Page MenuHomeVyOS Platform
Feed All Stories

Aug 10 2021

c-po assigned T3732: override-default helper should support adding defaultValues to default less nodes to jestabro.
Aug 10 2021, 6:55 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po created T3732: override-default helper should support adding defaultValues to default less nodes.
Aug 10 2021, 6:55 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Aug 9 2021

Unknown Object (User) added a comment to T3731: verify_accel_ppp_base_service return wrong config error for SSP.

PR for Equuleus https://github.com/vyos/vyos-1x/pull/959

Aug 9 2021, 9:08 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Unknown Object (User) changed the status of T3731: verify_accel_ppp_base_service return wrong config error for SSP from Open to In progress.
Aug 9 2021, 8:55 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Unknown Object (User) created T3731: verify_accel_ppp_base_service return wrong config error for SSP.
Aug 9 2021, 8:54 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po assigned T3727: VPN IPsec ESP proposal and ESP presented in config missmatch to sarthurdev.
Aug 9 2021, 7:17 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T3730: op-mode conntrack-sync miss some functions: test.
Aug 9 2021, 7:08 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav changed the status of T3730: op-mode conntrack-sync miss some functions from Open to Needs testing.
Aug 9 2021, 7:07 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po edited a custom field on T3720: IPSec set vti secondary address cause interface disable.
Aug 9 2021, 7:06 PM · VyOS 1.4 Sagitta
c-po closed T3720: IPSec set vti secondary address cause interface disable, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Aug 9 2021, 7:06 PM · VyOS 1.4 Sagitta
c-po closed T3720: IPSec set vti secondary address cause interface disable as Resolved.
Aug 9 2021, 7:06 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX96049e6fdad0: ipsec: T3720: assigning vti secondary address caused interface in A/D state.
Aug 9 2021, 7:04 PM
GitHub <noreply@github.com> committed rVYOSONEX3203f2a6d495: Merge pull request #958 from sever-sever/T3730 (authored by jestabro).
Aug 9 2021, 6:56 PM
Viacheslav committed rVYOSONEX852d056fbd6a: template: T3730: Add bracketize_ipv6 filter.
Aug 9 2021, 6:56 PM
Viacheslav added a comment to T3730: op-mode conntrack-sync miss some functions.

PR https://github.com/vyos/vyos-1x/pull/958

Aug 9 2021, 6:45 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav claimed T3730: op-mode conntrack-sync miss some functions.
Aug 9 2021, 6:34 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav added a comment to T3730: op-mode conntrack-sync miss some functions.
  • Backport configquerry.py [Done]

https://github.com/vyos/vyos-1x/commit/2aa75521a829712256c3c34685e60a9d36b33791

Aug 9 2021, 6:21 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
paunadeu added a comment to T3728: FRR not respect configured RD and RT for L3VNI.

Need to implement in customer, if I can help in something, please don't hesitate to ask.

Aug 9 2021, 6:15 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3728: FRR not respect configured RD and RT for L3VNI.

Maybe with FRR 8.1
In any case, we'll do more tests.

Aug 9 2021, 6:13 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEX2aa75521a829: configquery: T3402: add library for querying config values from op mode.
Aug 9 2021, 5:11 PM
jestabro added a project to T3402: Add VyOS programming library for operational level commands: VyOS 1.3 Equuleus.
Aug 9 2021, 5:03 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav created T3730: op-mode conntrack-sync miss some functions.
Aug 9 2021, 4:38 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
paunadeu added a comment to T3728: FRR not respect configured RD and RT for L3VNI.

It's upgrade on FRR planned?

