Page MenuHomeVyOS Platform
Feed All Stories

May 21 2020

c-po committed rVYOSONEXe7ebf1c54c26: pppoe: wwan: T2488: drop individual ppp logs.
May 21 2020, 4:45 PM
c-po changed the status of T2488: Remove logfile for dialup interfaces like pppoe and wwan from Open to In progress.
May 21 2020, 4:42 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T2488: Remove logfile for dialup interfaces like pppoe and wwan.
May 21 2020, 4:42 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T2380: After PPPoE 0 is restarted, the default static route is lost from Open to Confirmed.
May 21 2020, 4:37 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2380: After PPPoE 0 is restarted, the default static route is lost.

@jack9603301 bumping tasks won't make it faster - it usually has the opposite effect

May 21 2020, 4:33 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEX2c9bbd821d6c: wireless: T1627: remove get_conf_file().
May 21 2020, 4:21 PM
c-po committed rVYOSONEXe12390d75b5e: macsec: T2023: delete wpa_supplicant config when interface is removed.
May 21 2020, 4:21 PM
c-po moved T2375: WireGuard: throw exception if address and port are not given as both are mandatory from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:18 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2382: salt-minion: Throws KeyError on commit from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:17 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2384: salt-minion: log to syslog and remove custom logging option from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:17 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2383: Update Linux Kernel to v4.19.118 from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:17 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2385: salt-minion: improve completion helpers from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
c-po moved T2386: salt: upgrade to 2019.2 packages from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2392: SSTP with ipv6 from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
c-po moved T2393: dhclient: migrate from SysVinit to systemd from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2394: dhcpv6 client does not start from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2398: op-mode "dhcp client leases interface" completion helper misses interfaces from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
c-po moved T2399: op-mode "dhcp client leases" does not return leases from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2406: DHCPv6 CLI improvements from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
c-po moved T2411: op-mode: make "monitor traceroute" VRF aware from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2412: ping flood does not work as unprivileged user from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2413: Update Linux Kernel to v4.19.119 from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2414: Improve runtime from Python numeric validator from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2421: Update WireGuard to Debian release 1.0.20200429-2_bpo10+1 from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2420: Update Linux Kernel to v4.19.120 from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2429: Vyos cannot apply VLAN sub interface to bridge from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2439: Configuration dependency problem, unable to load complex configuration after reboot from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2446: VRF IPv6 static routes subnet deletion from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2445: VRF route leaking for ipv4 not working from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:15 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2454: Update Linux Kernel to v4.19.122 from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:15 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2456: netflow source-ip cannot be configured from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:15 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2471: PPPoE server: always add AdvAutonomousFlag when IPv6 is configured from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:15 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2470: Update to PowerDNS recursor 4.3 from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:15 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2469: Update Linux Kernel to v4.19.123 from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:15 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2480: NAT: after rewrite commit tells that dnat IP address is not locally connected from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:15 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2481: WireGuard: support tunnel via IPv6 underlay from Need Triage to Finished on the VyOS 1.3 Equuleus board.
May 21 2020, 4:15 PM · VyOS 1.3 Equuleus (1.3.0)
c-po merged T1493: PPPoE IPv6 prefix delegation into T421: Add Pv6 prefix delegation support.
May 21 2020, 3:25 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po merged task T1493: PPPoE IPv6 prefix delegation into T421: Add Pv6 prefix delegation support.
May 21 2020, 3:25 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXf8e2d8acd8a0: macsec: T2023: stop wpa_supplicant on interface deletion.
May 21 2020, 3:24 PM
jjakob added a comment to T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.
In T2486#64335, @jjakob wrote:

Also, this is reproducible with pdns-recursor from upstream master (4.4.0) so upgrading won't help.

