Add git, neofetch, replace iptables with nftables, setup /etc/sysctl.conf

This commit is contained in:
markmental 2026-09-11 00:34:18 -04:00
commit 8202f22735
5 changed files with 133 additions and 18 deletions

44
.config
View file

@ -1,6 +1,6 @@
#
# Automatically generated file; DO NOT EDIT.
# Buildroot -g1d86d4f-dirty Configuration
# Buildroot -ga43e95b-dirty Configuration
#
BR2_HAVE_DOT_CONFIG=y
BR2_HOST_GCC_AT_LEAST_4_9=y
@ -873,7 +873,7 @@ BR2_PACKAGE_CMAKE_ARCH_SUPPORTS=y
# BR2_PACKAGE_GAWK is not set
# BR2_PACKAGE_GETTEXT is not set
BR2_PACKAGE_PROVIDES_HOST_GETTEXT="host-gettext-tiny"
# BR2_PACKAGE_GIT is not set
BR2_PACKAGE_GIT=y
#
# git-crypt needs a toolchain w/ C++, gcc >= 4.9
@ -884,7 +884,7 @@ BR2_PACKAGE_PROVIDES_HOST_GETTEXT="host-gettext-tiny"
#
# BR2_PACKAGE_GREP is not set
# BR2_PACKAGE_JO is not set
# BR2_PACKAGE_JQ is not set
BR2_PACKAGE_JQ=y
# BR2_PACKAGE_LIBTOOL is not set
BR2_PACKAGE_MAKE=y
# BR2_PACKAGE_MAWK is not set
@ -3143,7 +3143,15 @@ BR2_PACKAGE_LIBOPENH264_ARCH_SUPPORTS=y
#
# libcpprestsdk needs a toolchain w/ NPTL, C++, wchar, locale
#
# BR2_PACKAGE_LIBCURL is not set
BR2_PACKAGE_LIBCURL=y
# BR2_PACKAGE_LIBCURL_CURL is not set
# BR2_PACKAGE_LIBCURL_VERBOSE is not set
BR2_PACKAGE_LIBCURL_PROXY_SUPPORT=y
BR2_PACKAGE_LIBCURL_COOKIES_SUPPORT=y
# BR2_PACKAGE_LIBCURL_WEBSOCKETS_SUPPORT is not set
BR2_PACKAGE_LIBCURL_EXTRA_PROTOCOLS_FEATURES=y
BR2_PACKAGE_LIBCURL_OPENSSL=y
# BR2_PACKAGE_LIBCURL_TLS_NONE is not set
# BR2_PACKAGE_LIBDNET is not set
# BR2_PACKAGE_LIBEXOSIP2 is not set
# BR2_PACKAGE_LIBEST is not set
@ -3168,7 +3176,8 @@ BR2_PACKAGE_LIBOPENH264_ARCH_SUPPORTS=y
#
# BR2_PACKAGE_LIBMICROHTTPD is not set
# BR2_PACKAGE_LIBMINIUPNPC is not set
# BR2_PACKAGE_LIBMNL is not set
BR2_PACKAGE_LIBMNL=y
# BR2_PACKAGE_LIBMNL_EXAMPLES is not set
# BR2_PACKAGE_LIBMODBUS is not set
#
@ -3185,7 +3194,7 @@ BR2_PACKAGE_LIBOPENH264_ARCH_SUPPORTS=y
# BR2_PACKAGE_LIBNETFILTER_LOG is not set
# BR2_PACKAGE_LIBNETFILTER_QUEUE is not set
# BR2_PACKAGE_LIBNFNETLINK is not set
# BR2_PACKAGE_LIBNFTNL is not set
BR2_PACKAGE_LIBNFTNL=y
# BR2_PACKAGE_LIBNICE is not set
# BR2_PACKAGE_LIBNIDS is not set
# BR2_PACKAGE_LIBNL is not set
@ -4035,9 +4044,7 @@ BR2_PACKAGE_IFUPDOWN_SCRIPTS=y
# BR2_PACKAGE_IPERF3 is not set
# BR2_PACKAGE_IPROUTE2 is not set
# BR2_PACKAGE_IPSET is not set
BR2_PACKAGE_IPTABLES=y