Aug 9 2021, 2:48 PM · VyOS 1.4 Sagitta
UnicronNL closed T1501: VPN Commit Errors, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Aug 9 2021, 2:09 PM · VyOS 1.4 Sagitta
UnicronNL closed T1501: VPN Commit Errors as Resolved.

https://github.com/vyos/vyatta-cfg-vpn/commit/2cec760601a6e85ca8e0b6a30c173196a97a777a
Back-ported the dhcp ip check loop to 1.3

Aug 9 2021, 2:09 PM · VyOS 1.3 Equuleus (1.3.0), test
dmbaturin renamed T3729: Split the image build and config load smoke test into separate jobs from Separate the image build and config load smoke test into separate jobs to Split the image build and config load smoke test into separate jobs.
Aug 9 2021, 1:46 PM
dmbaturin added projects to T3729: Split the image build and config load smoke test into separate jobs: VyOS 1.3 Equuleus, VyOS 1.4 Sagitta.
Aug 9 2021, 1:45 PM
dmbaturin created T3729: Split the image build and config load smoke test into separate jobs.
Aug 9 2021, 1:45 PM
Viacheslav edited a custom field on T3728: FRR not respect configured RD and RT for L3VNI.
Aug 9 2021, 1:18 PM · VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEXe737bac9fc8c: dhcp-server: T2432: Run dhcpd in group vyattacfg to allow recreate lease files (authored by Unknown Object (User)).
Aug 9 2021, 1:04 PM
paunadeu added a comment to T3728: FRR not respect configured RD and RT for L3VNI.
Aug 9 2021, 1:00 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3728: FRR not respect configured RD and RT for L3VNI.

It is possible this bug.
https://github.com/FRRouting/frr/issues/9181

Aug 9 2021, 12:51 PM · VyOS 1.4 Sagitta
paunadeu added a comment to T3728: FRR not respect configured RD and RT for L3VNI.

Take a look to:

Aug 9 2021, 12:37 PM · VyOS 1.4 Sagitta
paunadeu created T3728: FRR not respect configured RD and RT for L3VNI.
Aug 9 2021, 12:37 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3537: Unable to override the default OSPFv3 link cost for wireguard interface.

@dtoux Did you test it in 1.3.0-rc5?

Aug 9 2021, 12:18 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav assigned T3677: "sipcalc" not included in 1.3 to dmbaturin.
Aug 9 2021, 12:11 PM · VyOS 1.3 Equuleus (1.3.0), test
Viacheslav added a comment to T3717: BGP Peer group without 'remote-as' gives shell error.

@xrobau As I mentioned before, peer-group can't exist without peer-as/remote-as in your case remote-as should be internal. It can exist without remote-as but with "route-reflector-client" it shouldn't
You can check it with vtysh FRR:

Aug 9 2021, 12:06 PM · VyOS 1.3 Equuleus (1.3.0), vyos-frr
Unknown Object (User) closed T2776: QAT acceleration not working for IPSec AES-128 (CBC) / SHA256 tunnel as Invalid.
Aug 9 2021, 11:17 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
Unknown Object (User) added a comment to T2776: QAT acceleration not working for IPSec AES-128 (CBC) / SHA256 tunnel .

Tested on 1.3-rc5, all works properly

set vpn ipsec esp-group ESP_DEFAULT compression 'disable'
set vpn ipsec esp-group ESP_DEFAULT lifetime '3600'
set vpn ipsec esp-group ESP_DEFAULT mode 'tunnel'
set vpn ipsec esp-group ESP_DEFAULT pfs 'dh-group19'
set vpn ipsec esp-group ESP_DEFAULT proposal 10 encryption 'aes128'
set vpn ipsec esp-group ESP_DEFAULT proposal 10 hash 'sha256'
set vpn ipsec ike-group IKEv2_DEFAULT close-action 'none'
set vpn ipsec ike-group IKEv2_DEFAULT dead-peer-detection action 'hold'
set vpn ipsec ike-group IKEv2_DEFAULT dead-peer-detection interval '30'
set vpn ipsec ike-group IKEv2_DEFAULT dead-peer-detection timeout '120'
set vpn ipsec ike-group IKEv2_DEFAULT ikev2-reauth 'no'
set vpn ipsec ike-group IKEv2_DEFAULT key-exchange 'ikev2'
set vpn ipsec ike-group IKEv2_DEFAULT lifetime '10800'
set vpn ipsec ike-group IKEv2_DEFAULT mobike 'disable'
set vpn ipsec ike-group IKEv2_DEFAULT proposal 10 dh-group '19'
set vpn ipsec ike-group IKEv2_DEFAULT proposal 10 encryption 'aes128'
set vpn ipsec ike-group IKEv2_DEFAULT proposal 10 hash 'sha256'

