd-dhcp-host.service.in diff --git a/.gitignore b/.gitignore index bf962c8a..d70517f4 100644 --- a/.gitignore +++ b/.gitignore @@ -81,7 +81,6 @@ test-*.trs /data/org.freedesktop.NetworkManager.service /data/server.conf /data/org.freedesktop.NetworkManager.policy -/data/org.freedesktop.NetworkManager.policy.in /data/nm-sudo.service /data/nm-priv-helper.service /data/NetworkManager-config-initrd.service @@ -250,7 +249,6 @@ test-*.trs /src/core/devices/wifi/tests/test-devices-wifi /src/core/devices/wwan/tests/test-service-providers /src/core/dhcp/nm-dhcp-helper -/src/core/dhcp/tests/test-dhcp-dhclient /src/core/dhcp/tests/test-dhcp-options /src/core/dhcp/tests/test-dhcp-utils /src/core/dnsmasq/tests/test-dnsmasq-utils @@ -428,11 +426,9 @@ test-*.trs /src/devices/wifi/tests/test-wifi-ap-utils /src/devices/wwan/tests/test-service-providers /src/dhcp-manager/nm-dhcp-helper -/src/dhcp-manager/tests/test-dhcp-dhclient /src/dhcp-manager/tests/test-dhcp-options /src/dhcp-manager/tests/test-dhcp-utils /src/dhcp/nm-dhcp-helper -/src/dhcp/tests/test-dhcp-dhclient /src/dhcp/tests/test-dhcp-options /src/dhcp/tests/test-dhcp-utils /src/dnsmasq-manager/tests/test-dnsmasq-utils diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index 67fcf026..fdc65200 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -60,11 +60,11 @@ variables: # # This is done by running `ci-fairy generate-template` and possibly bumping # ".default_tag". - ALPINE_TAG: 'tag-0c3a6f855fb8' - CENTOS_TAG: 'tag-c1c23df75dda' - DEBIAN_TAG: 'tag-d4bf5db9e214' - FEDORA_TAG: 'tag-c1c23df75dda' - UBUNTU_TAG: 'tag-d4bf5db9e214' + ALPINE_TAG: 'tag-c501b92e52c1' + CENTOS_TAG: 'tag-e01fd12e49d7' + DEBIAN_TAG: 'tag-7c9bad89a15e' + FEDORA_TAG: 'tag-e01fd12e49d7' + UBUNTU_TAG: 'tag-7c9bad89a15e' ALPINE_EXEC: 'bash .gitlab-ci/alpine-install.sh' CENTOS_EXEC: 'bash .gitlab-ci/fedora-install.sh' @@ -72,6 +72,18 @@ variables: FEDORA_EXEC: 'bash .gitlab-ci/fedora-install.sh' UBUNTU_EXEC: 'bash .gitlab-ci/debian-install.sh' +# Retry only on transient infrastructure failures. script_failure is +# intentionally excluded so real (and flaky) test failures stay visible. +default: + retry: + max: 2 + when: + - runner_system_failure + - stuck_or_timeout_failure + - scheduler_failure + - api_failure + - unknown_failure + .nm_artifacts: variables: NM_BUILD_TARBALL: 1 diff --git a/.gitlab-ci/ci.template b/.gitlab-ci/ci.template index 4ef3ff9e..7aef02aa 100644 --- a/.gitlab-ci/ci.template +++ b/.gitlab-ci/ci.template @@ -77,6 +77,18 @@ variables: {{"%-13s"| format(distro_group.name.upper() + '_EXEC:')}}'bash .gitlab-ci/{{base_types[distro_group.name]}}-install.sh' {% endfor %} +# Retry only on transient infrastructure failures. script_failure is +# intentionally excluded so real (and flaky) test failures stay visible. +default: + retry: + max: 2 + when: + - runner_system_failure + - stuck_or_timeout_failure + - scheduler_failure + - api_failure + - unknown_failure + .nm_artifacts: variables: NM_BUILD_TARBALL: 1 diff --git a/.gitlab-ci/debian-install.sh b/.gitlab-ci/debian-install.sh index 737d4052..f46323fb 100755 --- a/.gitlab-ci/debian-install.sh +++ b/.gitlab-ci/debian-install.sh @@ -31,6 +31,13 @@ if [ $IS_DEBIAN_9 = 1 -o $IS_UBUNTU_18_04 = 1 ]; then ln -sf /bin/true /usr/bin/chfn fi +# The udev postinst runs systemd-tmpfiles, which fails to chown the +# read-only /dev/kvm, /dev/vhost-* nodes the CI runner exposes. We only +# need udev for its pkgconfig file, not the daemon; mask the offending +# tmpfiles so the postinst succeeds. +mkdir -p /etc/tmpfiles.d +: > /etc/tmpfiles.d/static-nodes-permissions.conf + DEBIAN_FRONTEND=noninteractive apt-get update DEBIAN_FRONTEND=noninteractive NM_INSTALL="apt-get --yes install" bash -x ./contrib/debian/REQUIRED_PACKAGES diff --git a/.gitlab/merge_request_templates/Default.md b/.gitlab/merge_request_templates/Default.md index ab71553b..5c65eb3a 100644 --- a/.gitlab/merge_request_templates/Default.md +++ b/.gitlab/merge_request_templates/Default.md @@ -12,9 +12,9 @@ Please read https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/blob/main/CONTRIBUTING.md before opening the merge request. In particular, check that: - - [ ] the subject for all commits is concise and explicative - - [ ] the message for all commits explains the reason for the change - - [ ] the source is properly formatted - - [ ] any relevant documentation is up to date - - [ ] you have added unit tests if applicable - - [ ] the NEWS file is updated when the change deserves to be mentioned, for example for new features, behavior changes, API deprecations, etc. + - [ ] The subject for all commits is concise, explanatory, and includes a prefix indicating the area of code changed (e.g., "nmcli: ", "core: ") + - [ ] The message for all commits explains the reason for the change + - [ ] The source is properly formatted + - [ ] Any relevant documentation is up to date + - [ ] You have added unit tests if applicable + - [ ] The NEWS file is updated when the change deserves to be mentioned, for example for new features, behavior changes, API deprecations, etc. diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml new file mode 100644 index 00000000..7ef2373e --- /dev/null +++ b/.pre-commit-config.yaml @@ -0,0 +1,28 @@ +repos: + - repo: local + hooks: + - id: nm-clang-format + name: clang-format (CI version, container) + entry: ./contrib/scripts/nm-code-format-container.sh -n + language: script + files: \.