Page MenuHomeVyOS Platform
Feed All Stories

Sep 4 2023

sarthurdev changed the status of T4309: Support network/address-groups and ipv6-network/ipv6-address-groups in "conntrack ignore" from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2199

Sep 4 2023, 10:50 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
mlk-89 updated the task description for T5545: sflow is not working.
Sep 4 2023, 10:26 AM · VyOS 1.3 Equuleus (1.3.4)
mlk-89 created T5545: sflow is not working.
Sep 4 2023, 10:13 AM · VyOS 1.3 Equuleus (1.3.4)
sarthurdev changed the status of T4309: Support network/address-groups and ipv6-network/ipv6-address-groups in "conntrack ignore" from Open to In progress.
Sep 4 2023, 9:38 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev changed the status of T4903: Support IPv6 addresses in "set system conntrack ignore" from Open to In progress.
Sep 4 2023, 9:38 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Sep 3 2023

Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Disabling all validators for both vyatta-cfg and vyatta-op bring the boot time down to approx 73 seconds.

Sep 3 2023, 9:41 PM · Restricted Project, VyOS 1.5 Circinus
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Modifying node.def (comment out "syntax:expression:") recursively in the paths of:

Sep 3 2023, 9:11 PM · Restricted Project, VyOS 1.5 Circinus
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Moving along in the blamegame I will after a tip try to disable the various validators being runned.

Sep 3 2023, 8:56 PM · Restricted Project, VyOS 1.5 Circinus
Apachez added a comment to T2431: Python validators are slow.

Any updates to this?

Sep 3 2023, 8:28 PM · VyOS 1.3 Equuleus (1.3.6)
cacack added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

That relates would seem reasonable. I'm seeing a similar explosion in commit lag but I have zero static routes. I did change to zone-based firewall and added about 6 vlans. Lines of my config went from ~500 to ~3000. Commit times increased almost linearly.

Sep 3 2023, 8:17 PM · Restricted Project, VyOS 1.5 Circinus
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Can be related: https://vyos.dev/T2431

Sep 3 2023, 7:14 PM · Restricted Project, VyOS 1.5 Circinus
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Continued debugging by also modifying /usr/libexec/vyos/services/vyos-configd by adding:

Sep 3 2023, 7:10 PM · Restricted Project, VyOS 1.5 Circinus
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Attempted some debugging on this issue.

Sep 3 2023, 6:43 PM · Restricted Project, VyOS 1.5 Circinus
syncer reassigned T1869: Install and Boot from RAID Doesn't Work from UnicronNL to zsdc.
Sep 3 2023, 6:30 PM · Restricted Project, VyOS 1.3 Equuleus (1.3.9)
syncer triaged T5544: Allow CAP_SYS_MODULE to be set on containers as Low priority.
Sep 3 2023, 5:44 PM · VyOS 1.4 Sagitta
syncer triaged T5543: Fix source address handling in static joins as Normal priority.
Sep 3 2023, 5:44 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Apachez added a comment to T5544: Allow CAP_SYS_MODULE to be set on containers .

According to https://man7.org/linux/man-pages/man7/capabilities.7.html this capability can load, unload AND delete kernel modules.

Sep 3 2023, 4:27 PM · VyOS 1.4 Sagitta
anthr76 added a comment to T5544: Allow CAP_SYS_MODULE to be set on containers .

https://github.com/vyos/vyos-1x/pull/2197

Sep 3 2023, 4:20 PM · VyOS 1.4 Sagitta
anthr76 created T5544: Allow CAP_SYS_MODULE to be set on containers .
Sep 3 2023, 4:10 PM · VyOS 1.4 Sagitta
alainlamar changed the status of T5540: vyos-1x: Wrong VHT configuration for WiFi 802.11ac from Open to In progress.
Sep 3 2023, 2:19 PM · VyOS 1.4 Sagitta
syncer moved T5543: Fix source address handling in static joins from Need Triage to Backlog on the VyOS 1.3 Equuleus (1.3.4) board.
Sep 3 2023, 11:44 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
syncer changed the status of T5543: Fix source address handling in static joins from Open to Backport pending.

@Viacheslav, can you backport this to 1.3

Sep 3 2023, 11:43 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
vfreex added a comment to T5543: Fix source address handling in static joins.