Flow served QAT

vyos@R2-QAT#  run show system acceleration qat device qat_dev0 flows 
+------------------------------------------------+
| FW Statistics for Qat Device                   |
+------------------------------------------------+
| Firmware Requests [AE  0]:               60046 |
| Firmware Responses[AE  0]:               60046 |
+------------------------------------------------+
| Firmware Requests [AE  1]:              112720 |
| Firmware Responses[AE  1]:              112720 |
+------------------------------------------------+
| Firmware Requests [AE  2]:              219657 |
| Firmware Responses[AE  2]:              219657 |
+------------------------------------------------+
| Firmware Requests [AE  3]:               60046 |
| Firmware Responses[AE  3]:               60046 |
+------------------------------------------------+
| Firmware Requests [AE  4]:              112722 |
| Firmware Responses[AE  4]:              112722 |
+------------------------------------------------+
| Firmware Requests [AE  5]:              219657 |
| Firmware Responses[AE  5]:              219657 |
+------------------------------------------------+

Interrupts

vyos@R2-QAT# run show system acceleration qat interrupts 
140:      44039          0          0          0          0          0          0          0  IR-PCI-MSI 524288-edge      qat0-bundle0
141:          0      42358          0          0          0          0          0          0  IR-PCI-MSI 524289-edge      qat0-bundle1
142:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524290-edge      qat0-bundle2
143:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524291-edge      qat0-bundle3
144:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524292-edge      qat0-bundle4
145:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524293-edge      qat0-bundle5
146:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524294-edge      qat0-bundle6
147:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524295-edge      qat0-bundle7
148:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524296-edge      qat0-bundle8
149:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524297-edge      qat0-bundle9
150:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524298-edge      qat0-bundle10
151:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524299-edge      qat0-bundle11
152:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524300-edge      qat0-bundle12
153:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524301-edge      qat0-bundle13
154:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524302-edge      qat0-bundle14
155:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524303-edge      qat0-bundle15
156:          0          0          0          0          0          0          0          0  IR-PCI-MSI 524304-edge      qat0-ae-cluster
Aug 9 2021, 11:17 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin committed rVYOSONEXf8a34aedf168: T3695: reword the ocserv fail message..
Aug 9 2021, 10:20 AM
Unknown Object (User) committed rVYOSONEXc3d536f77d62: openconnect: T3695: Add systemd service checker on commit.
Aug 9 2021, 10:16 AM
GitHub <noreply@github.com> committed rVYOSONEX8709e3561f1d: Merge pull request #957 from DmitriyEshenko/1x-equuleus-09082021 (authored by dmbaturin).
Aug 9 2021, 10:16 AM
Unknown Object (User) changed the status of T3695: OpenConnect reports commit success when ocserv fails to start due to SSL cert/key file issues from Open to Needs testing.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/957

Aug 9 2021, 9:58 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav closed T2606: ikev2 mobike commit failed , a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Invalid.
Aug 9 2021, 8:42 AM · VyOS 1.4 Sagitta
Viacheslav closed T2606: ikev2 mobike commit failed as Invalid.

I closed it. Can't reproduce it.
Re-open it if necessary. Just attach your vpn configuration.

Aug 9 2021, 8:42 AM · VyOS 1.2 Crux
Viacheslav updated the task description for T3727: VPN IPsec ESP proposal and ESP presented in config missmatch.
Aug 9 2021, 8:34 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T2816: Rewrite IPsec scripts with the new XML/Python approach: T3727: VPN IPsec ESP proposal and ESP presented in config missmatch.
Aug 9 2021, 7:41 AM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T3727: VPN IPsec ESP proposal and ESP presented in config missmatch: T2816: Rewrite IPsec scripts with the new XML/Python approach.
Aug 9 2021, 7:41 AM · VyOS 1.4 Sagitta
Viacheslav created T3727: VPN IPsec ESP proposal and ESP presented in config missmatch.
Aug 9 2021, 7:40 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3144: Support op-mode command to release DHCP leases.

