Page MenuHomeVyOS Platform
Feed All Stories

Dec 20 2023

indrajitr created T5840: Upgrade Kea to 2.4.x.
Dec 20 2023, 6:29 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
Viacheslav moved T5798: reverse-proxy load-balancing service should support multiple certificates for frontend from Open to Finished on the VyOS 1.5 Circinus board.
Dec 20 2023, 1:09 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXa3e059e7e8d3: T5798: load-balancing revese-proxy add multiple SSL certificates (authored by Viacheslav).
Dec 20 2023, 1:07 AM

Dec 19 2023

jamcole added a comment to T5799: vyos unbootable after 1.4-rolling-202308240020 to 1.5-rolling-202312010026 upgrade.

Thanks for that heads-up @Viacheslav - My bigger concern with this task was the failure-mode of the configuration problem being so unexpected and hard to troubleshoot.

Dec 19 2023, 11:25 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jamcole added a comment to T5798: reverse-proxy load-balancing service should support multiple certificates for frontend.

@Viacheslav I upgraded to the latest rolling release and this seems to work perfectly.

Dec 19 2023, 11:21 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro updated the task description for T5839: Remove trivial redundancies in calls to config dependency scripts.
Dec 19 2023, 8:09 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Zen3515 added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

So, I tested the version 1.5-rolling-202312191154

Dec 19 2023, 8:06 PM · VyOS 1.5 Circinus
mcbridematt committed rVYOSONEX37bd574c4e1f: T5828: fix grub installation on arm64-efi machines.
Dec 19 2023, 8:05 PM
Restricted Repository Identity closed T5828: Fix GRUB installation on arm64 as Resolved by committing rVYOSONEXac170ee4bb0a: Merge pull request #2643 from mcbridematt/t5828-grub-arm64-fix.
Dec 19 2023, 8:04 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEXac170ee4bb0a: Merge pull request #2643 from mcbridematt/t5828-grub-arm64-fix (authored by dmbaturin).
Dec 19 2023, 8:04 PM
jestabro added projects to T5839: Remove trivial redundancies in calls to config dependency scripts: VyOS 1.5 Circinus, VyOS 1.4 Sagitta.
Dec 19 2023, 8:04 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a comment to T5839: Remove trivial redundancies in calls to config dependency scripts.

PR:
https://github.com/vyos/vyos-1x/pull/2659

Dec 19 2023, 8:04 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po committed rVYOSONEX5b0c7bbf8c82: smoketest: bgp: T4163: add explicit timeout when starting BMP.
Dec 19 2023, 8:03 PM
c-po committed rVYOSONEXc0fbfe8aea4c: smoketest: bgp: T4163: use explicit kill to respawn bgpd process.
Dec 19 2023, 8:03 PM
GitHub <noreply@github.com> committed rVYOSONEX01fd13f8e15f: Merge pull request #2657 from c-po/backports (authored by dmbaturin).
Dec 19 2023, 8:03 PM
jestabro added a subtask for T5660: Remove redundant calls to config dependency scripts: T5839: Remove trivial redundancies in calls to config dependency scripts.
Dec 19 2023, 7:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a parent task for T5839: Remove trivial redundancies in calls to config dependency scripts: T5660: Remove redundant calls to config dependency scripts.
Dec 19 2023, 7:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro triaged T5839: Remove trivial redundancies in calls to config dependency scripts as Normal priority.
Dec 19 2023, 7:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
zsdc created T5838: Add Infiniband kernel modules.
Dec 19 2023, 7:41 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T5829: Can't Add IPv6 Address to Containers.

