Add git, neofetch, replace iptables with nftables, setup /etc/sysctl.conf
This commit is contained in:
parent
a43e95b17f
commit
8202f22735
5 changed files with 133 additions and 18 deletions
44
.config
44
.config
|
|
@ -1,6 +1,6 @@
|
||||||
#
|
#
|
||||||
# Automatically generated file; DO NOT EDIT.
|
# Automatically generated file; DO NOT EDIT.
|
||||||
# Buildroot -g1d86d4f-dirty Configuration
|
# Buildroot -ga43e95b-dirty Configuration
|
||||||
#
|
#
|
||||||
BR2_HAVE_DOT_CONFIG=y
|
BR2_HAVE_DOT_CONFIG=y
|
||||||
BR2_HOST_GCC_AT_LEAST_4_9=y
|
BR2_HOST_GCC_AT_LEAST_4_9=y
|
||||||
|
|
@ -873,7 +873,7 @@ BR2_PACKAGE_CMAKE_ARCH_SUPPORTS=y
|
||||||
# BR2_PACKAGE_GAWK is not set
|
# BR2_PACKAGE_GAWK is not set
|
||||||
# BR2_PACKAGE_GETTEXT is not set
|
# BR2_PACKAGE_GETTEXT is not set
|
||||||
BR2_PACKAGE_PROVIDES_HOST_GETTEXT="host-gettext-tiny"
|
BR2_PACKAGE_PROVIDES_HOST_GETTEXT="host-gettext-tiny"
|
||||||
# BR2_PACKAGE_GIT is not set
|
BR2_PACKAGE_GIT=y
|
||||||
|
|
||||||
#
|
#
|
||||||
# git-crypt needs a toolchain w/ C++, gcc >= 4.9
|
# git-crypt needs a toolchain w/ C++, gcc >= 4.9
|
||||||
|
|
@ -884,7 +884,7 @@ BR2_PACKAGE_PROVIDES_HOST_GETTEXT="host-gettext-tiny"
|
||||||
#
|
#
|
||||||
# BR2_PACKAGE_GREP is not set
|
# BR2_PACKAGE_GREP is not set
|
||||||
# BR2_PACKAGE_JO is not set
|
# BR2_PACKAGE_JO is not set
|
||||||
# BR2_PACKAGE_JQ is not set
|
BR2_PACKAGE_JQ=y
|
||||||
# BR2_PACKAGE_LIBTOOL is not set
|
# BR2_PACKAGE_LIBTOOL is not set
|
||||||
BR2_PACKAGE_MAKE=y
|
BR2_PACKAGE_MAKE=y
|
||||||
# BR2_PACKAGE_MAWK is not set
|
# BR2_PACKAGE_MAWK is not set
|
||||||
|
|
@ -3143,7 +3143,15 @@ BR2_PACKAGE_LIBOPENH264_ARCH_SUPPORTS=y
|
||||||
#
|
#
|
||||||
# libcpprestsdk needs a toolchain w/ NPTL, C++, wchar, locale
|
# libcpprestsdk needs a toolchain w/ NPTL, C++, wchar, locale
|
||||||
#
|
#
|
||||||
# BR2_PACKAGE_LIBCURL is not set
|
BR2_PACKAGE_LIBCURL=y
|
||||||
|
# BR2_PACKAGE_LIBCURL_CURL is not set
|
||||||
|
# BR2_PACKAGE_LIBCURL_VERBOSE is not set
|
||||||
|
BR2_PACKAGE_LIBCURL_PROXY_SUPPORT=y
|
||||||
|
BR2_PACKAGE_LIBCURL_COOKIES_SUPPORT=y
|
||||||
|
# BR2_PACKAGE_LIBCURL_WEBSOCKETS_SUPPORT is not set
|
||||||
|
BR2_PACKAGE_LIBCURL_EXTRA_PROTOCOLS_FEATURES=y
|
||||||
|
BR2_PACKAGE_LIBCURL_OPENSSL=y
|
||||||
|
# BR2_PACKAGE_LIBCURL_TLS_NONE is not set
|
||||||
# BR2_PACKAGE_LIBDNET is not set
|
# BR2_PACKAGE_LIBDNET is not set
|
||||||
# BR2_PACKAGE_LIBEXOSIP2 is not set
|
# BR2_PACKAGE_LIBEXOSIP2 is not set
|
||||||
# BR2_PACKAGE_LIBEST is not set
|
# BR2_PACKAGE_LIBEST is not set
|
||||||