The same task T1375

Aug 9 2021, 12:23 AM · VyOS 1.3 Equuleus (1.3.4)

Aug 8 2021

c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.135 / 5.10.53 to Update Linux Kernel to v5.4.139 / 5.10.57.
Aug 8 2021, 9:03 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po committed rVYOSONEXb40e57cc9b51: pki: wireguard: T3642: add alias "generate wireguard key-pair" command.
Aug 8 2021, 8:24 PM
c-po committed rVYOSONEX9cde21563cd2: ipsec: l2tp: T2816: remove duplicate 3des-sha1-modp1024 proposal.
Aug 8 2021, 8:24 PM
c-po committed rVYOSONEX976062ed2981: Debian: T3641: drop dead symlink file in /etc/init.d.
Aug 8 2021, 8:12 PM
c-po closed T3705: IPSec: VTI interface does not honor default-esp-group as Resolved.
Aug 8 2021, 5:00 PM · VyOS 1.4 Sagitta
c-po claimed T3705: IPSec: VTI interface does not honor default-esp-group.
Aug 8 2021, 5:00 PM · VyOS 1.4 Sagitta
c-po closed T2027: get_config_dict is failing when the configuration section is empty/missing as Resolved.
Aug 8 2021, 4:48 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po added a comment to T2027: get_config_dict is failing when the configuration section is empty/missing.
>>> from vyos.config import Config
>>> conf = Config()
>>> conf.get_config_dict(['service', 'ssh'])
{'ssh': {'disable-host-validation': {}, 'port': ['22']}}
>>> conf.get_config_dict(['service', 'non-existing'])
{}
Aug 8 2021, 4:47 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po committed rVYOSONEX495b18c351ed: Debian: add missing runtime dependency on ndisc6.
Aug 8 2021, 4:34 PM
UnicronNL closed T169: Image install should put correct serial console device in created GRUB menu entry, a subtask of T2452: Serial console related issues, as Resolved.
Aug 8 2021, 4:22 PM · VyOS 1.3 Equuleus (1.3.6)
UnicronNL closed T169: Image install should put correct serial console device in created GRUB menu entry as Resolved.

Checks the grub config rule by rule if ttyS/ttyUSB is used then updates the newly to be included grub template to the same.

Aug 8 2021, 4:22 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin changed the status of T169: Image install should put correct serial console device in created GRUB menu entry, a subtask of T2452: Serial console related issues, from Open to Needs testing.
Aug 8 2021, 3:53 PM · VyOS 1.3 Equuleus (1.3.6)
dmbaturin changed the status of T169: Image install should put correct serial console device in created GRUB menu entry from Open to Needs testing.
Aug 8 2021, 3:53 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po committed rVYOSONEX99e9bcd7720a: smoketest: rpki: remporary disable SSH based connection testing due to FRR bug.
Aug 8 2021, 3:47 PM
Cheeze_It committed rVYOSONEXd012c732a890: PING: T3634: Fixing do not fragment to Ping.
Aug 8 2021, 2:48 PM
GitHub <noreply@github.com> committed rVYOSONEX293c31785abe: Merge pull request #956 from Cheeze-It/current (authored by c-po).
Aug 8 2021, 2:48 PM
c-po committed rVYOSONEX92db99f8e21b: ping: T3634: Fixing do not fragment to Ping (authored by Cheeze_It).
Aug 8 2021, 2:48 PM
erkin changed the status of T3275: Disable conntrack helpers by default from Open to In progress.
Aug 8 2021, 12:14 PM · VyOS 1.5 Circinus
erkin added a project to T1161: Does Vyos take advantage of linux's improved security features?: VyOS 1.4 Sagitta.
Aug 8 2021, 4:20 AM

Aug 7 2021

vfreex added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

I'm also affected by this. My configuration has about 5k ip prefixes in network group for policy based routing.

