Page MenuHomeVyOS Platform
Feed All Stories

Today

n.fort added a comment to T5621: Show uncommited "commands" (compare | commands).

You mean this existing option, or I am missing something?

vyos@vyos-suri:~$ conf
[edit]
vyos@vyos-suri# set int eth eth0 description TEST
[edit]
vyos@vyos-suri# set serv ssh port 8877
[edit]
vyos@vyos-suri# set system host-name foo
[edit]
vyos@vyos-suri# compare 
[interfaces ethernet eth0]
+ description "TEST"
[service ssh]
+ port "8877"
[system]
- host-name "vyos-suri"
+ host-name "foo"
Fri, Sep 29, 10:43 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav updated the task description for T5623: Add tunnel over Socks5 proxy .
Fri, Sep 29, 8:41 AM · VyOS 1.5 Circinus
Viacheslav created T5623: Add tunnel over Socks5 proxy .
Fri, Sep 29, 8:40 AM · VyOS 1.5 Circinus
Viacheslav changed the status of T5261: Add aws gateway load-balance -tunnel-handler gwlbtun from In progress to Needs testing.
Fri, Sep 29, 7:53 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T5620: "Deactivate" certain config snippets from "Task" to "Feature Request".
Fri, Sep 29, 7:26 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5622: Add system upgrade uses local script instead of updated script provided by ISO.

I suppose the maintainers already considered the below but I got a suggestion on how to resolve this issue:

Fri, Sep 29, 5:47 AM · VyOS 1.5 Circinus
Apachez added a comment to T5593: Further shrink VyOS imagesize.

Created https://vyos.dev/T5622 which must first be resolved before T5593 can get successfully merged.

Fri, Sep 29, 12:29 AM · VyOS 1.5 Circinus
Apachez created T5622: Add system upgrade uses local script instead of updated script provided by ISO.
Fri, Sep 29, 12:28 AM · VyOS 1.5 Circinus
Apachez added a comment to T5593: Further shrink VyOS imagesize.

PR updated for part 1/2 (vyatta-cfg-system): https://github.com/vyos/vyatta-cfg-system/pull/209

Fri, Sep 29, 12:12 AM · VyOS 1.5 Circinus
GernhardReinlunzen triaged T5621: Show uncommited "commands" (compare | commands) as Wishlist priority.
Fri, Sep 29, 12:02 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Yesterday

GernhardReinlunzen triaged T5620: "Deactivate" certain config snippets as Wishlist priority.
Thu, Sep 28, 11:47 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
syncer triaged T5576: Add bgp remove-private-as all option as Normal priority.
Thu, Sep 28, 10:44 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5593: Further shrink VyOS imagesize.

PR updated for part 2/2 (vyos-build): https://github.com/vyos/vyos-build/pull/427

Thu, Sep 28, 8:46 PM · VyOS 1.5 Circinus
c-po closed T5596: bgp: add new features from FRR 9 as Resolved.
Thu, Sep 28, 6:55 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
zsdc changed the status of T5618: Flow-accounting crushes when IMT is enabled from Open to In progress.

This should fix the problem: https://github.com/vyos/vyos-build/pull/428

Thu, Sep 28, 4:57 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
samip537 raised the priority of T5619: Update the Intel ixgbe driver due to issues with Intel X533 from Normal to Requires assessment.
Thu, Sep 28, 2:32 PM · VyOS 1.4 Sagitta
samip537 triaged T5619: Update the Intel ixgbe driver due to issues with Intel X533 as Normal priority.
Thu, Sep 28, 2:32 PM · VyOS 1.4 Sagitta
jestabro closed T5412: Add support for extending config-mode dependencies in supplemental package, a subtask of T4820: Support for inter-config-mode script dependencies, as Resolved.
Thu, Sep 28, 2:07 PM · VyOS 1.4 Sagitta
jestabro closed T5412: Add support for extending config-mode dependencies in supplemental package, a subtask of T5403: Add support for extending xml cache , as Resolved.
Thu, Sep 28, 2:07 PM · VyOS 1.4 Sagitta
jestabro closed T5412: Add support for extending config-mode dependencies in supplemental package as Resolved.
Thu, Sep 28, 2:07 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
erkin added a comment to T4038: Rewrite `vyatta-image-tools.pl` in Python.

show-dhcp-leases.pl under vyatta-op remains the only extant deadweight Vyatta script and needs to be removed.

