Page MenuHomeVyOS Platform
Feed All Stories

Wed, Jan 21

Firefishy added a comment to T8196: MTU adjust-mss currently only modifying TCP SYN MSS in single direction.

Also both to IPv4 and IPv6 per applicable vyos adjust-mss options.

Wed, Jan 21, 1:17 PM · VyOS Rolling
Firefishy created T8196: MTU adjust-mss currently only modifying TCP SYN MSS in single direction.
Wed, Jan 21, 1:15 PM · VyOS Rolling
SrividyaA triaged T8195: "restart ipsec" command does not reinitiate the ipsec connection in DMVPN setup as Normal priority.
Wed, Jan 21, 12:59 PM
SrividyaA created T8195: "restart ipsec" command does not reinitiate the ipsec connection in DMVPN setup.
Wed, Jan 21, 12:59 PM
sarthurdev added a comment to T8049: Add support for MaxMind GeoIP database.

PR: https://github.com/vyos/vyos-1x/pull/4949

Wed, Jan 21, 12:18 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q4), VyOS Rolling
sarthurdev added a comment to T7926: Refactor and improve geoip handling.

PR: https://github.com/vyos/vyos-1x/pull/4949

Wed, Jan 21, 12:18 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q4), VyOS Rolling
Viacheslav changed the status of T8135: CVE-2025-68615: remote DoS in snmptrapd from Open to In progress.
Wed, Jan 21, 11:57 AM · VyOS Rolling
patient0 added a comment to T7857: Add Realtek r8126 driver.

@patient0 could you confirm it works as expected?

Wed, Jan 21, 8:53 AM · VyOS Rolling
hedrok closed T6962: FRR zebra: Kernel routes are not updated properly as Resolved.

Still under review in FRR, but merged as FRR patch in VyOS.

Wed, Jan 21, 7:04 AM · VyOS 1.5 Circinus (2025.11)
hedrok closed T8046: Provide CLI for FRR link-params and mpls-te export as Resolved.

Done.

Wed, Jan 21, 7:01 AM · VyOS Rolling
hedrok closed T8131: Fix FRR build after SNMP update as Not Applicable.

It was decided to roll back SNMP update, so fix is not needed.

Wed, Jan 21, 6:59 AM · VyOS Rolling
hedrok added a comment to T8158: ISIS: lsp-refresh-interval does not accept higher value other than default 900.

PR: https://github.com/vyos/vyos-1x/pull/4938

Wed, Jan 21, 6:57 AM
hedrok closed T8159: Clean up after pmacct removal as Resolved.

Resolved with https://github.com/vyos/vyos-build/pull/1098

Wed, Jan 21, 6:54 AM · VyOS Rolling

Tue, Jan 20

dmbaturin added a comment to T8135: CVE-2025-68615: remote DoS in snmptrapd.

https://github.com/vyos/vyos-build/pull/1105

Tue, Jan 20, 4:43 PM · VyOS Rolling
Viacheslav assigned T7924: dns-dynamic 0-to-1 probably missing migration of rfc2136 -> nsupdate to o.kuchmystyi.
Tue, Jan 20, 2:46 PM · VyOS Rolling
Viacheslav changed the status of T7703: DHCP default route lost in VRF when no static route defined from Open to Needs testing.

@dsg, could you re-check the latest rolling?

Tue, Jan 20, 2:26 PM · VyOS Rolling
Viacheslav closed T7766: add support to receive multiple labels in BGP-LU - FRR feature! as Resolved.
Tue, Jan 20, 2:23 PM · VyOS Rolling
Viacheslav changed the status of T7857: Add Realtek r8126 driver from Open to Needs testing.
Tue, Jan 20, 2:12 PM · VyOS Rolling
Viacheslav added a comment to T7857: Add Realtek r8126 driver.

@patient0 could you confirm it works as expected?

Tue, Jan 20, 2:12 PM · VyOS Rolling
Viacheslav added a comment to T7937: local role attribute can be set multiple times.

