Page MenuHomeVyOS Platform
Feed All Stories

Aug 16 2023

twan added a comment to T5481: Upgrade bug.

Another update. I noticed that all firewall configuration was gone (apart from the groups) after a reboot.

Aug 16 2023, 7:14 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5160: Firewall refactor.

If there would never be such then "INVALID" wouldnt exist as an option.

Aug 16 2023, 7:05 PM · VyOS 1.4 Sagitta
fernando changed the status of T5466: L3VPN - label allocation mode from Open to In progress.
Aug 16 2023, 6:55 PM · VyOS 1.4 Sagitta
fernando added a comment to T5466: L3VPN - label allocation mode .

PR https://github.com/vyos/vyos-1x/pull/2152

Aug 16 2023, 6:55 PM · VyOS 1.4 Sagitta
twan added a comment to T5481: Upgrade bug.

I have attached both files.

Aug 16 2023, 6:41 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX1ab8166a5481: netplug: T5476: rewrite dhclient helper from Perl -> Python.
Aug 16 2023, 5:51 PM
GitHub <[email protected]> committed rVYOSONEX65ea7cef9fe9: Merge pull request #2151 from c-po/netplug-t5476 (authored by c-po).
Aug 16 2023, 5:51 PM
dmbaturin committed rVYOSONEX4bc012d2b241: T5270: generate 'dh none' unconditionally when dh-params is no present.
Aug 16 2023, 2:09 PM
dmbaturin committed rVYOSONEX1d6180b74cff: T5271: correct dict path in the template for OpenVPN peer fingerprint.
Aug 16 2023, 2:09 PM
dmbaturin committed rVYOSONEX26d7ab49d92d: T5271: allow the user to specify either CA or peer fingerprint.
Aug 16 2023, 2:09 PM
GitHub <[email protected]> committed rVYOSONEX9cdc76fe5bad: Merge pull request #2150 from dmbaturin/T5271-openvpn-peer-fingerprint… (authored by jestabro).
Aug 16 2023, 2:09 PM
c-po added a comment to T5476: netplug: replace Perl helper scripts with a Python equivalent.

PRs:

Aug 16 2023, 11:32 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX3a3e490a198a: wireguard: T1843: add peer description CLI option.
Aug 16 2023, 11:22 AM
sarthurdev added a comment to T5160: Firewall refactor.

2.2: Invalid shall ALWAYS be processed BEFORE established/related/other rules otherwise it will not serve it purpose.

Aug 16 2023, 9:57 AM · VyOS 1.4 Sagitta
tjjh89017 added a comment to T5469: Incorrect dependency set in the openvpn-dco package when building VyOS for arm64.

I will suggest to move all arm64 kernel flavour to "arm64-vyos" as "amd64-vyos" in x86_64.
It will be better not to have "LOCALVERSION=-v8" in kernel configs.

Aug 16 2023, 9:03 AM · VyOS 1.4 Sagitta
Viacheslav updated subscribers of T5448: Add service zabbix-agent.

Thanks, @jestabro
Zabbix-agent really can include config directory, and if it is set and exists any *.conf file it thinks that those files related to zabbix-agent and expects specific config syntax/options.
I.e. it extends zabbix-agent with custom .confg files.
As it was a wrong format, most likely it can't start at all.

Aug 16 2023, 7:33 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5160: Firewall refactor.

2.2: Invalid shall ALWAYS be processed BEFORE established/related/other rules otherwise it will not serve it purpose.

Aug 16 2023, 5:06 AM · VyOS 1.4 Sagitta
jestabro closed T5483: Residual dhcp-server test file causing zabbix-agent smoketest to fail, a subtask of T5448: Add service zabbix-agent, as Resolved.
Aug 16 2023, 2:44 AM · VyOS 1.4 Sagitta
jestabro closed T5483: Residual dhcp-server test file causing zabbix-agent smoketest to fail as Resolved.
Aug 16 2023, 2:44 AM · VyOS 1.4 Sagitta
jestabro added a parent task for T5483: Residual dhcp-server test file causing zabbix-agent smoketest to fail: T5448: Add service zabbix-agent.
Aug 16 2023, 2:44 AM · VyOS 1.4 Sagitta
jestabro added a subtask for T5448: Add service zabbix-agent: T5483: Residual dhcp-server test file causing zabbix-agent smoketest to fail.
Aug 16 2023, 2:44 AM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEX4ea96d248597: T5483: clean up tmp config file.
Aug 16 2023, 2:42 AM
jestabro triaged T5483: Residual dhcp-server test file causing zabbix-agent smoketest to fail as Urgent! priority.
Aug 16 2023, 2:37 AM · VyOS 1.4 Sagitta
giga1699 changed Difficulty level from unknown to easy on T5447: Allow static MACsec keys with peers.
Aug 16 2023, 12:46 AM · VyOS 1.4 Sagitta

Aug 15 2023

fernando added a comment to T5160: Firewall refactor.

yes, but it's in process to merge : https://github.com/vyos/vyos-documentation/pull/1035

Aug 15 2023, 11:31 PM · VyOS 1.4 Sagitta
Sophie added a comment to T5160: Firewall refactor.