[ch]$ + require_serial: true + exclude: | + (?x)^( + src/c-list/| + src/c-rbtree/| + src/c-siphash/| + src/c-stdaux/| + src/libnm-std-aux/unaligned(-fundamental)?\.h| + src/libnm-systemd-core/src/| + src/libnm-systemd-shared/src/| + src/linux-headers/| + src/n-acd/| + src/n-dhcp4/ + ) + - id: nm-potfiles + name: POTFILES.in consistency + entry: src/tests/check-potfile-list.py + language: script + pass_filenames: false + always_run: true diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index d755ef74..f5d78f2f 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -147,6 +147,28 @@ $ git config --add 'blame.ignoreRevsFile' '.git-blame-ignore-revs' You may integrate clang-formatter in your editor (for [vim](https://github.com/rhysd/vim-clang-format)). +### pre-commit hooks + +A [pre-commit](https://pre-commit.com/) config (`.pre-commit-config.yaml`) is +provided to catch the two issues that most often fail CI's "check-tree" stage +before you push: + +- clang-format on the C/H files you touched, via + `contrib/scripts/nm-code-format-container.sh` so it matches CI's clang-format + version (requires podman); +- `POTFILES.in` consistency (`src/tests/check-potfile-list.py`). + +To enable it, install pre-commit (`pip install pre-commit`, or your distro's +package) and run once in the checkout: + +``` +$ pre-commit install +``` + +The hooks then run on every `git commit`. Use `git commit --no-verify` to skip +them for a work-in-progress commit, or `pre-commit run --all-files` to check the +whole tree. + ### Style As we use clang-format, our style is in parts determined by the tool. diff --git a/NEWS b/NEWS index 109688ad..21451a5e 100644 --- a/NEWS +++ b/NEWS @@ -1,22 +1,122 @@ ============================================= -NetworkManager-1.56.1 +NetworkManager-1.58 Overview of changes since NetworkManager-1.56 ============================================= +This is a snapshot of NetworkManager development. The API is +subject to change and not guaranteed to be compatible with +the later release. +USE AT YOUR OWN RISK. NOT RECOMMENDED FOR PRODUCTION USE! + +* Unify the versioning to use everywhere the scheme with the -rcX or -dev + suffixes when appropriate. This affects, for example, the URL and filename + of the release tarball and the version reported by nmcli and the daemon. + As an exception, the C API will continue to use the 90+ scheme for RC versions. +* Connection profiles with manual IP addressing and with gateways that are not + directly reachable will generate a warning on activation and when they are + added/modified via nmcli and nmtui. NetworkManager currently adds on-link + routes for them automatically, but this will change in the future. To fix the + warning, users should add addresses or routes whose subnets cover these + gateways. A gateway (either the default gateway or the next-hop of a route) is + considered directly reachable if it falls within the subnet of a direct route + (a route without a next hop) or of a prefix route from a static address. +* Restrict the connectivity check to use the DNS servers defined on the + same link. If the link has no DNS servers, the connectivity check will + use any servers available in the system. +* Install the systemd units in the initramfs using a systemd generator. +* A new "check-connectivity" configuration option is available to disable the + connectivity check for selected interfaces. +* Remove the modify_system build option that allowed setting up the + polkit permissions to allow non-admin users to create system-wide + connection. That configuration is discouraged because it can be used + to bypass filesystem permissions. +* For private connections (the ones that specify a user in the + "connection.permissions" property), verify that the user can access + the 802.1X certificates and keys set in the connection. +* Introduce a libnm function that can be used by VPN plugins to check + user permissions on certificate and keys. +* The support for Wireless Extensions is deprecated and will be + removed in a future release. Wireless Extensions are now disabled by + default. +* Use an internal implementation of the ping functionality when the + "connection.gateway-ping-timeout" or "connection.ip-ping-addresses" + properties are set, instead of relying on the "ping" tool. +* The powersave property now functions with the iwd backend. +* The "band" property of Wi-fi connections now accepts the "6GHz" + value. +* Show the Wi-Fi band of APs in the scan results from nmcli. +* New button in nmtui that allows users to chose from list of + available devices when creating connection profiles for physical interfaces + (Ethernet, Wi-Fi, etc.). +* Add support for CLAT (464XLAT) using a BPF program. +* Change the default value of the ipv4.dhcp-ipv6-only-preferred property + to a new value "auto" which automatically enables the option when CLAT + is enabled ("yes" or "auto") in the connection profile. +* WIFI connections using wpa-psk respect the setting connection.auth-retry + and only prompt for new secrets during the last authentication attempt before + failing. * Add support for GENEVE interface. +* The DHCPv4 internal client now ignores option 3 (Router) if the lease + contains option 121 (Classless Static Route), as recommended by RFC 3442. * Allow persisting the managed state across reboots from nmcli and the D-Bus API. * Allow changing the device's administrative state in the kernel at the same time as a change to the managed state from nmcli and the D-Bus API. +* Allow configuring all bond options in nmtui