Page MenuHomeVyOS Platform
Feed All Stories

Sep 28 2023

GitHub <[email protected]> committed rVYOSONEXfed59f9bddea: Merge pull request #2322 from sarthurdev/synproxy_fix (authored by c-po).
Sep 28 2023, 7:15 PM
c-po closed T5596: bgp: add new features from FRR 9 as Resolved.
Sep 28 2023, 6:55 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEXf6a87a32d61c: Merge pull request #2321 from vyos/mergify/bp/sagitta/pr-2307 (authored by c-po).
Sep 28 2023, 5:34 PM
zsdc changed the status of T5618: Flow-accounting crushes when IMT is enabled from Open to In progress.

This should fix the problem: https://github.com/vyos/vyos-build/pull/428

Sep 28 2023, 4:57 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX39d30e2034d7: mdns: T5615: Rename avahi-daemon config file (authored by indrajitr).
Sep 28 2023, 4:23 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX8701282fbcb5: mdns: T5615: Allow controlling IP version to use for mDNS repeater (authored by indrajitr).
Sep 28 2023, 4:23 PM
indrajitr committed rVYOSONEXe66f7075ee12: mdns: T5615: Allow controlling IP version to use for mDNS repeater.
Sep 28 2023, 4:22 PM
indrajitr committed rVYOSONEX3a3123485f2e: mdns: T5615: Rename avahi-daemon config file.
Sep 28 2023, 4:22 PM
GitHub <[email protected]> committed rVYOSONEX34772d635fa5: Merge pull request #2307 from indrajitr/mdns-ipversions (authored by c-po).
Sep 28 2023, 4:22 PM
GitHub <[email protected]> committed rVYOSONEX5fc286ae5262: Merge pull request #2319 from vyos/mergify/bp/sagitta/pr-2313 (authored by c-po).
Sep 28 2023, 3:24 PM
GitHub <[email protected]> committed rVYOSONEXef94ff7f9959: Merge pull request #2320 from vyos/mergify/bp/sagitta/pr-2306 (authored by c-po).
Sep 28 2023, 3:24 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX11641f9979d4: firewall: T5614: Add support for matching on conntrack helper (authored by sarthurdev).
Sep 28 2023, 3:10 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX8953f97829b1: T5165: Add option protocol for policy local-route (authored by Viacheslav).
Sep 28 2023, 3:07 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX1476dd6f90e0: T5217: Add firewall synproxy (authored by Viacheslav).
Sep 28 2023, 3:04 PM
Viacheslav committed rVYOSONEXbdad4e046872: T5217: Add firewall synproxy.
Sep 28 2023, 3:02 PM
GitHub <[email protected]> committed rVYOSONEX852e9c3328e6: Merge pull request #2295 from sever-sever/T5217-synproxy (authored by c-po).
Sep 28 2023, 3:02 PM
GitHub <[email protected]> committed rVYOSONEX7c2a0e781e23: Merge pull request #2317 from vyos/mergify/bp/sagitta/pr-2305 (authored by c-po).
Sep 28 2023, 3:02 PM
sarthurdev committed rVYOSONEXfd0bcaf120bc: conntrack: T5376: T5598: Fix for kernel conntrack helpers.
Sep 28 2023, 2:54 PM
sarthurdev committed rVYOSONEX5acf5acedbf7: conntrack: T5376: Use vyos.configdep to call conntrack-sync.
Sep 28 2023, 2:54 PM
GitHub <[email protected]> committed rVYOSONEX5bcd00a2ee5e: Merge pull request #2304 from sarthurdev/conntrack_helpers (authored by jestabro).
Sep 28 2023, 2:54 PM
sarthurdev committed rVYOSONEX81dee963a9ca: firewall: T5614: Add support for matching on conntrack helper.
Sep 28 2023, 2:52 PM
GitHub <[email protected]> committed rVYOSONEX6aa367918724: Merge pull request #2306 from sarthurdev/fw_helper (authored by jestabro).
Sep 28 2023, 2:52 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXe927f1912be4: ipsec: T5606: Add support for whole CA chains (authored by sarthurdev).
Sep 28 2023, 2:46 PM
sarthurdev committed rVYOSONEX1ac230548c86: ipsec: T5606: Add support for whole CA chains.
Sep 28 2023, 2:43 PM
GitHub <[email protected]> committed rVYOSONEX8ffe4a8cdd93: Merge pull request #2305 from sarthurdev/T5606 (authored by dmbaturin).
Sep 28 2023, 2:43 PM
Viacheslav committed rVYOSONEX96b8b38a3c17: T5165: Add option protocol for policy local-route.
Sep 28 2023, 2:37 PM
GitHub <[email protected]> committed rVYOSONEX448c140c0717: Merge pull request #2313 from sever-sever/T5165 (authored by dmbaturin).
Sep 28 2023, 2:37 PM
Unknown Object (User) raised the priority of T5619: Update the Intel ixgbe driver due to issues with Intel X533 from Normal to Requires assessment.
Sep 28 2023, 2:32 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Unknown Object (User) triaged T5619: Update the Intel ixgbe driver due to issues with Intel X533 as Normal priority.
Sep 28 2023, 2:32 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro changed the status of T5412: Add support for extending config-mode dependencies in supplemental package, a subtask of T4820: Support for inter-config-mode script dependencies, from Unknown Status to Resolved.
Sep 28 2023, 2:07 PM · VyOS 1.4 Sagitta
jestabro changed the status of T5412: Add support for extending config-mode dependencies in supplemental package, a subtask of T5403: Add support for extending xml cache , from Unknown Status to Resolved.
Sep 28 2023, 2:07 PM · VyOS 1.4 Sagitta
jestabro changed the status of T5412: Add support for extending config-mode dependencies in supplemental package from Unknown Status to Resolved.
Sep 28 2023, 2:07 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
erkin added a comment to T4038: Rewrite `vyatta-image-tools.pl` in Python.