Now we have this included in the nightly builds, is there any documentation on how these refactored rules should be modified? Just bumped my version and was completely lost

Aug 15 2023, 9:49 PM · VyOS 1.4 Sagitta
fernando added a comment to T5481: Upgrade bug.

Could you share the full configuration ? so we can analyze what is the source of this problem .

Aug 15 2023, 9:48 PM · VyOS 1.4 Sagitta
dcplaya created T5482: Chrony NTP Server Fails To Sync Time.
Aug 15 2023, 8:26 PM · VyOS 1.4 Sagitta
twan created T5481: Upgrade bug.
Aug 15 2023, 8:04 PM · VyOS 1.4 Sagitta
dmbaturin closed T5273: Add op mode commands for displaying certificate details and fingerprints, a subtask of T5269: OpenVPN non-TLS site-to-site mode deprecation, as Resolved.
Aug 15 2023, 6:22 PM · VyOS 1.4 Sagitta
dmbaturin closed T5273: Add op mode commands for displaying certificate details and fingerprints as Resolved.
Aug 15 2023, 6:22 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
dmbaturin closed T5270: Make OpenVPN `tls dh-params` optional, a subtask of T5269: OpenVPN non-TLS site-to-site mode deprecation, as Resolved.
Aug 15 2023, 6:22 PM · VyOS 1.4 Sagitta
dmbaturin closed T5270: Make OpenVPN `tls dh-params` optional as Resolved.
Aug 15 2023, 6:21 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
aga closed T5293: Support for Floating Rules (Global Firewall-Rules that are automatically applied before all other Zone Rules) as Resolved.
Aug 15 2023, 3:52 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5478: Cannot configure resolver-cache options for firewall from Confirmed to In progress.

PR: https://github.com/vyos/vyos-1x/pull/2149

Aug 15 2023, 12:01 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5478: Cannot configure resolver-cache options for firewall from Open to Confirmed.
Aug 15 2023, 10:18 AM · VyOS 1.4 Sagitta
n.fort added a comment to T5160: Firewall refactor.

2.1:
Suggestion that established/related merges to a single rule such as:

Aug 15 2023, 10:09 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5448: Add service zabbix-agent.

Cannot pass the smoketest in CI

07:19:00  DEBUG - Running Testcase: /usr/libexec/vyos/tests/smoke/cli/test_service_monitoring_zabbix-agent.py
07:19:02  DEBUG - test_01_zabbix_agent (__main__.TestZabbixAgent.test_01_zabbix_agent) ... FAIL
07:19:04  DEBUG - 
07:19:04  DEBUG - ======================================================================
07:19:04  DEBUG - FAIL: test_01_zabbix_agent (__main__.TestZabbixAgent.test_01_zabbix_agent)
07:19:04  DEBUG - ----------------------------------------------------------------------
07:19:04  DEBUG - Traceback (most recent call last):
07:19:04  DEBUG -   File "/usr/libexec/vyos/tests/smoke/cli/test_service_monitoring_zabbix-agent.py", line 34, in tearDown
07:19:04  DEBUG -     self.assertTrue(process_named_running(PROCESS_NAME))
07:19:04  DEBUG - AssertionError: None is not true
07:19:04  DEBUG - 
07:19:04  DEBUG - ----------------------------------------------------------------------

Is not reproduced in the local VM test

vyos@r14:~$ /usr/libexec/vyos/tests/smoke/cli/test_service_monitoring_zabbix-agent.py
test_01_zabbix_agent (__main__.TestZabbixAgent.test_01_zabbix_agent) ... ok
Aug 15 2023, 8:31 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled.

