Page MenuHomeVyOS Platform
Feed All Stories

May 25 2024

talmakion attached a referenced file: F4328045: vyatta-cfg-separate-completer.diff.
May 25 2024, 10:21 AM · VyOS 1.4 Sagitta (1.4.0-GA)
talmakion attached a referenced file: F4328046: vyatta-cfg-combined-completer.diff.
May 25 2024, 10:21 AM · VyOS 1.4 Sagitta (1.4.0-GA)
talmakion attached a referenced file: Unknown Object (File).
May 25 2024, 10:21 AM · Bugs, VyOS 1.4 Sagitta (1.4.1)
syncer assigned T6397: Triger action on merge to Vijayakumar.
May 25 2024, 10:19 AM · GitHub Infrastructure
syncer created T6397: Triger action on merge.
May 25 2024, 10:19 AM · GitHub Infrastructure
talmakion added a comment to T6157: Can not create two GRE tunnels to the same DST but from different SRC addresses.

As far as I can tell the test will always error if the remote matches and neither source-interface and source-address are configured differently, including the case where they're both blank (source-interface == None on both tunnels triggers this particular case).

May 25 2024, 9:52 AM · Bugs, VyOS 1.4 Sagitta (1.4.1)
Vijayakumar claimed T6372: global CODEOWERS not reflecting in other repos.
May 25 2024, 8:03 AM · GitHub Infrastructure
Vijayakumar claimed T6392: validate backport with reusable action.
May 25 2024, 8:03 AM · GitHub Infrastructure
Vijayakumar closed T6392: validate backport with reusable action, a subtask of T6309: Check code quality with CodeQL, as Resolved.
May 25 2024, 8:02 AM · GitHub Infrastructure
Vijayakumar closed T6392: validate backport with reusable action as Resolved.
May 25 2024, 8:02 AM · GitHub Infrastructure
Vijayakumar added a comment to T6392: validate backport with reusable action.

https://github.com/vyos/vyos-workflow-test-temp/pull/5
Validated.

May 25 2024, 8:02 AM · GitHub Infrastructure
c-po reassigned T6300: [1.3->1.4 Migration] An empty interface configuration drops all interfaces configuration from c-po to jestabro.
May 25 2024, 6:26 AM · Bugs, VyOS 1.4 Sagitta (1.4.1)
c-po closed T6345: Source NAT Port Mapping setting of Fully-Random is superfluous in Kernels 5.0 onwards as Resolved.
May 25 2024, 6:26 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po claimed T6377: PermissionError on /config/auth/letsencrypt/live/ when running show pki.
May 25 2024, 6:26 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
c-po moved T6345: Source NAT Port Mapping setting of Fully-Random is superfluous in Kernels 5.0 onwards from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 25 2024, 6:25 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po moved T6345: Source NAT Port Mapping setting of Fully-Random is superfluous in Kernels 5.0 onwards from Open to 1.4.0-GA on the VyOS 1.4 Sagitta board.
May 25 2024, 6:25 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po renamed T751: IDS and IPS (suricata) from IDS and IPS to IDS and IPS (suricata).
May 25 2024, 6:25 AM · VyOS 1.5 Circinus
c-po moved T6345: Source NAT Port Mapping setting of Fully-Random is superfluous in Kernels 5.0 onwards from Open to Finished on the VyOS 1.5 Circinus board.
May 25 2024, 6:24 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
talmakion added a comment to T6383: Incorrect completion for rollback-soft.

Only recently moved from 1.3 to 1.5 and noticed rollback-soft immediately (great stuff), the completion message was annoying me too.

May 25 2024, 5:45 AM · VyOS 1.4 Sagitta (1.4.0-GA)
tjh created T6396: MINOR Typo: set system conntrack timeout custom ipv4 rule X.
May 25 2024, 5:04 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

May 24 2024

zsdc moved T6395: Enable VFIO No-IOMMU support in kernel config from Open to In Progress on the VyOS 1.5 Circinus board.