by introducing a + "other options" field, which covers options not already covered by a + dedicated input field. +* IPv6 interfaces that receive PD via DHCPv6 are considered healthy without a + non-temporary address. The delegated prefix can be used via an interface + configured with "ipv6.method: shared" +* nmtui now offers a "Show password" checkbox in the dialog that prompts for + secrets when activating a connection, matching the connection editor. +* Fix an out-of-bounds read in the internal DHCPv4 client that an on-link + attacker could trigger with a malformed UDP packet, crashing NetworkManager. +* The nmtui connection lists ("nmtui connect" and "nmtui edit") support a + vim-style "/" search that filters the list to matching entries as you type. +* nmtui now redraws its forms when the terminal is resized, instead of leaving + them off-center or clipped until the form is reopened. +* The "Activate a connection" screen in nmtui now has a "Rescan Wi-Fi" button + that scans for nearby Wi-Fi networks on demand. +* Validate hostnames and MUD URLs before pasting them into the dhclient + configuration file, rejecting characters that could alter the config + syntax (CVE-2026-10805). +* Fix reapply not honoring the ipv6.ignore-auto-dns, ipv6.ignore-auto-routes + and ipv6.never-default properties when DHCPv6 was not restarted (for example + when the IPv6 DNS came from a DHCPv6 lease), so that DHCPv6-provided DNS and + routes are now correctly suppressed on reapply without a connection restart. +* Accept 64 hex-character PSK in WPS credentials which are returned by some + access points. +* Drop support for dhclient as a DHCP backend, which has been deprecated + since NetworkManager-1.50. +* nmtui can now share a Wi-Fi connection as a QR code via the "Share QR..." + button in the "Edit a connection" view, mirroring "nmcli device wifi + show-password". +* nmcli "device wifi show-password" no longer prints a QR code when the + Wi-Fi password cannot be read due to insufficient privileges; it prints a + warning instead. +* Fix stale global connectivity state with connectivity checking enabled: + NetworkManager could report limited connectivity while another device had full + connectivity, or keep reporting limited after a device regained internet + access. +* nmcli "connection show" now labels the ports column "PORT" instead of + "SLAVE" (the "SLAVE" field name is still accepted as an alias), and adds + the BRIDGE.PORTS, TEAM.PORTS and GENERAL.CONTROLLER-PATH fields. +* Add a "polkit_noauth_group" build option to install a polkit rule that + lets admin users in the given group (typically "sudo" or "wheel") make + system-wide connection changes from a local console without entering a + password. It is empty (disabled) by default and is discouraged. +* When wpa_supplicant reports a WPA3-SAE password mismatch, prompt the + user for the password again instead of failing, matching the WPA-PSK + behavior. +* Fix VPN connections with "ipv4.dns-search" or "ipv6.dns-search" set + ignoring the search domains pushed by the VPN; the manually configured + and VPN-provided search domains are now merged. ============================================= NetworkManager-1.56 Overview of changes since NetworkManager-1.54 ============================================= -* Unify the versioning to use everywhere the scheme with the -rcX or -dev - suffixes when appropriate. This affects, for example, the URL and filename - of the release tarball and the version reported by nmcli and the daemon. - As an exception, the C API will continue to use the 90+ scheme for RC versions. * nmcli now supports viewing and managing WireGuard peers. * Support reapplying the "sriov.vfs" property as long as "sriov.total-vfs" is not changed. @@ -29,8 +129,8 @@ Overview of changes since NetworkManager-1.54 * Add gsm device-uid setting to restrict the devices the connection applies to. * Support configuring the HSR protocol version via the "hsr.protocol-version" property. -* Fix a bug that makes broadband connections auto-connect getting - blocked if the connection tries to reconnect when modem status is +* Fix a bug that makes broadband connections auto-connect getting + blocked if the connection tries to reconnect when modem status is "disconnecting" / "disconnected". * Treat modem connection not having an operator code available as a recoverable error. @@ -45,11 +145,6 @@ Overview of changes since NetworkManager-1.54 for eBPF is now detected at run time. * Add new MPTCP 'laminar' endpoint type, and set it by default alongside the 'subflow' one. -* For private connections (the ones that specify a user in the - "connection.permissions" property), verify that the user can access - the 802.1X certificates and keys set in the connection. -* Introduce a libnm function that can be used by VPN plugins to check - user permissions on certificate and keys. ============================================= NetworkManager-1.54 diff --git a/config.h.meson b/config.h.meson index 05d346bb..6eb4f03f 100644 --- a/config.h.meson +++ b/config.h.meson @@ -1,9 +1,6 @@ /* Define if building universal (internal helper macro) */ #mesondefine AC_APPLE_UNIVERSAL_BUILD -/* Define to path of dhclient binary */ -#mesondefine DHCLIENT_PATH - /* Define to path of dhcpcd binary */ #mesondefine DHCPCD_PATH @@ -221,9 +218,6 @@ /* Define if you want connectivity checking support */ #mesondefine WITH_CONCHECK -/* Define if you have dhclient */ -#mesondefine WITH_DHCLIENT - /* Define if you