|
|
@ -3168,7 +3176,8 @@ BR2_PACKAGE_LIBOPENH264_ARCH_SUPPORTS=y
|
||||||
#
|
#
|
||||||
# BR2_PACKAGE_LIBMICROHTTPD is not set
|
# BR2_PACKAGE_LIBMICROHTTPD is not set
|
||||||
# BR2_PACKAGE_LIBMINIUPNPC is not set
|
# BR2_PACKAGE_LIBMINIUPNPC is not set
|
||||||
# BR2_PACKAGE_LIBMNL is not set
|
BR2_PACKAGE_LIBMNL=y
|
||||||
|
# BR2_PACKAGE_LIBMNL_EXAMPLES is not set
|
||||||
# BR2_PACKAGE_LIBMODBUS is not set
|
# BR2_PACKAGE_LIBMODBUS is not set
|
||||||
|
|
||||||
#
|
#
|
||||||
|
|
@ -3185,7 +3194,7 @@ BR2_PACKAGE_LIBOPENH264_ARCH_SUPPORTS=y
|
||||||
# BR2_PACKAGE_LIBNETFILTER_LOG is not set
|
# BR2_PACKAGE_LIBNETFILTER_LOG is not set
|
||||||
# BR2_PACKAGE_LIBNETFILTER_QUEUE is not set
|
# BR2_PACKAGE_LIBNETFILTER_QUEUE is not set
|
||||||
# BR2_PACKAGE_LIBNFNETLINK is not set
|
# BR2_PACKAGE_LIBNFNETLINK is not set
|
||||||
# BR2_PACKAGE_LIBNFTNL is not set
|
BR2_PACKAGE_LIBNFTNL=y
|
||||||
# BR2_PACKAGE_LIBNICE is not set
|
# BR2_PACKAGE_LIBNICE is not set
|
||||||
# BR2_PACKAGE_LIBNIDS is not set
|
# BR2_PACKAGE_LIBNIDS is not set
|
||||||
# BR2_PACKAGE_LIBNL is not set
|
# BR2_PACKAGE_LIBNL is not set
|
||||||
|
|
@ -4035,9 +4044,7 @@ BR2_PACKAGE_IFUPDOWN_SCRIPTS=y
|
||||||
# BR2_PACKAGE_IPERF3 is not set
|
# BR2_PACKAGE_IPERF3 is not set
|
||||||
# BR2_PACKAGE_IPROUTE2 is not set
|
# BR2_PACKAGE_IPROUTE2 is not set
|
||||||
# BR2_PACKAGE_IPSET is not set
|
# BR2_PACKAGE_IPSET is not set
|
||||||
BR2_PACKAGE_IPTABLES=y
|
# BR2_PACKAGE_IPTABLES is not set
|
||||||
# BR2_PACKAGE_IPTABLES_BPF_NFSYNPROXY is not set
|
|
||||||
# BR2_PACKAGE_IPTABLES_NFTABLES is not set
|
|
||||||
# BR2_PACKAGE_IPTRAF_NG is not set
|
# BR2_PACKAGE_IPTRAF_NG is not set
|
||||||
# BR2_PACKAGE_IPUTILS is not set
|
# BR2_PACKAGE_IPUTILS is not set
|
||||||
# BR2_PACKAGE_IRSSI is not set
|
# BR2_PACKAGE_IRSSI is not set
|
||||||
|
|
@ -4108,10 +4115,10 @@ BR2_PACKAGE_LYNX=y
|
||||||
# BR2_PACKAGE_NBD is not set
|
# BR2_PACKAGE_NBD is not set
|
||||||
# BR2_PACKAGE_NCFTP is not set
|
# BR2_PACKAGE_NCFTP is not set
|
||||||
# BR2_PACKAGE_NDISC6 is not set
|
# BR2_PACKAGE_NDISC6 is not set
|
||||||
# BR2_PACKAGE_NET_TOOLS is not set
|
BR2_PACKAGE_NET_TOOLS=y
|
||||||
# BR2_PACKAGE_NETATALK is not set
|
# BR2_PACKAGE_NETATALK is not set
|
||||||
# BR2_PACKAGE_NETCALC is not set
|
# BR2_PACKAGE_NETCALC is not set
|
||||||
# BR2_PACKAGE_NETCAT is not set
|
BR2_PACKAGE_NETCAT=y
|
||||||
# BR2_PACKAGE_NETCAT_OPENBSD is not set
|
# BR2_PACKAGE_NETCAT_OPENBSD is not set
|
||||||
|
|
||||||
#
|
#
|
||||||
|
|
@ -4124,7 +4131,8 @@ BR2_PACKAGE_LYNX=y
