- Feed Queries
- All Stories
- Search
- Feed Search
- Transactions
- Transaction Logs
Jun 16 2026
HttpC.download() in python/vyos/remote.py always sends a HEAD request before GET to discover redirects and Content-Length. Some remote APIs (notably AbuseIPDB blocklist endpoints) reject HEAD with 405 Method Not Allowed while GET works fine. vyos-domain-resolver catches the failure and falls back to the cached list file — which on first commit is an empty placeholder — so remote-groups stay at 0 members.
Jun 15 2026
Looks like I'll have to use a workaround and run BGP between the two VRFs instead.
In my previous deployments using FRR on Debian, I never had to rely on a full FRR reload for routine BGP policy changes. In most cases, applying the change and performing a soft refresh (for example, clear ip bgp vrf test * soft in/out) was sufficient and did not impact forwarding.
FRR reloads the whole configuration per commit, not only one protocol
So policy-route-map is related to FRR config and prefix-lists are the same between all FRR routing daemons.
https://github.com/vyos/vyos-1x/blob/c2f87f243a1f813fbdd319b1004fd3a26397ab3e/python/vyos/frrender.py#L850
Jun 14 2026
Jun 13 2026
The subject migration is added by T8492
Jun 12 2026
@a.apostoliuk Could you please share the full logs from the crash?
UPD: fixed by https://github.com/vyos/vyos-1x/pull/5253
Jun 11 2026
Looks like protocols_bgp.py has been refactored a bit since i last worked on this and the issue i ran into no longer exists. PR submitted.
Jun 10 2026
vyos-build: https://github.com/vyos/vyos-build/pull/1222
vyos-1x: https://github.com/vyos/vyos-1x/pull/5267
Created an initial pull request at https://github.com/vyos/vyos-1x/pull/5266
If somebody could explain to me what value addr (at https://github.com/vyos/vyos-1x/blob/a6ad73d72ba8d5256ff77978e63c07143787eb44/python/vyos/utils/network.py#L400) is set to when the current listen address is *, I might be able to come up with a PR to fix this.
I tried to work around the issue by leveraging VRRP transition scripts, when I’ve noticed haproxy by default listens to every interface (i.e. binds to *) when no explicit listen-address is set. However due to this behavior it is no longer possible to add a listen-address when haproxy is already running, as the on-commit check refuses to apply due to the port being occupied. For obvious reasons it should ignore the port being in use in such cases. The only solution for now is completely removing all haproxy config before reapplying all of it, which is very much suboptimal.
I think it should check the state of net.ipv4.ip_nonlocal_bind / net.ipv6.ip_nonlocal_bind, and if set to 1, skip the check.
I found the culprit: https://github.com/vyos/vyos-1x/pull/5186 introduced a check if the address is assigned. I think this should be changed to check for an address, that is generally available (via config), not minding if it is actually configured. Open for suggestions to send in a PR.
This is the reproduce.py I used to validate on a fresh instance.