diff --git a/.claude/WIP.md b/.claude/WIP.md index b610d349..63ccbf65 100644 --- a/.claude/WIP.md +++ b/.claude/WIP.md @@ -1,9 +1,92 @@ # WIP — Work In Progress -*Mis à jour : 2026-04-15 (Session 59)* +*Mis à jour : 2026-06-26 15:30 (Session 60)* --- -## 🔄 En cours (Session 59) — v1.7.0 Image Builds & Fixes +## 🔄 En cours (Session 60) — EspressoBin eMMC Boot Fixes + +### S60-01 — HAProxy Service Restart Loop Fix ✅ + +**Status:** ✅ Complete + +#### Problem +secubox-haproxy.service was failing with NAMESPACE errors: +``` +Failed to set up mount namespacing: /run/systemd/unit-root/etc/haproxy: No such file or directory +``` + +#### Root Cause +`ReadWritePaths=/etc/haproxy /run/haproxy` in service file requires directories to exist for namespace setup, but haproxy is only `Recommends:` not `Depends:`. + +#### Fix +Removed sandboxing directives that cause issues when haproxy not installed. + +#### Files Modified +- `packages/secubox-haproxy/debian/secubox-haproxy.service` + +--- + +### S60-02 — Network Fallback Script Fix ✅ + +**Status:** ✅ Complete + +#### Problem +secubox-net-fallback was trying DHCP on `lan0`, `lan1` interfaces which are downstream LAN ports where SecuBox provides DHCP (not receives it). + +#### Root Cause +Script processed `lan*` interfaces for DHCP, but these are LAN downstream ports on EspressoBin DSA switch. + +#### Fix +Added logic to skip `lan*` interfaces and bridged interfaces: +```bash +case "$IFACE" in + lan*) + logger -t secubox-net "Skipping LAN interface $IFACE (downstream port)" + continue + ;; +esac +``` + +#### Files Modified +- `image/build-image.sh` — Updated secubox-net-fallback script + +--- + +### S60-03 — Network Configuration Fix ✅ + +**Status:** ✅ Complete + +#### Problem +1. dummy0 had IP 192.168.255.1/24 which conflicted with gateway +2. IP was assigned to eth0 (CPU port) instead of wan (physical DSA port) + +#### Root Cause +- dummy0 IP overlapped with upstream gateway IP +- EspressoBin DSA topology: eth0 is CPU port, wan/lan0/lan1 are physical ports + +#### Fix +- Changed dummy0 to use 10.55.255.1/24 (non-conflicting) +- Updated all board netplan configs to include dummy0 +- Fixed IP assignment to wan interface instead of eth0 + +#### Files Modified +- `board/espressobin-v7/netplan/00-secubox.yaml` +- `board/espressobin-ultra/netplan/00-secubox.yaml` +- `board/mochabin/netplan/00-secubox.yaml` + +--- + +### S60-04 — EspressoBin V7 Device Mapping Notes + +**Important for future reference:** +- **U-Boot**: eMMC is `mmc 1`, SD card is `mmc 0` +- **Linux**: eMMC is `/dev/mmcblk0`, detected by presence of `boot0` partition +- **DSA Switch**: eth0 is CPU port (master), wan/lan0/lan1 are physical ports (slaves) +- **Network**: Assign IPs to `wan` interface, not `eth0` + +--- + +## ✅ Completed (Session 59) — v1.7.0 Image Builds & Fixes ### S59-01 — EspressoBin Live USB with eMMC Flasher ✅ @@ -233,12 +316,20 @@ Implemented USB OTG composite gadget connection between RPi Zero W (Remote UI) a #### Files Modified - `remote-ui/round/install_zerow.sh` — Use KMS overlay by default, all fixes integrated - `remote-ui/round/README.md` — Updated troubleshooting for KMS overlay +- `remote-ui/round/secubox_dashboard.py` — **NEW** Python/PIL dashboard (no Chromium!) #### Testing Status - [x] SD card flashing works - [x] USB OTG