Page MenuHomeVyOS Platform
Feed All Stories

Sep 7 2023

sarthurdev moved T5558: Update config test to check resulting migrations from Open to In Progress on the VyOS 1.5 Circinus board.
Sep 7 2023, 5:53 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5558: Update config test to check resulting migrations from Open to In progress.
Sep 7 2023, 5:53 PM · VyOS 1.5 Circinus
Apachez added a comment to T5556: reboot now and poweroff does not work.

Related to https://vyos.dev/T5514 ?

Sep 7 2023, 5:49 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T5554: Disable sudo for PAM RADIUS.

For 1.4 add session [default=ignore success=2] pam_succeed_if.so service = sudo to /etc/pam.d/common-session-noninteractive fixes the issue

# here are the per-package modules (the "Primary" block)
session [default=1]                     pam_permit.so
# here's the fallback if no module succeeds
session requisite                       pam_deny.so
# prime the stack with a positive return value if there isn't one already;
# this avoids us returning an error just because nothing sets a success code
# since the modules above will each just jump around
session required                        pam_permit.so
# and here are more per-package modules (the "Additional" block)
session required        pam_mkhomedir.so umask=0022 skel=/etc/skel
session [default=ignore success=2] pam_succeed_if.so service = sudo
session [default=ignore success=ignore] pam_succeed_if.so user ingroup aaa quiet
session [authinfo_unavail=ignore success=ok default=ignore] pam_radius_auth.so
session required        pam_unix.so
# end of pam-auth-update config
Sep 7 2023, 4:02 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav edited projects for T5555: Fix timezone migrator (system 13-to-14), added: VyOS 1.3 Equuleus (1.3.4); removed VyOS 1.3 Equuleus (1.3.5).
Sep 7 2023, 3:13 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro committed rVYOSONEX0869b91c0b15: conf-mode: T5412: add script for add-on package check of dependencies.
Sep 7 2023, 3:07 PM
jestabro committed rVYOSONEXd9ad551816e3: conf-mode: T5412: add support for supplemental dependency definitions.
Sep 7 2023, 3:07 PM
jestabro committed rVYOSONEX12440ea1af8e: conf-mode: T5412: move dependency check from smoketest to nosetest.
Sep 7 2023, 3:06 PM
GitHub <noreply@github.com> committed rVYOSONEX73ee99fac6c6: Merge pull request #2216 from jestabro/ext-dependency (authored by c-po).
Sep 7 2023, 3:06 PM
sarthurdev committed rVYOSONEXb357b70647c9: system: T5555: Fix time-zone migrator changing valid time-zones to UTC.
Sep 7 2023, 3:06 PM
GitHub <noreply@github.com> committed rVYOSONEX8d11722f1829: Merge pull request #2219 from sarthurdev/T5555_equuleus (authored by c-po).
Sep 7 2023, 3:06 PM
sarthurdev committed rVYOSONEXd1edbfd18e71: system: T5555: Fix time-zone migrator changing valid time-zones to UTC.
Sep 7 2023, 2:17 PM
GitHub <noreply@github.com> committed rVYOSONEX0fcf2cbcfcab: Merge pull request #2218 from sarthurdev/T5555_sagitta (authored by c-po).
Sep 7 2023, 2:17 PM
sarthurdev committed rVYOSONEXc85095572c0a: system: T5555: Fix time-zone migrator changing valid time-zones to UTC.
Sep 7 2023, 2:16 PM
GitHub <noreply@github.com> committed rVYOSONEX05dd8edcae53: Merge pull request #2217 from sarthurdev/T5555 (authored by c-po).
Sep 7 2023, 2:16 PM
c-po added a comment to T5557: bgp: Use treat-as-withdraw for tunnel encapsulation attribute CVE-2023-38802.