Firstly, this bug should be fixed T5837

Dec 19 2023, 4:00 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav created T5837: vyos.configdict.node_changed does not return keys per adding .
Dec 19 2023, 3:59 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <noreply@github.com> committed rVYOSONEXb9cdf8a710c8: Merge pull request #2656 from vyos/mergify/bp/sagitta/pr-2637 (authored by c-po).
Dec 19 2023, 3:00 PM
Viacheslav changed the status of T5823: Protocol BGP add default values for config dictionary from Open to In progress.
Dec 19 2023, 2:14 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX810008107185: T5823: Add recursive_defaults for BGP get_config dictionary (authored by Viacheslav).
Dec 19 2023, 2:11 PM
jestabro closed T5836: Add boolean check for whether config-mode script was called as a dependency, a subtask of T4820: Support for inter-config-mode script dependencies, as Unknown Status.
Dec 19 2023, 1:45 PM · VyOS 1.4 Sagitta
jestabro closed T5836: Add boolean check for whether config-mode script was called as a dependency as Unknown Status.
Dec 19 2023, 1:45 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po committed rVYOSONEXb873112dd725: smoketest: bgp: T4163: use explicit kill to respawn bgpd process.
Dec 19 2023, 10:46 AM
Viacheslav changed the status of T5249: Add rollback-soft feature to rollback without a reboot from Open to Needs testing.
Dec 19 2023, 10:45 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T2117: Update Cloud-init version and actualize our changes to it.

@zsdc Can we close it?

Dec 19 2023, 8:37 AM
Viacheslav closed T2116: Processing configuration via Cloud-init User-Data as Resolved.
Dec 19 2023, 8:33 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav closed T2045: Can't commit due to with the same name, but different firewall groups types, a subtask of T2199: Rewrite firewall in new XML/Python style, as Wontfix.
Dec 19 2023, 8:32 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav closed T2045: Can't commit due to with the same name, but different firewall groups types as Wontfix.

It won't fix due the old backend
Fixed in 1.4/1.5

Dec 19 2023, 8:32 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav closed T1434: Add support for global-parameters, shared-network-parameters, subnet-parameters and static-mapping-parameters in dhcpv6-server as already implemented in (v4) dhcp-server as Wontfix.

We agree not to use raw options anymore.
If some options are required, it should be a separate PR per configured option.

Dec 19 2023, 8:15 AM · VyOS 1.3 Equuleus (1.3.6)
c-po committed rVYOSONEX259a3d637081: smoketest: bgp: T4163: add explicit timeout when starting BMP.
Dec 19 2023, 8:12 AM
c-po added a reverting change for rVYOSONEX7036c761e74b: smoketesT: bgp: temporary disable BMP test: rVYOSONEXf07ef753e1b1: Revert "smoketest: bgp: temporary disable BMP test".
Dec 19 2023, 8:12 AM
c-po committed rVYOSONEXf07ef753e1b1: Revert "smoketest: bgp: temporary disable BMP test".
Dec 19 2023, 8:12 AM
Viacheslav added a comment to T1810: Commit to add new l2tp local user shouldn't disconnect all current l2tp sessions.

Most of the changes are not supported by reload accel-cmd/systemctl unit.
Accel-ppp cannot apply some features/changes without the daemon restarting. In other words, there are only several features that could be applied by reload.

Dec 19 2023, 8:03 AM
Viacheslav closed T922: OSPF - Process Crash after peer reboot as Not Applicable.

The current FRR 7.5
There are no reports with this bug.
Close it. Re-open if you still have issues or create a new bug report.

Dec 19 2023, 7:10 AM · VyOS 1.3 Equuleus (1.3.6)
jestabro committed rVYOSONEX80077eee89e4: configdep: T5836: add boolean check whether script called as dependency.
Dec 19 2023, 6:05 AM
GitHub <noreply@github.com> committed rVYOSONEX36adc4672684: Merge pull request #2655 from jestabro/called_as_dependent (authored by c-po).
Dec 19 2023, 6:05 AM
jestabro triaged T5836: Add boolean check for whether config-mode script was called as a dependency as Normal priority.
Dec 19 2023, 4:31 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a comment to T5836: Add boolean check for whether config-mode script was called as a dependency.

