Page MenuHomeVyOS Platform
Feed All Stories

Jun 20 2026

c-po raised the priority of T8990: VPNv4 imported routes are withdrawn and reinstalled on every commit from Normal to High.
Jun 20 2026, 9:22 AM · VyOS Rolling
hedrok added a comment to T8097: Add ESN support for IPSec.

PR: https://github.com/vyos/vyos-1x/pull/5284
Suggested CLI and details in PR.

Jun 20 2026, 7:26 AM · VyOS Rolling
Apachez created T9005: Make net.*.ip_nonlocal_bind being default.
Jun 20 2026, 3:28 AM · VyOS Rolling

Jun 19 2026

syncer added a comment to T8490: Rollout typos check workflow.

Phase 1 + Phase 2 (evaluate) progress — 2026-06-19:

Jun 19 2026, 10:26 PM · GitHub Infrastructure
Apachez added a comment to T9000: Add VRF or source-interface capability to set container registry feature.

A workaround to using a custom private registry is to manually preload the images.

Jun 19 2026, 5:50 PM · VyOS Rolling
Apachez created T9004: Using containers in VyOS with netns config present needs package slirp4netns (with dependencies).
Jun 19 2026, 5:36 PM · VyOS Rolling
o.kuchmystyi closed T8985: password-reset: unbounded sed ranges in standalone_root_pw_reset spill into the next user's block, corrupting other accounts as Resolved.
Jun 19 2026, 2:02 PM · VyOS Rolling
dmbaturin closed T8858: Fix mutable default argument bug in Config API methods as Resolved.
Jun 19 2026, 1:35 PM
natali-rs1985 added a comment to T8998: openvpn: enabling reject-unconfigured-clients without defining any clients breaks server startup.

https://github.com/vyos/vyos-1x/pull/5283

Jun 19 2026, 11:32 AM · VyOS Rolling
Viacheslav added a comment to T8546: Conntrack VRF zone mapping not applied when only global state-policy is configured.

'Resolved for the rolling

Jun 19 2026, 11:30 AM · VyOS 1.4 Sagitta (1.4.0)
Viacheslav closed T8546: Conntrack VRF zone mapping not applied when only global state-policy is configured as Resolved.
Jun 19 2026, 11:29 AM · VyOS 1.4 Sagitta (1.4.0)
Viacheslav closed T8881: PowerDNS refresh-on-ttl-perc, nothing-below-nxdomain, minimum-ttl-override, response policy zones (malware / adblocking) as Resolved.
Jun 19 2026, 11:26 AM · VyOS Rolling
Viacheslav closed T7139: Changing VPN IPsec configuration kills Strongswan bug as Not Applicable.
Jun 19 2026, 11:18 AM · VyOS Rolling
Viacheslav triaged T9003: Introduce new vyos.utils.process.cmdl() helper for improved security as Normal priority.
Jun 19 2026, 11:16 AM · VyOS Rolling
natali-rs1985 changed the status of T8998: openvpn: enabling reject-unconfigured-clients without defining any clients breaks server startup from Open to In progress.
Jun 19 2026, 10:40 AM · VyOS Rolling
natali-rs1985 added a comment to T7139: Changing VPN IPsec configuration kills Strongswan bug.

Cannot reproduce on version 2026.06.16-1247-rolling

Jun 19 10:10:41 vyos dhclient[1840]: DHCPDISCOVER on eth3 to 255.255.255.255 port 67 interval 12
Jun 19 10:10:50 vyos vyos-configd[738]: Received message: {"type": "init"}
Jun 19 10:10:50 vyos vyos-configd[738]: config session pid is 2765
Jun 19 10:10:50 vyos vyos-configd[738]: config session sudo_user is vyos
Jun 19 10:10:50 vyos vyos-configd[738]: commit_scripts: ['vpn_ipsec']
Jun 19 10:10:50 vyos vyos-configd[738]: Received message: {"type": "node", "last": true, "data": "/usr/libexec/vyos/conf_mode/vpn_ipsec.py"}
Jun 19 10:10:50 vyos systemd[1]: Reloading strongSwan IPsec IKEv1/IKEv2 daemon using swanctl...
Jun 19 10:10:50 vyos charon-systemd[3326]: loaded 0 entries for attr plugin configuration
Jun 19 10:10:50 vyos charon-systemd[3326]: loaded 0 RADIUS server configurations
Jun 19 10:10:50 vyos charon-systemd[3326]: loaded IKE shared key with id 'ike-VPP' for: '192.0.2.1', '192.0.2.2'
Jun 19 10:10:50 vyos charon-systemd[3326]: updated vici connection: VPP
Jun 19 10:10:50 vyos swanctl[3857]: loaded ike secret 'ike-VPP'
Jun 19 10:10:50 vyos swanctl[3857]: no authorities found, 0 unloaded
Jun 19 10:10:50 vyos swanctl[3857]: no pools found, 0 unloaded
Jun 19 10:10:50 vyos swanctl[3857]: loaded connection 'VPP'
Jun 19 10:10:50 vyos swanctl[3857]: successfully loaded 1 connections, 0 unloaded
Jun 19 10:10:50 vyos systemd[1]: Reloaded strongSwan IPsec IKEv1/IKEv2 daemon using swanctl.
Jun 19 10:10:50 vyos vyos-configd[738]: [vpn_ipsec]
Jun 19 10:10:50 vyos vyos-configd[738]: scripts_called: ['vpn_ipsec']
Jun 19 10:10:50 vyos vyos-configd[738]: Sending reply: SUCCESS with output
Jun 19 10:10:50 vyos systemd[1]: opt-vyatta-config-tmp-new_config_2765.mount: Deactivated successfully.
Jun 19 10:10:52 vyos commit[3904]: Successful change to active configuration by user vyos on /dev/ttyS0
Jun 19 2026, 10:16 AM · VyOS Rolling
syncer claimed T8490: Rollout typos check workflow.

Taking over from @Vijayakumar and re-scoping. Research outcome: Mergify cannot run content scanners (it only gates on *existing* check results), so the path forward is fleet-wide-capable enforcement via a GitHub repository ruleset ("require workflows to pass") — no per-repo caller files — piloted on vyos-1x / vyos-build / vyatta-cfg-system / vyconf (branches rolling/circinus/sagitta) in evaluate → active mode, with a rebuilt standalone typos.yml (official crate-ci/typos action, prebuilt binary, fork-safe on: pull_request, full-tree scan, central _typos.toml allowlist). The per-repo-caller rollout (stalled ~2 months at 1 repo) is superseded.

Jun 19 2026, 4:16 AM · GitHub Infrastructure

Jun 18 2026

evgmol closed T8040: vyos.vyos.vyos_config can't use templates anymore with ansible 2.19 and 2.20 as Resolved.
Jun 18 2026, 11:38 PM · VyOS Ansible Collection
evgmol closed T8983: vyos.vyos.vyos_logging_global incompatibility with VyOS1.5 LTS as Resolved.
Jun 18 2026, 11:09 PM · VyOS Rolling
evgmol added a comment to T8983: vyos.vyos.vyos_logging_global incompatibility with VyOS1.5 LTS.

https://github.com/vyos/vyos.vyos/pull/486

Jun 18 2026, 11:09 PM · VyOS Rolling
j.vela added a comment to T660: 802.1p CoS priority support.

I was able to achieve the PCP set with different CoS value with subsystem tc of linux. Re-using the available options of QoS, it is possible to identify CoS values (L2 traffic) for ingress and egress. Let me explain how Linux performs the PCP values.

Jun 18 2026, 8:54 PM · VyOS Rolling
sarthurdev changed the status of T8987: geoip: add support for (manual) updates via given source interface from Open to In progress.

PR: https://github.com/vyos/vyos-1x/pull/5282

Jun 18 2026, 8:39 PM · VyOS Rolling
c-po updated the task description for T9003: Introduce new vyos.utils.process.cmdl() helper for improved security.
Jun 18 2026, 6:26 PM · VyOS Rolling
jestabro closed T8995: Update supporting packages of vyos-http-api-tools: pyjwt and python-multipart as Resolved.
Jun 18 2026, 5:54 PM · VyOS Rolling
c-po created T9003: Introduce new vyos.utils.process.cmdl() helper for improved security.
Jun 18 2026, 5:02 PM · VyOS Rolling
c-po closed T8971: Add bgpq4 (maybe replace bgpq3 as Resolved.
Jun 18 2026, 2:38 PM · VyOS Rolling
c-po reassigned T8987: geoip: add support for (manual) updates via given source interface from c-po to sarthurdev.
Jun 18 2026, 2:38 PM · VyOS Rolling
c-po closed T8994: certbot: dependent services might stop on certificate renewal issues as Resolved.
Jun 18 2026, 2:37 PM · VyOS Rolling
Viacheslav closed T8524: insufficient validation for dhcp-server dynamic-dns-update key-name as Resolved.
Jun 18 2026, 2:25 PM · VyOS 1.5 Circinus
Viacheslav closed T8979: VPP: Defunct interface contains IP addresses after crash, a subtask of T7070: VPP related bugs the root task, as Resolved.
Jun 18 2026, 2:13 PM · VyOS Rolling
Viacheslav closed T8979: VPP: Defunct interface contains IP addresses after crash as Resolved.
Jun 18 2026, 2:13 PM · VyOS Rolling
natali-rs1985 added a comment to T8979: VPP: Defunct interface contains IP addresses after crash.

https://github.com/vyos/vyos-1x/pull/5281

Jun 18 2026, 1:46 PM · VyOS Rolling
Viacheslav triaged T8998: openvpn: enabling reject-unconfigured-clients without defining any clients breaks server startup as Normal priority.
Jun 18 2026, 11:49 AM · VyOS Rolling
Viacheslav triaged T8999: openvpn: misleading "no openvpn shared-secrets in PKI" error for a dangling auth-key/crypt-key reference as Normal priority.
Jun 18 2026, 11:46 AM · VyOS Rolling
Viacheslav triaged T9002: blackbox-exporter ICMP probes fail silently in default configuration due to missing net.ipv4.ping_group_range permission as Normal priority.
Jun 18 2026, 11:39 AM · VyOS Rolling
natali-rs1985 changed the status of T8979: VPP: Defunct interface contains IP addresses after crash, a subtask of T7070: VPP related bugs the root task, from Open to In progress.
Jun 18 2026, 10:40 AM · VyOS Rolling
natali-rs1985 changed the status of T8979: VPP: Defunct interface contains IP addresses after crash from Open to In progress.
Jun 18 2026, 10:40 AM · VyOS Rolling
DarkDreamSan created T9002: blackbox-exporter ICMP probes fail silently in default configuration due to missing net.ipv4.ping_group_range permission.
Jun 18 2026, 10:33 AM · VyOS Rolling
syncer added a comment to T8490: Rollout typos check workflow.

Status check 2026-06-18 (triage of open GitHub Infrastructure tasks). @Vijayakumar — current state of this rollout:

Jun 18 2026, 4:40 AM · GitHub Infrastructure
syncer closed T8585: Centralize Mergify config via extends in .github repos as Resolved.

Resolving — superseded by T8782 (IS-432, Passed). The centralization goal (eliminate per-repo Mergify-config duplication via extends; future policy changes = 2 PRs not 30+) is delivered fleet-wide — but via dedicated vyos/mergify + VyOS-Networks/mergify repos with extends: mergify, not this task's extends: .github design (the bare mergify repo name was chosen for fleet symmetry, and .github-repo hosting was dropped). Live on ~55 product repos; fleet extends adoption tracked/closed under T8852. No per-repo config duplication remains. Closing as resolved (delivered via sibling); Jira companion IS-404 being cancelled as superseded by IS-432.

Jun 18 2026, 4:33 AM · GitHub Infrastructure
Apachez created T9000: Add VRF or source-interface capability to set container registry feature.
Jun 18 2026, 12:38 AM · VyOS Rolling

Jun 17 2026

a.kudientsov created T8999: openvpn: misleading "no openvpn shared-secrets in PKI" error for a dangling auth-key/crypt-key reference.
Jun 17 2026, 10:53 PM · VyOS Rolling
a.kudientsov created T8998: openvpn: enabling reject-unconfigured-clients without defining any clients breaks server startup.
Jun 17 2026, 10:34 PM · VyOS Rolling
syncer added a comment to T8997: docs.vyos.io: Cookiebot consent dialog renders unstyled and breaks the page on first load.

Fix merged to rolling in vyos-documentation#2108 (Phase 0 CodeRabbit clean on the diff; root cause + fix verified in-browser).

Jun 17 2026, 7:27 PM
syncer created T8997: docs.vyos.io: Cookiebot consent dialog renders unstyled and breaks the page on first load.
Jun 17 2026, 7:12 PM
natali-rs1985 added a comment to T8603: VPP: Expand ACL support to logical interfaces.
Jun 17 2026, 2:19 PM · VyOS Rolling
a.kudientsov created T8996: QoS: set-dscp option has no effect.
Jun 17 2026, 2:19 PM · VyOS Rolling
Viacheslav closed T8950: vyos-netlinkd: DHCP restart on every RTM_NEWLINK(UP) without tracking previous state as Resolved.
Jun 17 2026, 2:03 PM · VyOS Rolling
sarthurdev added a comment to T8546: Conntrack VRF zone mapping not applied when only global state-policy is configured.

PR: https://github.com/vyos/vyos-1x/pull/5279

Jun 17 2026, 12:55 PM · VyOS 1.4 Sagitta (1.4.0)
Viacheslav moved T8223: EVPN-VXLAN L3VPN / VRF config validation is broken, "Please unconfigure EVPN in VRF default" from Backport Candidates to Completed on the VyOS Rolling board.
Jun 17 2026, 12:38 PM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav closed T8223: EVPN-VXLAN L3VPN / VRF config validation is broken, "Please unconfigure EVPN in VRF default" as Resolved.
Jun 17 2026, 12:37 PM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav closed T8492: CRL generated by VyOS PKI lacks X.509 extensions required for strongSwan validation as Resolved.
Jun 17 2026, 11:24 AM · VyOS 1.4 Sagitta (1.4.0)
Viacheslav closed T8923: General XML definition cleanup and typo fixes as Resolved.
Jun 17 2026, 11:22 AM · VyOS Rolling
sarthurdev added a comment to T8991: The vyos-domain-resolver daemon crashes with an IndexError when processing remote-group threat lists that contain blank lines, leaving ALL remote-group nftables sets empty and all associated firewall rules non-functional..

PR: https://github.com/vyos/vyos-1x/pull/5278

Jun 17 2026, 8:51 AM · VyOS Rolling
jestabro created T8995: Update supporting packages of vyos-http-api-tools: pyjwt and python-multipart.
Jun 17 2026, 12:50 AM · VyOS Rolling

Jun 16 2026

c-po added a comment to T8994: certbot: dependent services might stop on certificate renewal issues.

https://github.com/vyos/vyos-1x/pull/5276

Jun 16 2026, 4:08 PM · VyOS Rolling
c-po added a comment to T8923: General XML definition cleanup and typo fixes.

https://github.com/vyos/vyos-1x/pull/5277

Jun 16 2026, 3:51 PM · VyOS Rolling
c-po renamed T8923: General XML definition cleanup and typo fixes from XML definition cleanup after overwritable help support to General XML definition cleanup and typo fixes.
Jun 16 2026, 3:42 PM · VyOS Rolling
Viacheslav closed T8972: Add support for propagating VyOS interface VRF assignment to VPP dataplane FIB tables for LCP-managed interfaces., a subtask of T7221: VPP related features the root task, as Resolved.
Jun 16 2026, 3:35 PM · VyOS Rolling
Viacheslav closed T8972: Add support for propagating VyOS interface VRF assignment to VPP dataplane FIB tables for LCP-managed interfaces. as Resolved.
Jun 16 2026, 3:35 PM · VyOS Rolling
c-po claimed T8994: certbot: dependent services might stop on certificate renewal issues.
Jun 16 2026, 3:23 PM · VyOS Rolling
c-po created T8994: certbot: dependent services might stop on certificate renewal issues.
Jun 16 2026, 3:22 PM · VyOS Rolling
c-po closed T8988: pki/0-to-1 migration unreachable in sagitta - pki absent from xml-component-version.xml.in, a subtask of T8492: CRL generated by VyOS PKI lacks X.509 extensions required for strongSwan validation, as Resolved.
Jun 16 2026, 3:19 PM · VyOS 1.4 Sagitta (1.4.0)
c-po closed T8988: pki/0-to-1 migration unreachable in sagitta - pki absent from xml-component-version.xml.in as Resolved.
Jun 16 2026, 3:19 PM · VyOS Rolling
Viacheslav triaged T8981: op-mode: "show system commit diff N" prints nothing - catch_broken_pipe decorator discards return values (regression from T8362) as Normal priority.
Jun 16 2026, 12:19 PM · VyOS Rolling
Viacheslav changed the status of T8829: firewall remote-group downloader errors if HEAD method is not supported from Open to In progress.
Jun 16 2026, 11:35 AM · VyOS Rolling
evgbondarenko defrocked sever.
Jun 16 2026, 11:11 AM
evgbondarenko empowered Viacheslav as an administrator.
Jun 16 2026, 11:10 AM
evgbondarenko empowered sever as an administrator.
Jun 16 2026, 11:06 AM
bradkollmyer added a comment to T8829: firewall remote-group downloader errors if HEAD method is not supported.

HttpC.download() in python/vyos/remote.py always sends a HEAD request before GET to discover redirects and Content-Length. Some remote APIs (notably AbuseIPDB blocklist endpoints) reject HEAD with 405 Method Not Allowed while GET works fine. vyos-domain-resolver catches the failure and falls back to the cached list file — which on first commit is an empty placeholder — so remote-groups stay at 0 members.

Jun 16 2026, 3:14 AM · VyOS Rolling

Jun 15 2026

Boris added a comment to T8990: VPNv4 imported routes are withdrawn and reinstalled on every commit.

Looks like I'll have to use a workaround and run BGP between the two VRFs instead.

Jun 15 2026, 7:32 PM · VyOS Rolling
Boris added a comment to T8990: VPNv4 imported routes are withdrawn and reinstalled on every commit.

In my previous deployments using FRR on Debian, I never had to rely on a full FRR reload for routine BGP policy changes. In most cases, applying the change and performing a soft refresh (for example, clear ip bgp vrf test * soft in/out) was sufficient and did not impact forwarding.

Jun 15 2026, 7:27 PM · VyOS Rolling
jestabro renamed T8993: Initialization bug when config-sync diff runs before first synced commit from Initialization bug when config-sync diff run before first synced commit to Initialization bug when config-sync diff runs before first synced commit.
Jun 15 2026, 5:01 PM · VyOS Rolling
jestabro created T8993: Initialization bug when config-sync diff runs before first synced commit.
Jun 15 2026, 5:01 PM · VyOS Rolling
jestabro closed T8980: config-sync: phantom drift on converged pair - sync diff op-mode does not apply the exclusion mask, a subtask of T8502: Add exclusion mask to config-sync, as Resolved.
Jun 15 2026, 4:55 PM · VyOS Rolling
jestabro closed T8980: config-sync: phantom drift on converged pair - sync diff op-mode does not apply the exclusion mask as Resolved.
Jun 15 2026, 4:55 PM · VyOS Rolling
jestabro added a subtask for T8502: Add exclusion mask to config-sync: T8980: config-sync: phantom drift on converged pair - sync diff op-mode does not apply the exclusion mask.
Jun 15 2026, 4:55 PM · VyOS Rolling
jestabro added a parent task for T8980: config-sync: phantom drift on converged pair - sync diff op-mode does not apply the exclusion mask: T8502: Add exclusion mask to config-sync.
Jun 15 2026, 4:55 PM · VyOS Rolling
sarthurdev changed the status of T8546: Conntrack VRF zone mapping not applied when only global state-policy is configured from Open to In progress.
Jun 15 2026, 3:51 PM · VyOS 1.4 Sagitta (1.4.0)
sarthurdev triaged T8991: The vyos-domain-resolver daemon crashes with an IndexError when processing remote-group threat lists that contain blank lines, leaving ALL remote-group nftables sets empty and all associated firewall rules non-functional. as Normal priority.
Jun 15 2026, 3:51 PM · VyOS Rolling
sarthurdev changed the status of T8991: The vyos-domain-resolver daemon crashes with an IndexError when processing remote-group threat lists that contain blank lines, leaving ALL remote-group nftables sets empty and all associated firewall rules non-functional. from Open to In progress.
Jun 15 2026, 3:51 PM · VyOS Rolling
asklymenko created T8992: Fix integration builds.
Jun 15 2026, 3:15 PM · VyOS Rolling
o.kuchmystyi added a comment to T8985: password-reset: unbounded sed ranges in standalone_root_pw_reset spill into the next user's block, corrupting other accounts.

PR: https://github.com/vyos/vyos-1x/pull/5273

Jun 15 2026, 2:38 PM · VyOS Rolling
natali-rs1985 renamed T8603: VPP: Expand ACL support to logical interfaces from VPP: Expland ACL support to logical interfaces to VPP: Expand ACL support to logical interfaces.
Jun 15 2026, 2:25 PM · VyOS Rolling
kmadaras created T8991: The vyos-domain-resolver daemon crashes with an IndexError when processing remote-group threat lists that contain blank lines, leaving ALL remote-group nftables sets empty and all associated firewall rules non-functional..
Jun 15 2026, 1:41 PM · VyOS Rolling
natali-rs1985 changed the status of T8603: VPP: Expand ACL support to logical interfaces, a subtask of T7221: VPP related features the root task, from Open to In progress.
Jun 15 2026, 1:19 PM · VyOS Rolling
natali-rs1985 changed the status of T8603: VPP: Expand ACL support to logical interfaces from Open to In progress.
Jun 15 2026, 1:19 PM · VyOS Rolling
Viacheslav triaged T8985: password-reset: unbounded sed ranges in standalone_root_pw_reset spill into the next user's block, corrupting other accounts as Normal priority.
Jun 15 2026, 1:04 PM · VyOS Rolling
Viacheslav triaged T8990: VPNv4 imported routes are withdrawn and reinstalled on every commit as Normal priority.
Jun 15 2026, 1:03 PM · VyOS Rolling
Viacheslav added a comment to T8990: VPNv4 imported routes are withdrawn and reinstalled on every commit.

FRR reloads the whole configuration per commit, not only one protocol
So policy-route-map is related to FRR config and prefix-lists are the same between all FRR routing daemons.
https://github.com/vyos/vyos-1x/blob/c2f87f243a1f813fbdd319b1004fd3a26397ab3e/python/vyos/frrender.py#L850

Jun 15 2026, 1:03 PM · VyOS Rolling
o.kuchmystyi changed the status of T8985: password-reset: unbounded sed ranges in standalone_root_pw_reset spill into the next user's block, corrupting other accounts from Open to In progress.
Jun 15 2026, 12:24 PM · VyOS Rolling
Boris created T8990: VPNv4 imported routes are withdrawn and reinstalled on every commit.
Jun 15 2026, 12:09 PM · VyOS Rolling
Viacheslav triaged T8980: config-sync: phantom drift on converged pair - sync diff op-mode does not apply the exclusion mask as Normal priority.
Jun 15 2026, 11:42 AM · VyOS Rolling

Jun 14 2026

c-po added a subtask for T8492: CRL generated by VyOS PKI lacks X.509 extensions required for strongSwan validation: T8988: pki/0-to-1 migration unreachable in sagitta - pki absent from xml-component-version.xml.in.
Jun 14 2026, 8:32 PM · VyOS 1.4 Sagitta (1.4.0)
c-po added a parent task for T8988: pki/0-to-1 migration unreachable in sagitta - pki absent from xml-component-version.xml.in: T8492: CRL generated by VyOS PKI lacks X.509 extensions required for strongSwan validation.
Jun 14 2026, 8:32 PM · VyOS Rolling
c-po updated the task description for T8988: pki/0-to-1 migration unreachable in sagitta - pki absent from xml-component-version.xml.in.
Jun 14 2026, 8:31 PM · VyOS Rolling
c-po changed Version from 1.4 to 1.4-stable-20260612 on T8988: pki/0-to-1 migration unreachable in sagitta - pki absent from xml-component-version.xml.in.
Jun 14 2026, 8:29 PM · VyOS Rolling
evgmol closed T8348: Add interface option to VRRP address attribute as Resolved.
Jun 14 2026, 8:29 PM · VyOS Ansible Collection
evgmol added a comment to T8348: Add interface option to VRRP address attribute.

This task is covered by https://github.com/vyos/vyos.vyos/pull/438

Jun 14 2026, 8:28 PM · VyOS Ansible Collection
evgmol updated subscribers of T8516: Add unit tests for vyos_l3_interfaces module and bug fix.
Jun 14 2026, 7:32 PM · VyOS Ansible Collection