Page MenuHomeVyOS Platform
Feed Search

Mar 31 2025

xeluior added a comment to T7285: CVE-2024-3596 (BlastRADIUS) mitigations for pam_radius.

The above linked PR is ready for review by a maintainer. I've tried to cherry-pick only the most relevant commits from the upstream. The build was tested in the vyos-build container (as modified in https://vyos.dev/T7300) after each commit and the overall authentication flow was tested once as described in the PR.

Mar 31 2025, 6:42 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS 1.4 Sagitta (1.4.3), VyOS Rolling
xeluior added a comment to T7300: Missing dependencies for libpam-radius-auth build in the vyos-build container.

https://github.com/vyos/vyos-build/pull/939

Mar 31 2025, 3:05 PM · VyOS Rolling
xeluior created T7300: Missing dependencies for libpam-radius-auth build in the vyos-build container.
Mar 31 2025, 2:11 PM · VyOS Rolling

Mar 25 2025

xeluior added a comment to T7285: CVE-2024-3596 (BlastRADIUS) mitigations for pam_radius.

I have drafted https://github.com/vyos/libpam-radius-auth/pull/9 with the relevant commits cherry-picked from the upstream FreeRADIUS repo. I haven't been able to test the build yet due to some (probably) unrelated issues with apt in a Debian container.

Mar 25 2025, 8:12 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS 1.4 Sagitta (1.4.3), VyOS Rolling
xeluior created T7285: CVE-2024-3596 (BlastRADIUS) mitigations for pam_radius.
Mar 25 2025, 6:53 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS 1.4 Sagitta (1.4.3), VyOS Rolling

Jan 28 2025

xeluior added a comment to T7095: Git commit-archive broken by T6975.

PR https://github.com/vyos/vyos-1x/pull/4323

Jan 28 2025, 2:31 PM

Jan 27 2025

xeluior created T7095: Git commit-archive broken by T6975.
Jan 27 2025, 4:04 PM

Jan 21 2025

xeluior added a comment to T6975: Add 'vrf' and 'netns' arguments to functions in 'vyos.utils.process'.

Line 86 in python/vyos/utils/process.py breaks the git commit-archive functionality since it passes a list to the rc_cmd function which eventually gets passed to popen. The new line added for this wrapper converts the list to a string similar to "['git', 'clone', 'git@<github url>', '/tmp/git-commit-archive-ypvbmg7z/repository', '--depth=1']". Since there is no wrapper, the command becomes a space followed by that string rather than the intended git clone git@<github url> /tmp/git-commit-archive-ypvbmg7z/repository --depth=1. I expect it would be better if get_wrapper returned a similar list, then if the passed in command is a string, join the wrapper and prepend to the string, otherwise if the command is a list prepend the elements of the wrapper to the list.

Jan 21 2025, 5:51 PM · VyOS 1.5 Circinus, VyOS Rolling

Jan 15 2025

xeluior added a comment to T7048: SSH Agent is not available for Git commit archive.

PR https://github.com/vyos/vyos-1x/pull/4303

Jan 15 2025, 3:07 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS 1.4 Sagitta (1.4.2)

Jan 14 2025

xeluior updated the task description for T7048: SSH Agent is not available for Git commit archive.
Jan 14 2025, 4:43 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS 1.4 Sagitta (1.4.2)
xeluior created T7048: SSH Agent is not available for Git commit archive.
Jan 14 2025, 4:39 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS 1.4 Sagitta (1.4.2)