|
||||||
# NetworkManager needs udev /dev management and a glibc or musl toolchain w/ headers >= 4.20, dynamic library, wchar, threads, gcc >= 4.9
|
# NetworkManager needs udev /dev management and a glibc or musl toolchain w/ headers >= 4.20, dynamic library, wchar, threads, gcc >= 4.9
|
||||||
#
|
#
|
||||||
# BR2_PACKAGE_NFACCT is not set
|
# BR2_PACKAGE_NFACCT is not set
|
||||||
# BR2_PACKAGE_NFTABLES is not set
|
BR2_PACKAGE_NFTABLES=y
|
||||||
|
BR2_PACKAGE_NFTABLES_PYTHON=y
|
||||||
# BR2_PACKAGE_NGINX is not set
|
# BR2_PACKAGE_NGINX is not set
|
||||||
# BR2_PACKAGE_NGIRCD is not set
|
# BR2_PACKAGE_NGIRCD is not set
|
||||||
# BR2_PACKAGE_NGREP is not set
|
# BR2_PACKAGE_NGREP is not set
|
||||||
|
|
@ -4237,7 +4245,7 @@ BR2_PACKAGE_LYNX=y
|
||||||
# BR2_PACKAGE_TINYSSH is not set
|
# BR2_PACKAGE_TINYSSH is not set
|
||||||
# BR2_PACKAGE_TIPIDEE is not set
|
# BR2_PACKAGE_TIPIDEE is not set
|
||||||
# BR2_PACKAGE_TOR is not set
|
# BR2_PACKAGE_TOR is not set
|
||||||
# BR2_PACKAGE_TRACEROUTE is not set
|
BR2_PACKAGE_TRACEROUTE=y
|
||||||
|
|
||||||
#
|
#
|
||||||
# transmission needs a toolchain w/ dynamic library, threads, C++, gcc >= 7
|
# transmission needs a toolchain w/ dynamic library, threads, C++, gcc >= 7
|
||||||
|
|
@ -4392,11 +4400,11 @@ BR2_PACKAGE_BASH=y
|
||||||
# BR2_PACKAGE_CATATONIT is not set
|
# BR2_PACKAGE_CATATONIT is not set
|
||||||
# BR2_PACKAGE_CCRYPT is not set
|
# BR2_PACKAGE_CCRYPT is not set
|
||||||
# BR2_PACKAGE_CRUDINI is not set
|
# BR2_PACKAGE_CRUDINI is not set
|
||||||
# BR2_PACKAGE_DIALOG is not set
|
BR2_PACKAGE_DIALOG=y
|
||||||
# BR2_PACKAGE_DTACH is not set
|
# BR2_PACKAGE_DTACH is not set
|
||||||
# BR2_PACKAGE_EASY_RSA is not set
|
# BR2_PACKAGE_EASY_RSA is not set
|
||||||
# BR2_PACKAGE_EZA is not set
|
# BR2_PACKAGE_EZA is not set
|
||||||
# BR2_PACKAGE_FILE is not set
|
BR2_PACKAGE_FILE=y
|
||||||
# BR2_PACKAGE_GNUPG is not set
|
# BR2_PACKAGE_GNUPG is not set
|
||||||
BR2_PACKAGE_GNUPG2_DEPENDS=y
|
BR2_PACKAGE_GNUPG2_DEPENDS=y
|
||||||
# BR2_PACKAGE_GNUPG2 is not set
|
# BR2_PACKAGE_GNUPG2 is not set
|
||||||
|
|
@ -4405,7 +4413,7 @@ BR2_PACKAGE_GNUPG2_DEPENDS=y
|
||||||
# BR2_PACKAGE_LOGROTATE is not set
|
# BR2_PACKAGE_LOGROTATE is not set
|
||||||
# BR2_PACKAGE_LOGSURFER is not set
|
# BR2_PACKAGE_LOGSURFER is not set
|
||||||
# BR2_PACKAGE_MINISIGN is not set
|
# BR2_PACKAGE_MINISIGN is not set
|
||||||
# BR2_PACKAGE_NEOFETCH is not set
|
BR2_PACKAGE_NEOFETCH=y
|
||||||
# BR2_PACKAGE_PDMENU is not set
|
# BR2_PACKAGE_PDMENU is not set
|