1.4 running FRR9 is already mitigated

Sep 7 2023, 2:14 PM · VyOS 1.3 Equuleus (1.3.4)
c-po claimed T5557: bgp: Use treat-as-withdraw for tunnel encapsulation attribute CVE-2023-38802.
Sep 7 2023, 2:13 PM · VyOS 1.3 Equuleus (1.3.4)
c-po created T5557: bgp: Use treat-as-withdraw for tunnel encapsulation attribute CVE-2023-38802.
Sep 7 2023, 2:13 PM · VyOS 1.3 Equuleus (1.3.4)
jestabro triaged T5556: reboot now and poweroff does not work as Urgent! priority.

Logic error in recent bug fix; correction is being checked ...

Sep 7 2023, 1:37 PM · VyOS 1.5 Circinus
sarthurdev moved T5555: Fix timezone migrator (system 13-to-14) from Need Triage to In Progress on the VyOS 1.3 Equuleus (1.3.5) board.
Sep 7 2023, 1:13 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev moved T5555: Fix timezone migrator (system 13-to-14) from Open to In Progress on the VyOS 1.5 Circinus board.
Sep 7 2023, 1:13 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev moved T5555: Fix timezone migrator (system 13-to-14) from Open to In Progress on the VyOS 1.4 Sagitta board.
Sep 7 2023, 1:13 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev changed the status of T5555: Fix timezone migrator (system 13-to-14) from In progress to Needs testing.

current PR: https://github.com/vyos/vyos-1x/pull/2217
1.4 PR: https://github.com/vyos/vyos-1x/pull/2218
1.3 PR: https://github.com/vyos/vyos-1x/pull/2219

Sep 7 2023, 12:54 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro claimed T5556: reboot now and poweroff does not work.
Sep 7 2023, 12:43 PM · VyOS 1.5 Circinus
Viacheslav renamed T5556: reboot now and poweroff does not work from reboot now does not work to reboot now and poweroff does not work.
Sep 7 2023, 12:39 PM · VyOS 1.5 Circinus
Viacheslav created T5556: reboot now and poweroff does not work.
Sep 7 2023, 12:38 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5555: Fix timezone migrator (system 13-to-14) from Open to In progress.
Sep 7 2023, 12:29 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev created T5555: Fix timezone migrator (system 13-to-14).
Sep 7 2023, 12:29 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav updated the task description for T5554: Disable sudo for PAM RADIUS.
Sep 7 2023, 11:50 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav created T5554: Disable sudo for PAM RADIUS.
Sep 7 2023, 11:43 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
ildar added a comment to T5232: Flow-accounting uacctd.service cannot restart correctly.

I see this in 20230329 rolling, but don't see on the latest one.

Sep 7 2023, 11:01 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T4928: Upgrade Linux Kernel to 6.1.y (2022 LTS edition).

Could please the vyos_debconfig files be updated aswell?

Sep 7 2023, 5:19 AM · VyOS 1.4 Sagitta
Apachez closed T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax as Resolved.
Sep 7 2023, 5:15 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

PR392 was merged in VyOS 1.4-rolling-202309070021.

Sep 7 2023, 5:14 AM · VyOS 1.4 Sagitta
jestabro edited a custom field on T5353: config-mgmt: normalize archive updates and commit log entries.
Sep 7 2023, 2:20 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a comment to T5412: Add support for extending config-mode dependencies in supplemental package.

PR:
https://github.com/vyos/vyos-1x/pull/2216

Sep 7 2023, 2:19 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a comment to T5353: config-mgmt: normalize archive updates and commit log entries.

PR for Sagitta (draft until dependency PR 2207 is merged to Sagitta):
https://github.com/vyos/vyos-1x/pull/2215

Sep 7 2023, 2:09 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Sep 6 2023

anthr76 added a comment to T5546: Failed upgrade from 1.4-rolling-202212310809 to 1.4-rolling-202309030023.

