Add git, neofetch, replace iptables with nftables, setup /etc/sysctl.conf
This commit is contained in:
parent
a43e95b17f
commit
8202f22735
5 changed files with 133 additions and 18 deletions
44
.config
44
.config
|
|
@ -1,6 +1,6 @@
|
|||
#
|
||||
# Automatically generated file; DO NOT EDIT.
|
||||
# Buildroot -g1d86d4f-dirty Configuration
|
||||
# Buildroot -ga43e95b-dirty Configuration
|
||||
#
|
||||
BR2_HAVE_DOT_CONFIG=y
|
||||
BR2_HOST_GCC_AT_LEAST_4_9=y
|
||||
|
|
@ -873,7 +873,7 @@ BR2_PACKAGE_CMAKE_ARCH_SUPPORTS=y
|
|||
# BR2_PACKAGE_GAWK is not set
|
||||
# BR2_PACKAGE_GETTEXT is not set
|
||||
BR2_PACKAGE_PROVIDES_HOST_GETTEXT="host-gettext-tiny"
|
||||
# BR2_PACKAGE_GIT is not set
|
||||
BR2_PACKAGE_GIT=y
|
||||
|
||||
#
|
||||
# git-crypt needs a toolchain w/ C++, gcc >= 4.9
|
||||
|
|
@ -884,7 +884,7 @@ BR2_PACKAGE_PROVIDES_HOST_GETTEXT="host-gettext-tiny"
|
|||
#
|
||||
# BR2_PACKAGE_GREP is not set
|
||||
# BR2_PACKAGE_JO is not set
|
||||
# BR2_PACKAGE_JQ is not set
|
||||
BR2_PACKAGE_JQ=y
|
||||
# BR2_PACKAGE_LIBTOOL is not set
|
||||
BR2_PACKAGE_MAKE=y
|
||||
# BR2_PACKAGE_MAWK is not set
|
||||
|
|
@ -3143,7 +3143,15 @@ BR2_PACKAGE_LIBOPENH264_ARCH_SUPPORTS=y
|
|||
#
|
||||
# libcpprestsdk needs a toolchain w/ NPTL, C++, wchar, locale
|
||||
#
|
||||
# BR2_PACKAGE_LIBCURL is not set
|
||||
BR2_PACKAGE_LIBCURL=y
|
||||
# BR2_PACKAGE_LIBCURL_CURL is not set
|
||||
# BR2_PACKAGE_LIBCURL_VERBOSE is not set
|
||||
BR2_PACKAGE_LIBCURL_PROXY_SUPPORT=y
|
||||
BR2_PACKAGE_LIBCURL_COOKIES_SUPPORT=y
|
||||
# BR2_PACKAGE_LIBCURL_WEBSOCKETS_SUPPORT is not set
|
||||
BR2_PACKAGE_LIBCURL_EXTRA_PROTOCOLS_FEATURES=y
|
||||
BR2_PACKAGE_LIBCURL_OPENSSL=y
|
||||
# BR2_PACKAGE_LIBCURL_TLS_NONE is not set
|
||||
# BR2_PACKAGE_LIBDNET is not set
|
||||
# BR2_PACKAGE_LIBEXOSIP2 is not set
|
||||
# BR2_PACKAGE_LIBEST is not set
|
||||
|