||||||
# BR2_PACKAGE_PINENTRY is not set
|
# BR2_PACKAGE_PINENTRY is not set
|
||||||
# BR2_PACKAGE_QPRINT is not set
|
# BR2_PACKAGE_QPRINT is not set
|
||||||
|
|
@ -4415,7 +4423,7 @@ BR2_PACKAGE_GNUPG2_DEPENDS=y
|
||||||
# BR2_PACKAGE_SCREEN is not set
|
# BR2_PACKAGE_SCREEN is not set
|
||||||
# BR2_PACKAGE_SCREENFETCH is not set
|
# BR2_PACKAGE_SCREENFETCH is not set
|
||||||
# BR2_PACKAGE_SEXPECT is not set
|
# BR2_PACKAGE_SEXPECT is not set
|
||||||
# BR2_PACKAGE_SUDO is not set
|
BR2_PACKAGE_SUDO=y
|
||||||
# BR2_PACKAGE_TIME is not set
|
# BR2_PACKAGE_TIME is not set
|
||||||
# BR2_PACKAGE_TINI is not set
|
# BR2_PACKAGE_TINI is not set
|
||||||
# BR2_PACKAGE_TMUX is not set
|
# BR2_PACKAGE_TMUX is not set
|
||||||
|
|
@ -4474,7 +4482,7 @@ BR2_PACKAGE_EFIVAR_ARCH_SUPPORTS=y
|
||||||
# BR2_PACKAGE_FTOP is not set
|
# BR2_PACKAGE_FTOP is not set
|
||||||
# BR2_PACKAGE_GETENT is not set
|
# BR2_PACKAGE_GETENT is not set
|
||||||
# BR2_PACKAGE_GKRELLM is not set
|
# BR2_PACKAGE_GKRELLM is not set
|
||||||
# BR2_PACKAGE_HTOP is not set
|
BR2_PACKAGE_HTOP=y
|
||||||
# BR2_PACKAGE_IBM_SW_TPM2 is not set
|
# BR2_PACKAGE_IBM_SW_TPM2 is not set
|
||||||
BR2_PACKAGE_INITSCRIPTS=y
|
BR2_PACKAGE_INITSCRIPTS=y
|
||||||
# BR2_PACKAGE_IOTOP is not set
|
# BR2_PACKAGE_IOTOP is not set
|
||||||
|
|
|
||||||
|
|
@ -141,3 +141,14 @@ CONFIG_VGA_CONSOLE=y
|
||||||
# CONFIG_NET_VENDOR_WIZNET is not set
|
# CONFIG_NET_VENDOR_WIZNET is not set
|
||||||
# CONFIG_NET_VENDOR_XILINX is not set
|
# CONFIG_NET_VENDOR_XILINX is not set
|
||||||
# CONFIG_NET_VENDOR_XIRCOM is not set
|
# CONFIG_NET_VENDOR_XIRCOM is not set
|
||||||
|
|
||||||
|
# --- nftables firewall (kernel side) ---
|
||||||
|
CONFIG_NF_TABLES=y
|
||||||
|
CONFIG_NF_TABLES_INET=y
|
||||||
|
CONFIG_NFT_CT=y
|
||||||
|
CONFIG_NFT_LIMIT=y
|
||||||
|
CONFIG_NFT_LOG=y
|
||||||
|
CONFIG_NFT_NAT=y
|
||||||
|
CONFIG_NFT_MASQ=y
|
||||||
|
CONFIG_NFT_REJECT=y
|
||||||
|
CONFIG_NFT_REJECT_INET=y
|
||||||
|
|
|
||||||
49
board/mentalnet/overlay/etc/init.d/S35nftables
Executable file
49
board/mentalnet/overlay/etc/init.d/S35nftables
Executable file
|
|
@ -0,0 +1,49 @@
|
||||||
|
#!/bin/sh
|
||||||
|
#
|
||||||
|
# Load the nftables firewall ruleset from /etc/nftables.conf.
|
||||||
|
|
||||||
|
DAEMON="nft"
|
||||||
|
CONF="/etc/nftables.conf"
|
||||||
|
|
||||||
|
start() {
|
||||||
|
printf 'Loading nftables firewall: '
|
||||||
|
if ! [ -f "$CONF" ]; then
|
||||||
|
echo "MISSING $CONF"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
"$DAEMON" -f "$CONF"
|
||||||
|
status=$?
