Page MenuHomeVyOS Platform
Feed All Stories

Nov 5 2022

ssasso created T4800: undefined var includes_chroot_dir in build-vyos-image .
Nov 5 2022, 1:01 PM · VyOS 1.4 Sagitta
c-po added a comment to T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.

Thanks for catching this

Nov 5 2022, 11:53 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
initramfs committed rVYOSONEXff09d4f47e5f: dns: T4799: fix bug with not reloading powerdns config.
Nov 5 2022, 7:24 AM
GitHub <noreply@github.com> committed rVYOSONEX6c0473efd272: Merge pull request #1639 from initramfs/current-fix-pdns-reload (authored by c-po).
Nov 5 2022, 7:24 AM
initramfs committed rVYOSONEXae30110b9fe4: dns: T4799: fix bug with not reloading powerdns config.
Nov 5 2022, 7:04 AM
GitHub <noreply@github.com> committed rVYOSONEXb3e524c29e9f: Merge pull request #1640 from initramfs/equuleus-fix-pdns-reload (authored by c-po).
Nov 5 2022, 7:04 AM
initramfs added a comment to T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.

Relevant PRs:

Nov 5 2022, 1:39 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
initramfs updated the task description for T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.
Nov 5 2022, 1:28 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
initramfs created T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.
Nov 5 2022, 1:19 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)

Nov 4 2022

jestabro added a subtask for T4795: Cleanup custom python validators: T4798: Migrate the file-exists validator away from Python.
Nov 4 2022, 3:54 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro added a parent task for T4798: Migrate the file-exists validator away from Python: T4795: Cleanup custom python validators.
Nov 4 2022, 3:54 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dmbaturin added a project to T4798: Migrate the file-exists validator away from Python: VyOS 1.3 Equuleus (1.3.3).
Nov 4 2022, 3:27 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dmbaturin created T4798: Migrate the file-exists validator away from Python.
Nov 4 2022, 3:26 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dmbaturin closed T2417: Python validator cleanup as Resolved.
Nov 4 2022, 3:26 PM · VyOS 1.3 Equuleus (1.3.0)
dmbaturin claimed T4770: Rewrite OpenVPN op-mode to vyos.opmode format.
Nov 4 2022, 1:18 PM · VyOS 1.4 Sagitta

Nov 3 2022

TheSin- updated the task description for T4797: External address/network lists for firewall (Local and remote).
Nov 3 2022, 9:15 PM · VyOS Rolling
TheSin- updated the task description for T4797: External address/network lists for firewall (Local and remote).
Nov 3 2022, 8:59 PM · VyOS Rolling
sarthurdev committed rVYOSONEX051e063fdf2e: firewall: T970: Refactor domain resolver, add firewall source/destination….
Nov 3 2022, 8:11 PM
sarthurdev committed rVYOSONEXb4b491d424fb: nat: T1877: T970: Add firewall groups to NAT.
Nov 3 2022, 8:11 PM
GitHub <noreply@github.com> committed rVYOSONEX36e54927217d: Merge pull request #1633 from sarthurdev/fqdn (authored by c-po).
Nov 3 2022, 8:11 PM
TheSin- added a comment to T4797: External address/network lists for firewall (Local and remote).

After a few hours of digging I do think this request would be very similar to geoip, only ipv4, and ipv6 groups would be required per list.

Nov 3 2022, 8:06 PM · VyOS Rolling
c-po committed rVYOSONEXd4cb20e1cef2: validators: T4795: migrate fqdn python validator to validate-value.
Nov 3 2022, 7:59 PM
sarthurdev triaged T4797: External address/network lists for firewall (Local and remote) as Wishlist priority.
Nov 3 2022, 7:44 PM · VyOS Rolling
Viacheslav changed the status of T4758: Rewrite show dhcp server to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from In progress to Needs testing.
Nov 3 2022, 7:42 PM · VyOS Rolling
Viacheslav changed the status of T4758: Rewrite show dhcp server to vyos.opmode format from In progress to Needs testing.
Nov 3 2022, 7:42 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T1097: Make firewall groups work everywhere that's appropropriate from Open to In progress.