show-dhcp-leases.pl under vyatta-op remains the only extant deadweight Vyatta script and needs to be removed.

Sep 28 2023, 2:07 PM · Restricted Project, VyOS 1.4 Sagitta
GitHub <[email protected]> committed rVYOSONEX4b323a2de6cc: Merge pull request #2315 from vyos/mergify/bp/sagitta/pr-2216 (authored by jestabro).
Sep 28 2023, 2:06 PM
JeffWDH added a comment to T5497: Add ability to resequence rule numbers for firewall.

https://github.com/vyos/vyos-1x/pull/2323

Sep 28 2023, 11:26 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
diodep updated subscribers of T5049: Configure GRE over IPsec tunnel when source port is in VRF, OSPF causes GRE tunnel broken..

It seems this problem is not caused by IPsec, but it was caused by GRE implementation.

Sep 28 2023, 8:29 AM · Restricted Project, VyOS 1.5 Circinus, VyOS Rolling

Sep 27 2023

jestabro moved T5412: Add support for extending config-mode dependencies in supplemental package from Open to Backport Candidates on the VyOS 1.4 Sagitta board.
Sep 27 2023, 5:55 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a comment to T5412: Add support for extending config-mode dependencies in supplemental package.

PR for sagitta:
https://github.com/vyos/vyos-1x/pull/2315

Sep 27 2023, 5:54 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX0cc75919dbaf: conf-mode: T5412: move dependency check from smoketest to nosetest (authored by jestabro).
Sep 27 2023, 5:53 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX540145791ecd: conf-mode: T5412: add script for add-on package check of dependencies (authored by jestabro).
Sep 27 2023, 5:53 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX2a94d9be0dc5: conf-mode: T5412: add support for supplemental dependency definitions (authored by jestabro).
Sep 27 2023, 5:53 PM
n.fort renamed T5616: Firewall mark - Add capabilities for matching firewall mark from Firewall marl - Add capabilities for matching firewall mark to Firewall mark - Add capabilities for matching firewall mark.
Sep 27 2023, 5:48 PM · VyOS 1.5 Circinus
n.fort added a comment to T5616: Firewall mark - Add capabilities for matching firewall mark.

