Page MenuHomeVyOS Platform
Feed All Stories

Sep 26 2023

Apachez added a comment to T5593: Further shrink VyOS imagesize.

Point 1 might be solved by using a hooks/live-script for the binary part which is the part after the chroot have been created.

Sep 26 2023, 9:49 PM · VyOS 2.0.x
Apachez added a comment to T5589: Nonstripped binaries exists in VyOS.

PR created: https://github.com/vyos/vyos-build/pull/426

Sep 26 2023, 8:58 PM · VyOS 1.5 Circinus
GitHub <noreply@github.com> committed rVYOSONEX58344bc76962: Merge pull request #2311 from vyos/mergify/bp/sagitta/pr-2308 (authored by c-po).
Sep 26 2023, 6:50 PM
c-po committed rVYOSONEXd0d48cde5097: rpki: T2044: add to daemons Jinja2 template.
Sep 26 2023, 6:48 PM
GitHub <noreply@github.com> committed rVYOSONEX254c2907525a: Merge pull request #2312 from c-po/rpki-fixes (authored by c-po).
Sep 26 2023, 6:48 PM
GitHub <noreply@github.com> committed rVYOSONEX13e9c9e85320: Merge pull request #2309 from vyos/mergify/bp/sagitta/pr-2302 (authored by Viacheslav).
Sep 26 2023, 6:35 PM
Apachez added a comment to T5589: Nonstripped binaries exists in VyOS.

Turned out to be little of a challenge do "just" strip all binaries (and libraries, modules etc).

Sep 26 2023, 6:12 PM · VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX07dfc6216be7: firewall: T5160: Remove zone policy op-mode (authored by sarthurdev).
Sep 26 2023, 6:11 PM
sarthurdev committed rVYOSONEX9b9b37e9cbb2: firewall: T5160: Remove zone policy op-mode.
Sep 26 2023, 6:11 PM
GitHub <noreply@github.com> committed rVYOSONEX6ffb104ada0a: Merge pull request #2308 from sarthurdev/fw_opmode (authored by c-po).
Sep 26 2023, 6:10 PM
syncer assigned T5497: Add ability to resequence rule numbers for firewall to n.fort.
Sep 26 2023, 6:10 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
JeffWDH added a comment to T5497: Add ability to resequence rule numbers for firewall.

Also added flowtable as nothing needs to be sequenced in there either:
https://github.com/JeffWDH/vyos-1x/commit/ac22cc054d9c15af010c824ac9a05f5cc71fc954

Sep 26 2023, 6:10 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
JeffWDH added a comment to T5497: Add ability to resequence rule numbers for firewall.

I have not contributed code to this project before so let me know if I've missed conventions...

Sep 26 2023, 5:52 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
b- added a comment to T4915: Minisign verification failure == pass??.

Just to be clear, the build I'm going from is just my own build of current to my own build of current -- it says 1.4 because I only changed the version string to 1.5 after this build went through since i'm the only one using my build :)

Sep 26 2023, 5:48 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
b- triaged T4915: Minisign verification failure == pass?? as High priority.

I just noticed that this still is a problem. Excerpt below from downloading an upgrade:

Sep 26 2023, 5:42 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
dmbaturin created T5617: Add an option to exclude single values to the numeric validator.
Sep 26 2023, 5:40 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T5586: Disable by default SNMP for Keepalived VRRP.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/2310

Sep 26 2023, 3:00 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T5497: Add ability to resequence rule numbers for firewall.

1.5-rolling-202309250022

Is there a reason why some global options and some address groups (not all) are included in the output? Seems unintentional to me.

Sep 26 2023, 2:41 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
JeffWDH added a comment to T5497: Add ability to resequence rule numbers for firewall.

Is there a reason why some global options and some address groups (not all) are included in the output? Seems unintentional to me.

Sep 26 2023, 2:24 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav closed T5480: Ability to disable SNMP for VRRP keepalived service as Resolved.
Sep 26 2023, 1:26 PM · VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXecfb617e99dc: T5497: op-mode: Add generate firewall rule-resequence (authored by Viacheslav).
Sep 26 2023, 1:20 PM
Viacheslav added a comment to T5616: Firewall mark - Add capabilities for matching firewall mark.

We have fwmark for policy local-route
But it is only for match mark and routing decision

vyos@vyos-lns# set policy local-route rule 100 
Possible completions:
+  destination          Destination address or prefix
   fwmark               Match fwmark value
   inbound-interface    Inbound Interface
 > set                  Packet modifications
+  source               Source address or prefix
Sep 26 2023, 12:47 PM · VyOS 1.5 Circinus
n.fort changed the status of T5616: Firewall mark - Add capabilities for matching firewall mark from Open to Confirmed.
Sep 26 2023, 12:11 PM · VyOS 1.5 Circinus
n.fort created T5616: Firewall mark - Add capabilities for matching firewall mark.
Sep 26 2023, 12:11 PM · VyOS 1.5 Circinus

Sep 25 2023

Apachez added a comment to T5589: Nonstripped binaries exists in VyOS.

