Page MenuHomeVyOS Platform
Feed Search

Aug 8 2026

catalyys added a comment to T9180: default_action return is missing in vyos_firewall_rules.

I have added a Pull Request under https://github.com/vyos/vyos.vyos/pull/494

Aug 8 2026, 8:33 PM · VyOS Rolling
c-po created T9181: Kernel: modernize packaging and remove redundant work.
Aug 8 2026, 8:32 PM · VyOS Rolling
catalyys created T9180: default_action return is missing in vyos_firewall_rules.
Aug 8 2026, 7:56 PM · VyOS Rolling
hedrok closed T9036: ipt-NETFLOW: support VRF as Resolved.

Closed in https://vyos.dev/T9122

Aug 8 2026, 5:12 PM · VyOS Rolling
hedrok created T9179: Completion and validation don't match for source interface name.
Aug 8 2026, 5:02 PM · VyOS Rolling
Restricted Repository Identity closed T9107: Fix integration workflow after recent GitHub security updates as Resolved by committing Restricted Diffusion Commit.
Aug 8 2026, 4:37 PM · VyOS Rolling
drixter created T9178: ipv6 ospfv3 redistribute.
Aug 8 2026, 3:15 PM · VyOS Rolling
asklymenko closed T9125: Add new exception to the workflow that checks for typos as Resolved.
Aug 8 2026, 3:00 PM · VyOS Rolling
hybridops added a comment to T6941: cloud-init cannot clean up previously downloaded instance data.

I checked the current public vyos-cloud-init branches and the issue still appears to be present: cloudinit/stages.py calls util.del_file(self.paths.instance_link), while util.del_file() uses os.unlink(), so a stale real directory at that path still raises IsADirectoryError.

Aug 8 2026, 2:41 PM · VyOS 1.5 Circinus, VyOS Rolling
hybridops added a comment to T8999: openvpn: misleading "no openvpn shared-secrets in PKI" error for a dangling auth-key/crypt-key reference.

I would like to work on this task.

Aug 8 2026, 1:58 PM · VyOS Rolling
hybridops added a comment to T9172: cloud-init: add regression coverage for vyos_config_commands.

PR submitted and ready for review:
https://github.com/vyos/vyos-cloud-init/pull/116

Aug 8 2026, 11:24 AM · VyOS Rolling
hybridops added a comment to T9145: WAN Load Balancing: User-defined health-check scripts do not receive interface context (WLB_INTERFACE_NAME).

I would like to work on this task.

Aug 8 2026, 11:20 AM · VyOS Rolling

Aug 7 2026

L0crian added a comment to T9176: firewall: Implement nftables concatenation support for firewall groups.

PR: https://github.com/vyos/vyos-1x/pull/5385

Aug 7 2026, 11:08 PM · VyOS Rolling
rherold added a comment to T9177: are_same_ip() in python/vyos/utils/network.py uses wrong address family for second argument.

PR: https://github.com/vyos/vyos-1x/pull/5383

Aug 7 2026, 9:01 PM · VyOS Rolling
rherold created T9177: are_same_ip() in python/vyos/utils/network.py uses wrong address family for second argument.
Aug 7 2026, 8:48 PM · VyOS Rolling
L0crian created T9176: firewall: Implement nftables concatenation support for firewall groups.
Aug 7 2026, 6:01 PM · VyOS Rolling
itspngu created T9175: PowerDNS periodically queries security-status.secpoll.powerdns.com and discards the result.
Aug 7 2026, 5:53 PM · VyOS Rolling
jesper.beltman added a comment to T9174: WWAN modem not up, counter 100 not long enough.

Running Commit again after the modem 0 is exist does work.