Thu, Sep 28, 2:07 PM · VyOS 1.4 Sagitta
JeffWDH added a comment to T5497: Add ability to resequence rule numbers for firewall.

https://github.com/vyos/vyos-1x/pull/2316

Thu, Sep 28, 11:26 AM · VyOS 1.4 Sagitta
diodep updated subscribers of T5049: Configure GRE over IPsec tunnel when source port is in VRF, OSPF causes GRE tunnel broken..

It seems this problem is not caused by IPsec, but it was caused by GRE implementation.

Thu, Sep 28, 8:29 AM · VyOS 1.4 Sagitta

Wed, Sep 27

jestabro moved T5412: Add support for extending config-mode dependencies in supplemental package from Need Triage to Backport Candidates on the VyOS 1.4 Sagitta board.
Wed, Sep 27, 5:55 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a comment to T5412: Add support for extending config-mode dependencies in supplemental package.

PR for sagitta:
https://github.com/vyos/vyos-1x/pull/2315

Wed, Sep 27, 5:54 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort renamed T5616: Firewall mark - Add capabilities for matching firewall mark from Firewall marl - Add capabilities for matching firewall mark to Firewall mark - Add capabilities for matching firewall mark.
Wed, Sep 27, 5:48 PM · VyOS 1.5 Circinus
n.fort added a comment to T5616: Firewall mark - Add capabilities for matching firewall mark.

PR: https://github.com/vyos/vyos-1x/pull/2314

Wed, Sep 27, 5:48 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T5165: Policy local-route ability set protocol and port.

Add option protocol, PR https://github.com/vyos/vyos-1x/pull/2313

set policy local-route rule 100 destination '192.0.2.12'
set policy local-route rule 100 protocol 'tcp'
set policy local-route rule 100 set table '100'
Wed, Sep 27, 2:10 PM · VyOS 1.4 Sagitta
jestabro added a comment to T5403: Add support for extending xml cache .

Adding use outline from PR for future reference; the dir vyos-1x-current below refers to a local copy of the vyos-1x source:

Wed, Sep 27, 1:56 PM · VyOS 1.4 Sagitta
a.apostoliuk created T5618: Flow-accounting crushes when IMT is enabled.
Wed, Sep 27, 1:21 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5593: Further shrink VyOS imagesize.

PR created for part 1/2 (vyatta-cfg-system): https://github.com/vyos/vyatta-cfg-system/pull/209

Wed, Sep 27, 8:52 AM · VyOS 1.5 Circinus
Viacheslav closed T5197: Conntrack-sync external cache commit error as Resolved N/A.

Fixed

Wed, Sep 27, 7:54 AM · VyOS 1.4 Sagitta
Viacheslav placed T5203: load-balancing wan add systemd unit instead of old vyatta-wanloadbalance.init up for grabs.
Wed, Sep 27, 7:28 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5593: Further shrink VyOS imagesize.
Wed, Sep 27, 12:16 AM · VyOS 1.5 Circinus
Apachez added a comment to T5593: Further shrink VyOS imagesize.

Build was successful and smoketests are currently in progress.

Wed, Sep 27, 12:07 AM · VyOS 1.5 Circinus

Tue, Sep 26

Apachez added a comment to T5593: Further shrink VyOS imagesize.

If build and smoketests are successful a commit will arrive later today.

Tue, Sep 26, 11:15 PM · VyOS 1.5 Circinus
jestabro added a comment to T5593: Further shrink VyOS imagesize.

... of course, feel free to experiment; I have not yet considered the proposed idea.

Tue, Sep 26, 10:55 PM · VyOS 1.5 Circinus
jestabro added a comment to T5593: Further shrink VyOS imagesize.

@Apachez note that those legacy image install scripts will be removed following
https://vyos.dev/T4516
Work on completing that is active this week and should be finished soon. You may want to hold off on this investigation until then.