@peterablehmann It is not clear what you want in this task. Could you clarify?
Under local-role peer, the strict option is available.

vyos@r16# set vrf name net protocols bgp neighbor 11::5 local-role peer 
Possible completions:
   strict               Neighbor must send this exact capability, otherwise a role
                        missmatch notification will be sent
Tue, Jan 20, 12:13 PM · VyOS Rolling
Viacheslav closed T7982: consolidate container run arguments as Resolved.
Tue, Jan 20, 11:46 AM · VyOS Rolling
Viacheslav closed T8162: Consider switching to more active ipt_NETFLOW fork as Resolved.
Tue, Jan 20, 10:56 AM · VyOS Rolling
Viacheslav moved T8145: LUKS Encryption Passphrase Observable from Need Triage to Completed on the VyOS Rolling board.
Tue, Jan 20, 10:40 AM · VyOS Rolling
Viacheslav closed T8145: LUKS Encryption Passphrase Observable as Resolved.
Tue, Jan 20, 10:40 AM · VyOS Rolling
Viacheslav closed T8146: Confirm the key when config encryption is configured without TPM as Resolved.
Tue, Jan 20, 10:37 AM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav closed T8138: Modifying firewall groups does not update dependent NAT66 nft rules as Resolved.
Tue, Jan 20, 10:34 AM · VyOS Rolling
Viacheslav closed T8096: Normalize operational mode command names that use capital letters as Resolved.

PR https://github.com/vyos/vyos-1x/pull/4897

Tue, Jan 20, 10:22 AM · VyOS Rolling
Viacheslav added a comment to T8083: tacacs: nss_tacplus: buffer truncated due to size limitation.

PR https://github.com/vyos/libnss-tacplus/pull/4

Tue, Jan 20, 10:21 AM · VyOS Rolling, VyOS 1.5 Circinus (1.5-stream-2025-Q4)
Viacheslav assigned T8083: tacacs: nss_tacplus: buffer truncated due to size limitation to Ritika.
Tue, Jan 20, 10:20 AM · VyOS Rolling, VyOS 1.5 Circinus (1.5-stream-2025-Q4)
Viacheslav added a comment to T8065: Add the ability to start smoketests on arm64 platform.

Updated PR https://github.com/vyos/vyos-build/pull/1092

Tue, Jan 20, 10:02 AM · VyOS Rolling
Viacheslav changed the status of T8190: Password for vyos user in Proxmox image always needs setting from Resolved to Invalid.
Tue, Jan 20, 9:26 AM · VyOS 1.4 Sagitta
Viacheslav closed T8091: New accounts for vyos.dev cannot be created as Not Applicable.
Tue, Jan 20, 9:25 AM
Viacheslav moved T7594: The `respond` connection-type in IPSec peer settings must be renamed to `trap` from Need Triage to Completed on the VyOS Rolling board.
Tue, Jan 20, 9:23 AM · VyOS 1.5 Circinus, VyOS Rolling
Viacheslav closed T7594: The `respond` connection-type in IPSec peer settings must be renamed to `trap` as Resolved.
Tue, Jan 20, 9:23 AM · VyOS 1.5 Circinus, VyOS Rolling
Viacheslav changed the status of T8022: Do not assign dynamic prefix assignment mode to transport-mode IPsec tunnels from Open to In progress.
Tue, Jan 20, 9:22 AM · VyOS 1.5 Circinus
Viacheslav added a comment to T7860: VPP DHCP address cannot be assigned on some clouds.

Should be fixed after merging https://github.com/vyos/vyos-1x/pull/4942

Tue, Jan 20, 8:59 AM · VyOS Rolling

Mon, Jan 19

evgmol added a comment to T8152: Re-instate (vyos.vyos.vyos_command) module parameter support for answer, prompt.

New Playbook

Mon, Jan 19, 8:26 PM · VyOS Ansible Collection
dmbaturin updated the task description for T8193: Show a more descriptive error on trying to use non-existent build types.
Mon, Jan 19, 7:09 PM · VyOS Rolling
dmbaturin renamed T8193: Show a more descriptive error on trying to use non-existent build types from Show a more descriptive error on trying to use non-existent build types and architectures to Show a more descriptive error on trying to use non-existent build types.
Mon, Jan 19, 6:56 PM · VyOS Rolling
dmbaturin created T8194: Use exceptions instead of direct exit calls in the image build script.
Mon, Jan 19, 6:13 PM · VyOS Rolling
dmbaturin created T8193: Show a more descriptive error on trying to use non-existent build types.
Mon, Jan 19, 6:06 PM · VyOS Rolling
bmtauer closed T8190: Password for vyos user in Proxmox image always needs setting as Resolved.
Mon, Jan 19, 3:16 PM · VyOS 1.4 Sagitta
bmtauer added a comment to T8190: Password for vyos user in Proxmox image always needs setting.