Aug 7 2026, 3:13 PM · VyOS Rolling
jesper.beltman created T9174: WWAN modem not up, counter 100 not long enough.
Aug 7 2026, 3:13 PM · VyOS Rolling
Viacheslav changed the status of T9172: cloud-init: add regression coverage for vyos_config_commands from Open to In progress.
Aug 7 2026, 11:21 AM · VyOS Rolling
Viacheslav triaged T9173: Feature Request: Automate RFC 8195 Large-Community tagging from existing BGP config (Role, neighbor ASN) as Normal priority.
Aug 7 2026, 11:08 AM · VyOS Rolling
rherold added a comment to T9160: Config-path-derived group/prefix-list membership (analogous to Junos `apply-path`).

Update: the "Low fit" verdict above for policy as-path-list/community-list/extcommunity-list/large-community-list ("no natural derivation source") needs a caveat.

Aug 7 2026, 11:02 AM · VyOS Rolling
rherold created T9173: Feature Request: Automate RFC 8195 Large-Community tagging from existing BGP config (Role, neighbor ASN).
Aug 7 2026, 10:58 AM · VyOS Rolling
rherold updated subscribers of T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

@Viacheslav thx for cleanup the task,. Did you see that I ask for an decision from the team about the implementation?

Aug 7 2026, 10:38 AM · VyOS Rolling
hybridops added a comment to T9172: cloud-init: add regression coverage for vyos_config_commands.

@hybridops Would you like to claim this task?

Aug 7 2026, 10:19 AM · VyOS Rolling
Viacheslav changed the status of T9159: # Feature Request: Expose a client-side source-address option for `service ntp` from Open to In progress.
Aug 7 2026, 10:03 AM · VyOS Rolling
Viacheslav changed the status of T9160: Config-path-derived group/prefix-list membership (analogous to Junos `apply-path`) from Open to In progress.
Aug 7 2026, 9:11 AM · VyOS Rolling
Viacheslav closed T9163: Typos in the completion help for the service conntrack-sync interface as Resolved.
Aug 7 2026, 8:55 AM · VyOS Rolling
Viacheslav closed T9073: Add CLI support for frr_exporter optional collectors and collector options as Resolved.
Aug 7 2026, 8:53 AM · VyOS Rolling
Viacheslav closed T8921: QoS/CAKE / FQ_CODEL IFB redirect fails at boot when WireGuard interface has fixed local port as Resolved.
Aug 7 2026, 8:51 AM · VyOS Rolling
Viacheslav closed T9018: VPP VLAN does not work as Resolved.
Aug 7 2026, 8:49 AM · VyOS Rolling
Viacheslav closed T9133: fstrim systemd timer/unit does effectively nothing as Resolved.
Aug 7 2026, 8:35 AM · VyOS Rolling
Viacheslav changed the status of T9167: dhcp: Kea HA max-response-delay equals heartbeat-delay (disagrees with Kea defaults) from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/5382

Aug 7 2026, 6:19 AM · VyOS Rolling
Viacheslav triaged T9167: dhcp: Kea HA max-response-delay equals heartbeat-delay (disagrees with Kea defaults) as Normal priority.
Aug 7 2026, 6:18 AM · VyOS Rolling
Viacheslav added a comment to T9167: dhcp: Kea HA max-response-delay equals heartbeat-delay (disagrees with Kea defaults).

@bradkollmyer Would you like to claim this task?
At first glance all related changes here https://github.com/vyos/vyos-1x/blob/278fba204200f02bb461f786f889b40dc38a26f6/python/vyos/template.py#L907

Aug 7 2026, 6:18 AM · VyOS Rolling
Viacheslav closed T9065: VPP sflow not work when enable-egress is disabled as Resolved.
Aug 7 2026, 6:05 AM · VyOS Rolling
Viacheslav closed T8996: QoS: set-dscp option has no effect as Resolved.
Aug 7 2026, 6:01 AM · VyOS Rolling
Viacheslav assigned T9171: IPv6 BFD sessions never reach `Up` on unnumbered VLAN sub-interfaces sharing a parent's MAC (upstream FRR bug, tracked as FRRouting/frr#22921) to hedrok.
Aug 7 2026, 4:23 AM · VyOS Rolling
Viacheslav added a comment to T9172: cloud-init: add regression coverage for vyos_config_commands.