PR https://github.com/vyos/vyos-1x/pull/2196

Sep 3 2023, 11:19 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
vfreex created T5543: Fix source address handling in static joins.
Sep 3 2023, 11:17 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
sarthurdev closed T4612: Support arbitrary netmasks in firewall rules as Resolved.
Sep 3 2023, 10:37 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5542: ipoe-server: external-dhcp(dhcp-relay) not woking / not implemented from Open to Needs testing.
Sep 3 2023, 9:13 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5532: After add system image the boot stuck and works again after the second reboot.

Still occurs for:

Sep 3 2023, 6:10 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

PR created: https://github.com/vyos/vyos-build/pull/392

Sep 3 2023, 5:17 AM · VyOS 1.4 Sagitta
Apachez closed T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos as Resolved.
Sep 3 2023, 5:04 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.

Verified working with VyOS 1.4-rolling-202309030023.

Sep 3 2023, 5:03 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.

Was missing quotes around the variable within lb_config_tmpl like so:

Sep 3 2023, 5:02 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

Some further testing:

Sep 3 2023, 4:57 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

Reference to https://jonathancarter.org/2015/04/06/squashfs-performance-testing/ using 1M blocksize will give approx the same readspeed as with default 128k blocksize but result in an even smaller file.

Sep 3 2023, 4:02 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

Regarding filesystem.squashfs the changes through changed mksquashfs syntax are:

Sep 3 2023, 2:48 AM · VyOS 1.4 Sagitta
Niklasthegeek claimed T5542: ipoe-server: external-dhcp(dhcp-relay) not woking / not implemented.
Sep 3 2023, 2:09 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

Was missing quotes around the variable within lb_config_tmpl like so:

Sep 3 2023, 2:01 AM · VyOS 1.4 Sagitta
Niklasthegeek created T5542: ipoe-server: external-dhcp(dhcp-relay) not woking / not implemented.
Sep 3 2023, 12:55 AM · VyOS 1.4 Sagitta

Sep 2 2023

Apachez added a comment to T5541: Zone-Based Firewalling in VyOS Sagitta 1.4.

The firewall refactoring released 4th aug 2023 only (so far) took care about the documentation in the configuration section:

Sep 2 2023, 1:20 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
alainlamar created T5541: Zone-Based Firewalling in VyOS Sagitta 1.4.
Sep 2 2023, 1:11 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
alainlamar removed a project from T5540: vyos-1x: Wrong VHT configuration for WiFi 802.11ac: vyatta-wireless.
Sep 2 2023, 12:44 PM · VyOS 1.4 Sagitta
alainlamar created T5540: vyos-1x: Wrong VHT configuration for WiFi 802.11ac.
Sep 2 2023, 12:42 PM · VyOS 1.4 Sagitta
alainlamar updated the task description for T5539: vyos-build: wireless-regdb would not load due to signature mismatch.
Sep 2 2023, 12:17 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
alainlamar added projects to T5539: vyos-build: wireless-regdb would not load due to signature mismatch: VyOS 1.4 Sagitta, vyos-build.
Sep 2 2023, 12:16 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
alainlamar created T5539: vyos-build: wireless-regdb would not load due to signature mismatch.
Sep 2 2023, 12:15 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
Apachez claimed T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.
Sep 2 2023, 11:19 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.

PR created: https://github.com/vyos/vyos-build/pull/391

Sep 2 2023, 11:00 AM · VyOS 1.4 Sagitta
Apachez claimed T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.
Sep 2 2023, 10:45 AM · VyOS 1.4 Sagitta
Apachez created T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.
Sep 2 2023, 10:45 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

PR created: https://github.com/vyos/vyos-build/pull/390

Sep 2 2023, 1:27 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

PR389 build failed:

Sep 2 2023, 1:18 AM · VyOS 1.4 Sagitta

Sep 1 2023

Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

PR created: https://github.com/vyos/vyos-build/pull/389

Sep 1 2023, 7:57 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5536: show dhcp client leases caues No module named 'vyos.validate' from In progress to Needs testing.
Sep 1 2023, 3:10 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4712: Collaborative Protection Profile cPP for Network Devices root task: VyOS 1.5 Circinus.
Sep 1 2023, 12:51 PM · VyOS 1.5 Circinus
Apachez added a comment to T5534: VRRP rfc3768-compatibility broken after build 1.4-rolling-202308260020.

There was a similar case where it turned out that INPUT/OUTPUT chains for the firewall must be updated to include the stuff VRRP is doing.

Sep 1 2023, 12:22 PM
Apachez added a comment to T5536: show dhcp client leases caues No module named 'vyos.validate'.

Reported in: https://forum.vyos.io/t/error-show-dhcp-lease/12030

Sep 1 2023, 12:12 PM · VyOS 1.4 Sagitta
Apachez closed T5537: show dhcp client leases fails to complete as Invalid.