May 21 2020, 2:53 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2023: Add support for 802.1ae MACsec as Resolved.
May 21 2020, 2:10 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXab29e70bdd5b: Merge branch 'macsec-t2023' of github.com:c-po/vyos-1x into current.
May 21 2020, 2:09 PM
c-po committed rVYOSONEX2417c2feedd6: macsec: T2023: support MACsec Key Agreement protocol actor priority.
May 21 2020, 2:09 PM
c-po committed rVYOSONEX5df7e8f35234: macsec: T2023: cleanup wpa_supplicant config file name.
May 21 2020, 2:09 PM
c-po committed rVYOSONEXd8d3c1cb5a5a: macsec: T2023: improve verify() when encryption is enabled.
May 21 2020, 2:09 PM
c-po committed rVYOSONEX68d54d8d79f2: macsec: T2023: rename "security key" node to "security mka".
May 21 2020, 2:09 PM
c-po committed rVYOSONEX3872f5995644: macsec: T2023: use wpa_supplicant for key management.
May 21 2020, 2:09 PM
c-po committed rVYOSONEX5cde2142a253: macsec: T2023: extend key generator for CAK and CKN in operation mode.
May 21 2020, 2:09 PM
c-po committed rVYOSONEX63a3110298e5: macsec: T2023: cli: move "cipher" and "encryption" under new "secutiry" node.
May 21 2020, 2:09 PM
c-po committed rVYOSONEXf48f19063561: macsec: T2023: remove gcm-aes-256 cipher type.
May 21 2020, 2:09 PM
c-po committed rVYOSONEX576951171b25: macsec: T2023: cipher suite is mandatory.
May 21 2020, 2:09 PM
c-po committed rVYOSONEX4a0c0b4e041d: macsec: T2023: use list when working with Config().
May 21 2020, 2:09 PM
c-po committed rVYOSONEX04d03f5bdd26: macsec: T2023: add optional encryption command.
May 21 2020, 2:09 PM
c-po committed rVYOSONEXe9c9af90a8ee: macsec: T2023: add 'show interfaces macsec' op-mode tree.
May 21 2020, 2:09 PM
c-po committed rVYOSONEX5038eb5856b8: macsec: T2023: generate secure channel keys in operation mode.
May 21 2020, 2:09 PM
c-po committed rVYOSONEX2e8bd0ced896: ifconfig: T2023: add initial MACsec abstraction.
May 21 2020, 2:09 PM
c-po committed rVYOSONEXfe9d399a4e78: macsec: T2023: add initial XML and Python interfaces.
May 21 2020, 2:09 PM
c-po committed rVYOSONEX0f98642dfbc6: interface: T2023: adopt _delete() to common style.
May 21 2020, 2:09 PM
c-po committed rVYOSONEX3f932b66a552: interface: T2023: remove superfluous at end of list.
May 21 2020, 2:09 PM
c-po committed rVYOSONEXd457ef195293: macvlan: T2023: prepare common source interface include file.
May 21 2020, 2:09 PM
c-po added a comment to T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.

Latest rolling runs PowerDNS recursor 4.3 T2470

May 21 2020, 12:28 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.

Although I wanted to try it out, it seems the best way is to try to upgrade to the latest stable version. From the perspective of version management, the higher version often fixes some existing bugs, while the stable version ensures sufficient testing to avoid 0days.

May 21 2020, 12:17 PM · VyOS 1.3 Equuleus (1.3.0)
thomas-mangin added a comment to T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.
vyos@vyos:~$ dpkg -l | grep pdns
ii  pdns-recursor                    4.2.1-1pdns.buster                  amd64        PowerDNS Recursor
May 21 2020, 12:00 PM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T2023: Add support for 802.1ae MACsec.
May 21 2020, 11:47 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.

@jjakob I'm sorry, but I think you may have misunderstood me. I just summarized the problems that can be solved at present. Of course, this patch can finally be submitted to PDNS. Relatively speaking, the current solution to the problem may be the first priority, and there are only two main ways to solve the problem, either to solve it or to bypass it.

May 21 2020, 11:41 AM · VyOS 1.3 Equuleus (1.3.0)
jjakob added a comment to T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.

I can summarize the following solutions, and maybe there are other solutions:
a) Fix the bug yourself
b) Use other storage mechanisms to resolve records to bypass
c) Self parsing hosts

May 21 2020, 11:40 AM · VyOS 1.3 Equuleus (1.3.0)
jjakob added a comment to T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.

If you mean we should maintain our own fork of powerdns, I'm against that. PowerDNS is open source and anyone can submit patches to it the same as VyOS. If you want to try fixing the bug in pdns-recursor, you can clone pdns, debug it, build it, test it and submit the patch at https://github.com/PowerDNS/pdns . Of course you have to oblige by their contribution guidelines that are listed there. They also have a IRC channel at OFTC #powerdns .

May 21 2020, 11:35 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.

I can summarize the following solutions, and maybe there are other solutions:
a) Fix the bug yourself
b) Use other storage mechanisms to resolve records to bypass
c) Self parsing hosts

May 21 2020, 11:32 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.

Alas, it's really a troublesome problem. If it's a bug, I haven't used pdns-recursor. I usually use ISC bind, but I have a solution different from the one you put forward. It is based on the independent maintenance of open source branches, looking for the code with problems and implementing the patch. @jjakob

May 21 2020, 11:25 AM · VyOS 1.3 Equuleus (1.3.0)
jjakob added a comment to T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.

You mean that when pdns-recursor recursively forwards the request to the back-end recursive parsing service, the static entries in the query / etc / hosts will always return NXDOMAIN?

May 21 2020, 11:19 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.

You mean that when pdns-recursor forwards the query to the back-end recursive parsing service for the first time, after that, the static entries in query /etc/hosts will always return NODOMAIN.

May 21 2020, 11:00 AM · VyOS 1.3 Equuleus (1.3.0)
jjakob added a comment to T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.

The full description and way to reproduce is at https://github.com/PowerDNS/pdns/issues/9136 since this is a pdns-recursor bug. But in essence, after pdns-recursor startup or restart, requests that come in to pdns-recursor (service dns forwarding in VyOS) for a domain from /etc/hosts work normally. Then a request for any other domain comes in, that gets forwarded via forward-zones-recurse (service dns forwarding name-server), for example google.com, that request gets resolved without errors, but causes this bug to manifest. After that, a request for any hostname from /etc/hosts returns NXDOMAIN.