@hybridops Would you like to claim this task?

Aug 7 2026, 4:22 AM · VyOS Rolling

Aug 6 2026

c-po closed T8128: RTL8723AE WiFi Card Firmware Missing as Resolved.
Aug 6 2026, 8:59 PM · VyOS 1.5 Circinus (Circinus-Next), VyOS Rolling
c-po added a comment to T8128: RTL8723AE WiFi Card Firmware Missing.

File is present int rolling release. Please use any rolling release published AFTER this post.

Aug 6 2026, 8:59 PM · VyOS 1.5 Circinus (Circinus-Next), VyOS Rolling
c-po closed T9170: Kernel: missing firmware files after enabling module compression as Resolved.
Aug 6 2026, 8:40 PM · VyOS Rolling
hybridops created T9172: cloud-init: add regression coverage for vyos_config_commands.
Aug 6 2026, 5:46 PM · VyOS Rolling
rherold created T9171: IPv6 BFD sessions never reach `Up` on unnumbered VLAN sub-interfaces sharing a parent's MAC (upstream FRR bug, tracked as FRRouting/frr#22921).
Aug 6 2026, 3:07 PM · VyOS Rolling
c-po added a comment to T9170: Kernel: missing firmware files after enabling module compression.

https://github.com/vyos/vyos-build/pull/1261

Aug 6 2026, 5:26 AM · VyOS Rolling
c-po changed the status of T9170: Kernel: missing firmware files after enabling module compression from Open to In progress.
Aug 6 2026, 5:16 AM · VyOS Rolling
c-po created T9170: Kernel: missing firmware files after enabling module compression.
Aug 6 2026, 5:16 AM · VyOS Rolling
c-po claimed T8128: RTL8723AE WiFi Card Firmware Missing.
Aug 6 2026, 5:13 AM · VyOS 1.5 Circinus (Circinus-Next), VyOS Rolling
jestabro added a comment to T9169: Refactor vyos1x-config diff functions in functorial style.

PR:
https://github.com/vyos/vyos1x-config/pull/90

Aug 6 2026, 2:21 AM · VyOS Rolling
jestabro created T9169: Refactor vyos1x-config diff functions in functorial style.
Aug 6 2026, 1:51 AM · VyOS Rolling
jestabro added a parent task for T9168: Fix vyconf build by use of correct ocaml-protoc / pbrt version: T9044: vyconf: add CI build + test workflow (dune build + runtest on PR).
Aug 6 2026, 1:36 AM · VyOS Rolling
jestabro created T9168: Fix vyconf build by use of correct ocaml-protoc / pbrt version.
Aug 6 2026, 1:36 AM · VyOS Rolling

Aug 5 2026

bradkollmyer created T9167: dhcp: Kea HA max-response-delay equals heartbeat-delay (disagrees with Kea defaults).
Aug 5 2026, 11:22 PM · VyOS Rolling
rherold added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).
Thanks for reproducing this independently — matches what we found on our own multi-device-unnumbered topology (loopback address duplicated across lo + 3 P2P bond
interfaces per router, full-mesh OSPF core). We proved the same underlying inconsistency with a logging-only rule (no notrack, just log+counter, run in parallel with live
traffic, zero production impact):
Aug 5 2026, 3:27 PM · VyOS Rolling
L0crian added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

I tested with 2 interfaces when testing BGP over OSPF, but with 8 for BGP only ip unnumbered:

Aug 5 2026, 3:17 PM · VyOS Rolling
rherold added a comment to T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

You're right that device binding implicitly selects the VRF — bindacqdevice/binddevice on an interface that belongs to a VRF scopes that socket to it, no separate VRF
option needed for that to work at the chrony level.