PR: https://github.com/vyos/vyos-1x/pull/2314

Sep 27 2023, 5:48 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T5165: Policy local-route ability set protocol and port.

Add option protocol, PR https://github.com/vyos/vyos-1x/pull/2313

set policy local-route rule 100 destination '192.0.2.12'
set policy local-route rule 100 protocol 'tcp'
set policy local-route rule 100 set table '100'
Sep 27 2023, 2:10 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a comment to T5403: Add support for extending xml cache .

Adding use outline from PR for future reference; the dir vyos-1x-current below refers to a local copy of the vyos-1x source:

Sep 27 2023, 1:56 PM · VyOS 1.4 Sagitta
a.apostoliuk created T5618: Flow-accounting crushes when IMT is enabled.
Sep 27 2023, 1:21 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5593: Further shrink VyOS imagesize.

PR created for part 1/2 (vyatta-cfg-system): https://github.com/vyos/vyatta-cfg-system/pull/209

Sep 27 2023, 8:52 AM · VyOS 2.0.x
Viacheslav closed T5197: Conntrack-sync external cache commit error as Not Applicable.

Fixed

Sep 27 2023, 7:54 AM · VyOS 1.4 Sagitta
Viacheslav placed T5203: load-balancing wan add systemd unit instead of old vyatta-wanloadbalance.init up for grabs.
Sep 27 2023, 7:28 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5593: Further shrink VyOS imagesize.
Sep 27 2023, 12:16 AM · VyOS 2.0.x
Apachez added a comment to T5593: Further shrink VyOS imagesize.

Build was successful and smoketests are currently in progress.

Sep 27 2023, 12:07 AM · VyOS 2.0.x

Sep 26 2023

Apachez added a comment to T5593: Further shrink VyOS imagesize.

If build and smoketests are successful a commit will arrive later today.

Sep 26 2023, 11:15 PM · VyOS 2.0.x
jestabro added a comment to T5593: Further shrink VyOS imagesize.

... of course, feel free to experiment; I have not yet considered the proposed idea.

Sep 26 2023, 10:55 PM · VyOS 2.0.x
jestabro added a comment to T5593: Further shrink VyOS imagesize.

@Apachez note that those legacy image install scripts will be removed following
https://vyos.dev/T4516
Work on completing that is active this week and should be finished soon. You may want to hold off on this investigation until then.

Sep 26 2023, 10:54 PM · VyOS 2.0.x
Apachez claimed T5593: Further shrink VyOS imagesize.
Sep 26 2023, 9:50 PM · VyOS 2.0.x
Apachez added a comment to T5593: Further shrink VyOS imagesize.

Point 1 might be solved by using a hooks/live-script for the binary part which is the part after the chroot have been created.

Sep 26 2023, 9:49 PM · VyOS 2.0.x
Apachez added a comment to T5589: Nonstripped binaries exists in VyOS.

PR created: https://github.com/vyos/vyos-build/pull/426

Sep 26 2023, 8:58 PM · VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEX58344bc76962: Merge pull request #2311 from vyos/mergify/bp/sagitta/pr-2308 (authored by c-po).
Sep 26 2023, 6:50 PM
c-po committed rVYOSONEXd0d48cde5097: rpki: T2044: add to daemons Jinja2 template.
Sep 26 2023, 6:48 PM
GitHub <[email protected]> committed rVYOSONEX254c2907525a: Merge pull request #2312 from c-po/rpki-fixes (authored by c-po).
Sep 26 2023, 6:48 PM
GitHub <[email protected]> committed rVYOSONEX13e9c9e85320: Merge pull request #2309 from vyos/mergify/bp/sagitta/pr-2302 (authored by Viacheslav).
Sep 26 2023, 6:35 PM
Apachez added a comment to T5589: Nonstripped binaries exists in VyOS.