|
@ -3168,7 +3176,8 @@ BR2_PACKAGE_LIBOPENH264_ARCH_SUPPORTS=y
|
|||
#
|
||||
# BR2_PACKAGE_LIBMICROHTTPD is not set
|
||||
# BR2_PACKAGE_LIBMINIUPNPC is not set
|
||||
# BR2_PACKAGE_LIBMNL is not set
|
||||
BR2_PACKAGE_LIBMNL=y
|
||||
# BR2_PACKAGE_LIBMNL_EXAMPLES is not set
|
||||
# BR2_PACKAGE_LIBMODBUS is not set
|
||||
|
||||
#
|
||||
|
|
@ -3185,7 +3194,7 @@ BR2_PACKAGE_LIBOPENH264_ARCH_SUPPORTS=y
|
|||
# BR2_PACKAGE_LIBNETFILTER_LOG is not set
|
||||
# BR2_PACKAGE_LIBNETFILTER_QUEUE is not set
|
||||
# BR2_PACKAGE_LIBNFNETLINK is not set
|
||||
# BR2_PACKAGE_LIBNFTNL is not set
|
||||
BR2_PACKAGE_LIBNFTNL=y
|
||||
# BR2_PACKAGE_LIBNICE is not set
|
||||
# BR2_PACKAGE_LIBNIDS is not set
|
||||
# BR2_PACKAGE_LIBNL is not set
|
||||
|
|
@ -4035,9 +4044,7 @@ BR2_PACKAGE_IFUPDOWN_SCRIPTS=y
|
|||
# BR2_PACKAGE_IPERF3 is not set
|
||||
# BR2_PACKAGE_IPROUTE2 is not set
|
||||
# BR2_PACKAGE_IPSET is not set
|
||||
BR2_PACKAGE_IPTABLES=y
|
||||
# BR2_PACKAGE_IPTABLES_BPF_NFSYNPROXY is not set
|
||||
# BR2_PACKAGE_IPTABLES_NFTABLES is not set
|
||||
# BR2_PACKAGE_IPTABLES is not set
|
||||
# BR2_PACKAGE_IPTRAF_NG is not set
|
||||
# BR2_PACKAGE_IPUTILS is not set
|
||||
# BR2_PACKAGE_IRSSI is not set
|
||||
|
|
@ -4108,10 +4115,10 @@ BR2_PACKAGE_LYNX=y
|
|||
# BR2_PACKAGE_NBD is not set
|
||||
# BR2_PACKAGE_NCFTP is not set
|
||||
# BR2_PACKAGE_NDISC6 is not set
|
||||
# BR2_PACKAGE_NET_TOOLS is not set
|
||||
BR2_PACKAGE_NET_TOOLS=y
|
||||
# BR2_PACKAGE_NETATALK is not set
|
||||
# BR2_PACKAGE_NETCALC is not set
|
||||
# BR2_PACKAGE_NETCAT is not set
|
||||
BR2_PACKAGE_NETCAT=y
|
||||
# BR2_PACKAGE_NETCAT_OPENBSD is not set
|
||||
|
||||
#
|
||||
|
|
@ -4124,7 +4131,8 @@ BR2_PACKAGE_LYNX=y
|
|||
# NetworkManager needs udev /dev management and a glibc or musl toolchain w/ headers >= 4.20, dynamic library, wchar, threads, gcc >= 4.9