Have to add Debian package "binutils" to make "strip" work within the chroot of livebuild.

Sep 25 2023, 7:05 PM · VyOS 1.5 Circinus
jestabro added a comment to T5611: Difference in config file after interface MAC changed.

This is an artifact of the remaining use in 1.3 of the legacy XorpConfigParser: the last use of that legacy piece was removed from 1.4 in Sep 2021, but is still called by 'vyatta_interface_rescan' in 1.3, so will be seen after changing MAC addresses if the config is not saved. A quick summary of the history is here and quoted below:

Sep 25 2023, 4:51 PM · VyOS Rolling, Bugs
Apachez claimed T5589: Nonstripped binaries exists in VyOS.
Sep 25 2023, 4:34 PM · VyOS 1.5 Circinus
Apachez added a comment to T5589: Nonstripped binaries exists in VyOS.

Implement hooks-script for livebuild that recursively go through following directories using "strip --strip-all" (syntax to be verified):

Sep 25 2023, 4:30 PM · VyOS 1.5 Circinus
Apachez added a comment to T5522: Add logging for which mksquashfs syntax is being used.

Shouldnt that be default for lb then in the vyos buildscripts and how does --debug affect things other than logging during build?

Sep 25 2023, 4:00 PM · VyOS Rolling
Apachez added a comment to T5379: show system updates doesnt seem to be working.

What is the "system update-check url" supposed to be once its implemented?

Sep 25 2023, 3:54 PM · VyOS 1.4 Sagitta
dmbaturin edited the content of 1.3.4.
Sep 25 2023, 3:42 PM
dmbaturin merged T3144: Support op-mode command to release DHCP leases into T1375: Add clear dhcp server lease function.
Sep 25 2023, 2:13 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dmbaturin merged task T3144: Support op-mode command to release DHCP leases into T1375: Add clear dhcp server lease function.
Sep 25 2023, 2:12 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin edited projects for T2640: Running VyOS inside Docker containers, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus (1.3.4).
Sep 25 2023, 2:08 PM · VyOS 1.3 Equuleus (1.3.3)
dmbaturin changed Issue type from feature to bug on T3070: Firewall going OOM, possible related to nftables migration.
Sep 25 2023, 1:52 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin changed Issue type from feature to internal on T4874: Add Warning message to Equuleus.
Sep 25 2023, 1:46 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin changed Issue type from unspecified to bug on T5524: Add config directory to liveCD.
Sep 25 2023, 1:41 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dmbaturin changed Issue type from unspecified to feature on T5354: Add sshguard to protect against brut-forces for 1.3.
Sep 25 2023, 1:40 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin changed Issue type from unspecified to improvement on T5315: vrrp: add support for version 3.
Sep 25 2023, 1:39 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dmbaturin changed the status of T4479: generate wireguard client command prompt has some error from Not Applicable to Invalid.
Sep 25 2023, 1:38 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin renamed T3546: Add support for running scripts on PPPoE server session events from Add pppoe-server CLI custom script feature to Add support for running scripts on PPPoE server session events.
Sep 25 2023, 1:37 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin set Issue type to feature on T3546: Add support for running scripts on PPPoE server session events.
Sep 25 2023, 1:36 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin set Issue type to bug on T3339: Cloud-Init domain search setting not applied.
Sep 25 2023, 1:36 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dmbaturin closed T5533: Keepalived VRRP IPv6 group enters in FAULT state as Resolved.
Sep 25 2023, 1:28 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dmbaturin renamed T5526: Clarify the error message when trying to set an interface as a BGP peer group using the wrong syntax from BGP peer-group - don't support add interfaces over peer neigborhs to Clarify the error message when trying to set an interface as a BGP peer group using the wrong syntax.
Sep 25 2023, 1:27 PM · Bugs, VyOS 1.3 Equuleus (1.3.8)
indrajitr updated the task description for T5615: Narrow down spurious name conflict with mdns.
Sep 25 2023, 4:47 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
indrajitr updated the task description for T5615: Narrow down spurious name conflict with mdns.
Sep 25 2023, 4:31 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
indrajitr triaged T5615: Narrow down spurious name conflict with mdns as Normal priority.
Sep 25 2023, 4:29 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro added a comment to T5522: Add logging for which mksquashfs syntax is being used.

Note that is is the "--debug" flag that one wants in order to see the full mksquashfs command that is executed.