PR adds groups to NAT: https://github.com/vyos/vyos-1x/pull/1633

Nov 3 2022, 7:41 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T1097: Make firewall groups work everywhere that's appropropriate, a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to In progress.
Nov 3 2022, 7:41 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
a.apostoliuk committed rVYOSONEX2e83c1eb53e9: T4496: Added lists of values in the help of op-mode ping command.
Nov 3 2022, 7:41 PM
c-po committed rVYOSONEX760cb6d9286c: Merge branch 'T4496-sagitta' of https://github.com/aapostoliuk/vyos-1x into….
Nov 3 2022, 7:41 PM
Viacheslav committed rVYOSONEX738641a6c66d: T4758: Rewrite show DHCP(v6) server leases to vyos.opmode format.
Nov 3 2022, 7:34 PM
Viacheslav committed rVYOSONEX46eda54c88ae: T4758: Fix conflicts op-mode-standardized.
Nov 3 2022, 7:34 PM
GitHub <noreply@github.com> committed rVYOSONEX99200f77afeb: Merge pull request #1604 from sever-sever/T4758 (authored by c-po).
Nov 3 2022, 7:34 PM
jestabro reopened T3574: Add constraintGroup for combining validators with logical AND as "Open".

Reopened, as this was never backported to 1.3; set for 1.3.3.

Nov 3 2022, 6:14 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
TheSin- added a comment to T4797: External address/network lists for firewall (Local and remote).

I didn't look deep into the nft groups, so I wasn't sure if we could mix ipv4/6 and addresses and networks, if we can then I agree one group would be best, though I'm sure ipv4/6 would still need to separate but checking each line for : makes that task super easy and fast.

Nov 3 2022, 5:38 PM · VyOS Rolling
n.fort added a comment to T4797: External address/network lists for firewall (Local and remote).

From my point of fiew, looks interesting.
The proposed structure and behaviour doesn't look that different than what is currently in geoip filtering: external URLs with data, and sync from time to time.

Nov 3 2022, 5:29 PM · VyOS Rolling
c-po committed rVYOSONEX3f5464d0ee85: validators: T4795: migrate mac-address python validator to validate-value.
Nov 3 2022, 5:04 PM
c-po committed rVYOSONEX81a70033cc95: validators: T4795: drop unused Python validators.
Nov 3 2022, 5:04 PM
c-po committed rVYOSONEX6f37744ad45a: xml: T4795: superseed allowed-vlan validator by numeric range validator.
Nov 3 2022, 5:04 PM
c-po committed rVYOSONEX4ae434d50337: xml: T4795: provide common and re-usable XML definitions for policy.
Nov 3 2022, 5:04 PM
TheSin- created T4797: External address/network lists for firewall (Local and remote).
Nov 3 2022, 5:00 PM · VyOS Rolling
dmbaturin created T4796: build-vyos-image ignores multiple options.
Nov 3 2022, 4:42 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po changed the status of T4795: Cleanup custom python validators from Open to In progress.
Nov 3 2022, 4:17 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po created T4795: Cleanup custom python validators.
Nov 3 2022, 4:15 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
TheSin- renamed T4794: show firewall name <name> - Can't use .items() on a list from Can't use .items() on a list to show firewall name <name> - Can't use .items() on a list.
Nov 3 2022, 2:33 PM · VyOS 1.4 Sagitta
TheSin- created T4794: show firewall name <name> - Can't use .items() on a list.
Nov 3 2022, 2:14 PM · VyOS 1.4 Sagitta
a.apostoliuk added a subtask for T3953: IPSec with vti interfaces by default add default route to table 220: T4793: Create warning message about disable-route-autoinstall when ipsec vti is used.
Nov 3 2022, 12:37 PM · VyOS 1.3 Equuleus (1.3.9)
a.apostoliuk added a parent task for T4793: Create warning message about disable-route-autoinstall when ipsec vti is used: T3953: IPSec with vti interfaces by default add default route to table 220.
Nov 3 2022, 12:37 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
a.apostoliuk changed the status of T4793: Create warning message about disable-route-autoinstall when ipsec vti is used from Open to In progress.
Nov 3 2022, 12:32 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
a.apostoliuk triaged T4793: Create warning message about disable-route-autoinstall when ipsec vti is used as Normal priority.
Nov 3 2022, 12:31 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
jack9603301 added a comment to T1797: Implement DPDK Fast-Path using FRR's Alternate Forwarding Planes and VPP.
Nov 3 2022, 10:02 AM
giezi added a comment to T1797: Implement DPDK Fast-Path using FRR's Alternate Forwarding Planes and VPP.

The enhanced linux-cp plugin (from IPng) is since 21.06 an official part of VPP, so the integration should be simple:
https://vpp.flirble.org/master/aboutvpp/releasenotes/v21.06.html#linux-control-plane-plugin-linux-cp

Nov 3 2022, 9:49 AM
Viacheslav placed T3953: IPSec with vti interfaces by default add default route to table 220 up for grabs.
Nov 3 2022, 7:43 AM · VyOS 1.3 Equuleus (1.3.9)
initramfs added a comment to T4760: VyOS does not support running multiple instances of DHCPv6 clients.