# BR2_PACKAGE_IPTABLES_BPF_NFSYNPROXY is not set
# BR2_PACKAGE_IPTABLES_NFTABLES is not set
# BR2_PACKAGE_IPTABLES is not set
# BR2_PACKAGE_IPTRAF_NG is not set
# BR2_PACKAGE_IPUTILS is not set
# BR2_PACKAGE_IRSSI is not set
@ -4108,10 +4115,10 @@ BR2_PACKAGE_LYNX=y
# BR2_PACKAGE_NBD is not set
# BR2_PACKAGE_NCFTP is not set
# BR2_PACKAGE_NDISC6 is not set
# BR2_PACKAGE_NET_TOOLS is not set
BR2_PACKAGE_NET_TOOLS=y
# BR2_PACKAGE_NETATALK is not set
# BR2_PACKAGE_NETCALC is not set
# BR2_PACKAGE_NETCAT is not set
BR2_PACKAGE_NETCAT=y
# BR2_PACKAGE_NETCAT_OPENBSD is not set
#
@ -4124,7 +4131,8 @@ BR2_PACKAGE_LYNX=y
# NetworkManager needs udev /dev management and a glibc or musl toolchain w/ headers >= 4.20, dynamic library, wchar, threads, gcc >= 4.9
#
# BR2_PACKAGE_NFACCT is not set
# BR2_PACKAGE_NFTABLES is not set
BR2_PACKAGE_NFTABLES=y
BR2_PACKAGE_NFTABLES_PYTHON=y
# BR2_PACKAGE_NGINX is not set
# BR2_PACKAGE_NGIRCD is not set
# BR2_PACKAGE_NGREP is not set
@ -4237,7 +4245,7 @@ BR2_PACKAGE_LYNX=y
# BR2_PACKAGE_TINYSSH is not set
# BR2_PACKAGE_TIPIDEE is not set
# BR2_PACKAGE_TOR is not set
# BR2_PACKAGE_TRACEROUTE is not set
BR2_PACKAGE_TRACEROUTE=y
#
# transmission needs a toolchain w/ dynamic library, threads, C++, gcc >= 7
@ -4392,11 +4400,11 @@ BR2_PACKAGE_BASH=y
# BR2_PACKAGE_CATATONIT is not set
# BR2_PACKAGE_CCRYPT is not set
# BR2_PACKAGE_CRUDINI is not set
# BR2_PACKAGE_DIALOG is not set
BR2_PACKAGE_DIALOG=y
# BR2_PACKAGE_DTACH is not set
# BR2_PACKAGE_EASY_RSA is not set
# BR2_PACKAGE_EZA is not set
# BR2_PACKAGE_FILE is not set
BR2_PACKAGE_FILE=y
# BR2_PACKAGE_GNUPG is not set
BR2_PACKAGE_GNUPG2_DEPENDS=y
# BR2_PACKAGE_GNUPG2 is not set
@ -4405,7 +4413,7 @@ BR2_PACKAGE_GNUPG2_DEPENDS=y
# BR2_PACKAGE_LOGROTATE is not set
# BR2_PACKAGE_LOGSURFER is not set
# BR2_PACKAGE_MINISIGN is not set
# BR2_PACKAGE_NEOFETCH is not set
BR2_PACKAGE_NEOFETCH=y
# BR2_PACKAGE_PDMENU is not set
# BR2_PACKAGE_PINENTRY is not set
# BR2_PACKAGE_QPRINT is not set
@ -4415,7 +4423,7 @@ BR2_PACKAGE_GNUPG2_DEPENDS=y
# BR2_PACKAGE_SCREEN is not set
# BR2_PACKAGE_SCREENFETCH is not set
# BR2_PACKAGE_SEXPECT is not set
# BR2_PACKAGE_SUDO is not set
BR2_PACKAGE_SUDO=y
# BR2_PACKAGE_TIME is not set
# BR2_PACKAGE_TINI is not set
# BR2_PACKAGE_TMUX is not set
@ -4474,7 +4482,7 @@ BR2_PACKAGE_EFIVAR_ARCH_SUPPORTS=y
# BR2_PACKAGE_FTOP is not set
# BR2_PACKAGE_GETENT is not set
# BR2_PACKAGE_GKRELLM is not set
# BR2_PACKAGE_HTOP is not set
BR2_PACKAGE_HTOP=y
# BR2_PACKAGE_IBM_SW_TPM2 is not set
BR2_PACKAGE_INITSCRIPTS=y
# BR2_PACKAGE_IOTOP is not set

View file

@ -141,3 +141,14 @@ CONFIG_VGA_CONSOLE=y
# CONFIG_NET_VENDOR_WIZNET is not set
# CONFIG_NET_VENDOR_XILINX is not set
# CONFIG_NET_VENDOR_XIRCOM is not set
# --- nftables firewall (kernel side) ---
CONFIG_NF_TABLES=y
CONFIG_NF_TABLES_INET=y
CONFIG_NFT_CT=y
CONFIG_NFT_LIMIT=y
CONFIG_NFT_LOG=y
CONFIG_NFT_NAT=y
CONFIG_NFT_MASQ=y
CONFIG_NFT_REJECT=y
CONFIG_NFT_REJECT_INET=y

View file

@ -0,0 +1,49 @@
#!/bin/sh
#
# Load the nftables firewall ruleset from /etc/nftables.conf.
DAEMON="nft"
CONF="/etc/nftables.conf"
start() {
printf 'Loading nftables firewall: '
if ! [ -f "$CONF" ]; then
echo "MISSING $CONF"
return 1
fi
"$DAEMON" -f "$CONF"
status=$?
if [ "$status" -eq 0 ]; then
echo "OK"
else
echo "FAIL"
fi
return "$status"
}
stop() {
printf 'Flushing nftables ruleset: '
"$DAEMON" flush ruleset
status=$?
if [ "$status" -eq 0 ]; then
echo "OK"
else
echo "FAIL"
fi
return "$status"
}
restart() {
stop
start
}
case "$1" in
start|stop|restart)
"$1";;
reload)
restart;;
*)
echo "Usage: $0 {start|stop|restart|reload}"
exit 1
esac

View file

@ -0,0 +1,41 @@
# /etc/nftables.conf - Mentalnet GNU/Linux firewall
# Loaded by /etc/init.d/S35nftables at boot. Edit and re-run:
# nft -f /etc/nftables.conf
flush ruleset
table inet filter {
chain input {
type filter hook input priority 0; policy drop;
# loopback
iifname "lo" accept
# established and related connections
ct state established,related accept
# DHCP client replies
udp sport 67 udp dport 68 accept
# ICMP (ping et al.)
ip protocol icmp accept
ip6 nexthdr icmpv6 accept
# services: SSH, HTTP
tcp dport 22 accept
tcp dport 80 accept
# log and reject everything else (rate-limited: goes to
# syslog, not the TTY - see /etc/sysctl.conf)
limit rate 1/minute log prefix "nft-drop: " counter
counter reject with icmpx type port-unreachable
}
chain forward {
type filter hook forward priority 0; policy accept;
}
chain output {
type filter hook output priority 0; policy accept;
}
}

View file

@ -0,0 +1,6 @@
# /etc/sysctl.conf - Mentalnet GNU/Linux runtime kernel settings
# Applied by /etc/init.d/S02sysctl at boot.
# Keep the TTY quiet: console shows errors and worse only.
# Kernel warnings (e.g. nft-drop lines) still reach syslog via klogd.
kernel.printk = 3 4 1 3