have dhcpcd */ #mesondefine WITH_DHCPCD @@ -294,3 +288,6 @@ /* Define to 1 if dlvsym() is available */ #mesondefine HAVE_DLVSYM + +/* Define to 1 if you want CLAT support. */ +#mesondefine HAVE_CLAT diff --git a/contrib/alpine/REQUIRED_PACKAGES b/contrib/alpine/REQUIRED_PACKAGES index 3a3cc1ab..d263d87f 100755 --- a/contrib/alpine/REQUIRED_PACKAGES +++ b/contrib/alpine/REQUIRED_PACKAGES @@ -8,6 +8,7 @@ apk add \ 'alpine-sdk' \ 'autoconf' \ 'bash' \ + 'bpftool' \ 'clang' \ 'curl-dev' \ 'dbus' \ @@ -23,12 +24,12 @@ apk add \ 'iproute2' \ 'iptables' \ 'jansson-dev' \ + 'libbpf-dev' \ 'libgudev-dev' \ 'libndp-dev' \ 'libnvme-dev' \ 'libnl3-dev' \ 'libpsl-dev' \ - 'libsoup-dev' \ 'libteam-dev' \ 'linux-headers' \ 'meson' \ diff --git a/contrib/debian/REQUIRED_PACKAGES b/contrib/debian/REQUIRED_PACKAGES index 68f62570..a4fb8985 100755 --- a/contrib/debian/REQUIRED_PACKAGES +++ b/contrib/debian/REQUIRED_PACKAGES @@ -43,6 +43,7 @@ install \ iproute2 \ iptables \ libaudit-dev \ + libbpf-dev \ libcurl4-gnutls-dev \ libdbus-1-dev \ libgirepository1.0-dev \ @@ -80,6 +81,16 @@ install \ \ #end +# bpftool is a virtual package on Ubuntu 22.04 and 24.04 (provided by +# linux-tools-*), with no install candidate. Install it where a candidate +# exists (Debian, Fedora, Ubuntu 25.04+) and skip it otherwise. It only +# builds the CLAT skeleton, and CLAT needs libndp >= 1.9, which those images +# lack (they ship 1.8), so their builds run with clat off and never use it. +install_ignore_missing \ + bpftool \ + \ + #end + install_ignore_missing \ python-setuptools \ policykit-1 \ diff --git a/contrib/fedora/REQUIRED_PACKAGES b/contrib/fedora/REQUIRED_PACKAGES index 6f70537d..48650202 100755 --- a/contrib/fedora/REQUIRED_PACKAGES +++ b/contrib/fedora/REQUIRED_PACKAGES @@ -49,6 +49,7 @@ install \ ModemManager-glib-devel \ audit-libs-devel \ bluez-libs-devel \ + bpftool \ clang \ dbus-devel \ dbus-x11 \ @@ -64,6 +65,7 @@ install \ iptables \ jansson-devel \ jq \ + libbpf-devel \ libcurl-devel \ libndp-devel \ libnvme-devel \ @@ -91,7 +93,6 @@ install \ # some packages don't exist in certain distributions. Install them one-by-one, and ignore errors. install_ignore_missing \ black \ - dhclient \ iproute-tc \ libasan \ libpsl-devel \ diff --git a/contrib/fedora/rpm/24-clat-auto.conf b/contrib/fedora/rpm/24-clat-auto.conf new file mode 100644 index 00000000..668ec04e --- /dev/null +++ b/contrib/fedora/rpm/24-clat-auto.conf @@ -0,0 +1,32 @@ +# CLAT implements the client part of 464XLAT (RFC 6877), an +# architecture that provides IPv4 connectivity to hosts on IPv6-only +# networks. +# +# The default value for the connection property 'ipv4.clat' is still +# 'no'. Change it globally to 'auto' (1) so that CLAT gets enabled +# automatically when the network advertises a PREF64 and there is no +# native IPv4 configured (either because DHCPv4 option 108 was +# received or because there is no DHCPv4 server). +# +# See: https://fedoraproject.org/wiki/Changes/IPv6-Mostly_Support_In_NetworkManager + +# Do not modify this file. You can hide/overwrite this file by +# creating "/etc/NetworkManager/conf.d/24-clat-auto.conf". You can +# also add configuration snippets with higher priority that override +# this setting (see `man 5 NetworkManager.conf`). Most importantly, +# this snippet only sets default values for the profile. You can +# explicitly set the value for each profile, so that this default +# value is not used. + +# For example, on a particular profile/network set +# +# $ nmcli connection modify "$PROFILE" ipv4.clat no +# +# to disable CLAT. This prevents the default from this file to take +# effect. + +[connection-24-clat-auto] +ipv4.clat=1 + +[.config] +enable=nm-version-min:1.57 diff --git a/contrib/fedora/rpm/NetworkManager.spec b/contrib/fedora/rpm/NetworkManager.spec index 73ab88f3..c7521bff 100644 --- a/contrib/fedora/rpm/NetworkManager.spec +++ b/contrib/fedora/rpm/NetworkManager.spec @@ -42,11 +42,6 @@ Release: __RELEASE_VERSION__%{?dist} %global systemd_units_cloud_setup nm-cloud-setup.service nm-cloud-setup.timer ############################################################################### -%if 0%{?fedora} > 40 || 0%{?rhel} >= 10 -%bcond_with dhclient -%else -%bcond_without dhclient -%endif %bcond_without adsl %bcond_without bluetooth %bcond_without wwan @@ -100,7 +95,13 @@ Release: __RELEASE_VERSION__%{?dist} %else %bcond_without iwd %endif - +%bcond_without polkit_noauth_group +%ifarch %{ix86} +# there is no bpftool in i686 +%bcond_with clat +%else +%bcond_without clat +%endif ############################################################################### %global dbus_version 1.9.18 @@ -164,21 +165,21 @@ Source6: 22-wifi-mac-addr.conf Source7: 70-nm-connectivity.conf Source8: readme-ifcfg-rh.txt Source9: readme-ifcfg-rh-migrated.txt +Source10: 24-clat-auto.conf #Patch1: 0001-some.patch Requires(post): systemd -Requires(post): systemd-udev -Requires(post): /usr/sbin/update-alternatives Requires(preun): systemd -Requires(preun): /usr/sbin/update-alternatives Requires(postun): systemd Requires: dbus >= %{dbus_version} Requires: glib2 >= %{glib2_version} Requires: %{name}-libnm%{?_isa} = %{epoch}:%{version}-%{release} -Recommends: iputils +%if %{with clat} +Requires: libbpf +%endif %if 0%{?rhel} == 8 # Older libndp versions use select() (rh#1933041). On well known distros, @@ -227,6 +228,7 @@ Conflicts: NetworkManager-dispatcher-routing-rules <= 1:1.47.5-3 %endif BuildRequires: gcc +BuildRequires: clang BuildRequires: pkgconfig BuildRequires: meson BuildRequires: gettext-devel >= 0.19.8 @@ -281,6 +283,10 @@ BuildRequires: firewalld-filesystem BuildRequires: iproute BuildRequires: iproute-tc BuildRequires: libnvme-devel >= 1.5 +%if %{with clat} +BuildRequires: libbpf-devel +BuildRequires: bpftool +%endif Provides: %{name}-dispatcher%{?