Sep 25 2023, 12:57 AM · VyOS Rolling
jestabro claimed T5611: Difference in config file after interface MAC changed.
Sep 25 2023, 12:08 AM · VyOS Rolling, Bugs

Sep 24 2023

jestabro added a comment to T3871: Resolve unexpected interface name reordering.

@stingalleman As mentioned above (and confirmed in discussions earlier this week), we've had few if any reports of issues with the udev approach, so we would be very interested to hear details of your case.

Sep 24 2023, 11:52 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA)
sarthurdev added a comment to T5599: Firewall unexpectedly changes some sysctl options.

Not sure what to do on this one. The firewall is depending on conntrack module, which updates the conntrack related sysctls. It'd be the same if someone defines custom sysctls used by other conf scripts.

Sep 24 2023, 6:30 PM · VyOS Rolling, Bugs
stingalleman added a comment to T3871: Resolve unexpected interface name reordering.

When will this bug be fixed? I am having a lot of issues with this.

Sep 24 2023, 4:17 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA)
Apachez closed T5511: Cleanup of unused directories (and files) in order to shrink image-size as Resolved.

Verified to be working as expected.

Sep 24 2023, 2:47 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5522: Add logging for which mksquashfs syntax is being used.

@jestabro I havent verified it yet but then perhaps the buildscript for VyOS should be altered to include --verbose?

Sep 24 2023, 2:45 PM · VyOS Rolling
Apachez closed T5591: Cleanup of FRR daemons-file and various FRR fixes as Resolved.

Verified through smoketests.

Sep 24 2023, 2:45 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5614: Add conntrack helper matching on firewall from Open to In progress.
Sep 24 2023, 2:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez closed T5604: List of debian archives is out of date (non-free-firmware is missing) as Resolved.
Sep 24 2023, 2:44 PM · VyOS 1.5 Circinus
Apachez added a comment to T5604: List of debian archives is out of date (non-free-firmware is missing).

Verified through smoketests.

Sep 24 2023, 2:44 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5606: IPSec VPN: Allow multiple CAs certificates from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2305

Sep 24 2023, 1:54 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev moved T5606: IPSec VPN: Allow multiple CAs certificates from Open to In Progress on the VyOS 1.5 Circinus board.
Sep 24 2023, 12:17 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev added a project to T5606: IPSec VPN: Allow multiple CAs certificates: VyOS 1.5 Circinus.
Sep 24 2023, 12:17 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev changed the status of T5606: IPSec VPN: Allow multiple CAs certificates from Open to In progress.
Sep 24 2023, 12:17 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev added a comment to T5160: Firewall refactor.

PR removing zone-policy op-mode: https://github.com/vyos/vyos-1x/pull/2304

Sep 24 2023, 11:44 AM · VyOS 1.4 Sagitta
sarthurdev changed the status of T5376: Conntrack FTP helper does not work properly from Confirmed to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2304

Sep 24 2023, 11:44 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
sarthurdev changed the status of T5598: unknown parameter 'nf_conntrack_helper' ignored from Confirmed to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2304

Sep 24 2023, 11:44 AM · VyOS 1.5 Circinus
indrajitr updated the task description for T5612: Miscellaneous improvements and fixes for dynamic DNS configuration.
Sep 24 2023, 1:32 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Sep 23 2023

Viacheslav changed the edit policy for T5613: VyOS in container bugs.
Sep 23 2023, 5:56 PM · VyOS Rolling, Bugs
Viacheslav added a parent task for T2115: VyOS cannot load configs when running in a container: T5613: VyOS in container bugs.
Sep 23 2023, 5:53 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a subtask for T5613: VyOS in container bugs: T2115: VyOS cannot load configs when running in a container.
Sep 23 2023, 5:53 PM · VyOS Rolling, Bugs
Viacheslav added a project to T2115: VyOS cannot load configs when running in a container: VyOS 1.5 Circinus.
Sep 23 2023, 5:53 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav committed rVYOSONEX7ad1e8c7d344: T5497: op-mode: Add generate firewall rule-resequence.
Sep 23 2023, 5:26 PM
GitHub <noreply@github.com> committed rVYOSONEX734392fdff12: Merge pull request #2302 from sever-sever/T5497 (authored by Viacheslav).
Sep 23 2023, 5:26 PM
Viacheslav updated the task description for T5613: VyOS in container bugs.
Sep 23 2023, 5:08 PM · VyOS Rolling, Bugs
Viacheslav created T5613: VyOS in container bugs.
Sep 23 2023, 5:07 PM · VyOS Rolling, Bugs
Viacheslav closed T5518: Add MLD protocol support as Resolved.
Sep 23 2023, 2:22 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3214: OpenVPN IPv6 fixes from Open to Needs testing.
Sep 23 2023, 1:55 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T5604: List of debian archives is out of date (non-free-firmware is missing) from Open to Needs testing.
Sep 23 2023, 1:48 PM · VyOS 1.5 Circinus