PR for 1.5: https://github.com/vyos/vyos-build/pull/638

May 24 2024, 5:43 PM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
zsdc changed the status of T6395: Enable VFIO No-IOMMU support in kernel config from Open to In progress.
May 24 2024, 5:42 PM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
talmakion added a comment to T5049: Configure GRE over IPsec tunnel when source port is in VRF, OSPF causes GRE tunnel broken..

I've just been picking at this one tonight because it's close to some areas of interest (DMVPNs in VRFs), so hopefully this input is useful and appropriate:

May 24 2024, 5:40 PM · Bugs, VyOS Rolling
zsdc created T6395: Enable VFIO No-IOMMU support in kernel config.
May 24 2024, 5:32 PM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
Viacheslav moved T6391: load-balancing reverse-proxy: typo in timeout help from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 24 2024, 1:57 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav closed T6391: load-balancing reverse-proxy: typo in timeout help as Resolved.
May 24 2024, 1:57 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
GitHub <noreply@github.com> committed rVYOSONEXb8d844027482: load-balancing haproxy: T6391: fix typo in timeout help (#3513) (#3514) (authored by mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>).
May 24 2024, 1:57 PM
tuxnet added a comment to T6211: VRF support for Kea-based DHCP server.

yes, that would be a very good solution/implementation

May 24 2024, 1:34 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q3), VyOS Rolling
GitHub <noreply@github.com> committed rVYOSONEX9cde20b45783: Merge pull request #3512 from vyos/mergify/bp/sagitta/pr-3487 (authored by dmbaturin).
May 24 2024, 1:25 PM
n.fort changed the status of T6394: Migrate conntrack timeout sysctl parameter to firewall from Open to In progress.
May 24 2024, 12:34 PM · VyOS 1.5 Circinus
n.fort created T6394: Migrate conntrack timeout sysctl parameter to firewall.
May 24 2024, 12:33 PM · VyOS 1.5 Circinus
alainlamar added a comment to T6318: vyos-1x: WiFi Regulatory Domain should be set system-wide instead of per-device.

Is there already something in the works? As for now, there seem to be issues with regdom settings in VyOS 1.5 anyways (see https://vyos.dev/T6320 "Quirks and Workarounds").

May 24 2024, 12:14 PM · VyOS 1.5 Circinus
alainlamar updated the task description for T6320: WiFi: Enable support for 6GHz AccesPoints.
May 24 2024, 12:12 PM · VyOS Rolling, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
Viacheslav added a comment to T6211: VRF support for Kea-based DHCP server.

Probably the best way will be moving the config to the vrf section (not implemented)
For example:

set vrf name foo service dhcp-server shared-network-name eth1 option default-router '192.168.1.1'
set vrf name foo service dhcp-server shared-network-name eth1 subnet 192.168.1.0/24 lease '300'
set vrf name foo service dhcp-server shared-network-name eth1 subnet 192.168.1.0/24 range default start '192.168.1.10'
set vrf name foo service dhcp-server shared-network-name eth1 subnet 192.168.1.0/24 range default stop '192.168.1.100'
set vrf name foo service dhcp-server shared-network-name eth1 subnet 192.168.1.0/24 subnet-id '1'

And start several instances, each with its configuration.

May 24 2024, 12:04 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q3), VyOS Rolling
tuxnet added a comment to T6211: VRF support for Kea-based DHCP server.

you have to adapt a few more things, if absolutely necessary it also works with several VRFs - but it is very ugly...

May 24 2024, 10:55 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q3), VyOS Rolling
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXf9363fb00b80: load-balancing haproxy: T6391: fix typo in timeout help (#3513) (authored by hirnpfirsich).
May 24 2024, 7:56 AM
GitHub <noreply@github.com> committed rVYOSONEX609563d6acfe: load-balancing haproxy: T6391: fix typo in timeout help (#3513) (authored by hirnpfirsich).
May 24 2024, 7:55 AM
Viacheslav triaged T6393: Port mirroring to tunnel interface fails during boot as Normal priority.
May 24 2024, 7:50 AM · VyOS Rolling, Bugs
haakon.nore added a comment to T6393: Port mirroring to tunnel interface fails during boot.