Turned out to be little of a challenge do "just" strip all binaries (and libraries, modules etc).

Sep 26 2023, 6:12 PM · VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX07dfc6216be7: firewall: T5160: Remove zone policy op-mode (authored by sarthurdev).
Sep 26 2023, 6:11 PM
sarthurdev committed rVYOSONEX9b9b37e9cbb2: firewall: T5160: Remove zone policy op-mode.
Sep 26 2023, 6:11 PM
GitHub <[email protected]> committed rVYOSONEX6ffb104ada0a: Merge pull request #2308 from sarthurdev/fw_opmode (authored by c-po).
Sep 26 2023, 6:10 PM
syncer assigned T5497: Add ability to resequence rule numbers for firewall to n.fort.
Sep 26 2023, 6:10 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
JeffWDH added a comment to T5497: Add ability to resequence rule numbers for firewall.

Also added flowtable as nothing needs to be sequenced in there either:
https://github.com/JeffWDH/vyos-1x/commit/ac22cc054d9c15af010c824ac9a05f5cc71fc954

Sep 26 2023, 6:10 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
JeffWDH added a comment to T5497: Add ability to resequence rule numbers for firewall.

I have not contributed code to this project before so let me know if I've missed conventions...

Sep 26 2023, 5:52 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
b- added a comment to T4915: Minisign verification failure == pass??.

Just to be clear, the build I'm going from is just my own build of current to my own build of current -- it says 1.4 because I only changed the version string to 1.5 after this build went through since i'm the only one using my build :)

Sep 26 2023, 5:48 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
b- triaged T4915: Minisign verification failure == pass?? as High priority.

I just noticed that this still is a problem. Excerpt below from downloading an upgrade:

Sep 26 2023, 5:42 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
dmbaturin created T5617: Add an option to exclude single values to the numeric validator.
Sep 26 2023, 5:40 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T5586: Disable by default SNMP for Keepalived VRRP.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/2310

Sep 26 2023, 3:00 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T5497: Add ability to resequence rule numbers for firewall.

1.5-rolling-202309250022

Is there a reason why some global options and some address groups (not all) are included in the output? Seems unintentional to me.

Sep 26 2023, 2:41 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
JeffWDH added a comment to T5497: Add ability to resequence rule numbers for firewall.

Is there a reason why some global options and some address groups (not all) are included in the output? Seems unintentional to me.

Sep 26 2023, 2:24 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav closed T5480: Ability to disable SNMP for VRRP keepalived service as Resolved.
Sep 26 2023, 1:26 PM · VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXecfb617e99dc: T5497: op-mode: Add generate firewall rule-resequence (authored by Viacheslav).
Sep 26 2023, 1:20 PM
Viacheslav added a comment to T5616: Firewall mark - Add capabilities for matching firewall mark.

We have fwmark for policy local-route
But it is only for match mark and routing decision

vyos@vyos-lns# set policy local-route rule 100 
Possible completions:
+  destination          Destination address or prefix
   fwmark               Match fwmark value
   inbound-interface    Inbound Interface
 > set                  Packet modifications
+  source               Source address or prefix
Sep 26 2023, 12:47 PM · VyOS 1.5 Circinus
n.fort changed the status of T5616: Firewall mark - Add capabilities for matching firewall mark from Open to Confirmed.
Sep 26 2023, 12:11 PM · VyOS 1.5 Circinus
n.fort created T5616: Firewall mark - Add capabilities for matching firewall mark.
Sep 26 2023, 12:11 PM · VyOS 1.5 Circinus

Sep 25 2023

Apachez added a comment to T5589: Nonstripped binaries exists in VyOS.