Sounds great @jestabro I'm happy to assist in any way possible

Sep 6 2023, 11:09 PM · VyOS 1.4 Sagitta (1.4.1)
jestabro closed T5353: config-mgmt: normalize archive updates and commit log entries, a subtask of T5347: Compare commit revision bug, as Unknown Status.
Sep 6 2023, 6:28 PM · VyOS 1.4 Sagitta
jestabro closed T5353: config-mgmt: normalize archive updates and commit log entries, a subtask of T5551: Missing check for boot_configuration_complete raises error in vyos-save-config.py, as Unknown Status.
Sep 6 2023, 6:28 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5353: config-mgmt: normalize archive updates and commit log entries as Unknown Status.
Sep 6 2023, 6:28 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T5489: Change to BBR as TCP congestion control, or at least make it an config option from In progress to Needs testing.
Sep 6 2023, 6:26 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX5a8e3089b35e: conntrack: T4309: T4903: Refactor `system conntrack ignore` rule generation….
Sep 6 2023, 6:26 PM
sarthurdev committed rVYOSONEX02d1cf37ef1a: conntrack: T4309: Add `conntrack ignore` smoketest.
Sep 6 2023, 6:26 PM
sarthurdev committed rVYOSONEX2c88d01697ee: nat: T1877: Fix typo in nat ConfigError.
Sep 6 2023, 6:26 PM
GitHub <noreply@github.com> committed rVYOSONEX50f3e9f66abf: Merge pull request #2199 from sarthurdev/T4309 (authored by c-po).
Sep 6 2023, 6:26 PM
Viacheslav committed rVYOSONEXb99ed37dd1cf: T5489: Add sysctl TCP congestion control by default to BBR.
Sep 6 2023, 6:25 PM
Viacheslav committed rVYOSONEX97326920e290: T5423: Fix for op-mode show vpn ike secrets.
Sep 6 2023, 6:25 PM
GitHub <noreply@github.com> committed rVYOSONEXc37f78087ba9: Merge pull request #2205 from sever-sever/T5489 (authored by c-po).
Sep 6 2023, 6:25 PM
GitHub <noreply@github.com> committed rVYOSONEX1cad06b6db63: Merge pull request #2206 from sever-sever/T5423 (authored by c-po).
Sep 6 2023, 6:25 PM
sarthurdev committed rVYOSONEX0de3de1e0a78: interface: T5550: Interface source-validation priority over global value.
Sep 6 2023, 6:25 PM
GitHub <noreply@github.com> committed rVYOSONEXe0825b52df4a: Merge pull request #2208 from sarthurdev/T5550 (authored by c-po).
Sep 6 2023, 6:25 PM
sarthurdev committed rVYOSONEXbe3d2f9f6623: firewall: T3509: Split IPv4 and IPv6 reverse path filtering like on interfaces.
Sep 6 2023, 6:25 PM
jestabro committed rVYOSONEX73e317bee57c: config-mgmt: T5353: only add log entry if archiving.
Sep 6 2023, 6:25 PM
jestabro committed rVYOSONEX730e744931e4: config-mgmt: T5353: correct update check during boot.
Sep 6 2023, 6:25 PM
jestabro committed rVYOSONEX52e4b4431ef4: config-mgmt: T5353: after updated save-config, one can include init rev.
Sep 6 2023, 6:25 PM
GitHub <noreply@github.com> committed rVYOSONEXe208d75edd79: Merge pull request #2211 from jestabro/bug-config-mgmt (authored by c-po).
Sep 6 2023, 6:25 PM
Apachez added a comment to T5553: Firewall - Add action continue.

In case there are other just like me who didnt know about "action continue":

Sep 6 2023, 5:55 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5553: Firewall - Add action continue from Open to Confirmed.
Sep 6 2023, 5:39 PM · VyOS 1.4 Sagitta
n.fort created T5553: Firewall - Add action continue.
Sep 6 2023, 5:39 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Something else to consider is to increase the readcache of squashfs by changing this:

Sep 6 2023, 4:35 PM · VyOS Rolling, Bugs
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Looking at the kernel configs from both arm and x86 arch:

Sep 6 2023, 4:24 PM · VyOS Rolling, Bugs
Apachez added a comment to T5455: Migrate SSH fingerprints to the new image on upgrade.

So what needs to be done is to copy that block and make a separate question regarding:

Sep 6 2023, 3:26 PM · VyOS 1.5 Circinus (2025.11)
Apachez added a comment to T5440: Restore pre/postconfig scripts if user deleted them.

