Page MenuHomeVyOS Platform

firewall remote-group downloader errors if HEAD method is not supported
Closed, ResolvedPublic

Description

The remote.py downloader used for firewall remote-groups aborts if HEAD is not successful. Head is used to retrieve content-length, which can also be retrieved from the GET headers.

Observing the error requires code modification. vyos-domain-resolver does not log or in any way indicate a reason for filter.

Details

Version
-
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Unspecified (please specify)

Event Timeline

HttpC.download() in python/vyos/remote.py always sends a HEAD request before GET to discover redirects and Content-Length. Some remote APIs (notably AbuseIPDB blocklist endpoints) reject HEAD with 405 Method Not Allowed while GET works fine. vyos-domain-resolver catches the failure and falls back to the cached list file — which on first commit is an empty placeholder — so remote-groups stay at 0 members.

Fix

PR: https://github.com/vyos/vyos-1x/pull/5275

Changes:
• python/vyos/remote.py — treat HEAD 405/501 as "HEAD not supported" and proceed with GET; recover Content-Length from GET headers when HEAD didn't provide it; re-run check_storage() once size is known from GET
• src/services/vyos-domain-resolver — log download failures without exposing API keys/tokens from exception messages (class name at error level, full traceback at debug)
• src/tests/test_remote.py — unit tests with mock servers returning 405/501 on HEAD and 200 on GET

Testing

• Unit tests pass locally (405 + 501 fallback paths)
• PR CI: lint/typos/CLA green; ISO build pending
• Smoketest remote-group tests not run locally (QEMU harness)

Real-world impact

Unblocks firewall remote-group URLs that only support GET (e.g. AbuseIPDB). Servers that accept HEAD are unaffected.

Viacheslav changed the task status from Open to In progress.Jun 16 2026, 11:35 AM
Viacheslav moved this task from Need Triage to Completed on the VyOS Rolling board.