Page MenuHomeVyOS Platform
Feed All Stories

Sep 4 2023

Apachez added a comment to T5549: Result of system audit by Lynis.

Sep 4 2023, 6:26 PM · Invalid
dmbaturin committed rVYOSONEX7f0a363c9034: T671: call dmidecode directly in "show hardware dmi".
Sep 4 2023, 6:25 PM
GitHub <noreply@github.com> committed rVYOSONEX432726d83c2e: Merge pull request #2201 from dmbaturin/T671-show-dmi (authored by c-po).
Sep 4 2023, 6:25 PM
Apachez created T5549: Result of system audit by Lynis.
Sep 4 2023, 6:23 PM · Invalid
jestabro added a project to T5412: Add support for extending config-mode dependencies in supplemental package: VyOS 1.5 Circinus.
Sep 4 2023, 6:00 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
mhamzahkhan created T5548: HAProxy renders timeouts incorrectly.
Sep 4 2023, 5:11 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T5480: Ability to disable SNMP for VRRP keepalived service from Open to In progress.
Sep 4 2023, 4:13 PM · VyOS 1.4 Sagitta
Viacheslav moved T5506: Container bridge interfaces do not have a link-local address from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.4) board.
Sep 4 2023, 4:11 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav closed T5506: Container bridge interfaces do not have a link-local address as Resolved.
Sep 4 2023, 4:11 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
anthr76 added a comment to T5546: Failed upgrade from 1.4-rolling-202212310809 to 1.4-rolling-202309030023.

I would like to stage this in a VM if I do try the above as physical access to the router is tough. Does anyone know where I can find a ISO for 1.4-rolling-202212310809. It seems the old s3 endpoint doesn't resolve https://s3.vyos.io/rolling/current/vyos-1.4-rolling-202212310809-amd64.iso

Sep 4 2023, 4:00 PM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav moved T5533: Keepalived VRRP IPv6 group enters in FAULT state from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 4 2023, 3:59 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav edited projects for T5533: Keepalived VRRP IPv6 group enters in FAULT state , added: VyOS 1.3 Equuleus (1.3.4); removed VyOS 1.3 Equuleus (1.3.5).

PR 1.3.4 https://github.com/vyos/vyos-1x/pull/2200

Sep 4 2023, 3:59 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
jestabro added a comment to T5546: Failed upgrade from 1.4-rolling-202212310809 to 1.4-rolling-202309030023.

Adding vyos-config-debug to the boot cmdline should allow you to log in and will provide some information in /tmp/boot-config-trace. Cf.:
https://docs.vyos.io/en/latest/contributing/debugging.html

Sep 4 2023, 3:54 PM · VyOS 1.4 Sagitta (1.4.1)
jagekurt added a comment to T5508: Configuration Migration Fails to New Netfilter Firewall Syntax.

I upgraded from 1.4-rolling-202307060317 to 1.4-rolling-202309040919 and the issue mention in this post was resolved. The configuration was migrated. However nothing worked in regards to the firewall, and I am not familiar enough with the new syntax so I cannot, nor do I have time to troubleshoot it right now.

Sep 4 2023, 3:48 PM · VyOS 1.4 Sagitta
Viacheslav closed T5536: show dhcp client leases caues No module named 'vyos.validate' as Resolved.
Sep 4 2023, 3:05 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5543: Fix source address handling in static joins.

@syncer At first glance, the generated config is correct for VyOS 1.3-stable-202308240442

set protocols igmp interface eth0 join 239.1.2.3 source '192.0.2.1'
set protocols igmp interface eth1 join 239.1.2.3
set protocols igmp interface eth2
Sep 4 2023, 2:18 PM · VyOS 1.4 Sagitta, VyOS Rolling, VyOS 1.3 Equuleus (1.3.6)
fernando changed the status of T5547: ISIS: The L1-2 router cannot advertise L1 routes into L2 from Open to Confirmed.
Sep 4 2023, 1:37 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Known issue
fernando created T5547: ISIS: The L1-2 router cannot advertise L1 routes into L2.
Sep 4 2023, 1:36 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Known issue
swanduron added a comment to T5376: Conntrack FTP helper does not work properly.

Unless there is something wrong with the firewall ruleset in VyOS any malfunctions in the FTP helper itself will mainly be fixed upstream at the Linux kernel or in this particular case the netfilter team:

Sep 4 2023, 1:36 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
anthr76 added a comment to T5546: Failed upgrade from 1.4-rolling-202212310809 to 1.4-rolling-202309030023.

