Page MenuHomeVyOS Platform

stuck on configure after commit hang
Needs testing, NormalPublicBUG

Description

Hi,

during some tests for T8883 I've made a mistake in configuration giving these 2 commands:

set protocols static route <redacted_ip>/32 blackhole
set protocols static route <redacted_ip>/32 next-hop 2.2.2.2 vrf mgmt

wanting to put the redacted_ip/32 in the "mgmt" vrf (but there's no option after the blackhole command to select a vrf)

Note, i have an interface direcly connected on the <redacted_ip>/24 network, so command correctly didn't worked

I tried to commit, and it hangs indefinitely (5+ minutes while usually it takes around 10 secs), so i CTRL+Z to exit, and after that i'm stuck in the configure subsection.
If i try to give any command or exit I get this (i tried to text show protocols, but tabbed ad show pro)

show proDEBUG vexit_internal: calling getCompletionEnv() without config session
calling getCompletionEnv() without config session
DEBUG vexit_internal: calling getCompletionEnv() without config session
calling getCompletionEnv() without config session
DEBUG vexit_internal: calling getCompletionEnv() without config session
calling getCompletionEnv() without config session

I can't exit, but if i enter with a new vty session i can enter configuration.

If i then try to delete, for example, second command, it starts to hang indefinitely again

Version:
Extended version:
Version: VyOS 2026.03
Release train: circinus
Release flavor: generic

Built by: autobuild@vyos.net
Built on: Wed 18 Mar 2026 20:03 UTC
Build UUID: 3969e1c7-a4bb-459a-ac7f-54749c153d21
Build commit ID: 1cac4fd63750b0

Details

Version
2026.03 circinus
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)

Event Timeline

I do not see 5 minutes hang, but I see this configuration is incorrect for FRR

set vrf name mgmt table '123'
set interfaces dummy dum0 address '192.0.2.14/24'
set interfaces dummy dum0 vrf 'mgmt'
set interfaces ethernet eth1 address '192.168.122.111/24'
set interfaces ethernet eth1 vrf 'mgmt'

set protocols static route 192.0.2.99/32 blackhole
set protocols static route 192.0.2.99/32 next-hop 192.168.122.1 vrf 'mgmt'
commit

Commit:

vyos@r14# commit
[ protocols static ]
[3645|mgmtd] sending configuration [3646|zebra] sending configuration
[3647|ripd] sending configuration [3648|ripngd] sending configuration
[3649|ospfd] sending configuration [3650|ospf6d] sending configuration
[3651|ldpd] sending configuration [3646|zebra] done [3652|bgpd] sending
configuration [3649|ospfd] done [3648|ripngd] done [3647|ripd] done
[3653|isisd] sending configuration [3655|nhrpd] sending configuration
[3650|ospf6d] done [3651|ldpd] done [3657|babeld] sending configuration
[3652|bgpd] done [3659|fabricd] sending configuration [3661|staticd]
sending configuration [3657|babeld] done [3655|nhrpd] done
[3659|fabricd] done % Configuration failed.  commit failed session-id 50
on Unknown-FD-16 req-id 3 source-ds: candidate target-ds: running
validate-only: 0: reason: 'Failed to create cfgdata: Route cannot have
blackhole and non-blackhole nexthops simultaneously' [3645|mgmtd]
Configuration file[/etc/frr/frr.conf] processing failure: 13
[3665|pim6d] sending configuration Waiting for children to finish
applying config... [3666|watchfrr] sending configuration [3653|isisd]
done [3662|bfdd] sending configuration [3664|pathd] sending
configuration [3661|staticd] done [3662|bfdd] done [3665|pim6d] done
[3664|pathd] done [3666|watchfrr] done [3670|mgmtd] sending
configuration [3671|zebra] sending configuration [3672|ripd] sending
configuration [3673|ripngd] sending configuration [3674|ospfd] sending
configuration [3675|ospf6d] sending configuration [3673|ripngd] done
[3677|bgpd] sending configuration [3678|isisd] sending configuration
[3676|ldpd] sending configuration [3674|ospfd] done [3672|ripd] done
[3671|zebra] done [3684|fabricd] sending configuration [3682|babeld]
sending configuration [3680|nhrpd] sending configuration [3686|staticd]
sending configuration [3678|isisd] done [3689|pathd] sending
configuration Waiting for children to finish applying config...
[3675|ospf6d] done [3687|bfdd] sending configuration [3690|pim6d]
sending configuration [3691|watchfrr] sending configuration [3677|bgpd]
done [3682|babeld] done [3690|pim6d] done [3684|fabricd] done
[3680|nhrpd] done [3687|bfdd] done [3689|pathd] done [3676|ldpd] done
[3686|staticd] done [3691|watchfrr] done % Configuration failed.  commit
failed session-id 52 on Unknown-FD-16 req-id 3 source-ds: candidate
target-ds: running validate-only: 0: reason: 'Failed to create cfgdata:
Route cannot have blackhole and non-blackhole nexthops simultaneously'
[3670|mgmtd] Configuration file[/etc/frr/frr.conf] processing failure:
13
[[protocols static]] failed
Commit failed
[edit]
vyos@r14#

@noc.tlc, it would be helpful if you could provide a minimal set of commands to reproduce. It will save developers and the QA team a lot of time.
It is not clear whether you faced this issue or another one.

