Page MenuHomeVyOS Platform
Feed All Stories

Mar 18 2024

Viacheslav closed T3522: policy based routing not working, a subtask of T3505: Commits do not respect changes in FRR that are not stored in a config, as Not Applicable.
Mar 18 2024, 9:13 AM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav closed T3522: policy based routing not working as Not Applicable.

@matthewr Thanks for confirming!
Closing it as resolved now. Feel free to reopen or create a new one if this bug remains again.

Mar 18 2024, 9:13 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
Viacheslav triaged T6135: HTTPS API endpoint to check if an empty config exists as Normal priority.
Mar 18 2024, 9:10 AM · VyOS 1.5 Circinus
Viacheslav triaged T6131: Disabling openvpn interface(s) causes OSPF to fail to load on reboot as High priority.
Mar 18 2024, 9:07 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav changed the status of T6136: Configuring a dynamic address group, config script did not check whether the group was created from Open to Confirmed.
Mar 18 2024, 9:06 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6137: dhcp files and directory permission not correct after image uprgading as Normal priority.
Mar 18 2024, 9:04 AM · VyOS 1.5 Circinus
opswill created T6137: dhcp files and directory permission not correct after image uprgading .
Mar 18 2024, 4:38 AM · VyOS 1.5 Circinus
wenzk created T6136: Configuring a dynamic address group, config script did not check whether the group was created.
Mar 18 2024, 1:23 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 17 2024

GitHub <noreply@github.com> committed rVYOSONEX42f3b83dd898: Merge pull request #3142 from vyos/mergify/bp/sagitta/pr-3139 (authored by c-po).
Mar 17 2024, 8:46 PM
GitHub <noreply@github.com> committed rVYOSONEX2942040d8099: Merge pull request #3141 from vyos/mergify/bp/sagitta/pr-3140 (authored by c-po).
Mar 17 2024, 8:45 PM
c-po claimed T6131: Disabling openvpn interface(s) causes OSPF to fail to load on reboot.
Mar 17 2024, 6:12 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
trae32566 added a comment to T6132: Conntrack-sync Internal Cache Growing Uncontrollably.

Here's the generated configuration from /run/conntrackd/conntrackd.conf:

# Synchronizer settings
Sync {
    Mode FTFW {
        DisableExternalCache on
    }
    Multicast {
        IPv4_address 225.0.0.50
        Group 3780
        IPv4_interface 192.168.15.3
        Interface bond0.110
        SndSocketBuffer 104857600
        RcvSocketBuffer 104857600
        Checksum on
    }
}
Helper {
    Type rpc inet tcp {
        QueueNum 3
        Policy rpc {
            ExpectMax 1
            ExpectTimeout 300
        }
    }
    Type rpc inet udp {
        QueueNum 4
        Policy rpc {
            ExpectMax 1
            ExpectTimeout 300
        }
    }
    Type tns inet tcp {
        QueueNum 5
        Policy tns {
            ExpectMax 1
            ExpectTimeout 300
        }
    }
}
Mar 17 2024, 5:41 PM · VyOS Rolling, Bugs
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXc54b1fd63d5a: policy: T6129: add route-map option "as-path exclude all" (authored by c-po).
Mar 17 2024, 5:19 PM
GitHub <noreply@github.com> committed rVYOSONEX987b7e599fda: Merge pull request #3139 from c-po/as-path-T6129 (authored by c-po).
Mar 17 2024, 5:17 PM
c-po committed rVYOSONEX16395c902ff7: policy: T6129: add route-map option "as-path exclude all".
Mar 17 2024, 5:17 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX443c9018a55e: T6133: append domain-name to commit-archive if defined (authored by c-po).
Mar 17 2024, 5:12 PM
c-po committed rVYOSONEX4291a1a423c3: T6133: append domain-name to commit-archive if defined.
Mar 17 2024, 5:11 PM
GitHub <noreply@github.com> committed rVYOSONEX2bf1aeb17f83: Merge pull request #3140 from c-po/config-mgmt-T6133 (authored by c-po).
Mar 17 2024, 5:11 PM
penetal updated the task description for T6135: HTTPS API endpoint to check if an empty config exists.
Mar 17 2024, 4:32 PM · VyOS 1.5 Circinus
penetal created T6135: HTTPS API endpoint to check if an empty config exists.
Mar 17 2024, 4:31 PM · VyOS 1.5 Circinus
robertoberto closed T6134: AttributeError in vyos_unattended_installer.py When Installing GRUB Configuration as Resolved.
Mar 17 2024, 3:58 PM · Unknown Object (Project)
robertoberto added a comment to T6134: AttributeError in vyos_unattended_installer.py When Installing GRUB Configuration.