Thank you. I see my mistake now. When I read under step 3, "Optionally, the user can attach a CDROM with an ISO as a cloud-init data source", it left me with the impression this was *optional*—that skipping this would not cause problems. I didn't realize that it would mean no default username/password would be set.

Mon, Jan 19, 3:16 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T8190: Password for vyos user in Proxmox image always needs setting.

If you use the official proxmox image, you have to use cloud-init to set login/pass for the proxmox flavors.
Feel free to improve the documentation.
Thanks.

Mon, Jan 19, 2:51 PM · VyOS 1.4 Sagitta
bmtauer added a comment to T8190: Password for vyos user in Proxmox image always needs setting.

What is the intended way to apply configuration to a newly created proxmox flavor instance? At the page I referenced, it doesn't give any indication how to login or add a configuration under the "deploy from qcow2" section. Under the deploy from rolling release, it does mention the normal default vyos/vyos credentials.

Mon, Jan 19, 2:11 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T8165: Add operational commands to display PKI private keys and certificate bundles in PEM format.

We will get rid of this in the near future if we implement it now.
If we are focusing on the Common Criteria Profile for Network Devices, it is not accepted.
Needs to figure out in which form we can/should implement it if we want.

Mon, Jan 19, 12:11 PM · VyOS Rolling
Viacheslav triaged T8189: Configuration of conntrackd PurgeTimeout at the vbash level as Normal priority.
Mon, Jan 19, 12:08 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q4), VyOS Rolling, VyOS 1.4 Sagitta
Viacheslav added a comment to T8190: Password for vyos user in Proxmox image always needs setting.

Proxmox images don't use any default passwords.
You use this flavour incorrectly.

Mon, Jan 19, 12:04 PM · VyOS 1.4 Sagitta
Viacheslav triaged T8192: VPP: pppoe server doesn't work with xdp driver as Normal priority.
Mon, Jan 19, 11:59 AM · VyOS Rolling
Viacheslav added a comment to T8192: VPP: pppoe server doesn't work with xdp driver.

We should dissalow to configure PPPoE if we use XDP, XDP wasn't implemented for VPP/PPPoE

Mon, Jan 19, 11:59 AM · VyOS Rolling
Viacheslav added a comment to T8191: Improve clarity of the Packets and Bytes column headings in the show firewall command output..

In my opinion the headers are correct.
It could be described in the documentation.

Mon, Jan 19, 11:57 AM
natali-rs1985 changed the status of T8188: VPP: DHCP client on an interface breaks its configuration, a subtask of T7070: VPP related bugs the root task, from Open to In progress.
Mon, Jan 19, 10:17 AM · VyOS Rolling
natali-rs1985 changed the status of T8188: VPP: DHCP client on an interface breaks its configuration from Open to In progress.
Mon, Jan 19, 10:17 AM · VyOS Rolling
Viacheslav closed T8181: The kernel CONFIG_MODULE_SIG is missed for the ARM64 as Resolved.
Mon, Jan 19, 9:51 AM · VyOS Rolling

Sun, Jan 18

n.sambajon updated the task description for T8191: Improve clarity of the Packets and Bytes column headings in the show firewall command output..
Sun, Jan 18, 10:29 PM
a.kudientsov added a subtask for T7070: VPP related bugs the root task: T8192: VPP: pppoe server doesn't work with xdp driver.
Sun, Jan 18, 8:23 PM · VyOS Rolling
a.kudientsov added a parent task for T8192: VPP: pppoe server doesn't work with xdp driver: T7070: VPP related bugs the root task.
Sun, Jan 18, 8:23 PM · VyOS Rolling
a.kudientsov created T8192: VPP: pppoe server doesn't work with xdp driver.
Sun, Jan 18, 8:23 PM · VyOS Rolling
Firefishy added a comment to T7101: Add hardware watchdog support via systemd.

I can confirm it is now working on my system since https://github.com/vyos/vyos-1x/pull/4946

Sun, Jan 18, 3:20 PM · VyOS Rolling

Sat, Jan 17

c-po moved T7483: SSH FIDO2 Support from Need Triage to Completed on the VyOS Rolling board.
Sat, Jan 17, 8:54 AM · VyOS 1.5 Circinus, VyOS Rolling
c-po added a project to T7483: SSH FIDO2 Support: VyOS 1.5 Circinus.
Sat, Jan 17, 8:54 AM · VyOS 1.5 Circinus, VyOS Rolling
GitHub <noreply@github.com> committed rVYOSONEX0868f3dc7246: Merge pull request #4852 from scj643/ssh-fido2-options (authored by c-po).
Sat, Jan 17, 8:54 AM
c-po committed rVYOSONEX2473e1bfdeeb: ssh: T7483: Add fido2 PubkeyAuthOptions (authored by scj643).
Sat, Jan 17, 8:54 AM
GitHub <noreply@github.com> committed rVYOSONEX240123722abf: Merge pull request #4946 from Firefishy/T8187-fix-watchdog-timeout-validation (authored by c-po).
Sat, Jan 17, 8:52 AM
Firefishy committed rVYOSONEX94d27bc0331d: T8187: fix watchdog timeout validation if kernel min/max timeout are zero.
Sat, Jan 17, 8:52 AM
c-po closed T8169: vrf: prevent deletion if instance referenced in PBR as Resolved.
Sat, Jan 17, 8:52 AM · VyOS Rolling, VyOS 1.5 Circinus
c-po moved T8169: vrf: prevent deletion if instance referenced in PBR from Need Triage to Completed on the VyOS Rolling board.
Sat, Jan 17, 8:52 AM · VyOS Rolling, VyOS 1.5 Circinus
c-po closed T8187: Hardware watchdog timeout validation fix - watchdog may report 0 min/max timeout if hardware limit is unknown as Resolved.
Sat, Jan 17, 8:51 AM · VyOS Rolling
n.sambajon created T8191: Improve clarity of the Packets and Bytes column headings in the show firewall command output..
Sat, Jan 17, 4:10 AM
evgmol updated subscribers of T8152: Re-instate (vyos.vyos.vyos_command) module parameter support for answer, prompt.

@nicolas Fort @Srividya Anantapatnaikuni here is the solution

Sat, Jan 17, 12:05 AM · VyOS Ansible Collection

Fri, Jan 16

bmtauer added a comment to T8190: Password for vyos user in Proxmox image always needs setting.

As an update, I didn't realize originally but it seems I need to both the new VM once before the password reset option will work. If I go directly to it on first boot I get a message about no config.boot file and this not being a restore tool. Booting normally once seems to create the default config, then the password recovery option works from the serial interface.

Fri, Jan 16, 10:39 PM · VyOS 1.4 Sagitta
jestabro added a comment to T8185: config.boot.default path inconsistency between cloud-init and build system causes flavor-defined configs to be ignored.

PR:
https://github.com/vyos/vyos-build/pull/1103

Fri, Jan 16, 9:44 PM · VyOS Rolling
bmtauer updated the task description for T8190: Password for vyos user in Proxmox image always needs setting.
Fri, Jan 16, 9:29 PM · VyOS 1.4 Sagitta
bmtauer created T8190: Password for vyos user in Proxmox image always needs setting.
Fri, Jan 16, 9:28 PM · VyOS 1.4 Sagitta
c.faria created T8189: Configuration of conntrackd PurgeTimeout at the vbash level.
Fri, Jan 16, 8:01 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q4), VyOS Rolling, VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEX97e66dfd6dc9: Merge pull request #4944 from jestabro/add-completion-help-to-completion-env (authored by Viacheslav).
Fri, Jan 16, 7:06 PM
jestabro committed rVYOSONEX5943564e6373: T8156: T8157: T8164: update commit hash for completion and other fixes.
Fri, Jan 16, 7:06 PM
zsdc updated the task description for T8188: VPP: DHCP client on an interface breaks its configuration.
Fri, Jan 16, 6:56 PM · VyOS Rolling
Viacheslav added a subtask for T7070: VPP related bugs the root task: T8188: VPP: DHCP client on an interface breaks its configuration.
Fri, Jan 16, 6:55 PM · VyOS Rolling
Viacheslav added a parent task for T8188: VPP: DHCP client on an interface breaks its configuration: T7070: VPP related bugs the root task.
Fri, Jan 16, 6:55 PM · VyOS Rolling
zsdc created T8188: VPP: DHCP client on an interface breaks its configuration.
Fri, Jan 16, 6:43 PM · VyOS Rolling
jestabro added a comment to T8185: config.boot.default path inconsistency between cloud-init and build system causes flavor-defined configs to be ignored.

There is a straightforward solution here, which requires adjusting the image flavor build tools to respect the changes of https://vyos.dev/T6006, which resolved long-standing issues of migration and config initialization.
In short, after T6006:

  • the file /usr/share/vyos/config.boot.defult is the build-time source of truth --- the flavor build system should install any flavor-defined config.boot.default at that location
  • both /opt/vyatta/etc/config.boot.default and /opt/vyatta/etc/config/config.boot are installed on first boot, at different stages of gathering system-specific information in vyos-router (component version information, respectively, migration and activation updates)
Fri, Jan 16, 6:05 PM · VyOS Rolling
Viacheslav triaged T8083: tacacs: nss_tacplus: buffer truncated due to size limitation as Normal priority.
Fri, Jan 16, 5:08 PM · VyOS Rolling, VyOS 1.5 Circinus (1.5-stream-2025-Q4)
GideonKuijt added a comment to T8040: vyos.vyos.vyos_config can't use templates anymore with ansible 2.19 and 2.20.

A workaround could be the following:
Old:

vyos_config:
  src: "templates/template.j2"

New:

vyos_config:
    lines: "{{ lookup('template', 'templates/template.j2').splitlines() }}"
Fri, Jan 16, 5:07 PM · VyOS Ansible Collection
Viacheslav closed T8170: VPP: 'show vpp ipfix' unhandled exception when vpp is not enabled, a subtask of T7070: VPP related bugs the root task, as Resolved.
Fri, Jan 16, 5:07 PM · VyOS Rolling
Viacheslav closed T8170: VPP: 'show vpp ipfix' unhandled exception when vpp is not enabled as Resolved.
Fri, Jan 16, 5:07 PM · VyOS Rolling
Viacheslav closed T8161: Remove patch numbers from subject lines in VPP as Resolved.
Fri, Jan 16, 5:06 PM · VyOS Rolling
Viacheslav closed T8108: Add smoketest for Kernel kexec and ARM Marvell CN9130 options as Resolved.
Fri, Jan 16, 5:04 PM · VyOS Rolling
Viacheslav closed T7876: VPP: Increase allowable num-rx-desc limit for DPDK as Resolved.
Fri, Jan 16, 5:01 PM · VyOS Rolling
Viacheslav closed T7876: VPP: Increase allowable num-rx-desc limit for DPDK, a subtask of T7221: VPP related features the root task, as Resolved.
Fri, Jan 16, 5:01 PM · VyOS Rolling
Viacheslav triaged T8166: Large prefix lists in config cause VyOS to fail to commit or compare as High priority.
Fri, Jan 16, 4:41 PM · VyOS 1.4 Sagitta (1.4.0)
Viacheslav triaged T8185: config.boot.default path inconsistency between cloud-init and build system causes flavor-defined configs to be ignored as High priority.
Fri, Jan 16, 4:38 PM · VyOS Rolling
Viacheslav triaged T8186: NetFlow commit fails due to ip6tables hook when version 5 is configured as High priority.
Fri, Jan 16, 4:38 PM · VyOS Rolling
Viacheslav closed T8132: Update the APT mirror list before a package build as Resolved.
Fri, Jan 16, 4:35 PM · VyOS Rolling
dmbaturin closed T7635: OpenConnect Certificate Authentication as Resolved.
Fri, Jan 16, 4:30 PM · VyOS Rolling
Viacheslav moved T8172: VPP: pppoe doesn't work with vpp in circinus from Open to Finished on the VyOS 1.5 Circinus board.
Fri, Jan 16, 4:26 PM · VyOS 1.5 Circinus
Viacheslav closed T8172: VPP: pppoe doesn't work with vpp in circinus, a subtask of T7070: VPP related bugs the root task, as Resolved.
Fri, Jan 16, 4:26 PM · VyOS Rolling
Viacheslav closed T8172: VPP: pppoe doesn't work with vpp in circinus as Resolved.
Fri, Jan 16, 4:26 PM · VyOS 1.5 Circinus
natali-rs1985 added a comment to T8183: VPP: Incorrect mapping in IPFIX for bond interfaces.

https://github.com/vyos/vyos-1x/pull/4947

Fri, Jan 16, 3:49 PM · VyOS Rolling
Viacheslav changed the status of T8187: Hardware watchdog timeout validation fix - watchdog may report 0 min/max timeout if hardware limit is unknown from Open to In progress.
Fri, Jan 16, 3:20 PM · VyOS Rolling