Fix WiFi conflict and SSH accessibility on fresh flash
- Remove wpa_supplicant@wlan0.service enablement: Netplan spawns its own wpa_supplicant instance, enabling the @wlan0 unit creates a second one that fights for the socket, causing WiFi instability and SSH drops - Write /etc/nftables.conf to card at flash time: Armbian bookworm default nftables policy drops all input; SSH was unreachable despite sshd running. Ruleset allows established, loopback, ICMP, and TCP/22 only Fixes DevTrack #317 and #295
This commit is contained in:
+25
-9
@@ -525,15 +525,6 @@ DHCP=yes
|
|||||||
IPv6PrivacyExtensions=yes
|
IPv6PrivacyExtensions=yes
|
||||||
EOF
|
EOF
|
||||||
|
|
||||||
# Enable wpa_supplicant@wlan0 if the template service exists
|
|
||||||
WPA_TEMPLATE="${MOUNT_POINT}/lib/systemd/system/wpa_supplicant@.service"
|
|
||||||
WPA_WANTS="${MOUNT_POINT}/etc/systemd/system/multi-user.target.wants"
|
|
||||||
if [[ -f "$WPA_TEMPLATE" ]]; then
|
|
||||||
mkdir -p "$WPA_WANTS"
|
|
||||||
ln -sf /lib/systemd/system/wpa_supplicant@.service \
|
|
||||||
"${WPA_WANTS}/wpa_supplicant@wlan0.service"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Disable the generic wpa_supplicant.service — it conflicts with @wlan0 instance
|
# Disable the generic wpa_supplicant.service — it conflicts with @wlan0 instance
|
||||||
# Both would fight over wlan0, causing WiFi instability and SSH drops
|
# Both would fight over wlan0, causing WiFi instability and SSH drops
|
||||||
rm -f "${MOUNT_POINT}/etc/systemd/system/multi-user.target.wants/wpa_supplicant.service"
|
rm -f "${MOUNT_POINT}/etc/systemd/system/multi-user.target.wants/wpa_supplicant.service"
|
||||||
@@ -598,6 +589,31 @@ chmod 700 "$SSH_DIR"
|
|||||||
chmod 600 "${SSH_DIR}/authorized_keys"
|
chmod 600 "${SSH_DIR}/authorized_keys"
|
||||||
info "SSH authorized_keys configured"
|
info "SSH authorized_keys configured"
|
||||||
|
|
||||||
|
# Ensure SSH is allowed through nftables (Armbian default drops input)
|
||||||
|
step "Configuring nftables firewall..."
|
||||||
|
cat > "${MOUNT_POINT}/etc/nftables.conf" << 'NFTEOF'
|
||||||
|
#!/usr/sbin/nft -f
|
||||||
|
flush ruleset
|
||||||
|
|
||||||
|
table inet filter {
|
||||||
|
chain input {
|
||||||
|
type filter hook input priority 0; policy drop;
|
||||||
|
ct state established,related accept
|
||||||
|
iif lo accept
|
||||||
|
ip protocol icmp accept
|
||||||
|
ip6 nexthdr icmpv6 accept
|
||||||
|
tcp dport 22 accept
|
||||||
|
}
|
||||||
|
chain forward {
|
||||||
|
type filter hook forward priority 0; policy drop;
|
||||||
|
}
|
||||||
|
chain output {
|
||||||
|
type filter hook output priority 0; policy accept;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
NFTEOF
|
||||||
|
info "nftables config written (SSH allowed)"
|
||||||
|
|
||||||
# Hostname
|
# Hostname
|
||||||
step "Setting hostname..."
|
step "Setting hostname..."
|
||||||
echo "$BB_HOSTNAME" > "${MOUNT_POINT}/etc/hostname"
|
echo "$BB_HOSTNAME" > "${MOUNT_POINT}/etc/hostname"
|
||||||
|
|||||||
Reference in New Issue
Block a user