The original task https://vyos.dev/T5080

Aug 15 2023, 8:23 AM · VyOS 1.4 Sagitta
Viacheslav moved T5457: Add environmental variable pointing to current rootfs directory from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 15 2023, 8:12 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T5480: Ability to disable SNMP for VRRP keepalived service: VyOS 1.4 Sagitta.
Aug 15 2023, 8:10 AM · VyOS 1.4 Sagitta
Viacheslav created T5480: Ability to disable SNMP for VRRP keepalived service.
Aug 15 2023, 8:06 AM · VyOS 1.4 Sagitta
a.hajiyev updated the task description for T5473: Detect what conflicts with POSIX mode.
Aug 15 2023, 5:27 AM · VyOS Rolling, Restricted Project
a.hajiyev updated the task description for T5473: Detect what conflicts with POSIX mode.
Aug 15 2023, 5:26 AM · VyOS Rolling, Restricted Project

Aug 14 2023

Apachez closed T5457: Add environmental variable pointing to current rootfs directory as Resolved.
Aug 14 2023, 9:58 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5457: Add environmental variable pointing to current rootfs directory.

Still works in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 9:58 PM · VyOS 1.4 Sagitta
Apachez closed T5440: Restore pre/postconfig scripts if user deleted them as Resolved.
Aug 14 2023, 9:55 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5440: Restore pre/postconfig scripts if user deleted them.

Verified in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 9:55 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5437: logrotate.service fails to start.

Seems to still be happy in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 9:54 PM · VyOS 1.4 Sagitta
Apachez closed T5436: vyos-preconfig-bootup.script is missing as Resolved.
Aug 14 2023, 9:51 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5436: vyos-preconfig-bootup.script is missing.

Verified in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 9:50 PM · VyOS 1.4 Sagitta
Apachez created T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled.
Aug 14 2023, 9:41 PM · VyOS 1.4 Sagitta
Apachez created T5478: Cannot configure resolver-cache options for firewall.
Aug 14 2023, 9:16 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5160: Firewall refactor.

1:
Shouldnt set firewall global-options resolver-cache have "enable" and "disable" as options?

Aug 14 2023, 9:10 PM · VyOS 1.4 Sagitta
Apachez closed T5461: Improve rootfs directory variable as Resolved.
Aug 14 2023, 8:27 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5461: Improve rootfs directory variable.

Looks like its working as expected in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 8:27 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T5434: Replace remaining calls of vyos.xml library: T5477: op-mode pki.py should use Config for defaults.
Aug 14 2023, 4:18 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T5477: op-mode pki.py should use Config for defaults: T5434: Replace remaining calls of vyos.xml library.
Aug 14 2023, 4:18 PM · VyOS 1.4 Sagitta
jestabro closed T5477: op-mode pki.py should use Config for defaults as Resolved.
Aug 14 2023, 4:02 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEXf67614c66d65: pki: T5477: use Config instead of ConfigTreeQuery for defaults.
Aug 14 2023, 4:01 PM
jestabro created T5477: op-mode pki.py should use Config for defaults.
Aug 14 2023, 3:58 PM · VyOS 1.4 Sagitta
a.hajiyev updated the task description for T5473: Detect what conflicts with POSIX mode.
Aug 14 2023, 1:15 PM · VyOS Rolling, Restricted Project
zsdc updated the task description for T5473: Detect what conflicts with POSIX mode.
Aug 14 2023, 1:12 PM · VyOS Rolling, Restricted Project
Viacheslav changed the status of T5461: Improve rootfs directory variable from Open to Needs testing.
Aug 14 2023, 11:24 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T5473: Detect what conflicts with POSIX mode from "Task" to "Bug".
Aug 14 2023, 11:17 AM · VyOS Rolling, Restricted Project
Apachez added a comment to T5473: Detect what conflicts with POSIX mode.

What is the purpose of:

Aug 14 2023, 11:08 AM · VyOS Rolling, Restricted Project
Viacheslav awarded T5474: Establish common file name pattern for XML conf mode commands a Like token.
Aug 14 2023, 11:00 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort changed the status of T5472: NAT redirect should not require port from Open to Confirmed.
Aug 14 2023, 10:09 AM · VyOS 1.4 Sagitta
c-po added a comment to T2044: RPKI doesn't boot properly.

interesting, as the above diff actually does the same but a bit earlier in the boot process