See this task instead: https://vyos.dev/T5536

Sep 1 2023, 12:11 PM · VyOS 1.4 Sagitta
Apachez created T5537: show dhcp client leases fails to complete.
Sep 1 2023, 12:10 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5536: show dhcp client leases caues No module named 'vyos.validate'.

PR https://github.com/vyos/vyos-1x/pull/2193

Sep 1 2023, 11:51 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5536: show dhcp client leases caues No module named 'vyos.validate' from Open to In progress.
Sep 1 2023, 10:56 AM · VyOS 1.4 Sagitta
Viacheslav created T5536: show dhcp client leases caues No module named 'vyos.validate'.
Sep 1 2023, 10:53 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5533: Keepalived VRRP IPv6 group enters in FAULT state .

PR https://github.com/vyos/vyos-1x/pull/2192

Sep 1 2023, 10:50 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav added a comment to T5533: Keepalived VRRP IPv6 group enters in FAULT state .

At the moment of applying vrrp configuration eth1 IPv6 address

inet6 2001:db8::3/125 scope global tentative

Then

inet6 2001:db8::3/125 scope global
Sep 1 2023, 8:49 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav added a project to T4754: Improvement: system login: show configured 2FA OTP key: VyOS 1.5 Circinus.
Sep 1 2023, 8:08 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav edited projects for T3214: OpenVPN IPv6 fixes, added: VyOS 1.5 Circinus; removed VyOS 1.4 Sagitta.
Sep 1 2023, 8:08 AM · VyOS 1.5 Circinus
Viacheslav added a project to T4919: TPM-backed config encryption: VyOS 1.5 Circinus.
Sep 1 2023, 8:07 AM · VyOS 1.5 Circinus
Viacheslav edited projects for T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6), added: VyOS 1.5 Circinus; removed VyOS 1.4 Sagitta.
Sep 1 2023, 8:00 AM · VyOS 1.5 Circinus
Viacheslav edited projects for T160: Support NAT64, added: VyOS 1.5 Circinus; removed VyOS 1.4 Sagitta.
Sep 1 2023, 7:59 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po added a comment to T5428: dhcp: client renewal fails when running inside VRF.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/2191

Sep 1 2023, 6:32 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
giga1699 added a comment to T5192: RNDIS Missing from Kernel.

Thanks for the follow-up @eyanulis!

Sep 1 2023, 1:08 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta

Aug 31 2023

Unknown Object (User) added a comment to T5192: RNDIS Missing from Kernel.
Aug 31 2023, 9:14 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
vishvas added a comment to T5534: VRRP rfc3768-compatibility broken after build 1.4-rolling-202308260020.

Dear Sir
Problem is with virtual address is not reachable on this build. Does not work after VRRP restart.

Aug 31 2023, 8:57 PM
syncer changed the status of T5048: QoS doesn't work correctly root task from Open to In progress.
Aug 31 2023, 8:37 PM · VyOS 1.4 Sagitta
jestabro edited projects for T5528: Replace legacy loadFile with config_diff, added: VyOS 1.5 Circinus; removed VyOS 1.4 Sagitta.
Aug 31 2023, 6:23 PM · VyOS 1.5 Circinus
syncer set the image for VyOS 1.5 Circinus to F3834018: profile.
Aug 31 2023, 6:00 PM
Viacheslav closed T3414: Add ChangeLog to the GitHub Repo as Invalid.

Close it for now.
There are no requirements to do it.

Aug 31 2023, 5:32 PM · VyOS 1.4 Sagitta
Apachez created T5535: Move disable-directed-broadcast to firewall global-options.
Aug 31 2023, 5:23 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jagekurt added a comment to T5508: Configuration Migration Fails to New Netfilter Firewall Syntax.

Ok, thanks for the info.

Aug 31 2023, 4:47 PM · VyOS 1.4 Sagitta
Viacheslav closed T5531: Containers add label option as Resolved.
Aug 31 2023, 4:36 PM · VyOS 1.4 Sagitta
jestabro added a comment to T5508: Configuration Migration Fails to New Netfilter Firewall Syntax.

We have seen occasional corruption of config.boot during system update, as reported, for example:
https://vyos.dev/T5267
That issue has been resolved here:
https://vyos.dev/T5520

Aug 31 2023, 4:32 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5534: VRRP rfc3768-compatibility broken after build 1.4-rolling-202308260020.