Aug 5 2026, 3:13 PM · VyOS Rolling
Apachez added a comment to T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

Again, VRF is selected through both bindacqdevice and binddevice so having "asymmetric incoming/outgoing VRF binding" works perfectly fine.

Aug 5 2026, 2:39 PM · VyOS Rolling
rherold added a comment to T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

binddevice/bindacqdevice are already separately configurable — binddevice maps to the existing interface option (incoming/listen), bindacqdevice to this PR's new
ource-interface (outgoing/client). So incoming vs. outgoing device binding is already independent.

Aug 5 2026, 1:51 PM · VyOS Rolling
rherold added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

Thanks for testing this — appreciate the data. To reconcile with what we saw: our issue wasn't IP-unnumbered per se, but specifically that our own address appears on
multiple devices simultaneously in the local route table (ip route show table local showed our loopback duplicated across lo + 3 P2P bond interfaces used for OSPF, since
our full-mesh core reuses the loopback address on each P2P link). We proved with a logging-only rule (fib daddr . iif type unicast log) that real traffic to our own
address was classified unicast, never local, even though ip route get reported local for the same case.

Aug 5 2026, 1:49 PM · VyOS Rolling
L0crian added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

OSPF and BGP is for input, so they should be there.

Aug 5 2026, 1:27 PM · VyOS Rolling
Apachez added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

@L0crian: When you did that test did you try to reboot in between?

Aug 5 2026, 1:25 PM · VyOS Rolling
Apachez added a comment to T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

Its worsen the situation since selecting source-address wont work if thats in a different vrf so that smoketest will fail where it shouldnt.

Aug 5 2026, 1:17 PM · VyOS Rolling
L0crian added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

Can you provide your config you tested with. I just tested and it works as expected even with using ip unnumbered. This is with forwarding traffic going across the router:

Using ip unnumbered BGP over OSPF:
vyos@vyos# run show conntrack table ipv4
Original src    Original dst    Original packets    Original bytes    Reply src     Reply dst       Reply packets    Reply bytes    Protocol    State        Timeout    Mark    Zone
--------------  --------------  ------------------  ----------------  ------------  --------------  ---------------  -------------  ----------  -----------  ---------  ------  ------
10.0.0.1        224.0.0.5       0                   0                 224.0.0.5     10.0.0.1        0                0              unknown                  596        0
10.0.0.2        224.0.0.5       0                   0                 224.0.0.5     10.0.0.2        0                0              unknown                  598        0
10.0.0.1:43585  10.0.0.2:179    0                   0                 10.0.0.2:179  10.0.0.1:43585  0                0              tcp         ESTABLISHED  431985     0

And if I then delete the disable-conntrack, you can see forward traffic now enters conntrack:

vyos@vyos# delete firewall ipv4 forward filter disable-conntrack 
vyos@vyos# commit
vyos@vyos# run show conntrack table ipv4
Original src    Original dst    Original packets    Original bytes    Reply src     Reply dst       Reply packets    Reply bytes    Protocol    State        Timeout    Mark    Zone
--------------  --------------  ------------------  ----------------  ------------  --------------  ---------------  -------------  ----------  -----------  ---------  ------  ------
10.0.10.10      10.0.11.10      0                   0                 10.0.11.10    10.0.10.10      0                0              icmp                     27         0
10.0.0.1        224.0.0.5       0                   0                 224.0.0.5     10.0.0.1        0                0              unknown                  596        0
10.0.0.2        224.0.0.5       0                   0                 224.0.0.5     10.0.0.2        0                0              unknown                  597        0
10.0.0.1:43585  10.0.0.2:179    0                   0                 10.0.0.2:179  10.0.0.1:43585  0                0              tcp         ESTABLISHED  431979     0
Using ip unnumbered only BGP:
vyos@vyos# run show conntrack table ipv4
Entries not found
vyos@vyos# run show conntrack table ipv6
Original src               Original dst                 Original packets    Original bytes    Reply src                    Reply dst                  Reply packets    Reply bytes    Protocol    State        Timeout    Mark    Zone
-------------------------  ---------------------------  ------------------  ----------------  ---------------------------  -------------------------  ---------------  -------------  ----------  -----------  ---------  ------  ------
fe80::ecd:a4ff:fec2:0:179  fe80::eda:29ff:fe4e:0:39492  0                   0                 fe80::eda:29ff:fe4e:0:39492  fe80::ecd:a4ff:fec2:0:179  0                0              tcp         ESTABLISHED  431999     0
fe80::ecd:a4ff:fec2:0:179  fe80::eda:29ff:fe4e:0:39496  0                   0                 fe80::eda:29ff:fe4e:0:39496  fe80::ecd:a4ff:fec2:0:179  0                0              tcp         ESTABLISHED  431999     0
Aug 5 2026, 11:38 AM · VyOS Rolling
rherold added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).
Thanks both for the input.
Aug 5 2026, 6:48 AM · VyOS Rolling
rherold added a comment to T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