_isa} = %{epoch}:%{version}-%{release} @@ -549,6 +555,8 @@ Group: System Environment/Base BuildArch: noarch Requires: NetworkManager Requires: /usr/bin/nmcli +Requires(post): /usr/sbin/update-alternatives +Requires(preun): /usr/sbin/update-alternatives Obsoletes: NetworkManager < %{obsoletes_initscripts_updown} %description initscripts-updown @@ -572,11 +580,6 @@ Preferably use nmcli instead. -Dnft=%{_sbindir}/nft \ -Diptables=%{_sbindir}/iptables \ -Dip6tables=%{_sbindir}/ip6tables \ -%if %{with dhclient} - -Ddhclient=%{_sbindir}/dhclient \ -%else - -Ddhclient=no \ -%endif -Ddhcpcd=no \ -Dcrypto=gnutls \ %if %{with debug} @@ -600,19 +603,20 @@ Preferably use nmcli instead. %endif %if %{with wifi} -Dwifi=true \ -%if 0%{?fedora} - -Dwext=true \ -%else - -Dwext=false \ -%endif %else -Dwifi=false \ %endif + -Dwext=false \ %if %{with iwd} -Diwd=true \ %else -Diwd=false \ %endif +%if %{with clat} + -Dclat=true \ +%else + -Dclat=false \ +%endif %if %{with bluetooth} -Dbluez5_dun=true \ %else @@ -649,7 +653,9 @@ Preferably use nmcli instead. -Dselinux=true \ -Dpolkit=true \ -Dconfig_auth_polkit_default=true \ - -Dmodify_system=true \ +%if %{with polkit_noauth_group} + -Dpolkit_noauth_group=wheel \ +%endif -Dconcheck=true \ %if 0%{?fedora} -Dlibpsl=true \ @@ -659,6 +665,7 @@ Preferably use nmcli instead. -Dsession_tracking=systemd \ -Dsuspend_resume=systemd \ -Dsystemdsystemunitdir=%{_unitdir} \ + -Dsystemdsystemgeneratordir=%{_systemdgeneratordir} \ -Dsystem_ca_path=/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem \ -Ddbus_conf_dir=%{dbus_sys_dir} \ -Dtests=yes \ @@ -710,6 +717,9 @@ cp %{SOURCE7} %{buildroot}%{_sysctldir} %if 0%{?fedora} >= 40 cp %{SOURCE6} %{buildroot}%{nmlibdir}/conf.d/ %endif +%if 0%{?fedora} >= 45 +cp %{SOURCE10} %{buildroot}%{nmlibdir}/conf.d/ +%endif %if %{with ifcfg_warning} cp %{SOURCE8} %{buildroot}%{_sysconfdir}/sysconfig/network-scripts @@ -731,6 +741,7 @@ rm -f %{buildroot}%{_libdir}/pppd/%{ppp_version}/*.la rm -f %{buildroot}%{nmplugindir}/*.la # Don't use the *-initrd.service files yet, wait dracut to support them +rm -f %{buildroot}%{_systemdgeneratordir}/nm-initrd-generator.sh rm -f %{buildroot}%{_unitdir}/NetworkManager-config-initrd.service rm -f %{buildroot}%{_unitdir}/NetworkManager-initrd.service rm -f %{buildroot}%{_unitdir}/NetworkManager-wait-online-initrd.service @@ -822,8 +833,12 @@ fi %postun -/usr/bin/udevadm control --reload-rules || : -/usr/bin/udevadm trigger --subsystem-match=net || : +# skip triggering if udevd isn't even accessible, e.g. containers or +# rpm-ostree-based systems +if [ -S /run/udev/control ]; then + /usr/bin/udevadm control --reload-rules || : + /usr/bin/udevadm trigger --subsystem-match=net || : +fi %firewalld_reload %systemd_postun %{systemd_units} @@ -858,6 +873,9 @@ fi %if 0%{?fedora} >= 40 %{nmlibdir}/conf.d/22-wifi-mac-addr.conf %endif +%if 0%{?fedora} >= 45 +%{nmlibdir}/conf.d/24-clat-auto.conf +%endif %ghost %{_sysconfdir}/%{name}/VPN %{_bindir}/nm-online %{_libexecdir}/nm-dhcp-helper @@ -896,6 +914,9 @@ fi %{_datadir}/dbus-1/system-services/org.freedesktop.nm_dispatcher.service %{_datadir}/dbus-1/system-services/org.freedesktop.nm_priv_helper.service %{_datadir}/polkit-1/actions/*.policy +%if %{with polkit_noauth_group} +%{_datadir}/polkit-1/rules.d/org.freedesktop.NetworkManager.rules +%endif %{_prefix}/lib/udev/rules.d/*.rules %{_prefix}/lib/firewalld/zones/nm-shared.xml # systemd stuff diff --git a/contrib/fedora/rpm/build.sh b/contrib/fedora/rpm/build.sh index 10180587..9f988b65 100755 --- a/contrib/fedora/rpm/build.sh +++ b/contrib/fedora/rpm/build.sh @@ -143,6 +143,7 @@ SOURCE_CONFIG_WIFI_MAC_ADDR="$(abs_path "$SOURCE_CONFIG_WIFI_MAC_ADDR" "$SCRIPTD SOURCE_SYSCTL_RP_FILTER_REDHAT="$(abs_path "$SOURCE_SYSCTL_RP_FILTER_REDHAT" "$SCRIPTDIR/70-nm-connectivity.conf")" || die "invalid \$SOURCE_SYSCTL_RP_FILTER_REDHAT argument" SOURCE_README_IFCFG_FILES="$(abs_path "$SOURCE_README_IFCFG_FILES" "$SCRIPTDIR/readme-ifcfg-rh.txt")" || die "invalid \$SOURCE_README_IFCFG_FILES argument" SOURCE_README_IFCFG_MIGRATED="$(abs_path "$SOURCE_README_IFCFG_MIGRATED" "$SCRIPTDIR/readme-ifcfg-rh-migrated.txt")" || die "invalid \$SOURCE_README_IFCFG_MIGRATED argument" +SOURCE_CONFIG_CLAT_AUTO="$(abs_path "$SOURCE_CONFIG_CLAT_AUTO" "$SCRIPTDIR/24-clat-auto.conf")" || die "invalid \$SOURCE_CONFIG_CLAT_AUTO argument" TEMP="$(mktemp -d "$SCRIPTDIR/NetworkManager.$DATE.XXXXXX")" TEMPBASE="$(basename "$TEMP")" @@ -202,6 +203,7 @@ cp "$SOURCE_CONFIG_WIFI_MAC_ADDR" "$TEMP/SOURCES/22-wifi-mac-addr.conf" || die " cp "$SOURCE_SYSCTL_RP_FILTER_REDHAT" "$TEMP/SOURCES/70-nm-connectivity.conf" || die "Could not copy source $SOURCE_SYSCTL_RP_FILTER_REDHAT to $TEMP/SOURCES" cp "$SOURCE_README_IFCFG_FILES" "$TEMP/SOURCES/readme-ifcfg-rh.txt" || die "Could not copy source $SOURCE_README_IFCFG_FILES to $TEMP/SOURCES" cp "$SOURCE_README_IFCFG_MIGRATED" "$TEMP/SOURCES/readme-ifcfg-rh-migrated.txt" || die "Could not copy source $SOURCE_README_IFCFG_MIGRATED to $TEMP/SOURCES" +cp "$SOURCE_CONFIG_CLAT_AUTO" "$TEMP/SOURCES/24-clat-auto.conf" || die "Could not copy source $SOURCE_CONFIG_CLAT_AUTO to $TEMP/SOURCES" write_changelog diff --git a/contrib/fedora/rpm/build_clean.sh b/contrib/fedora/rpm/build_clean.sh index 68599bda..4accc0d3 100755 --- a/contrib/fedora/rpm/build_clean.sh +++ b/contrib/fedora/rpm/build_clean.sh @@ -218,7 +218,6 @@ if [[ $NO_DIST != 1 ]]; then -Dlibaudit=yes-disabled-by-default \ -Dpolkit=true \ -Dnm_cloud_setup=true \ - -Ddhclient=/usr/sbin/dhclient \ -Dconfig_dhcp_default=internal \ -Dconfig_dns_rc_manager_default=auto \ -Diptables=/usr/sbin/iptables \ diff --git a/contrib/fedora/rpm/configure-for-system.sh b/contrib/fedora/rpm/configure-for-system.sh index 6bdf6682..066d7fc9 100755 --- a/contrib/fedora/rpm/configure-for-system.sh +++ b/contrib/fedora/rpm/configure-for-system.sh @@ -173,6 +173,7 @@ P_WIFI="${WIFI-1}" P_WWAN="${WWAN-1}" P_TEAM="${TEAM-1}" P_BLUETOOTH="${BLUETOOTH-1}" +P_IFCFG_RH="${IFCFG_RH-0}" P_NMTUI="${NMTUI-1}" P_NM_CLOUD_SETUP="${NM_CLOUD_SETUP-1}" P_OVS="${OVS-1}" @@ -202,7 +203,7 @@ if [ -z "$P_FEDORA" -a -z "$P_RHEL" ] ; then P_FEDORA="$x" P_RHEL=0 else - x="$(grep -q "ID=fedora" /etc/os-release && sed -n 's/VERSION_ID=//p' /etc/os-release)" + x="$(grep -q 'ID="rhel"' /etc/os-release && sed -n 's/^VERSION_ID="*\([0-9]*\).*/\1/p' /etc/os-release)" if test "$x" -gt 0 ; then P_FEDORA=0 P_RHEL="$x" @@ -262,11 +263,7 @@ if [ -z "$P_LOGGING_BACKEND_DEFAULT" ] ; then fi if [ -z "$P_DHCP_DEFAULT" ] ; then - if [ "$P_FEDORA" -ge 31 -o "$P_RHEL" -ge 8 ] ; then - P_DHCP_DEFAULT=internal - else - P_DHCP_DEFAULT=dhclient - fi + P_DHCP_DEFAULT=internal fi if [ -z "$P_FIREWALLD_ZONE" ] ; then @@ -293,6 +290,14 @@ if [ -z "$P_MODEM_MANAGER_1" ] ; then fi fi +if [ -z "$TEAM" ] && [ "${P_RHEL-0}" -ge 10 ] ; then + P_TEAM=0 +fi + +if [ -z "$IFCFG_RH" ] && [ -n "$P_RHEL" ] && [ "$P_RHEL" -le 9 ] ; then + P_IFCFG_RH=1 +fi + if bool "$P_DEBUG" ; then P_CFLAGS="-g -Og -fexceptions${P_CFLAGS:+ }$P_CFLAGS" else @@ -368,7 +373,6 @@ meson setup\ -Dnft="${D_SBINDIR}/nft" \ -Diptables="${D_SBINDIR}/iptables" \ -Dip6tables="${D_SBINDIR}/ip6tables" \ - -Ddhclient="${D_SBINDIR}/dhclient" \ -Ddhcpcd=no \ -Dconfig_dhcp_default="$P_DHCP_DEFAULT" \ "-Dcrypto=$P_CRYPTO" \ @@ -378,7 +382,7 @@ meson setup\ -Db_lto="$(bool_true "$P_LTO")" \ -Dlibaudit=yes-disabled-by-default \ -Dmodem_manager="$(bool_true "$P_MODEM_MANAGER_1")" \ - $(args_enable "$P_WIFI" -Dwifi=true -Dwext="$(bool_true "$P_FEDORA")") \ + $(args_enable "$P_WIFI" -Dwifi=true -Dwext=false) \ $(args_enable "$(bool_not_true "$P_WIFI")" -Dwifi=false ) \ -Diwd="$(bool_true "$P_IWD")" \ -Dbluez5_dun="$(bool_true "$P_BLUETOOTH")" \ @@ -392,17 +396,17 @@ meson setup\ -Dselinux=true \ -Dpolkit=true \ -Dconfig_auth_polkit_default=true \ - -Dmodify_system=true \ -Dconcheck=true \ -Dlibpsl="$(bool_true "$P_FEDORA")" \ -Dsession_tracking=systemd \ -Dsuspend_resume=systemd \ -Dsystemdsystemunitdir=/usr/lib/systemd/system \ + -Dsystemdsystemgeneratordir=/usr/lib/systemd/system-generators \ -Dsystem_ca_path=/etc/pki/tls/cert.pem \ -Ddbus_conf_dir="$P_DBUS_SYS_DIR" \ -Dtests=yes \ -Dvalgrind=no \ - -Difcfg_rh=true \ + -Difcfg_rh="$(bool_true "$P_IFCFG_RH")" \ -Difupdown=false \ $(args_enable "$P_PPP" -Dppp=true -Dpppd="$D_SBINDIR/pppd" -Dpppd_plugin_dir="$D_LIBDIR/pppd/$P_PPP_VERSION") \ $(args_enable "$(bool_not_true "$P_PPP")" -Dppp=false ) \ diff --git a/contrib/scripts/nm-ci-run.sh b/contrib/scripts/nm-ci-run.sh index 57b867c5..49b31f6d 100755 --- a/contrib/scripts/nm-ci-run.sh +++ b/contrib/scripts/nm-ci-run.sh @@ -55,6 +55,7 @@ _WITH_LIBTEAM="true" _WITH_DOCS="true" _WITH_SYSTEMD_LOGIND="true" _WITH_NBFT="true" +_WITH_CLAT="true" if [ $IS_ALPINE = 1 ]; then _WITH_SYSTEMD_LOGIND="false" fi @@ -63,6 +64,14 @@ if ! pkgconf 'libnvme >= 1.5'; then _WITH_NBFT="false" fi +if ! pkgconf 'libndp >= 1.9'; then + _WITH_CLAT="false" +fi + +if ! pkgconf 'libbpf >= 1.3'; then + _WITH_CLAT="false" +fi + if [ -z "${NMTST_SEED_RAND+x}" ]; then NMTST_SEED_RAND="$SRANDOM" if [ -z "$NMTST_SEED_RAND" ]; then @@ -169,6 +178,7 @@ meson setup build \ -D ld_gc=false \ -D session_tracking=no \ -D systemdsystemunitdir=no \ + -D systemdsystemgeneratordir=no \ -D systemd_journal=false \ -D selinux=false \ -D libaudit=no \ @@ -184,7 +194,6 @@ meson setup build \ -D ofono=true \ -D teamdctl=$_WITH_LIBTEAM \ \ - -D dhclient=/bin/nowhere/dhclient \ -D dhcpcd=/bin/nowhere/dhcpd \ \ -D netconfig=/bin/nowhere/netconfig \ @@ -194,6 +203,7 @@ meson setup build \ -D ifupdown=true \ \ -D nbft=$_WITH_NBFT \ + -D clat=$_WITH_CLAT \ \ #end diff --git a/contrib/scripts/nm-copr-build.sh b/contrib/scripts/nm-copr-build.sh index 93dcc083..0fdfdf6c 100755 --- a/contrib/scripts/nm-copr-build.sh +++ b/contrib/scripts/nm-copr-build.sh @@ -74,9 +74,13 @@ get_nm_git_bundle() { fi mkdir nm-git-bundle pushd nm-git-bundle - time curl "$NM_GIT_BUNDLE" \ - | rpm2cpio - \ - | cpio -idmv + if ! time curl --fail -o nm-git-bundle.rpm "$NM_GIT_BUNDLE"; then + # The bundle is only a fetch speed-up; fall back to the git fetch below. + echo "nm-git-bundle unavailable at $NM_GIT_BUNDLE, falling back to upstream git fetch" >&2 + popd + return 0 + fi + rpm2cpio nm-git-bundle.rpm | cpio -idmv popd git remote add nm-git-bundle "$PWD/nm-git-bundle/usr/share/NetworkManager/nm-git-bundle.git" git fetch nm-git-bundle diff --git a/data/NetworkManager-config-initrd.service.in b/data/NetworkManager-config-initrd.service.in index 4baf0f64..4f038036 100644 --- a/data/NetworkManager-config-initrd.service.in +++ b/data/NetworkManager-config-initrd.service.in @@ -1,10 +1,10 @@ [Unit] Description=NetworkManager Configuration (initrd) +AssertPathExists=/etc/initrd-release