FYI: The configuration is valid and works. It just fails during boot.

May 24 2024, 7:06 AM · VyOS Rolling, Bugs
Viacheslav added a comment to T6393: Port mirroring to tunnel interface fails during boot.

The similar task for redirect T260

May 24 2024, 7:05 AM · VyOS Rolling, Bugs
haakon.nore created T6393: Port mirroring to tunnel interface fails during boot.
May 24 2024, 6:56 AM · VyOS Rolling, Bugs
Apachez added a comment to T6211: VRF support for Kea-based DHCP server.

I assume that workaround would only work for a single VRF or can one do something like this?

May 24 2024, 5:57 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q3), VyOS Rolling
tuxnet added a comment to T6211: VRF support for Kea-based DHCP server.

The following can be configured as a quick and dirty workaround:

May 24 2024, 5:16 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q3), VyOS Rolling
Vijayakumar created T6392: validate backport with reusable action.
May 24 2024, 4:34 AM · GitHub Infrastructure

May 23 2024

syncer assigned T6391: load-balancing reverse-proxy: typo in timeout help to Viacheslav.
May 23 2024, 11:25 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
syncer triaged T6391: load-balancing reverse-proxy: typo in timeout help as Normal priority.
May 23 2024, 11:25 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
hirnpfirsich added a comment to T6391: load-balancing reverse-proxy: typo in timeout help.

PR: https://github.com/vyos/vyos-1x/pull/3513

May 23 2024, 11:15 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
hirnpfirsich added a comment to T6391: load-balancing reverse-proxy: typo in timeout help.

I am already working on the PR :)

May 23 2024, 11:00 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
hirnpfirsich created T6391: load-balancing reverse-proxy: typo in timeout help.
May 23 2024, 10:59 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po closed T6293: add Mediatek MT7921 to defconfig as Resolved.
May 23 2024, 7:58 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po moved T6293: add Mediatek MT7921 to defconfig from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 23 2024, 7:58 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po moved T6293: add Mediatek MT7921 to defconfig from In Progress to Finished on the VyOS 1.5 Circinus board.
May 23 2024, 7:58 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po added a project to T6293: add Mediatek MT7921 to defconfig: VyOS 1.4 Sagitta (1.4.0-GA).
May 23 2024, 7:58 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po moved T751: IDS and IPS (suricata) from Open to Finished on the VyOS 1.5 Circinus board.
May 23 2024, 7:57 PM · VyOS 1.5 Circinus
c-po changed the status of T751: IDS and IPS (suricata) from Open to Needs testing.
May 23 2024, 7:57 PM · VyOS 1.5 Circinus
0xThiebaut committed rVYOSONEX549089a970e3: suricata: T751: Initial support for suricata.
May 23 2024, 7:56 PM
c-po committed rVYOSONEXcd32928e1856: suricata: T751: move CLI from "service ids suricata" -> "service suricata".
May 23 2024, 7:56 PM
c-po committed rVYOSONEX01464a6069fa: suricata: T751: use key_mangling in get_config_dict().
May 23 2024, 7:56 PM
c-po committed rVYOSONEX2af04a53a4c1: suricata: T751: remove implicit default dictionary.
May 23 2024, 7:56 PM
GitHub <noreply@github.com> committed rVYOSONEX9f9fb8d63f92: Merge pull request #3399 from 0xThiebaut/suricata (authored by c-po).
May 23 2024, 7:56 PM
Embezzle changed the status of T6370: Add option to set custom HTTP headers in reverse-proxy responses from In progress to Needs testing.
May 23 2024, 7:50 PM · VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX6c25888fe0e3: reverse-proxy: T6370: Set custom HTTP headers in reverse-proxy responses (authored by Embezzle).
May 23 2024, 7:24 PM
Embezzle committed rVYOSONEXe1450096b4c6: reverse-proxy: T6370: Set custom HTTP headers in reverse-proxy responses.
May 23 2024, 7:23 PM
GitHub <noreply@github.com> committed rVYOSONEX3e69d8bbe01b: Merge pull request #3487 from Embezzle/T6370 (authored by c-po).
May 23 2024, 7:23 PM
syncer moved T6390: Compensate for packer packaging update from Need Triage to In Progress on the VyOS 1.3 Equuleus (1.3.8) board.
May 23 2024, 7:16 PM · VyOS 1.3 Equuleus (1.3.8)
syncer edited projects for T6390: Compensate for packer packaging update, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.5 Circinus.
May 23 2024, 7:16 PM · VyOS 1.3 Equuleus (1.3.8)
syncer edited projects for T6390: Compensate for packer packaging update, added: VyOS 1.5 Circinus; removed VyOS 1.3 Equuleus.
May 23 2024, 7:09 PM · VyOS 1.3 Equuleus (1.3.8)
cjac created T6390: Compensate for packer packaging update.
May 23 2024, 4:37 PM · VyOS 1.3 Equuleus (1.3.8)
Viacheslav moved T6381: Typos in select ConfigError messages in dhcpv6-server from Open to Finished on the VyOS 1.5 Circinus board.
May 23 2024, 3:53 PM · VyOS 1.5 Circinus
Giggum closed T6381: Typos in select ConfigError messages in dhcpv6-server as Resolved.