Fixed in https://github.com/vyos/vyos-1x/commit/84b520dd580b7725de4c9e62b11ec490cb8d3f4f. The 1.4.0-epa2 build was created before the patch was applied.

Mar 17 2024, 3:58 PM · Unknown Object (Project)
matthewr added a comment to T3522: policy based routing not working.

Just in case it helps, after a migration from 1.3 to 1.4.0-epa2, the migrated config ends up as:-

Mar 17 2024, 3:34 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
robertoberto created T6134: AttributeError in vyos_unattended_installer.py When Installing GRUB Configuration.
Mar 17 2024, 3:17 PM · Unknown Object (Project)
c-po updated the task description for T6133: Add domain-name to commit-archive.
Mar 17 2024, 1:47 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po added a comment to T6133: Add domain-name to commit-archive.

https://github.com/vyos/vyos-1x/pull/3140

Mar 17 2024, 1:47 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po changed the status of T6133: Add domain-name to commit-archive, a subtask of T4942: Rewrite vyatta-config-mgmt to Python/XML, from Open to In progress.
Mar 17 2024, 1:42 PM · VyOS 1.4 Sagitta
c-po changed the status of T6133: Add domain-name to commit-archive from Open to In progress.
Mar 17 2024, 1:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po created T6133: Add domain-name to commit-archive.
Mar 17 2024, 1:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
trae32566 triaged T6132: Conntrack-sync Internal Cache Growing Uncontrollably as High priority.
Mar 17 2024, 12:35 PM · VyOS Rolling, Bugs
matthewr added a comment to T6076: [1.3.3->1.4.0-epa1 Migration] Most of config missing.

See T6131 for a report of the VTUN/OSPF issue with a simple lab config, which occurs separately from a migration.

Mar 17 2024, 10:26 AM · Bugs, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
matthewr created T6131: Disabling openvpn interface(s) causes OSPF to fail to load on reboot.
Mar 17 2024, 10:22 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
matthewr created T6130: [1.3.6->1.4.0-epa2 Migration] BGP "set community" missing.
Mar 17 2024, 9:48 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po added a comment to T6129: bgp: add route-map option "as-path exclude all".

https://github.com/vyos/vyos-1x/pull/3139

Mar 17 2024, 7:44 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po updated the task description for T6129: bgp: add route-map option "as-path exclude all".
Mar 17 2024, 7:42 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po changed the status of T6129: bgp: add route-map option "as-path exclude all" from Open to In progress.
Mar 17 2024, 7:40 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po changed the status of T6129: bgp: add route-map option "as-path exclude all", a subtask of T5788: frr: update to 9.1 release, from Open to In progress.
Mar 17 2024, 7:40 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po created T6129: bgp: add route-map option "as-path exclude all".
Mar 17 2024, 7:40 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 16 2024

dmbaturin added a comment to T6128: minisign.pub is wrong on https://vyos.net/get/nightly-builds/.

We'll update the key and make a post about it soon, sorry for the lengthy mix-up.

Mar 16 2024, 8:30 PM · VyOS 1.5 Circinus
robertoberto added a comment to T6128: minisign.pub is wrong on https://vyos.net/get/nightly-builds/.

comments above are for https://vyos.net/get/nightly-builds/

Mar 16 2024, 5:51 PM · VyOS 1.5 Circinus
robertoberto created T6128: minisign.pub is wrong on https://vyos.net/get/nightly-builds/.
Mar 16 2024, 5:34 PM · VyOS 1.5 Circinus
penetal added a comment to T5083: extend interface schema to include which parameters are required.

Bumped into another instance of this issue:

curl -k --location --request POST "https://$VYOS_HOST/configure" --form key="$VYOS_KEY" --form data='[{"op":"set","path":["policy", "access-list", "2", "rule", "5", "description", "2024-03-16T14:52:44Z"]}]'
{"success": false, "error": "[[policy]] failed\nCommit failed\n", "data": null}
Mar 16 2024, 2:59 PM · VyOS Rolling
c-po moved T4022: Add package nat-rtsp-dkms from Open to Finished on the VyOS 1.5 Circinus board.
Mar 16 2024, 11:33 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
GitHub <noreply@github.com> committed rVYOSONEX5daebff4a5cc: Merge pull request #3112 from Ingramz/add-rtsp-2 (authored by c-po).
Mar 16 2024, 11:33 AM
Indrek Ardel <indrek@ardel.eu> committed rVYOSONEX3e1e2a3e7b6f: conntrack: T4022: add RTSP conntrack helper.
Mar 16 2024, 11:33 AM
c-po added a project to T4022: Add package nat-rtsp-dkms: VyOS 1.4 Sagitta (1.4.0).
Mar 16 2024, 11:33 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
GitHub <noreply@github.com> committed rVYOSONEXd18d773238ef: Merge pull request #3138 from vyos/mergify/bp/sagitta/pr-3137 (authored by dmbaturin).
Mar 16 2024, 11:22 AM
penetal added a comment to T6069: HTTP API segfault during concurrent configuration requests.

@jestabro I have tested my usecase now and it seems the problem is fixed and the API no longer segfaults. Thank you so much for the fix and the fantastic turn around on this.

Mar 16 2024, 9:11 AM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
Viacheslav committed rVYOSONEX25b611f50452: T6121: Extend service config-sync to new sections.
Mar 16 2024, 8:47 AM
GitHub <noreply@github.com> committed rVYOSONEXaea9bfb803c8: Merge pull request #3132 from sever-sever/T6121 (authored by c-po).
Mar 16 2024, 8:47 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX4413e5b633c6: T6090: fix policy route migration script. Ensure that tcp flags migration… (authored by n.fort).
Mar 16 2024, 8:47 AM
n.fort committed rVYOSONEX1048f49e403d: T6090: fix policy route migration script. Ensure that tcp flags migration….
Mar 16 2024, 8:46 AM
GitHub <noreply@github.com> committed rVYOSONEX828e94d7cb67: Merge pull request #3137 from nicolas-fort/T6090-policy (authored by c-po).
Mar 16 2024, 8:46 AM

Mar 15 2024

L0crian added a comment to T6127: Ability to view logs for rules with Offload not functional.

Should add the ability to view the default action log would be nice as well.

Mar 15 2024, 10:33 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
L0crian renamed T6127: Ability to view logs for rules with Offload not functional from Ability to view logs for rules with Offload not available to Ability to view logs for rules with Offload not functional.
Mar 15 2024, 10:09 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
L0crian created T6127: Ability to view logs for rules with Offload not functional.
Mar 15 2024, 10:06 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity.

PR for 1.5: https://github.com/vyos/vyos-1x/pull/3137

Mar 15 2024, 9:45 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a project to T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity: VyOS 1.5 Circinus.
Mar 15 2024, 9:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
anonuser445y6 added a comment to T6126: Unable to add image.

I can download the image and add it from path just fine, e.g this works fine:

Mar 15 2024, 7:45 PM · VyOS 1.4 Sagitta
anonuser445y6 created T6126: Unable to add image.
Mar 15 2024, 7:31 PM · VyOS 1.4 Sagitta
daniil renamed T6125: Support 802.1ad (0x88a8) vlan filtering for bridge from Support 802.1ad (0x88a8) for bridge to Support 802.1ad (0x88a8) vlan filtering for bridge.
Mar 15 2024, 6:10 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
daniil created T6125: Support 802.1ad (0x88a8) vlan filtering for bridge.
Mar 15 2024, 6:07 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Apachez added a comment to T6091: [1.3.3->1.4.0-epa1 Migration] NTP "listen-address" config removed.

Proper would be to throw out chrony and use ntpsec instead which supports proper filtering.

Mar 15 2024, 5:06 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T6124: Docker equuleus build image doesn't build due to fpm, added: VyOS 1.3 Equuleus (1.3.7); removed VyOS 1.3 Equuleus.
Mar 15 2024, 3:46 PM · VyOS 1.3 Equuleus (1.3.7)
Viacheslav triaged T6124: Docker equuleus build image doesn't build due to fpm as High priority.
Mar 15 2024, 3:45 PM · VyOS 1.3 Equuleus (1.3.7)
matthewr added a comment to T6091: [1.3.3->1.4.0-epa1 Migration] NTP "listen-address" config removed.

Given that Chrony only allows one bind address, versus ntpd which allows multiple, a "wontfix" sounds like the correct answer! :-)

Mar 15 2024, 3:12 PM · VyOS 1.4 Sagitta
MattK updated the task description for T6124: Docker equuleus build image doesn't build due to fpm.
Mar 15 2024, 3:02 PM · VyOS 1.3 Equuleus (1.3.7)
MattK created T6124: Docker equuleus build image doesn't build due to fpm.
Mar 15 2024, 2:57 PM · VyOS 1.3 Equuleus (1.3.7)
n.fort changed the status of T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity, a subtask of T5938: Migration fail root task for 1.4-rc, from Open to Confirmed.
Mar 15 2024, 2:33 PM · VyOS Rolling, Bugs
n.fort changed the status of T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity from Open to Confirmed.
Mar 15 2024, 2:33 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6116: VyOS can't work as expected at k8s platform as Normal priority.
Mar 15 2024, 2:30 PM · VyOS Rolling, Bugs
Viacheslav changed the status of T6109: remote syslog does not get all the logs from Open to Needs reporter action.

@m.serdienis Add set of configuration commands to reproduce.

Mar 15 2024, 2:26 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po closed T6091: [1.3.3->1.4.0-epa1 Migration] NTP "listen-address" config removed as Wontfix.
Mar 15 2024, 2:26 PM · VyOS 1.4 Sagitta
c-po added a comment to T6091: [1.3.3->1.4.0-epa1 Migration] NTP "listen-address" config removed.

The issue is which to choose if there are multiple, thus removing all, chrony will listen on all interfaces.

Mar 15 2024, 2:26 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T6108: VTYSH - Slowdown, added: VyOS 1.3 Equuleus (1.3.7); removed VyOS 1.3 Equuleus.
Mar 15 2024, 2:25 PM
Viacheslav triaged T6108: VTYSH - Slowdown as Normal priority.
Mar 15 2024, 2:25 PM
Viacheslav triaged T6106: Improve the commit error message for the case when route-reflector-client option is defined in a peer-group as High priority.
Mar 15 2024, 2:24 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6105: Service HTTPS using ACME certificate does not present full chain as Normal priority.
Mar 15 2024, 2:24 PM · VyOS 1.5 Circinus
Viacheslav triaged T6092: Static interface index as Wishlist priority.
Mar 15 2024, 2:23 PM
Viacheslav triaged T6091: [1.3.3->1.4.0-epa1 Migration] NTP "listen-address" config removed as Normal priority.

Most likely won't fix
https://chrony-project.org/doc/3.4/chrony.conf.html

Mar 15 2024, 2:23 PM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity: T5938: Migration fail root task for 1.4-rc.
Mar 15 2024, 2:02 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a subtask for T5938: Migration fail root task for 1.4-rc: T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity.
Mar 15 2024, 2:02 PM · VyOS Rolling, Bugs
Viacheslav triaged T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity as High priority.
Mar 15 2024, 2:01 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6120: integration speedtest cli as Wishlist priority.

I don't think it is expected to get speed to the node itself.
A router is generally used for forwarding traffic. It is better to use iperf to check the speed between 2 hosts.

Mar 15 2024, 1:54 PM · VyOS 1.5 Circinus
c-po closed T6118: radvd: RFC8781: add nat64prefix support as Resolved.
Mar 15 2024, 12:39 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po moved T6118: radvd: RFC8781: add nat64prefix support from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0) board.
Mar 15 2024, 12:39 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Apachez added a comment to T4610: Firewall with 20K entries cannot load after reboot.

There do already exists tasks regarding commit and boot times such as: https://vyos.dev/T5388

Mar 15 2024, 10:35 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4610: Firewall with 20K entries cannot load after reboot.

@Apachez the original issue was related nft

If use nftables natively as:
Mar 15 2024, 7:54 AM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEXa0b2b259484d: Merge pull request #3136 from vyos/mergify/bp/sagitta/pr-3135 (authored by c-po).
Mar 15 2024, 6:25 AM
GitHub <noreply@github.com> committed rVYOSONEXdbd54c1ed094: Merge pull request #3134 from vyos/mergify/bp/sagitta/pr-3133 (authored by c-po).
Mar 15 2024, 6:25 AM
Giggum changed Version from - to VyOS 1.4.0-epa1 on T6123: Limit NTP allow-client config to internal addresses by default.
Mar 15 2024, 1:01 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Giggum created T6123: Limit NTP allow-client config to internal addresses by default.
Mar 15 2024, 12:43 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Mar 14 2024

Apachez added a comment to T4610: Firewall with 20K entries cannot load after reboot.

I wouldnt call 1m37s of commit time for a single line of configchange as "resolved"...

Mar 14 2024, 10:33 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Also probably related: https://forum.vyos.io/t/long-commit-time-for-multiple-vrfs/14053

Mar 14 2024, 8:48 PM · VyOS Rolling, Bugs
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXaacdd44508d3: xml: T160: improve NAT64 help string (authored by c-po).
Mar 14 2024, 8:32 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX25005a9a95f5: xml: T2518: improve NAT66/NPTv6 help string (authored by c-po).
Mar 14 2024, 8:32 PM
c-po committed rVYOSONEX63de63f43aaa: xml: T2518: improve NAT66/NPTv6 help string.
Mar 14 2024, 8:31 PM
c-po committed rVYOSONEX7ca0ad917440: xml: T160: improve NAT64 help string.
Mar 14 2024, 8:31 PM
GitHub <noreply@github.com> committed rVYOSONEXf237e75e9fd1: Merge pull request #3135 from c-po/xml-nat66 (authored by c-po).
Mar 14 2024, 8:31 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX8bd803ec62e9: xml: T3642: improve PKI CLI help string (authored by c-po).
Mar 14 2024, 8:20 PM