My config file is https://gist.github.com/anthr76/4b091d952bcd69b1ac8d4c7d08aaaac6

Sep 4 2023, 12:50 PM · VyOS 1.4 Sagitta (1.4.1)
anthr76 created T5546: Failed upgrade from 1.4-rolling-202212310809 to 1.4-rolling-202309030023.
Sep 4 2023, 12:49 PM · VyOS 1.4 Sagitta (1.4.1)
sarthurdev changed the status of T4903: Support IPv6 addresses in "set system conntrack ignore" from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2199

Sep 4 2023, 10:50 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev changed the status of T4309: Support network/address-groups and ipv6-network/ipv6-address-groups in "conntrack ignore" from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2199

Sep 4 2023, 10:50 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
mlk-89 updated the task description for T5545: sflow is not working.
Sep 4 2023, 10:26 AM · VyOS 1.3 Equuleus (1.3.4)
mlk-89 created T5545: sflow is not working.
Sep 4 2023, 10:13 AM · VyOS 1.3 Equuleus (1.3.4)
sarthurdev changed the status of T4309: Support network/address-groups and ipv6-network/ipv6-address-groups in "conntrack ignore" from Open to In progress.
Sep 4 2023, 9:38 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev changed the status of T4903: Support IPv6 addresses in "set system conntrack ignore" from Open to In progress.
Sep 4 2023, 9:38 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav committed rVYOSONEX5fb77805f0fc: T5533: Fix VRRP IPv6 group enters in FAULT state.
Sep 4 2023, 7:59 AM
GitHub <noreply@github.com> committed rVYOSONEX8e22a2f6f77d: Merge pull request #2192 from sever-sever/T5533 (authored by zdc <zdc@users.noreply.github.com>).
Sep 4 2023, 7:59 AM
anthr76 committed rVYOSONEXe623c10ab41e: feat(T5544): Allow CAP_SYS_MODULE to be set on containers.
Sep 4 2023, 4:42 AM
anthr76 committed rVYOSONEXd9b0551c8517: fix: sys-module auto-tab completion.
Sep 4 2023, 4:42 AM
GitHub <noreply@github.com> committed rVYOSONEXbbcf94bba674: Merge pull request #2197 from anthr76/cap-sys-module (authored by c-po).
Sep 4 2023, 4:42 AM

Sep 3 2023

Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Disabling all validators for both vyatta-cfg and vyatta-op bring the boot time down to approx 73 seconds.

Sep 3 2023, 9:41 PM · VyOS Rolling, Bugs
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Modifying node.def (comment out "syntax:expression:") recursively in the paths of:

Sep 3 2023, 9:11 PM · VyOS Rolling, Bugs
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Moving along in the blamegame I will after a tip try to disable the various validators being runned.

Sep 3 2023, 8:56 PM · VyOS Rolling, Bugs
Apachez added a comment to T2431: Python validators are slow.

Any updates to this?

Sep 3 2023, 8:28 PM · VyOS 1.3 Equuleus (1.3.6)
cacack added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

That relates would seem reasonable. I'm seeing a similar explosion in commit lag but I have zero static routes. I did change to zone-based firewall and added about 6 vlans. Lines of my config went from ~500 to ~3000. Commit times increased almost linearly.

Sep 3 2023, 8:17 PM · VyOS Rolling, Bugs
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Can be related: https://vyos.dev/T2431

Sep 3 2023, 7:14 PM · VyOS Rolling, Bugs
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Continued debugging by also modifying /usr/libexec/vyos/services/vyos-configd by adding:

Sep 3 2023, 7:10 PM · VyOS Rolling, Bugs
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Attempted some debugging on this issue.

Sep 3 2023, 6:43 PM · VyOS Rolling, Bugs
syncer reassigned T1869: Install and Boot from RAID Doesn't Work from UnicronNL to zsdc.
Sep 3 2023, 6:30 PM
syncer triaged T5544: Allow CAP_SYS_MODULE to be set on containers as Low priority.
Sep 3 2023, 5:44 PM · VyOS 1.4 Sagitta
syncer triaged T5543: Fix source address handling in static joins as Normal priority.
Sep 3 2023, 5:44 PM · VyOS 1.4 Sagitta, VyOS Rolling, VyOS 1.3 Equuleus (1.3.6)
Apachez added a comment to T5544: Allow CAP_SYS_MODULE to be set on containers .

According to https://man7.org/linux/man-pages/man7/capabilities.7.html this capability can load, unload AND delete kernel modules.