Aug 7 2021, 10:46 PM · VyOS 1.3 Equuleus (1.3.6)
Cheeze_It added a comment to T3634: Add op command option for ping for do not fragment bit to be set.

Did more checks.....and noticed it *IS* properly sending the ping command:

Aug 7 2021, 5:19 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
SrividyaA added a comment to T3219: Typo in openvpn server client config for IPv6 iroute.

I see these error in the openvpn log:

Aug 7 2021, 2:55 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
mrlocke created T3726: System ntp servers are ignored if provided by DHCP (ISP).
Aug 7 2021, 2:54 PM
SrividyaA added a comment to T3219: Typo in openvpn server client config for IPv6 iroute.

I don't think so the configuration is working, the interface is down. It is not assigning the ipv6 addresses to the tunnel interfaces.

Aug 7 2021, 1:59 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin closed T66: IPSec v6 over v6 support, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Aug 7 2021, 7:52 AM · VyOS 1.4 Sagitta
dmbaturin closed T66: IPSec v6 over v6 support as Resolved.

It was enabled by commit https://github.com/vyos/vyatta-cfg-vpn/commit/993f5bf9f54bcb7af20d44e7618586b55064a372 quite a while ago and no one complains, so I assume it's not an issue anymore.

Aug 7 2021, 7:52 AM · Restricted Project
dmbaturin edited projects for T66: IPSec v6 over v6 support, added: Restricted Project; removed VyOS 1.2 Crux (VyOS 1.2.9), test, VyOS 1.3 Equuleus.
Aug 7 2021, 7:52 AM · Restricted Project
Viacheslav closed T548: BGP IPv6 multipath support as Resolved.
Aug 7 2021, 7:44 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav removed projects from T3712: route-map comm-list can't be used without option delete: VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus.
Aug 7 2021, 7:38 AM
Viacheslav added projects to T3712: route-map comm-list can't be used without option delete: VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.9).
Aug 7 2021, 7:36 AM
dmbaturin removed projects from T3712: route-map comm-list can't be used without option delete: VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus, test.
Aug 7 2021, 7:33 AM
dmbaturin added a project to T3712: route-map comm-list can't be used without option delete: VyOS 1.2 Crux (VyOS 1.2.9).
Aug 7 2021, 7:22 AM
dmbaturin added a comment to T3712: route-map comm-list can't be used without option delete.

It's not a bug, it's simply a weird syntax. That command could never be used without the delete option, so your config example wouldn't work in 1.2 or 1.1.8 either.

Aug 7 2021, 7:21 AM
Viacheslav updated the task description for T3725: show configuration in json format.
Aug 7 2021, 6:39 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro committed rVYOSONEX5b69aad5bfe1: http-api: T2768: add README.graphql.
Aug 7 2021, 12:18 AM
jestabro committed rVYOSONEXb168b4cc7da4: http-api: T2768: example using GraphQL for high-level config operations.
Aug 7 2021, 12:18 AM

Aug 6 2021

xrobau added a comment to T3717: BGP Peer group without 'remote-as' gives shell error.

You COULD have a peer-group without remote-as, as you could apply that peer group to multiple remotes, and override the remote-as. But that is an edge case. The BETTER way to handle it is to enforce having a remote-as -- especially if you enable route-reflector-client

Aug 6 2021, 10:28 PM · VyOS 1.3 Equuleus (1.3.0), vyos-frr
maznu added a comment to T3692: VyOS build failing due to repo.saltstack.com.

salt-minion in the debian buster tree is version 2016.11.2+ds-1+deb9u4

Aug 6 2021, 10:27 PM · VyOS 1.4 Sagitta
sempervictus added a comment to T3692: VyOS build failing due to repo.saltstack.com.

Seems like the repo's not needed anymore as my iso just built without it, twice, after a clean, and with a bunch of added stuff (tor, docker, systemd-nspawn, xtables-addons, hardened-malloc, a grsec kernel, etc) for which dependencies are also available without it.
Either way, probably a good idea to keep deps for anything third-party in the vyos repo itself since third parties can become hostile through buyouts or license changes any time and anywhere in these post-FOSS times.