Have to add Debian package "binutils" to make "strip" work within the chroot of livebuild.

Sep 25 2023, 7:05 PM · VyOS 1.5 Circinus
jestabro added a comment to T5611: Difference in config file after interface MAC changed.

This is an artifact of the remaining use in 1.3 of the legacy XorpConfigParser: the last use of that legacy piece was removed from 1.4 in Sep 2021, but is still called by 'vyatta_interface_rescan' in 1.3, so will be seen after changing MAC addresses if the config is not saved. A quick summary of the history is here and quoted below:

Sep 25 2023, 4:51 PM · Restricted Project, VyOS 1.3 Equuleus (1.3.9)
Apachez claimed T5589: Nonstripped binaries exists in VyOS.
Sep 25 2023, 4:34 PM · VyOS 1.5 Circinus
Apachez added a comment to T5589: Nonstripped binaries exists in VyOS.

Implement hooks-script for livebuild that recursively go through following directories using "strip --strip-all" (syntax to be verified):

Sep 25 2023, 4:30 PM · VyOS 1.5 Circinus
Apachez added a comment to T5522: Add logging for which mksquashfs syntax is being used.

Shouldnt that be default for lb then in the vyos buildscripts and how does --debug affect things other than logging during build?

Sep 25 2023, 4:00 PM · VyOS 1.5 Circinus
Apachez added a comment to T5379: show system updates doesnt seem to be working.

What is the "system update-check url" supposed to be once its implemented?

Sep 25 2023, 3:54 PM · VyOS 1.4 Sagitta
dmbaturin edited the content of 1.3.4.
Sep 25 2023, 3:42 PM
dmbaturin merged T3144: Support op-mode command to release DHCP leases into T1375: Add clear dhcp server lease function.
Sep 25 2023, 2:13 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dmbaturin merged task T3144: Support op-mode command to release DHCP leases into T1375: Add clear dhcp server lease function.
Sep 25 2023, 2:12 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin edited projects for T2640: Running VyOS inside Docker containers, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus (1.3.4).
Sep 25 2023, 2:08 PM · VyOS 1.3 Equuleus (1.3.3)
dmbaturin changed Issue type from feature to bug on T3070: Firewall going OOM, possible related to nftables migration.
Sep 25 2023, 1:52 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin changed Issue type from feature to internal on T4874: Add Warning message to Equuleus.
Sep 25 2023, 1:46 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin changed Issue type from unspecified to bug on T5524: Add config directory to liveCD.
Sep 25 2023, 1:41 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dmbaturin changed Issue type from unspecified to feature on T5354: Add sshguard to protect against brut-forces for 1.3.
Sep 25 2023, 1:40 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin changed Issue type from unspecified to improvement on T5315: vrrp: add support for version 3.
Sep 25 2023, 1:39 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dmbaturin changed the status of T4479: generate wireguard client command prompt has some error from Not Applicable to Invalid.
Sep 25 2023, 1:38 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin renamed T3546: Add support for running scripts on PPPoE server session events from Add pppoe-server CLI custom script feature to Add support for running scripts on PPPoE server session events.
Sep 25 2023, 1:37 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin set Issue type to feature on T3546: Add support for running scripts on PPPoE server session events.
Sep 25 2023, 1:36 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin set Issue type to bug on T3339: Cloud-Init domain search setting not applied.
Sep 25 2023, 1:36 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dmbaturin closed T5533: Keepalived VRRP IPv6 group enters in FAULT state as Resolved.
Sep 25 2023, 1:28 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dmbaturin renamed T5526: Clarify the error message when trying to set an interface as a BGP peer group using the wrong syntax from BGP peer-group - don't support add interfaces over peer neigborhs to Clarify the error message when trying to set an interface as a BGP peer group using the wrong syntax.
Sep 25 2023, 1:27 PM · Restricted Project, VyOS 1.3 Equuleus (1.3.8)