PR:
https://github.com/vyos/vyos-1x/pull/2655

Dec 19 2023, 4:30 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a parent task for T5836: Add boolean check for whether config-mode script was called as a dependency: T4820: Support for inter-config-mode script dependencies.
Dec 19 2023, 4:26 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a subtask for T4820: Support for inter-config-mode script dependencies: T5836: Add boolean check for whether config-mode script was called as a dependency.
Dec 19 2023, 4:26 AM · VyOS 1.4 Sagitta
jestabro created T5836: Add boolean check for whether config-mode script was called as a dependency.
Dec 19 2023, 4:26 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a parent task for T5660: Remove redundant calls to config dependency scripts: T4820: Support for inter-config-mode script dependencies.
Dec 19 2023, 4:08 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a subtask for T4820: Support for inter-config-mode script dependencies: T5660: Remove redundant calls to config dependency scripts.
Dec 19 2023, 4:08 AM · VyOS 1.4 Sagitta

Dec 18 2023

Unknown Object (User) added a comment to T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.

Excellent; thanks @GurliGebis! I built 1.4 today and confirmed it's working as expected.

As far as I'm concerned, this issue is now resolved and the ticket can now be closed.

Dec 18 2023, 9:14 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
marvin added a comment to T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.

Excellent; thanks @GurliGebis! I built 1.4 today and confirmed it's working as expected.

Dec 18 2023, 9:00 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T5829: Can't Add IPv6 Address to Containers.

Yes it should trigger to recreate container but it doesn’t get a dictionary key for recreating

Dec 18 2023, 6:51 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro changed the status of T5751: Adjust new image tools for non-interactive use, a subtask of T4516: Rewrite system image manipulation tools in Python, from Unknown Status to Resolved.
Dec 18 2023, 6:39 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro changed the status of T5751: Adjust new image tools for non-interactive use from Unknown Status to Resolved.
Dec 18 2023, 6:39 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro changed the status of T5758: Restore scanning configs when live installing, a subtask of T4516: Rewrite system image manipulation tools in Python, from Unknown Status to Resolved.
Dec 18 2023, 6:38 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro changed the status of T5758: Restore scanning configs when live installing from Unknown Status to Resolved.
Dec 18 2023, 6:38 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro changed the status of T5789: image-tools should copy ssh host keys on image update, a subtask of T4516: Rewrite system image manipulation tools in Python, from Unknown Status to Resolved.
Dec 18 2023, 6:38 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro changed the status of T5789: image-tools should copy ssh host keys on image update from Unknown Status to Resolved.
Dec 18 2023, 6:38 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro changed the status of T5806: Clear old raid data on new install image, a subtask of T4516: Rewrite system image manipulation tools in Python, from Unknown Status to Resolved.
Dec 18 2023, 6:37 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro changed the status of T5806: Clear old raid data on new install image from Unknown Status to Resolved.
Dec 18 2023, 6:37 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro moved T5821: image-tools: restore vrf-aware 'add system image' from Open to Finished on the VyOS 1.4 Sagitta board.
Dec 18 2023, 6:37 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5821: image-tools: restore vrf-aware 'add system image', a subtask of T4516: Rewrite system image manipulation tools in Python, as Resolved.
Dec 18 2023, 6:37 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro closed T5821: image-tools: restore vrf-aware 'add system image' as Resolved.
Dec 18 2023, 6:37 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro changed the status of T5819: Don't echo password on install image, a subtask of T4516: Rewrite system image manipulation tools in Python, from Unknown Status to Resolved.
Dec 18 2023, 6:36 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro changed the status of T5819: Don't echo password on install image from Unknown Status to Resolved.
Dec 18 2023, 6:36 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro moved T5825: image-tools: restore authentication on 'add system image' from Open to Finished on the VyOS 1.4 Sagitta board.
Dec 18 2023, 6:36 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5825: image-tools: restore authentication on 'add system image', a subtask of T5821: image-tools: restore vrf-aware 'add system image', as Resolved.
Dec 18 2023, 6:35 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5825: image-tools: restore authentication on 'add system image' as Resolved.
Dec 18 2023, 6:35 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro moved T5831: show system image should reverse order by addition date from Open to Finished on the VyOS 1.4 Sagitta board.
Dec 18 2023, 6:35 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5831: show system image should reverse order by addition date, a subtask of T5827: image-tools: 'show system image' Command Not in Order, as Resolved.
Dec 18 2023, 6:35 PM · VyOS 1.5 Circinus
jestabro closed T5831: show system image should reverse order by addition date as Resolved.
Dec 18 2023, 6:35 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <noreply@github.com> committed rVYOSONEX33225eebde7e: Merge pull request #2654 from vyos/mergify/bp/sagitta/pr-2649 (authored by jestabro).
Dec 18 2023, 6:33 PM
jestabro committed rVYOSONEX4ab72043bc0b: image-tools: T5831: show system image reverse ordered by date.
Dec 18 2023, 6:31 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX6763c844977d: image-tools: T5831: show system image reverse ordered by date (authored by jestabro).
Dec 18 2023, 6:16 PM
GitHub <noreply@github.com> committed rVYOSONEXd3f0d65c54e9: Merge pull request #2653 from vyos/mergify/bp/sagitta/pr-2596 (authored by dmbaturin).
Dec 18 2023, 6:13 PM
jestabro committed rVYOSONEXf19b2acb34e7: image-tools: T5831: show system image reverse ordered by date.
Dec 18 2023, 6:13 PM
GitHub <noreply@github.com> committed rVYOSONEXf2cd94167433: Merge pull request #2649 from jestabro/image-version-order (authored by dmbaturin).
Dec 18 2023, 6:13 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXaf7b233a7a10: T5249: Add rollback-soft feature (authored by Viacheslav).
Dec 18 2023, 6:09 PM
jbhardman added a comment to T5829: Can't Add IPv6 Address to Containers.