Sep 22 2023

indrajitr triaged T5612: Miscellaneous improvements and fixes for dynamic DNS configuration as Normal priority.
Sep 22 2023, 8:15 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T5602: For reverse-proxy type of load-balancing feature, support "backup" option in backends configuration as Resolved.
Sep 22 2023, 4:16 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a project to T4624: Move some op mode commands to "execute" and "produce" command families: VyOS 1.5 Circinus.
Sep 22 2023, 4:14 PM · VyOS Rolling
Viacheslav added a comment to T5497: Add ability to resequence rule numbers for firewall.

Op-mode command reduce
PR https://github.com/vyos/vyos-1x/pull/2302

vyos@r4:~$ show conf com | match firew
set firewall ipv4 input filter default-action 'accept'
set firewall ipv4 input filter rule 1 action 'accept'
set firewall ipv4 input filter rule 1 description 'Allow loopback'
set firewall ipv4 input filter rule 1 inbound-interface interface-name 'lo'
set firewall ipv4 input filter rule 1 source address '127.0.0.0/8'
set firewall ipv4 input filter rule 2 action 'accept'
set firewall ipv4 input filter rule 2 description 'Allow established/related'
set firewall ipv4 input filter rule 2 state established 'enable'
set firewall ipv4 input filter rule 2 state related 'enable'
set firewall ipv4 input filter rule 60 action 'accept'
set firewall ipv4 input filter rule 60 description 'Allow SSH from trusted networks'
set firewall ipv4 input filter rule 60 destination port '22'
set firewall ipv4 input filter rule 60 protocol 'tcp'
set firewall ipv4 input filter rule 10000 action 'drop'
set firewall ipv4 input filter rule 10000 description 'Drop everything else'
vyos@r4:~$ 
vyos@r4:~$ produce firewall rule-resequence start 10 step 10
Sep 22 2023, 3:58 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro moved T5607: Adjust RAID smoketest for non-deterministic SCSI device probing from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 22 2023, 3:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5607: Adjust RAID smoketest for non-deterministic SCSI device probing as Resolved.
Sep 22 2023, 3:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro moved T5608: Rewrite add/delete raid member to Python and remove from vyatta-op from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 22 2023, 3:05 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5608: Rewrite add/delete raid member to Python and remove from vyatta-op, a subtask of T5607: Adjust RAID smoketest for non-deterministic SCSI device probing, as Resolved.
Sep 22 2023, 3:05 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5608: Rewrite add/delete raid member to Python and remove from vyatta-op as Resolved.
Sep 22 2023, 3:05 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5608: Rewrite add/delete raid member to Python and remove from vyatta-op, a subtask of T5609: Add util to get drive device name from id, as Resolved.
Sep 22 2023, 3:05 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro moved T5609: Add util to get drive device name from id from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 22 2023, 3:04 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5609: Add util to get drive device name from id, a subtask of T5607: Adjust RAID smoketest for non-deterministic SCSI device probing, as Resolved.
Sep 22 2023, 3:04 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5609: Add util to get drive device name from id as Resolved.
Sep 22 2023, 3:04 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <noreply@github.com> committed rVYOSONEX90ce099f0653: Merge pull request #2301 from vyos/mergify/bp/sagitta/pr-2298 (authored by jestabro).
Sep 22 2023, 2:52 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX7447b4ef6e6c: op-mode: raid: T5608: define add/delete raid member (authored by jestabro).
Sep 22 2023, 2:33 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX4da9e2cf686a: op-mode: disk: T5609: add arg by-id to format disk (authored by jestabro).
Sep 22 2023, 2:33 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXb5edc618a442: vyos.utils: T5609: get disk device by partial id (authored by jestabro).
Sep 22 2023, 2:33 PM
a.apostoliuk created T5611: Difference in config file after interface MAC changed.
Sep 22 2023, 9:34 AM · VyOS Rolling, Bugs
GitHub <noreply@github.com> committed rVYOSONEXe0ce69365f46: Merge pull request #2291 from vyos/mergify/bp/sagitta/pr-2284 (authored by c-po).
Sep 22 2023, 4:17 AM
jestabro committed rVYOSONEXede0b5b1a19c: vyos.utils: T5609: get disk device by partial id.
Sep 22 2023, 4:17 AM
jestabro committed rVYOSONEX42736111facf: op-mode: disk: T5609: add arg by-id to format disk.
Sep 22 2023, 4:17 AM
jestabro committed rVYOSONEX2d3f3297b575: op-mode: raid: T5608: define add/delete raid member.
Sep 22 2023, 4:17 AM