According to https://github.com/vyos/vyos-1x/blob/current/src/init/vyos-router it should be named:

Sep 6 2023, 2:39 PM · VyOS 1.4 Sagitta
jestabro added a comment to T5546: Failed upgrade from 1.4-rolling-202212310809 to 1.4-rolling-202309030023.

@anthr76 T5520 would be unrelated to an upgrade from 1.4-rolling-202212310809, as the change to using Bookworm did not occur until 2023. We can take a look at the specific errors that you encountered.

Sep 6 2023, 2:37 PM · VyOS 1.4 Sagitta (1.4.1)
Apachez added a comment to T5546: Failed upgrade from 1.4-rolling-202212310809 to 1.4-rolling-202309030023.

There is a similar case going on at the forum with different workarounds which might help?

Sep 6 2023, 2:31 PM · VyOS 1.4 Sagitta (1.4.1)
fernando updated subscribers of T4919: TPM-backed config encryption.

@sdev take a look over these repository :

Sep 6 2023, 1:28 PM · VyOS Rolling, VyOS 1.5 Circinus
anthr76 added a comment to T5546: Failed upgrade from 1.4-rolling-202212310809 to 1.4-rolling-202309030023.

The steps above i can try as a last ditch effort but that means I need to be on site with the device and will require lots of time (and downtime)

Sep 6 2023, 12:53 PM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav moved T5542: ipoe-server: external-dhcp(dhcp-relay) not woking / not implemented from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 6 2023, 12:08 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5440: Restore pre/postconfig scripts if user deleted them.

I have two scripts
Is it ok?

vyos@r14:~$ sudo ls -la /config/scripts/vyos-postconfig-boot*
-rwxrwxr-x 1 root vyattacfg 413 Sep  6 15:04 /config/scripts/vyos-postconfig-boot.script
-rwxrwxr-x 1 root vyattacfg 230 Jun 27 06:17 /config/scripts/vyos-postconfig-bootup.script
vyos@r14:~$
Sep 6 2023, 12:07 PM · VyOS 1.4 Sagitta
Niklasthegeek closed T5542: ipoe-server: external-dhcp(dhcp-relay) not woking / not implemented as Resolved.
Sep 6 2023, 11:16 AM · VyOS 1.4 Sagitta
Niklasthegeek added a comment to T5542: ipoe-server: external-dhcp(dhcp-relay) not woking / not implemented.

@Viacheslav Sure. I am on VyOS 1.4-rolling-202309040919 and the issue is fixed. Config gets build correctly

Sep 6 2023, 11:16 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5542: ipoe-server: external-dhcp(dhcp-relay) not woking / not implemented.

@Niklasthegeek Could you re-check and close it if it was fixed?

Sep 6 2023, 10:13 AM · VyOS 1.4 Sagitta
Viacheslav reassigned T5544: Allow CAP_SYS_MODULE to be set on containers from Viacheslav to anthr76.
Sep 6 2023, 10:11 AM · VyOS 1.4 Sagitta
Viacheslav closed T5544: Allow CAP_SYS_MODULE to be set on containers as Resolved.

@

Sep 6 2023, 10:10 AM · VyOS 1.4 Sagitta
Viacheslav moved T5548: HAProxy renders timeouts incorrectly from Open to Finished on the VyOS 1.5 Circinus board.
Sep 6 2023, 10:09 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T5548: HAProxy renders timeouts incorrectly as Resolved.
Sep 6 2023, 10:08 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5552: 'set system option performance throughput' enables IPv6 forwarding even if it's explicitly disabled with 'set system ipv6 disable-forwarding'.

I think that would be a bad idea comparing to other vendors where you can select if you want to do IPv4 routing and/or IPv6 routing. If both are disabled the device will only do switching/bridging.

