From 8202f2273537983884d4b50af64eb0f37f9b26ed Mon Sep 17 00:00:00 2001 From: markmental Date: Fri, 11 Sep 2026 00:34:18 -0400 Subject: [PATCH] Add git, neofetch, replace iptables with nftables, setup /etc/sysctl.conf --- .config | 44 ++++++++++------- board/mentalnet/linux-slim.config | 11 +++++ .../mentalnet/overlay/etc/init.d/S35nftables | 49 +++++++++++++++++++ board/mentalnet/overlay/etc/nftables.conf | 41 ++++++++++++++++ board/mentalnet/overlay/etc/sysctl.conf | 6 +++ 5 files changed, 133 insertions(+), 18 deletions(-) create mode 100755 board/mentalnet/overlay/etc/init.d/S35nftables create mode 100644 board/mentalnet/overlay/etc/nftables.conf create mode 100644 board/mentalnet/overlay/etc/sysctl.conf diff --git a/.config b/.config index 4292289..9768a40 100644 --- a/.config +++ b/.config @@ -1,6 +1,6 @@ # # Automatically generated file; DO NOT EDIT. -# Buildroot -g1d86d4f-dirty Configuration +# Buildroot -ga43e95b-dirty Configuration # BR2_HAVE_DOT_CONFIG=y BR2_HOST_GCC_AT_LEAST_4_9=y @@ -873,7 +873,7 @@ BR2_PACKAGE_CMAKE_ARCH_SUPPORTS=y # BR2_PACKAGE_GAWK is not set # BR2_PACKAGE_GETTEXT is not set BR2_PACKAGE_PROVIDES_HOST_GETTEXT="host-gettext-tiny" -# BR2_PACKAGE_GIT is not set +BR2_PACKAGE_GIT=y # # git-crypt needs a toolchain w/ C++, gcc >= 4.9 @@ -884,7 +884,7 @@ BR2_PACKAGE_PROVIDES_HOST_GETTEXT="host-gettext-tiny" # # BR2_PACKAGE_GREP is not set # BR2_PACKAGE_JO is not set -# BR2_PACKAGE_JQ is not set +BR2_PACKAGE_JQ=y # BR2_PACKAGE_LIBTOOL is not set BR2_PACKAGE_MAKE=y # BR2_PACKAGE_MAWK is not set @@ -3143,7 +3143,15 @@ BR2_PACKAGE_LIBOPENH264_ARCH_SUPPORTS=y # # libcpprestsdk needs a toolchain w/ NPTL, C++, wchar, locale # -# BR2_PACKAGE_LIBCURL is not set +BR2_PACKAGE_LIBCURL=y +# BR2_PACKAGE_LIBCURL_CURL is not set +# BR2_PACKAGE_LIBCURL_VERBOSE is not set +BR2_PACKAGE_LIBCURL_PROXY_SUPPORT=y +BR2_PACKAGE_LIBCURL_COOKIES_SUPPORT=y +# BR2_PACKAGE_LIBCURL_WEBSOCKETS_SUPPORT is not set +BR2_PACKAGE_LIBCURL_EXTRA_PROTOCOLS_FEATURES=y +BR2_PACKAGE_LIBCURL_OPENSSL=y +# BR2_PACKAGE_LIBCURL_TLS_NONE is not set # BR2_PACKAGE_LIBDNET is not set # BR2_PACKAGE_LIBEXOSIP2 is not set # BR2_PACKAGE_LIBEST is not set @@ -3168,7 +3176,8 @@ BR2_PACKAGE_LIBOPENH264_ARCH_SUPPORTS=y # # BR2_PACKAGE_LIBMICROHTTPD is not set # BR2_PACKAGE_LIBMINIUPNPC is not set -# BR2_PACKAGE_LIBMNL is not set +BR2_PACKAGE_LIBMNL=y +# BR2_PACKAGE_LIBMNL_EXAMPLES is not set # BR2_PACKAGE_LIBMODBUS is not set # @@ -3185,7 +3194,7 @@ BR2_PACKAGE_LIBOPENH264_ARCH_SUPPORTS=y # BR2_PACKAGE_LIBNETFILTER_LOG is not set # BR2_PACKAGE_LIBNETFILTER_QUEUE is not set # BR2_PACKAGE_LIBNFNETLINK is not set -# BR2_PACKAGE_LIBNFTNL is not set +BR2_PACKAGE_LIBNFTNL=y # BR2_PACKAGE_LIBNICE is not set # BR2_PACKAGE_LIBNIDS is not set # BR2_PACKAGE_LIBNL is not set @@ -4035,9 +4044,7 @@ BR2_PACKAGE_IFUPDOWN_SCRIPTS=y # BR2_PACKAGE_IPERF3 is not set # BR2_PACKAGE_IPROUTE2 is not set # BR2_PACKAGE_IPSET