Tue, Sep 26, 10:54 PM · VyOS 1.5 Circinus
Apachez claimed T5593: Further shrink VyOS imagesize.
Tue, Sep 26, 9:50 PM · VyOS 1.5 Circinus
Apachez added a comment to T5593: Further shrink VyOS imagesize.

Point 1 might be solved by using a hooks/live-script for the binary part which is the part after the chroot have been created.

Tue, Sep 26, 9:49 PM · VyOS 1.5 Circinus
Apachez added a comment to T5589: Nonstripped binaries exists in VyOS.

PR created: https://github.com/vyos/vyos-build/pull/426

Tue, Sep 26, 8:58 PM · VyOS 1.5 Circinus
Apachez added a comment to T5589: Nonstripped binaries exists in VyOS.

Turned out to be little of a challenge do "just" strip all binaries (and libraries, modules etc).

Tue, Sep 26, 6:12 PM · VyOS 1.5 Circinus
syncer assigned T5497: Add ability to resequence rule numbers for firewall to n.fort.
Tue, Sep 26, 6:10 PM · VyOS 1.4 Sagitta
JeffWDH added a comment to T5497: Add ability to resequence rule numbers for firewall.

Also added flowtable as nothing needs to be sequenced in there either:
https://github.com/JeffWDH/vyos-1x/commit/ac22cc054d9c15af010c824ac9a05f5cc71fc954

Tue, Sep 26, 6:10 PM · VyOS 1.4 Sagitta
JeffWDH added a comment to T5497: Add ability to resequence rule numbers for firewall.

I have not contributed code to this project before so let me know if I've missed conventions...

Tue, Sep 26, 5:52 PM · VyOS 1.4 Sagitta
b- added a comment to T4915: Minisign verification failure == pass??.

Just to be clear, the build I'm going from is just my own build of current to my own build of current -- it says 1.4 because I only changed the version string to 1.5 after this build went through since i'm the only one using my build :)

Tue, Sep 26, 5:48 PM · VyOS 1.4 Sagitta
b- triaged T4915: Minisign verification failure == pass?? as High priority.

I just noticed that this still is a problem. Excerpt below from downloading an upgrade:

Tue, Sep 26, 5:42 PM · VyOS 1.4 Sagitta
dmbaturin created T5617: Add an option to exclude single values to the numeric validator.
Tue, Sep 26, 5:40 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T5586: Disable by default SNMP for Keepalived VRRP.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/2310

Tue, Sep 26, 3:00 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T5497: Add ability to resequence rule numbers for firewall.

1.5-rolling-202309250022

Is there a reason why some global options and some address groups (not all) are included in the output? Seems unintentional to me.

Tue, Sep 26, 2:41 PM · VyOS 1.4 Sagitta
JeffWDH added a comment to T5497: Add ability to resequence rule numbers for firewall.

Is there a reason why some global options and some address groups (not all) are included in the output? Seems unintentional to me.

Tue, Sep 26, 2:24 PM · VyOS 1.4 Sagitta
Viacheslav closed T5480: Ability to disable SNMP for VRRP keepalived service as Resolved.
Tue, Sep 26, 1:26 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5616: Firewall mark - Add capabilities for matching firewall mark.

We have fwmark for policy local-route
But it is only for match mark and routing decision

vyos@vyos-lns# set policy local-route rule 100 
Possible completions:
+  destination          Destination address or prefix
   fwmark               Match fwmark value
   inbound-interface    Inbound Interface
 > set                  Packet modifications
+  source               Source address or prefix
Tue, Sep 26, 12:47 PM · VyOS 1.5 Circinus
n.fort changed the status of T5616: Firewall mark - Add capabilities for matching firewall mark from Open to Confirmed.
Tue, Sep 26, 12:11 PM · VyOS 1.5 Circinus
n.fort created T5616: Firewall mark - Add capabilities for matching firewall mark.
Tue, Sep 26, 12:11 PM · VyOS 1.5 Circinus

Mon, Sep 25

Apachez added a comment to T5589: Nonstripped binaries exists in VyOS.

Have to add "binutils-common" to make "strip" work within the dockerimage.