Try restart vrrp
There could be this bug https://vyos.dev/T5533

Aug 31 2023, 4:10 PM
Viacheslav closed T2102: Add Vlan on PPPoE server on Fly as Wontfix.

Just use /usr/bin/accel-cmd -p 2001 pppoe interface add "xxx"

Aug 31 2023, 3:56 PM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav moved T738: Add local-port and resolver port options for powerdns in CLI configuration tree from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.4) board.
Aug 31 2023, 3:54 PM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav closed T738: Add local-port and resolver port options for powerdns in CLI configuration tree as Resolved.
Aug 31 2023, 3:54 PM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav moved T3546: Add support for running scripts on PPPoE server session events from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.4) board.
Aug 31 2023, 3:53 PM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav closed T3546: Add support for running scripts on PPPoE server session events as Resolved.
Aug 31 2023, 3:53 PM · VyOS 1.3 Equuleus (1.3.4)
vishvas created T5534: VRRP rfc3768-compatibility broken after build 1.4-rolling-202308260020.
Aug 31 2023, 3:31 PM
jestabro added a comment to T5493: Add capability to use local and external dynamic-lists for firewall rules but also for various policies such as access-list, route-maps etc..

Note that the PR for T4797 was never updated for requested changes:
https://github.com/vyos/vyos-1x/pull/1648

Aug 31 2023, 3:27 PM · VyOS 1.5 Circinus
jagekurt added a comment to T5508: Configuration Migration Fails to New Netfilter Firewall Syntax.

Any updates on this?

Aug 31 2023, 3:26 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5518: Add MLD protocol support from Open to In progress.
Aug 31 2023, 1:47 PM · VyOS 1.4 Sagitta
Viacheslav closed T4692: Docker Builds of Equuleus Fail - public_suffix requires Ruby version >= 2.6 as Resolved.
Aug 31 2023, 1:44 PM
Viacheslav closed T4776: NVME storage is not detected properly during installation as Resolved.
Aug 31 2023, 1:41 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav added a comment to T4811: Webproxy bypassing CLI whitelist command is missing.

Still bug

vyos@r1# set service webproxy 
Possible completions:
   append-domain
                Default domain name
 > authentication
                Proxy Authentication Settings
+> cache-peer   Specify other caches in a hierarchy
   cache-size   Disk cache size in MB (default: 100)
   default-port Default Proxy Port (default: 3128)
   disable-access-log
                Disable logging of HTTP accesses
+  domain-block Domain name to block
+  domain-noncache
                Domain name to access without caching
+> listen-address
                IPv4 listen-address for WebProxy [REQUIRED]
   maximum-object-size
                Maximum size of object to be stored in cache in kilobytes
   mem-cache-size
                Memory cache size in MB
   minimum-object-size
                Maximum size of object to be stored in cache in kilobytes
   outgoing-address
                Outgoing IP address for webproxy
+  reply-block-mime
                MIME type to block
   reply-body-max-size
                Maximum reply body size in KB
 > url-filtering
                URL filtering settings
Aug 31 2023, 1:31 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
syncer triaged T5531: Containers add label option as Normal priority.
Aug 31 2023, 12:35 PM · VyOS 1.4 Sagitta
syncer moved T5531: Containers add label option from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Aug 31 2023, 12:35 PM · VyOS 1.4 Sagitta
evgbondarenko changed the Default View Policy policy for application Files from All Users to Custom Policy.
Aug 31 2023, 11:53 AM
Viacheslav moved T4855: Trying to create more than one tunnel of the same type to the same address causes unhandled exception from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.4) board.
Aug 31 2023, 11:42 AM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav closed T4855: Trying to create more than one tunnel of the same type to the same address causes unhandled exception as Resolved.

Fixed VyOS 1.3-stable-202308240442

set interfaces tunnel tun1 encapsulation 'gre'
set interfaces tunnel tun1 remote '203.0.113.254'
set interfaces tunnel tun1 source-address '203.0.113.1'
Aug 31 2023, 11:42 AM · VyOS 1.3 Equuleus (1.3.4)
evgbondarenko changed the Default View Policy policy for application Files from Custom Policy to All Users.
Aug 31 2023, 11:33 AM
Viacheslav removed a project from T4972: Support FQDN and IPv6 addresses for RADIUS servers in accel-ppp-backed protocols: VyOS 1.3 Equuleus (1.3.5).
Aug 31 2023, 11:07 AM · VyOS 1.5 Circinus
Viacheslav closed T4895: Tag nodes are overwritten when configured by Cloud-Init from User-Data as Resolved.
Aug 31 2023, 11:06 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta