Page MenuHomeVyOS Platform
Feed All Stories

Aug 17 2023

Viacheslav created T5488: System conntrack ignore does not take any effect.
Aug 17 2023, 4:52 PM · VyOS 1.4 Sagitta
fernando created T5487: OPENVPN -DEPRECATED OPTION: --cipher.
Aug 17 2023, 4:06 PM · VyOS 1.5 Circinus, Restricted Project
Viacheslav committed rVYOSONEX477c2def5fb4: T5223: Fix removing key id for GRE tunnel.
Aug 17 2023, 12:43 PM
GitHub <noreply@github.com> committed rVYOSONEXdcb02916ddde: Merge pull request #2153 from sever-sever/T5223 (authored by dmbaturin).
Aug 17 2023, 12:43 PM
c-po moved T5428: dhcp: client renewal fails when running inside VRF from Finished to Backlog on the VyOS 1.3 Equuleus (1.3.4) board.
Aug 17 2023, 11:11 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po committed rVYOSONEX08cb4f350b33: console-server: T2490: add op-mode commands to display log.
Aug 17 2023, 11:10 AM
c-po committed rVYOSONEX1a69e9bb4b4e: Revert: dhcp: T5428: always release lease from default VRF.
Aug 17 2023, 11:10 AM
c-po added a reverting change for rVYOSONEX9afcea251bdc: dhcp: T5428: always release lease from default VRF: rVYOSONEX1a69e9bb4b4e: Revert: dhcp: T5428: always release lease from default VRF.
Aug 17 2023, 11:10 AM
Viacheslav added a comment to T5486: Service dns dynamic cannot pass the smoketest.

PR https://github.com/vyos/vyos-1x/pull/2154

Aug 17 2023, 11:10 AM · VyOS 1.3 Equuleus (1.3.5)
c-po added a comment to T5428: dhcp: client renewal fails when running inside VRF.

Tested after merging T5476 and now we see a proper DHCP release message

Aug 17 2023, 11:04 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav closed T5486: Service dns dynamic cannot pass the smoketest as Unknown Status.
Aug 17 2023, 10:58 AM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav added a comment to T5486: Service dns dynamic cannot pass the smoketest.

It could be incorrect process name name='ddclient - sleeping for 10 seconds' expectedd ddclient, possible bug after commit https://github.com/vyos/vyos-1x/commit/58a20e42087cbb7a1b3b4725fa40fd15a31bb4ed

psutil.Process(pid=2282, name='sshd', started='12:29:23')
psutil.Process(pid=2283, name='vbash', started='12:29:23')
psutil.Process(pid=2625, name='rsyslogd', started='12:30:31')
psutil.Process(pid=9841, name='vbash', started='13:02:24')
psutil.Process(pid=10249, name='kworker/u2:1-events_unbound', started='13:03:58')
psutil.Process(pid=10735, name='kworker/0:1-mm_percpu_wq', started='13:10:42')
psutil.Process(pid=10737, name='kworker/u2:2-events_unbound', started='13:10:42')
psutil.Process(pid=10987, name='ddclient - sleeping for 10 seconds', started='13:12:47')
Aug 17 2023, 10:37 AM · VyOS 1.3 Equuleus (1.3.5)
fett0 <fernando.gmaidana@gmail.com> committed rVYOSONEX77ef9f800421: T5466: L3VPN label allocation mode.
Aug 17 2023, 10:13 AM
GitHub <noreply@github.com> committed rVYOSONEXd4e9652083ce: Merge pull request #2152 from fett0/T5466 (authored by c-po).
Aug 17 2023, 10:13 AM
Viacheslav created T5486: Service dns dynamic cannot pass the smoketest.
Aug 17 2023, 9:54 AM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav moved T5223: tunnel key doesn't clear from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 17 2023, 9:44 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav added a comment to T5223: tunnel key doesn't clear .

PR for 1.3.4 https://github.com/vyos/vyos-1x/pull/2153

Aug 17 2023, 9:44 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
c-po closed T5476: netplug: replace Perl helper scripts with a Python equivalent as Resolved.
Aug 17 2023, 9:42 AM · VyOS 1.4 Sagitta
c-po closed T5437: logrotate.service fails to start as Not Applicable.
Aug 17 2023, 9:24 AM · VyOS 1.4 Sagitta
c-po added a comment to T5437: logrotate.service fails to start.

Thanks @Apachez - closing

Aug 17 2023, 9:24 AM · VyOS 1.4 Sagitta
Viacheslav closed T4202: NFT: Zone policies fail to apply when "l2tp+" is in the interface list as Resolved.
Aug 17 2023, 7:46 AM · VyOS 1.4 Sagitta
SrividyaA added projects to T5223: tunnel key doesn't clear : VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3).
Aug 17 2023, 6:45 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
SrividyaA closed T5223: tunnel key doesn't clear as Resolved.
Aug 17 2023, 6:35 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav edited projects for T5484: set extcommunity - just allow one extend community, added: VyOS 1.3 Equuleus (1.3.4); removed VyOS 1.3 Equuleus.
Aug 17 2023, 5:39 AM

Aug 16 2023

c-po created T5485: pppoe: using dialer interfaces in wan-load balancing does not re-install default route.
Aug 16 2023, 9:15 PM · Bugs, VyOS Rolling
fernando updated the task description for T5484: set extcommunity - just allow one extend community.
Aug 16 2023, 8:29 PM
fernando created T5484: set extcommunity - just allow one extend community.
Aug 16 2023, 7:41 PM
Sophie added a comment to T5160: Firewall refactor.

If there would never be such then "INVALID" wouldnt exist as an option.

Aug 16 2023, 7:29 PM · VyOS 1.4 Sagitta
twan added a comment to T5481: Upgrade bug.

Another update. I noticed that all firewall configuration was gone (apart from the groups) after a reboot.

Aug 16 2023, 7:14 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5160: Firewall refactor.

If there would never be such then "INVALID" wouldnt exist as an option.

Aug 16 2023, 7:05 PM · VyOS 1.4 Sagitta
fernando changed the status of T5466: L3VPN - label allocation mode from Open to In progress.
Aug 16 2023, 6:55 PM · VyOS 1.4 Sagitta
fernando added a comment to T5466: L3VPN - label allocation mode .

PR https://github.com/vyos/vyos-1x/pull/2152

Aug 16 2023, 6:55 PM · VyOS 1.4 Sagitta
twan added a comment to T5481: Upgrade bug.

I have attached both files.

Aug 16 2023, 6:41 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX1ab8166a5481: netplug: T5476: rewrite dhclient helper from Perl -> Python.
Aug 16 2023, 5:51 PM
GitHub <noreply@github.com> committed rVYOSONEX65ea7cef9fe9: Merge pull request #2151 from c-po/netplug-t5476 (authored by c-po).
Aug 16 2023, 5:51 PM
dmbaturin committed rVYOSONEX4bc012d2b241: T5270: generate 'dh none' unconditionally when dh-params is no present.
Aug 16 2023, 2:09 PM
dmbaturin committed rVYOSONEX1d6180b74cff: T5271: correct dict path in the template for OpenVPN peer fingerprint.
Aug 16 2023, 2:09 PM
dmbaturin committed rVYOSONEX26d7ab49d92d: T5271: allow the user to specify either CA or peer fingerprint.
Aug 16 2023, 2:09 PM
GitHub <noreply@github.com> committed rVYOSONEX9cdc76fe5bad: Merge pull request #2150 from dmbaturin/T5271-openvpn-peer-fingerprint… (authored by jestabro).
Aug 16 2023, 2:09 PM
c-po added a comment to T5476: netplug: replace Perl helper scripts with a Python equivalent.

PRs:

Aug 16 2023, 11:32 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX3a3e490a198a: wireguard: T1843: add peer description CLI option.
Aug 16 2023, 11:22 AM
sarthurdev added a comment to T5160: Firewall refactor.

2.2: Invalid shall ALWAYS be processed BEFORE established/related/other rules otherwise it will not serve it purpose.

Aug 16 2023, 9:57 AM · VyOS 1.4 Sagitta
tjjh89017 added a comment to T5469: Incorrect dependency set in the openvpn-dco package when building VyOS for arm64.

I will suggest to move all arm64 kernel flavour to "arm64-vyos" as "amd64-vyos" in x86_64.
It will be better not to have "LOCALVERSION=-v8" in kernel configs.

Aug 16 2023, 9:03 AM · VyOS 1.4 Sagitta
Viacheslav updated subscribers of T5448: Add service zabbix-agent.

Thanks, @jestabro
Zabbix-agent really can include config directory, and if it is set and exists any *.conf file it thinks that those files related to zabbix-agent and expects specific config syntax/options.
I.e. it extends zabbix-agent with custom .confg files.
As it was a wrong format, most likely it can't start at all.

Aug 16 2023, 7:33 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5160: Firewall refactor.

2.2: Invalid shall ALWAYS be processed BEFORE established/related/other rules otherwise it will not serve it purpose.

Aug 16 2023, 5:06 AM · VyOS 1.4 Sagitta
jestabro closed T5483: Residual dhcp-server test file causing zabbix-agent smoketest to fail, a subtask of T5448: Add service zabbix-agent, as Resolved.
Aug 16 2023, 2:44 AM · VyOS 1.4 Sagitta
jestabro closed T5483: Residual dhcp-server test file causing zabbix-agent smoketest to fail as Resolved.
Aug 16 2023, 2:44 AM · VyOS 1.4 Sagitta
jestabro added a parent task for T5483: Residual dhcp-server test file causing zabbix-agent smoketest to fail: T5448: Add service zabbix-agent.
Aug 16 2023, 2:44 AM · VyOS 1.4 Sagitta
jestabro added a subtask for T5448: Add service zabbix-agent: T5483: Residual dhcp-server test file causing zabbix-agent smoketest to fail.
Aug 16 2023, 2:44 AM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEX4ea96d248597: T5483: clean up tmp config file.
Aug 16 2023, 2:42 AM
jestabro triaged T5483: Residual dhcp-server test file causing zabbix-agent smoketest to fail as Urgent! priority.
Aug 16 2023, 2:37 AM · VyOS 1.4 Sagitta
giga1699 edited a custom field on T5447: Allow static MACsec keys with peers.
Aug 16 2023, 12:46 AM · VyOS 1.4 Sagitta (1.4.1)

Aug 15 2023

fernando added a comment to T5160: Firewall refactor.

yes, but it's in process to merge : https://github.com/vyos/vyos-documentation/pull/1035

Aug 15 2023, 11:31 PM · VyOS 1.4 Sagitta
Sophie added a comment to T5160: Firewall refactor.

Now we have this included in the nightly builds, is there any documentation on how these refactored rules should be modified? Just bumped my version and was completely lost

Aug 15 2023, 9:49 PM · VyOS 1.4 Sagitta
fernando added a comment to T5481: Upgrade bug.

Could you share the full configuration ? so we can analyze what is the source of this problem .

Aug 15 2023, 9:48 PM · VyOS 1.4 Sagitta
dcplaya created T5482: Chrony NTP Server Fails To Sync Time.
Aug 15 2023, 8:26 PM · VyOS 1.4 Sagitta
twan created T5481: Upgrade bug.
Aug 15 2023, 8:04 PM · VyOS 1.4 Sagitta
dmbaturin closed T5273: Add op mode commands for displaying certificate details and fingerprints, a subtask of T5269: OpenVPN non-TLS site-to-site mode deprecation, as Resolved.
Aug 15 2023, 6:22 PM · VyOS 1.4 Sagitta
dmbaturin closed T5273: Add op mode commands for displaying certificate details and fingerprints as Resolved.
Aug 15 2023, 6:22 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
dmbaturin closed T5270: Make OpenVPN `tls dh-params` optional, a subtask of T5269: OpenVPN non-TLS site-to-site mode deprecation, as Resolved.
Aug 15 2023, 6:22 PM · VyOS 1.4 Sagitta
dmbaturin closed T5270: Make OpenVPN `tls dh-params` optional as Resolved.
Aug 15 2023, 6:21 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
aga closed T5293: Support for Floating Rules (Global Firewall-Rules that are automatically applied before all other Zone Rules) as Resolved.
Aug 15 2023, 3:52 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5478: Cannot configure resolver-cache options for firewall from Confirmed to In progress.

PR: https://github.com/vyos/vyos-1x/pull/2149

Aug 15 2023, 12:01 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5478: Cannot configure resolver-cache options for firewall from Open to Confirmed.
Aug 15 2023, 10:18 AM · VyOS 1.4 Sagitta
n.fort added a comment to T5160: Firewall refactor.

2.1:
Suggestion that established/related merges to a single rule such as:

Aug 15 2023, 10:09 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5448: Add service zabbix-agent.

Cannot pass the smoketest in CI

07:19:00  DEBUG - Running Testcase: /usr/libexec/vyos/tests/smoke/cli/test_service_monitoring_zabbix-agent.py
07:19:02  DEBUG - test_01_zabbix_agent (__main__.TestZabbixAgent.test_01_zabbix_agent) ... FAIL
07:19:04  DEBUG - 
07:19:04  DEBUG - ======================================================================
07:19:04  DEBUG - FAIL: test_01_zabbix_agent (__main__.TestZabbixAgent.test_01_zabbix_agent)
07:19:04  DEBUG - ----------------------------------------------------------------------
07:19:04  DEBUG - Traceback (most recent call last):
07:19:04  DEBUG -   File "/usr/libexec/vyos/tests/smoke/cli/test_service_monitoring_zabbix-agent.py", line 34, in tearDown
07:19:04  DEBUG -     self.assertTrue(process_named_running(PROCESS_NAME))
07:19:04  DEBUG - AssertionError: None is not true
07:19:04  DEBUG - 
07:19:04  DEBUG - ----------------------------------------------------------------------

Is not reproduced in the local VM test

vyos@r14:~$ /usr/libexec/vyos/tests/smoke/cli/test_service_monitoring_zabbix-agent.py
test_01_zabbix_agent (__main__.TestZabbixAgent.test_01_zabbix_agent) ... ok
Aug 15 2023, 8:31 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled.

The original task https://vyos.dev/T5080

Aug 15 2023, 8:23 AM · VyOS 1.4 Sagitta
Viacheslav moved T5457: Add environmental variable pointing to current rootfs directory from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 15 2023, 8:12 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T5480: Ability to disable SNMP for VRRP keepalived service: VyOS 1.4 Sagitta.
Aug 15 2023, 8:10 AM · VyOS 1.4 Sagitta
Viacheslav created T5480: Ability to disable SNMP for VRRP keepalived service.
Aug 15 2023, 8:06 AM · VyOS 1.4 Sagitta
a.hajiyev updated the task description for T5473: Detect what conflicts with POSIX mode.
Aug 15 2023, 5:27 AM · VyOS Rolling, Bugs
a.hajiyev updated the task description for T5473: Detect what conflicts with POSIX mode.
Aug 15 2023, 5:26 AM · VyOS Rolling, Bugs

Aug 14 2023

Apachez closed T5457: Add environmental variable pointing to current rootfs directory as Resolved.
Aug 14 2023, 9:58 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5457: Add environmental variable pointing to current rootfs directory.

Still works in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 9:58 PM · VyOS 1.4 Sagitta
Apachez closed T5440: Restore pre/postconfig scripts if user deleted them as Resolved.
Aug 14 2023, 9:55 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5440: Restore pre/postconfig scripts if user deleted them.

Verified in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 9:55 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5437: logrotate.service fails to start.

Seems to still be happy in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 9:54 PM · VyOS 1.4 Sagitta
Apachez closed T5436: vyos-preconfig-bootup.script is missing as Resolved.
Aug 14 2023, 9:51 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5436: vyos-preconfig-bootup.script is missing.

Verified in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 9:50 PM · VyOS 1.4 Sagitta
Apachez created T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled.
Aug 14 2023, 9:41 PM · VyOS 1.4 Sagitta
Apachez created T5478: Cannot configure resolver-cache options for firewall.
Aug 14 2023, 9:16 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5160: Firewall refactor.

1:
Shouldnt set firewall global-options resolver-cache have "enable" and "disable" as options?

Aug 14 2023, 9:10 PM · VyOS 1.4 Sagitta
Apachez closed T5461: Improve rootfs directory variable as Resolved.
Aug 14 2023, 8:27 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5461: Improve rootfs directory variable.

Looks like its working as expected in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 8:27 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T5434: Replace remaining calls of vyos.xml library: T5477: op-mode pki.py should use Config for defaults.
Aug 14 2023, 4:18 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T5477: op-mode pki.py should use Config for defaults: T5434: Replace remaining calls of vyos.xml library.
Aug 14 2023, 4:18 PM · VyOS 1.4 Sagitta
jestabro closed T5477: op-mode pki.py should use Config for defaults as Resolved.
Aug 14 2023, 4:02 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEXf67614c66d65: pki: T5477: use Config instead of ConfigTreeQuery for defaults.
Aug 14 2023, 4:01 PM
jestabro created T5477: op-mode pki.py should use Config for defaults.
Aug 14 2023, 3:58 PM · VyOS 1.4 Sagitta
a.hajiyev updated the task description for T5473: Detect what conflicts with POSIX mode.
Aug 14 2023, 1:15 PM · VyOS Rolling, Bugs
zsdc updated the task description for T5473: Detect what conflicts with POSIX mode.
Aug 14 2023, 1:12 PM · VyOS Rolling, Bugs
Viacheslav changed the status of T5461: Improve rootfs directory variable from Open to Needs testing.
Aug 14 2023, 11:24 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T5473: Detect what conflicts with POSIX mode from "Task" to "Bug".
Aug 14 2023, 11:17 AM · VyOS Rolling, Bugs
Apachez added a comment to T5473: Detect what conflicts with POSIX mode.

What is the purpose of:

Aug 14 2023, 11:08 AM · VyOS Rolling, Bugs
Viacheslav awarded T5474: Establish common file name pattern for XML conf mode commands a Like token.
Aug 14 2023, 11:00 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort changed the status of T5472: NAT redirect should not require port from Open to Confirmed.
Aug 14 2023, 10:09 AM · VyOS 1.4 Sagitta
c-po added a comment to T2044: RPKI doesn't boot properly.

interesting, as the above diff actually does the same but a bit earlier in the boot process

Aug 14 2023, 6:43 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po updated the task description for T5476: netplug: replace Perl helper scripts with a Python equivalent.
Aug 14 2023, 6:09 AM · VyOS 1.4 Sagitta
c-po claimed T5476: netplug: replace Perl helper scripts with a Python equivalent.
Aug 14 2023, 6:06 AM · VyOS 1.4 Sagitta
c-po created T5476: netplug: replace Perl helper scripts with a Python equivalent.
Aug 14 2023, 6:05 AM · VyOS 1.4 Sagitta