A patch to the WIDE DHCPv6 client seems to be sufficient to resolve this issue with respect to the way VyOS currently uses the daemon (one daemon per configured interface), PRs below:

Nov 3 2022, 1:59 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Viacheslav renamed T4789: Ability to get L2TP/PPTP/SSTP sessions info in a machine readable format from Ability to get L2TP/PPTP sessions info in a machine readable format to Ability to get L2TP/PPTP/SSTP sessions info in a machine readable format.
Nov 3 2022, 12:17 AM · VyOS 1.4 Sagitta

Nov 2 2022

jestabro committed rVYOSONEXc6f7ef4b84b2: op-mode: T4791: decamelize raw output of 'show_*' before normalization.
Nov 2 2022, 7:29 PM
jestabro committed rVYOSONEX702fc6272672: op-mode: T4791: add python3-pyhumps as build dep for op-mode nosetest.
Nov 2 2022, 7:28 PM
jestabro committed rVYOSONEXdb0791238c9c: graphql: T4791: decamelize/normalize result of op-mode queries.
Nov 2 2022, 7:28 PM
GitHub <noreply@github.com> committed rVYOSONEXf11b76ec56f9: Merge pull request #1636 from jestabro/standardize-op-mode-output (authored by jestabro).
Nov 2 2022, 7:28 PM
c-po moved T4177: Strip-private doesn't work for service monitoring from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Nov 2 2022, 6:52 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
zsdc changed the status of T4776: NVME storage is not detected properly during installation from In progress to Needs testing.

Sure, it is fully compatible with 1.3. If no problems are found after the changes in 1.4 it must be backported.

Nov 2 2022, 4:10 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav created T4792: Add SSTP VPN client.
Nov 2 2022, 3:29 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4771: Rewrite protocol BGP op-mode to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from In progress to Needs testing.
Nov 2 2022, 2:40 PM · VyOS Rolling
Viacheslav changed the status of T4771: Rewrite protocol BGP op-mode to vyos.opmode format from In progress to Needs testing.
Nov 2 2022, 2:40 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4777: Ability to get logs in machine readable format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from In progress to Needs testing.
Nov 2 2022, 2:39 PM · VyOS Rolling
Viacheslav changed the status of T4777: Ability to get logs in machine readable format from In progress to Needs testing.

Requires rewriting function show to python-systemd

Nov 2 2022, 2:39 PM · VyOS 1.5 Circinus
Viacheslav committed rVYOSONEX1afb3f8bd5de: T4771: Ability to get raw format for op-mode BGP commands.
Nov 2 2022, 12:00 PM
GitHub <noreply@github.com> committed rVYOSONEXf2ec92a78c4e: Merge pull request #1623 from sever-sever/T4771 (authored by dmbaturin).
Nov 2 2022, 12:00 PM
Viacheslav committed rVYOSONEXf489c5ecdab5: T4777: Ability to get logs in machine-readable format.
Nov 2 2022, 11:49 AM
GitHub <noreply@github.com> committed rVYOSONEX1bc2a0e8659a: Merge pull request #1635 from sever-sever/T4777 (authored by dmbaturin).
Nov 2 2022, 11:49 AM
hard added a comment to T4502: Consider implementing (NAT/other) flow table offload.

on nightly build nftables v1.0.5 and kernel 5.15.76

Nov 2 2022, 9:10 AM · VyOS 1.4 Sagitta
jack9603301 added a comment to T4756: General applications that support SOCAT.

As a first step, we need a wrapper script to control the start, stop and restart of socat, because socat sometimes exits automatically

Nov 2 2022, 7:37 AM
jack9603301 added a comment to T4766: Enable Cross-Protocol Translation (relay).

As a first step, we need a wrapper script to control the start, stop and restart of socat, because socat sometimes exits automatically

Nov 2 2022, 7:37 AM
a.apostoliuk changed the status of T4790: RADIUS login does not work if sum of timeouts more than 50s from Open to In progress.
Nov 2 2022, 6:41 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
a.apostoliuk claimed T4790: RADIUS login does not work if sum of timeouts more than 50s .
Nov 2 2022, 6:41 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta

Nov 1 2022

ordex added a comment to T3214: OpenVPN IPv6 fixes.

I created a PR to solve this specific issue (and some more related to this): https://github.com/vyos/vyos-1x/pull/1637

Nov 1 2022, 10:38 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T4777: Ability to get logs in machine readable format.

PR https://github.com/vyos/vyos-1x/pull/1635

Nov 1 2022, 5:36 PM · VyOS 1.5 Circinus
Viacheslav edited projects for T4737: FRRouting/zebra 7.5.1 does not redistribute routes to other protocols, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus.
Nov 1 2022, 5:31 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav awarded T4791: Consistent normalization of 'raw' output of op-mode scripts for CLI and API a Like token.
Nov 1 2022, 5:30 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T4790: RADIUS login does not work if sum of timeouts more than 50s , added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus.
Nov 1 2022, 5:28 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po changed the status of T4177: Strip-private doesn't work for service monitoring from Unknown Status to Resolved.
Nov 1 2022, 5:24 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po committed rVYOSONEXa18a722a93fd: strip-private: T4177: Fix for hiding private data token/url/bucket (authored by Viacheslav).
Nov 1 2022, 5:24 PM
GitHub <noreply@github.com> committed rVYOSONEX333e87dc69dc: Merge pull request #1634 from c-po/t4177-equuleus (authored by c-po).
Nov 1 2022, 5:24 PM
jestabro changed the status of T4791: Consistent normalization of 'raw' output of op-mode scripts for CLI and API from Open to In progress.
Nov 1 2022, 4:34 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4777: Ability to get logs in machine readable format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Nov 1 2022, 3:45 PM · VyOS Rolling
Viacheslav changed the status of T4777: Ability to get logs in machine readable format from Open to In progress.
Nov 1 2022, 3:45 PM · VyOS 1.5 Circinus
a.apostoliuk created T4790: RADIUS login does not work if sum of timeouts more than 50s .
Nov 1 2022, 3:43 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
fernando added a comment to T4788: Factory-reset/default command .

normally, when I want to make an empty-base config, I save config.boot another place. So I load it when I need to restart the configuration. I was thinking that we can make something like it by cli, it should be saved in the first config.boot file and restored.

Nov 1 2022, 2:51 PM · VyOS Rolling
n.fort added a comment to T4788: Factory-reset/default command .

Maybe a simplified and interactive cli, as when adding new image? So user can decide what to do with other images and containers.

Nov 1 2022, 1:29 PM · VyOS Rolling
sarthurdev changed the status of T1877: Feature Request: Allow NAT to use network and address groups from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1633

Nov 1 2022, 12:48 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T970: Support matching domain name in firewall rules.

Adds firewall node rule N source/destination fqdn domain.com for single domains per rule and refactors resolver daemon.

Nov 1 2022, 12:47 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav updated the task description for T4789: Ability to get L2TP/PPTP/SSTP sessions info in a machine readable format.
Nov 1 2022, 11:46 AM · VyOS 1.4 Sagitta
Viacheslav created T4789: Ability to get L2TP/PPTP/SSTP sessions info in a machine readable format.
Nov 1 2022, 11:45 AM · VyOS 1.4 Sagitta
sarthurdev moved T4759: domain-group on policy route not working from Open to In Progress on the VyOS 1.4 Sagitta board.
Nov 1 2022, 9:19 AM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4759: domain-group on policy route not working from Open to In progress.
Nov 1 2022, 9:19 AM · VyOS 1.4 Sagitta
sarthurdev closed T4764: NAT tables vyos_nat and vyos_static_nat not deleting after deleting nat as Resolved.
Nov 1 2022, 9:19 AM · VyOS 1.4 Sagitta
sarthurdev closed T4774: Disallow duplicate pubkey on peers of a wireguard interface as Unknown Status.
Nov 1 2022, 9:18 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4788: Factory-reset/default command from "Task" to "Feature Request".

In addition to the configuration, you also need to reset all logs/custom scripts and boot from the base image.
What will be if you have several images? Should we delete all other images?
What will be if you have container images? Should we delete them?
And there are many other nuances.

Nov 1 2022, 9:02 AM · VyOS Rolling
c-po changed the status of T4750: Support of higher level SSH keys (sk-ssh-ed25519) from In progress to Needs testing.
Nov 1 2022, 8:22 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXf50f7b043a86: login: T4750: add ecdsa-sk and ed25519-sk as supported public key type.
Nov 1 2022, 8:22 AM
c-po changed the status of T4750: Support of higher level SSH keys (sk-ssh-ed25519) from Open to In progress.
Nov 1 2022, 8:03 AM · VyOS 1.4 Sagitta