Hi,

ofc. This is the whole configuration:

set firewall global-options send-redirects 'disable'
set firewall ipv4 input filter default-action 'drop'
set firewall ipv4 input filter rule 1 action 'accept'
set firewall ipv4 input filter rule 1 protocol 'icmp'
set firewall ipv4 input filter rule 10 action 'accept'
set firewall ipv4 input filter rule 10 inbound-interface name 'lo'
set interfaces dummy dum1
set interfaces ethernet eth0 address '192.168.88.175/24'
set interfaces ethernet eth0 description 'redacted'
set interfaces ethernet eth0 hw-id 'redacted'
set interfaces ethernet eth0 vrf 'mgmt'

set interfaces loopback lo address '192.168.88.175/32'
set policy local-route rule 10 destination address '192.168.88.28'
set policy local-route rule 10 destination port '1812'
set policy local-route rule 10 protocol 'udp'
set policy local-route rule 10 set vrf 'mgmt'
set policy local-route rule 20 destination address '192.168.88.28'
set policy local-route rule 20 destination port '1813'
set policy local-route rule 20 protocol 'udp'
set policy local-route rule 20 set vrf 'mgmt'

set protocols static

set service pppoe-server accept-any-service
set service pppoe-server accept-blank-service
set service pppoe-server access-concentrator 'en-PA-bras04-VyOS'
set service pppoe-server authentication mode 'radius'
set service pppoe-server authentication protocols 'pap'
set service pppoe-server authentication radius accounting-interim-interval '3600'
set service pppoe-server authentication radius called-sid-format 'ifname'
set service pppoe-server authentication radius nas-identifier 'KIT-PA'
set service pppoe-server authentication radius preallocate-vif
set service pppoe-server authentication radius server ip_radius1 acct-port '1813'
set service pppoe-server authentication radius server ip_radius1 backup
set service pppoe-server authentication radius server ip_radius1 fail-time '10'
set service pppoe-server authentication radius server ip_radius1 key 'En3g4nT!C'
set service pppoe-server authentication radius server ip_radius1 port '1812'
set service pppoe-server authentication radius server 192.168.88.28 acct-port '1813'
set service pppoe-server authentication radius server 192.168.88.28 fail-time '10'
set service pppoe-server authentication radius server 192.168.88.28 key 'En3g4nT!C'
set service pppoe-server authentication radius server 192.168.88.28 port '1812'
set service pppoe-server gateway-address 'redacted'
set service pppoe-server interface eth2.91 combined
set service pppoe-server interface eth2.91 vlan '2-100'
set service pppoe-server interface eth2.91 vlan-mon
set service pppoe-server interface eth2.92 vlan '101-4094'
set service pppoe-server interface eth2.92 vlan-mon
set service pppoe-server log level '3'
set service pppoe-server name-server 'redacted'
set service pppoe-server name-server 'redacted'
set service pppoe-server pado-delay 250
set service pppoe-server ppp-options disable-ccp
set service pppoe-server service-name 'redacted'
set service pppoe-server snmp

set system ipv6 disable-forwarding
set system option keyboard-layout 'it'
set system option reboot-on-upgrade-failure '5'

set vrf bind-to-all
set vrf name mgmt protocols static route redacted/24 next-hop 192.168.88.254
set vrf name mgmt protocols static route redacted/24 next-hop 192.168.88.254
set vrf name mgmt table '100'
set vrf name vrf-OOB protocols static route redacted/24
set vrf name vrf-OOB protocols static route redacted/27 next-hop redacted
set vrf name vrf-OOB table '110'

Given the networks these ars the above commands i did:

set protocols static route 192.168.88.28/32 blackhole
set protocols static route 192.168.88.28/32 next-hop 2.2.2.2 vrf mgmt

You'll find a curious configuration, on the lo address due to the lack of a source-interface command for radius and the fact it's not working on vrf mgmt without binding accel-ppp on vrf (which we cannot)

Viacheslav changed the task status from Open to Needs testing.May 20 2026, 1:09 PM
c-po triaged this task as Normal priority.May 25 2026, 6:29 AM