In my case, the container is created and running using IPv4 only. The network it is in has a defined prefix for IPv4 and IPv6. Then, the only thing I try to do is add an IPv6 address to the container. The network it is connected to already has the IPv6 prefix defined. That is when it dies.

Dec 18 2023, 5:56 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

The mentioned file that missing is located upstream in https://github.com/miniupnp/miniupnp/tree/miniupnpd_2_3_1/miniupnpd/netfilter_nft/scripts
and the upstream configuration options that we think are missing to match vyos chains is https://github.com/miniupnp/miniupnp/blob/miniupnpd_2_3_1/miniupnpd/miniupnpd.conf#L77

Dec 18 2023, 4:49 PM
Viacheslav updated subscribers of T5835: UPnP port mapping / rule installation fails.

Could you point out some documentation/examples on which scripts are missing?
It seems it has never been tested since @jack9603301 implemented it in task T3420. It seems he also didn't test it.

Dec 18 2023, 4:35 PM
GitHub <noreply@github.com> committed rVYOSONEXceec796a3d3d: Merge pull request #2652 from vyos/mergify/bp/sagitta/pr-2627 (authored by c-po).
Dec 18 2023, 4:19 PM
Unknown Object (User) created T5835: UPnP port mapping / rule installation fails.
Dec 18 2023, 2:10 PM
Viacheslav added a comment to T5829: Can't Add IPv6 Address to Containers.

Adding a new container with both addresses and networks in one commit works fine.

set container name alp01 image 'alpine'
set container name alp01 network NET01 address '10.0.0.12'
set container name alp01 network NET01 address '2001:db8::12'
set container network NET01 prefix '10.0.0.0/24'
set container network NET01 prefix '2001:db8::/64'
Dec 18 2023, 10:40 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX8a17966ed7ed: T4163: Add BGP Monitoring Protocol BMP feature (authored by Viacheslav).
Dec 18 2023, 10:08 AM
Viacheslav changed the status of T5829: Can't Add IPv6 Address to Containers from Open to In progress.
Dec 18 2023, 9:59 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav closed T2431: Python validators are slow as Not Applicable.