Sep 3 2023, 4:27 PM · VyOS 1.4 Sagitta
anthr76 added a comment to T5544: Allow CAP_SYS_MODULE to be set on containers .

https://github.com/vyos/vyos-1x/pull/2197

Sep 3 2023, 4:20 PM · VyOS 1.4 Sagitta
anthr76 created T5544: Allow CAP_SYS_MODULE to be set on containers .
Sep 3 2023, 4:10 PM · VyOS 1.4 Sagitta
alainlamar changed the status of T5540: vyos-1x: Wrong VHT configuration for WiFi 802.11ac from Open to In progress.
Sep 3 2023, 2:19 PM · VyOS 1.4 Sagitta
syncer moved T5543: Fix source address handling in static joins from Need Triage to Backlog on the VyOS 1.3 Equuleus (1.3.4) board.
Sep 3 2023, 11:44 AM · VyOS 1.4 Sagitta, VyOS Rolling, VyOS 1.3 Equuleus (1.3.6)
syncer closed T5543: Fix source address handling in static joins as Unknown Status.

@Viacheslav, can you backport this to 1.3

Sep 3 2023, 11:43 AM · VyOS 1.4 Sagitta, VyOS Rolling, VyOS 1.3 Equuleus (1.3.6)
GitHub <noreply@github.com> committed rVYOSONEX630d40046b4f: T5543: IGMP: fix source address handling in static joins (authored by vfreex).
Sep 3 2023, 11:28 AM
vfreex added a comment to T5543: Fix source address handling in static joins.

PR https://github.com/vyos/vyos-1x/pull/2196

Sep 3 2023, 11:19 AM · VyOS 1.4 Sagitta, VyOS Rolling, VyOS 1.3 Equuleus (1.3.6)
vfreex created T5543: Fix source address handling in static joins.
Sep 3 2023, 11:17 AM · VyOS 1.4 Sagitta, VyOS Rolling, VyOS 1.3 Equuleus (1.3.6)
sarthurdev closed T4612: Support arbitrary netmasks in firewall rules as Resolved.
Sep 3 2023, 10:37 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5542: ipoe-server: external-dhcp(dhcp-relay) not woking / not implemented from Open to Needs testing.
Sep 3 2023, 9:13 AM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEX1ae9c4162dc1: ipoe: T5542: fix Jinja2 template and add missing dhcp relay config (authored by Niklasthegeek).
Sep 3 2023, 7:25 AM
c-po committed rVYOSONEXb295a1470b04: wireless: T5540: fix smoketests after adjusting VHT channel width.
Sep 3 2023, 6:40 AM
c-po committed rVYOSONEX6ff0e8f6a024: wireless: T5540: use elif in Jinja2 template for VHT channel width.
Sep 3 2023, 6:40 AM
Apachez added a comment to T5532: After add system image the boot stuck and works again after the second reboot.

Still occurs for:

Sep 3 2023, 6:10 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

PR created: https://github.com/vyos/vyos-build/pull/392

Sep 3 2023, 5:17 AM · VyOS 1.4 Sagitta
Apachez closed T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos as Resolved.
Sep 3 2023, 5:04 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.

Verified working with VyOS 1.4-rolling-202309030023.

Sep 3 2023, 5:03 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.

Was missing quotes around the variable within lb_config_tmpl like so:

Sep 3 2023, 5:02 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

Some further testing:

Sep 3 2023, 4:57 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

Reference to https://jonathancarter.org/2015/04/06/squashfs-performance-testing/ using 1M blocksize will give approx the same readspeed as with default 128k blocksize but result in an even smaller file.

Sep 3 2023, 4:02 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

Regarding filesystem.squashfs the changes through changed mksquashfs syntax are:

Sep 3 2023, 2:48 AM · VyOS 1.4 Sagitta
Niklasthegeek claimed T5542: ipoe-server: external-dhcp(dhcp-relay) not woking / not implemented.
Sep 3 2023, 2:09 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

Was missing quotes around the variable within lb_config_tmpl like so:

Sep 3 2023, 2:01 AM · VyOS 1.4 Sagitta
Niklasthegeek created T5542: ipoe-server: external-dhcp(dhcp-relay) not woking / not implemented.
Sep 3 2023, 12:55 AM · VyOS 1.4 Sagitta

Sep 2 2023

GitHub <noreply@github.com> committed rVYOSONEX6896aabb6406: wireless: T5540: fix VHT capability settings for 802.11ac (authored by alainlamar).
Sep 2 2023, 5:26 PM
c-po committed rVYOSONEX396329cc9a24: vrf: T5428: stop DHCP processes on VRF removal.
Sep 2 2023, 5:03 PM
c-po committed rVYOSONEX47d9c8067135: T5428: fix DHCP address renewal/release when running in VRF.
Sep 2 2023, 5:03 PM
c-po committed rVYOSONEXad6a3bdcb7e5: container: T578: fix XML build warning about '.
Sep 2 2023, 5:03 PM
c-po committed rVYOSONEXf7473c735ab2: container: T4353: capitalize ascii -> ASCII.
Sep 2 2023, 5:03 PM
GitHub <noreply@github.com> committed rVYOSONEXe74b38c4d862: Merge pull request #2191 from c-po/equuleus (authored by c-po).
Sep 2 2023, 5:03 PM
Apachez added a comment to T5541: Zone-Based Firewalling in VyOS Sagitta 1.4.