interface appears on host - [x] SSH connection works (pi:raspberry via userconf) - [x] HyperPixel display works with KMS overlay +- [x] Python dashboard running with live metrics + +#### Technical Notes +- Framebuffer is RGB565 (16-bit), not 32-bit BGRA +- KMS overlay provides DRM `/dev/fb0` at 480x480 +- Dashboard uses PIL for rendering, direct FB write for display +- No X11, no Chromium = lightweight (~18MB RAM) --- diff --git a/board/espressobin-ultra/netplan/00-secubox.yaml b/board/espressobin-ultra/netplan/00-secubox.yaml index 28ea50f6..be241a54 100644 --- a/board/espressobin-ultra/netplan/00-secubox.yaml +++ b/board/espressobin-ultra/netplan/00-secubox.yaml @@ -16,6 +16,11 @@ network: lan3: optional: true + # Dummy interface for internal services + dummy0: + addresses: [10.55.255.1/24] + optional: true + bridges: br-lan: interfaces: [lan0, lan1, lan2, lan3] diff --git a/board/espressobin-v7/flash-emmc.cmd b/board/espressobin-v7/flash-emmc.cmd index b0a6b781..5f01ab1b 100644 --- a/board/espressobin-v7/flash-emmc.cmd +++ b/board/espressobin-v7/flash-emmc.cmd @@ -17,11 +17,13 @@ fi # Load compressed image echo "Loading image..." -if load usb 0:1 ${loadaddr} secubox-espressobin-v7-bookworm.img.gz; then +if load usb 0:1 ${loadaddr} secubox-ebin-v7.img.gz; then echo "Image loaded: ${filesize} bytes" +elif load usb 0:1 ${loadaddr} secubox-espressobin-v7-bookworm.img.gz; then + echo "Image loaded (alt name): ${filesize} bytes" else echo "ERROR: Image not found on USB" - echo "Expected: secubox-espressobin-v7-bookworm.img.gz" + echo "Expected: secubox-ebin-v7.img.gz" exit 1 fi diff --git a/board/espressobin-v7/netplan/00-secubox.yaml b/board/espressobin-v7/netplan/00-secubox.yaml index a4c38f0b..b92de774 100644 --- a/board/espressobin-v7/netplan/00-secubox.yaml +++ b/board/espressobin-v7/netplan/00-secubox.yaml @@ -40,6 +40,11 @@ network: lan1: optional: true + # Dummy interface for internal services (non-conflicting with gateway) + dummy0: + addresses: [10.55.255.1/24] + optional: true + bridges: br-lan: interfaces: [lan0, lan1] diff --git a/board/mochabin/netplan/00-secubox.yaml b/board/mochabin/netplan/00-secubox.yaml index 39602939..b6c33d88 100644 --- a/board/mochabin/netplan/00-secubox.yaml +++ b/board/mochabin/netplan/00-secubox.yaml @@ -28,6 +28,11 @@ network: eth6: optional: true + # Dummy interface for internal services + dummy0: + addresses: [10.55.255.1/24] + optional: true + bridges: # Bridge LAN br-lan: diff --git a/image/build-image.sh b/image/build-image.sh index cee9e8f5..9ed36351 100755 --- a/image/build-image.sh +++ b/image/build-image.sh @@ -470,9 +470,24 @@ for iface in /sys/class/net/*; do lo|dummy*|docker*|veth*|br-*|virbr*) continue ;; esac - # Only process physical network interfaces + # Skip LAN interfaces - SecuBox IS the router on these (provides DHCP, not receives it) + # lan0, lan1 on EspressoBin are downstream ports to clients case "$IFACE" in - e*|w*|lan*|eth*|wan*) ;; + lan*) + logger -t secubox-net "Skipping LAN interface $IFACE (downstream port)" + continue + ;; + esac + + # Skip interfaces that are part of a bridge (already managed) + if [[ -d "/sys/class/net/$IFACE/brport" ]]; then + logger -t secubox-net "Skipping $IFACE (bridged interface)" + continue + fi + + # Only process WAN/uplink interfaces (need DHCP from