Aug 14 2023, 6:43 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po updated the task description for T5476: netplug: replace Perl helper scripts with a Python equivalent.
Aug 14 2023, 6:09 AM · VyOS 1.4 Sagitta
c-po claimed T5476: netplug: replace Perl helper scripts with a Python equivalent.
Aug 14 2023, 6:06 AM · VyOS 1.4 Sagitta
c-po created T5476: netplug: replace Perl helper scripts with a Python equivalent.
Aug 14 2023, 6:05 AM · VyOS 1.4 Sagitta
c-po changed Version from - to 1.4-rolling on T5474: Establish common file name pattern for XML conf mode commands.
Aug 14 2023, 6:00 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po triaged T5475: Analyse if forked live-boot package can be dropped as Low priority.
Aug 14 2023, 6:00 AM · VyOS Rolling
c-po claimed T5475: Analyse if forked live-boot package can be dropped.
Aug 14 2023, 5:59 AM · VyOS Rolling
c-po created T5475: Analyse if forked live-boot package can be dropped.
Aug 14 2023, 5:59 AM · VyOS Rolling
c-po changed the status of T5474: Establish common file name pattern for XML conf mode commands from Open to Confirmed.
Aug 14 2023, 5:55 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po created T5474: Establish common file name pattern for XML conf mode commands.
Aug 14 2023, 5:54 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
a.hajiyev created T5473: Detect what conflicts with POSIX mode.
Aug 14 2023, 4:24 AM · VyOS Rolling, Restricted Project

Aug 13 2023

aderouineau updated the task description for T5472: NAT redirect should not require port.
Aug 13 2023, 8:45 AM · VyOS 1.4 Sagitta
aderouineau created T5472: NAT redirect should not require port.
Aug 13 2023, 8:45 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX50c0bc7b2582: smoketest: T5467: verify OSPF(v3) interface removal in VRF context.
Aug 13 2023, 8:34 AM
c-po committed rVYOSONEX191c8c40023e: smoketest: openvpn: T5270:.
Aug 13 2023, 8:34 AM

Aug 12 2023

syncer triaged T4818: IPv6 NDP not working everytime as Normal priority.
Aug 12 2023, 10:17 PM · VyOS Rolling, Restricted Project
syncer assigned T5469: Incorrect dependency set in the openvpn-dco package when building VyOS for arm64 to c-po.
Aug 12 2023, 10:15 PM · VyOS 1.4 Sagitta
syncer changed the edit policy for T1869: Install and Boot from RAID Doesn't Work.
Aug 12 2023, 10:13 PM
syncer triaged T5471: Conntrack logging doesnt seem to be working as Low priority.
Aug 12 2023, 10:10 PM · VyOS Rolling, Restricted Project
syncer triaged T2044: RPKI doesn't boot properly as Normal priority.
Aug 12 2023, 10:09 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez created T5471: Conntrack logging doesnt seem to be working.
Aug 12 2023, 8:53 PM · VyOS Rolling, Restricted Project
egoistdream added a comment to T2044: RPKI doesn't boot properly.

I was able to fix by adding the following code in /config/scripts/vyos-postconfig-bootup.script you can edit and save by running:

Aug 12 2023, 7:13 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
egoistdream added a comment to T4818: IPv6 NDP not working everytime.

I can confirm that the issue is still here, something is wrong and usually when you assign ipv6 address to sub-interface like vlan or bridge etc.

Aug 12 2023, 7:09 PM · VyOS Rolling, Restricted Project
Apachez added a comment to T4818: IPv6 NDP not working everytime.

How is your IPv6 config from the VyOS config?

Aug 12 2023, 5:08 PM · VyOS Rolling, Restricted Project
c-po committed rVYOSONEX4eaf65c673e4: smoketest: T5465: add config migration test for VLAN interface.
Aug 12 2023, 4:11 PM
zsdc committed rVYOSONEX0ed6aa72e7d2: utils: T5410: Extended supported types in `convert_data()`.
Aug 12 2023, 4:09 PM
GitHub <[email protected]> committed rVYOSONEX485585e19e7a: Merge pull request #2117 from zdc/T5410-sagitta (authored by dmbaturin).
Aug 12 2023, 4:09 PM
c-po added a comment to T5325: Moschip MCS9900 fix driver.

Enabled inside VyOS kernel - please check with the next available rolling ISO

Aug 12 2023, 4:08 PM · VyOS 1.4 Sagitta
c-po changed the status of T5325: Moschip MCS9900 fix driver from Open to Needs testing.
Aug 12 2023, 4:07 PM · VyOS 1.4 Sagitta
c-po changed the status of T5470: wlan: can not disable interface if SSID is not configured from Open to In progress.
Aug 12 2023, 3:48 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po created T5470: wlan: can not disable interface if SSID is not configured.
Aug 12 2023, 3:47 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
jestabro committed rVYOSONEX928c78f5b976: T5160: fix merge regression.
Aug 12 2023, 3:06 PM