@Apachez: Thanks for the feedback — you're right that a source IP alone doesn't fully solve this for multi-VRF setups with overlapping address ranges.

Aug 5 2026, 6:41 AM · VyOS Rolling
Viacheslav changed the status of T9162: show nat source rules` crashes with `KeyError: 0` for rules without `inbound-interface` from Open to In progress.
Aug 5 2026, 4:59 AM · VyOS Rolling
Apachez added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

Is this the same (exists in Stream 2026.03)?

Aug 5 2026, 3:45 AM · VyOS Rolling
Apachez added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

Also currently missing in Stream 2026.03:

Aug 5 2026, 3:43 AM · VyOS Rolling
Apachez added a comment to T9146: support no-multi-seg in DPDK VPP.

It seems that this change occurs behind the scenes as in not a configurable option. Being dealt with by adjusting buffers so jumboframes are still properly supported (even if DPDK documentation claims this is NOT compatible with jumbo frames!?).

Aug 5 2026, 3:39 AM · VyOS Rolling
Apachez added a comment to T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

How will it work if I got 2 different VRFs?

Aug 5 2026, 3:23 AM · VyOS Rolling

Aug 4 2026

rherold created T9165: BGP EVPN control-plane integration for the VPP dataplane.
Aug 4 2026, 7:50 PM · VyOS Rolling
c-po added a comment to T7736: Container: virtual-ethernet exception when attempting to modify container network created veth.

https://github.com/vyos/vyos-build/pull/1259

Aug 4 2026, 7:28 PM · VyOS Rolling
Viacheslav triaged T9163: Typos in the completion help for the service conntrack-sync interface as Normal priority.
Aug 4 2026, 5:12 PM · VyOS Rolling
Viacheslav created T9163: Typos in the completion help for the service conntrack-sync interface.
Aug 4 2026, 5:08 PM · VyOS Rolling
Viacheslav triaged T9153: interface: source-validation is not removed when a logical interface is removed as Normal priority.
Aug 4 2026, 3:42 PM · VyOS Rolling
Viacheslav changed the status of T9153: interface: source-validation is not removed when a logical interface is removed from Open to In progress.
Aug 4 2026, 3:42 PM · VyOS Rolling
natali-rs1985 added a comment to T9146: support no-multi-seg in DPDK VPP.
Aug 4 2026, 3:01 PM · VyOS Rolling
Viacheslav added a comment to T9154: IPsec vti-up-down: DB keyed only by connection name causes admin-down of a VTI still carried by a live IKE_SA.