is not set -BR2_PACKAGE_IPTABLES=y -# BR2_PACKAGE_IPTABLES_BPF_NFSYNPROXY is not set -# BR2_PACKAGE_IPTABLES_NFTABLES is not set +# BR2_PACKAGE_IPTABLES is not set # BR2_PACKAGE_IPTRAF_NG is not set # BR2_PACKAGE_IPUTILS is not set # BR2_PACKAGE_IRSSI is not set @@ -4108,10 +4115,10 @@ BR2_PACKAGE_LYNX=y # BR2_PACKAGE_NBD is not set # BR2_PACKAGE_NCFTP is not set # BR2_PACKAGE_NDISC6 is not set -# BR2_PACKAGE_NET_TOOLS is not set +BR2_PACKAGE_NET_TOOLS=y # BR2_PACKAGE_NETATALK is not set # BR2_PACKAGE_NETCALC is not set -# BR2_PACKAGE_NETCAT is not set +BR2_PACKAGE_NETCAT=y # BR2_PACKAGE_NETCAT_OPENBSD is not set # @@ -4124,7 +4131,8 @@ BR2_PACKAGE_LYNX=y # NetworkManager needs udev /dev management and a glibc or musl toolchain w/ headers >= 4.20, dynamic library, wchar, threads, gcc >= 4.9 # # BR2_PACKAGE_NFACCT is not set -# BR2_PACKAGE_NFTABLES is not set +BR2_PACKAGE_NFTABLES=y +BR2_PACKAGE_NFTABLES_PYTHON=y # BR2_PACKAGE_NGINX is not set # BR2_PACKAGE_NGIRCD is not set # BR2_PACKAGE_NGREP is not set @@ -4237,7 +4245,7 @@ BR2_PACKAGE_LYNX=y # BR2_PACKAGE_TINYSSH is not set # BR2_PACKAGE_TIPIDEE is not set # BR2_PACKAGE_TOR is not set -# BR2_PACKAGE_TRACEROUTE is not set +BR2_PACKAGE_TRACEROUTE=y # # transmission needs a toolchain w/ dynamic library, threads, C++, gcc >= 7 @@ -4392,11 +4400,11 @@ BR2_PACKAGE_BASH=y # BR2_PACKAGE_CATATONIT is not set # BR2_PACKAGE_CCRYPT is not set # BR2_PACKAGE_CRUDINI is not set -# BR2_PACKAGE_DIALOG is not set +BR2_PACKAGE_DIALOG=y # BR2_PACKAGE_DTACH is not set # BR2_PACKAGE_EASY_RSA is not set # BR2_PACKAGE_EZA is not set -# BR2_PACKAGE_FILE is not set +BR2_PACKAGE_FILE=y # BR2_PACKAGE_GNUPG is not set BR2_PACKAGE_GNUPG2_DEPENDS=y # BR2_PACKAGE_GNUPG2 is not set @@ -4405,7 +4413,7 @@ BR2_PACKAGE_GNUPG2_DEPENDS=y # BR2_PACKAGE_LOGROTATE is not set # BR2_PACKAGE_LOGSURFER is not set # BR2_PACKAGE_MINISIGN is not set -# BR2_PACKAGE_NEOFETCH is not set +BR2_PACKAGE_NEOFETCH=y # BR2_PACKAGE_PDMENU is not set # BR2_PACKAGE_PINENTRY is not set # BR2_PACKAGE_QPRINT is not set @@ -4415,7 +4423,7 @@ BR2_PACKAGE_GNUPG2_DEPENDS=y # BR2_PACKAGE_SCREEN is not set # BR2_PACKAGE_SCREENFETCH is not set # BR2_PACKAGE_SEXPECT is not set -# BR2_PACKAGE_SUDO is not set +BR2_PACKAGE_SUDO=y # BR2_PACKAGE_TIME is not set # BR2_PACKAGE_TINI is not set # BR2_PACKAGE_TMUX is not set @@ -4474,7 +4482,7 @@ BR2_PACKAGE_EFIVAR_ARCH_SUPPORTS=y # BR2_PACKAGE_FTOP is not set # BR2_PACKAGE_GETENT is not set # BR2_PACKAGE_GKRELLM is not set -# BR2_PACKAGE_HTOP is not set +BR2_PACKAGE_HTOP=y # BR2_PACKAGE_IBM_SW_TPM2 is not set BR2_PACKAGE_INITSCRIPTS=y # BR2_PACKAGE_IOTOP is not set diff --git a/board/mentalnet/linux-slim.config b/board/mentalnet/linux-slim.config index fe5799e..a33c08f 100644 --- a/board/mentalnet/linux-slim.config +++ b/board/mentalnet/linux-slim.config @@ -141,3 +141,14 @@ CONFIG_VGA_CONSOLE=y # CONFIG_NET_VENDOR_WIZNET is not set # CONFIG_NET_VENDOR_XILINX is not set # CONFIG_NET_VENDOR_XIRCOM is not set + +# --- nftables firewall (kernel side) --- +CONFIG_NF_TABLES=y +CONFIG_NF_TABLES_INET=y +CONFIG_NFT_CT=y +CONFIG_NFT_LIMIT=y +CONFIG_NFT_LOG=y +CONFIG_NFT_NAT=y +CONFIG_NFT_MASQ=y +CONFIG_NFT_REJECT=y +CONFIG_NFT_REJECT_INET=y diff --git a/board/mentalnet/overlay/etc/init.d/S35nftables b/board/mentalnet/overlay/etc/init.d/S35nftables new file mode 100755 index 0000000..9f98bba --- /dev/null +++ b/board/mentalnet/overlay/etc/init.d/S35nftables @@ -0,0 +1,49 @@ +#!/bin/sh +# +# Load the nftables firewall ruleset from /etc/nftables.conf. + +DAEMON="nft" +CONF="/etc/nftables.conf" + +start() { + printf 'Loading nftables firewall: ' + if ! [ -f "$CONF" ]; then + echo "MISSING $CONF" + return 1 + fi + "$DAEMON" -f "$CONF" + status=$? + if [ "$status" -eq 0 ]; then + echo "OK" + else + echo "FAIL" + fi + return "$status" +} + +stop() { + printf 'Flushing nftables ruleset: ' + "$DAEMON" flush ruleset + status=$? + if [ "$status" -eq 0 ]; then + echo "OK" + else + echo "FAIL" + fi + return "$status" +} + +restart() { + stop + start +} + +case "$1" in + start|stop|restart) + "$1";; + reload) + restart;; + *) + echo "Usage: $0 {start|stop|restart|reload}" + exit 1 +esac diff --git a/board/mentalnet/overlay/etc/nftables.conf b/board/mentalnet/overlay/etc/nftables.conf new file mode 100644 index 0000000..75bfd59 --- /dev/null +++ b/board/mentalnet/overlay/etc/nftables.conf @@ -0,0 +1,41 @@ +# /etc/nftables.conf - Mentalnet GNU/Linux firewall +# Loaded by /etc/init.d/S35nftables at boot. Edit and re-run: +# nft -f /etc/nftables.conf + +flush ruleset + +table inet filter { + chain input { + type filter hook input priority 0; policy drop; + + # loopback + iifname "lo" accept + + # established and related connections + ct state established,related accept + + # DHCP client replies + udp sport 67 udp dport 68 accept + + # ICMP (ping et al.) + ip protocol icmp accept + ip6 nexthdr icmpv6 accept + + # services: SSH, HTTP + tcp dport 22 accept + tcp dport 80 accept + + # log and reject everything else (rate-limited: goes to + # syslog, not the TTY - see /etc/sysctl.conf) + limit rate 1/minute log prefix "nft-drop: " counter + counter reject with icmpx type port-unreachable + } + + chain forward { + type filter hook forward priority 0; policy accept; + } + + chain output { + type filter hook output priority 0; policy accept; + } +} diff --git a/board/mentalnet/overlay/etc/sysctl.conf b/board/mentalnet/overlay/etc/sysctl.conf new file mode 100644 index 0000000..84a9265 --- /dev/null +++ b/board/mentalnet/overlay/etc/sysctl.conf @@ -0,0 +1,6 @@ +# /etc/sysctl.conf - Mentalnet GNU/Linux runtime kernel settings +# Applied by /etc/init.d/S02sysctl at boot. + +# Keep the TTY quiet: console shows errors and worse only. +# Kernel warnings (e.g. nft-drop lines) still reach syslog via klogd. +kernel.printk = 3 4 1 3