Mon, Sep 25, 7:05 PM · VyOS 1.5 Circinus
jestabro added a comment to T5611: Difference in config file after interface MAC changed.

This is an artifact of the remaining use in 1.3 of the legacy XorpConfigParser: the last use of that legacy piece was removed from 1.4 in Jan 2021, but is still called by 'vyatta_interface_rescan' so will be seen after changing MAC addresses if the config is not saved. A quick summary of the history is here and quoted below:

Mon, Sep 25, 4:51 PM · VyOS 1.3 Equuleus
Apachez claimed T5589: Nonstripped binaries exists in VyOS.
Mon, Sep 25, 4:34 PM · VyOS 1.5 Circinus
Apachez added a comment to T5589: Nonstripped binaries exists in VyOS.

Implement hooks-script for livebuild that recursively go through following directories using "strip --strip-all" (syntax to be verified):

Mon, Sep 25, 4:30 PM · VyOS 1.5 Circinus
Apachez added a comment to T5522: Add logging for which mksquashfs syntax is being used.

Shouldnt that be default for lb then in the vyos buildscripts and how does --debug affect things other than logging during build?

Mon, Sep 25, 4:00 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5379: show system updates doesnt seem to be working.

What is the "system update-check url" supposed to be once its implemented?

Mon, Sep 25, 3:54 PM · VyOS 1.4 Sagitta
dmbaturin edited the content of 1.3.4.
Mon, Sep 25, 3:42 PM
dmbaturin merged T3144: Support op-mode command to release DHCP leases into T1375: Add clear dhcp server lease function.
Mon, Sep 25, 2:13 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dmbaturin merged task T3144: Support op-mode command to release DHCP leases into T1375: Add clear dhcp server lease function.
Mon, Sep 25, 2:12 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin edited projects for T2640: Running VyOS inside Docker containers, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus (1.3.4).
Mon, Sep 25, 2:08 PM · VyOS 1.3 Equuleus (1.3.3)
dmbaturin changed Issue type from feature to bug on T3070: Firewall going OOM, possible related to nftables migration.
Mon, Sep 25, 1:52 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin changed Issue type from feature to internal on T4874: Add Warning message to Equuleus.
Mon, Sep 25, 1:46 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin changed Issue type from unspecified to bug on T5524: Add config directory to liveCD.
Mon, Sep 25, 1:41 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dmbaturin changed Issue type from unspecified to feature on T5354: Add sshguard to protect against brut-forces for 1.3.
Mon, Sep 25, 1:40 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin changed Issue type from unspecified to improvement on T5315: vrrp: add support for version 3.
Mon, Sep 25, 1:39 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dmbaturin changed the status of T4479: generate wireguard client command prompt has some error from Resolved N/A to Invalid.
Mon, Sep 25, 1:38 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin renamed T3546: Add support for running scripts on PPPoE server session events from Add pppoe-server CLI custom script feature to Add support for running scripts on PPPoE server session events.
Mon, Sep 25, 1:37 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin set Issue type to feature on T3546: Add support for running scripts on PPPoE server session events.
Mon, Sep 25, 1:36 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin set Issue type to bug on T3339: Cloud-Init domain search setting not applied.
Mon, Sep 25, 1:36 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dmbaturin closed T5533: Keepalived VRRP IPv6 group enters in FAULT state as Resolved.
Mon, Sep 25, 1:28 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dmbaturin renamed T5526: Clarify the error message when trying to set an interface as a BGP peer group using the wrong syntax from BGP peer-group - don't support add interfaces over peer neigborhs to Clarify the error message when trying to set an interface as a BGP peer group using the wrong syntax.
Mon, Sep 25, 1:27 PM · VyOS 1.3 Equuleus (1.3.5)
indrajitr updated the task description for T5615: Narrow down spurious name conflict with mdns.
Mon, Sep 25, 4:47 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
indrajitr updated the task description for T5615: Narrow down spurious name conflict with mdns.
Mon, Sep 25, 4:31 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
indrajitr triaged T5615: Narrow down spurious name conflict with mdns as Normal priority.
Mon, Sep 25, 4:29 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a comment to T5522: Add logging for which mksquashfs syntax is being used.