Resolved, merged PR: https://github.com/vyos/vyos-1x/pull/3508

May 23 2024, 2:53 PM · VyOS 1.5 Circinus
GitHub <noreply@github.com> committed rVYOSONEX371517c4dcf9: Merge pull request #3511 from vyos/mergify/bp/sagitta/pr-3507 (authored by dmbaturin).
May 23 2024, 2:49 PM
dmbaturin created T6389: Check architecture and flavor compatibility on upgrade attempts.
May 23 2024, 2:36 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.2), VyOS Rolling
jestabro added a comment to T6363: Expose element 'secret' in xml cache and add boolean check.

Difficulty changed to normal to consider one subtlety of xml cache, and add POC for use in (a later version of) the strip-private filter. POC below; some subset of commits may be added to 1.5:
https://github.com/vyos/vyos-1x/compare/current...jestabro:example-property-secret

May 23 2024, 2:21 PM · VyOS Rolling
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX2c94114a3fe1: nat: T6345: source NAT port mapping "fully-random" is superfluous in Kernel >=5. (authored by c-po).
May 23 2024, 2:19 PM
jestabro edited a custom field on T6363: Expose element 'secret' in xml cache and add boolean check.
May 23 2024, 2:19 PM · VyOS Rolling
erkin added a comment to T6352: Tool for generating valid configs based on XML schemas.

The idea is feasible for parameters with constraints (like number ranges) defined in the XML, but there are many other cases where human input is necessary. We could give the tool a set of parameters to randomly generate, or a half-complete config with slots to fill in with random values. Worst case, we'd discover new constraints for more rigid templates; best case, we'd have a proper tool for generating corner cases for smoke tests and fuzzing.

May 23 2024, 2:16 PM · VyOS Rolling
dmbaturin created T6388: Use OCaml 4.14 for CI builds.
May 23 2024, 1:11 PM · VyOS 1.4 Sagitta (1.4.0), VyOS Rolling, VyOS 1.5 Circinus
HollyGurza moved T4576: vpn l2tp logging level configuration from Open to In Progress on the VyOS 1.5 Circinus board.
May 23 2024, 12:19 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
HollyGurza changed the status of T4576: vpn l2tp logging level configuration from Open to In progress.
May 23 2024, 12:19 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
HollyGurza added a comment to T4576: vpn l2tp logging level configuration.