PR https://github.com/vyos/vyos-1x/pull/5370

Aug 4 2026, 11:40 AM · VyOS Rolling
rherold added a comment to T9162: show nat source rules` crashes with `KeyError: 0` for rules without `inbound-interface`.

https://github.com/vyos/vyos-1x/pull/5375

Aug 4 2026, 11:21 AM · VyOS Rolling
rherold created T9162: show nat source rules` crashes with `KeyError: 0` for rules without `inbound-interface`.
Aug 4 2026, 11:13 AM · VyOS Rolling
natali-rs1985 created T9161: VPP: interface MTU handling — keep kernel and dataplane in sync.
Aug 4 2026, 9:50 AM · VyOS Rolling
L0crian added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

Correct, if you want to test it you'd have to test on rolling. If the feature works for you, you could then request the feature get backported to 1.5. The commit was on the 1.5 board, so I'm not sure why it wasn't backported before the GA was released.

Aug 4 2026, 1:39 AM · VyOS Rolling
rherold added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

@L0crian the command :

Aug 4 2026, 1:04 AM · VyOS Rolling
rherold added a comment to T9160: Config-path-derived group/prefix-list membership (analogous to Junos `apply-path`).

https://github.com/vyos/vyos-documentation/pull/2187

Aug 4 2026, 12:46 AM · VyOS Rolling
rherold added a comment to T9160: Config-path-derived group/prefix-list membership (analogous to Junos `apply-path`).

https://github.com/vyos/vyos-1x/pull/5374

Aug 4 2026, 12:45 AM · VyOS Rolling

Aug 3 2026

rherold added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

@L0crian thx for this information, this could help with my current setup. I will try it in the lab. But I also see that my patched could be usefull

Aug 3 2026, 11:20 PM · VyOS Rolling
rherold added a comment to T9160: Config-path-derived group/prefix-list membership (analogous to Junos `apply-path`).

I can create a patch for this if wanted

Aug 3 2026, 11:12 PM · VyOS Rolling
rherold created T9160: Config-path-derived group/prefix-list membership (analogous to Junos `apply-path`).
Aug 3 2026, 11:12 PM · VyOS Rolling
L0crian added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

Your addition is still useful because it lets you match only on specific interfaces or traffic, but have you seen that you can already do this?:

Aug 3 2026, 11:10 PM · VyOS Rolling
rherold added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

https://github.com/vyos/vyos-documentation/pull/2186

Aug 3 2026, 10:53 PM · VyOS Rolling
rherold added a comment to T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).

https://github.com/vyos/vyos-1x/pull/5372

Aug 3 2026, 10:41 PM · VyOS Rolling
rherold added a comment to T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.

https://github.com/vyos/vyos-documentation/pull/2185

Aug 3 2026, 9:46 PM · VyOS Rolling
rherold placed T9159: # Feature Request: Expose a client-side source-address option for `service ntp` up for grabs.

See https://github.com/vyos/vyos-1x/pull/5371

Aug 3 2026, 9:37 PM · VyOS Rolling
rherold created T9159: # Feature Request: Expose a client-side source-address option for `service ntp`.
Aug 3 2026, 9:13 PM · VyOS Rolling
ServerForge created T9158: Add option to disable/enable rx offload.
Aug 3 2026, 8:57 PM · VyOS Rolling
jestabro added a comment to T9156: configsession: enforce consistent use of finalizers.

PR:
https://github.com/vyos/vyos-1x/pull/5369

Aug 3 2026, 8:22 PM · VyOS Rolling
Viacheslav triaged T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`) as Normal priority.
Aug 3 2026, 4:50 PM · VyOS Rolling
Viacheslav changed the status of T9152: firewall: Move source-validation rules into a vmap to improve traffic processing speed. from Open to In progress.
Aug 3 2026, 4:41 PM · VyOS Rolling
rherold created T9157: Support `fib daddr type` / `fib saddr type` matching in firewall rules (especially `prerouting raw`).
Aug 3 2026, 4:02 PM · VyOS Rolling
jestabro created T9156: configsession: enforce consistent use of finalizers.
Aug 3 2026, 3:43 PM · VyOS Rolling