May 21 2020, 10:52 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.

via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone

May 21 2020, 10:17 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2023: Add support for 802.1ae MACsec.

This is a 1300 byte ping running through a MACsec connection with wpa_supplicant for key management.

May 21 2020, 10:08 AM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T2023: Add support for 802.1ae MACsec.
May 21 2020, 10:07 AM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T2023: Add support for 802.1ae MACsec.
May 21 2020, 9:33 AM · VyOS 1.3 Equuleus (1.3.0)
jjakob updated the task description for T2054: Changing "system name-server" doesn't update dns forwarding config, neither does "restart dns forwarding".
May 21 2020, 9:31 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) closed T1876: IPSec VTI tunnels are deleted after rekey and dangling around as A/D as Resolved.
May 21 2020, 9:29 AM · VyOS 1.3 Equuleus (1.3.0)
jjakob renamed T2463: DHCP-received nameserver not added to vyos-hostsd from DHCP-received nameserver not added to vyos-hostsd (with T2409 patch) to DHCP-received nameserver not added to vyos-hostsd.
May 21 2020, 9:26 AM · VyOS 1.3 Equuleus (1.3.0)
Merijn added a comment to T2214: BGP peers dropping randomly.

Just to confirm, increasing the route,max_size fixed this issue completely. I think it can be closed. But maybe we should set these settings by default before closing this.

May 21 2020, 9:10 AM · VyOS 1.2 Crux
Unknown Object (User) closed T2364: Add CLI command for mroute , a subtask of T1729: PIM (Protocol Independent Multicast) implementation, as Resolved.
May 21 2020, 9:06 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
Unknown Object (User) closed T2364: Add CLI command for mroute as Resolved.
May 21 2020, 9:06 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) closed T1820: VRRP transition scripts for sync-groups are not supported in VyOS (anymore) as Resolved.

Tested on 1.3-rolling-202005210117, works properly

May 21 2020, 9:04 AM · VyOS 1.3 Equuleus (1.3.0)
jjakob added a comment to T2476: Bond member description change leads to network outage.

I think the way to do this is in src/conf-mode/interfaces-ethernet.py in apply(), don't change the interfaces mac if eth['is_bond_member'] is set.

May 21 2020, 8:40 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
c-po updated the task description for T2023: Add support for 802.1ae MACsec.
May 21 2020, 8:28 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) created T2487: VRRP does not display info when group disabled.
May 21 2020, 8:06 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) closed T2342: Bridge l2tpv3 + ethX errors as Resolved.
May 21 2020, 6:59 AM · VyOS 1.2 Crux (VyOS 1.2.6)

May 20 2020

jjakob added a subtask for T2464: DNS bugs (parent task): T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.
May 20 2020, 10:17 PM · VyOS Rolling
jjakob added a parent task for T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone: T2464: DNS bugs (parent task).
May 20 2020, 10:17 PM · VyOS 1.3 Equuleus (1.3.0)
jjakob triaged T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone as High priority.
May 20 2020, 10:17 PM · VyOS 1.3 Equuleus (1.3.0)
jjakob added a subtask for T2464: DNS bugs (parent task): T2465: DHCP isn't updating host file when hostfile-update enabled..
May 20 2020, 10:14 PM · VyOS Rolling
jjakob added a parent task for T2465: DHCP isn't updating host file when hostfile-update enabled.: T2464: DNS bugs (parent task).
May 20 2020, 10:14 PM
kroy changed the status of T2483: DHCP most likely not restarting pdns_recursor, a subtask of T2465: DHCP isn't updating host file when hostfile-update enabled., from In progress to Needs testing.
May 20 2020, 8:13 PM
kroy changed the status of T2483: DHCP most likely not restarting pdns_recursor from In progress to Needs testing.

This PR419 should take care of this and the parent task

May 20 2020, 8:13 PM · VyOS 1.3 Equuleus (1.3.0)
thomas-mangin claimed T2431: Python validators are slow.
May 20 2020, 7:53 PM · VyOS 1.3 Equuleus (1.3.6)
c-po added a comment to T103: DHCP server prepends shared network name to hostnames.

@richardpowellus you could test it on an 1.2.5 system by running the following commands:

May 20 2020, 7:52 PM · VyOS 1.2 Crux (VyOS 1.2.6)
thomas-mangin added a comment to T2431: Python validators are slow.

related to T2088 where performance is also being discussed.

May 20 2020, 7:52 PM · VyOS 1.3 Equuleus (1.3.6)
thomas-mangin claimed T2407: alternate installation for the vyos-1x python code.
May 20 2020, 7:51 PM
c-po closed T103: DHCP server prepends shared network name to hostnames, a subtask of T2464: DNS bugs (parent task), as Resolved.
May 20 2020, 7:50 PM · VyOS Rolling
c-po closed T103: DHCP server prepends shared network name to hostnames as Resolved.
May 20 2020, 7:50 PM · VyOS 1.2 Crux (VyOS 1.2.6)