https://github.com/vyos/vyos-1x/pull/3510

May 23 2024, 12:14 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
GitHub <noreply@github.com> committed rVYOSONEXc9945d09c2ad: Merge pull request #3509 from vyos/mergify/bp/sagitta/pr-3505 (authored by c-po).
May 23 2024, 9:49 AM
c-po committed rVYOSONEX7fe568ca1672: nat: T6345: source NAT port mapping "fully-random" is superfluous in Kernel >=5..
May 23 2024, 9:23 AM
GitHub <noreply@github.com> committed rVYOSONEX5678e37fd0b3: Merge pull request #3507 from c-po/nat-T6345 (authored by dmbaturin).
May 23 2024, 9:23 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXb1342f186c56: nat66: T6365: remove warnings for negated interface selections by name (authored by c-po).
May 23 2024, 9:23 AM
c-po committed rVYOSONEX59781ff365a5: nat66: T6365: remove warnings for negated interface selections by name.
May 23 2024, 9:22 AM
GitHub <noreply@github.com> committed rVYOSONEX0f551d2a1d58: Merge pull request #3505 from c-po/nat66-T6365 (authored by dmbaturin).
May 23 2024, 9:22 AM
GitHub <noreply@github.com> committed rVYOSONEX7279f7496698: Merge pull request #3504 from vyos/mergify/bp/sagitta/pr-3482 (authored by dmbaturin).
May 23 2024, 9:21 AM
Vijayakumar added a comment to T6386: add caller workflows and codeowners file for vyos-build.

https://github.com/vyos/vyos-build/pull/634 Merged

May 23 2024, 7:05 AM · VyOS 1.4 Sagitta
Vijayakumar closed T6386: add caller workflows and codeowners file for vyos-build as Resolved.
May 23 2024, 7:04 AM · VyOS 1.4 Sagitta
Vijayakumar renamed T6386: add caller workflows and codeowners file for vyos-build from add caller workflows and codeowners file for vyox-build to add caller workflows and codeowners file for vyos-build.
May 23 2024, 6:11 AM · VyOS 1.4 Sagitta
Viacheslav edited projects for T6387: Bump conntrack to version 1:1.4.7-1, added: VyOS 1.5 Circinus; removed VyOS 1.4 Sagitta.
May 23 2024, 6:07 AM · VyOS 1.5 Circinus
Viacheslav created T6387: Bump conntrack to version 1:1.4.7-1.
May 23 2024, 6:07 AM · VyOS 1.5 Circinus
Vijayakumar changed the status of T6386: add caller workflows and codeowners file for vyos-build from Open to In progress.
May 23 2024, 5:14 AM · VyOS 1.4 Sagitta
Viacheslav closed T6357: Create test repository to validate setup, a subtask of T6309: Check code quality with CodeQL, as Resolved.
May 23 2024, 5:14 AM · GitHub Infrastructure
Viacheslav closed T6357: Create test repository to validate setup as Resolved.
May 23 2024, 5:14 AM · GitHub Infrastructure
Vijayakumar added a comment to T6357: Create test repository to validate setup.

Please mark this as resolved

May 23 2024, 5:13 AM · GitHub Infrastructure
GitHub <noreply@github.com> committed rVYOSONEX55f2681bc5ec: dhcpv6-server: T6381: fix typos in select ConfigError messages in VyOS current… (authored by Giggum).
May 23 2024, 5:10 AM
Viacheslav assigned T6371: Show nat source rules shows unexpected dictionary to Giggum.
May 23 2024, 5:05 AM · VyOS Rolling, Bugs
Giggum added a comment to T6371: Show nat source rules shows unexpected dictionary.

Follow up, I was able to make nat.py throw the error below.

May 23 2024, 3:10 AM · VyOS Rolling, Bugs
Giggum added a comment to T6371: Show nat source rules shows unexpected dictionary.

@Viacheslav, same behaviour exists for epa3, I numbered mine 999 so as not to interfere with existing rules.

May 23 2024, 2:34 AM · VyOS Rolling, Bugs