The firewall refactoring released 4th aug 2023 only (so far) took care about the documentation in the configuration section:

Sep 2 2023, 1:20 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
alainlamar created T5541: Zone-Based Firewalling in VyOS Sagitta 1.4.
Sep 2 2023, 1:11 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
alainlamar removed a project from T5540: vyos-1x: Wrong VHT configuration for WiFi 802.11ac: vyatta-wireless.
Sep 2 2023, 12:44 PM · VyOS 1.4 Sagitta
alainlamar created T5540: vyos-1x: Wrong VHT configuration for WiFi 802.11ac.
Sep 2 2023, 12:42 PM · VyOS 1.4 Sagitta
alainlamar updated the task description for T5539: vyos-build: wireless-regdb would not load due to signature mismatch.
Sep 2 2023, 12:17 PM · VyOS Rolling, Bugs
alainlamar added projects to T5539: vyos-build: wireless-regdb would not load due to signature mismatch: VyOS 1.4 Sagitta, vyos-build.
Sep 2 2023, 12:16 PM · VyOS Rolling, Bugs
alainlamar created T5539: vyos-build: wireless-regdb would not load due to signature mismatch.
Sep 2 2023, 12:15 PM · VyOS Rolling, Bugs
Apachez claimed T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.
Sep 2 2023, 11:19 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.

PR created: https://github.com/vyos/vyos-build/pull/391

Sep 2 2023, 11:00 AM · VyOS 1.4 Sagitta
Apachez claimed T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.
Sep 2 2023, 10:45 AM · VyOS 1.4 Sagitta
Apachez created T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.
Sep 2 2023, 10:45 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

PR created: https://github.com/vyos/vyos-build/pull/390

Sep 2 2023, 1:27 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

PR389 build failed:

Sep 2 2023, 1:18 AM · VyOS 1.4 Sagitta

Sep 1 2023

c-po committed rVYOSONEX8daf7f95d832: container: T4353: capitalize ascii -> ASCII.
Sep 1 2023, 9:22 PM
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

PR created: https://github.com/vyos/vyos-build/pull/389

Sep 1 2023, 7:57 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5536: show dhcp client leases caues No module named 'vyos.validate' from In progress to Needs testing.
Sep 1 2023, 3:10 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX99837ad340ff: T5536: Fix show dhcp client leases.
Sep 1 2023, 3:09 PM
GitHub <noreply@github.com> committed rVYOSONEXd3da15234e52: Merge pull request #2193 from sever-sever/T5536 (authored by c-po).
Sep 1 2023, 3:09 PM
c-po committed rVYOSONEXb92515dc8159: T2546: re-add "monitor command" op-mode command with a new "diff" option as well.
Sep 1 2023, 3:08 PM
Viacheslav added a project to T4712: Collaborative Protection Profile cPP for Network Devices root task: VyOS 1.5 Circinus.
Sep 1 2023, 12:51 PM · VyOS Rolling, VyOS 1.5 Circinus (1.5-stream-2025-Q4)
Apachez added a comment to T5534: VRRP rfc3768-compatibility broken after build 1.4-rolling-202308260020.

There was a similar case where it turned out that INPUT/OUTPUT chains for the firewall must be updated to include the stuff VRRP is doing.

Sep 1 2023, 12:22 PM
Apachez added a comment to T5536: show dhcp client leases caues No module named 'vyos.validate'.

Reported in: https://forum.vyos.io/t/error-show-dhcp-lease/12030

Sep 1 2023, 12:12 PM · VyOS 1.4 Sagitta
Apachez closed T5537: show dhcp client leases fails to complete as Invalid.

See this task instead: https://vyos.dev/T5536

Sep 1 2023, 12:11 PM · VyOS 1.4 Sagitta
Apachez created T5537: show dhcp client leases fails to complete.
Sep 1 2023, 12:10 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5536: show dhcp client leases caues No module named 'vyos.validate'.

PR https://github.com/vyos/vyos-1x/pull/2193

Sep 1 2023, 11:51 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5536: show dhcp client leases caues No module named 'vyos.validate' from Open to In progress.
Sep 1 2023, 10:56 AM · VyOS 1.4 Sagitta