|
||||||
|
if [ "$status" -eq 0 ]; then
|
||||||
|
echo "OK"
|
||||||
|
else
|
||||||
|
echo "FAIL"
|
||||||
|
fi
|
||||||
|
return "$status"
|
||||||
|
}
|
||||||
|
|
||||||
|
stop() {
|
||||||
|
printf 'Flushing nftables ruleset: '
|
||||||
|
"$DAEMON" flush ruleset
|
||||||
|
status=$?
|
||||||
|
if [ "$status" -eq 0 ]; then
|
||||||
|
echo "OK"
|
||||||
|
else
|
||||||
|
echo "FAIL"
|
||||||
|
fi
|
||||||
|
return "$status"
|
||||||
|
}
|
||||||
|
|
||||||
|
restart() {
|
||||||
|
stop
|
||||||
|
start
|
||||||
|
}
|
||||||
|
|
||||||
|
case "$1" in
|
||||||
|
start|stop|restart)
|
||||||
|
"$1";;
|
||||||
|
reload)
|
||||||
|
restart;;
|
||||||
|
*)
|
||||||
|
echo "Usage: $0 {start|stop|restart|reload}"
|
||||||
|
exit 1
|
||||||
|
esac
|
||||||
41
board/mentalnet/overlay/etc/nftables.conf
Normal file
41
board/mentalnet/overlay/etc/nftables.conf
Normal file
|
|
@ -0,0 +1,41 @@
|
||||||
|
# /etc/nftables.conf - Mentalnet GNU/Linux firewall
|
||||||
|
# Loaded by /etc/init.d/S35nftables at boot. Edit and re-run:
|
||||||
|
# nft -f /etc/nftables.conf
|
||||||
|
|
||||||
|
flush ruleset
|
||||||
|
|
||||||
|
table inet filter {
|
||||||
|
chain input {
|
||||||
|
type filter hook input priority 0; policy drop;
|
||||||
|
|
||||||
|
# loopback
|
||||||
|
iifname "lo" accept
|
||||||
|
|
||||||
|
# established and related connections
|
||||||
|
ct state established,related accept
|
||||||
|
|
||||||
|
# DHCP client replies
|
||||||
|
udp sport 67 udp dport 68 accept
|
||||||
|
|
||||||
|
# ICMP (ping et al.)
|
||||||
|
ip protocol icmp accept
|
||||||
|
ip6 nexthdr icmpv6 accept
|
||||||
|
|
||||||
|
# services: SSH, HTTP
|
||||||
|
tcp dport 22 accept
|
||||||
|
tcp dport 80 accept
|
||||||
|
|
||||||
|
# log and reject everything else (rate-limited: goes to
|
||||||
|
# syslog, not the TTY - see /etc/sysctl.conf)
|
||||||
|
limit rate 1/minute log prefix "nft-drop: " counter
|
||||||
|
counter reject with icmpx type port-unreachable
|
||||||
|
}
|
||||||
|
|
||||||
|
chain forward {
|
||||||
|
type filter hook forward priority 0; policy accept;
|
||||||
|
}
|
||||||
|
|
||||||
|
chain output {
|
||||||
|
type filter hook output priority 0; policy accept;
|
||||||
|
}
|
||||||
|
}
|
||||||
6
board/mentalnet/overlay/etc/sysctl.conf
Normal file
6
board/mentalnet/overlay/etc/sysctl.conf
Normal file
|
|
@ -0,0 +1,6 @@
|
||||||
|
# /etc/sysctl.conf - Mentalnet GNU/Linux runtime kernel settings
|
||||||
|
# Applied by /etc/init.d/S02sysctl at boot.
|
||||||
|
|
||||||
|
# Keep the TTY quiet: console shows errors and worse only.
|
||||||
|
# Kernel warnings (e.g. nft-drop lines) still reach syslog via klogd.
|
||||||
|
kernel.printk = 3 4 1 3
|
||||||
Loading…
Add table
Add a link
Reference in a new issue