upstream router) + case "$IFACE" in + eth*|wan*|en*) ;; *) continue ;; esac @@ -504,8 +519,8 @@ for iface in /sys/class/net/*; do continue fi - # DHCP failed - try auto-discovery then fallback - if [[ "$IFACE" == e* ]] || [[ "$IFACE" == lan* ]] || [[ "$IFACE" == eth* ]] || [[ "$IFACE" == wan* ]]; then + # DHCP failed on WAN interface - try auto-discovery then fallback + if [[ "$IFACE" == e* ]] || [[ "$IFACE" == eth* ]] || [[ "$IFACE" == wan* ]] || [[ "$IFACE" == en* ]]; then logger -t secubox-net "DHCP failed on $IFACE, trying LAN auto-discovery..." if discover_lan "$IFACE"; then logger -t secubox-net "LAN auto-discovery succeeded on $IFACE" diff --git a/image/sbin/secubox-flash-emmc b/image/sbin/secubox-flash-emmc index e6d58570..caf1870d 100755 --- a/image/sbin/secubox-flash-emmc +++ b/image/sbin/secubox-flash-emmc @@ -19,9 +19,23 @@ NC='\033[0m' # Default paths DEFAULT_IMAGE="/secubox/secubox-ebin-v7.img.gz" -EMMC_DEVICE="/dev/mmcblk1" LOG_FILE="/var/log/secubox-flash.log" +# Auto-detect eMMC device (has boot0 partition - unique to eMMC, not SD cards) +detect_emmc() { + local dev + for dev in /dev/mmcblk0 /dev/mmcblk1 /dev/mmcblk2; do + # eMMC has boot0 partition (block device), SD cards don't + if [[ -b "${dev}boot0" ]]; then + echo "$dev" + return 0 + fi + done + return 1 +} + +EMMC_DEVICE="" + # Options AUTO_MODE=0 DRY_RUN=0 @@ -87,22 +101,32 @@ done BOOT_DEVICE=$(findmnt -no SOURCE / 2>/dev/null | sed 's/[0-9]*$//' | sed 's/p$//') log "Boot device: $BOOT_DEVICE" +# Auto-detect eMMC device +if ! EMMC_DEVICE=$(detect_emmc); then + err "eMMC device not found! + + Checked: /dev/mmcblk0, /dev/mmcblk1, /dev/mmcblk2 + Looking for: boot0, boot1, rpmb partitions (eMMC signature) + + This could mean: + - No eMMC installed on this board + - Kernel module not loaded (sdhci-xenon-esdhc) + - Check 'lsblk' output for available devices" +fi + +log "Detected eMMC: $EMMC_DEVICE" + # CRITICAL: Don't flash if running from eMMC -if [[ "$BOOT_DEVICE" == "$EMMC_DEVICE" ]]; then +if [[ "$BOOT_DEVICE" == "$EMMC_DEVICE" ]] || [[ "$BOOT_DEVICE" == "${EMMC_DEVICE}p"* ]]; then err "SAFETY STOP: Currently booted from eMMC ($EMMC_DEVICE)! You cannot flash the eMMC while running from it. Please boot from USB drive first, then run this script." fi -# Check if eMMC exists +# Verify eMMC is accessible if [[ ! -b "$EMMC_DEVICE" ]]; then - err "eMMC device not found: $EMMC_DEVICE - - This could mean: - - No eMMC installed on this board - - Wrong device path (check with 'lsblk') - - Kernel module not loaded (sdhci-xenon)" + err "eMMC device not accessible: $EMMC_DEVICE" fi # ── Find image ────────────────────────────────────────────────────── diff --git a/packages/secubox-haproxy/debian/secubox-haproxy.service b/packages/secubox-haproxy/debian/secubox-haproxy.service index a85194c7..354ac90d 100644 --- a/packages/secubox-haproxy/debian/secubox-haproxy.service +++ b/packages/secubox-haproxy/debian/secubox-haproxy.service @@ -21,7 +21,8 @@ RestartSec=5 NoNewPrivileges=true RuntimeDirectory=secubox RuntimeDirectoryMode=0775 -ReadWritePaths=/run/secubox /var/lib/secubox /etc/secubox /etc/haproxy /run/haproxy +# ReadWritePaths removed - causes NAMESPACE errors when haproxy not installed +# (haproxy is Recommends, not Depends - /etc/haproxy may not exist) [Install] WantedBy=multi-user.target