|
||||
#
|
||||
# BR2_PACKAGE_NFACCT is not set
|
||||
# BR2_PACKAGE_NFTABLES is not set
|
||||
BR2_PACKAGE_NFTABLES=y
|
||||
BR2_PACKAGE_NFTABLES_PYTHON=y
|
||||
# BR2_PACKAGE_NGINX is not set
|
||||
# BR2_PACKAGE_NGIRCD is not set
|
||||
# BR2_PACKAGE_NGREP is not set
|
||||
|
|
@ -4237,7 +4245,7 @@ BR2_PACKAGE_LYNX=y
|
|||
# BR2_PACKAGE_TINYSSH is not set
|
||||
# BR2_PACKAGE_TIPIDEE is not set
|
||||
# BR2_PACKAGE_TOR is not set
|
||||
# BR2_PACKAGE_TRACEROUTE is not set
|
||||
BR2_PACKAGE_TRACEROUTE=y
|
||||
|
||||
#
|
||||
# transmission needs a toolchain w/ dynamic library, threads, C++, gcc >= 7
|
||||
|
|
@ -4392,11 +4400,11 @@ BR2_PACKAGE_BASH=y
|
|||
# BR2_PACKAGE_CATATONIT is not set
|
||||
# BR2_PACKAGE_CCRYPT is not set
|
||||
# BR2_PACKAGE_CRUDINI is not set
|
||||
# BR2_PACKAGE_DIALOG is not set
|
||||
BR2_PACKAGE_DIALOG=y
|
||||
# BR2_PACKAGE_DTACH is not set
|
||||
# BR2_PACKAGE_EASY_RSA is not set
|
||||
# BR2_PACKAGE_EZA is not set
|
||||
# BR2_PACKAGE_FILE is not set
|
||||
BR2_PACKAGE_FILE=y
|
||||
# BR2_PACKAGE_GNUPG is not set
|
||||
BR2_PACKAGE_GNUPG2_DEPENDS=y
|
||||
# BR2_PACKAGE_GNUPG2 is not set
|
||||
|
|
@ -4405,7 +4413,7 @@ BR2_PACKAGE_GNUPG2_DEPENDS=y
|
|||
# BR2_PACKAGE_LOGROTATE is not set
|
||||
# BR2_PACKAGE_LOGSURFER is not set
|
||||
# BR2_PACKAGE_MINISIGN is not set
|
||||
# BR2_PACKAGE_NEOFETCH is not set
|
||||
BR2_PACKAGE_NEOFETCH=y
|
||||
# BR2_PACKAGE_PDMENU is not set
|
||||
# BR2_PACKAGE_PINENTRY is not set
|
||||
# BR2_PACKAGE_QPRINT is not set
|
||||
|
|
@ -4415,7 +4423,7 @@ BR2_PACKAGE_GNUPG2_DEPENDS=y
|
|||
# BR2_PACKAGE_SCREEN is not set
|
||||
# BR2_PACKAGE_SCREENFETCH is not set
|
||||
# BR2_PACKAGE_SEXPECT is not set
|
||||
# BR2_PACKAGE_SUDO is not set
|
||||
BR2_PACKAGE_SUDO=y
|
||||
# BR2_PACKAGE_TIME is not set
|
||||
# BR2_PACKAGE_TINI is not set
|
||||
# BR2_PACKAGE_TMUX is not set
|
||||
|
|
@ -4474,7 +4482,7 @@ BR2_PACKAGE_EFIVAR_ARCH_SUPPORTS=y
|
|||
# BR2_PACKAGE_FTOP is not set
|
||||
# BR2_PACKAGE_GETENT is not set
|
||||
# BR2_PACKAGE_GKRELLM is not set
|
||||
# BR2_PACKAGE_HTOP is not set
|
||||
BR2_PACKAGE_HTOP=y
|
||||
# BR2_PACKAGE_IBM_SW_TPM2 is not set
|
||||
BR2_PACKAGE_INITSCRIPTS=y
|
||||
# BR2_PACKAGE_IOTOP is not set
|
||||
|
|
|
|||
|
|
@ -141,3 +141,14 @@ CONFIG_VGA_CONSOLE=y
|
|||
# CONFIG_NET_VENDOR_WIZNET is not set
|
||||
# CONFIG_NET_VENDOR_XILINX is not set
|
||||
# CONFIG_NET_VENDOR_XIRCOM is not set
|
||||
|
||||
# --- nftables firewall (kernel side) ---
|
||||
CONFIG_NF_TABLES=y
|
||||
CONFIG_NF_TABLES_INET=y
|
||||
CONFIG_NFT_CT=y
|
||||
CONFIG_NFT_LIMIT=y
|
||||
CONFIG_NFT_LOG=y
|
||||
CONFIG_NFT_NAT=y
|
||||
CONFIG_NFT_MASQ=y
|
||||
CONFIG_NFT_REJECT=y
|
||||
CONFIG_NFT_REJECT_INET=y
|
||||
|
|
|
|||
49
board/mentalnet/overlay/etc/init.d/S35nftables
Executable file
49
board/mentalnet/overlay/etc/init.d/S35nftables
Executable file
|
|
@ -0,0 +1,49 @@
|
|||
#!/bin/sh
|
||||
#
|
||||
# Load the nftables firewall ruleset from /etc/nftables.conf.
|
||||
|
||||
DAEMON="nft"
|
||||
CONF="/etc/nftables.conf"
|
||||
|
||||
start() {
|
||||
printf 'Loading nftables firewall: '
|
||||
if ! [ -f "$CONF" ]; then
|
||||
echo "MISSING $CONF"
|
||||
return 1
|
||||
fi
|
||||
"$DAEMON" -f "$CONF"
|
||||
status=$?
|
||||
if [ "$status" -eq 0 ]; then
|
||||
echo "OK"
|
||||
else
|
||||
echo "FAIL"
|
||||
fi
|
||||
return "$status"
|
||||
}
|
||||
|
||||
stop() {
|
||||
printf 'Flushing nftables ruleset: '
|
||||
"$DAEMON" flush ruleset
|
||||
status=$?
|
||||
if [ "$status" -eq 0 ]; then
|
||||
echo "OK"
|
||||
else
|
||||
echo "FAIL"
|
||||
fi
|
||||
return "$status"
|
||||
}
|
||||
|
||||
restart() {
|
||||
stop
|
||||
start
|
||||
}
|
||||
|
||||
case "$1" in
|
||||
start|stop|restart)
|
||||
"$1";;
|
||||
reload)
|
||||
restart;;
|
||||
*)
|
||||
echo "Usage: $0 {start|stop|restart|reload}"
|
||||
exit 1
|
||||
esac
|
||||
41
board/mentalnet/overlay/etc/nftables.conf
Normal file
41
board/mentalnet/overlay/etc/nftables.conf
Normal file
|
|
@ -0,0 +1,41 @@
|
|||
# /etc/nftables.conf - Mentalnet GNU/Linux firewall
|
||||
# Loaded by /etc/init.d/S35nftables at boot. Edit and re-run:
|
||||
# nft -f /etc/nftables.conf
|
||||
|
||||
flush ruleset
|
||||
|
||||
table inet filter {
|
||||
chain input {
|
||||
type filter hook input priority 0; policy drop;
|
||||
|
||||
# loopback
|
||||
iifname "lo" accept
|
||||
|
||||
# established and related connections
|
||||
ct state established,related accept
|
||||
|
||||
# DHCP client replies
|
||||
udp sport 67 udp dport 68 accept
|
||||
|
||||
# ICMP (ping et al.)
|
||||
ip protocol icmp accept
|
||||
ip6 nexthdr icmpv6 accept
|
||||
|
||||
# services: SSH, HTTP
|
||||
tcp dport 22 accept
|
||||
tcp dport 80 accept
|
||||
|
||||
# log and reject everything else (rate-limited: goes to
|
||||
# syslog, not the TTY - see /etc/sysctl.conf)
|
||||
limit rate 1/minute log prefix "nft-drop: " counter
|
||||
counter reject with icmpx type port-unreachable
|
||||
}
|
||||
|
||||
chain forward {
|
||||
type filter hook forward priority 0; policy accept;
|
||||
}
|
||||
|
||||
chain output {
|
||||
type filter hook output priority 0; policy accept;
|
||||
}
|
||||
}
|
||||
6
board/mentalnet/overlay/etc/sysctl.conf
Normal file
6
board/mentalnet/overlay/etc/sysctl.conf
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
# /etc/sysctl.conf - Mentalnet GNU/Linux runtime kernel settings
|
||||
# Applied by /etc/init.d/S02sysctl at boot.
|
||||
|
||||
# Keep the TTY quiet: console shows errors and worse only.
|
||||
# Kernel warnings (e.g. nft-drop lines) still reach syslog via klogd.
|
||||
kernel.printk = 3 4 1 3
|
||||
Loading…
Add table
Add a link
Reference in a new issue