Aug 6 2021, 10:12 PM · VyOS 1.4 Sagitta
maznu added a comment to T3692: VyOS build failing due to repo.saltstack.com.

salt-minion which depends on salt-common which may depend on a couple of other things:

Aug 6 2021, 9:43 PM · VyOS 1.4 Sagitta
sempervictus added a comment to T3692: VyOS build failing due to repo.saltstack.com.

What packages are we actually pulling from there? Any reason they're not in the VyOS repo itself?
I removed their repo entirely from the JSON config and my image built fine (apparently i now have to add a /debian suffix for all packages in our repo, but that's weirdness in the repo management stack):

Reading package lists...
Building dependency tree...
Reading state information...
[2021-08-06 21:39:40] lb source 
P: Source stage disabled, skipping
P: Build completed successfully
Aug 6 2021, 9:40 PM · VyOS 1.4 Sagitta
maznu added a comment to T3692: VyOS build failing due to repo.saltstack.com.

The procedure I usually end up using:

Aug 6 2021, 9:36 PM · VyOS 1.4 Sagitta
maznu added a comment to T3692: VyOS build failing due to repo.saltstack.com.

https://repo.saltproject.io/py3/debian/10/amd64/latest buster Release looks wrong - shouldn't it read main at the end, instead of Release?

Aug 6 2021, 9:34 PM · VyOS 1.4 Sagitta
sempervictus added a comment to T3692: VyOS build failing due to repo.saltstack.com.

Trying to use their instructions from https://repo.saltproject.io/#debian i'm back to the certificate issue - repo is set to https://repo.saltproject.io/py3/debian/10/amd64/latest buster main and the custom GPG key has been added, but certificate checks still fail hard:

Reading package lists...
W: https://repo.saltproject.io/py3/debian/10/amd64/latest/dists/buster/InRelease: No system certificates available. Try installing ca-certificates.
W: https://repo.saltproject.io/py3/debian/10/amd64/latest/dists/buster/Release: No system certificates available. Try installing ca-certificates.
E: The repository 'https://repo.saltproject.io/py3/debian/10/amd64/latest buster Release' does not have a Release file.
E: An unexpected failure occurred, exiting...
P: Begin unmounting filesystems...
P: Saving caches...
Reading package lists...
Building dependency tree...
Del nftables 0.9.6-1 [66.8 kB]
Aug 6 2021, 9:31 PM · VyOS 1.4 Sagitta
sempervictus added a comment to T3692: VyOS build failing due to repo.saltstack.com.

After cleaning the chroot and retrying, it now fails utterly with the '#' in there:

Aug 6 2021, 9:19 PM · VyOS 1.4 Sagitta
dmbaturin closed T3196: No NAT translations showing up as Resolved.

Thanks! This is definitely a non-issue then, closing.

Aug 6 2021, 9:18 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin added a comment to T2947: Nat translation many-many with prefix does not map 1-1..

Since we cannot update the kernel in 1.3 due to the QAT issues, we likely need to backport netmap support. It seems to have been introduced by this commit: https://github.com/torvalds/linux/commit/3ff7ddb1353da

Aug 6 2021, 9:15 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3724: Allow setting host-name in l2tp section of accel-ppp.

@maznu
Add these lines:

Aug 6 2021, 9:03 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
sempervictus added a comment to T3692: VyOS build failing due to repo.saltstack.com.

Thank you for pointing that out - updated defaults.json and it seems to have made that issue go away.
For some reason its now breaking on using our internal repo (no TLS there, inside the datacenter), but i suspect its got something to do with the repo itself or some change in Debian since we started using it.

Aug 6 2021, 8:54 PM · VyOS 1.4 Sagitta
dmbaturin changed the status of T1083: Implement persistent/random address and port mapping options for NAT rules, a subtask of T2198: Rewrite NAT in new XML/Python style, from Open to Needs testing.
Aug 6 2021, 8:26 PM · VyOS 1.3 Equuleus (1.3.0)