DefaultDependencies=no Wants=systemd-journald.socket After=systemd-journald.socket Before=systemd-udevd.service systemd-udev-trigger.service -ConditionPathExists=/etc/initrd-release [Service] Type=oneshot @@ -22,6 +22,3 @@ ExecStartPost=/bin/sh -c ' \ fi \ ' RemainAfterExit=yes - -[Install] -WantedBy=initrd.target diff --git a/data/NetworkManager-initrd.service.in b/data/NetworkManager-initrd.service.in index aef73a57..f936ffd2 100644 --- a/data/NetworkManager-initrd.service.in +++ b/data/NetworkManager-initrd.service.in @@ -1,11 +1,11 @@ [Unit] Description=NetworkManager (initrd) +AssertPathExists=/etc/initrd-release DefaultDependencies=no Wants=systemd-udev-trigger.service network.target After=systemd-udev-trigger.service network-pre.target dbus.service NetworkManager-config-initrd.service Before=network.target BindsTo=dbus.service -ConditionPathExists=/etc/initrd-release ConditionPathExists=/run/NetworkManager/initrd/neednet ConditionPathExistsGlob=|/usr/lib/NetworkManager/system-connections/* ConditionPathExistsGlob=|/run/NetworkManager/system-connections/* @@ -22,11 +22,3 @@ Environment=NM_CONFIG_ENABLE_TAG=initrd Restart=on-failure ProtectSystem=true ProtectHome=read-only - -[Install] -WantedBy=initrd.target -# We want to enable NetworkManager-wait-online-initrd.service whenever this -# service is enabled. NetworkManager-wait-online-initrd.service has -# WantedBy=network-online.target, so enabling it only has an effect if -# network-online.target itself is enabled or pulled in by some other unit. -Also=NetworkManager-config-initrd.service NetworkManager-wait-online-initrd.service diff --git a/data/NetworkManager-wait-online-initrd.service.in b/data/NetworkManager-wait-online-initrd.service.in index da4a2522..b89aa816 100644 --- a/data/NetworkManager-wait-online-initrd.service.in +++ b/data/NetworkManager-wait-online-initrd.service.in @@ -1,10 +1,10 @@ [Unit] Description=NetworkManager Wait Online (initrd) +AssertPathExists=/etc/initrd-release DefaultDependencies=no Requires=NetworkManager-initrd.service After=NetworkManager-initrd.service Before=network-online.target -ConditionPathExists=/etc/initrd-release ConditionPathExists=/run/NetworkManager/initrd/neednet [Service] @@ -21,6 +21,3 @@ Type=oneshot ExecStart=@bindir@/nm-online -s -q RemainAfterExit=yes Environment=NM_ONLINE_TIMEOUT=3600 - -[Install] -WantedBy=initrd.target network-online.target diff --git a/data/NetworkManager.service.in b/data/NetworkManager.service.in index d0cd8b73..b27b8d2d 100644 --- a/data/NetworkManager.service.in +++ b/data/NetworkManager.service.in @@ -21,8 +21,16 @@ TimeoutStartSec=600 CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_BPF CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE CAP_AUDIT_WRITE CAP_KILL CAP_SYS_CHROOT -ProtectSystem=true +PrivateTmp=true + +ProtectClock=true +ProtectControlGroups=true ProtectHome=read-only +ProtectKernelLogs=true +ProtectSystem=true + +RestrictRealtime=true +RestrictSUIDSGID=true # We require file descriptors for DHCP etc. When activating many interfaces, # the default limit of 1024 is easily reached. diff --git a/data/meson.build b/data/meson.build index 34c98e3b..3e292cb2 100644 --- a/data/meson.build +++ b/data/meson.build @@ -55,16 +55,8 @@ if install_udevdir endif if enable_polkit - policy = 'org.freedesktop.NetworkManager.policy' - - policy_in = configure_file( - input: policy + '.in.in', - output: '@BASENAME@', - configuration: data_conf, - ) - i18n.merge_file( - input: policy_in, + input: 'org.freedesktop.NetworkManager.policy.in', output: '@BASENAME@', po_dir: po_dir, install: true, diff --git a/data/org.freedesktop.NetworkManager.policy.in b/data/org.freedesktop.NetworkManager.policy.in new file mode 100644 index 00000000..cb143a2d --- /dev/null +++ b/data/org.freedesktop.NetworkManager.policy.in @@ -0,0 +1,174 @@ + + + + + + NetworkManager + https://networkmanager.dev/ + nm-icon + + + Enable or disable system networking + System policy prevents enabling or disabling system networking + + no + yes + + + + + Reload NetworkManager configuration + System policy prevents reloading NetworkManager + + auth_admin_keep + auth_admin_keep + auth_admin_keep + + + + + Put NetworkManager to sleep or wake it up (should only be used by system power management) + System policy prevents putting NetworkManager to sleep or waking it up + + no + no + + + + + Enable or disable Wi-Fi devices + System policy prevents enabling or disabling Wi-Fi devices + + no + yes + + + + + Enable or disable mobile broadband devices + System policy prevents enabling or disabling mobile broadband devices + + no + yes + + + + + Enable or disable WiMAX mobile broadband devices + System policy prevents enabling or disabling WiMAX mobile broadband devices + + no + yes + + + + + Allow control of network connections + System policy prevents control of network connections + + auth_admin + yes + yes + + + + + Allow control of Wi-Fi scans + System policy prevents Wi-Fi scans + + auth_admin + yes + yes + + + + + Connection sharing via a protected Wi-Fi network + System policy prevents sharing connections via a protected Wi-Fi network + + no + yes + + + + + Connection sharing via an open Wi-Fi network + System policy prevents sharing connections via an open Wi-Fi network + + no + yes + + + + + Modify personal network connections + System policy prevents modification of personal network settings + + auth_self_keep + yes + yes + + + + + Modify network connections for all users + System policy prevents modification of network settings for all users + + auth_admin_keep + auth_admin_keep + auth_admin_keep + + + + + Modify persistent system hostname + System policy prevents modification of the persistent system hostname + + auth_admin_keep + auth_admin_keep + auth_admin_keep + + + + + Modify persistent global DNS configuration + System policy prevents modification of the persistent global DNS configuration + + auth_admin_keep + auth_admin_keep + auth_admin_keep + + + + + Perform a checkpoint or rollback of interfaces configuration + System policy prevents the creation of a checkpoint or its rollback + + auth_admin_keep + auth_admin_keep + auth_admin_keep + + + + + Enable or disable device statistics + System policy prevents enabling or disabling device statistics + + no + yes + + + + + Enable or disable connectivity checking + System policy prevents enabling or disabling connectivity checking + + no + yes + + + + + diff --git a/data/org.freedesktop.NetworkManager.policy.in.in b/data/org.freedesktop.NetworkManager.policy.in.in deleted file mode 100644 index 13a0a5b5..00000000 --- a/data/org.freedesktop.NetworkManager.policy.in.in +++ /dev/null @@ -1,174 +0,0 @@ - - - - - - NetworkManager - https://networkmanager.dev/ - nm-icon - - - Enable or disable system networking - System policy prevents enabling or disabling system networking - - no - yes - - - - - Reload NetworkManager configuration - System policy prevents reloading NetworkManager - - auth_admin_keep - auth_admin_keep - auth_admin_keep - - - - - Put NetworkManager to sleep or wake it up (should only be used by system power management) - System policy prevents putting NetworkManager to sleep or waking it up - - no - no - - - - - Enable or disable Wi-Fi devices - System policy prevents enabling or disabling Wi-Fi devices - - no - yes - - - - - Enable or disable mobile broadband devices - System policy prevents enabling or disabling mobile broadband devices - - no - yes - - - - - Enable or disable WiMAX mobile broadband devices - System policy prevents enabling or disabling WiMAX mobile broadband devices - - no - yes - - - - - Allow control of network connections - System policy prevents control of network connections - - auth_admin - yes - yes - - - - - Allow control of Wi-Fi scans - System policy prevents Wi-Fi scans - - auth_admin - yes - yes - - - - - Connection sharing via a protected Wi-Fi network - System policy prevents sharing connections via a protected Wi-Fi network - - no - yes - - - - - Connection sharing via an open Wi-Fi network - System policy prevents sharing connections via an open Wi-Fi network - - no - yes - - - - - Modify personal network connections - System policy prevents modification of personal network settings - - auth_self_keep - yes - yes - - - - - Modify network connections for all users - System policy prevents modification of network settings for all users - - auth_admin_keep - @NM_MODIFY_SYSTEM_POLICY@ - @NM_MODIFY_SYSTEM_POLICY@ - - - - - Modify persistent system hostname - System policy prevents modification of the persistent system hostname - - auth_admin_keep - auth_admin_keep - auth_admin_keep - - - - - Modify persistent global DNS configuration - System policy prevents modification of the persistent global DNS configuration - - auth_admin_keep - auth_admin_keep - auth_admin_keep - - - - - Perform a checkpoint or rollback of interfaces configuration - System policy prevents the creation of a checkpoint or its rollback - - auth_admin_keep - auth_admin_keep - auth_admin_keep - - - - - Enable or disable device statistics - System policy prevents enabling or disabling device statistics - - no - yes - - - - - Enable or disable connectivity checking - System policy prevents enabling or disabling connectivity checking - - no - yes - - - - - diff --git a/docs/libnm/libnm.svg b/docs/libnm/libnm.svg index 6bbfa295..769984c9 100644 --- a/docs/libnm/libnm.svg +++ b/docs/libnm/libnm.svg @@ -202,7 +202,7 @@ sodipodi:role="line" x="19.192902" y="360.40768" - id="tspan3839">Retrieves, adds, and notifes of changesRetrieves, adds, and notifies of changes @@ -17,7 +17,7 @@ diff --git a/introspection/org.freedesktop.NetworkManager.Device.xml b/introspection/org.freedesktop.NetworkManager.Device.xml index d770cfe6..3b0c2c46 100644 --- a/introspection/org.freedesktop.NetworkManager.Device.xml +++ b/introspection/org.freedesktop.NetworkManager.Device.xml @@ -176,7 +176,7 @@ the keyfile.unmanaged-devices setting in NetworkManager.conf. Changes to this value are not persistent and lost after NetworkManager restart. - DEPRECATED: 1.56.1: Use the SetManaged method instead, which supports + DEPRECATED: 1.58: Use the SetManaged method instead, which supports additional features like persisting the state to disk --> @@ -398,7 +398,7 @@ SetManaged: @managed:(NMDeviceManaged) Whether the device is managed. Possible values are "no" (0), "yes" (1) and "reset" (2). @flags: (NMDeviceManagedFlags) flags. - @since: 1.56.1 + @since: 1.58 Set the managed state of the device. With the flags argument different behaviors can be achieved, like storing the new managed state to disk. diff --git a/introspection/org.freedesktop.NetworkManager.Settings.Connection.xml b/introspection/org.freedesktop.NetworkManager.Settings.Connection.xml index 9b876e75..d5717d5d 100644 --- a/introspection/org.freedesktop.NetworkManager.Settings.Connection.xml +++ b/introspection/org.freedesktop.NetworkManager.Settings.Connection.xml @@ -62,7 +62,7 @@