Note that is is the "--debug" flag that one wants in order to see the full mksquashfs command that is executed.

Mon, Sep 25, 12:57 AM · VyOS 1.4 Sagitta
jestabro claimed T5611: Difference in config file after interface MAC changed.
Mon, Sep 25, 12:08 AM · VyOS 1.3 Equuleus

Sun, Sep 24

jestabro added a comment to T3871: Resolve unexpected interface name reordering.

@stingalleman As mentioned above (and confirmed in discussions earlier this week), we've had few if any reports of issues with the udev approach, so we would be very interested to hear details of your case.

Sun, Sep 24, 11:52 PM · VyOS 1.4 Sagitta
sdev added a comment to T5599: Firewall unexpectedly changes some sysctl options.

Not sure what to do on this one. The firewall is depending on conntrack module, which updates the conntrack related sysctls. It'd be the same if someone defines custom sysctls used by other conf scripts.

Sun, Sep 24, 6:30 PM · VyOS 1.5 Circinus
stingalleman added a comment to T3871: Resolve unexpected interface name reordering.

When will this bug be fixed? I am having a lot of issues with this.

Sun, Sep 24, 4:17 PM · VyOS 1.4 Sagitta
Apachez closed T5511: Cleanup of unused directories (and files) in order to shrink image-size as Resolved.

Verified to be working as expected.

Sun, Sep 24, 2:47 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5522: Add logging for which mksquashfs syntax is being used.

@jestabro I havent verified it yet but then perhaps the buildscript for VyOS should be altered to include --verbose?

Sun, Sep 24, 2:45 PM · VyOS 1.4 Sagitta
Apachez closed T5591: Cleanup of FRR daemons-file and various FRR fixes as Resolved.

Verified through smoketests.

Sun, Sep 24, 2:45 PM · VyOS 1.5 Circinus
sdev changed the status of T5614: Add conntrack helper matching on firewall from Open to In progress.
Sun, Sep 24, 2:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez closed T5604: List of debian archives is out of date (non-free-firmware is missing) as Resolved.
Sun, Sep 24, 2:44 PM · VyOS 1.5 Circinus
Apachez added a comment to T5604: List of debian archives is out of date (non-free-firmware is missing).

Verified through smoketests.

Sun, Sep 24, 2:44 PM · VyOS 1.5 Circinus
sdev changed the status of T5606: IPSec VPN: Allow multiple CAs certificates from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2305

Sun, Sep 24, 1:54 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sdev moved T5606: IPSec VPN: Allow multiple CAs certificates from Need Triage to In Progress on the VyOS 1.5 Circinus board.
Sun, Sep 24, 12:17 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sdev added a project to T5606: IPSec VPN: Allow multiple CAs certificates: VyOS 1.5 Circinus.
Sun, Sep 24, 12:17 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sdev changed the status of T5606: IPSec VPN: Allow multiple CAs certificates from Open to In progress.
Sun, Sep 24, 12:17 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sdev added a comment to T5160: Firewall refactor.

PR removing zone-policy op-mode: https://github.com/vyos/vyos-1x/pull/2304

Sun, Sep 24, 11:44 AM · VyOS 1.4 Sagitta
sdev changed the status of T5376: Conntrack FTP helper does not work properly from Confirmed to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2304

Sun, Sep 24, 11:44 AM · VyOS 1.4 Sagitta
sdev changed the status of T5598: unknown parameter 'nf_conntrack_helper' ignored from Confirmed to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2304

Sun, Sep 24, 11:44 AM · VyOS 1.5 Circinus
indrajitr updated the task description for T5612: Miscellaneous improvements and fixes for dynamic DNS configuration.
Sun, Sep 24, 1:32 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Sat, Sep 23

Viacheslav changed the edit policy for T5613: VyOS in container bugs.
Sat, Sep 23, 5:56 PM · VyOS 1.5 Circinus
Viacheslav added a parent task for T2115: VyOS Docker container not load config: T5613: VyOS in container bugs.
Sat, Sep 23, 5:53 PM · VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.5)