We don't use /usr/libexec/vyos/validate-value.py anymore
There should be a separates tasks if required.

Dec 18 2023, 9:52 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav closed T2234: Controlling whitespace in Jinja templates (template cleanup parent task) as Not Applicable.

There is nothing to do there, all checks for linter Jinja included to vyos-build.
Close it.

Dec 18 2023, 9:46 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav closed T2215: Make “default no-ipv4-unicast” the default setting, a subtask of T1148: epa2 BGP peers initiate before config is fully loaded, routes leak., as Wontfix.
Dec 18 2023, 9:44 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav closed T2215: Make “default no-ipv4-unicast” the default setting as Wontfix.

It was changed for 1.4/1.5 and won't be changed for 1.3 LTS (old backend)
If someone wants it for 1.3

set protocols bgp 65001 parameters default no-ipv4-unicast
Dec 18 2023, 9:44 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav closed T2191: Using tallow to block sshd probes as Resolved.

We are using sshguard

set service ssh dynamic-protection
Dec 18 2023, 9:37 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a comment to T2187: Python Unit testing.

@thomas-mangin Do you have a PoC?

Dec 18 2023, 9:35 AM · VyOS 1.5 Circinus
Viacheslav closed T1500: Slow boot/load and CLI response times as Not Applicable.

Comparing boot time for now 1.3 and 1.1.8 is not actual
There are 2 different systems :)
Also, some validators were rewritten on 1.2 to Python and for 1.3 to sh, OCAML and so on (python validators could be cause of the issue)
In my internal test VM loads ~40 sec tested in VyOS 1.3.5
We always can improve something, but lets find what we can improve in separate tasks.

Dec 18 2023, 9:25 AM · VyOS 1.3 Equuleus (1.3.6)
indrajitr claimed T5834: Rename 'enable-default-log' to 'default-log'.
Dec 18 2023, 9:23 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
indrajitr created T5834: Rename 'enable-default-log' to 'default-log'.
Dec 18 2023, 9:17 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T1317: OpenVPN configuration fails if it depends on another interface..

@mb300sd could you re-check?

Dec 18 2023, 9:14 AM · VyOS 1.3 Equuleus (1.3.9), test
Viacheslav closed T1304: Make frr daemons configurable as Wontfix.

The main issue is synchronization between all routing daemons and zebra, especially with "policy".
So you are getting strange things like a policy configured for zebra but the same policy not exists/applied for other daemons.
It is impossible to integrate it the correct way.
Reopen for 1.5, 2.0 if required and if it will be possible in the future with correct syncing between all daemons.

Dec 18 2023, 9:12 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav edited projects for T1253: Feature Request: FRR Flowspec, added: VyOS 1.5 Circinus; removed VyOS 1.3 Equuleus (1.3.6), vyos-frr.
Dec 18 2023, 9:04 AM · VyOS 1.5 Circinus
Viacheslav closed T1230: Improving Boot Time for Large Firewall Configurations as Wontfix.

We can't do more due to old backend on the 1.3
If there will be a specific options to improve it should be a separate task
Close it.

Dec 18 2023, 9:02 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav closed T1113: Unwanted/broken "disable" option in firewall state as Wontfix.

Refactored in 1.4/1.5
Let's avoid the firewall migrations for the stable branch.

Dec 18 2023, 8:52 AM · VyOS 1.3 Equuleus (1.3.6), test
Viacheslav removed a project from T970: Support matching domain name in firewall rules: VyOS 1.3 Equuleus (1.3.6).

It won't be implemented for 1.3

Dec 18 2023, 8:45 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T927: IPv6 GRE packets not being forwarded as Invalid.

Configs weren't provided, so closed the task as invalid. Works with internal tetts.
Re-open it or add steps to reproduce.

Dec 18 2023, 8:44 AM · VyOS 1.3 Equuleus (1.3.6), test