Sep 6 2023, 9:08 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
Viacheslav added a project to T3191: PAM RADIUS freezing when accounting does not configured on RADIUS server: VyOS 1.5 Circinus.
Sep 6 2023, 8:39 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T5552: 'set system option performance throughput' enables IPv6 forwarding even if it's explicitly disabled with 'set system ipv6 disable-forwarding'.

Related task T2133
I guess we should drop this option ipv6 disable-forwarding

Sep 6 2023, 8:09 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
a.apostoliuk created T5552: 'set system option performance throughput' enables IPv6 forwarding even if it's explicitly disabled with 'set system ipv6 disable-forwarding'.
Sep 6 2023, 7:54 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
Apachez added a comment to T5546: Failed upgrade from 1.4-rolling-202212310809 to 1.4-rolling-202309030023.

Ehm, are you sure you operate on the correct config?

Sep 6 2023, 5:29 AM · VyOS 1.4 Sagitta (1.4.1)

Sep 5 2023

Viacheslav committed rVYOSONEX5ae730a52de2: T5480: Ability to disable SNMP for keepalived service VRRP.
Sep 5 2023, 11:26 PM
Viacheslav committed rVYOSONEX5f2926cf04e8: T5533: Fix for vrrp dict key if virtual-server is used.
Sep 5 2023, 11:26 PM
GitHub <noreply@github.com> committed rVYOSONEX490249bc57d9: Merge pull request #2204 from sever-sever/T5480 (authored by jestabro).
Sep 5 2023, 11:26 PM
svd135 added a comment to T5376: Conntrack FTP helper does not work properly.

Firewall can be turned off. It does not affect the result.

Sep 5 2023, 9:48 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
Viacheslav added a comment to T5521: Home owner directory changed to vyos for the user after reboot.
In T5521#158836, @c-po wrote:

Please re-test with latest rolling-release if the issue persists.

Sep 5 2023, 9:12 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a project to T5532: After add system image the boot stuck and works again after the second reboot: VyOS 1.5 Circinus.
Sep 5 2023, 9:04 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro moved T5492: CLI node priority is not inversed on node deletion from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.5) board.
Sep 5 2023, 8:48 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
jestabro moved T5492: CLI node priority is not inversed on node deletion from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 5 2023, 8:47 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
jestabro closed T5492: CLI node priority is not inversed on node deletion as Wontfix.

A workaround was provided in T5428 for the specific issue.

Sep 5 2023, 8:47 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav reopened T5533: Keepalived VRRP IPv6 group enters in FAULT state as "Needs testing".

Cannot pass smoketest for virtual-server which also uses vrrp

Sep 5 2023, 8:31 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
jestabro added a comment to T5353: config-mgmt: normalize archive updates and commit log entries.

PR for current:
https://github.com/vyos/vyos-1x/pull/2211

Sep 5 2023, 8:02 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
svd135 added a comment to T5376: Conntrack FTP helper does not work properly.

Now I'm using this build: VyOS 1.4-rolling-202301071830
It's working fine as with active as with passive FTP.

Sep 5 2023, 8:01 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
Viacheslav committed rVYOSONEX41143c901a75: T5548: Fix load-balancing reverse-proxy timeouts.
Sep 5 2023, 7:52 PM
GitHub <noreply@github.com> committed rVYOSONEX435af2778716: Merge pull request #2210 from sever-sever/T5548-sag (authored by Viacheslav).
Sep 5 2023, 7:52 PM
Viacheslav committed rVYOSONEX24d65014bbdb: T2958: Refactor DHCP-server systemd unit and lease.
Sep 5 2023, 7:51 PM
GitHub <noreply@github.com> committed rVYOSONEX17d83fe780fd: Merge pull request #2209 from sever-sever/T2958-sag (authored by Viacheslav).
Sep 5 2023, 7:51 PM
sarthurdev added a comment to T5376: Conntrack FTP helper does not work properly.

@svd135 Can you provide a version string when you last had it working? Seeing the firewall config might also be helpful.

Sep 5 2023, 7:31 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
c-po changed the status of T5521: Home owner directory changed to vyos for the user after reboot from In progress to Needs testing.
Sep 5 2023, 7:22 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta