Page MenuHomeVyOS Platform
Feed All Stories

Nov 7 2022

ssasso added a comment to T4801: Support for building AWS-ready ISO.

https://github.com/vyos/vyos-build/pull/277

Nov 7 2022, 12:29 PM · VyOS 1.4 Sagitta
hard added a comment to T4502: Consider implementing (NAT/other) flow table offload.

i see it like that

Nov 7 2022, 9:51 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4801: Support for building AWS-ready ISO from Open to In progress.
Nov 7 2022, 8:45 AM · VyOS 1.4 Sagitta

Nov 6 2022

c-po closed T2913: Failure to install fpm while building builder docker image as Resolved.
Nov 6 2022, 8:08 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
c-po added a comment to T2913: Failure to install fpm while building builder docker image.

re-signed crux repo

Nov 6 2022, 8:08 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
jestabro closed T4803: The header 'Authorization' needs to be explictly allowed in http-api CORS middleware as Resolved.
Nov 6 2022, 3:33 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEXe1d9982c7b46: graphql: T4803: allow 'Authorization' header in CORS middleware.
Nov 6 2022, 3:33 PM
jestabro triaged T4803: The header 'Authorization' needs to be explictly allowed in http-api CORS middleware as Normal priority.
Nov 6 2022, 3:29 PM · VyOS 1.4 Sagitta
Rain added a comment to T4612: Support arbitrary netmasks in firewall rules.

I'm not sure if wildcard-address fits. The address and the mask together combine to create the wildcard.

Nov 6 2022, 4:34 AM · VyOS 1.4 Sagitta

Nov 5 2022

c-po closed T4802: Ability to define per container shared-memory size as Resolved.
Nov 5 2022, 6:54 PM · VyOS 1.4 Sagitta
c-po closed T4802: Ability to define per container shared-memory size, a subtask of T578: Support Linux Container, as Resolved.
Nov 5 2022, 6:54 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po committed rVYOSONEXacf2c24f8eec: container: T4802: support per container shared-memory size configuration.
Nov 5 2022, 6:53 PM
c-po moved T4802: Ability to define per container shared-memory size from Open to Finished on the VyOS 1.4 Sagitta board.
Nov 5 2022, 6:53 PM · VyOS 1.4 Sagitta
c-po changed the status of T4802: Ability to define per container shared-memory size, a subtask of T578: Support Linux Container, from Open to In progress.
Nov 5 2022, 6:47 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po changed the status of T4802: Ability to define per container shared-memory size from Open to In progress.
Nov 5 2022, 6:47 PM · VyOS 1.4 Sagitta
c-po created T4802: Ability to define per container shared-memory size.
Nov 5 2022, 6:47 PM · VyOS 1.4 Sagitta
ssasso updated the task description for T4801: Support for building AWS-ready ISO.
Nov 5 2022, 1:24 PM · VyOS 1.4 Sagitta
ssasso added a comment to T4801: Support for building AWS-ready ISO.

Note: this requires https://phabricator.vyos.net/T4800 to be completed.

Nov 5 2022, 1:22 PM · VyOS 1.4 Sagitta
ssasso added a comment to T4801: Support for building AWS-ready ISO.

https://github.com/vyos/vyos-build/pull/277

Nov 5 2022, 1:21 PM · VyOS 1.4 Sagitta
ssasso created T4801: Support for building AWS-ready ISO.
Nov 5 2022, 1:13 PM · VyOS 1.4 Sagitta
ssasso added a comment to T4800: undefined var includes_chroot_dir in build-vyos-image .

See https://github.com/vyos/vyos-build/pull/276

Nov 5 2022, 1:10 PM · VyOS 1.4 Sagitta
ssasso added a comment to T4800: undefined var includes_chroot_dir in build-vyos-image .

Well, after a better code reading, the var should be named chroot_includes_dir instead of includes_chroot_dir.

Nov 5 2022, 1:07 PM · VyOS 1.4 Sagitta
ssasso created T4800: undefined var includes_chroot_dir in build-vyos-image .
Nov 5 2022, 1:01 PM · VyOS 1.4 Sagitta
c-po added a comment to T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.

Thanks for catching this

Nov 5 2022, 11:53 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
initramfs committed rVYOSONEXff09d4f47e5f: dns: T4799: fix bug with not reloading powerdns config.
Nov 5 2022, 7:24 AM
GitHub <noreply@github.com> committed rVYOSONEX6c0473efd272: Merge pull request #1639 from initramfs/current-fix-pdns-reload (authored by c-po).
Nov 5 2022, 7:24 AM
initramfs committed rVYOSONEXae30110b9fe4: dns: T4799: fix bug with not reloading powerdns config.
Nov 5 2022, 7:04 AM
GitHub <noreply@github.com> committed rVYOSONEXb3e524c29e9f: Merge pull request #1640 from initramfs/equuleus-fix-pdns-reload (authored by c-po).
Nov 5 2022, 7:04 AM
initramfs added a comment to T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.

Relevant PRs:

Nov 5 2022, 1:39 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
initramfs updated the task description for T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.
Nov 5 2022, 1:28 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
initramfs created T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.
Nov 5 2022, 1:19 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)

Nov 4 2022

jestabro added a subtask for T4795: Cleanup custom python validators: T4798: Migrate the file-exists validator away from Python.
Nov 4 2022, 3:54 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro added a parent task for T4798: Migrate the file-exists validator away from Python: T4795: Cleanup custom python validators.
Nov 4 2022, 3:54 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dmbaturin added a project to T4798: Migrate the file-exists validator away from Python: VyOS 1.3 Equuleus (1.3.3).
Nov 4 2022, 3:27 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dmbaturin created T4798: Migrate the file-exists validator away from Python.
Nov 4 2022, 3:26 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dmbaturin closed T2417: Python validator cleanup as Resolved.
Nov 4 2022, 3:26 PM · VyOS 1.3 Equuleus (1.3.0)
dmbaturin claimed T4770: Rewrite OpenVPN op-mode to vyos.opmode format.
Nov 4 2022, 1:18 PM · VyOS 1.4 Sagitta

Nov 3 2022

TheSin- updated the task description for T4797: External address/network lists for firewall (Local and remote).
Nov 3 2022, 9:15 PM · VyOS Rolling
TheSin- updated the task description for T4797: External address/network lists for firewall (Local and remote).
Nov 3 2022, 8:59 PM · VyOS Rolling
sarthurdev committed rVYOSONEX051e063fdf2e: firewall: T970: Refactor domain resolver, add firewall source/destination….
Nov 3 2022, 8:11 PM
sarthurdev committed rVYOSONEXb4b491d424fb: nat: T1877: T970: Add firewall groups to NAT.
Nov 3 2022, 8:11 PM
GitHub <noreply@github.com> committed rVYOSONEX36e54927217d: Merge pull request #1633 from sarthurdev/fqdn (authored by c-po).
Nov 3 2022, 8:11 PM
TheSin- added a comment to T4797: External address/network lists for firewall (Local and remote).

After a few hours of digging I do think this request would be very similar to geoip, only ipv4, and ipv6 groups would be required per list.

Nov 3 2022, 8:06 PM · VyOS Rolling
c-po committed rVYOSONEXd4cb20e1cef2: validators: T4795: migrate fqdn python validator to validate-value.
Nov 3 2022, 7:59 PM
sarthurdev triaged T4797: External address/network lists for firewall (Local and remote) as Wishlist priority.
Nov 3 2022, 7:44 PM · VyOS Rolling
Viacheslav changed the status of T4758: Rewrite show dhcp server to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from In progress to Needs testing.
Nov 3 2022, 7:42 PM · VyOS Rolling
Viacheslav changed the status of T4758: Rewrite show dhcp server to vyos.opmode format from In progress to Needs testing.
Nov 3 2022, 7:42 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T1097: Make firewall groups work everywhere that's appropropriate from Open to In progress.

PR adds groups to NAT: https://github.com/vyos/vyos-1x/pull/1633

Nov 3 2022, 7:41 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T1097: Make firewall groups work everywhere that's appropropriate, a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to In progress.
Nov 3 2022, 7:41 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
a.apostoliuk committed rVYOSONEX2e83c1eb53e9: T4496: Added lists of values in the help of op-mode ping command.
Nov 3 2022, 7:41 PM
c-po committed rVYOSONEX760cb6d9286c: Merge branch 'T4496-sagitta' of https://github.com/aapostoliuk/vyos-1x into….
Nov 3 2022, 7:41 PM
Viacheslav committed rVYOSONEX738641a6c66d: T4758: Rewrite show DHCP(v6) server leases to vyos.opmode format.
Nov 3 2022, 7:34 PM
Viacheslav committed rVYOSONEX46eda54c88ae: T4758: Fix conflicts op-mode-standardized.
Nov 3 2022, 7:34 PM
GitHub <noreply@github.com> committed rVYOSONEX99200f77afeb: Merge pull request #1604 from sever-sever/T4758 (authored by c-po).
Nov 3 2022, 7:34 PM
jestabro reopened T3574: Add constraintGroup for combining validators with logical AND as "Open".

Reopened, as this was never backported to 1.3; set for 1.3.3.

Nov 3 2022, 6:14 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
TheSin- added a comment to T4797: External address/network lists for firewall (Local and remote).

I didn't look deep into the nft groups, so I wasn't sure if we could mix ipv4/6 and addresses and networks, if we can then I agree one group would be best, though I'm sure ipv4/6 would still need to separate but checking each line for : makes that task super easy and fast.

Nov 3 2022, 5:38 PM · VyOS Rolling
n.fort added a comment to T4797: External address/network lists for firewall (Local and remote).

From my point of fiew, looks interesting.
The proposed structure and behaviour doesn't look that different than what is currently in geoip filtering: external URLs with data, and sync from time to time.

Nov 3 2022, 5:29 PM · VyOS Rolling
c-po committed rVYOSONEX3f5464d0ee85: validators: T4795: migrate mac-address python validator to validate-value.
Nov 3 2022, 5:04 PM
c-po committed rVYOSONEX81a70033cc95: validators: T4795: drop unused Python validators.
Nov 3 2022, 5:04 PM
c-po committed rVYOSONEX6f37744ad45a: xml: T4795: superseed allowed-vlan validator by numeric range validator.
Nov 3 2022, 5:04 PM
c-po committed rVYOSONEX4ae434d50337: xml: T4795: provide common and re-usable XML definitions for policy.
Nov 3 2022, 5:04 PM
TheSin- created T4797: External address/network lists for firewall (Local and remote).
Nov 3 2022, 5:00 PM · VyOS Rolling
dmbaturin created T4796: build-vyos-image ignores multiple options.
Nov 3 2022, 4:42 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po changed the status of T4795: Cleanup custom python validators from Open to In progress.
Nov 3 2022, 4:17 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po created T4795: Cleanup custom python validators.
Nov 3 2022, 4:15 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
TheSin- renamed T4794: show firewall name <name> - Can't use .items() on a list from Can't use .items() on a list to show firewall name <name> - Can't use .items() on a list.
Nov 3 2022, 2:33 PM · VyOS 1.4 Sagitta
TheSin- created T4794: show firewall name <name> - Can't use .items() on a list.
Nov 3 2022, 2:14 PM · VyOS 1.4 Sagitta
a.apostoliuk added a subtask for T3953: IPSec with vti interfaces by default add default route to table 220: T4793: Create warning message about disable-route-autoinstall when ipsec vti is used.
Nov 3 2022, 12:37 PM · VyOS 1.3 Equuleus (1.3.9)
a.apostoliuk added a parent task for T4793: Create warning message about disable-route-autoinstall when ipsec vti is used: T3953: IPSec with vti interfaces by default add default route to table 220.
Nov 3 2022, 12:37 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
a.apostoliuk changed the status of T4793: Create warning message about disable-route-autoinstall when ipsec vti is used from Open to In progress.
Nov 3 2022, 12:32 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
a.apostoliuk triaged T4793: Create warning message about disable-route-autoinstall when ipsec vti is used as Normal priority.
Nov 3 2022, 12:31 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
jack9603301 added a comment to T1797: Implement DPDK Fast-Path using FRR's Alternate Forwarding Planes and VPP.
Nov 3 2022, 10:02 AM
giezi added a comment to T1797: Implement DPDK Fast-Path using FRR's Alternate Forwarding Planes and VPP.

The enhanced linux-cp plugin (from IPng) is since 21.06 an official part of VPP, so the integration should be simple:
https://vpp.flirble.org/master/aboutvpp/releasenotes/v21.06.html#linux-control-plane-plugin-linux-cp

Nov 3 2022, 9:49 AM
Viacheslav placed T3953: IPSec with vti interfaces by default add default route to table 220 up for grabs.
Nov 3 2022, 7:43 AM · VyOS 1.3 Equuleus (1.3.9)
initramfs added a comment to T4760: VyOS does not support running multiple instances of DHCPv6 clients.

A patch to the WIDE DHCPv6 client seems to be sufficient to resolve this issue with respect to the way VyOS currently uses the daemon (one daemon per configured interface), PRs below:

Nov 3 2022, 1:59 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Viacheslav renamed T4789: Ability to get L2TP/PPTP/SSTP sessions info in a machine readable format from Ability to get L2TP/PPTP sessions info in a machine readable format to Ability to get L2TP/PPTP/SSTP sessions info in a machine readable format.
Nov 3 2022, 12:17 AM · VyOS 1.4 Sagitta

Nov 2 2022

jestabro committed rVYOSONEXc6f7ef4b84b2: op-mode: T4791: decamelize raw output of 'show_*' before normalization.
Nov 2 2022, 7:29 PM
jestabro committed rVYOSONEX702fc6272672: op-mode: T4791: add python3-pyhumps as build dep for op-mode nosetest.
Nov 2 2022, 7:28 PM
jestabro committed rVYOSONEXdb0791238c9c: graphql: T4791: decamelize/normalize result of op-mode queries.
Nov 2 2022, 7:28 PM
GitHub <noreply@github.com> committed rVYOSONEXf11b76ec56f9: Merge pull request #1636 from jestabro/standardize-op-mode-output (authored by jestabro).
Nov 2 2022, 7:28 PM
c-po moved T4177: Strip-private doesn't work for service monitoring from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Nov 2 2022, 6:52 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
zsdc changed the status of T4776: NVME storage is not detected properly during installation from In progress to Needs testing.

Sure, it is fully compatible with 1.3. If no problems are found after the changes in 1.4 it must be backported.

Nov 2 2022, 4:10 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav created T4792: Add SSTP VPN client.
Nov 2 2022, 3:29 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4771: Rewrite protocol BGP op-mode to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from In progress to Needs testing.
Nov 2 2022, 2:40 PM · VyOS Rolling
Viacheslav changed the status of T4771: Rewrite protocol BGP op-mode to vyos.opmode format from In progress to Needs testing.
Nov 2 2022, 2:40 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4777: Ability to get logs in machine readable format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from In progress to Needs testing.
Nov 2 2022, 2:39 PM · VyOS Rolling
Viacheslav changed the status of T4777: Ability to get logs in machine readable format from In progress to Needs testing.

Requires rewriting function show to python-systemd

Nov 2 2022, 2:39 PM · VyOS 1.5 Circinus
Viacheslav committed rVYOSONEX1afb3f8bd5de: T4771: Ability to get raw format for op-mode BGP commands.
Nov 2 2022, 12:00 PM
GitHub <noreply@github.com> committed rVYOSONEXf2ec92a78c4e: Merge pull request #1623 from sever-sever/T4771 (authored by dmbaturin).
Nov 2 2022, 12:00 PM
Viacheslav committed rVYOSONEXf489c5ecdab5: T4777: Ability to get logs in machine-readable format.
Nov 2 2022, 11:49 AM
GitHub <noreply@github.com> committed rVYOSONEX1bc2a0e8659a: Merge pull request #1635 from sever-sever/T4777 (authored by dmbaturin).
Nov 2 2022, 11:49 AM
hard added a comment to T4502: Consider implementing (NAT/other) flow table offload.

on nightly build nftables v1.0.5 and kernel 5.15.76

Nov 2 2022, 9:10 AM · VyOS 1.4 Sagitta
jack9603301 added a comment to T4756: General applications that support SOCAT.

As a first step, we need a wrapper script to control the start, stop and restart of socat, because socat sometimes exits automatically

Nov 2 2022, 7:37 AM
jack9603301 added a comment to T4766: Enable Cross-Protocol Translation (relay).

As a first step, we need a wrapper script to control the start, stop and restart of socat, because socat sometimes exits automatically

Nov 2 2022, 7:37 AM
a.apostoliuk changed the status of T4790: RADIUS login does not work if sum of timeouts more than 50s from Open to In progress.
Nov 2 2022, 6:41 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
a.apostoliuk claimed T4790: RADIUS login does not work if sum of timeouts more than 50s .
Nov 2 2022, 6:41 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta

Nov 1 2022

ordex added a comment to T3214: OpenVPN IPv6 fixes.

I created a PR to solve this specific issue (and some more related to this): https://github.com/vyos/vyos-1x/pull/1637

Nov 1 2022, 10:38 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T4777: Ability to get logs in machine readable format.

PR https://github.com/vyos/vyos-1x/pull/1635

Nov 1 2022, 5:36 PM · VyOS 1.5 Circinus
Viacheslav edited projects for T4737: FRRouting/zebra 7.5.1 does not redistribute routes to other protocols, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus.
Nov 1 2022, 5:31 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav awarded T4791: Consistent normalization of 'raw' output of op-mode scripts for CLI and API a Like token.
Nov 1 2022, 5:30 PM · VyOS 1.4 Sagitta