NETCONF as an OpenSSH subsystem - #1664
Merged
Merged
Conversation
troglobit
force-pushed
the
netopeer2-vs-openssh
branch
from
September 27, 2026 19:21
1b952c5 to
7c2b6dd
Compare
mattiaswal
approved these changes
Sep 28, 2026
Refactor netopeer2-server to act as an OpenSSH subsystem, similar to how sftp works. The SSH daemon authenticates the user and runs the new libnetconf2 netconf-subsystem helper, which bridges the session to a UNIX socket netopeer2-server listens on. The peer credentials of that socket tell the server who the user is, so NACM works as before, and netopeer2-server no longer needs an SSH implementation (libssh) of its own. The libnetconf2 patches add the helper and the API to create a UNIX endpoint without ietf-netconf-server; the netopeer2 patch teaches the server to use them. Buildroot gets an option for this mode, which the Infix defconfigs select. A build without it keeps libssh, NETCONF over TLS, call-home and netopeer2-cli. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
NETCONF becomes a netconf/enabled toggle under the ssh service, and in the default build depends on it the same way restconf depends on web: confd adds port 830 to the sshd listen addresses, forces the subsystem on that port with a Match block, and starts netopeer2-server with -U on the socket. ietf-netconf-server has nothing left to describe there, so it is not loaded and its factory data goes. The build without the OpenSSH subsystem keeps all of that: confd loads the SSH and TLS modules, ships the endpoint in the factory config, and leaves port 830 to netopeer2-server. The migration therefore comes in two flavours, one converts an old endpoint into netconf/enabled, the other only adds the leaf. sshd runs subsystems through the login shell, so the clish wrapper lets the helper through, and only the helper, when called with -c. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
syslogd starts in runlevel S and sshd not before runlevel 2, so the condition never held anything back. It did cost us: a configuration change that touches both, a hostname change together with an SSH change, reloads syslogd, which puts the condition in flux and pauses sshd; with Finit 4.x a second reload arriving right then loses sshd's pending reload, and it keeps its old listen addresses. NETCONF over sshd makes that a lockout. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
A service paused by a condition during a reload lost its own pending reload if another reload came in before it resumed. With NETCONF on sshd this shows up as a lockout: a hostname change together with an SSH change leaves sshd on its old listen addresses. Upstream commit f6b394e0 on the 4.x branch. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
troglobit
force-pushed
the
netopeer2-vs-openssh
branch
from
September 28, 2026 16:52
7c2b6dd to
ff4f6ef
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
With this PR, NETCONF is served by the OpenSSH daemon as a subsystem instead of
libsshembedded innetopeer2-server.sshdauthenticates the user and runs a small libnetconf2 helper that bridges the session to a UNIX socket netopeer2-server listens on. The server learns the user from the socket peer credentials, so NACM works as before.Changes
netconf-subsystemhelper-U PATHfor a UNIX-only endpoint,ietf-netconf-server.yangoptionalBR2_PACKAGE_LIBNETCONF2_SSH_SUBSYSTEMoption, selected by the Infix defconfigs/ssh/netconf/enabled(default true), independent of SSH logins: with logins disabled sshd keeps running on port 830 onlyssh -s <host> netconfalso works on the regular SSH portsclishlogin shell lets the subsystem helper throughBenefits
libssh;netopeer2-serverlinks onlylibnetconf2,libyang,sysrepoandlibcurl/sshietf-netconf-server.yangand its SSH/TLS models are gone from the default builds, less to configure and explainTrade-offs
netopeer2-cliare no longer available in default builds. A build withoutBR2_PACKAGE_LIBNETCONF2_SSH_SUBSYSTEMbrings backlibssh, TLS, call-home, the CLI andietf-netconf-server.yangietf-netconf-serverendpoint. Builds that turn the option off must add it backChecklist
Tick relevant boxes, this PR is-a or has-a: