Page MenuHomeVyOS Platform
Feed All Stories

May 23 2024

c-po added a project to T6293: add Mediatek MT7921 to defconfig: VyOS 1.4 Sagitta (1.4.0-GA).
May 23 2024, 7:58 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po moved T751: IDS and IPS (suricata) from Need Triage to Finished on the VyOS 1.5 Circinus board.
May 23 2024, 7:57 PM · VyOS 1.5 Circinus
c-po changed the status of T751: IDS and IPS (suricata) from Open to Needs testing.
May 23 2024, 7:57 PM · VyOS 1.5 Circinus
Embezzle changed the status of T6370: Add option to set custom HTTP headers in reverse-proxy responses from In progress to Needs testing.
May 23 2024, 7:50 PM · VyOS 1.5 Circinus
syncer moved T6390: Compensate for packer packaging update from Need Triage to In Progress on the VyOS 1.3 Equuleus (1.3.8) board.
May 23 2024, 7:16 PM · VyOS 1.3 Equuleus (1.3.8)
syncer edited projects for T6390: Compensate for packer packaging update, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.5 Circinus.
May 23 2024, 7:16 PM · VyOS 1.3 Equuleus (1.3.8)
syncer edited projects for T6390: Compensate for packer packaging update, added: VyOS 1.5 Circinus; removed VyOS 1.3 Equuleus.
May 23 2024, 7:09 PM · VyOS 1.3 Equuleus (1.3.8)
cjac created T6390: Compensate for packer packaging update.
May 23 2024, 4:37 PM · VyOS 1.3 Equuleus (1.3.8)
Viacheslav moved T6381: Typos in select ConfigError messages in dhcpv6-server from Need Triage to Finished on the VyOS 1.5 Circinus board.
May 23 2024, 3:53 PM · VyOS 1.5 Circinus
Giggum closed T6381: Typos in select ConfigError messages in dhcpv6-server as Resolved.

Resolved, merged PR: https://github.com/vyos/vyos-1x/pull/3508

May 23 2024, 2:53 PM · VyOS 1.5 Circinus
dmbaturin created T6389: Check architecture and flavor compatibility on upgrade attempts.
May 23 2024, 2:36 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a comment to T6363: Expose element 'secret' in xml cache and add boolean check.

Difficulty changed to normal to consider one subtlety of xml cache, and add POC for use in (a later version of) the strip-private filter. POC below; some subset of commits may be added to 1.5:
https://github.com/vyos/vyos-1x/compare/current...jestabro:example-property-secret

May 23 2024, 2:21 PM · VyOS 1.5 Circinus
jestabro changed Difficulty level from easy to normal on T6363: Expose element 'secret' in xml cache and add boolean check.
May 23 2024, 2:19 PM · VyOS 1.5 Circinus
erkin added a comment to T6352: Tool for generating valid configs based on XML schemas.

The idea is feasible for parameters with constraints (like number ranges) defined in the XML, but there are many other cases where human input is necessary. We could give the tool a set of parameters to randomly generate, or a half-complete config with slots to fill in with random values. Worst case, we'd discover new constraints for more rigid templates; best case, we'd have a proper tool for generating corner cases for smoke tests and fuzzing.

May 23 2024, 2:16 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dmbaturin created T6388: Use OCaml 4.14 for CI builds.
May 23 2024, 1:11 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
HollyGurza moved T4576: vpn l2tp logging level configuration from Need Triage to In Progress on the VyOS 1.5 Circinus board.
May 23 2024, 12:19 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
HollyGurza changed the status of T4576: vpn l2tp logging level configuration from Open to In progress.
May 23 2024, 12:19 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
HollyGurza added a comment to T4576: vpn l2tp logging level configuration.

https://github.com/vyos/vyos-1x/pull/3510

May 23 2024, 12:14 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
Vijayakumar added a comment to T6386: add caller workflows and codeowners file for vyos-build.

https://github.com/vyos/vyos-build/pull/634 Merged

May 23 2024, 7:05 AM · VyOS 1.4 Sagitta
Vijayakumar closed T6386: add caller workflows and codeowners file for vyos-build as Resolved.
May 23 2024, 7:04 AM · VyOS 1.4 Sagitta
Vijayakumar renamed T6386: add caller workflows and codeowners file for vyos-build from add caller workflows and codeowners file for vyox-build to add caller workflows and codeowners file for vyos-build.
May 23 2024, 6:11 AM · VyOS 1.4 Sagitta
Viacheslav edited projects for T6387: Bump conntrack to version 1:1.4.7-1, added: VyOS 1.5 Circinus; removed VyOS 1.4 Sagitta.
May 23 2024, 6:07 AM · VyOS 1.5 Circinus
Viacheslav created T6387: Bump conntrack to version 1:1.4.7-1.
May 23 2024, 6:07 AM · VyOS 1.5 Circinus
Vijayakumar changed the status of T6386: add caller workflows and codeowners file for vyos-build from Open to In progress.
May 23 2024, 5:14 AM · VyOS 1.4 Sagitta
Viacheslav closed T6357: Create test repository to validate setup, a subtask of T6309: Check code quality with CodeQL, as Resolved.
May 23 2024, 5:14 AM · GitHub Infrastructure
Viacheslav closed T6357: Create test repository to validate setup as Resolved.
May 23 2024, 5:14 AM · GitHub Infrastructure
Vijayakumar added a comment to T6357: Create test repository to validate setup.

Please mark this as resolved

May 23 2024, 5:13 AM · GitHub Infrastructure
Viacheslav assigned T6371: Show nat source rules shows unexpected dictionary to Giggum.
May 23 2024, 5:05 AM · Restricted Project, VyOS 1.5 Circinus
Giggum added a comment to T6371: Show nat source rules shows unexpected dictionary.

Follow up, I was able to make nat.py throw the error below.

May 23 2024, 3:10 AM · Restricted Project, VyOS 1.5 Circinus
Giggum added a comment to T6371: Show nat source rules shows unexpected dictionary.

@Viacheslav, same behaviour exists for epa3, I numbered mine 999 so as not to interfere with existing rules.

May 23 2024, 2:34 AM · Restricted Project, VyOS 1.5 Circinus

May 22 2024

Giggum added a comment to T6371: Show nat source rules shows unexpected dictionary.

@Viacheslav
Happy to dig into this if can assign it to me.

May 22 2024, 8:39 PM · Restricted Project, VyOS 1.5 Circinus
c-po added a comment to T6345: Source NAT Port Mapping setting of Fully-Random is superfluous in Kernels 5.0 onwards.

https://github.com/vyos/vyos-1x/pull/3507

May 22 2024, 7:36 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po added a project to T6345: Source NAT Port Mapping setting of Fully-Random is superfluous in Kernels 5.0 onwards: VyOS 1.5 Circinus.
May 22 2024, 7:13 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po closed T6367: op-mode: commit-archive: TypeError: attribute name must be string, not 'NoneType' as Resolved.
May 22 2024, 7:12 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po moved T6367: op-mode: commit-archive: TypeError: attribute name must be string, not 'NoneType' from In Progress to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 22 2024, 7:12 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po added a comment to T6365: Negating interface names in NAT configuration causes invalid warnings.

Same issue applies to NAT66, too

May 22 2024, 6:12 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po added a comment to T6365: Negating interface names in NAT configuration causes invalid warnings.

https://github.com/vyos/vyos-1x/pull/3482

May 22 2024, 6:07 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po changed the status of T6365: Negating interface names in NAT configuration causes invalid warnings from Open to In progress.
May 22 2024, 6:01 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
jestabro closed T5940: [1.3.5 -> 1.4.0-RC1 Migration] commit-archive Fails to Migrate, a subtask of T5938: Migration fail root task for 1.4-rc, as Resolved.
May 22 2024, 5:40 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
jestabro closed T5940: [1.3.5 -> 1.4.0-RC1 Migration] commit-archive Fails to Migrate as Resolved.
May 22 2024, 5:40 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav closed T3493: DHCPv6 does not have prefix range validation as Resolved.
May 22 2024, 5:39 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav triaged T6382: Add dkms in order to make firmware updates of NIC's possible as Wishlist priority.
May 22 2024, 5:37 PM · VyOS 1.5 Circinus
Viacheslav moved T6384: rollback-soft should tell the user to compare and commit from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 22 2024, 5:34 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav closed T6384: rollback-soft should tell the user to compare and commit as Resolved.
May 22 2024, 5:34 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
dmbaturin created T6385: interrupting rollback with Ctrl-C displays an exception trace.
May 22 2024, 5:08 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dmbaturin created T6384: rollback-soft should tell the user to compare and commit.
May 22 2024, 4:43 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
dmbaturin created T6383: Incorrect completion for rollback-soft.
May 22 2024, 4:38 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Apachez created T6382: Add dkms in order to make firmware updates of NIC's possible.
May 22 2024, 3:57 PM · VyOS 1.5 Circinus
Giggum created T6381: Typos in select ConfigError messages in dhcpv6-server.
May 22 2024, 2:56 PM · VyOS 1.5 Circinus
Giggum added a comment to T3493: DHCPv6 does not have prefix range validation.

Does 1.5 has the same bug?

May 22 2024, 2:44 PM · VyOS 1.4 Sagitta (1.4.0-GA)
HollyGurza added a project to T4576: vpn l2tp logging level configuration: VyOS 1.5 Circinus.
May 22 2024, 2:00 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin created T6380: Reorganize the directory structure in vyos-utils.
May 22 2024, 1:09 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav edited projects for T6373: QoS Policy Limiter - classes for marked traffic do not work, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta.
May 22 2024, 12:38 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav moved T3493: DHCPv6 does not have prefix range validation from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 22 2024, 12:35 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav added a comment to T3493: DHCPv6 does not have prefix range validation.

Does 1.5 has the same bug?

May 22 2024, 12:35 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav triaged T6379: "generate openvpn" uses "comp-lzo no", which leads to problems on Android-Clients as Normal priority.
May 22 2024, 12:33 PM · VyOS 1.4 Sagitta (1.4.1)
natali-rs1985 changed the status of T6227: Rewrite show conntrack-sync cache internal to use tabulate output from Open to In progress.
May 22 2024, 12:23 PM · VyOS 1.5 Circinus
Viacheslav closed T6366: CGNAT add the ability to show allocation per external or internal address, a subtask of T5169: Add CGNAT Carrier-Grade NAT based on nftables, as Resolved.
May 22 2024, 12:22 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav closed T6366: CGNAT add the ability to show allocation per external or internal address as Resolved.
May 22 2024, 12:22 PM · VyOS 1.5 Circinus
manuel81 created T6379: "generate openvpn" uses "comp-lzo no", which leads to problems on Android-Clients.
May 22 2024, 10:52 AM · VyOS 1.4 Sagitta (1.4.1)
Giggum added a comment to T3493: DHCPv6 does not have prefix range validation.

PR merged: https://github.com/vyos/vyos-1x/pull/3499/

May 22 2024, 10:46 AM · VyOS 1.4 Sagitta (1.4.0-GA)
HollyGurza claimed T4576: vpn l2tp logging level configuration.
May 22 2024, 10:28 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
Vijayakumar changed the status of T6378: move labeler.yml to reusable repo from Open to In progress.
May 22 2024, 9:48 AM · Restricted Project, VyOS 1.4 Sagitta
Vijayakumar created T6378: move labeler.yml to reusable repo.
May 22 2024, 9:38 AM · Restricted Project, VyOS 1.4 Sagitta
Vijayakumar added a comment to T6357: Create test repository to validate setup.

Done.
https://github.com/vyos/vyos-workflow-test-temp

May 22 2024, 9:27 AM · GitHub Infrastructure
a.apostoliuk closed T6359: Multicast does not forward after reboot as Resolved.
May 22 2024, 8:15 AM · VyOS 1.3 Equuleus (1.3.8)
a.apostoliuk changed the status of T6359: Multicast does not forward after reboot from In progress to Needs testing.
May 22 2024, 7:58 AM · VyOS 1.3 Equuleus (1.3.8)
aidan-gibson added a comment to T5835: UPnP port mapping / rule installation fails.

I'd prefer to integrate the Port Control Protocol (PCP) instead.

pcp.png (410×767 px, 50 KB)

May 22 2024, 7:58 AM
Res added a comment to T5835: UPnP port mapping / rule installation fails.

You can still have it in a container easily; as I mentioned, it has never worked since 2021
You do not lose anything.

May 22 2024, 7:30 AM
HollyGurza moved T6373: QoS Policy Limiter - classes for marked traffic do not work from Need Triage to In Progress on the VyOS 1.5 Circinus board.
May 22 2024, 7:22 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
HollyGurza moved T6373: QoS Policy Limiter - classes for marked traffic do not work from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
May 22 2024, 7:22 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
HollyGurza claimed T6373: QoS Policy Limiter - classes for marked traffic do not work.
May 22 2024, 7:21 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

May 21 2024

jestabro added a comment to T5940: [1.3.5 -> 1.4.0-RC1 Migration] commit-archive Fails to Migrate.

PR merged into vyos-utils:
https://github.com/vyos/vyos-utils/pull/20
and backported. The fix has been tested with migration from 1.3.x with settings as suggested by @trae32566

May 21 2024, 6:49 PM · VyOS 1.4 Sagitta (1.4.0-GA)
syncer lowered the priority of T5584: System cannot boot with commit-arachive location sftp in some cases from High to Normal.
May 21 2024, 5:22 PM · Restricted Project, VyOS 1.3 Equuleus (1.3.9)
jestabro added a comment to T5584: System cannot boot with commit-arachive location sftp in some cases.

Yes, @c-po that would be a reasonable explanation; the timeout was added for Equuleus by 1.3.4. Without a reporting user to ask; other reports on later version; or further information, I would vote to close ...

May 21 2024, 5:19 PM · Restricted Project, VyOS 1.3 Equuleus (1.3.9)
manuel81 created T6377: PermissionError on /config/auth/letsencrypt/live/ when running show pki.
May 21 2024, 4:40 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
L0crian updated the task description for T6375: Fix/Update NAT Logging.
May 21 2024, 4:37 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
L0crian created T6376: EVPN-MH uplink command not fully working correctly (protodown not supported).
May 21 2024, 3:53 PM · Restricted Project, VyOS 1.5 Circinus, VyOS 1.4 Sagitta
HollyGurza added a comment to T6373: QoS Policy Limiter - classes for marked traffic do not work.

https://github.com/vyos/vyos-1x/pull/3494

May 21 2024, 2:06 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
natali-rs1985 updated the task description for T6374: Openvpn site-to-site mode with TLS not starting.
May 21 2024, 1:59 PM · VyOS 1.5 Circinus
L0crian added a comment to T6375: Fix/Update NAT Logging.

PR: https://github.com/vyos/vyos-1x/pull/3493

May 21 2024, 1:57 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
natali-rs1985 updated the task description for T6374: Openvpn site-to-site mode with TLS not starting.
May 21 2024, 1:56 PM · VyOS 1.5 Circinus
natali-rs1985 updated the task description for T6374: Openvpn site-to-site mode with TLS not starting.
May 21 2024, 1:55 PM · VyOS 1.5 Circinus
natali-rs1985 updated the task description for T6374: Openvpn site-to-site mode with TLS not starting.
May 21 2024, 1:53 PM · VyOS 1.5 Circinus
L0crian created T6375: Fix/Update NAT Logging.
May 21 2024, 1:10 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro claimed T5940: [1.3.5 -> 1.4.0-RC1 Migration] commit-archive Fails to Migrate.
May 21 2024, 1:03 PM · VyOS 1.4 Sagitta (1.4.0-GA)
jestabro updated subscribers of T5940: [1.3.5 -> 1.4.0-RC1 Migration] commit-archive Fails to Migrate.

The argument would be to relax the url validator regex for compatibility with 1.3: since the plan is to replace this mechanism in 1.5 with something similar to @trae32566 suggestion above (brought up for discussion by @Viacheslav recently), and since it is deprecated/not advised anyway (RFC 3986). The simple change will be made to the validator.

May 21 2024, 1:02 PM · VyOS 1.4 Sagitta (1.4.0-GA)
natali-rs1985 created T6374: Openvpn site-to-site mode with TLS not starting.
May 21 2024, 12:26 PM · VyOS 1.5 Circinus
HollyGurza moved T5307: QoS - traffic-class-map services from Need Triage to In Progress on the VyOS 1.5 Circinus board.
May 21 2024, 10:11 AM · VyOS 1.5 Circinus
HollyGurza moved T5307: QoS - traffic-class-map services from Need Triage to In Progress on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 21 2024, 10:11 AM · VyOS 1.5 Circinus
HollyGurza moved T6225: Unhandled exception when configuring random-detect QoS policy from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 21 2024, 10:09 AM · VyOS 1.4 Sagitta (1.4.0-GA)
HollyGurza closed T6225: Unhandled exception when configuring random-detect QoS policy as Resolved.
May 21 2024, 10:09 AM · VyOS 1.4 Sagitta (1.4.0-GA)
HollyGurza changed the status of T5307: QoS - traffic-class-map services from Open to In progress.
May 21 2024, 10:05 AM · VyOS 1.5 Circinus
HollyGurza added a comment to T5307: QoS - traffic-class-map services .

https://github.com/vyos/vyos-1x/pull/3492

May 21 2024, 10:05 AM · VyOS 1.5 Circinus
natali-rs1985 closed T6328: Add a warning message about deprecation of web proxy URL filtering as Resolved.
May 21 2024, 9:42 AM · VyOS 1.4 Sagitta (1.4.0-GA)
natali-rs1985 closed T4393: sstp: add support for configuring host-name (SNI) as Resolved.
May 21 2024, 9:40 AM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav added a comment to T6247: Add CGN "full cone" EIF support per RFC6888 REQ-7.

https://github.com/debiansid/nftables-fullcone

May 21 2024, 9:33 AM
natali-rs1985 closed T6348: SNAT op-mode fails with flowtable offload entries as Resolved.
May 21 2024, 9:32 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav changed the status of T6366: CGNAT add the ability to show allocation per external or internal address, a subtask of T5169: Add CGNAT Carrier-Grade NAT based on nftables, from Open to In progress.
May 21 2024, 8:18 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav changed the status of T6366: CGNAT add the ability to show allocation per external or internal address from Open to In progress.
May 21 2024, 8:18 AM · VyOS 1.5 Circinus